Communication method, and apparatus
By adding specific information of the environmental IoT terminal in the core network equipment, the difficulty of selecting the appropriate network element to perform the security authentication process is solved, and reliable access and efficient security authentication of the IoT terminal are achieved.
Patent Information
- Application Number
- PCT/CN2024/135718
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-15
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-19
AI Technical Summary
In the field of IoT, due to its low power consumption and low complexity, the authentication process of environmental IoT terminals is inconsistent with ordinary 3GPP user equipment, which makes it difficult to select a suitable network element to perform the security authentication process.
By adding new capability information of environmental IoT devices, service requester information or device type information to the core network equipment, the mobile management device can select appropriate authentication service equipment based on the characteristics of the terminal equipment and execute security processes.
It effectively avoids the failure of terminal equipment authentication, ensures that the Internet of Things terminals can access the network, and improves the reliability and security of communication.
Smart Images

Figure CN2024135718_19062025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 15, 2023, with application number 202311733106.8 and invention name “Communication Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and more particularly, to a communication method and apparatus. Background Art
[0003] In the field of Internet of Things (IoT), the Ambient Energy Internet of Things (AIoT) is an emerging technology field that has attracted much attention. Ambient Energy Internet of Things refers to IoT terminals that do not have a power supply or built-in battery, but instead draw energy from the environment to meet their operating needs.
[0004] Because IoT terminals are low-power, low-complexity devices, their authentication processes and algorithms may not be consistent with those of standard 3GPP user devices. Therefore, lightweight security authentication algorithms and processes may be used to implement security processes for these terminals. However, not all network elements performing security authentication in the network support these new algorithms and processes.
[0005] Therefore, how to select appropriate network elements to execute the security authentication process of IoT terminals is an urgent problem that needs to be solved. Summary of the Invention
[0006] The present application provides a communication method and apparatus, which adds capability information, service requester information, or device type information corresponding to the environmental IoT device in the execution of network element selection and network element configuration information, enabling the core network device to select the appropriate network element to execute the security process based on the service request or the characteristics and capabilities of the IoT terminal, thereby avoiding the terminal device from being unable to access the network due to authentication failure.
[0007] In a first aspect, a communication method is provided, which includes a mobile management device obtaining a first message, the first message including identification information of a terminal device, the first message indicating a device type of the terminal device, and the terminal device accessing a network using Internet of Things access technology; the mobile management device selecting an authentication service device based on the first message, the authentication service device supporting authentication and / or authorization of terminal devices accessing the network using Internet of Things access technology; the mobile management device sending a first authentication request message to the authentication service device, the first authentication request message including identification information of the terminal device, the first authentication request message being used to request authentication and / or authorization of the terminal device.
[0008] By indicating to a mobile management device such as an AMF network element that the terminal device is an environmental IoT device, the AMF can select a network element that can support the execution of a security authentication process or algorithm for the IoT device for authentication and certification.
[0009] According to the solution of this application, by adding device type information of environmental IoT devices, the core network can optimize and adapt the network function selection for the access process of the IoT terminal, enabling the core network equipment to select appropriate network functions to execute security processes based on business requests or the characteristics and capabilities of the IoT terminal.
[0010] In this application, the Internet of Things can be an environmental Internet of Things, an energy acquisition Internet of Things, an environmental energy acquisition Internet of Things, or a passive Internet of Things.
[0011] In this application, the devices that access the network using the Internet of Things access technology can be devices in the environmental Internet of Things, energy acquisition Internet of Things, environmental energy acquisition Internet of Things, and passive Internet of Things.
[0012] In combination with the first aspect, in certain implementations of the first aspect, the first message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, the mobile management device determines that the terminal device is an Internet of Things device based on the first message, and the mobile management device selects an authentication service device based on the first message, including: the mobile management device determines that the terminal device is an Internet of Things device based on the first message, and selects an authentication service device that supports authentication and / or authentication of the Internet of Things device.
[0013] In a possible implementation, the indication information instructs the terminal device to access the network using an Internet of Things access technology.
[0014] The device type information can further indicate whether the terminal device is an active terminal or a passive terminal. The indication information can come from the reader device, which determines that the terminal device is an IoT device based on the device identification sent by the terminal device and sends the indication information directly to the mobility management device.
[0015] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device sends a first request message to the network storage device based on the first message, where the first request message is used to request the discovery of an authentication service device, and the first request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the mobile management device obtains a first response information from the network storage device, where the first response information includes identification information and / or address information of the authentication service device; the mobile management device selects the authentication service device based on the first response information.
[0016] In combination with the first aspect, in certain implementations of the first aspect, the first response information is determined based on the first request message and the first configuration information of the authentication service device, and the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authorization of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authorization.
[0017] In a possible implementation, the first support information indicates support for authentication and / or authorization of the IoT device.
[0018] In this application, a group identifier can be used to indicate a service requester in a variety of ways. For example, the group identifier can be the identifier of the service requester; another example is that the group identifier can correspond to the identifier of the service requester. A first support group identifier can be used to indicate a first service requester in a variety of ways. For example, the first support group identifier can be the identifier of the first service requester; another example is that the first support group identifier can correspond to the identifier of the first service requester. The authentication service device supports authentication and / or authorization of a terminal device corresponding to the first service requester.
[0019] When an authentication service device, such as an AUSF network element, registers with a network storage device, such as an NRF network element, it may report its ability to support IoT device authentication (or further report its support for authentication of active or passive devices) and / or supported device identification range (e.g., supported fields for indicating the service requester). Thus, the mobile management device may dynamically discover, through the network storage device, an authentication service device that can support the authentication and / or certification process of the terminal device.
[0020] According to the solution of the present application, the core network device can select the AUSF network element based on the NRF discovery mechanism, so that the selected AUSF supports the execution of security procedures for the IoT terminal, avoiding the situation where the selected AUSF does not support the security procedures of the terminal, resulting in authentication failure and inability to access the network.
[0021] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device sends a second request message to the network storage device, the second request message is used to request the discovery of a unified data management device, and the second request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the mobile management device obtains a second response message from the network storage device, the second response information includes the identification information and / or address information of the unified data management device; the mobile management device selects the unified data management device based on the second response message.
[0022] In combination with the first aspect, in certain implementations of the first aspect, the second response information is determined based on the second request information and the second configuration information of the unified data management device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier indicates support for the corresponding second business requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second business requester, the second support information indicates whether management of the contract data of the Internet of Things device is supported, and the second support type information is used to indicate the device type corresponding to the terminal device supported by the unified data management device for managing contract data.
[0023] In a possible implementation, the second support information indicates support for managing subscription data of the IoT device.
[0024] The second support group identifier indicates that the second service requester can be implemented in multiple ways. Exemplarily, the second support group identifier can be the identifier of the second service requester; another example is that the second support group identifier can have a corresponding relationship with the identifier of the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester.
[0025] When a unified data management device, such as a UDM network element, registers with a network storage device, such as an NRF network element, it can report its ability to manage IoT device subscription data (or further report its support for authentication of active or passive devices) and / or supported device identification ranges (e.g., supported fields for indicating the service requester). Thus, a mobile management device can dynamically discover a unified data management device capable of managing the subscription data of a terminal device through the network storage device.
[0026] According to the solution of the present application, the core network device can select the UDM network element based on the NRF discovery mechanism, so that the selected UDM supports the execution of security processes for the IoT terminal, avoiding the situation where the selected UDM does not support the security processes of the terminal, resulting in authentication failure and inability to access the network.
[0027] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects an authentication service device based on the first message and the third configuration information, and the third configuration information includes a correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein the authentication service device information includes the identifier and / or address information of the authentication service device, the first support group identifier corresponds to the first service requester, and the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether the authentication service device supports authentication and / or authentication of the Internet of Things device, and the first support type information indicates the type of device that the authentication service device supports for authentication and / or authentication.
[0028] Mobile management devices such as AMF network elements can locally configure information of authentication service devices such as AUSF network elements that support IoT terminal device authentication and / or authorization processes, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0029] According to the solution of the present application, by configuring information for selecting network elements in mobile management devices such as AMF network elements, the mobile management device is capable of selecting other core network devices that support the security process of IoT terminals. There is no need to dynamically execute requests through NRF between network elements, thereby reducing signaling overhead.
[0030] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device sends a third request message to the unified data management device, the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the mobile management device obtains a third response information from the unified data management device, the third response information includes the identification information and / or address information of the authentication service device; the mobile management device selects the authentication service device based on the first response information.
[0031] In combination with the first aspect, in certain implementations of the first aspect, the third response information is determined based on the third request information and the fourth configuration information, and the fourth configuration information includes a correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication.
[0032] Unified data management devices such as UDM network elements can locally configure information of authentication service devices such as AUSF network elements that support IoT terminal device authentication and / or authentication processes, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0033] According to the solution of the present application, by configuring information for selecting network elements in a unified data management device such as a UDM network element, the mobile management device can select a core network device that supports the IoT terminal security process through the unified data management device. There is no need to dynamically execute requests through NRF between network elements, thereby reducing signaling overhead.
[0034] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects a unified data management device based on the first message and the third configuration information, and the third configuration information includes a correspondence between the unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
[0035] Mobile management devices such as AMF network elements can locally configure information of unified data management devices such as UDM network elements that support IoT terminal device authentication and / or authorization processes, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0036] According to the solution of the present application, by configuring information for selecting network elements in mobile management devices such as AMF network elements, the mobile management device is capable of selecting other core network devices that support the security process of IoT terminals. There is no need to dynamically execute requests through NRF between network elements, thereby reducing signaling overhead.
[0037] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device sends a registration request message to the unified data management device, the registration request message includes identification information of the mobile management device and identification information and / or address information of the authentication service device, and the registration request message indicates the mobile management device and authentication service device of the service terminal device.
[0038] In combination with the first aspect, in some implementations of the first aspect, the mobility management device stores identification information of the authentication service device and / or identification information of the unified data management device.
[0039] According to the solution of the present application, the mobile management device can provide the information of the authentication service device during registration, so that the unified data management device can store the authentication service device information that supports the execution of the IoT terminal security process. In this way, in the event of subsequent mobility, the new mobile management device can obtain the authentication service device information that supports the execution of the security process through the information stored in the unified data management device, saving signaling overhead.
