Paging access method and apparatus, and device
By using group keys to encrypt the terminal identification in the paging terminal device process of network equipment, the problems of high computing complexity and high power consumption in the prior art are solved, and lower signaling overhead and power consumption are achieved.
Patent Information
- Application Number
- PCT/CN2024/128077
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-29
- Publication Date
- 2025-05-08
AI Technical Summary
In the process of paging terminal equipment in the prior art, asymmetric key encryption and decryption are used for the protection mechanism of terminal identification, resulting in high computational complexity, large processing overhead and high power consumption.
The terminal identifier of the terminal device is encrypted using a group key, and by carrying the group key indication information in the paging message, the first terminal device can encrypt and decrypt the terminal identifier using the indicated group key.
Reduces the complexity of the terminal identification encryption and decryption process, reduces signaling overhead, and reduces overall power consumption.
Smart Images

Figure CN2024128077_08052025_PF_FP_ABST
Abstract
Description
Paging access method, device and equipment
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on October 31, 2023, with application number 202311442823.5 and application name “A Paging Access Method, Device and Equipment”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a paging access method, apparatus, and device. Background Art
[0003] Currently, when a network device pages a terminal device, the protection mechanism for the terminal identity document (ID) is to encrypt and decrypt the terminal identity using an asymmetric key. For example, different keys are used for the encryption and decryption processes. Specifically, the user equipment (UE) encrypts and transmits its ID anonymously using a temporary key. The unified data management (UDM) calls the subscription identifier de-concealing function (SIDF) module to decrypt the user permanent identifier (SUPI). Based on the SUPI, the UDM selects the corresponding authentication method according to local policy and sends a message to the UE. After calculation, the UE sends an authentication response message to the UDM, carrying the corresponding SUPI, authentication timestamp, authentication type, serving network name, and other information. The UDM confirms and stores the received message content and authentication result. The encryption and decryption process based on this mechanism has high computational complexity, large processing overhead, and high power consumption.
[0004] Summary of the Invention
[0005] The present application provides a paging access method, apparatus, and device, which can use a group key to encrypt the terminal identification of a terminal device, thereby ensuring the security of the terminal identification during transmission while reducing the complexity of the terminal identification encryption and decryption process and the signaling overhead.
[0006] To achieve the above objectives, this application adopts the following technical solutions:
[0007] In a first aspect, a paging access method is provided, applied to a first terminal device, and the method may include:
[0008] First, a first terminal device receives a paging message from a core network device. The paging message carries group key indication information, and the group key indication information is targeted at at least one terminal device, including the first terminal device. This step is primarily used to receive the paging message sent by the core network device and obtain the group key indication information in the paging message. The group key indication information may indicate a corresponding group key, and the same group key can be sent to one or more terminal devices.
[0009] Then, the first terminal device sends a first authentication request message to the core network device. The first authentication request message includes the terminal identifier of the first terminal device. The terminal identifier is encrypted based on the first information. The first information includes the identifier of the group key indicated by the group key indication information. This step is mainly used when the first terminal device randomly accesses the core network. The first terminal device sends an authentication request message to the core network device. The terminal identifier in the authentication request message needs to be encrypted. The terminal identifier is encrypted using the group key indicated by the group key indication information. Among them, the group key indication information is used to indicate the group key in the process of the core network device sending a paging message. The same group key can correspond to one or more group key indication information. The first information is used when the first terminal device sends the first authentication request message. The first information may include the group key.
[0010] Exemplarily, the above-mentioned first terminal device may include a terminal and a tag, specifically, including a device without energy storage and independent signal generation, such as a backscatter transmission device with this characteristic; including a device with energy storage but without independent signal generation, such as a backscatter transmission device with this characteristic, wherein the use of stored energy may include amplification of the reflected signal; and also including a device with energy storage and independent signal generation, such as an active wireless radio frequency (RF) component for transmission.
[0011] As a possible implementation method, the above-mentioned first authentication request message includes a first identifier, and the first identifier includes one or more of the following: a group key identifier, an inventory identifier corresponding to the group key, a group identifier information, a mask information, an inventory identifier, an event identifier, and a group key identifier index. Based on this, during the authentication process of the terminal device, in the first authentication request message sent by the terminal device to the core network device, the first identifier can be a group key identifier or an inventory identifier corresponding to the group key identifier, a group identifier information, a mask information, an inventory identifier, an event identifier, and a group key identifier index, wherein the group key identifier can directly indicate the corresponding group key for the core network device to decrypt the first authentication request message, and the inventory identifier can indicate the storage location of the group key so that the core network device can obtain the group key to decrypt the first authentication request message.
[0012] As a possible implementation, the group key indication information may include one or more of the following: group identification information, mask information, inventory identification, event identification, and group key identification index. Based on this, during the paging process of a terminal device, the core network device sends a paging message to one or more terminal devices. The group key indication information carried in the paging message may include the group identification information, mask information, inventory identification, event identification, and group key identification index. The group identification information, mask information, inventory identification, event identification, and group key identification index may directly or indirectly indicate the corresponding group key to the terminal device, so that the terminal device uses the group key to encrypt the terminal identification.
[0013] As a possible implementation, the first information may also include a random number. The random number can be used as a parameter in the encryption process of the terminal identifier using the group key to improve the security of the terminal identifier during transmission. Accordingly, the first authentication request message includes the random number. The random number is used as a parameter when encrypting the terminal identifier using the group key when sending the first authentication request message.
[0014] As a possible implementation, sending the first authentication request message to the core network device may include: sending the first authentication request message to the core network device via the first network device. Based on this, the first terminal device may directly send the first authentication request message to the core network device so that the core network device authenticates the first terminal device. At the same time, the first terminal device may also send the first authentication request message to the core network device via the first network device so that the core network device authenticates the first terminal device.
[0015] Specifically, as a possible implementation method, the above-mentioned sending of the first authentication request message to the core network device through the first network device may include: sending the first authentication request message and the second authentication request message to the first network device, sending a third message to the core network device through the first network device, the third message including one or more authentication request information, and the multiple authentication request information including the first authentication request message and the second authentication request message. Based on this, the terminal device sends the authentication request message to the core network device through the first network device, which may be one or more terminal devices sending one or more authentication request information to the first network device. The first network device may send one or more authentication request information to the core network device separately, the multiple authentication request information may come from one or more terminal devices, or one or more authentication request information may be sent together as a third message to the core network device. The third message may be one or more, so that the core network device authenticates one or more terminal devices.
[0016] As a possible implementation, the first authentication request message and the second authentication request message do not include the first identifier, while the third message includes the first identifier. Based on this, if the authentication request message sent by the first terminal device to the first network device does not include the first identifier, the first network device may add the corresponding first identifier to the authentication request message to indicate the group key used to encrypt the terminal identifier in the authentication request message sent by the first network device.
[0017] As a possible implementation, before sending the first authentication request message to the core network device, the method may further include: accessing the core network device according to the paging message. Based on this, after receiving the paging message, the first terminal device may access the core network device through a 2-step random access or a 4-step random access method, and then send the authentication request message to the core network device.
[0018] As a possible implementation, the method may further include: encrypting the target data using a group key indicated by the core network device or the first network device, or a root key corresponding to the first terminal device, and sending the encrypted target data to the core network device. Based on this, data transmission can be performed between the core network device and the terminal device. During the data transmission process, the target data can be encrypted using the group key indicated by the core network device or the first network device, or the root key corresponding to the first terminal device, to ensure data security during transmission.
[0019] In a second aspect, a paging access method is provided, which is applied to a core network device. The method may include:
[0020] First, in response to the first service request, the core network device sends a paging message to the first terminal device. The paging message carries group key indication information. The group key indication information is for at least one terminal device, and the at least one terminal device includes the first terminal device. This step is mainly used to enable the core network device to send a paging message to one or more terminal devices upon receiving the first service request. The paging message includes group key indication information, where the group key indication information can indicate a corresponding group key, and the same group key can be sent to one or more terminal devices.
[0021] Then, a first authentication request message is received from the first terminal device. The first authentication request message includes a terminal identifier of the first terminal device, the terminal identifier is encrypted based on the first information, and the first information includes an identifier of the group key indicated by the group key indication information. This step is primarily used by the core network device to obtain the first authentication request message sent by the first terminal device, where the first authentication request message includes the first information indicating the group key.
