Data transmission method and apparatus
By carrying the third information for authentication in the terminal device, the security of data transmission between the Internet of Things tag and the base station is solved, and the security and effectiveness of data transmission are achieved.
Patent Information
- Application Number
- PCT/CN2024/128435
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-30
- Publication Date
- 2025-05-08
AI Technical Summary
In wireless communication systems, there are security issues in data transmission between IoT tags and base stations, and illegal attackers may intercept and tamper with data, resulting in data collisions or incorrect inventory.
By carrying the third information for authentication in the terminal device, it is ensured that the uplink data can be authenticated by the network side during transmission, thereby improving the security of data transmission. The method involves receiving the first information and the second information, determining the third information based on these information, and carrying the third information when sending the uplink data.
Effectively prevent illegal devices from repeatedly sending or tampering with data, ensuring the security and effectiveness of data transmission, and avoiding data collisions and incorrect inventory.
Smart Images

Figure CN2024128435_08052025_PF_FP_ABST
Abstract
Description
Data transmission method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on October 31, 2023, with application number 202311443996.9 and invention name "A Data Transmission Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a data transmission method and device. Background Art
[0004] Wireless communication systems have incorporated the Internet of Things (IoT) technology. Tags in the IoT can function as end devices, and base stations can function as readers. Tags can communicate with base stations. In scenarios such as tag inventory, the reader can page the tag using paging signaling. After receiving the paging signaling, the reader uses query signaling to indicate an inventory cycle. During this cycle, the tag initiates random access. After successful random access, the tag can send data to the reader.
[0005] If an illegal attacker obtains the data sent by the tag and sends it to the base station, it may cause a collision with the data sent by other tags, causing the data transmission of other tags to fail; or, if the attacker sends the data to other base stations, it will cause the tag to be incorrectly inventoried in the area where the other base stations are located. Therefore, how to improve the security of data transmission between tags and readers is an urgent problem to be solved.
[0006] Summary of the Invention
[0007] The present application provides a data transmission method and apparatus to improve the security of data transmission.
[0008] In a first aspect, the present application provides a data transmission method applicable to scenarios such as the environmental Internet of Things. The method is performed by a terminal device or a module or chip within the terminal device, and is described herein using the terminal device as the example. In the method, at least one of first and second information is received; the second information is included in selection signaling or paging signaling; third information is determined based on at least one of the first and second information; the third information is transmitted along with uplink data; and the third information is used to authenticate the uplink data.
[0009] Through the above process, when the terminal device sends uplink data, it carries the third information for authenticating the uplink data, so that the network side can authenticate the uplink data based on the third information. Therefore, through this method, the security of data transmission can be improved.
[0010] In a possible implementation, the first information is a first random number, or the first information is an identifier of a cell of the access network device, or the first information is determined based on the identifier of the cell.
[0011] In the above method, since the first information is a random number or is determined according to the cell identifier, the third information determined by the terminal devices in different cells based on the first information is different. In this way, even if an illegal device obtains uplink data, the illegal device will be considered as invalid data when reporting the uplink data in other cells or to other access network devices, thereby improving the security of data transmission.
[0012] In a possible implementation, the first information is configured according to the granularity of a cell, and different cells correspond to different first information.
[0013] In the above method, if the first information corresponding to the same cell is different, then the third information determined by the terminal devices in different cells of the access network device based on the first information is different. In this way, even if the illegal device is in other cells or reports the uplink data of the terminal device to other access network devices again, it will be regarded as invalid data, thereby improving the security of data transmission.
[0014] In a possible implementation, the second information is a second random number.
[0015] In the above method, the second information is a second random number, so the second information obtained by different access network devices is different, and the third information determined by the terminal devices under different access network devices based on the second information is different. In this way, even if the illegal device reports the uplink data of the terminal device to other access network devices again, it will be regarded as invalid data, thereby improving the security of data transmission.
[0016] In a possible implementation, the second information is valid within an inventory service process corresponding to the uplink data.
[0017] In the above method, the second information in different inventory business processes is different, which can further improve the security of data transmission.
[0018] In a possible implementation, the second information is configured according to the granularity of the access network device, and different access network devices correspond to different second information.
[0019] In the above method, the core network device configures different second information for different access network devices, so the terminal devices under different access network devices determine different third information based on the second information. In this way, even if an illegal device reports the uplink data of the terminal device to other access network devices again, it will be considered as invalid data, thereby improving the security of data transmission.
[0020] In a possible implementation manner, the first information is included in selection signaling, query signaling, or query repetition signaling.
[0021] In one possible implementation, the terminal device is an environmental Internet of Things terminal.
[0022] In the second aspect, the present application provides a data transmission method, which is applicable to scenarios such as the environmental Internet of Things. The execution subject of the method is a core network device or a module or chip in the core network device. Here, the core network device is used as the execution subject for description. In this method, third information and uplink data are received from a terminal device; at least one of first information and second information is received from the terminal device or access network device; the first information is configured for the access network device; the second information is configured for the core network device; the fourth information is determined based on at least one of the first information and the second information, and if the fourth information matches the third information, the uplink data is saved.
[0023] In one possible implementation, the method further includes: if the fourth information does not match the third information, discarding the uplink data, and / or sending fifth information to the terminal device, wherein the fifth information indicates that the uplink data is invalid.
[0024] In a possible implementation, before saving the uplink data, the method further includes: determining the first time the third information and the uplink data are received; or determining the first time the third information and the uplink data are received within a preset time period.
[0025] In a possible implementation manner, the first information is a first random number, or the first information is an identifier of a cell of the access network device, or the first information is determined according to the identifier of the cell.
[0026] In a possible implementation, the first information is valid in the cell where the terminal device is located.
[0027] In a possible implementation, the second information is a second random number.
[0028] In a possible implementation, the second information is valid within an inventory service process corresponding to the uplink data.
[0029] In a possible implementation, the second information is configured according to the granularity of the access network device, and different access network devices correspond to different second information.
[0030] In a possible implementation, the terminal device is an environmental Internet of Things terminal.
[0031] On the third aspect, the present application provides a data transmission method, which is applicable to scenarios such as the environmental Internet of Things. The execution subject of the method is an access network device or a module or chip in the access network device. Here, the access network device is used as the execution subject for description. In this method, the terminal device sends at least one of the first information and the second information; the first information is configured by the access network device; the second information is configured by the core network device; the third information and uplink data from the terminal device are received, and the third information and the uplink data are sent to the core network device; the third information is determined based on at least one of the first information and the second information, and the third information is used to authenticate the uplink data.
[0032] In a possible implementation, before sending the first signaling to the terminal device, the method further includes: receiving the second information from the core network device.
[0033] In a possible implementation manner, the method further includes: sending at least one of the first information and the second information to the core network device.
[0034] In a fourth aspect, the present application provides a data transmission method applicable to scenarios such as the environmental Internet of Things. The method is performed by a terminal device or a module or chip in the terminal device, and is described herein using the terminal device as the example. In this method, first signaling is received from the access network device; the first signaling is a query duplication signaling or a contention resolution message; third information and uplink data are sent to the access network device; the third information is used to authenticate the uplink data, the third information is determined based on the first information, and the first information is determined based on the first signaling.
[0035] Through the above process, when the terminal device sends uplink data, it carries the third information for authenticating the uplink data, so that the network side can authenticate the uplink data based on the third information. Therefore, through this method, the security of data transmission can be improved.
[0036] In one possible implementation, the first information is determined based on the first signaling, including: the first information is the number of transmissions of the first signaling; or, the first information is the time unit index included in the first signaling; or, the first information is a random number included in the first signaling.
[0037] In the above method, the first information is determined according to the first signaling, so the first information determined according to different first signaling is different. If the illegal device obtains the uplink data, the time of sending the uplink data and the time of sending the uplink data by the terminal device correspond to different first signalings, then the network side can determine whether the obtained uplink data is valid based on the third information, thereby improving the security of data transmission.
[0038] In a fifth aspect, the present application provides a data transmission method, which is applicable to scenarios such as the environmental Internet of Things. The execution subject of the method is an access network device or a module or chip in the access network device. Here, the access network device is used as the execution subject for description. In this method, a first signaling is sent; the first signaling is a query duplicate signaling or a contention resolution message; a third information and uplink data are received from a terminal device; the third information is used to authenticate the uplink data, the third information is determined based on the first information, and the first information is determined based on the first signaling; the third information and the uplink data are sent to the core network device.
[0039] In a possible implementation, the method further includes: sending the first information to the core network device.
[0040] In one possible implementation, the first information is determined based on the first signaling, including: the first information is the number of transmissions of the first signaling; or, the first information is the time unit index included in the first signaling; or, the first information is a random number included in the first signaling.
[0041] In a possible implementation, the terminal device is an environmental Internet of Things terminal.
[0042] In a sixth aspect, the present application provides a data transmission method applicable to scenarios such as the environmental Internet of Things. The method is performed by a core network device or a module or chip within the core network device. The method is described herein using the core network device as an example. In this method, third information and uplink data are received; the third information is used to authenticate the uplink data; first information is received from an access network device, and fourth information is determined based on the first information; and if the fourth information matches the third information, the uplink data is saved.
[0043] In one possible implementation, the method further includes: if the fourth information does not match the third information, discarding the uplink data, and / or sending fifth information to the terminal device, wherein the fifth information indicates that the uplink data is invalid.
[0044] In a possible implementation, before saving the uplink data, the method further includes: determining the first time the third information and the uplink data are received; or determining the first time the third information and the uplink data are received within a preset time period.
[0045] In a possible implementation, the terminal device is an environmental Internet of Things terminal.