[0040] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device obtains a sixth request message from the network open function, the sixth request message includes network function information, the network function information includes identification information and / or address information of at least one of the following devices: authentication service device, unified data management device, specific network slice authentication function NSAAF and AAA server; the mobile management device selects the authentication service device and / or unified data management device based on the first message and the sixth request message.
[0041] When the security process is executed by the AAA server, the mobility management device discovers the address of the AAA server through a network open function such as an NEF network element.
[0042] In a second aspect, a communication method is provided, which includes an authentication service device receiving a first authentication request message from a mobile management device, the first authentication request message including identification information of a terminal device, the first authentication request message being used to request authentication and / or authorization of the terminal device, and the terminal device accessing a network using Internet of Things access technology.
[0043] In combination with the second aspect, in certain implementations of the second aspect, the first authentication request message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, and the authentication service device determines that the terminal device is an Internet of Things device based on the first authentication request message.
[0044] In combination with the second aspect, in certain implementations of the second aspect, the authentication service device selects a unified data management device based on the first authentication request message, and the unified data management device supports authentication and / or authorization of devices that access the network using Internet of Things access technology; the authentication service device sends a second authentication request message to the unified data management device, and the second authentication request message is used to determine the authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0045] In combination with the second aspect, in certain implementations of the second aspect, the first authentication request message includes terminal device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device, and the second authentication request message includes at least one of the following: identification information, group identification, indication information and device type information, the group identification is included in the identification information, and the group identification indicates the service requester corresponding to the terminal device.
[0046] In combination with the second aspect, in certain implementations of the second aspect, the authentication service device sends first configuration information to the network storage device, and the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first service requester, and the authentication service device supports authentication and / or authorization of the terminal device corresponding to the first service requester, the first support information is used to indicate whether the authentication service device supports authentication and / or authorization of the Internet of Things device, and the first support type information is used to indicate the type of device that the authentication service device supports authentication and / or authorization.
[0047] When an authentication service device, such as an AUSF network element, registers with a network storage device, such as an NRF network element, it may report its ability to support IoT device authentication (or further report its support for authentication of active or passive devices) and / or supported device identification ranges (e.g., supported fields for indicating the service requester). Thus, other devices may dynamically discover authentication service devices that can support the authentication and / or certification process of terminal devices through the network storage device.
[0048] In combination with the second aspect, in certain implementations of the second aspect, the authentication service device sends a fourth request message to the network storage device based on the first authentication request message, the fourth request message is used to request the discovery of a unified data management device, and the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the authentication service device obtains a fourth response information from the network storage device, the fourth response information includes identification information and / or address information of the unified data device; the authentication service device selects the unified data management device based on the fourth response information.
[0049] In combination with the second aspect, in certain implementations of the second aspect, the fourth response information is determined based on the fourth request message and the second configuration information of the unified data management device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device whose contract data the unified data management device supports managing.
[0050] When a unified data management device, such as a UDM network element, registers with a network storage device, such as an NRF network element, it can report its ability to support the management of IoT device subscription data (or further report its support for authentication of active or passive devices) and / or supported device identification ranges (e.g., supported fields for indicating the service requester). Thus, the authentication service device can dynamically discover, through the network storage device, a unified data management device that can support the management of terminal device subscription data.
[0051] In combination with the second aspect, in certain implementations of the second aspect, the authentication service device selects a unified data management device based on the first authentication information and the fifth configuration information, and the fifth configuration information includes a correspondence between the unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract number of Internet of Things devices, and the second support type information is used to indicate the type of terminal device corresponding to the contract data that the unified data management device supports managing.
[0052] Authentication service devices such as AUSF network elements can locally configure information that supports managing the contract data of IoT terminal devices, such as UDM network elements, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0053] In combination with the second aspect, in certain implementations of the second aspect, the authentication service device obtains a second authentication response message from the unified data management device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0054] In combination with the second aspect, in certain implementations of the second aspect, the authentication service device sends a fifth request message to the network storage device, the fifth request message is used to request the discovery of NSSAAF, and the fifth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the authentication service device obtains a fifth response information from the network storage device, the fifth response information includes the identification information and / or address information of the NSSAAF, the identification information and / or address information of the AAA server; the authentication service device selects the NSSAAF based on the fifth response information.
[0055] In combination with the second aspect, in certain implementations of the second aspect, the fifth response information is determined based on the fifth request message and the sixth configuration information of the NSSAAF, and the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information, wherein the third support group identifier corresponds to the third service requester, and the NSSAAF supports authentication and / or authorization of the terminal device corresponding to the third service requester, the third support information indicates whether the NSSAAF supports authentication and / or authentication of the Internet of Things device, and the third support type information is used to indicate the type of device that the NSSAAF supports authentication and / or authorization.
[0056] In one possible implementation, the third support information indicates that the NSSAAF supports authentication and / or authorization of the IoT device.
[0057] The authentication and authorization functions of a specific network slice can locally configure information that supports the authentication and / or authorization process of IoT terminal devices, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc., and send the configuration information to a network storage device such as an NRF network element, thereby obtaining the address of the AAA server through the network storage device, thereby completing the terminal security process.
[0058] In combination with the second aspect, in certain implementations of the second aspect, the first authentication request message includes specific network slice authentication function NSSAAF information and / or AAA server information, and the NSSAAF information indicates the NSSAAF used to perform authentication and / or authentication; the authentication service device sends a third authentication request message to the NSSAAF, and the third authentication request message includes at least one of the following: device identification, indication information, device type information and AAA server information, wherein the indication information indicates that the terminal device is an Internet of Things device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes the identification information and / or address information of the AAA server.
[0059] When the access process of the IoT terminal is triggered by the service requester, the network elements involved in the subsequent process can be determined in advance, for example, by the network open function NEF. In this way, when the AMF receives a registration request (or access request) from the IoT terminal, it can directly select the appropriate network element to execute the process based on the network element information provided by the NEF. This eliminates the need for the entire 5GC to perform enhancements and function upgrades. It only requires the NEF to perform network element selection, reducing the required new configuration.
[0060] According to a third aspect, a communication method is provided, which includes a unified data management device receiving a second authentication request message from an authentication service device, the second authentication request message including at least one of the following: identification information of the terminal device, a group identifier, indication information and device type information, wherein the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the unified data management device determines an authentication method based on the second authentication request message, and the authentication method is used to authenticate and / or authorize the terminal device.
[0061] In combination with the third aspect, in certain implementations of the third aspect, the unified data management device sends second configuration information to the network storage device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
[0062] When a unified data management device, such as a UDM network element, registers with a network storage device, such as an NRF network element, it can report the ability to support IoT device authentication (or further report support for authentication of active devices or passive devices) and / or the supported device identification range (for example, the supported field for indicating the service requester).
[0063] In combination with the third aspect, in certain implementations of the third aspect, the unified data management device receives a third request message from the mobile management device, the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information, and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the unified data management device selects the authentication service device based on the third request information and fourth configuration information, the fourth configuration information includes a correspondence between the authentication service device information and at least one of the following: a first supported group identification, first support information, and first support type information, wherein the first supported group identification corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that supports authentication and / or authentication; the unified data management device sends a third response message to the mobile management device, and the third response information includes identification information and / or address information of the authentication service device.
[0064] In combination with the third aspect, in certain implementations of the third aspect, the unified data management device sends a second authentication response message to the authentication service device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0065] In combination with the third aspect, in certain implementations of the third aspect, the unified data management device receives a registration request message from a mobile management device, the registration request message includes identification information of the mobile management device and identification information and / or address information of the authentication service device, and the registration request message indicates the mobile management device and authentication service device that serve the terminal device.
[0066] In combination with the third aspect, in certain implementations of the third aspect, the unified data management device stores identification information of the authentication service device.
[0067] In a fourth aspect, a communication method is provided, which includes a network open function receiving a service request message from a service requester, the service request message being used to perform service operations on at least one terminal device corresponding to the service requester, the network open function determining network function information based on the service request message, and the network function corresponding to the network function information being used to perform authentication and / or authorization on at least one terminal device; the network open function sends a sixth request message to a mobile management device, the sixth request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: an authentication service device, a unified data management device, a specific network slice authentication and authorization function NSSAAF, and an AAA server.
[0068] In a fifth aspect, a communication method is provided, which includes a terminal device sending a request message to a reader, the terminal device accessing the network using Internet of Things access technology, the request message including identification information and / or device type of the terminal device, and the device type information indicating whether the terminal device is an active terminal or a passive terminal.
[0069] In a sixth aspect, a communication method is provided, which includes a reader receiving a request message from a terminal device, the terminal device accessing a network using Internet of Things access technology, the request message including identification information and / or device type of the terminal device, the device type information indicating whether the terminal device is an active terminal or a passive terminal; the reader sending a first message to a mobile management device, the first message including identification information of the terminal device, the first message indicating the device type of the terminal device, the first message being used to determine an authentication service device, the authentication service device supporting authentication and / or authorization of devices accessing the network using Internet of Things access technology.
[0070] In a seventh aspect, a communication method is provided, the method comprising: a network storage device receives first configuration information from an authentication service device, the first configuration information comprising at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to a first service requester, the authentication service device supports authentication and / or authentication of a terminal device corresponding to the first service requester, the first support information indicates whether the authentication service device supports authentication and / or authentication of an Internet of Things device, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication; the network storage device receives a first request message from a mobile management device, the first request message comprising at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the network storage device discovers the authentication service device based on the first request message and the first configuration information; the network storage device sends a first response information to the mobile management device, the first response information comprising identification information and / or address information of the authentication service device.
[0071] In combination with the seventh aspect, in certain implementations of the seventh aspect, the network storage device receives second configuration information from the unified data management device, the second configuration information including at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier indicates support for the corresponding second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether management of the contract data of the Internet of Things device is supported, and the second support type information is used to indicate the device type corresponding to the terminal device supported by the unified data management device for managing the contract data; the network storage device receives a second request message from the mobile management device, the second request message including at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the network storage device discovers the authentication service device based on the second request message and the second configuration information; the network storage device sends a second response information to the mobile management device, the second response information including the identification information and / or address information of the unified data management device.