[0022] Finally, the first terminal device is authenticated based on the first authentication request message. This step is mainly used by the core network device to obtain the first information in the first authentication request message, decrypt the terminal identifier of the first terminal device based on the first information, obtain the terminal identifier of the first terminal device, and authenticate the first terminal device based on the terminal identifier.
[0023] As a possible implementation, authenticating the first terminal device based on the first authentication request message may include: decrypting the first authentication request message to obtain a terminal identifier of the first terminal device; and authenticating the terminal identifier of the first terminal device. Based on this, the core network device may decrypt the terminal identifier of the first terminal device using the group key indicated by the first information in the first authentication request message, and authenticate the first terminal device based on the decrypted terminal identifier to obtain an authentication result.
[0024] As a possible implementation, the first authentication request message includes a first identifier, and the first identifier includes one or more of the following: a group key identifier, an inventory identifier corresponding to the group key, group identifier information, mask information, an inventory identifier, an event identifier, and a group key identifier index. Based on this, during the authentication process of the terminal device, in the first authentication request message received by the core network device, the first identifier may be a group key identifier or an inventory identifier corresponding to the group key identifier, wherein the group key identifier may directly indicate the corresponding group key for the core network device to decrypt the first authentication request message, and the inventory identifier may indicate the storage location of the group key so that the core network device can obtain the group key to decrypt the first authentication request message.
[0025] As a possible implementation, the group key indication information includes one or more of the following: group identification information, mask information, inventory identification, event identification, and group key identification index. Based on this, during the paging process of a terminal device, the core network device sends a paging message to one or more terminal devices. The group key indication information carried in the paging message may include group identification information, mask information, inventory identification, event identification, and group key identification index. The group identification information, mask information, inventory identification, event identification, and group key identification index can directly or indirectly indicate the corresponding group key to the terminal device, so that the terminal device uses the group key to encrypt the terminal identification and send it to the core network device.
[0026] As a possible implementation, the first information may also include a random number. The random number can be used as a parameter in the decryption process of the terminal identifier using the group key to improve the security of the terminal identifier during transmission. Accordingly, the first authentication request message may include the random number. The random number is used as a parameter when decrypting the terminal identifier using the group key upon receiving the first authentication request message.
[0027] As a possible implementation, receiving the first authentication request message from the first terminal device may include receiving the first authentication request message forwarded by the first terminal device via the first network device. Based on this, the core network device may directly receive the first authentication request message sent by the terminal device and authenticate the first terminal device. Simultaneously, the core network device may also receive the first authentication request message sent by the first terminal device via the first network device and authenticate the first terminal device.
[0028] As a possible implementation method, the above-mentioned receiving of the first authentication request message forwarded by the first terminal device through the first network device includes: receiving a third message through the first network device, the third message including one or more authentication request messages, the multiple authentication request messages including the first authentication request message and the second authentication request message. Based on this, the core network device receives the third message through the first network device, which may be the first terminal device sending one or more authentication request messages to the first network device, the first network device may send one or more authentication request messages sent by the terminal device to the core network device, and the multiple authentication request messages may come from multiple terminal devices. Then, the core network device authenticates the one or more terminal devices based on the received third message.
[0029] As a possible implementation, after the core network device sends a paging message to the first terminal device, the method may further include: responding to a random access request from the first terminal device to allow the first terminal device to access the core network device. Based on this, after sending the paging message, the core network device may allow the terminal device to access the core network device by responding to a 2-step random access or 4-step random access request, and then receive an authentication request message from the terminal device.
[0030] As a possible implementation, after the first terminal device passes authentication, the method may further include: receiving target data from the first terminal device; and decrypting the target data using a group key indicated by the core network device or the first network device, or a root key corresponding to the first terminal device. Based on this, if authentication between the core network device and the terminal device is successful and data transmission is possible, the target data may be encrypted during the data transmission process using the group key indicated by the core network device or the first network device, or the root key corresponding to the first terminal device, to ensure data security during transmission.
[0031] According to a third aspect, an electronic device is provided, which may include:
[0032] Transceiver, used for sending and receiving signals;
[0033] a memory for storing computer program instructions;
[0034] A processor is used to execute computer program instructions to support an electronic device to implement the method in any possible implementation manner of the first aspect and the second aspect.
[0035] In a fourth aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processing circuit, the method in any possible implementation of the first aspect and the second aspect is implemented.
[0036] In a fifth aspect, a computer program product comprising instructions is provided, which, when the computer program product is run on a computer, enables the computer to execute the method in any possible implementation of the first and second aspects.
[0037] In a sixth aspect, a chip system is provided, which includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, a method in any possible implementation of the first aspect and the second aspect is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] FIG1 is a flowchart illustrating an authentication method for a terminal device according to a related art;
[0039] FIG2 is a schematic diagram a of an application scenario of a paging access method provided in an embodiment of the present application;
[0040] FIG3 is a schematic diagram b of an application scenario of a paging access method provided in an embodiment of the present application;
[0041] FIG4 is a schematic diagram c of an application scenario of a paging access method provided in an embodiment of the present application;
[0042] FIG5 is a schematic diagram d of an application scenario of a paging access method provided in an embodiment of the present application;
[0043] FIG6 is a schematic diagram e of an application scenario of a paging access method provided in an embodiment of the present application;
[0044] FIG7 is a flow chart a of a paging access method provided in an embodiment of the present application;
[0045] FIG8 is a flow chart b of a paging access method provided in an embodiment of the present application;
[0046] FIG9 is a flow chart c of a paging access method provided in an embodiment of the present application;
[0047] FIG10 is a flow chart d of a paging access method provided in an embodiment of the present application;
[0048] FIG11 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0049] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in a wireless communication system, communication devices can use air interface resources for wireless communication. Among them, communication devices may include network devices and terminal devices, and network devices may also be referred to as network side devices. Air interface resources may include at least one of time domain resources, frequency domain resources, code resources and space resources. In the embodiments of the present application, at least one can also be described as one or more, and multiple can be two, three, four or more, and this application does not impose any restrictions.
[0050] Hereinafter, the terms "first," "second," and so on are used solely to distinguish different descriptive objects and have no limiting effect on the position, order, priority, quantity, or content of the described objects. For example, if the described object is a "field," the ordinal number preceding the "field" in "first field" and "second field" does not define the position or order of the "fields." "First" and "second" do not define whether the modified "fields" are in the same message, nor do they restrict the order of the "first field" and "second field." For another example, if the described object is a "level," the ordinal number preceding the "level" in "first level" and "second level" does not define the priority of the "levels." For another example, the number of described objects is not limited by the ordinal number and can be one or more. For example, in the case of "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," the "first device" and "second device" can be the same type of device or different types of devices. For another example, if the described object is "information," the "first information" and "second information" can be information of the same content or different contents. In short, the use of prefixes such as ordinal numbers to distinguish the described objects in the embodiments of the present application does not constitute a restriction on the described objects. For the statement of the described objects, please refer to the description in the context of the claims or embodiments, and no unnecessary restrictions should be constituted due to the use of such prefixes.
[0051] Furthermore, in the embodiments of the present application, "connection" may be a direct connection or an indirect connection; in addition, it may refer to an electrical connection or a communication connection; for example, the connection between two electrical components A and B may refer to a direct connection between A and B, or may refer to an indirect connection between A and B through other electrical components or connection media, or may refer to an indirect connection between A and B through other communication devices or communication media, as long as communication between A and B can be achieved.
[0052] For ease of understanding, the relevant technical terms involved in the embodiments of this application are first explained below.
[0053] 1. Terminal device: It can be a device with wireless transceiver capabilities, which can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal device can be user equipment (UE), where UE includes handheld devices, vehicle-mounted devices, wearable devices or computing devices with wireless communication capabilities. For example, UE can be a mobile phone, a tablet computer or a computer with wireless transceiver capabilities. The terminal device can also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in smart grids, a wireless terminal in smart cities, a wireless terminal in smart homes, etc. In the embodiment of the present application, the device for realizing the function of the terminal can be a terminal; it can also be a device that can support the terminal to realize the function, such as a chip system, which can be installed in the terminal. In the embodiment of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices. In the technical solutions provided in the embodiments of the present application, the device for implementing the functions of the terminal is a terminal, and the terminal is a UE as an example to describe the technical solutions provided in the embodiments of the present application.