[0046] In a seventh aspect, the present application further provides a communication device capable of implementing any of the methods provided in any of the first to sixth aspects. The communication device can be implemented via hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units or modules corresponding to the aforementioned functions.
[0047] In one possible implementation, the communication device includes a processor configured to support the communication device in executing the corresponding functions of the terminal device, access network device, or core network device in the above-described method. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit for supporting communication between the communication device and a device such as a terminal device.
[0048] In one possible implementation, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0049] In one possible implementation, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples. For details, please refer to the description of the method provided in any one of the first to sixth aspects, which will not be repeated here.
[0050] In an eighth aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being configured to receive signals from a communication device other than the communication device and transmit them to the processor, or to transmit signals from the processor to a communication device other than the communication device, the processor implementing the functional modules of the method in any possible implementation of any of the first to sixth aspects through logic circuitry or by executing a computer program or instruction. Optionally, the communication device further comprises a memory configured to store the computer program or instruction.
[0051] In the ninth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed by a processor, the method in any possible implementation of any one of the first to sixth aspects is implemented.
[0052] In a tenth aspect, a computer program product storing instructions is provided, which, when read and executed by a computer, implements the method in any possible implementation of any one of the first to sixth aspects.
[0053] In an eleventh aspect, a circuit is provided for executing the method in any possible implementation of any one of the first to sixth aspects, wherein the circuit may include a chip circuit. Optionally, the circuit may also be coupled to a memory.
[0054] In a twelfth aspect, a chip is provided, comprising a processor. When the processor executes a computer program or instruction, the processor is configured to implement the method of any possible implementation of any of the first to sixth aspects. Optionally, the chip may further include a memory. The chip may be composed of a single chip or may include a chip and other discrete components.
[0055] In the thirteenth aspect, a communication device is provided, comprising a processor, which implements the method in any possible implementation of any one of the first to sixth aspects through a logic circuit or executing a computer program or instruction.
[0056] In a fourteenth aspect, a communication device is provided, comprising a unit or module for executing the method in any possible implementation of any one of the first to sixth aspects above.
[0057] In a fifteenth aspect, embodiments of the present application further provide a communication system. The communication system includes: a terminal device for implementing the method in the aforementioned first aspect and any possible implementation thereof; a core network device for implementing the method in the aforementioned second aspect and any possible implementation thereof; and an access network device for implementing the method in the aforementioned third aspect and any possible implementation thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] FIG1 is a schematic diagram of an access network device architecture provided in an embodiment of the present application;
[0059] FIG2 is a schematic diagram of an environmental Internet of Things architecture provided by an embodiment of the present application;
[0060] FIG3 is a schematic diagram of a network architecture provided in an embodiment of the present application;
[0061] FIG4 is a schematic diagram of a network architecture provided in an embodiment of the present application;
[0062] FIG5 is a schematic diagram of a network architecture provided in an embodiment of the present application;
[0063] FIG6 is a schematic diagram of a network architecture provided in an embodiment of the present application;
[0064] FIG7 is a schematic diagram of an inventory process provided in an embodiment of the present application;
[0065] FIG8 is a flow chart of a data transmission method provided in an embodiment of the present application;
[0066] FIG9 is a schematic diagram of a data transmission method according to an embodiment of the present application;
[0067] FIG10 is a flow chart of a data transmission method provided in an embodiment of the present application;
[0068] FIG11 is a flow chart of a data transmission method provided in an embodiment of the present application;
[0069] FIG12 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0070] FIG13 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0071] FIG14 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0072] Below with reference to the accompanying drawings in the embodiment of the present application, the technical scheme in the embodiment of the present application is described. Obviously, the embodiment described is only a part of the embodiment of the present application, rather than all of the embodiments. The terms "first", "second" and corresponding terminology numbers in the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiment of the present application. In addition, the terms "comprise" and "have" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0073] The method provided in the embodiment of the present application can be applied to various types of mobile communication systems, for example, the Internet of Things (IoT), narrowband Internet of Things (NB-IoT), the fourth generation (4G) communication system (such as long term evolution (LTE)), the fifth generation (5G) communication system (such as 5G new radio (NR)), the hybrid architecture of LTE and NR, 6G or new communication systems that will emerge in future communication developments, etc. The communication system may also include a machine to machine (M2M) network, a machine type communication (MTC) or other networks. Exemplarily, the method provided in the embodiment of the present application can be applied to a communication system that supports ambient IoT (AIoT) technology.
[0074] The methods and devices provided in the embodiments of the present application are based on the same or similar technical concepts. Since the principles of solving problems by the methods and devices are similar, the implementation of the devices and methods can refer to each other, and the repeated parts will not be repeated.
[0075] Below, some terms used in the embodiments of the present application are first explained to facilitate understanding by those skilled in the art.
[0076] In the embodiments of the present application, an access network device is a device in a wireless network. An access network device may also be referred to as a network device or a wireless access network device. For example, an access network device may be a radio access network (RAN) node that connects a terminal device to a wireless network, and may also be referred to as an access network device. Access network equipment includes but is not limited to: base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), next generation NodeBs (gNBs) in fifth generation (5G) mobile communication systems, access network equipment in open radio access networks (O-RANs), next generation base stations in sixth generation (6G) mobile communication systems, base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems, etc.; or it may be a module or unit that completes part of the functions of a base station, for example, a centralized unit (CU), a distributed unit (DU), a centralized unit control plane (CU-CP) module, or a centralized unit user plane (CU-UP) module. The access network equipment may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, etc. The specific technology and specific device form adopted by the access network equipment are not limited in this application.
[0077] As shown in Figure 1, in some implementations, access network equipment may include a centralized unit (CU) and a distributed unit (DU). The RAN equipment, including the CU and DU nodes, splits the protocol layers of the gNB in the NR system. Some protocol layer functions are centrally controlled by the CU, while some or all of the remaining protocol layer functions are distributed in the DU, which is then centrally controlled by the CU. Furthermore, the CU can be divided into a control plane (CU-CP) and a user plane (CU-UP). The CU-CP is responsible for control plane functions, primarily including radio resource control (RRC) and the control plane's corresponding packet data convergence protocol (PDCP) (i.e., PDCP-C). PDCP-C is primarily responsible for encryption, decryption, integrity protection, and data transmission of control plane data. The CU-UP is responsible for user plane functions, primarily including the service data adaptation protocol (SDAP) and the user plane's corresponding PDCP (i.e., PDCP-U). SDAP is primarily responsible for processing core network data and mapping flows to bearers. The PDCP-U is primarily responsible for data plane encryption and decryption, integrity protection, header compression, sequence number maintenance, and data transmission. The CU-CP and CU-UP are connected via the E1 interface. The CU-CP represents the gNB's connection to the core network via the NG interface and to the DU via the F1 interface control plane (i.e., F1-C). The CU-UP connects to the DU via the F1 interface user plane (i.e., F1-U). Alternatively, the PDCP-C may also reside in the CU-UP.
[0078] It is understandable that in different systems, CU (including CU-CP or CU-UP) or DU may have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (O-RAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, and CU-UP may also be called O-CU-UP. For convenience of description, this application uses CU, CU-CP, CU-UP and DU as examples for description. The access network equipment may also include an active antenna unit (AAU). The CU implements some functions of the gNB, and the DU implements some functions of the gNB. For example, the CU is responsible for processing non-real-time protocols and services and implementing the functions of the RRC layer. The DU is responsible for processing physical layer protocols and real-time services and implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer and the physical (PHY) layer. In some deployments, the CU can be further divided into a Centralized Unit Control Plane (CU-CP) node and a Centralized Unit User Plane (CU-UP) node, where the CU-CP is responsible for control plane functions and the CU-UP is responsible for user plane functions.
[0079] The terminal device involved in the embodiments of the present application may be a wireless terminal device capable of receiving access network device scheduling and instruction information. The terminal device may be referred to as a terminal device, and may also be referred to as user equipment (UE), mobile station (MS), mobile terminal (MT), etc. The terminal device may be a device that includes wireless communication capabilities (providing voice / data connectivity to the user). For example, a handheld device with wireless connection capabilities, or an in-vehicle device, in-vehicle module, etc. Currently, some examples of terminal devices include: mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in the Internet of Vehicles, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, device-to-device (D2D) communication terminal devices, vehicle-to-everything (V2X) communication terminal devices, smart vehicles, telematics boxes (T-boxes), machine-to-machine / machine-type communications (M2M / MTC) terminal devices, Internet of Things (IoT) The IoT (Internet of Things) terminal devices, etc. For example, the terminal device can be an onboard device, complete vehicle equipment, an onboard module, a vehicle, an onboard unit (OBU), a roadside unit (RSU), a T-box, a chip, or a system on chip (SOC), etc. The above chip or SOC can be installed in the vehicle, OBU, RSU, or T-box. Wireless terminals in industrial control can be cameras, robots, etc. Wireless terminals in smart homes can be TVs, air conditioners, vacuum cleaners, speakers, set-top boxes, etc.The terminal device can also be a V2X device, such as a smart car (or intelligent car), a digital car, an unmanned car (or driverless car or pilotless car or automobile), a self-driving car (or autonomous car), a pure electric vehicle (or battery EV), a hybrid electric vehicle (HEV), a range extended EV (REEV), a plug-in hybrid electric vehicle (PHEV), a new energy vehicle (new energy vehicle), or a roadside unit (RSU). The terminal device can also be a device in device-to-device (D2D) communication, such as an electricity meter, a water meter, etc. In addition, in an embodiment of the present application, the terminal device can also be a tag in an IoT system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0080] Tags can also be called electronic tags, RFID tags, or tag devices. Alternatively, tags can also be called AIoT terminal devices or AIoT devices. In this application, tags can also be regarded as a terminal device.