[0072] In combination with the seventh aspect, in certain implementations of the seventh aspect, the network storage device receives second configuration information from the unified data management device, the second configuration information including at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier indicates support for the corresponding second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether management of the contract data of the Internet of Things device is supported, and the second support type information is used to indicate the device type corresponding to the terminal device supported by the unified data management device for managing the contract data; the network storage device receives a second request message from the mobile management device, the second request message including at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the network storage device discovers the authentication service device based on the second request message and the second configuration information; the network storage device sends a second response information to the mobile management device, the second response information including the identification information and / or address information of the unified data management device.
[0073] In combination with the seventh aspect, in certain implementations of the seventh aspect, the network storage device receives a fourth request message from the authentication service device, the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the network storage device discovers the authentication service device based on the fourth request message and the second configuration information; the network storage device sends a fourth response information to the authentication service device, and the fourth response information includes the identification information and / or address information of the unified data management device.
[0074] In combination with the seventh aspect, in certain implementations of the seventh aspect, the network storage device receives sixth configuration information from the authentication and authorization function NSSAAF of a specific network slice, and the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information, wherein the third support group identifier corresponds to a third service requester, and NSSAAF supports authentication and / or authorization of the terminal device corresponding to the third service requester, and the third support information indicates whether NSSAAF supports authentication and / or authentication of the Internet of Things device, and the third support type information is used to indicate that NSSAAF supports the device for authentication and / or authorization. Device type; the network storage device receives a fifth request message from the authentication service device, the fifth request message includes at least one of the following: a group identifier, indication information and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the network storage device discovers the authentication service device according to the fifth request message and the sixth configuration information; the network storage device sends a fifth response information to the authentication service device, the fifth response information includes the identification information and / or address information of the NSSAAF, and the identification information and / or address information of the AAA server.
[0075] In an eighth aspect, a communication device is provided, which includes an interface unit for obtaining a first message, the first message including identification information of a terminal device, the first message indicating a device type of the terminal device, and the terminal device accessing the network using Internet of Things access technology; a processing unit for selecting an authentication service device based on the first message, the authentication service device supporting authentication and / or authentication of terminal devices accessing the network using Internet of Things access technology; the interface unit is also used to send a first authentication request message to the authentication service device, the first authentication request message including identification information of the terminal device, and the first authentication request message is used to request authentication and / or authentication of the terminal device.
[0076] In combination with the eighth aspect, in certain implementations of the eighth aspect, the first message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, and the mobile management device determines that the terminal device is an Internet of Things device based on the first message; the processing unit is also used to determine that the terminal device is an Internet of Things device based on the first message, and select an authentication service device that supports authentication and / or authorization of the Internet of Things device.
[0077] In combination with the eighth aspect, in certain implementations of the eighth aspect, the interface unit is used to send a first request message to the network storage device based on the first message, where the first request message is used to request the discovery of an authentication service device, and the first request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit is also used to obtain first response information from the network storage device, the first response information includes identification information and / or address information of the authentication service device; the processing unit is used to select an authentication service device based on the first response information.
[0078] In combination with the eighth aspect, in certain implementations of the eighth aspect, the first response information is determined based on the first request message and the first configuration information of the authentication service device, and the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authorization of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authorization.
[0079] In combination with the eighth aspect, in certain implementations of the eighth aspect, the interface unit is used to send a second request message to the network storage device, the second request message is used to request the discovery of a unified data management device, and the second request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit is used to obtain a second response message from the network storage device, the second response information includes identification information and / or address information of the unified data management device; the processing unit is used to select the unified data management device based on the second response message.
[0080] In combination with the eighth aspect, in certain implementations of the eighth aspect, the second response information is determined based on the second request information and the second configuration information of the unified data management device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier indicates support for the corresponding second business requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second business requester, the second support information indicates whether management of the contract data of the Internet of Things device is supported, and the second support type information is used to indicate the device type corresponding to the terminal device supported by the unified data management device for managing contract data.
[0081] In combination with the eighth aspect, in certain implementations of the eighth aspect, the processing unit is used to select an authentication service device based on the first message and the third configuration information, the third configuration information includes the correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein the authentication service device information includes the identifier and / or address information of the authentication service device, the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication.
[0082] In combination with the eighth aspect, in certain implementations of the eighth aspect, the interface unit is used to send a third request message to the unified data management device, the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the interface unit is also used to obtain third response information from the unified data management device, the third response information includes identification information and / or address information of the authentication service device; the processing unit is used to determine the authentication service device based on the third response information.
[0083] In combination with the eighth aspect, in certain implementations of the eighth aspect, the third response information is determined based on the third request information and the fourth configuration information, and the fourth configuration information includes the correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first business requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first business requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication.
[0084] In combination with the eighth aspect, in certain implementations of the eighth aspect, the processing unit is used to determine the unified data management device based on the first message and the third configuration information, the third configuration information includes the correspondence between the unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second business requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second business requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
[0085] In combination with the eighth aspect, in certain implementations of the eighth aspect, the interface unit is used to send a registration request message to the unified data management device, the registration request message including the identification information of the mobile management device and the identification information and / or address information of the authentication service device, the registration request message indicating the mobile management device and the authentication service device of the service terminal device.
[0086] In combination with the eighth aspect, in certain implementations of the eighth aspect, the apparatus further includes a storage unit for storing identification information of the authentication service device and / or identification information of the unified data management device.
[0087] In combination with the eighth aspect, in certain implementations of the eighth aspect, the interface unit is used to obtain a sixth request message from the network open function, the sixth request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following devices: authentication service device, unified data management device, specific network slice authentication function NSAAF and AAA server; the processing unit is used to select the authentication service device and / or unified data management device based on the first message and the sixth request message.
[0088] In the ninth aspect, a communication device is provided, which includes an interface unit for receiving a first authentication request message from a mobile management device, the first authentication request message including identification information of the terminal device, the first authentication request message being used to request authentication and / or authorization of the terminal device, and the terminal device accessing the network using Internet of Things access technology.
[0089] In combination with the ninth aspect, in certain implementations of the ninth aspect, the first authentication request message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device, and the processing unit is used to determine that the terminal device is an Internet of Things device based on the first authentication request message.
[0090] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processing unit is used to select a unified data management device based on the first authentication request message, and the unified data management device supports authentication and / or authorization of devices that access the network using Internet of Things access technology; the interface unit is used to send a second authentication request message to the unified data management device, and the second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authenticate the terminal device.
[0091] In combination with the ninth aspect, in certain implementations of the ninth aspect, the first authentication request message includes terminal device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device, and the second authentication request message includes at least one of the following: identification information, group identification, indication information and device type information, the group identification is included in the identification information, and the group identification indicates the service requester corresponding to the terminal device.
[0092] In combination with the ninth aspect, in certain implementations of the ninth aspect, the interface unit is used to send first configuration information to the network storage device, the first configuration information including at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication.
[0093] In combination with the ninth aspect, in certain implementations of the ninth aspect, the interface unit is used to send a fourth request message to the network storage device based on the first authentication request message, the fourth request message is used to request the discovery of a unified data management device, and the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit is also used to obtain fourth response information from the network storage device, the fourth response information includes identification information and / or address information of the unified data device; the processing unit is used to determine the unified data management device based on the fourth response information.
[0094] In combination with the ninth aspect, in certain implementations of the ninth aspect, the fourth response information is determined based on the fourth request message and the second configuration information of the unified data management device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second business requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second business requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
[0095] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processing unit is used to determine the unified data management device based on the first authentication information and the fifth configuration information, and the fifth configuration information includes the correspondence between the unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device whose contract data the unified data management device supports managing.
[0096] In combination with the ninth aspect, in certain implementations of the ninth aspect, the interface unit is used to obtain a second authentication response message from the unified data management device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0097] In combination with the ninth aspect, in certain implementations of the ninth aspect, the interface unit is used to send a fifth request message to the network storage device, the fifth request message is used to request the discovery of NSSAAF, and the fifth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit is also used to obtain fifth response information from the network storage device, the fifth response information includes the identification information and / or address information of the NSSAAF, the identification information and / or address information of the AAA server; the processing unit is used to determine the NSSAAF based on the fifth response information.
[0098] In combination with the ninth aspect, in certain implementations of the ninth aspect, the fifth response information is determined based on the fifth request message and the sixth configuration information of the NSSAAF, and the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information, wherein the third support group identifier corresponds to the third service requester, and the NSSAAF supports authentication and / or authorization of the terminal device corresponding to the third service requester, the third support information indicates whether the NSSAAF supports authentication and / or authentication of the Internet of Things device, and the third support type information is used to indicate the type of device that the NSSAAF supports authentication and / or authorization.
[0099] In combination with the ninth aspect, in certain implementations of the ninth aspect, the first authentication request message includes specific network slice authentication function NSSAAF information and / or AAA server information, and the NSSAAF information indicates the NSSAAF used to perform authentication and / or authentication; the interface unit is used to send a third authentication request message to the NSSAAF, and the third authentication request message includes at least one of the following: device identification, indication information, device type information and AAA server information, wherein the indication information indicates that the terminal device is an Internet of Things device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes the identification information and / or address information of the AAA server.
[0100] In the tenth aspect, a communication device is provided, which includes an interface unit for receiving a second authentication request message from an authentication service device, the second authentication request message including at least one of the following: identification information, group identification, indication information and device type information of the terminal device, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; a processing unit for determining an authentication method based on the second authentication request message, the authentication method is used to authenticate and / or authenticate the terminal device.
[0101] In combination with the tenth aspect, in certain implementations of the tenth aspect, the interface unit is used to send second configuration information to the network storage device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
[0102] In combination with the tenth aspect, in some implementations of the tenth aspect, the interface unit is used to receive a third request message from the mobile management device, the third request message is used to select the authentication service device, the third request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the processing unit is used to select the authentication service device according to the third request information and the fourth configuration information, and the fourth configuration information The information includes a correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication; an interface unit is used to send a third response information to the mobile management device, and the third response information includes the identification information and / or address information of the authentication service device.