[0054] 2. Core network equipment: It is a network element device that performs core switching or call routing functions. Its main function is to control the entire call signaling and establish bearer. It provides user connection, user management, and service bearer, and provides an interface to the external network as a bearer network. The establishment of user connection includes functions such as mobility management (MM), call management, switching / routing, and recording notification (combined with intelligent network services to complete the connection relationship to the intelligent network peripheral equipment). User management includes user description, QoS (including the description of user service QoS), user communication records (Accounting), dialogue with the intelligent network platform to provide a virtual home environment, and security (the authentication center provides corresponding security measures, including security management of mobile services and security processing of external network access). Bearer connections (Access to) include those to the external public switched telephone network (PSTN), external circuit data network and packet data network, wide area network and local area network, as well as mobile's own SMS server, etc. The basic services that the core network can provide include mobile office, e-commerce, communication, entertainment services, travel and location-based services, telemetry services - simple messaging services (monitoring and control), etc.
[0055] 3. Network device: It can be any device with wireless transceiver functions. Including but not limited to: evolved base stations (E-UTRAN NodeB or e-NodeB or eNB) in LTE, base stations (gNodeB or gNB) or transmission / reception points (TRP) in 5G or new radio (NR) access technology, base stations of subsequent 3GPP evolution, access nodes in WiFi systems, wireless relay nodes, wireless backhaul nodes, etc. Base stations can be: macro base stations, micro base stations, pico base stations, small stations, wireless controllers, centralized units (CU), and / or distributed units (DU) in the cloud access network (CRAN) scenario. Network devices can also be servers, wearable devices, or vehicle-mounted devices. The following description takes the network device as a base station as an example. The multiple network devices can be base stations of the same type or different types. The base station can communicate with the terminal device or communicate with the terminal device through a relay station. The terminal device can communicate with multiple base stations of different technologies. For example, the terminal device can communicate with a base station that supports the LTE network, and can also communicate with a base station that supports the 5G network. It can also support dual connections with base stations of the LTE network and base stations of the 5G network.
[0056] The network equipment involved in the embodiments of the present application may include a base station (BS), which may be a device deployed in a wireless access network that can communicate wirelessly with a terminal. Among them, the base station may have various forms, such as a macro base station, a micro base station, a relay station, and an access point. Exemplarily, the base station involved in the embodiments of the present application may be a base station in 5G or a base station in long term evolution (LTE), wherein the base station in 5G can also be called a transmission reception point (TRP) or gNB. In the embodiments of the present application, the device for realizing the function of the network device may be a network device; it may also be a device that can support the network device to realize the function, such as a chip system, which can be installed in the network device. In the technical solution provided in the embodiments of the present application, the technical solution provided in the embodiments of the present application is described by taking the device for realizing the function of the network device as a network device and the network device as a base station as an example.
[0057] The technical solution provided in the embodiment of the present application can be applied to wireless communication between communication devices. Wireless communication between communication devices may include: wireless communication between network devices and terminals, wireless communication between network devices and network devices, and wireless communication between terminals. Specifically, uplink and downlink transmission can be performed between network devices and terminal devices via a cellular link (Uu link). In the embodiment of the present application, the term "wireless communication" can also be referred to as "communication", and the term "communication" can also be described as "data transmission", "information transmission" or "transmission".
[0058] In one possible implementation, the terminal device may communicate with the core network device through the network device.
[0059] 4. Electronic tag: An electronic tag can also be called a terminal or device. These tags can be categorized into three types: active, passive, and semi-active. Alternatively, they can be divided into passive, semi-passive, and active tags. Passive and semi-passive tags utilize backscatter-based communication, while active tags employ active carrier generation. Tags can be categorized based on whether they utilize backscatter-based communication, whether they have the ability to store energy, whether they don't, or a combination of both. At present, in the discussion on artificial intelligence and internet of things (AIOT), three types of terminals or devices have been preliminarily defined in the standard, which are also applicable to the application, including: devices without energy storage and independent signal generation, such as devices with backscatter transmission with this characteristic, such as device A; or, devices with energy storage but without independent signal generation, such as devices with backscatter transmission with this characteristic, such as device B, where the use of stored energy may include amplification of reflected signals; or, devices with energy storage and independent signal generation, such as active wireless radio frequency (RF) components for transmission, such as device C.
[0060] 5. Reader / writer: It can be a handheld or fixed device that reads (and sometimes writes) tag information. It can also be understood as a device that communicates with the tag. It can be in the form of a terminal, a base station, or a device with read and write functions. It can also be an IAB node or a relay node. The reader / writer helper / excitation source involved in the embodiments of the present application can be a terminal, or a base station or a small station. The device has only downlink communication with the tag, and has uplink and downlink data transmission with the reader / writer, which may be through an air interface or a wired connection.
[0061] 6. Inventory: The process in which the reader triggers multiple tags to complete reporting is called the inventory process.
[0062] 7. Inventory flag: This can be implemented in software or as a hardware capacitor, with a two-state flag (either A / B or 0 / 1). A tag can contain at least one inventory flag, which determines whether to respond to the reader's instructions. The reader can select tags with inventory flag A or B to access the network.
[0063] The following is a brief description of the main network elements in the 5G network system involved in the embodiments of the present application.
[0064] 1. User equipment (UE). 2. Radio access network (R)AN), hereinafter referred to as RAN, corresponding to access network equipment. For example, RAN can be NB, eNB, gNB, ng-eNB, or any other access network equipment. 3. Access and mobility management function (AMF). 4. Application function (AF): used for data routing affected by applications, access network open function network elements, interaction with the policy framework for policy control, etc. 5. Unified data management (UDM): used for processing UE identification, access authentication, registration and mobility management, etc. 6. Authentication server function (AUSF). It can be understood that the above-mentioned network elements or functions can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (for example, a cloud platform).
[0065] With the increasing adoption of 5G NR machine-type communications (MTC) and the Internet of Things (IoT), the number of connected IoT devices is growing daily. Consequently, the industry is increasingly demanding lower costs and power consumption for IoT devices. During the 4G era, 3GPP introduced the narrowband IoT (NB-IoT) system. However, NB-IoT terminals require external power (batteries) and are capable of generating a local high-frequency local oscillator (LO). Consequently, these terminals can only consume milliwatts of power. However, with the evolution and development of 5G IoT, the demand for even lower-power terminals within 5G networks is growing. Radio frequency identification (RFID) technology offers a promising technology for achieving low power consumption, supporting microwatts. RFID terminals (tags) use low-precision, low-power, medium- to low-frequency ring oscillators or no LO at all to receive downlink signals. When operating, the tag's communication energy and carrier are supplied by the reader, and communication is based on reflected carrier waves.
[0066] Given the low-power advantages of RFID communication technology, the 5G Ambient IoT (Ambient IoT) has emerged. To meet ultra-low power requirements, terminal devices in the Ambient IoT use low-precision, low-power, medium- and low-frequency ring oscillators, or even no local oscillator at all, to receive downlink signals. This reception method can further reduce the power consumption of downlink reception on terminal devices. However, for such low-power reception methods, only amplitude detection, such as envelope detection, can be performed, as a low-precision ring oscillator alone cannot guarantee accurate demodulation of signal phase information. Existing RFID terminals are low-cost and low-complexity in design, but their coverage is poor and their application scenarios are limited. During the research process for 5G Ambient IoT, coverage enhancement designs were implemented, which also presented corresponding challenges.
[0067] In the related art, the authentication process of a terminal device is shown in FIG1 , which shows a flow chart of a terminal device authentication method provided by the related art. The terminal identification document (ID) is first decrypted, and then the authentication is performed. Specifically, as shown in FIG1 , the method may include:
[0068] S1: The terminal connects to the network and initiates a registration request to the core network through the NAS layer. The registration request message may carry a temporary terminal device identifier (5G Globally Unique Temporary Identifier, 5G-GUTI) or a user hidden identifier (SUCI) or a user permanent identifier (SUPI) depending on the actual status of the UE.