[0081] In one classification method, tags can be divided into passive tags, semi-passive tags, and active tags. Passive tags and semi-passive tags can use a backscatter-based communication method, while active tags use an actively generated carrier communication method.
[0082] Another classification method is to divide tags into the following three types of devices:
[0083] Device A: has no energy storage, cannot generate signals independently, and uses backscattering to transmit signals.
[0084] Device B: It has energy storage but cannot generate signals independently. It uses backscattering to transmit signals, and its stored energy can amplify the reflected signal.
[0085] Device C: has energy storage, can independently generate signals, and has active RF components for transmission.
[0086] The tag uses a low-precision, low-power medium-to-low-frequency ring oscillator or no local oscillator at all to receive downlink signals. When the tag is operating, the communication energy and carrier are provided by the reader, and communication is based on the reflected carrier.
[0087] The reader / writer involved in this embodiment can be a handheld or fixed device that reads or writes tag information, or can be understood as a device that communicates with tags. The reader / writer can be a terminal device, an access network device, or a device with reading and writing functions. The reader / writer can also be an IAB node or a relay node.
[0088] For example, as shown in Figure 2, a reader can transmit a carrier signal to a tag, which receives the carrier signal via its antenna. The solid line in the figure represents the carrier signal transmitted by the reader, while the dashed line represents the reflected signal transmitted by the tag based on the carrier signal. The tag can then adjust the information it wants to transmit based on the reflected signal. By using this approach, the tag can receive downlink signals using a low-precision, low-power medium- and low-frequency ring oscillator, or by eliminating the local oscillator altogether, further reducing the power consumption of the tag's downlink reception.
[0089] A tag is a miniature wireless transceiver, which mainly includes a built-in tag device antenna, a coupling element and a chip. The tag chip has a storage space that can support the reader to read or write tag data. After the tag receives the radio frequency signal sent by the reader through the antenna, it can couple the radio frequency signal through the coupling element, and then provide energy to the tag chip within the coupling channel, and feed back the data stored in the chip to the reader through the antenna. A communication network based on cellular network infrastructure, consisting of readers and tags, can be called a passive Internet of Things (IOT) network, or an ambient Internet of Things (IoT), in which the tag device can also be regarded as a terminal device, which can be an active tag device, a passive tag device or a semi-active tag device.
[0090] Environmental IoT systems can be applied to passive or semi-passive IoT scenarios. For example, in logistics and warehousing scenarios, tags can be used to inventory and track goods, and to monitor the status of goods during transportation. In industrial manufacturing scenarios, tags can be used to monitor the environment and equipment status.
[0091] In an environmental IoT system, the following operations can be performed between tags and readers:
[0092] Inventory operation: An inventory operation, also known as an inventory operation, retrieves a tag's identification information. For example, a reader can use commands such as query and acknowledgement (ACK) to obtain this information. To facilitate tag inventory, tags include four session identifiers, S0-S3. Each session identifier corresponds to two inventory states: A and B. The inventory state is indicated by the sessInventoried flag. When a reader selects a tag, it sends a select command containing the session identifier, which the tag then stores. When the reader performs an inventory operation on the tag, it sends a query command containing the session identifier. The tag then flips the inventory state corresponding to the session identifier from A to B. If the reader sends a query command to perform another inventory operation, the tag will not respond because its inventory state is B, thus preventing the same tag from being inventoried multiple times during a single inventory cycle.
[0093] Read operation: The read operation can read the electronic product code (EPC) in the tag's storage area, the tag identifier (TID), the content stored in the tag's reserved area, or the content stored in the user storage area.
[0094] Write operation: The write operation can write to the storage area of the tag.
[0095] Kill operation: The kill operation can make the tag unable to work forever.
[0096] Lock Operation: A lock operation can lock the tag's information, preventing read or write operations on the tag. Alternatively, a lock operation can lock a storage area, preventing or allowing read or write operations on the storage area.
[0097] The above are just examples. Other operations can be performed between the tag and the reader, which will not be explained one by one here.
[0098] FIG3 shows a schematic diagram of a communication system applicable to an embodiment of the present application. As shown in FIG3 , the communication system includes an access network device and a tag. The tag can be a standalone device or integrated with a terminal device, i.e., the tag is part of the terminal device. In this communication system, the access network device can have the function of a reader in a radio frequency identification (RFID) system, i.e., the access network device can function as a reader to communicate with the tag.
[0099] FIG4 is a schematic diagram of another communication system applicable to embodiments of the present application. As shown in FIG4 , the communication system includes a terminal device and a tag. The tag can be a standalone device or integrated with the terminal device. In this communication system, the terminal device can function as a reader / writer in an RFID system, i.e., the terminal device can function as a reader / writer to communicate with the tag.
[0100] FIG5 shows a schematic diagram of another communication system applicable to an embodiment of the present application. As shown in FIG5 , the communication system includes an access network device, an integrated access and backhaul (IAB) node, and a tag. The communication system may also include other devices, such as terminal devices. In this communication system, the access network device may have the function of a reader / writer in an RFID system, and the IAB node may serve as a relay node between the access network device and the tag. The tag transmits information to the IAB node, and the IAB node forwards the information to the access network device via the uu interface.
[0101] In the present application, the communication system including the access network device, the terminal device and the tag can also be a system with a separated architecture. In this communication system, as shown in FIG6 , the access network device and the terminal device can communicate directly with each other. The access network device can also have the function of a reader / writer in an RFID system. There is an uplink connection between the tag and the access network device, and a downlink connection between the tag and the terminal device. The terminal device can transmit information to the tag, and the tag then forwards the information to the access network device. Alternatively, there is a downlink connection between the tag and the access network device, and an uplink connection between the tag and the terminal device. The access network device can transmit information to the tag, and the tag then forwards the information to the terminal network device. The energy required for the tag to send information can be provided by an excitation signal, and the excitation signal can come from the access network device or from the terminal device.
[0102] In the AIoT, before a reader can perform an inventory, the tags must connect to the reader through random access. After random access, the tags can report their identification to the reader, allowing the reader to determine the presence of tags within its coverage area. For example, Figure 7 shows a schematic diagram of an inventory process, including the following steps.
[0103] Step 701: The reader sends a paging or selection signaling to select or page one or a group of tags for access.
[0104] Paging or select signaling includes mask information or a group identifier. One mask information or group identifier can match multiple tags. If the mask information included in the tag matches the mask information included in the paging or select signaling, it indicates that the tag is selected. If the group identifier included in the tag matches the group identifier included in the paging or select signaling, it indicates that the tag is selected.
[0105] For example, the mask information included in the paging or select command is an inventory flag, such as the value of the inventory flag is state A; if the inventory flag of the tag is state A, it is determined to be selected.
[0106] Step 702: The reader sends a query signaling, which is used to initiate an inventory cycle.
[0107] For example, the query signaling includes a value of a parameter Q, where the parameter Q is used to calculate the total number of time slots allocated to the reader.
[0108] Step 703: The tag selects a time slot to send a random access request message;
[0109] The random access request message is used to initiate random access. For example, the random access request message may be a 16-bit random number (random number 16, RN16) generated by a tag.
[0110] Here, RN16 is taken as an example. The tag can also send random numbers of other lengths, such as 8-bit random numbers.
[0111] Specifically, the tag can calculate the access time slot range according to the Q value to be [0,2 Q -1], the label generates a [0,2 Q -1], and use this random number as the initial value of the counter. For example, if Q=4, the random number generated by the tag is one in [0,15]. For example, if the random number generated by the tag is 10, the initial value of the counter is 10.
[0112] Each time a tag receives a QueryRep signaling, the counter value is decremented by one. When the counter value reaches 0, the tag can send an RN16, which can be used to trigger the random access process and can serve as a random access request message. The first time slot after the query signaling is time slot 0. If the random number generated by the tag is 0, it can send an RN16 immediately after receiving the query signaling.
[0113] Step 704: If the reader successfully receives the RN16, it will feedback an acknowledgement (ACK) message, which includes the RN16 from the tag.
[0114] The ACK message may also be called a random access response message.
[0115] Step 705: When the tag receives the ACK message including its own RN16, it sends uplink data to the reader.
[0116] When the tag receives an ACK message containing its own RN16, it determines that random access is successful and can then send uplink data. For example, the uplink data can be the tag's electronic product code (EPC). The tag can also flip the inventory flag, for example, from state A to state B.
[0117] If the ACK message received by the tag does not include its own RN16, the tag ignores the ACK message and determines that the random access has failed.
[0118] After the reader receives the uplink data from the tag, it can send a query repeat signaling to trigger the next time slot.
[0119] During the above inventory process, if an illegal device intercepts the uplink data of a tag. If the illegal device sends the uplink data to another reader (e.g., a second reader), the second reader mistakenly believes that the inventory of the tag is complete. If the illegal device replays the uplink data, i.e., repeatedly sends it multiple times, it may cause interference with the uplink data of other tags, resulting in the uplink data of other tags being unable to be received by the reader. To this end, the present application provides a method that can ensure the security of data transmission.
[0120] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0121] When the method provided in the present application is applied to the system in Figures 3 to 6, the method executed by the terminal device in the embodiment of the present application can be implemented by the terminal device in Figures 3 to 6 or the module in the terminal device, and the method executed by the access network device in the embodiment of the present application can be implemented by the access network device in Figures 3 to 6 or the module in the access network device.