[0103] In combination with the tenth aspect, in certain implementations of the tenth aspect, the interface unit is used to send a second authentication response message to the authentication service device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0104] In combination with the tenth aspect, in certain implementations of the tenth aspect, the interface unit is used to receive a registration request message from a mobile management device, the registration request message including identification information of the mobile management device and identification information and / or address information of the authentication service device, the registration request message indicating the mobile management device and authentication service device serving the terminal device.
[0105] In combination with the tenth aspect, in some implementations of the tenth aspect, the apparatus further includes a storage unit for storing identification information of the authentication service device.
[0106] In the eleventh aspect, a communication device is provided, which includes an interface unit for receiving a service request message from a service requester, the service request message is used to perform service operations on at least one terminal device corresponding to the service requester, and the network open function determines the network function information based on the service request message, and the network function corresponding to the network function information is used to perform authentication and / or authorization on at least one terminal device; the interface unit is also used to send a service request message to a mobile management device, the service request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: authentication service device, unified data management device, specific network slice authentication and authorization function NSSAAF and AAA server.
[0107] In the twelfth aspect, a communication device is provided, which includes an interface unit for sending a request message to a reader. The terminal device accesses the network using Internet of Things access technology. The request message includes identification information and / or device type of the terminal device. The device type information indicates whether the terminal device is an active terminal or a passive terminal.
[0108] In the thirteenth aspect, a communication device is provided, which includes an interface unit for receiving a request message from a terminal device, the terminal device adopts the Internet of Things access technology to access the network, the request message includes the identification information and / or device type of the terminal device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the interface unit is also used to send a first message to a mobile management device, the first message includes the identification information of the terminal device, the first message indicates the device type of the terminal device, and the first message is used to determine an authentication service device, and the authentication service device supports authentication and / or authentication of devices that access the network using the Internet of Things access technology.
[0109] In a fourteenth aspect, a communication device is provided, which includes an interface unit for receiving first configuration information from an authentication service device, the first configuration information including at least one of the following: a first support group identifier, first support information and first support type information, wherein the first support group identifier corresponds to a first service requester, the authentication service device supports authentication and / or authentication of a terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of an Internet of Things device is supported, and the first support type information is used to indicate the type of device supported by the authentication service device for authentication and / or authentication; the interface unit is also used to receive a first request message from a mobile management device, the first request message including at least one of the following: a group identifier, indication information and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; a processing unit is used to discover the authentication service device according to the first request message and the first configuration information; the interface unit is used to send a first response information to the mobile management device, the first response information including identification information and / or address information of the authentication service device.
[0110] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, the interface unit is used to receive second configuration information from the unified data management device, the second configuration information including at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the contract data; the interface unit is also used to receive a second request message from the mobile management device, the second request message including at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit is used to discover the authentication service device based on the second request message and the second configuration information; the interface unit is used to send a second response information to the mobile management device, the second response information including the identification information and / or address information of the unified data management device.
[0111] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, the interface unit is used to receive second configuration information from the unified data management device, the second configuration information including at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the contract data; the interface unit is also used to receive a second request message from the mobile management device, the second request message including at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit is used to discover the authentication service device based on the second request message and the second configuration information; the interface unit is used to send a second response information to the mobile management device, the second response information including the identification information and / or address information of the unified data management device.
[0112] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, the interface unit is used to receive a fourth request message from the authentication service device, the fourth request message including at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit is used to discover the authentication service device based on the fourth request message and the second configuration information; the interface unit is used to send a fourth response information to the authentication service device, the fourth response information including the identification information and / or address information of the unified data management device.
[0113] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, the interface unit is used to receive sixth configuration information of the authentication and authorization function NSSAAF from a specific network slice, and the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information, wherein the third support group identifier corresponds to a third service requester, and the NSSAAF supports authentication and / or authorization of the terminal device corresponding to the third service requester, and the third support information indicates whether the NSSAAF supports authentication and / or authentication of the Internet of Things device, and the third support type information is used to indicate the device that the NSSAAF supports for authentication and / or authentication type; the interface unit is further used to receive a fifth request message from the authentication service device, the fifth request message includes at least one of the following: a group identifier, indication information and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the processing unit is used to discover the authentication service device according to the fifth request message and the sixth configuration information; the interface unit is used to send a fifth response information to the authentication service device, the fifth response information includes the identification information and / or address information of the NSSAAF, the identification information and / or address information of the AAA server.
[0114] In the fifteenth aspect, a communication device is provided. The device can be a core network device or a terminal device, or a component of the core network device or the terminal device (such as a processor, chip, or chip system), or a logical node, logic module, or software that can implement all or part of the functions of the core network device or the terminal device. The device has the function of implementing the above-mentioned first to seventh aspects and various possible implementation methods. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions.
[0115] In one possible design, the device includes: an interface unit, which may be at least one of a transceiver, a receiver, and a transmitter, and the interface unit may include a radio frequency circuit or an antenna. Optionally, the device also includes a processing unit, which may be a processor. Optionally, the device also includes a storage unit, which may be, for example, a memory. When a storage unit is included, the storage unit is used to store programs or instructions. The processing unit is connected to the storage unit, and the processing unit may execute the programs, instructions, or instructions derived from other sources stored in the storage unit, so that the device performs the communication methods of the first to seventh aspects and various possible implementations described above.
[0116] In another possible design, when the device is a chip, the chip includes: an interface unit and a processing unit, and the interface unit can be, for example, an input / output interface, a pin or a circuit on the chip. The processing unit can be, for example, a processor. The processing unit can execute instructions so that the chip in the network device executes the above-mentioned first aspect, second aspect, fourth aspect and fifth aspect and various possible implementation methods. Optionally, the processing unit can execute instructions in a storage unit, and the storage unit can be a storage module in the chip, such as a register, a cache, etc. The storage unit can also be located in the communication device but outside the chip, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0117] In a sixteenth aspect, a communication system is provided, comprising the communication apparatus provided in aspects eight to fourteen. The communication system can implement the communication method provided in aspects one to seven and any possible implementation of aspects one to seven.
[0118] In the seventeenth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is run on a computer, the computer is caused to execute instructions of the method of any possible implementation of the above-mentioned first to seventh aspects or the first to seventh aspects.
[0119] In the eighteenth aspect, a communication device is provided, comprising: a processor, wherein the processor or the processing unit can execute instructions to enable the method of any possible implementation of the above-mentioned first to seventh aspects or the first to seventh aspects to be executed.
[0120] Among them, the processor mentioned above can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the communication method of the first to fifth aspects mentioned above.
[0121] In a possible implementation, the communication device further includes a memory for storing the above-mentioned executable instructions. Optionally, the memory and the processor are integrated together.
[0122] In a possible implementation, the communication device further includes a communication interface for inputting and / or outputting signaling or data.
[0123] In a possible implementation, the communication device is a chip.
[0124] In the nineteenth aspect, a computer program product is provided, which includes a computer program code, which, when the computer program code is run, is used to execute instructions of the method of any possible implementation of the above-mentioned first to seventh aspects or the first to seventh aspects.
[0125] In the twentieth aspect, a chip system is provided, comprising a memory and a processor, wherein the memory is used to store instructions, and the processor is used to call and execute the instructions from the memory, so that the methods in the above-mentioned first to seventh aspects and their possible implementation methods are executed.
[0126] The chip system may include an input circuit or interface for sending information or data, and an output circuit or interface for receiving information or data.
[0127] Specifically, the beneficial effects of other aspects can refer to the beneficial effects described in the first to fourth aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0128] FIG1 is a schematic diagram of a communication system applicable to an embodiment of the present application;
[0129] FIG2 is a schematic diagram of an environmental Internet of Things architecture applicable to an embodiment of the present application;
[0130] FIG3 is a schematic diagram of a protocol stack supported by an IoT terminal provided by the present application;
[0131] FIG4 is a schematic diagram of a user hidden identifier structure provided by the present application;
[0132] FIG5 is a schematic diagram of a process for discovering network elements in the same network provided by the present application;
[0133] FIG6 is a schematic diagram of a registration process provided by this application;
[0134] FIG7 is a schematic diagram of an authentication process provided by the present application;
[0135] FIG8 is a flow chart of a communication method provided in an embodiment of the present application;
[0136] FIG9 is a flow chart of another communication method provided in an embodiment of the present application;
[0137] FIG10 is a flow chart of another communication method provided in an embodiment of the present application;
[0138] FIG11 is a flow chart of another communication method provided in an embodiment of the present application;
[0139] FIG12 is a schematic block diagram of a communication device provided in an embodiment of the present application;
[0140] FIG13 is a schematic block diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0141] The technical solution in this application will be described below with reference to the accompanying drawings.
[0142] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: global system of mobile communication (GSM) system, code division multiple access (CDMA) system, wideband code division multiple access (WCDMA) system, general packet radio service (GPRS), long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), universal mobile telecommunication system (UMTS), world-wide interoperability for microwave access (WiMAX) communication system, fifth generation (5G), sixth generation (6G) system or new radio (NR), and other future communication systems.
[0143] The technical solutions of the embodiments of the present application will be described below with reference to the accompanying drawings.
[0144] Figure 1 is a schematic diagram of a communication system. As shown in Figure 1, the network includes an access and mobility management function (AMF), a network exposure function (NEF), a network repository function (NRF), a unified data management (UDM), radio access network (RAN) equipment, a policy control function (PCF), user equipment (UE), a policy control function (PCF), a user plane function (UPF), a data network (DN), an authentication server function (AUSF), a network slice selection function (NSSF), an authentication, authorization, and accounting server (AAA Server), and a network slice-specific and SNPN authentication and authorization function (NSSAAF), etc.
[0145] It should be understood that FIG1 is merely a schematic descriptive diagram, and the embodiments of the present application do not limit the number and types of network elements (or devices) actually deployed in the network.
[0146] The main functions of the devices shown in Figure 1 are described as follows:
[0147] UE: can be called user equipment (UE), terminal, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent or user device. The UE may also be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a 5G network, or a terminal device in a future-evolved public land mobile network (PLMN) or a non-terrestrial network (NTN), etc. It may also be an end device, a logical entity, an intelligent device, such as a mobile phone, an intelligent terminal, or a communication device such as a server, a gateway, a base station, or a controller, or an Internet of Things (IoT) device, such as a tag, a passive tag, an active tag, a semi-active tag, a sensor, an electricity meter, a water meter, or the like. It may also be an unmanned aerial vehicle (UAV) with communication capabilities. When the terminal is a passive or semi-active terminal or tag, it can receive or send data by harvesting energy. Energy can be obtained through radio, solar energy, light energy, wind energy, water energy, thermal energy, kinetic energy, etc. This application does not limit the method of energy acquisition by passive or semi-active terminals. The embodiments of this application do not limit this. It should be noted that the tags involved in this application can be in the form of tags, or they can also be in any terminal form.