[0069] S2. The AMF initiates an initial authentication request. The authentication request includes (SUCI / SUPI, SNN). When a valid 5G-GUTI is received, the corresponding SUPI shall be included in the forwarding request message. If a SUCI is received, the SUCI shall be included directly in the request message. This message also includes information such as the Media Access Control Protocol (MAC) for the core network to verify the validity of the SUCI.
[0070] S3. Authentication server function (AUSF), carrying: SUCI / SUPI, SNN, event: checks the SNN and checks whether the AMF is authorized to use the serving network. If the check passes, the AUSF sends a message to the UDM / ARPF requesting authentication data. If the check fails, the AUSF returns "serving network not authorized" to the AMF.
[0071] S4.UDM sets Bit "0" (high bit, AMF separation bit) of AMF to 1, carries: authentication quadruple, SUPI, and then performs the following processing:
[0072] 4a. UDM calls the SIDF module to complete SUCI->SUPI decryption.
[0073] It should be noted that during this process, the UE only transmits its own ID encrypted with a temporary key in an anonymous manner. This does not prove that the UE is the legitimate identity of the corresponding SUPI. The home network completes the UE identity verification in step 17.
[0074] 4b. Check whether the security capabilities carried by the UE are valid or acceptable.
[0075] 4c.UDM is based on SUPI and selects the corresponding authentication method according to local policy.
[0076] 4d. Generate a random number (RAND) and obtain the user's current SQN.
[0077] 4e. Generate 5G HE AV (RAND, AUTN, XRES*, KAUSF).
[0078] S5. UDM sends a message to AUSF, carrying 5G HE AV. If SUCI is included in the message received in the previous step, the restored SUPI is placed in the message and the authentication method is selected based on the user's contract information.
[0079] S6.AUSF performs the following steps:
[0080] 6a. Calculate XRES*, store XRES* and the corresponding SUPI or SUCI, and generate KSEAF.
[0081] 6b. Generate 5G SE AV (RAND, AUTN, HXRES*).
[0082] S7.AUSF sends a message to AMF, carrying 5G SE AV (RAND, AUTN, HXRES*).
[0083] S8.AMF saves HXRES*.
[0084] S9. The AMF sends an Authentication Request message to the UE, carrying RAND, AUTN, ngKSI, and ABBA. ABBA (anti-bidding down between architectures parameter) is used to prevent network degradation attacks.
[0085] S10. The USIM calculates XMAC using RAND and AUTN, and compares it with the MAC in AUTN. If the two are consistent, it proceeds to the next step. Otherwise, the UE side fails to authenticate the network side, and an Authentication Failure message is sent to the AMF / SEAF.
[0086] S11. The USIM determines whether the SQN in the AUTN is within the correct range. If the result is correct, the UE is considered to have successfully completed the authentication of the network. Otherwise, it is considered that the UE and the network have failed to authenticate the SQN and a synchronization failure (Synchronisation Failure) is returned to the AMF / SEAF.
[0087] S12. The UE side performs the following processing: verifying AUTN, deriving RES, secret keys (CK, IK), and calculating RES*.
[0088] 12a. The USIM calculates RES and returns RES, CK, and IK to the ME.
[0089] 12b.ME uses RES to calculate RES*. RES* is calculated using KDF and the lower 128 bits are taken.
[0090] S13.UE sends an Authentication Response message to AMF, carrying RES*.
[0091] S14.AMF calculates HRES* from the received RES* and compares it with the locally stored HXRES*. If the two are equal, the service network is considered to have successfully authenticated the UE. Otherwise, the authentication is considered to have failed and an authentication message is returned to the AUSF.
[0092] S15.AMF sends a message to AUSF, carrying RES*.
[0093] S16.AUSF confirms whether the 5G AV corresponding to the received RES* is expired.
[0094] S17.AUSF compares RES* with the locally stored XRES* to see if they are consistent. If they are consistent, it is determined that the home network has successfully authenticated the UE. Otherwise, it is considered that the authentication has failed and an authentication failure is returned to the UDM.
[0095] S18.AUSF sends a message to UDM, carrying SUPI, authentication timestamp, authentication type (such as EAP or 5G-AKA), and serving network name.
[0096] S19. UDM saves the authentication result, specifically storing the message content and authentication result received above.
[0097] It should be noted that some variables in the above steps represent intermediate parameters.
[0098] In the aforementioned terminal device authentication method, the related art does not include the transmission of group services, and therefore lacks a security protection scheme for group services. The encryption and decryption of UE identification uses an asymmetric key scheme, which is computationally complex and has high overhead, typically between 400 and 500 bits. Existing terminal identification protection mechanisms employ asymmetric key encryption and decryption, which is computationally complex and has high overhead, and does not meet the low power requirements of terminals.
[0099] In order to solve the above problems, an embodiment of the present application provides a paging access method, in which a first terminal device receives a paging message from a core network device, and the paging message carries group key indication information. Then, the first terminal device sends a first authentication request message to the core network device. The first authentication request message includes a terminal identifier of the first terminal device, and the terminal identifier is encrypted according to the first information. The first information includes a group key indicated by the group key indication information. Based on the first authentication message, the core network authenticates the first terminal device. In this way, during the process of paging access by the terminal device, the terminal identifier of the terminal device can be encrypted using the group key, thereby ensuring the security of the terminal identifier during transmission, and reducing the computational complexity and processing overhead during the encryption process of the terminal identifier, thereby reducing the overall power consumption of the paging access process.
[0100] The following will describe in detail the paging access method provided in the embodiments of the present application with reference to the accompanying drawings.
[0101] In the embodiment of the present application, the terminal device may include but is not limited to an electronic tag, a smart phone (including a folding screen phone and a non-folding screen phone), a netbook, a tablet computer, a smart watch, a smart bracelet, a phone watch, a smart camera, a PDA, a personal computer (PC), a robot, a personal digital assistant (PDA), a portable multimedia player (PMP), an augmented reality (AR) / virtual reality (VR) device, a smart home device, a television, a projection device, or a somatosensory game console in a human-computer interaction scenario. The embedded device described in the embodiment of the present application may include but is not limited to a printer, a copier, a fax machine, a biochemical analyzer, a blood analyzer, a switch, a router, an industrial computer, a drone, an automated teller machine (ATM), etc. The embodiment of the present application does not specifically limit the specific function and type of the device including the controller.
[0102] Exemplarily, the embodiments of the present application can be used for air interface transmission between an electronic tag and a reader / writer. The form of the reader / writer is not limited and can be a base station, a terminal, or a relay node accessing an integrated access and backhaul (IAB) node. The UE can also be located within the coverage provided by the reader / writer. When the reader / writer is a terminal, the communication between the reader / writer and the UE can be regarded as transmission between terminals. When the reader / writer is a base station, the communication between the reader / writer and the UE is a uu interface, that is, air interface communication. The following figures respectively illustrate that the base station and the UE (tag) are connected via uu; the UE is connected to the IAB node via uu, and the IAB node is connected to the base station via uu; and the access point and the tag are connected via sidelink.
[0103] Specifically, referring to FIG2 , it shows a schematic diagram a of an application scenario of a paging access method provided by an embodiment of the present application. As shown in FIG2 , the application scenario of the embodiment of the present application may be between a base station and an electronic tag.
[0104] Refer to Figure 3, which shows a schematic diagram b of an application scenario of a paging access method provided by an embodiment of the present application. As shown in Figure 3, the application scenario of the embodiment of the present application may be between a terminal device and an electronic tag.
[0105] Refer to Figure 4, which shows a schematic diagram c of an application scenario of a paging access method provided in an embodiment of the present application. As shown in Figure 4, the application scenario of the embodiment of the present application can be between a base station and an electronic tag, specifically, the base station is connected to an IAB node, and the IAB node is connected to the electronic tag.
[0106] Optionally, a separate architecture can also be supported. Referring to Figure 5, a schematic diagram d of an application scenario of a paging access method provided in an embodiment of the present application is shown. As shown in Figure 5: The application scenario of the embodiment of the present application can be that the tag (i.e., the above-mentioned electronic tag) has only an uplink connection with the reader (such as a base station), and the tag has only a downlink connection with the UE or the excitation source (helper). The dotted line indicates the provision of carrier or energy, and the solid line indicates the data transmission connection.