[0122] It can be understood that the present application does not specifically limit the specific structure of the execution subject of the method provided in the embodiment of the present application. The method executed by the terminal device in the present application can be applied to the terminal device or the module or chip in the terminal device. The method executed by the network device can be applied to the access network device or the module or chip in the access network device, and can also be applied to the terminal device or the module or chip in the terminal device. As long as it is possible to communicate according to the method provided in the embodiment of the present application by running a program that records the code of the method provided in the embodiment of the present application, the interaction between the terminal device and the access network device is used as an example for explanation below.
[0123] In the present application, the first information can be configured by the access network device, and the second information can be configured by the core network device. When the terminal device transmits uplink data, it carries the third information determined based on at least one of the first information and the second information. The access network device or the core network device can authenticate the uplink data based on the third information. If the authentication is successful, the uplink data is considered valid, and the terminal device is a legal device, so the uplink data can be saved. If the authentication fails, the uplink data is considered invalid, and the terminal device is an illegal device, so the uplink data can be discarded or ignored. Through this method, even if an illegal device receives the uplink data of the terminal device and uploads the uplink data to the network again, the network side can also determine whether the uplink data is valid based on the third information, thereby improving the security of data transmission. The following is a detailed description through specific embodiments.
[0124] As shown in Figure 8, a flow chart of a data transmission method provided in an embodiment of the present application is provided. In this method flow, the terminal device can also be replaced by a tag, the access network device can also be replaced by a reader / writer, and the core network device can also be replaced by an access and mobility management function (AMF) network element. The method includes:
[0125] Step 801: The core network device sends second information to the access network device.
[0126] Correspondingly, the access network device receives the second information.
[0127] The specific form of the second information is not limited. For example, the second information is a second random number generated by the core network device, or a bit sequence. Optionally, the second information is valid within an inventory service process, that is, the second information in different service request messages sent by the core network device is different. From the perspective of the core network device, an inventory service process begins when the core network device sends a service request message and ends when it sends a service response message; or from the perspective of the access network device, an inventory service process begins when the access network device sends a selection signaling and ends when X or X-1 query repetition signalings are sent, where the selection signaling indicates X time units and a query repetition signaling triggers an update of one time unit; or, an inventory service process is a preset duration starting from the access network device sending the selection signaling. The second information can also be updated periodically, related to a service trigger (updated once per trigger), or the core network device can directly send an update command to update the second information, or the update command can come from the application layer, which is not limited in this application.
[0128] In one implementation, the second information is configured according to the granularity of the access network device, that is, different access network devices correspond to different second information, and the core network device configures different second information for different access network devices.
[0129] This application does not limit how the core network device sends the second information. For example, the core network device sends the second information via a service request message. The service request message can be replaced by an inventory service request message, a paging message, a positioning request message, a read request message, or a write request message, etc. This application does not limit the name of the service request message.
[0130] Step 802: The access network device sends at least one of the first information and the second information to the terminal device.
[0131] Accordingly, the terminal device receives at least one of the first information and the second information. The first information and the second information can be used to perform security operations on the terminal device or uplink data, such as authentication, anti-replay, encryption, integrity protection, etc.
[0132] For example, the first information is a first random number generated by the access network device, or the first information is an identifier of a cell of the access network device. Alternatively, the first information may be determined based on the identifier of the cell of the access network device, where the cell is the cell in which the terminal device is located. This application does not limit how the first information is determined.
[0133] In one implementation, the first information is configured according to the granularity of the cell, that is, different cells correspond to different first information, and the access network device configures different first information for different cells.
[0134] If the access network device sends the first information and the second information, the access network device may send the first information and the second information via a single message, or may send the first information and the second information via two separate messages. For example, the access network device sends the first information and the second information via selection signaling or paging signaling. The access network device may also send the second information via selection signaling or paging signaling, and send the first information via query signaling, query repetition signaling, or a random access response message.
[0135] Step 803: The terminal device sends uplink data and third information to the access network device.
[0136] Correspondingly, the access network device receives the uplink data and the third information.
[0137] The uplink data may include the EPC of the terminal device, sensor data collected by the terminal device, storage area data of the terminal device, and the like, and is not limited in this application. The terminal device may be a passive device, a semi-passive device, or an active device, or the terminal device may be an environmental IoT terminal device, such as a tag.
[0138] The third information can be used to perform security operations on the terminal device or uplink data. For example, the security operations may include but are not limited to authentication, anti-replay, encryption, integrity protection and other operations. The third information can be determined based on at least one of the first information and the second information. Specifically, the terminal device can use at least one of the first information and the second information as the input parameter of the encryption algorithm or the integrity protection algorithm, and use the output result of the encryption algorithm or the integrity protection algorithm as the third information. The encryption algorithm or the integrity protection algorithm is pre-configured on the network side, and the access network device and the core network device can determine the encryption algorithm or the integrity protection algorithm in advance. When determining the third information, the encryption algorithm or the integrity protection algorithm may also include other input parameters, such as a key, which is not limited in this application, and the key can be pre-configured on the network side.
[0139] For example, the encryption algorithm or integrity protection algorithm can be any of the following algorithms: 128-NEA1 (for example, 128-bit SNOW 3G encryption algorithm); 128-NEA2 (for example, 128-bit AES algorithm); 128-NEA3 (for example, 128-bit Zu Chongzhi algorithm); 128-EEA1 (for example, 128-bit SNOW 3G algorithm); 128-EEA2 (for example, 128-bit AES algorithm); 128-EEA3 (for example, 128-bit Zu Chongzhi algorithm).
[0140] NEA refers to the NR encryption algorithm, and EEA stands for the Evolved Packet System encryption algorithm (EPS encryption algorithm).
[0141] In the above method, if the core network device configures different second information for different access network devices, then the third information determined by the terminal devices under different access network devices based on the second information is different; if the access network device configures different first information for different cells, then the third information determined by the terminal devices in different cells of the access network device based on the first information is different; in this way, even if an illegal device obtains uplink data, the uplink data reported by the illegal device in other cells or to other access network devices will be regarded as invalid data, thereby improving the security of data transmission.
[0142] Step 804: The access network device forwards the uplink data and the third information to the core network device.
[0143] Correspondingly, the core network device receives the uplink data and the third information.
[0144] Step 805: The core network device determines fourth information based on at least one of the first information and the second information. If the fourth information matches the third information, the core network device saves the uplink data.
[0145] The core network device may use at least one of the first information and the second information as an input parameter for an authentication or authorization or encryption algorithm or an integrity protection algorithm, and use the output of the encryption algorithm or integrity protection algorithm as the fourth information. The encryption algorithm or integrity protection algorithm used by the core network device is the same as the encryption algorithm or integrity protection algorithm used by the terminal device when generating the third information. The parameters of the encryption algorithm or integrity protection algorithm input by the core network device when generating the fourth information are the same as the parameters of the encryption algorithm or integrity protection algorithm input by the terminal device when generating the third information.
[0146] In one implementation, the input parameters used by the core network device are pre-agreed with the terminal device. For example, if it is pre-agreed that the first information be used as an input parameter for an encryption algorithm or an integrity protection algorithm, then the terminal device only uses the first information to generate the third information, and the core network device also only uses the first information to generate the fourth information. For another example, if it is pre-agreed that the first information and the second information be used as input parameters for an encryption algorithm or an integrity protection algorithm, then the terminal device uses the first information and the second information to generate the third information, and the core network device also uses the first information and the second information to generate the fourth information.
[0147] In another implementation, the terminal device or access network device may also send at least one of the first information and the second information to the core network device, and the core network device may determine that the parameter required to generate the fourth information is at least one of the first information and the second information.
[0148] Among them, the terminal device can send at least one of the first information and the second information to the access network device, which will be forwarded to the core network device by the access network device; the access network device can also send at least one of the first information and the second information to the core network device; the access network device can also transparently forward at least one of the first information and the second information sent by the terminal device to the core network device. The specific process will not be repeated here.
[0149] In this application, the fourth information matches the third information, which may mean that the fourth information is the same as the third information. The fourth information matches the third information, indicating that the terminal device is a legitimate device and the uplink data reported by the terminal device is valid.
[0150] In one implementation, if the fourth information matches the third information, and this is the first time the core network device has received the third information and the uplink data, the core network device stores the uplink data. If the fourth information matches the third information, but this is not the first time the core network device has received the third information and the uplink data, the core network device discards or ignores the uplink data. This method allows, if uplink data is repeatedly sent by an unauthorized device, to determine that the uplink data has been received based on the third information, and to discontinue storage of the uplink data, thereby improving data transmission security.
[0151] In another implementation, if the fourth information matches the third information, and the third information and uplink data are the first received by the core network device within a preset duration, the core network device saves the uplink data; if the fourth information matches the third information, but the third information and uplink data are not the first received by the core network device within the preset duration, the core network device discards or ignores the uplink data; the preset duration is preset, preconfigured, or determined by the core network device. This method allows, if uplink data is repeatedly sent multiple times by an illegal device within a preset duration, to determine, based on the third information, that the uplink data has been received within the preset duration, and to no longer save the uplink data, thereby improving data transmission security.
[0152] In the above method, if an illegal device obtains uplink data of a terminal device from the cell of other access network devices and sends it to the core network device through another access network device, since the core network device configures different second information for different access network devices, the terminal devices under different access network devices determine different third information based on the second information. In this way, the fourth information determined by the core network device is different from the obtained third information. Therefore, the core network device can determine whether the obtained uplink data is valid based on the third information, thereby improving the security of data transmission.
[0153] If an illegal device obtains uplink data of a terminal device in a cell of an access network device and sends it to a core network device through the access network device in another cell, since the terminal devices in different cells determine different third information based on the first information, the fourth information determined by the core network device is different from the obtained third information. Therefore, the core network device can determine whether the obtained uplink data is valid based on the third information, thereby improving the security of data transmission.