[0148] It should be understood that the UE may be any device that can access a network, and the UE and the access network device may communicate with each other using a certain air interface technology.
[0149] Radio access network equipment (RAN) (also referred to as access network equipment) corresponds to different access networks in 5G, such as wired access, wireless base station access, and other methods. The RAN equipment in this application includes but is not limited to: next-generation base stations (gnodeB, gNB) in 5G, evolved node B (evolved node B, eNB), radio network controller (RNC), node B (node B, NB), base station controller (BSC), base transceiver station (BTS), home base station (for example, home evolved nodeB, or home node B, HNB), base band unit (BBU), transmission point (transmitting and receiving point, TRP), transmission point (transmitting point, TP), mobile switching center, etc.
[0150] Operation requester (or service requester or third party): can be a server or application function. In the embodiment of the present application, the operation requester can be understood as a device that sends an operation instruction, for example, the operation requester can be a server (server) or a P-IoT server or an application function (AF) or other device that sends an operation instruction. The operation requester can correspond to a certain type of user, and this type of user can include an enterprise, a tenant, a third party or a company, without limitation. Among them, the operation requester corresponding to a certain type of user can be understood as the operation requester belonging to this type of user and being managed by this type of user.
[0151] Unified data management (UDM): can also be called unified data management network element, unified data management entity, data management device, unified data management device, where the unified data management network element is used to process terminal device identification, access authentication, registration and mobility management, etc. In the 5G communication system, unified data management can be UDM or unified data management device. In future communication systems, unified data management can also be UDM network element, or it can have other names, which are not limited in the embodiments of this application. The unified data management device can be a core network device. The unified data management device can be a control plane device.
[0152] Policy Control Function (PCF): Also known as policy control network element, policy control function network element, policy control device, or policy control functional entity. It is responsible for policy control functions such as session and traffic-level billing, quality of service (QoS) bandwidth assurance and mobility management, and UE policy decision-making.
[0153] Session management function (SMF): It can also be called session management device. This device can be used to be responsible for session management of user equipment (including session establishment, modification and release), selection and reselection of user plane function network elements, allocation of Internet Protocol (IP) addresses of user equipment, QoS control, etc. For example, in 5G, the session management network element can be a session management function SMF network element. In future communication systems, such as 6G, the session management network element can still be an SMF network element, or have other names, which is not limited in this application. When the session management network element is an SMF network element, the SMF can provide Nsmf services.
[0154] Access and mobility management function (AMF): can also be called access and mobility management function entity, access and mobility management device, access and mobility management network element, access management device, mobility management device. It is a type of core network equipment, mainly used for mobility management and access management, etc. It can be used to implement other functions of the mobility management entity (MME) function except session management, such as lawful interception, or access authorization (or authentication), user equipment registration, mobility management, tracking area update process, reachability detection, selection of session management network element, mobile state transition management and other functions. For example, in 5G, the access and mobility management network element can be the access and mobility management function (AMF) network element. In future communications, such as 6G, the access and mobility management network element can still be the AMF network element, or have other names, which are not limited in this application. When the access and mobility management network element is an AMF network element, the AMF can provide Namf services.
[0155] User plane function (UPF): Also known as user plane equipment, user plane function network element, user plane network element, or user plane functional entity, it is a type of core network equipment. This device is responsible for forwarding and receiving user data from user devices. It receives user data from the data network and transmits it to the user device via the access network element. The UPF network element also receives user data from the user device via the access network element and forwards it to the data network. The transmission resources and scheduling functions provided by the UPF network element to the user device are managed and controlled by the session management function network element.
[0156] Authentication service function (AUSF): It can also be called authentication service function network element, authentication service function entity, authentication service equipment, and authentication equipment. It is mainly used for user authentication and authentication execution, that is, authentication between UE and operator network. After the authentication service function network element receives the authentication request initiated by the contracted user, it can authenticate and / or authorize the contracted user through the authentication information and / or authorization information stored in the unified data management network element, or generate the authentication and / or authorization information of the contracted user through the unified data management network element. The authentication service function network element can feedback the authentication information and / or authorization information to the contracted user. In one possible implementation method, the authentication service function network element can also be co-located with the unified data management network element. In the 5G communication system, the authentication service function network element can be an authentication service function (AUSF) network element. In future communication systems, the unified data management can still be AUSF, or it can have other names, which are not limited in the embodiments of the present application.
[0157] Network repository function (NRF): can also be called network storage device, network storage function network element, network storage function entity). It is mainly used to support service discovery function. A network element discovery request is received from a network element function or service communication proxy (SCP), and the network element discovery request information can be fed back. At the same time, NRF is also responsible for maintaining information about available network functions and the services they support. It can also be understood as a network storage device. Among them, the discovery process is the process by which the required network element function (NF) uses NRF to implement the addressing of a specific NF or a specific service. NRF provides the IP address or fully qualified domain name (FQDN) or unified resource identifier (URI) of the corresponding NF instance or NF service instance. In addition, NRF can also implement the cross-PLMN discovery process by providing a network identifier (such as PLMN ID). In order to realize the addressing discovery of network element functions, each network element needs to be registered in NRF, and some network element functions can be registered in NRF during the first operation. The network storage function device can be a core network device.
[0158] Network Exposure Function (NEF): Also known as network exposure device, network exposure function entity, network exposure function network element, network capability exposure function entity, network capability exposure function device, network capability exposure function network element, network capability exposure device, etc. It is primarily used to support the exposure of capabilities and events, such as securely exposing services and capabilities provided by 3GPP network functions to the outside world.
[0159] User data repository (UDR): Also known as a user database entity, user database network element, or user database device, it is the name for the unified data storage network element in the 5G architecture. The user database primarily includes the following functions: access to subscription data, policy data, application data, and other types of data.
[0160] An authentication, authorization, and accounting server (AAA server): Also known as an authentication and authorization server, authentication and authorization device, authentication device, or authentication, authorization, and accounting device, it is a server program that processes user access requests and provides authentication, authorization, and accounting services. AAA servers typically work in conjunction with network access control systems, gateway servers, databases, and user information directories. The network connection server interface that collaborates with AAA servers is Remote Authentication Dial-In User Service (RADIUS).
[0161] Network slice-specific and SNPN authentication and authorization function: mainly used to support specific network slice authentication and authorization with AAA server or AAA proxy, and to support access to SNPN using credentials from the credential holder (CH), which is authenticated by the AAA server.
[0162] As shown in FIG1 , a terminal device accesses the network through a RAN device.
[0163] The terminal device communicates with the AMF through the N1 interface (abbreviated as N1).
[0164] RAN communicates with AMF through the N2 interface (abbreviated as N2).
[0165] RAN communicates with UPF through the N3 interface (N3 for short).
[0166] The UPF communicates with the UPF through the N9 interface (abbreviated as N9).
[0167] The UPF communicates with the DN through the N6 interface (abbreviated as N6).
[0168] In addition, control plane functions such as AMF, SMF, NEF, NRF, PCF or UDM shown in Figure 1 can also interact using service-based interfaces.
[0169] For example, the service interface provided by AMF to the outside world may be Namf.
[0170] The service interface provided by NSSF to the outside world may be Nnssf.
[0171] The service interface provided by UDM to the outside world may be Nudm.
[0172] The service interface provided by NEF to the outside world may be Nnef.
[0173] The service interface provided by NRF to the outside world may be Nnrf.
[0174] The service interface provided by PCF to the outside world may be Npcf.
[0175] The service interface provided by AF to the outside world may be Naf.
[0176] The service interface provided by AUSF to the outside world may be Nausf.
[0177] The service interface provided by NSSAAF to the outside world may be Nnssaaf.
[0178] The service interface provided by SMF to the outside world may be Nsmf.
[0179] It should be understood that the RAN, SMF, PCF or AF in the embodiments of the present application may also be referred to as a communication device or communication equipment, which may be a general device or a dedicated device, and the present application does not make any specific limitations on this.
[0180] It should also be understood that the above naming is only used to distinguish different functions and does not mean that these devices are independent physical devices. This application does not limit the specific form of the above devices. For example, they can be integrated into the same physical device or they can be different physical devices. In actual deployment, network elements or devices can be co-located. For example, the access and mobility management network element can be co-located with the session management network element; the session management network element can be co-located with the user plane network element. When two network elements are co-located, the interaction between the two network elements provided in the embodiments of the present application becomes the internal operation of the co-located network element or can be omitted.
[0181] It is understandable that the above functions can be network elements in hardware devices, software functions running on dedicated hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (e.g., a cloud platform).
[0182] It should be noted that the naming of each device in Figure 1 (such as PCF, AMF, etc.) is only a name, and the name does not limit the function of the device itself. In 5G networks and other future networks, the above-mentioned devices may also have other names, and this application does not specifically limit this. For example, in a 6G network, some or all of the above-mentioned network elements may use the terminology in 5G, or may be named otherwise, etc., which are uniformly explained here and will not be repeated below.
[0183] It should be noted that the technical solutions of the embodiments of the present application are applicable to 5G networks, as well as 4G, 6G networks, and future communication networks, etc.
[0184] In order to better describe the technical solutions of the embodiments of the present application, the technical terms related to the technical solutions of the embodiments of the present application will be described below.