[0107] Referring to Figure 6, a schematic diagram e of an application scenario of a paging access method provided by an embodiment of the present application is shown. As shown in Figure 6, the application scenario of the embodiment of the present application can be that the tag (i.e., the electronic tag described above) has only a downlink connection with a reader (e.g., a base station), and the tag has only an uplink connection with a UE or an excitation source (helper). The dotted line indicates the provision of carrier or energy, and the solid line indicates the data transmission connection.
[0108] The present invention is primarily applicable to 5G New Radio (NR) or 6G systems. It can also be applied to other communication systems, such as Long Term Evolution (LTE), Code Division Multiple Access (CDMA), and Wi-Fi, as long as the communication system includes an access network unit (e.g., a gNB) and multiple terminals. A terminal is within the coverage area of a gNB, sending uplink signals to the gNB and / or receiving downlink signals from the gNB. Other terminals may or may not be within the coverage area of the gNB.
[0109] In some embodiments, referring to FIG7 , which shows a flow chart a of a paging access method provided in an embodiment of the present application, as shown in FIG7 , the method may include:
[0110] S701: The access and mobility management AMF receives a first service request message (inventory) from the AF, where the service request message may indicate the service type, information of the UE terminal device (or terminal) or device or ATIO device or a group of UEs, and the area in which the service is performed, etc.
[0111] In some examples, the tag management function (TMF) receives a second service request message (inventory) from the AF. The service request message may indicate the service type, information about the UE terminal device (or terminal) or device or ATIO device or a group of UEs, and the area where the service is performed. It should be noted that the AMF involved in the embodiments of the present application is only an example and can be replaced by the TMF or other network elements, and no limitation is made here.
[0112] In some examples, the first service request may indicate one or more service types, and the terminal devices are grouped according to different service types. That is, one service request may correspond to one or more terminal devices, and a connection may be established with one or more terminal devices in response to the first service request.
[0113] In some scenarios, the message sent by the base station can also be replaced by the message sent by the terminal. In other words, the method involved in the embodiment of the present application can also be applied between the terminal and the electronic tag (terminal).
[0114] S702: The AMF sends a first paging message (paging) to the interrogator or reader or base station (BS) or gNB, carrying a mask, inventory ID, group identifier, group index, etc.
[0115] In some examples, the first paging message includes at least one information such as group identification information, mask information, inventory or event identification, and group key identification index.
[0116] In some examples, the first paging message may also include a second random number. The second random number is sent to the base station or gNB via the first paging message and is used to encrypt the terminal identifier together with the group key.
[0117] Specifically, in some embodiments, group identification information is used to determine the UE that is paged by a group, the UE identification is used to determine the UE, and the mask information can also be used to indicate a group of UEs. The specific indication method is that when part or all of the information carried in the mask is consistent with the information stored in the terminal, the terminal is considered to be paged, that is, in this way, at least one terminal can be paged. The inventory or event identifier is used to identify an inventory event or identify a session or represent a service. The group key identifier index is used to indicate the key required by the terminal to encrypt or securely operate the terminal identifier. Specifically, it can be a group key identifier for each (per) public land mobile network (PLMN) PLMN, or a group key identifier for each service type, such as an inventory service group identifier or a read service group identifier. That is, in addition to the group key identifier, the PLMN identifier or service type identifier may not be carried.
[0118] S703: The base station sends a second paging message paging to the terminal, carrying a mask, inventory ID, group identifier, group index, etc.
[0119] In some examples, the second paging message includes at least one information such as group identification information, mask information, group key identification index, etc. The meaning of the information is the same as above and is not repeated here. The second paging message is used to page at least one terminal device to access the network.
[0120] In some examples, the second paging message may further include a second random number, wherein the second random number is sent to the terminal device through the first paging message, and the second random number is used to encrypt the terminal identifier together with the group key.
[0121] In some examples, the first paging message and / or the second paging message may be in the form of a multicast or groupcast message. When the first paging message and / or the second paging message is in the form of a multicast or groupcast message, it may include paging identification information or may not include paging identification information.
[0122] S704: The paged terminal initiates random access. The random access process may use 4-step random access or 2-step random access.
[0123] Specifically, in some examples, if it is a 4-step random access, the terminal first sends a preamble code, and after receiving the random access response sent by the base station, the terminal sends a message and waits to receive the message sent by the base station to the terminal. For details, please refer to 3GPP protocol 38.321 or 36.321 protocol.
[0124] In some examples, if it is a two-step random access, the terminal can send a random access request message and then receive a response message sent by the base station. This completes the random access process. Specifically, the two-step random access can use a slotted Aloha method. Other methods can also be used. Among them, the access opportunity used by random access can be an access opportunity with a fixed time unit in the time domain, or an access opportunity with a variable time unit. In the case of a variable time unit, the access opportunity can be a timing triggered by a special signaling, that is, when the special signaling is received, a time domain resource for terminal access is triggered.
[0125] S705: After completing access, the terminal sends a message authentication request message to the core network.
[0126] The authentication request message herein may also be referred to as other messages, and the specific name remains unchanged, that is, the authentication mentioned in the embodiment may be optional. Only the tag identifier may be encrypted, without the core network needing to authenticate the tag.
[0127] The terminal sends an authentication request message to the core network through the network device. In some examples, the authentication request message includes a terminal identifier, and optionally a random number and a group key identifier, and the UE ID is encrypted or protected using the group key indicated in the paging message.
[0128] In some examples, if a random number is included, it can also be used as one of the parameters when encrypting the terminal identifier. The authentication request message is sent to the core network AMF via the base station. The random number can be a first random number generated by the terminal device itself or a second random number indicated by the paging message. Both the first random number and the second random number are used to encrypt the terminal identifier in conjunction with the group key.
[0129] S706: The authentication request message includes an encrypted ID and / or a group identifier, a random number (a first and / or a second random number). Specifically, the authentication request message includes a terminal identifier, and optionally includes a random number and a group key identifier. The terminal identifier is encrypted or protected using the group key indicated in the paging message. If a random number is included, the random number can also be used as one of the parameters when encrypting the ID. If a group key identifier is carried, the identifier is used to indicate to the core network which group key is used to protect this ID. The message is sent to the core network AMF via the base station.
[0130] If the authentication request message does not carry a group key identifier, the base station may also carry a group key identifier and / or inventory identifier when sending the authentication request or ID transmission, indicating to the core network which key to use for security protection of the user ID. Optionally, when the base station sends multiple terminal identification information to the core network, it may also indicate key information to the core network using a group key identifier and / or inventory identifier. This indicates the key used to encrypt multiple terminal identifications.
[0131] Regardless of whether the terminal sends an authentication request carrying a key identifier, the base station may also carry a group key identifier and / or an inventory identifier when sending the authentication request or ID transmission, to indicate to the core network which key to use for security protection of the user ID.
[0132] In some examples, the authentication request information may also include a random number, where the random number may be a first random number generated by the terminal device itself, or a second random number indicated by a paging message, and both the first random number and the second random number are used to encrypt the terminal identifier in conjunction with the group key.
[0133] The optional encrypted UE ID may not need to use a random number, so the first or second random number may not be transmitted.
[0134] S707: The core network receives the ID information from the terminal and can determine which key is used to protect the received terminal ID through the group key identifier sent by the UE, or the group key identifier and / or inventory identifier sent by the base station, and then decrypt the ID information.
[0135] In some examples, the AMF may also send the encrypted UE ID and key information to the core network data management unit UDM for decryption.
[0136] S708: After the core network obtains the correct UE ID, if the authentication is successful, data transmission can be carried out.
[0137] S709: When transmitting data to each UE, a UE-specific root key may be used to encrypt the transmitted data and possibly perform integrity protection. The root key here refers to a key unique to each terminal. When data is encrypted using the root key, a key derived from the root key may also be used for encryption.
[0138] Based on this, in group services, the paged terminal identity is protected based on the group key, rather than the traditional terminal-specific key protection. This can achieve group terminal access while avoiding increasing computational complexity. The key used for the terminal identity is determined based on alignment of the group identity with the network side, which can achieve encryption of the user identity with low complexity and low signaling overhead, ensuring the privacy and security of the user identity.