[0154] After the core network device determines to save the uplink data, it may also send the uplink data to other devices, such as a network exposure function (NEF) network element or an application function (AF) network element.
[0155] In another implementation, if the fourth information does not match the third information, the core network device discards or ignores the uplink data.
[0156] The fourth information does not match the third information, which may mean that the fourth information is different from the third information. The fourth information does not match the third information, indicating that the terminal device is an illegal device and the uplink data reported by the terminal device is invalid.
[0157] Optionally, the fourth information does not match the third information, and the core network device may further send fifth information to the terminal device or the access network device, where the fifth information indicates that the uplink data is invalid, or the fifth information indicates that the terminal device authentication fails.
[0158] In the above process, the core network device determines whether the uplink data is valid based on the third information as an example. In another implementation, the access network device may also determine whether the uplink data is valid based on the third information. Specifically, the execution subject of step 805 may be replaced by the access network device. After the access network device determines that the uplink data is valid, it may send the uplink data to the core network device. The specific process is not repeated here.
[0159] Through the above process, the core network device can authenticate the uplink data based on the third information. If the authentication succeeds, the uplink data is considered valid and the terminal device is legitimate, and the uplink data can be saved. If the authentication fails, the uplink data is considered invalid and the terminal device is illegal, and the uplink data can be discarded or ignored. Therefore, this method improves the security of data transmission.
[0160] The following takes the inventory process of this application in the AIoT scenario as an example. Other application scenarios can refer to the following process, which will not be repeated here.
[0161] As shown in Figure 9, a flow chart of a data transmission method provided in an embodiment of the present application is provided. In this method flow, the terminal device is used as a tag, the access network device is a gNB, and the core network device is an AMF network element as an example. The core network device can also be a tag management function (TMF) network element, or an inventory network element, an external server, etc. The method includes:
[0162] Step 901: The AMF network element sends a service request message to the gNB.
[0163] The service request message is used to trigger the gNB to initiate A-IoT related processes (inventory, read, write, authentication, etc.). It can be N2 interface signaling or a newly defined interface message (for example, between a TMF network element and a base station). A-IoT related processes include but are not limited to inventory processes, read processes, write processes, authentication processes, etc.
[0164] The service request message includes the second information. The service request message may also include mask information or identification information, where the mask information or identification information is used to select at least one tag for inventory.
[0165] Optionally, the second information is valid within an inventory service flow, i.e., the second information in different service request messages sent by the AMF network element is different. From the perspective of the AMF network element, an inventory service flow begins with the AMF sending a service request message and ends with the AMF sending a service response message. Alternatively, from the perspective of the gNB, an inventory service flow begins with the gNB sending a selection signaling and ends after sending X or X-1 query repetition signalings, where the selection signaling indicates X time units, and one query repetition signaling triggers the update of one time unit. Alternatively, an inventory service flow is a preset duration starting from the gNB sending the selection signaling.
[0166] Optionally, the second information configured by the AMF network element to different gNBs is different.
[0167] Step 902: gNB sends selection signaling.
[0168] The selection signaling is used to select at least one terminal device. The selection signaling includes second information, mask information, or identification information. The mask information or identification information comes from the service request message, and the mask information or identification information is used to select at least one terminal device. The selection signaling may also include some transmission control indication information (such as cyclic redundancy check (CRC) rule indication, frequency domain resource allocation, coding rate, etc.). The selection signaling may also be replaced by a paging message. This application does not limit the name of the selection signaling.
[0169] For example, if the mask information included in the tag matches the mask information included in the selection signaling, it indicates that the tag is selected; or if the identification information included in the tag matches the identification information included in the selection signaling, it indicates that the tag is selected.
[0170] For example, the mask information included in the selection signaling is 0000. If the mask information in the tag is 00001111, since the first bit of "00001111" in the tag is the same as the mask information included in the selection signaling, the tag is determined to match and can respond to the selection signaling.
[0171] The selection signaling may further include the first information. Optionally, the first information included in the selection signaling sent by the gNB in different cells is different.
[0172] Step 903: The gNB sends query signaling.
[0173] The query signaling may be a message used to allocate access resources (e.g., time resources) to a terminal device waiting to access. For example, the query signaling may indicate X time units, where X is an integer greater than 0. The query signaling may also trigger the first time unit of the X time units. A time unit may be a time slot or a subframe.
[0174] This application does not limit how the query signaling indicates X time units. For example, the query signaling includes the value of parameter Q, which is used to determine X time units. For example, Q = 4, then X = 2 Q -1=16, that is, the query signaling indicates 16 time units.
[0175] In addition, if the selection signaling does not include the first information or the second information, the query signaling may also include the first information or the second information. The query signaling may also include some transmission control indication information (such as frequency domain resource allocation, coding rate, etc.). This application does not limit the information included in the query signaling.
[0176] In this application, the lengths of any two time units in the time domain may be the same or different. A time unit is triggered by a trigger message (e.g., a query message or a query repeat message). The length of a time unit in the time domain can be the interval between two adjacent trigger messages. The tag determines the specific number of time slots based on the number of trigger messages received or the time unit index carried in the trigger message.
[0177] Step 904: The tag sends a random access request message.
[0178] The random access request message is used to initiate random access. In the ambient IoT, the random access type can be RFID-based ALOHA asynchronous random access. Alternatively, the random access type can be 4-step random access or 2-step random access in NR or NB-IoT. The random access request message can be a 16-bit random number RN16 or a random number of other lengths, which is not limited in this application.
[0179] Step 905: The gNB sends a random access response message.
[0180] The random access response message may also be referred to as a contention resolution indicator. If the random access response message includes part or all of the random access request message, such as part or all of RN16, the terminal device can determine that the random access was successful and can send uplink data to the gNB.
[0181] If the selection signaling does not include the first information or the second information, the random access response message may also include the first information or the second information.
[0182] Step 904 and step 905 are optional steps. Step 906 may be directly executed without executing step 904 and step 905.
[0183] Step 906: The tag sends the third information and uplink data.
[0184] The tag may use at least one of the first information and the second information as an input parameter of an encryption algorithm or an integrity protection algorithm, and use an output result of the encryption algorithm or the integrity protection algorithm as the third information.
[0185] The uplink data may be the tag's identifier or EPC, or data in the tag's storage area, which is not limited in this application.
[0186] In this step, the tag may also send parameters for generating the third information to the gNB. For example, if the third information is determined based on the first information, the first information is also sent; if the third information is determined based on the first and second information, the first and second information are also sent.
[0187] Step 907: The gNB sends the third information and uplink data to the AMF network element.
[0188] In one implementation, if the third information and uplink data are not transparently transmitted to the AMF network element through the gNB, for example, the tag transmits the third information and uplink data through an access stratum (AS) message, after the gNB obtains the third information and uplink data, it can also send at least one of the first information and the second information to the AMF network element.
[0189] Step 908: The AMF network element determines that the fourth information matches the third information, and the AMF network element saves the uplink data.
[0190] The AMF network element may use at least one of the first information and the second information as an input parameter of an encryption algorithm or an integrity protection algorithm, and use an output result of the encryption algorithm or the integrity protection algorithm as the fourth information. The encryption algorithm or integrity protection algorithm used by the AMF network element to generate the fourth information is the same as the encryption algorithm or integrity protection algorithm used by the tag to generate the third information, and the algorithm is pre-agreed or configured.
[0191] Optionally, if the fourth information matches the third information, and the third information and the uplink data are received by the AMF network element for the first time, the AMF network element stores the uplink data. If the fourth information matches the third information, but the third information and the uplink data are not received by the AMF network element for the first time, the uplink data is discarded or ignored. At this time, the core network device may also send fifth information, indicating that the uplink data is invalid or that the terminal device authentication failed. The fifth information may also be referred to as an authentication failure message, etc.
[0192] Optionally, if the fourth information matches the third information, and the third information and uplink data are received for the first time by the AMF network element within a preset time period, the AMF network element saves the uplink data; if the fourth information matches the third information, but the third information and uplink data are not received for the first time by the AMF network element within a preset time period, the uplink data is discarded or ignored.
[0193] In another implementation, if the fourth information does not match the third information, the AMF network element discards or ignores the uplink data.
[0194] After the AMF network element saves the uplink data, it can also send the uplink data to the NEF network element or the AF network element. For example, the AMF network element sends a service response message to the NEF network element or the AF network element, and the service response message includes the uplink data. The specific process is not repeated here.
[0195] In the above process, the gNB may also determine whether the uplink data is valid. Specifically, steps 907 and 908 may be replaced by the following steps:
[0196] The gNB determines that the fourth information matches the third information and sends uplink data to the core network device.
[0197] The gNB can use the same method as the AMF network element to determine the fourth information, and the specific process will not be repeated.
[0198] Through the above process, during the inventory process, the AMF network element configures different second information to different gNBs, and the gNB configures different first information to different cells. Therefore, even if an illegal device obtains the tagged uplink data and repeatedly sends it to the network, if the illegal device sends the tagged uplink data to another gNB, the AMF network element or gNB determines the third information based on the second information and can determine that the uplink data of the illegal device is invalid based on the third information. If the illegal device sends the tagged uplink data to the gNB in another cell, the AMF network element or gNB determines the third information based on the first information and can determine that the uplink data of the illegal device is invalid based on the third information. Therefore, the method provided by this application can improve data transmission security.
[0199] The present application also provides a method that may not require the core network device to configure the second information, and may not require the access network device to configure the first information, which will be described in detail below.