[0185] 1. Ambient-IoT
[0186] The ambient IoT can also be referred to as the ambient power-enabled ambient IoT or the passive IoT (P-IoT). This refers to the fact that some network nodes (such as terminals or devices) can be passive, semi-passive, or active. Passive and semi-passive terminals can communicate via reflected carrier waves, meaning they rely on an external carrier source. Passive terminals may or may not have energy storage capacitors. If they do not have energy storage capacitors, they must rely on external environmental energy, such as radio frequency energy, for communication. Semi-passive terminals can have power amplifiers, which improves communication range compared to passive terminals. Semi-passive terminals typically have energy storage capacitors that can store environmental energy, such as solar energy or radio frequency energy. Active devices can actively generate carrier waves (or have carrier recovery capabilities), eliminating the need for external carrier sources for communication and thus possessing active communication capabilities. In one possible implementation, they can also have energy storage capacitors and can obtain energy through solar energy, radio frequency, wind energy, hydropower or tidal energy, and there is no restriction on the way of obtaining energy. These nodes are not equipped with or rely on power devices such as batteries, but obtain energy from the environment to support data perception, transmission and distributed computing. The nodes (terminals or devices) can also store the obtained energy. In this application, Ambient IoT can be understood as the environmental Internet of Things.
[0187] The environmental Internet of Things architecture may include terminals (i.e. the nodes or devices mentioned above), readers, and servers (or application functions, AF). The terminal may be in the form of a tag or any other terminal form, such as a sensor, license plate, nameplate, etc., without limitation. The reader may be an access network device, such as a base station, a pole station, a micro base station, a macro station, a relay point (such as an integrated access and backhaul node IAB node), a mobile base station, etc.; the reader may be a terminal device, such as a mobile phone, an IoT device, a handheld reader, etc. The reader performs contactless two-way data communication through wireless radio frequency, and uses wireless radio frequency to read and write to the terminal, thereby achieving the purpose of identifying the target and exchanging data. It works in two ways. One is that when the terminal enters the effective recognition range of the reader, it receives the radio frequency signal emitted by the reader and uses the energy obtained from the induced current to send out the information stored in the chip (corresponding to a passive tag); the other is that the terminal can store some electrical energy through solar energy or other means, so that it can actively send a signal of a certain frequency (this type of terminal can also be called a semi-passive or semi-active terminal). The reader receives and decodes the information and sends it to the central information system for relevant data processing. This technology is widely used in various industries and fields. The following briefly lists two application scenarios:
[0188] (1) Warehouse / Transportation / Supplies: Passive or semi-passive IoT terminals are embedded or attached to goods and stored in warehouses, shopping malls, etc. During the logistics process, the goods-related information is automatically collected by the reader, and the management personnel can quickly query the goods information in the system, reducing the risk of abandonment or theft, and can improve the speed and accuracy of goods delivery, and prevent cross-selling and counterfeiting;
[0189] (2) Fixed asset management: For places with large assets or valuable items, such as libraries, art galleries and museums, complete management procedures or strict protection measures are required. When there are abnormal changes in the storage information of books or valuable items, the administrator will be reminded in the system immediately to deal with the relevant situation.
[0190] (3) Sensor data transmission: The sensor terminal obtains energy from the environment (such as solar energy) and can actively generate a carrier to send information. The reader (or base station) receives the signal and sends the sensor information to the server (through the core network).
[0191] The reader interacts with the tag via radio frequency signals or wireless signals. It should be understood that this application does not limit the name of the reader. The reader can also be named a reading device or other names, that is, it can be understood that the terms reader and reader are interchangeable. The reader here has the functions involved in the reading device in this application, such as the reader having the function of performing the operations described in this application on the terminal (such as the tag) (such as obtaining tag information, inventory operations, read operations, write operations, invalidation operations, or message interaction operations with the tag, etc.), having the function of obtaining billing-related information and / or billing information, and sending billing information to the billing function. In one possible implementation, the reader can send instructions from a server or application function to the tag, or the reader can send messages from the tag to the server or application function. In one possible implementation, the reader can obtain information stored in a specified tag according to the instructions issued by the server. For example, if it is an inventory operation (or it can be called an inventory operation), the reader obtains the tag's identification information; this identification information can be the tag's unique identifier or a temporary identifier. For example, if it is a read operation, the reader reads the data in the tag's storage area. Optionally, in some situations where it is necessary to rewrite the information stored in the tag, the reader may also have a write function. For example, if it is a write operation, the reader will write the data into the storage area of the tag. In addition, the reader can also perform an invalidation operation on the tag. After the invalidation operation is performed, the tag becomes invalid and cannot be used to perform operations such as obtaining tag information, inventory operations, read operations, message interaction operations with the tag, or write operations. In one possible implementation, the inability to obtain tag information when the tag is invalid can be understood as the reader being unable to obtain the tag information of the invalid tag after the tag is invalid. In another possible implementation, the inability to interact with tags when the tag is invalid can be understood as the reader being unable to interact with the invalid tag through messages after the tag is invalid.
[0192] In this application, the reading device can be a terminal device, or an access network device, a pole station, an eNodeB, a gNodeB, an integrated access and backhaul (IAB) node, etc. This application does not limit the form of the reader.
[0193] Figure 2 shows a schematic diagram of the architecture of the environmental Internet of Things. In one possible implementation, the core network device (such as the mobile management device AMF, or a newly added independent core network device, such as the Internet of Things management function, the tag management function (TMF)) can execute the processes related to the environmental Internet of Things business, such as access management, security authentication, data transmission, instruction transmission, tag management and other functions of the Internet of Things terminal. In one possible implementation, the enhanced access management device (such as AMF) can be used to perform Internet of Things terminal management. In another possible implementation, a new function such as the tag management function or the ambient Internet of Things management function (AIoTMF) is added to perform Internet of Things terminal management, and the function can be connected to the access network device, which is equivalent to the access network device having an interface with the function, or can interact with the RAN through the AMF. From the deployment point of view, the function can be co-deployed with the AMF. In this application, the access network device is used as a reader, such as a base station (pole station or macro station) as an example, but this application does not limit the device form of the reader. The base station can also be called a radio access network device (RAN) or an access network device.
[0194] When a server performs an operation on an IoT terminal (e.g., performing an inventory, read, write, locate, or deactivate operation), it may send an operation instruction to the core network. These instructions may include, but are not limited to, obtaining IoT terminal information, performing an inventory operation (also known as an inventory operation), reading operations, writing operations, deactivating operations, and exchanging information with the IoT terminal. Instructions may include regional location information, IoT terminal identification information, and so on. The base station sends an access instruction to the IoT terminal. When the IoT terminal successfully accesses the IoT terminal through random access, the base station sends an instruction to the IoT terminal (the base station may forward the instruction sent by the core network to the IoT terminal). The IoT terminal obtains or sends the corresponding information based on the instruction. For example, when the instruction is an inventory instruction or an inventory operation, the IoT terminal sends its identification information; when the instruction is a read instruction or a read operation, the IoT terminal sends data stored in the tag storage area; when the instruction is a write instruction or a write operation, the IoT terminal stores the data to be written to the IoT terminal, included in the instruction, in the IoT terminal's storage area. The base station sends (or forwards) the information sent by the IoT terminal to the core network; the core network sends this information to the server.
[0195] The way the server sends instructions can be through the control plane channel. As shown in Figure 2, the server sends instructions to the AMF (or other core network devices that have management tags or execute tag instructions or support passive IoT, such as the tag management function TMF; at this time, the server can be an application function (AF), an application server (AS) or an environmental IoT application function (A-IoT AF or P-IoT AF). In one possible implementation method, the P-IoT AF sends instructions to the AMF or TMF through the NEF (as shown in Figure 2). Through the above architecture, after the AMF or TMF obtains the instructions, it parses the instructions from the AF, and the AMF or TMF triggers the access network device (such as RAN) to execute the random access process of the IoT terminal (or tag), and sends instructions to the IoT terminal through the RAN to complete the operation of the IoT terminal.
[0196] The IoT terminal management function (or tag management function) may be, for example, the tag management function TMF of FIG2 , or the IoT terminal management function may be the ambient IoT management function (AIMF) for acquiring ambient energy. The IoT terminal management function is used to execute the transmission of business data of the terminal device or to execute IoT terminal (or tag) management. For example, when the terminal device is a tag, the transmission and / or management of the tag's business data may be executed. This application does not limit the naming of the IoT terminal management function (or tag management function), which may be other names. This core network function can be an access management device that performs tag management, such as the Access and Mobility Management Function (AMF). It can also be the newly added function shown in Figure 2 that performs IoT terminal (e.g., tag) management or IoT data transmission, such as the IoT management function (IMF) or IoT device management function (IDMF), which can be called the ambient IoT management function (AIMF), ambient IoT device management function (AIDMF), passive IoT management function (PIMF), passive IoT device management function (PIDMF), or tag management function (TMF). This newly added function can be connected to the access network device in two ways: direct connection and indirect connection. Direct connection is equivalent to an interface between the access network device and the function, while indirect connection is to perform signaling or data forwarding through the AMF. The access network device / base station acts as a reader / writer to perform IoT terminal operations, such as reading, writing, inventorying, positioning, and invalidation. In this application, unless otherwise specified, IoT management function can be interchanged with IoT management device.
[0197] 2. Schematic diagram of IoT terminal protocol stack
[0198] As shown in Figure 3, in one possible implementation, the protocol stack supported by the IoT terminal may be a control plane protocol stack, which may include, for example, a non-access stratum protocol stack (NAS) for the terminal to interact with the core network, a radio resource control (RRC) protocol for interacting with access network equipment such as the RAN, and MAC and PHY protocol stacks for the link layer and physical layer, respectively, for transmitting data.
[0199] 3. Subscription permanent identifier (SUPI) and subscription concealed identifier (SUCI)
[0200] The terminal device identifiers defined by 3GPP mainly include user permanent identification SUPI, user hidden identification SUCI, generic public subscription identifier (GPSI), globally unique temporary identity (GUTI), 5G-GUTI, 5G temporary mobile subscriber identity (5G-TMSI), 5G system temporary mobile subscriber identity (5G-S-temporary mobile subscriber identity, 5G-S-TMSI), international mobile equipment identity (IMEI), international mobile subscriber identity (IMSI), etc.
[0201] SUPI is a globally unique permanent identification of terminal equipment. It can include:
[0202] (1) International mobile subscriber identity (IMSI).
[0203] (2) The format of the network-specific identifier (NSI) will adopt the format of the network access identifier (NAI), such as username@realm.
[0204] (3) The global cable identifier (GCI) and the operator identifier of the 5GC operator are in NAI format; in this case, it is used to support the fixed network broadband residential gateway (FN-BRG).