[0139] In some embodiments, referring to FIG8 , which shows a flow chart b of another paging access method provided in an embodiment of the present application, as shown in FIG8 , the method may include:
[0140] S801: The access and mobility management AMF receives a first service request (inventory) from an application (AF). The message may indicate the service type, information of the UE terminal device (or terminal) or device or ATIO device or a group of UEs, and the area where the service is performed, etc.
[0141] In some examples, the tag management function (TMF) receives a second service request message (inventory) from the AF. The service request message may indicate a service type, information about a UE terminal device (or terminal) or device or ATIO device or a group of UEs, and an area where the service is to be performed.
[0142] S802: AMF sends a first paging message Paging to the base station (Interrogator or Reader or base station). The first paging message includes a mask, an inventory ID, a group read / group write & key ID, a group identification information, a mask information, an inventory or event identification, at least one UE identification information, a group key identification index, and at least one information such as NAS data or a NAS container or other data carrying form. The group key identification index or key ID here is the key used to encrypt the network storage NAS data contained in the paging message. Optionally, the key can be the same as the group key of the first embodiment or different. The NAS data is NAS data sent to at least one terminal being paged. NAS data can be understood as data carried by a NAS message or a NAS layer. When the key can be different from the group key of the first embodiment, the paging message can include two group key identifications, one for decrypting data and one for encrypting the UE identification.
[0143] In some examples, the NAS data may not be carried in the first paging message, but may be a separate signaling bearer, but may be sent to the terminal together with the paging message.
[0144] S803: The base station sends a second paging message (Paging) to the terminal. The second paging message includes at least one of the following information: mask, inventory ID, group read / group write & key ID, group identification information, mask information, at least one UE identification information, group key identification index, and NAS data or NAS container or other data carrying format. The NAS data is NAS data sent to the at least one terminal being paged. NAS data can be understood as data carried via NAS messages or the NAS layer.
[0145] In some examples, the NAS data may not be carried in the second paging message, but may be a separate signaling bearer, but may be sent to the terminal together with the second paging message.
[0146] In some examples, the data may not be carried by NAS or RRC messages, but may be carried by the PDCP / RLC / MAC layer, but the data packet may be sent to the terminal together with the second paging message. Therefore, the data packet may also be encrypted or securely protected by the key indexed by the group key identifier.
[0147] The optional second page may also include a third random number for encrypting the data portion. The third random number may be the same as or different from the first or second random number.
[0148] S804: After receiving the second paging message, the terminal determines whether it is the paged terminal. If so, it decrypts the encrypted data using the indicated group key and initiates a random access process. The random access process can refer to the first embodiment.
[0149] S805: After completing random access, the terminal sends data to the base station, such as UL NAS (ID + data). This data may be a response to the paging data received. The sent data may be encrypted or integrity protected based on the terminal's unique root key or a derived key from the root key, or continue to use the group key to encrypt the sent data. The data may also be encrypted based on the instructions of the base station or core network in the paging message using one of the above keys.
[0150] S806: After completing random access, the terminal sends data to the core network element via the base station. For example, UL NAS (ID + data) can be a response to paging data. The sent data can be encrypted or integrity protected based on the terminal's unique root key or a derived key from the root key, or continue to use the group key to encrypt the sent data. The sent data can also continue to be encrypted using the group key based on the instructions of the base station or core network in the paging message.
[0151] S807: After completing random access, the terminal sends data to the application via the base station and core network element. For example, UL NAS (ID + data) can be a response to paging data. The sent data can be encrypted or integrity protected based on the terminal's unique root key or a key derived from the root key. It can also be encrypted using a group key based on the base station or core network's instructions in the paging message.
[0152] Based on this, existing service data can only be encrypted after the terminal is connected and security is activated. During the paging process, the data sent to a group of terminals can be encrypted and protected using the group key, without having to wait for the terminal to be connected and encrypted and sent separately according to the terminal-specific key. This avoids the situation where a single UE-specific key is used for encryption and sent separately, which greatly increases the signaling overhead. The data sent to a group of terminal devices can be encrypted and protected using the same group key to reduce signaling overhead and improve transmission efficiency. When performing group service transmission, the security protection of service data based on the group key ensures the security of the service data and avoids the problem that the group data on the network side cannot be encrypted and decrypted using the UE-specific key.
[0153] As an example, referring to FIG. 9 , which shows a flowchart c of another paging access method provided in an embodiment of the present application, as shown in FIG. 9 , the paging access method provided in an embodiment of the present application may include:
[0154] S901: A first terminal device receives a paging message from a core network device, wherein the paging message carries group key indication information, and the group key indication information is for at least one terminal device, and the at least one terminal device includes the first terminal device.
[0155] It should be noted that the first terminal device receives a paging message sent by the core network device and obtains the group key indication information in the paging message; wherein the group key indication information may indicate a corresponding group key, and the same group key may be sent to one or more terminal devices. The same group key may be used for a group of terminal devices executing the same service type, and there may be one or more terminal devices executing the same service type.
[0156] Exemplarily, the above-mentioned first terminal device may include a terminal and a tag, specifically, including a device without energy storage and independent signal generation, such as a backscatter transmission device with this characteristic; including a device with energy storage but without independent signal generation, such as a backscatter transmission device with this characteristic, wherein the use of stored energy may include amplification of the reflected signal; and also including a device with energy storage and independent signal generation, such as an active wireless radio frequency (RF) component for transmission.
[0157] As an example, the above-mentioned group key indication information may include one or more of the following: group identification information, mask information, inventory identification, event identification, and group key identification index.
[0158] It should be noted that, during the paging process of the terminal device, the core network device sends a paging message to one or more terminal devices. The group key indication information carried in the paging message may include one or more of the group identification information, mask information, inventory identification, event identification, and group key identification index. Among them, the group identification information, mask information, inventory identification, event identification, and group key identification index can directly or indirectly indicate the corresponding group key to the terminal device, so that the terminal device uses the group key to encrypt the terminal identification during the authentication request and data transmission process.
[0159] Specifically, the group identifier is used to identify a group of UEs to be paged, the UE identifier is used to identify the UE, and the mask information can also be used to indicate a group of UEs. Specifically, when some or all of the information carried in the mask matches the information stored by the terminal, the terminal is considered to be paged. In this way, at least one terminal can be paged. The inventory identifier or event identifier is used to identify an inventory event, a session, or a service.
[0160] As an example, before sending the first authentication request message to the core network device, the method may further include:
[0161] Access the core network device based on the paging message.
[0162] It should be noted that after receiving the paging message, the first terminal device determines the key indication information in the paging message, encrypts the terminal identifier of the first terminal device according to the key indication information, and then sends an authentication request message to the core network device, and can access the core network device through 2-step random access or 4-step random access.
[0163] As an example, the core network device may also instruct the terminal device whether to encrypt the terminal identifier. In the case where the core network device instructs the terminal device that the terminal identifier does not need to be encrypted, the terminal identifier may be sent directly.
[0164] S902: The first terminal device sends a first authentication request message to the core network device. The first authentication request message includes the terminal identifier of the first terminal device. The terminal identifier is encrypted based on the first information. The first information includes the identifier of the group key indicated by the group key indication information.
[0165] It should be noted that when the first terminal device randomly accesses the core network, the first terminal device sends an authentication request message to the core network device. The terminal identifier in the authentication request message needs to be encrypted, and the terminal identifier is encrypted using the group key indicated by the group key indication information. Among them, the group key indication information is used to indicate the group key in the process of the core network device sending a paging message. Since the group key indication information indicates the group key through different dimensions such as group identification information, mask information, inventory identification, event identification, group key identification index, etc., the same group key can correspond to one or more group key indication information. The first information is used when the first terminal device sends the first authentication request message, and the first information may include the group key.
[0166] As an example, the first authentication request message includes a first identifier, which includes one or more of the following: a group key identifier, an inventory identifier corresponding to the group key, group identifier information, mask information, inventory identifier, event identifier, and group key identifier index.
[0167] It should be noted that, during the authentication process of the terminal device, in the first authentication request information sent by the terminal device to the core network device, the first identifier may be a group key identifier or an inventory identifier corresponding to the group key identifier, wherein the group key identifier may directly indicate the corresponding group key for the core network device to decrypt the first authentication request information, and the inventory identifier may indicate the storage location of the group key so that the core network device can obtain the group key to decrypt the first authentication request information.