[0200] As shown in Figure 10, a flowchart of a data transmission method provided in an embodiment of the present application is provided. In this method flow, the terminal device can also be replaced with a tag, the access network device can also be replaced with a reader / writer, and the core network device can also be replaced with an AMF network element. The method includes:
[0201] Step 1001: The access network device sends a first signaling to the terminal device.
[0202] Correspondingly, the terminal device receives the first signaling.
[0203] The first signaling is a query repetition signaling or a contention resolution message, and the first signaling may also be other messages, which is not limited in this application. The contention resolution message may also be called a random access response message or the like.
[0204] Step 1002: The terminal device sends third information and uplink data to the access network device.
[0205] Among them, the third information can be used to perform security operations on the terminal device or uplink data. For example, the security operations may include but are not limited to authentication, anti-replay, encryption, integrity protection and other operations.
[0206] The terminal device can determine the first information based on the first signaling, and then determine the third information based on the first information.
[0207] For example, in implementation method 1, the terminal device determines the first information based on the number of transmissions of the first signaling. In this case, the first information may be the number of transmissions of the first signaling.
[0208] In this implementation, the number of transmissions of the first signaling may refer to the cumulative number of receptions in an inventory process. For example, if the terminal device receives the first signaling five times in an inventory process, the terminal device may determine that the first information is five.
[0209] In this implementation, the first signaling may be a query repetition signaling or a contention resolution message.
[0210] In implementation method 2, the first signaling is used to trigger the update of a time unit. A time unit can be a time slot or subframe, for example. Each time the access network device sends a first signaling, it indicates a new time unit, i.e., the end of one time unit and the beginning of another. The first signaling can include a time unit index, which can be the index of the time unit triggered by the first signaling.
[0211] In this implementation, the first information is a time unit index included in the first signaling.
[0212] In this implementation, the first signaling may be query repetition signaling.
[0213] In implementation method three, the first signaling includes a random number, which may be configured by the access network device. The first information may be the random number included in the first signaling. Optionally, before each first signaling transmission, the network device generates a random number and carries it in the first signaling. This ensures that the random numbers in different first signaling transmissions are different, thereby improving data transmission security.
[0214] In this implementation, the first signaling may be query repetition signaling, a contention resolution message, or query signaling.
[0215] In implementations 1 through 3 above, each time the access network device sends the first first signaling, the first information in the first signaling changes. That is, different first signalings contain different first information. This increases the frequency of first information updates, shortens the validity period of the first information, and further enhances the security of the third information determined based on the first information.
[0216] This application does not limit how the terminal device determines the third information based on the first information. For example, the terminal device may use the first information as an input parameter of an encryption algorithm or an integrity protection algorithm, and use the output result of the encryption algorithm or the integrity protection algorithm as the third information. The encryption algorithm or integrity protection algorithm is preset or pre-configured on the network side, and the access network device and the core network device can determine the encryption algorithm or integrity protection algorithm in advance. The encryption algorithm or integrity protection algorithm may also include other input parameters, such as a key, which may be pre-configured on the network side.
[0217] Optionally, when the terminal device sends the third information and uplink data, it may also send the first information, so that the access network device or the core network device can determine that the third information is determined based on the first information.
[0218] Step 1003: The access network device forwards the uplink data and the third information to the core network device.
[0219] Correspondingly, the core network device receives the uplink data and the third information.
[0220] Optionally, the access network device may also send the first information to the core network device.
[0221] Step 1004: The core network device determines fourth information based on the first information. If the fourth information matches the third information, the core network device saves the uplink data.
[0222] The core network device may use the first information as an input parameter of an encryption algorithm or an integrity protection algorithm, and use the output result of the encryption algorithm or the integrity protection algorithm as the fourth information. The encryption algorithm or integrity protection algorithm used by the core network device is the same as the encryption algorithm or integrity protection algorithm used by the terminal device when generating the third information.
[0223] Among them, the terminal device can send the first information to the access network device, which will be forwarded to the core network device by the access network device; the access network device can also send the first information to the core network device; the access network device can also transparently forward the first information sent by the terminal device to the core network device. The specific process will not be repeated here.
[0224] In this application, the fourth information matches the third information, which may mean that the fourth information is the same as the third information. The fourth information matches the third information, indicating that the terminal device is a legitimate device and the uplink data reported by the terminal device is valid.
[0225] In one implementation, if the fourth information matches the third information, and the third information and uplink data are received by the core network device for the first time, the core network device saves the uplink data; if the fourth information matches the third information, but the third information and uplink data are not received by the core network device for the first time, the core network device discards or ignores the uplink data.
[0226] In another implementation, if the fourth information matches the third information, and the third information and uplink data are received for the first time by the core network device within a preset time period, the core network device saves the uplink data; if the fourth information matches the third information, but the third information and uplink data are not received for the first time by the core network device within the preset time period, the core network device discards or ignores the uplink data.
[0227] In the above method, even if an illegal device obtains the uplink data of a terminal device and sends it to the core network device through the access network device, since the first information included in different first signaling is different, if the time when the illegal device sends the uplink data and the time when the terminal device sends the uplink data correspond to different first signaling, then the fourth information determined by the core network device is different from the third information reported by the illegal device. Therefore, the core network device can determine whether the obtained uplink data is valid based on the third information, thereby improving the security of data transmission.
[0228] After the core network device determines to save the uplink data, it may also send the uplink data to other devices, such as NEF network elements or AF network elements.
[0229] In this application, if the fourth information does not match the third information, the uplink data is discarded or ignored. The fourth information not matching the third information may mean that the fourth information is different from the third information. The fourth information not matching the third information indicates that the terminal device is an illegal device, and the uplink data reported by the terminal device is invalid.
[0230] Optionally, if the fourth information does not match the third information, the core network device may also send fifth information to the terminal device or access network device, where the fifth information indicates that the uplink data is invalid, or the fifth information indicates that the terminal device authentication fails.
[0231] In the above process, the core network device determines whether the uplink data is valid based on the third information. In another implementation, the access network device may also determine whether the uplink data is valid based on the third information. Specifically, the execution subject of step 1004 may be replaced by the access network device. After the access network device determines that the uplink data is valid, it may send the uplink data to the core network device. The specific process is not repeated here.
[0232] Through the above process, the core network device or access network device can authenticate the uplink data based on the third information. If the authentication succeeds, the uplink data is considered valid and the terminal device is legitimate, and the uplink data can be saved. If the authentication fails, the uplink data is considered invalid and the terminal device is illegal, and the uplink data can be discarded or ignored. Therefore, this method improves the security of data transmission.
[0233] The following takes the inventory process of this application in the AIoT scenario as an example. Other application scenarios can refer to the following process, which will not be repeated here.
[0234] As shown in Figure 11, a schematic diagram of a data transmission method flow provided in an embodiment of the present application is provided. In this method flow, taking the terminal device as a tag, the access network device as a gNB, and the core network device as an AMF network element as an example, the method includes:
[0235] Step 1101: The AMF network element sends a service request message to the gNB.
[0236] The Service Request message is used to trigger the gNB to initiate A-IoT-related processes (such as inventory, read, write, and authentication). The Service Request message may also have other names, which are not limited by this application. The Service Request message may include mask information or identification information, which is used to select at least one tag for inventory.
[0237] Step 1102: gNB sends selection signaling.
[0238] The selection signaling is used to select at least one terminal device. The selection signaling includes mask information or identification information, and the mask information or identification information comes from the service request message.
[0239] For example, if the mask information included in the tag matches the mask information included in the selection signaling, it indicates that the tag is selected; or if the identification information included in the tag matches the identification information included in the selection signaling, it indicates that the tag is selected.
[0240] For example, the mask information included in the selection signaling is 0000. If the mask information in the tag is 00001111, since the first bit of "00001111" in the tag is the same as the mask information included in the selection signaling, the tag is determined to match and can respond to the selection signaling.
[0241] Step 1103: gNB sends query signaling.
[0242] The query signaling may be a message used to allocate access resources (eg, time resources, etc.) to the terminal device to be accessed. For example, the query signaling indicates X time units, where X is an integer greater than 0.
[0243] This application does not limit how the query signaling indicates X time units. For example, the query signaling includes the value of parameter Q, which is used to determine X time units. For example, Q = 4, then X = 2 Q -1=16, that is, the query signaling indicates 16 time units.
[0244] Step 1104: The gNB sends query repetition signaling.
[0245] Query repetition signaling is used to trigger the update of one time unit.
[0246] Optionally, the query repetition signaling includes a random number, or the query repetition signaling includes a time unit index, where the time unit index is the index of the time unit triggered by the query repetition signaling.
[0247] Step 1105: The tag sends a random access request message.
[0248] The random access request message is used to initiate random access. In the ambient IoT, the random access type can be RFID-based ALOHA asynchronous random access. Alternatively, the random access type can be 4-step random access or 2-step random access in NR or NB-IoT.
[0249] The random access request message may be a 16-bit random number RN16, or a random number of other lengths, which is not limited in this application.
[0250] Step 1106: The gNB sends a random access response message.
[0251] If the random access response message includes part or all of the content of the random access request message, for example, part or all of RN16, then the terminal device can determine that the random access is successful and can send uplink data to the gNB.
[0252] If the query repetition signaling does not include a random number, the random access response message may also include a random number.
[0253] Step 1105 and step 1106 are optional steps. Step 1105 and step 1106 may be omitted and step 1107 may be directly executed.
[0254] Step 1107: The tag sends the third information and uplink data.
[0255] The tag may use the first information as an input parameter of an encryption algorithm or an integrity protection algorithm, and use the output result of the encryption algorithm or the integrity protection algorithm as the third information.