[0205] (4) The global line identifier (GLI) and the operator identifier of the 5GC operator are in NAI format; this is used to support fixed network-cable residential gateway (FN-CRG) and 5G-cable residential gateway (5G-CRG).
[0206] For SUPIs that include an NSI, it uses the format of a network access identifier (NAI), such as username@realm, where the realm portion is the same as the realm portion in the NSI.
[0207] SUCI can be understood as the encrypted SUPI. As shown in Figure 4, SUCI can include the following parts:
[0208] (1) SUPI Type: This parameter contains a value from 0 to 7. It is used to identify the type of SUPI encrypted by the SUCI. The SUPI type is defined as follows:
[0209] 0: IMSI;
[0210] 1: Network Specific Identifier (NSI);
[0211] 2: Global Line Identifier (GLI);
[0212] 3: Global Cable Identifier (GCI);
[0213] 4 to 7: Reserved for future use.
[0214] The specific SUPI type used depends on the service type initiated by the terminal. For example, if the terminal is powered off for a long time and then powered on again and initiates initial registration, the SUPI type used is 0 (IMSI).
[0215] 2) Home Network Identifier: This field identifies the subscriber's home network. When the SUPI type is IMSI, the HNI consists of two parts: the Mobile Country Code (MCC) and the Mobile Network Code (MNC). When the SUPI type is NSI, GLI, or GCI, the HNI consists of a variable-length string.
[0216] When the SUPI type is NSI, GLI, or GCI, the home network identifier is a variable-length character string representing a domain name.
[0217] 3) Routing indicator: It is allocated by the home network operator and allows the network signaling carrying SUCI to be sent to the AUSF or UDM in conjunction with the HNI to serve the subscriber.
[0218] 4) Protection scheme identifier: used to identify a null scheme or a non-null scheme; the non-null scheme is defined by the home network (HPLMN).
[0219] 5) Home network public key identifier: If the null protection mechanism is used, this value is also set to 0.
[0220] 6) Scheme Output: Contains a string of variable length, depending on the protection scheme used.
[0221] The SUCI structure shows that it can contain the UE's home network identification information. This identification information is used when the UE performs the registration process. The AMF in the serving PLMN will select the AUSF or UDM network element in the home network to perform the security authentication process for the UE based on the home network identification in the SUCI. This is because only the UE's home network has the UE's subscription data, so the AUSF or UDM in the home network must be selected to perform the security authentication process for the UE.
[0222] Figure 5 is a schematic diagram of the process of NF discovering network elements in the same network through NRF. As shown in Figure 5, the specific steps are as follows:
[0223] S201, the network function service user (NF Service Consumer) sends a network function discovery request message (Nnrf_NFDiscover_Request) to the NRF.
[0224] S202: The NRF authorizes the request message sent in step S201.
[0225] S203: If the NF is found, the response message will include one or more network function instances (NF instances), network function types (NF types), network function instance identifiers (NF instance IDs), and fully qualified domain names (FQDNs) or IP addresses of the network function. If the NF is not found, the failure reason will be fed back, such as 404 not found, indicating that the requested NF cannot be found in the NRF.
[0226] 4. UE Registration
[0227] Figure 6 is a schematic diagram of a UE registration process. Specific details are shown in Figure 6.
[0228] S301: RAN receives registration request information from UE.
[0229] It should be understood that when a UE needs to register with a network, the UE sends a registration request message, which includes a registration type and identification information of the terminal device. Exemplarily, the identification information of the UE may include one or more of the following information: a globally unique temporary identity (GUTI), a SUCI, and a permanent equipment identifier (PEI).
[0230] S302: RAN selects AMF.
[0231] It should be understood that after receiving the registration request information from the UE, the RAN will select an appropriate AMF and send the UE's registration request information to the AMF.
[0232] S303, AMF receives registration request information.
[0233] S304, AMF executes AUSF selection.
[0234] Specifically, the AMF selects an appropriate AUSF for authentication and other security procedures. The AMF selects an AUSF in the same manner as described above. The UE, AMF, AUSF, and UDM interact to complete authentication and other security procedures. For 3GPP UEs, this authentication process is a two-way authentication between the UE and the network.
[0235] S305: Execute authentication or security process.
[0236] It should be understood that the execution process of the above authentication or security process involves the interaction of UE, AMF, AUSF and UDM.
[0237] S306: Obtain the subscription data of the UE.
[0238] After the UE successfully authenticates itself with the core network element, the AMF can interact with the UDM to obtain the subscription data of the terminal device.
[0239] S307: AMF sends N2 information to RAN.
[0240] It should be understood that the N2 information sent by the AMF to the RAN includes non-access stratum (NAS) information, and the NAS information includes registration acceptance information.
[0241] S308: RAN sends a registration acceptance message to the UE.
[0242] After the RAN receives the registration acceptance message from the AMF, it forwards the registration acceptance message to the UE, thus completing the UE registration process.
[0243] Since IoT terminals are low-power and low-complexity terminal devices, specific authentication processes or authentication algorithms are required.
[0244] Based on the above problems, the present application provides a communication method. According to the solution of the present application, the Internet of Things terminal can access the core network to perform the security authentication process, thereby improving the communication reliability.
[0245] Figure 7 is a communication method 400 provided by the present application. The method is explained by taking the authentication service device as AUSF and the mobile management device as AMF as an example. In a possible implementation method, in the present application, the mobile management device can be replaced by a functional device for performing IoT device management or business processing, such as a tag management function (TMF), an ambient IoT function (AIoTF), an ambient IoT management function (AIoTMF), etc. The device name does not limit the function of the device itself. In future communication systems, some or all of the above-mentioned network elements may continue to use these names, or may be other names, which are uniformly explained here. The method may include the following steps:
[0246] S401, AMF obtains the first message.
[0247] The first message includes identification information of the terminal device, the first message indicates the device type of the terminal device, and the terminal device accesses the network using Internet of Things access technology.
[0248] In a possible embodiment, the Internet of Things may be specifically an environmental Internet of Things (e.g., ambient IoT), an environmental energy harvesting Internet of Things (e.g., ambient power-enabled IoT), or a passive Internet of Things (e.g., passive IoT).
[0249] In a possible embodiment, the first message includes device type information, where the device type information indicates that the terminal device is an Internet of Things device, an environmental Internet of Things device, an environmental energy acquisition Internet of Things device, or a passive Internet of Things device.
[0250] In a possible embodiment, the first message includes device type information, where the device type information indicates whether the terminal device is an active terminal or a passive terminal.
[0251] In a possible embodiment, the first message may include indication information, where the indication information indicates that the terminal device is an IoT device, or the indication information indicates that the terminal device uses IoT access technology to access the network, or indicates that the terminal device is a device corresponding to an IoT service. Exemplarily, an IoT service can be understood as an environmental IoT service (e.g., an ambient IoT service), an environmental energy acquisition IoT service (e.g., an ambient power-enabled IoT service), or a passive IoT service (e.g., a passive IoT service). In a possible implementation, the indication information may be access technology type information (e.g., radio access technology type, RAT type).
[0252] S402, AMF selects AUSF according to the first message.
[0253] This step may also include: AMF determines that the terminal device is an IoT device based on the first message.
[0254] In one possible implementation, AMF can indicate that the terminal device is an IoT device through the terminal device identification (e.g., device ID), that is, the format and structure of the identification information.
[0255] In another possible implementation, the AMF determines that the terminal device is an IoT device based on the device type information in the first message. Furthermore, the AMF may determine whether the terminal device is an active device or a passive device based on identification information. For example, the AMF may determine whether the terminal device is an active device or a passive device based on subscription data or configuration information.
[0256] In another possible implementation, the AMF determines that the terminal device is an IoT device based on the indication information in the first message. For example, the AMF may determine that the terminal device is an IoT device based on the access technology type information in the first message, or determine that the terminal device uses an IoT access technology.
[0257] S403, AMF sends a first authentication request message to AUSF.
[0258] The first authentication request message includes identification information of the terminal device, and the first authentication request message is used to request authentication and / or authorization to be performed on the terminal device.
[0259] The first authentication request message includes identification information of the terminal device.
[0260] In a possible embodiment, the first authentication request message may include indication information, the indication information indicating that the terminal device is an Internet of Things device, or the indication information indicating that the terminal device uses Internet of Things access technology to access the network, or the indication information indicating that the terminal device is a terminal device corresponding to an Internet of Things service.
[0261] S404, AUSF performs authentication and / or authorization on the terminal device according to the first message.
[0262] Figure 8 is a communication method 500 provided by the present application. The method is explained by taking the authentication service device as AUSF, the network storage device as NRF, the mobile management device as AMF, and the unified data management device as UDM as an example. The device name does not limit the function of the device itself. The device can be understood as the corresponding function. Unless otherwise specified, the two can be interchangeable. In future communication systems, some or all of the above-mentioned network elements may continue to use these names, or may be other names. They are uniformly explained here, and similar descriptions will not be repeated in the following methods 600-800. The method may include the following steps:
[0263] S501, AUSF sends first configuration information (eg, profile or NF profile) to NRF.
[0264] The first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier indicates a first service requester, and the first support group identifier can also be expressed as a first group identifier, the first group identifier indicates a supported service requester, or the first group identifier can represent that the AUSF supports authentication and / or authorization of the IoT device of the service requester corresponding to the first group identifier, or the first group identifier can represent that the AUSF supports authentication and / or authorization of the IoT device corresponding to the first group identifier. The first support information indicates whether authentication and / or authentication of the IoT device is supported, or the first support information indicates support for authentication and / or authentication of the IoT device. The first support type information can also be expressed as first type information, the first type information is used to indicate the type of device that supports authentication and / or authentication, or the first type information can represent that the AUSF supports authentication and / or authorization of the device type indicated by the first type information.
[0265] Exemplarily, the first configuration information may include one or more of the following information: network function type (NF type), identification information (such as NF instance ID), fully qualified domain name FQDN of the network function, IP address, network identifier (such as PLMN ID or PLMN ID+NID); wherein, the network function type may be indicated as an authentication service function (such as AUSF); the identification information may be the identifier of the authentication service function, the FQDN may be the FQDN of the authentication service function, and the IP address may be the IP address of the authentication service function; the network identifier may be used to indicate the network where the authentication service function is located or the network to which it belongs / serves.