[0168] As an example, the first information may also include a random number. The random number can be used as a parameter in the encryption process of the terminal identifier using the group key to improve the security of the terminal identifier during transmission. Accordingly, the first authentication request message includes the random number. The random number is used as a parameter when encrypting the terminal identifier using the group key when sending the first authentication request message.
[0169] As an example, the random number can be a first random number generated by the terminal device itself, or a second random number indicated by a paging message, and both the first random number and the second random number are used to encrypt the terminal identifier in conjunction with the group key. As an example, sending a first authentication request message to the core network device may include:
[0170] A first authentication request message is sent to the core network device through the first network device.
[0171] It should be noted that the first terminal device can directly send the first authentication request information to the core network device so that the core network device authenticates the first terminal device. At the same time, the first terminal device can also send the first authentication request message to the core network device through the first network device so that the core network device authenticates the first terminal device.
[0172] As an example, the sending of the first authentication request message to the core network device through the first network device may include:
[0173] A first authentication request message and a second authentication request message are sent to a first network device, and a third message is sent to a core network device through the first network device. The third message includes one or more authentication request information, and the multiple authentication request information include the first authentication request message and the second authentication request message.
[0174] It should be noted that the terminal device sends an authentication request message to the core network device through the first network device. One or more terminal devices may send one or more authentication request messages to the first network device. The first network device may send one or more authentication request messages to the core network device separately. Multiple authentication request messages may come from one or more terminal devices, or one or more authentication request messages may be sent to the core network device together as a third message. The third message may be one or more, so that the core network device can authenticate one or more terminal devices.
[0175] As an example, the first authentication request message and the second authentication request message do not include the first identifier, and the third message includes the first identifier.
[0176] As an example, the first authentication request message, the second authentication request message, and the third message all include a first identifier, and the specific identifier values in the first identifier may be different.
[0177] It should be noted that, when the first authentication request message and the second authentication request message sent by the first terminal device to the first network device do not include the first identifier, the first network device can add the corresponding first identifier in the authentication request message to indicate the group key used for encrypting the terminal identifier in the authentication request message sent by the first network device, and send the first authentication request message, the second authentication request message and the first identifier as a third message to the core network device.
[0178] As an example, the above method may further include:
[0179] The target data is encrypted using the group key indicated by the core network device or the first network device or the root key corresponding to the first terminal device, and the encrypted target data is sent to the core network device.
[0180] It should be noted that data transmission can be carried out between the core network device, the first network device and the terminal device, the terminal device can transmit data with the first network device, and can also transmit data with the core network device through the first network device. During the data transmission process, the target data can be encrypted by the group key indicated by the core network device or the first network device or the root key corresponding to the first terminal device or the derived key of the root key to ensure the security of the data during the transmission process.
[0181] As an example, referring to FIG. 10 , which shows a flowchart d of another paging access method provided in an embodiment of the present application, as shown in FIG. 10 , the paging access method provided in an embodiment of the present application may include:
[0182] S1001: In response to a first service request, a core network device sends a paging message to a first terminal device. The paging message carries group key indication information. The group key indication information is for at least one terminal device, and the at least one terminal device includes the first terminal device.
[0183] It should be noted that when the core network device receives the first service request, the core network device can send a paging message to one or more terminal devices, and the paging message includes group key indication information, wherein the group key indication information can indicate the corresponding group key, and the same group key can be sent to one or more terminal devices.
[0184] As an example, the above-mentioned group key indication information includes one or more of the following: group identification information, mask information, inventory identification, event identification, and group key identification index.
[0185] It should be noted that during the paging process of the terminal device, the core network device sends a paging message to one or more terminal devices. The group key indication information carried in the paging message may include group identification information, mask information, inventory identification, event identification, and group key identification index. Among them, the group identification information, mask information, inventory identification, event identification, and group key identification index can directly or indirectly indicate the corresponding group key to the terminal device, so that the terminal device uses the group key to encrypt the terminal identification and send it to the core network device.
[0186] S1002: Receive a first authentication request message from a first terminal device, where the first authentication request message includes a terminal identifier of the first terminal device, where the terminal identifier is encrypted based on first information, and where the first information includes an identifier of a group key indicated by group key indication information.
[0187] It should be noted that the core network device obtains the first authentication request information sent by the first terminal device, and the first authentication request message includes first information indicating the group key.
[0188] As an example, the receiving of the first authentication request message from the first terminal device may include:
[0189] Receive a first authentication request message forwarded by the first terminal device through the first network device.
[0190] It should be noted that the core network device can directly receive the first authentication request information sent by the terminal device and authenticate the first terminal device. At the same time, the core network device can also receive the first authentication request message sent by the first terminal device through the first network device, decrypt the terminal identification of the first terminal device according to the first information in the first authentication request message, and obtain the decrypted terminal identification.
[0191] As an example, after the terminal identification of the first terminal device is decrypted, the first terminal device is authenticated based on the decrypted terminal identification.
[0192] As an example, the receiving of the first authentication request message forwarded by the first terminal device through the first network device includes:
[0193] A third message is received through the first network device, where the third message includes one or more authentication request messages, where the multiple authentication request messages include a first authentication request message and a second authentication request message.
[0194] As an example, the third message may be an interface message between the base station and the core network, such as an NG-AP interface or other interface, which is not limited herein. It is understandable that the third message may be one or more, and some or all of the one or more third messages may be interface messages between the base station and the core network. The specific interface type is the same as above and is not described in detail here.
[0195] It should be noted that the core network device receives the third message through the first network device. The third message may be one or more messages. The third message may include the first terminal device sending one or more authentication request messages to the first network device. The first terminal device may send one or more authentication request messages sent by the terminal device to the core network device. The multiple authentication request messages may come from multiple terminal devices. Then, the core network device decrypts the terminal identifier in the one or more messages based on the received third message.
[0196] As an example, the core network device may also decrypt the received at least one terminal identifier based on the first information or the first identifier or the inventory identifier or the group key identifier in the third message. The first information may be in the authentication request information sent by the terminal, or may be added by the first network device when sending the authentication request information.
[0197] As an example, after the terminal identification of at least one terminal device is decrypted, the first terminal device is authenticated based on the decrypted terminal identification.
[0198] S1003: Authenticate the first terminal device according to the first authentication request message.
[0199] It should be noted that the core network device obtains the first information in the first authentication request message, and decrypts the terminal identification of the first terminal device according to the first information to obtain the terminal identification of the first terminal device.
[0200] As an example, after obtaining the terminal identification of the first terminal device, the first terminal device may be authenticated based on the terminal identification.
[0201] As an example, authenticating the first terminal device according to the first authentication request message may include:
[0202] Decrypting the first authentication request message to obtain a terminal identifier of the first terminal device;
[0203] Authenticate the terminal identification of the first terminal device.
[0204] It should be noted that the core network device can decrypt the terminal identification of the first terminal device using the group key indicated by the first information in the first authentication request message.
[0205] As an example, after obtaining the terminal identification of the first terminal device, the first terminal device may be authenticated based on the decrypted terminal identification to obtain an authentication result.
[0206] As an example, the first authentication request message includes a first identifier, which includes one or more of the following: a group key identifier, an inventory identifier corresponding to the group key, group identifier information, mask information, inventory identifier, event identifier, and group key identifier index.
[0207] It should be noted that, during the authentication process of the terminal device, in the first authentication request information received by the core network device, the first identifier may be a group key identifier or an inventory identifier corresponding to the group key identifier, wherein the group key identifier may directly indicate the corresponding group key for the core network device to decrypt the first authentication request information, and the inventory identifier may indicate the storage location of the group key so that the core network device can obtain the group key to decrypt the first authentication request information.
[0208] As an example, the above-mentioned first information may also include a random number. The random number may be used as a parameter in the decryption process when decrypting the terminal identifier using the group key to improve the security of the terminal identifier during transmission. Accordingly, the above-mentioned first authentication request message may include a random number. The random number is used as a parameter when decrypting the terminal identifier using the group key when receiving the first authentication request information. The random number may be a first random number generated by the terminal device itself, or a second random number indicated by a paging message. Both the first random number and the second random number are used to encrypt the terminal identifier in conjunction with the group key.