[0256] For example, if the query repetition signaling or random access request message includes a random number, the terminal device may use the random number as the first information; if the query repetition signaling includes a time unit index, the first information may be the time unit index. Alternatively, the terminal device may use the number of times the query repetition signaling or random access request message is received during the inventory process as the first information, which is not limited in this application.
[0257] The uplink data may be the tag's identifier or EPC, or data in the tag's storage area, which is not limited in this application.
[0258] In this step, the tag may also send the first information to the gNB.
[0259] Step 1108: The gNB sends the third information and uplink data to the AMF network element.
[0260] In one implementation, if the third information and uplink data are not transparently transmitted to the AMF network element through the gNB, for example, the tag transmits the third information and uplink data through an access stratum (AS) message, after the gNB obtains the third information and uplink data, it can also send the first information to the AMF network element.
[0261] Step 1109: The AMF network element determines that the fourth information matches the third information, and the AMF network element saves the uplink data.
[0262] The AMF network element may use the first information as an input parameter of an encryption algorithm or an integrity protection algorithm, and use the output result of the encryption algorithm or the integrity protection algorithm as the fourth information. The encryption algorithm or integrity protection algorithm used by the AMF network element to generate the fourth information is the same as the encryption algorithm or integrity protection algorithm used by the tag to generate the third information, and the algorithm is pre-agreed or configured. At this time, the core network device may also send fifth information, and the fifth information indicates that the uplink data is invalid, or the fifth information indicates that the terminal device authentication fails. The fifth information may also be called an authentication failure message or the like.
[0263] In another implementation, if the fourth information does not match the third information, the AMF network element discards or ignores the uplink data.
[0264] After the AMF network element saves the uplink data, it can also send the uplink data to the NEF network element or the AF network element. For example, the AMF network element sends a service response message to the NEF network element or the AF network element, and the service response message includes the uplink data. The specific process is not repeated here.
[0265] In the above process, the gNB can also determine whether the uplink data is valid. Specifically, steps 1108 and 1109 can be replaced by the following steps: the gNB determines that the fourth information matches the third information and sends the uplink data to the core network device.
[0266] The gNB can use the same method as the AMF network element to determine the fourth information, and the specific process will not be repeated.
[0267] Through the above process, in the inventory process, each query repetition signaling message is used to update a time unit, and each random access response message corresponds to a time unit. Therefore, the tag determines the first information based on the query repetition signaling message or the random access response message, and can use different first information to determine the third information in different time units. In this way, when an illegal device obtains the tag's uplink data and transmits the uplink data to the network at a different time unit than the tag transmits the uplink data, the network can determine that the uplink data was reported by the illegal device based on the third information and discard the uplink data, thereby improving data transmission security.
[0268] It is understandable that in order to implement the functions in the above embodiments, the terminal device or access network device or core network device includes a hardware structure and / or software module corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a computer software-driven hardware manner depends on the specific application scenario and design constraints of the technical solution.
[0269] The following is a schematic diagram of the structure of possible communication devices provided in the embodiments of the present application. These communication devices can be used to implement the functions of the terminal device, access network device, or core network device in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.
[0270] As shown in Figure 12, the communication device 1200 includes a processing unit 1210 and a communication unit 1220. The communication device 1200 is used to implement the functions of the terminal device, access network device, or core network device in the above-mentioned method embodiments.
[0271] In one implementation, the communication device 1200 is configured to implement the following functions:
[0272] A communication unit, configured to receive at least one of first information and second information; wherein the second information is included in selection signaling or paging signaling;
[0273] a processing unit, configured to determine third information based on at least one of the first information and the second information;
[0274] The communication unit is used to send the third information and uplink data; the third information is used to authenticate the uplink data.
[0275] In one implementation, the communication device 1200 is configured to implement the following functions:
[0276] A communication unit, configured to receive third information and uplink data from a terminal device; receive at least one of first information and second information from the terminal device or an access network device; the first information is configured for the access network device; the second information is configured for a core network device;
[0277] A processing unit is configured to determine fourth information based on at least one of the first information and the second information, and save the uplink data if the fourth information matches the third information.
[0278] In one implementation, the communication device 1200 is configured to implement the following functions:
[0279] A processing unit, configured to send at least one of first information and second information to a terminal device through a communication unit; the first information is configured by an access network device; and the second information is configured by a core network device;
[0280] The processing unit is used to receive the third information and uplink data from the terminal device through the communication unit, and send the third information and the uplink data to the core network device; the third information is determined based on at least one of the first information and the second information, and the third information is used to authenticate the uplink data.
[0281] In one implementation, the communication device 1200 is configured to implement the following functions:
[0282] A processing unit, configured to receive a first signaling from the access network device through a communication unit; the first signaling is a query duplication signaling or a contention resolution message;
[0283] The processing unit is used to send third information and uplink data to the access network device through the communication unit; the third information is used to authenticate the uplink data, the third information is determined according to the first information, and the first information is determined according to the first signaling.
[0284] In one implementation, the communication device 1200 is configured to implement the following functions:
[0285] A processing unit, configured to send a first signaling through a communication unit; the first signaling is a query duplication signaling or a contention resolution message;
[0286] The processing unit is used to receive third information and uplink data from the terminal device through the communication unit; the third information is used to authenticate the uplink data, the third information is determined based on the first information, and the first information is determined based on the first signaling; and the third information and the uplink data are sent to the core network device.
[0287] In one implementation, the communication device 1200 is configured to implement the following functions:
[0288] a communication unit configured to receive third information and uplink data; wherein the third information is used to authenticate the uplink data; receive first information from an access network device, and determine fourth information based on the first information;
[0289] A processing unit is configured to save the uplink data when the fourth information matches the third information.
[0290] A more detailed description of the processing unit 1210 and the communication unit 1220 can be directly obtained by referring to the relevant descriptions in the above-mentioned method embodiments, and will not be repeated here.
[0291] It should be understood that the division of units in the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or physically separated. Moreover, the units in the device can all be implemented in the form of software called through processing elements; or all be implemented in the form of hardware; or some units can be implemented in the form of software called through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated into a certain chip of the device. In addition, it can also be stored in the form of a program in a memory, called by a certain processing element of the device and execute the function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each operation of the above method or each unit above can be implemented by the integrated logic circuit of the hardware in the processor element or by software called through the processing element.
[0292] In one example, the unit in any of the above devices may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital singnal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general-purpose central processing unit (CPU), or other processor that can call a program. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0293] The above-mentioned receiving unit is an interface circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented as a chip, the receiving unit is the interface circuit of the chip used to receive signals from other chips or devices. The above-mentioned sending unit is an interface circuit of the device, which is used to send signals to other devices. For example, when the device is implemented as a chip, the sending unit is the interface circuit of the chip used to send signals to other chips or devices.
[0294] As another possible product form, the terminal device or access network device or core network device of the embodiment of the present application can be implemented by a general bus architecture. For ease of explanation, refer to Figure 13, which is a structural diagram of a communication device 1300 provided in an embodiment of the present application, and the communication device 1300 includes a processor 1301 and a transceiver 1302. The communication device 1300 can be a terminal device, or a chip or chip system therein; or, the communication device 1300 can be an access network device, or a chip or module therein; or, the communication device 1300 can be a core network device, or a chip or module therein. Figure 13 only shows the main components of the communication device 1300. In addition to the processor 1301 and the transceiver 1302, the communication device 1300 can further include a memory 1303, and an input and output device (not shown in the figure).
[0295] Optionally, processor 1301 is primarily used to process communication protocols and communication data, as well as control the entire communication device, execute software programs, and process software program data. Memory 1303 is primarily used to store software programs and data. Transceiver 1302 may include a radio frequency circuit and an antenna. The radio frequency circuit is primarily used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is primarily used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as a touch screen, display, and keyboard, are primarily used to receive user input and output data to the user.
[0296] Optionally, the processor 1301 , the transceiver 1302 , and the memory 1303 may be connected via a communication bus.
[0297] When the communication device is powered on, the processor 1301 can read the software program in the memory 1303, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent wirelessly, the processor 1301 performs baseband processing on the data to be sent and outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then transmits the radio frequency signal to the outside in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1301. The processor 1301 converts the baseband signal into data and processes the data.
[0298] In another implementation, the RF circuit and antenna can be set independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna can be arranged remotely from the communication device.
[0299] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the communication device 1200 may take the form of the communication device 1300 shown in FIG. 13 .
[0300] As an example, the functions / implementation process of the processing unit 1210 in FIG12 may be implemented by the processor 1301 in the communication device 1300 shown in FIG13 calling computer-executable instructions stored in the memory 1303. The functions / implementation process of the communication unit 1220 in FIG12 may be implemented by the transceiver 1302 in the communication device 1300 shown in FIG13.
[0301] As another possible product form, the terminal device, access network device, or core network device in this application may adopt the structure shown in Figure 14, or include the components shown in Figure 14. Figure 14 is a schematic diagram of the structure of a communication device 1400 provided in this application.
[0302] As shown in FIG14 , a communication device 1400 includes at least one processor 1401. Optionally, the communication device further includes a communication interface 1402.
[0303] When the program instructions are executed in the at least one processor 1401, the apparatus 1400 may implement the method provided in any of the aforementioned embodiments and any possible designs thereof. Alternatively, the processor 1401 may implement the method provided in any of the aforementioned embodiments and any possible designs thereof through logic circuits or by executing code instructions.
[0304] The communication interface 1402 may be used to receive program instructions and transmit them to the processor. Alternatively, the communication interface 1402 may be used for communication between the communication device 1400 and other communication devices, such as exchanging control signaling and / or service data. Exemplarily, the communication interface 1402 may be used to receive signals from devices other than the communication device 1400 and transmit them to the processor 1401, or to send signals from the processor 1401 to communication devices other than the communication device 1400.