[0209] As an example, after the core network device sends a paging message to the first terminal device, the method may further include:
[0210] Respond to the random access request of the first terminal device and allow the first terminal device to access the core network device.
[0211] It should be noted that after sending the paging message, the core network device can allow the terminal device to access the core network device by responding to 2-step random access or 4-step random access, and then receive the authentication request message sent by the terminal device.
[0212] As an example, after the first terminal device passes authentication, the method may further include:
[0213] receiving target data from a first terminal device;
[0214] Use the group key indicated by the core network device or the first network device or the root key corresponding to the first terminal device to decrypt the target data.
[0215] It should be noted that when the core network device and the terminal device are authenticated and data transmission can be carried out, the target data can be decrypted during the data transmission process by the group key indicated by the core network device or the first network device or the root key corresponding to the first terminal device or the derived key of the root key to obtain the decrypted target data.
[0216] As an example, refer to Figure 11, which shows a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. As shown in Figure 11, the electronic device 110 may include: a transceiver 1101, a memory 1102 and a processor 1103; each component is coupled together through a bus system 1104. It can be understood that the bus system 1104 is used to realize the connection and communication between these components. In addition to including a data bus, the bus system 1104 may also include a power bus, a control bus and a status signal bus. Among them, the transceiver 1101 is used to receive and send signals in the process of sending and receiving information with other external network elements; the memory 1102 is used to store a computer program that can be run on the processor 1103; the processor 1103 is used to execute the paging access method in any of the aforementioned possible implementations when running the computer program.
[0217] An embodiment of the present application provides a computer storage medium storing a vibration prompt program. When executed by at least one processor, the vibration prompt program implements the steps of the paging access method described in any of the aforementioned possible implementations. The storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0218] An embodiment of the present application provides a computer program product comprising instructions. When the computer program product is run on a computer, the computer is enabled to execute the paging access method in any of the possible implementations described above.
[0219] An embodiment of the present application provides a chip system, which includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the paging access method in any of the possible implementations described above is implemented.
[0220] It should be understood that the various schemes of the embodiments of the present application can be reasonably combined and used, and the explanations or descriptions of the various terms appearing in the embodiments can be referenced or explained with each other in the various embodiments, without limitation to this.
[0221] It should also be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0222] It is understandable that, in order to implement the functions of any of the above-mentioned embodiments, the controller or resource allocation simulation device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0223] The embodiments of the present application can divide the functional modules of a controller or resource allocation simulation device with controller resource allocation capabilities. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiments of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.
[0224] It should also be understood that the various modules in the controller or resource allocation simulation device can be implemented in software and / or hardware, without specific limitation. In other words, the electronic device is presented in the form of functional modules. The "module" here can refer to an application-specific integrated circuit (ASIC), a circuit, a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above-mentioned functions.
[0225] In an optional manner, when data transmission is implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is implemented in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disk (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)).
[0226] The steps of the method or algorithm described in conjunction with the embodiments of the present application can be implemented in hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, mobile hard disk, CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a controller or a resource allocation simulation device. Of course, the processor and storage medium can also exist as discrete components.
[0227] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
Claims
1. A paging access method, characterized in that: Applied to a first terminal device, the method includes: receiving a paging message from a core network device, where the paging message carries group key indication information, where the group key indication information is for at least one terminal device, where the at least one terminal device includes the first terminal device; The first terminal device sends a first authentication request message to the core network device, where the first authentication request message includes a terminal identifier of the first terminal device, where the terminal identifier is encrypted based on first information, and the first information includes an identifier of a group key indicated by the group key indication information.
2. The method according to claim 1, characterized in that The first authentication request message includes a first identifier, which includes one or more of the following: the group key identifier, an inventory identifier corresponding to the group key, group identifier information, mask information, an inventory identifier, an event identifier, and a group key identifier index.
3. The method according to claim 1 or 2, characterized in that: The group key indication information includes one or more of the following: group identification information, mask information, inventory identification, event identification, and group key identification index.
4. The method according to any one of claims 1 to 3, characterized in that The first information also includes a random number.
5. The method according to any one of claims 1 to 4, characterized in that The first authentication request message includes the random number.
6. The method according to any one of claims 1 to 5, characterized in that The sending a first authentication request message to the core network device includes: The first authentication request message is sent to the core network device through the first network device.
7. The method according to claim 6, characterized in that The sending the first authentication request message to the core network device through the first network device includes: The first authentication request message and the second authentication request message are sent to the first network device, and a third message is sent to the core network device through the first network device, wherein the third message includes the one or more authentication request information, and the multiple authentication request information include the first authentication request message and the second authentication request message.
8. The method according to claim 7, characterized in that The first authentication request message and the second authentication request message do not include the first identifier, and the third message includes the first identifier.
9. The method according to any one of claims 1 to 8, characterized in that Before sending the first authentication request message to the core network device, the method further includes: Access the core network device according to the paging message.
10. The method according to any one of claims 1 to 9, characterized in that The method further comprises: The target data is encrypted using the group key indicated by the core network device or the first network device or the root key corresponding to the first terminal device, and the encrypted target data is sent to the core network device.
11. A paging access method, characterized in that: Applied to a core network device, the method comprises: In response to the first service request, the core network device sends a paging message to the first terminal device, where the paging message carries group key indication information, where the group key indication information is for at least one terminal device, and the at least one terminal device includes the first terminal device; receiving a first authentication request message from the first terminal device, the first authentication request message including a terminal identifier of the first terminal device, the terminal identifier being encrypted according to first information, the first information including an identifier of the group key indicated by the group key indication information; Authenticate the first terminal device according to the first authentication request message.
12. The method according to claim 11, characterized in that The authenticating the first terminal device according to the first authentication request message includes: Decrypting the first authentication request message to obtain a terminal identifier of the first terminal device; Authenticate the terminal identification of the first terminal device.
13. The method according to claim 11 or 12, characterized in that: The first authentication request message includes a first identifier, which includes one or more of the following: the group key identifier, an inventory identifier corresponding to the group key, group identifier information, mask information, an inventory identifier, an event identifier, and a group key identifier index.
14. The method according to any one of claims 11 to 13, characterized in that The group key indication information includes one or more of the following: group identification information, mask information, inventory identification, event identification, and group key identification index.
15. The method according to any one of claims 11 to 14, characterized in that The first information also includes a random number.
16. The method according to any one of claims 11 to 15, characterized in that The first authentication request message includes the random number.
17. The method according to any one of claims 11 to 16, characterized in that: The receiving a first authentication request message from the first terminal device includes: Receive the first authentication request message forwarded by the first terminal device through the first network device.
18. The method according to any one of claims 11 to 17, characterized in that The receiving the first authentication request message forwarded by the first terminal device through the first network device includes: A third message is received through the first network device, where the third message includes one or more authentication request messages, where the multiple authentication request messages include the first authentication request message and the second authentication request message.
19. The method according to claims 11-18, characterized in that After the core network device sends a paging message to the first terminal device, the method further includes: In response to the random access request of the first terminal device, the first terminal device is allowed to access the core network device.
20. The method according to claims 11-19, characterized in that After the first terminal device passes authentication, the method further includes: receiving target data from the first terminal device; The target data is decrypted using the group key indicated by the core network device or the first network device or the root key corresponding to the first terminal device.
21. An electronic device, characterized in that: The electronic device comprises: A transceiver, used for sending and receiving signals; a memory for storing computer program instructions; A processor, configured to execute the computer program instructions to support the electronic device to implement the method as described in any one of claims 1-10 or 11-20.
22. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by the processing circuit, the method according to any one of claims 1-10 or 11-20 is implemented.
23. A computer program product comprising instructions, characterized in that When the computer program product is run on a computer, the computer is caused to execute the method according to any one of claims 1 to 10 or 11 to 20.
24. A chip system, characterized in that: The chip system includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method as described in any one of claims 1-10 or 11-20 is implemented.
Citation Information
Patent Citations
Group key hierarchical management method and system for broadband cluster system, and terminal
CN104010276A
Shared channel management method and system of broadband cluster system, terminals and base station
CN106358159A
User terminal network authentication method and device
CN108112012A
Broadcast Replenishment of Account Parameters for Groups of Wireless Devices
US20120314864A1