[0305] Optionally, the communication interface 1402 may be a code and / or data read / write interface circuit, or the communication interface 1402 may be a signal transmission interface circuit between a communication processor and a transceiver, or a pin of a chip.
[0306] Optionally, the communication device 1400 may further include at least one memory 1403, which may be used to store required program instructions and / or data. It should be noted that the memory 1403 may exist independently of the processor 1401 or may be integrated with the processor 1401. The memory 1403 may be located within or outside the communication device 1400, without limitation.
[0307] Optionally, the communication device 1400 may further include a power supply circuit 1404, which may be used to supply power to the processor 1401. The power supply circuit 1404 may be located in the same chip as the processor 1401, or in another chip other than the chip where the processor 1401 is located.
[0308] Optionally, the communication device 1400 may further include a bus, and various parts of the communication device 1400 may be interconnected via the bus.
[0309] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the communication device 1200 shown in FIG. 12 may take the form of the communication device 1400 shown in FIG. 14 .
[0310] As an example, the functions / implementation process of the processing unit 1210 in FIG12 may be implemented by the processor 1401 in the communication device 1400 shown in FIG14 calling computer-executable instructions stored in the memory 1403. The functions / implementation process of the communication unit 1220 in FIG12 may be implemented by the communication interface 1402 in the communication device 1400 shown in FIG14.
[0311] It should be noted that the structure shown in Figure 14 does not constitute a specific limitation on the terminal device, access network device, or core network device. For example, in other embodiments of the present application, the terminal device, access network device, or core network device may include more or fewer components than shown, or combine or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0312] When the communication device is a chip used in a terminal, the terminal chip implements the functions of the terminal in the above method embodiments. The terminal chip receives information from other modules in the terminal (such as a radio frequency module or antenna), and the information is sent by the base station to the terminal; or the terminal chip sends information to other modules in the terminal (such as a radio frequency module or antenna), and the information is sent by the terminal to the base station.
[0313] When the above-mentioned communication device is a module applied to a base station, the base station module implements the functions of the base station in the above-mentioned method embodiment. The base station module receives information from other modules in the base station (such as a radio frequency module or an antenna), and the information is sent by the terminal to the base station; or the base station module sends information to other modules in the base station (such as a radio frequency module or an antenna), and the information is sent by the base station to the terminal. The base station module here can be the baseband chip of the base station, or it can be a DU or other module. The DU here can be a DU under the open radio access network (O-RAN) architecture.
[0314] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0315] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also exist in a base station or a terminal as discrete components.
[0316] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0317] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0318] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) that contain computer-usable program code.
[0319] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0320] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0321] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A data transmission method, characterized in that: include: receiving at least one of first information and second information; The second information is included in the selection signaling or the paging signaling; determining third information according to at least one of the first information and the second information; Sending the third information and uplink data; The third information is used to authenticate the uplink data.
2. The method according to claim 1, characterized in that The first information is a first random number, or the first information is an identifier of a cell of the access network device, or the first information is determined according to the identifier of the cell.
3. The method according to claim 1 or 2, characterized in that: The first information is configured according to the granularity of the cell, and the first information corresponding to different cells is different.
4. The method according to any one of claims 1 to 3, characterized in that: The second information is a second random number.
5. The method according to any one of claims 1 to 4, characterized in that: The second information is valid within the inventory service process corresponding to the uplink data.
6. The method according to any one of claims 1 to 5, characterized in that: The second information is configured according to the granularity of the access network device, and different access network devices correspond to different second information.
7. The method according to any one of claims 1 to 6, characterized in that: The first information is included in selection signaling or query signaling or query repetition signaling.
8. A data transmission method, characterized in that: include: receiving third information and uplink data from a terminal device; Receiving at least one of the first information and the second information from the terminal device or the access network device; The first information is configured for the access network device; the second information is configured for the core network device; Determine fourth information according to at least one of the first information and the second information, and if the fourth information matches the third information, save the uplink data.
9. The method according to claim 8, characterized in that The method further comprises: If the fourth information does not match the third information, the uplink data is discarded, and / or, fifth information is sent to the terminal device, where the fifth information indicates that the uplink data is invalid.
10. The method according to claim 8 or 9, characterized in that: Before saving the uplink data, the method further includes: Determining that the third information and the uplink data are received for the first time; Alternatively, it is determined that the third information and the uplink data are received for the first time within a preset time period.
11. The method according to any one of claims 8 to 10, characterized in that: The first information is a first random number, or the first information is an identifier of a cell of the access network device, or the first information is determined according to the identifier of the cell.
12. The method according to claim 11, characterized in that The first information is valid within the cell where the terminal device is located.
13. The method according to any one of claims 8 to 12, characterized in that: The second information is a second random number.
14. The method according to any one of claims 8 to 13, characterized in that: The second information is valid within the inventory service process corresponding to the uplink data.
15. The method according to any one of claims 8 to 14, characterized in that: The second information is configured according to the granularity of the access network device, and different access network devices correspond to different second information.
16. The method according to any one of claims 8 to 15, characterized in that: The terminal device is an environmental Internet of Things terminal.
17. A data transmission method, characterized in that: include: Sending at least one of the first information and the second information to the terminal device; The first information is configured by the access network device; The second information is configured by the core network device; Receiving third information and uplink data from the terminal device, and sending the third information and the uplink data to a core network device; The third information is determined according to at least one of the first information and the second information, and the third information is used to authenticate the uplink data.
18. A data transmission method, characterized in that: include: Receiving a first signaling from the access network device; The first signaling is a query duplication signaling or a contention resolution message; Sending third information and uplink data to the access network device; The third information is used to authenticate the uplink data, the third information is determined according to the first information, and the first information is determined according to the first signaling.
19. The method according to claim 18, characterized in that The first information is determined according to the first signaling, including: The first information is the number of transmissions of the first signaling; Alternatively, the first information is a time unit index included in the first signaling; Alternatively, the first information is a random number included in the first signaling.
20. A data transmission method, characterized in that: include: Sending a first signaling; The first signaling is a query duplication signaling or a contention resolution message; receiving third information and uplink data from a terminal device; The third information is used to authenticate the uplink data, the third information is determined according to the first information, and the first information is determined according to the first signaling; The third information and the uplink data are sent to a core network device.
21. The method according to claim 20, characterized in that The first information is determined according to the first signaling, including: The first information is the number of transmissions of the first signaling; Alternatively, the first information is a time unit index included in the first signaling; Alternatively, the first information is a random number included in the first signaling.
22. A data transmission method, characterized in that: include: receiving third information and uplink data; The third information is used to authenticate the uplink data; receiving first information from an access network device, and determining fourth information according to the first information; If the fourth information matches the third information, the uplink data is saved.
23. A communication device, characterized in that: include: A communication unit, configured to receive at least one of the first information and the second information; The second information is included in the selection signaling or the paging signaling; a processing unit, configured to determine third information according to at least one of the first information and the second information; The communication unit is used to send the third information and uplink data; The third information is used to authenticate the uplink data.
24. A communication device, characterized in that: include: A communication unit, configured to receive third information and uplink data from a terminal device; Receiving at least one of the first information and the second information from the terminal device or the access network device; The first information is configured for the access network device; the second information is configured for the core network device; A processing unit is used to determine fourth information based on at least one of the first information and the second information, and if the fourth information matches the third information, save the uplink data.
25. A communication device, characterized in that: include: a processing unit, configured to send at least one of the first information and the second information to the terminal device through the communication unit; The first information is configured by the access network device; the second information is configured by the core network device; The processing unit is configured to receive the third information and the uplink data from the terminal device through the communication unit, and send the third information and the uplink data to the core network device; The third information is determined according to at least one of the first information and the second information, and the third information is used to authenticate the uplink data.
26. A communication device, characterized in that: include: A processing unit, configured to receive a first signaling from the access network device through a communication unit; The first signaling is a query duplication signaling or a contention resolution message; The processing unit is configured to send third information and uplink data to the access network device through the communication unit; The third information is used to authenticate the uplink data, the third information is determined according to the first information, and the first information is determined according to the first signaling.
27. A communication device, characterized in that: include: A processing unit, configured to send a first signaling through a communication unit; The first signaling is a query duplication signaling or a contention resolution message; The processing unit is configured to receive third information and uplink data from the terminal device through the communication unit; The third information is used to authenticate the uplink data, the third information is determined according to the first information, and the first information is determined according to the first signaling; The third information and the uplink data are sent to a core network device.
28. A communication device, characterized in that: include: A communication unit, configured to receive third information and uplink data; The third information is used to authenticate the uplink data; receiving first information from an access network device, and determining fourth information according to the first information; A processing unit is used to save the uplink data when the fourth information matches the third information.
29. A communication device, characterized in that: including a processor and a memory; The processor is used to execute the computer program or instructions stored in the memory, so that the communication device implements the method described in any one of claims 1 to 22.
30. A computer-readable storage medium, characterized in that: A computer program or instruction is stored, and when the computer program or instruction is executed on a computer, the computer is caused to implement the method according to any one of claims 1 to 22.
31. A chip, characterized in that: It includes a processor, which is coupled to a memory and is used to execute a computer program or instruction stored in the memory, so that the chip implements the method described in any one of claims 1 to 22.
Citation Information
Patent Citations
Communication method and device
CN115175189A
Communication method and communication device
CN116743212A
Information transmission method and device
CN116897355A
Security Parameter Negotiation in a Wireless Communication System
US20210409952A1