[0266] In a possible implementation, the first configuration information may include indication information (the indication information indicates support for Ambient IoT), one or more supported Owner IDs, and supported device types (eg, active terminals and / or passive terminals).
[0267] The indication information may be used to indicate support for authentication or certification of the Ambient IoT terminal, or may be used to indicate support for an authentication / certification algorithm or process of the Ambient IoT terminal.
[0268] The supported one or more Owner IDs (ie, the first support group identifier) represent support for executing the authentication / authorization process of one or more terminals (IoT terminals) corresponding to the one or more Owner IDs.
[0269] The owner ID can be replaced with a group ID or identification information indicating the service requester. The identification information indicating the service requester can be a service requester ID, a user ID, an enterprise ID, a third party ID, or an owner ID. The service requester ID, user ID, enterprise ID, third party ID, or owner ID is one implementation of the identification information indicating the service requester. In actual application, the identity of the service requester can be indicated by other identifiers. The operation requester, which can be called a service requester or a third party, can be a server, an application function, or other device that instructs the execution of an operation instruction. In the embodiment of the present application, the operation requester can be understood as a device that sends an operation instruction. For example, the operation requester can be a server / Ambient IoT server / Passive IoT server / AF / other device that sends an operation instruction. The operation requester can correspond to a certain type of user, which can include an enterprise, a tenant, a third party, or a company. This application does not limit this. Among them, the operation requester corresponding to a certain type of user can be understood as the operation requester belonging to that type of user and being managed by that type of user.
[0270] The supported device types (e.g., active terminals and / or passive terminals, or one or more of device types A / B / C) can be used to indicate the terminal types that support authentication and / or authorization; or, the supported device types (e.g., active terminals and / or passive terminals, or one or more of device types A / B / C) can be used to indicate support for authentication and / or authorization for the terminal type; or, the supported device types (e.g., active terminals and / or passive terminals, or one or more of device types A / B / C) can be used to indicate support for the authentication / authentication algorithm process corresponding to the terminal type.
[0271] In a possible implementation, the AUSF sends the first configuration information via Nnrf_NFManagement_NFRegister Request or Nnrf_NFManagement_NFUpdate Request.
[0272] S502, the NRF sends result indication information (such as Nnrf_NFManagement_NFRegister Response or Nnrf_NFManagement_NFUpdate Response) to the AUSF.
[0273] Exemplarily, after the NRF successfully obtains the first configuration information, it may send result indication information indicating success to the AUSF.
[0274] S503: The UDM sends second configuration information (eg, profile or NF profile) to the NRF.
[0275] Different from step S501, the network function type NF type is the NF type indicated as UDM, and what is provided is the identification information of the UDM, the fully qualified domain name FQDN of the network function, the IP address, and the network identifier (such as PLMN ID or PLMN ID+NID) instead of the relevant information of AUSF, wherein the network function type can be indicated as unified data management (such as UDM); the identification information can be the identifier of the unified data management, the FQDN can be the FQDN of the unified data management, and the IP address can be the IP address of the unified data management; the network identifier can be used to indicate the network where the unified data management is located or the network to which it belongs / serves.
[0276] The second configuration information includes at least one of the following: a second support group identifier, second support information and second support type information, wherein the second support group identifier indicates the second service requester, and the second support group identifier can also be expressed as a second group identifier, and the second group identifier indicates the service requester supported by the UDM, or the second group identifier can represent that the UDM supports the management of the contract data of the Internet of Things device of the service requester corresponding to the second group identifier, or the second group identifier can represent that the UDM supports the contract data of the Internet of Things device corresponding to the second group identifier; the second support information indicates whether the UDM supports authentication and / or authorization of the Internet of Things device; the second support type information can also be expressed as a second type of information, and the second type of information is used to indicate the type of device that supports authentication and / or authentication, or the first type of information can represent that the AUSF supports authentication and / or authentication for the device type indicated by the second type of information.
[0277] The message providing information may refer to step S501.
[0278] S504: The NRF sends result indication information to the UDM.
[0279] The message providing result indication information may refer to step S502.
[0280] S505: After the terminal device successfully initiates random access, it sends a second message (eg, a registration request message) to the reader (eg, RAN).
[0281] In a possible implementation, the IoT terminal sends an AS message (access stratum message) to the reader / writer, and the AS message includes the second message (eg, registration request message), that is, the second message (eg, registration request message) is a NAS message.
[0282] In one possible implementation, the second message may include a device identifier (e.g., device ID) and device type information, such as device type information indicating an active terminal (e.g., active device) or a passive terminal (e.g., passive device); wherein an active terminal may indicate that the terminal supports active communication and / or energy storage; and a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information may be indicated as device A, device B, or device C. wherein device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting carrier generation or supporting carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring reliance on an external excitation source or an external carrier source for communication. In one possible implementation, the device type information indicates a first type device or a second type device. The first type of device does not support active communication, or the first type of device needs to rely on an external carrier to perform uplink data transmission; the second type of device supports active communication, or the second type of device does not need to rely on an external carrier to perform uplink data transmission. Exemplarily, supporting active communication can be understood as supporting carrier generation or supporting carrier recovery.
[0283] S506: The reader (eg, RAN) selects AMF.
[0284] The RAN determines that the device sending the registration request message is an IoT terminal and selects an appropriate AMF.
[0285] For example, the RAN may determine that the IoT terminal uses the access technology type of Ambient IoT for access, and then select the AMF that supports Ambient IoT.
[0286] S507: RAN sends a first message to AMF.
[0287] The first message may include a second message, the first message includes identification information of the terminal device (for example, the first message includes the second message, and the second message includes identification information of the terminal device), and the first message indicates a device type of the terminal device.
[0288] In one possible embodiment, the RAN may send information indicating that the terminal is an IoT terminal (or an IoT terminal) or an Ambient IoT to the AMF (i.e., the first message includes an indication message); in another possible implementation, the RAN may send access technology type information indicating that the terminal is an Ambient IoT to the AMF. This information can be used by the AMF to determine that the terminal is an IoT terminal (or an IoT terminal) and select an AUSF that supports authentication / authentication of the terminal. Alternatively, the AMF may determine that the terminal is an IoT terminal based on the information sent by the RAN and select an AUSF that supports authentication / authentication of the terminal.
[0289] S508: AMF sends a first request message (e.g., Nnrf_NFDiscovery Request) to NRF.
[0290] The AMF determines that the terminal device is an Ambient IoT device based on the first message and selects an AUSF that supports Ambient IoT device authentication / authorization. The AMF determines that the terminal device is an Ambient IoT device in the following ways:
[0291] Method 1: according to the Ambient IoT indication information or access technology type sent by the RAN, that is, the indication information in the first message (step S507).
[0292] Method 2: Determine whether the device is an Ambient IoT device based on the device type transmitted by the IoT terminal. Exemplarily, the device type can be specifically active or passive, or device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, support for active communication can be understood as support for carrier generation or carrier recovery. In another possible implementation, not supporting active communication can be understood as support for passive communication, or as requiring reliance on an external excitation source or an external carrier source for communication. In one possible implementation, the device type information indicates a first type device or a second type device. A first type device may not support active communication, or may require reliance on an external carrier for uplink data transmission; a second type device may support active communication, or may not require reliance on an external carrier for uplink data transmission. Exemplarily, support for active communication can be understood as support for carrier generation or carrier recovery. Exemplarily, the identification information and device type information in the first message.
[0293] Method 3: Based on the identification information (device ID) sent by the IoT terminal.
[0294] In a possible implementation, the format and structure of the device ID may indicate an Ambient IoT device.
[0295] In another possible implementation, the device ID includes identification information indicating the service requester (e.g., group ID owner ID), and the AMF selects the AUSF based on the owner ID. The group ID indicates the service requester, and the group ID can be the ID of the service requester, or the group ID can correspond to the ID of the service requester.
[0296] In another possible implementation, the device ID includes information indicating the device type of the IoT terminal. For example, the device ID includes a field indicating whether it is an active device or a passive device.
[0297] The first request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal. The group identifier may indicate the service requester, or the group identifier may indicate that the selected AUSF needs to support authentication and / or authorization of the IoT device of the service requester corresponding to the group identifier, or the group identifier may indicate that the selected AUSF needs to support authentication and / or authorization of the IoT device corresponding to the group identifier; the indication information indicates that the selected AUSF needs to support authentication and / or authorization of the IoT device; or the indication information indicates that the selected AUSF needs to support authentication / authentication algorithm flow of the IoT device. An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information indicates device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, support for active communication can be understood as support for carrier generation or support for carrier recovery. In another possible implementation, support for passive communication can be understood as support for passive communication, or can be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0298] In one possible implementation, in this application, a passive terminal can be interchangeable with a passive device, a first type of terminal, device A, or device B; in another possible implementation, in this application, an active terminal can be interchangeable with an active device, a second type of terminal, device C.
[0299] In one possible implementation, the first request message is determined based on the first message; or, the AMF may determine the first request message based on the first message. Exemplarily, the first request message may include one or more of the following information: NF type information indicating AUSF, Owner ID, information indicating Ambient IoT, and device type (for example, active device / passive device); so that the NRF may select the AUSF based on the information.
[0300] S509, NRF sends the first response information to AMF.
[0301] The first response information includes AUSF information. In one possible implementation, the AUSF supports authentication and / or authorization of a terminal device corresponding to a service requester indicated by a group identifier in the first request message, or the AUSF supports authentication and / or authorization of a terminal device indicated as an IoT device by indication information in the first request message, or the AUSF supports authentication and / or authorization of a terminal device indicated as an active terminal or a passive terminal by device type information in the first request message.
[0302] Exemplarily, it may be AUSF identification information (AUSF instance ID), FQDN, IP address, etc.
[0303] S510, AMF sends a first authentication request message to the AUSF fed back in step S509.
[0304] The first authentication request message includes a device ID.
[0305] In one possible embodiment, the first authentication request message may include information indicating Ambient IoT and / or device type information. The information indicating Ambient IoT may be a displayed indication, such as Ambient IoT Indication / Indicator, or may be indicated as Ambient IoT via a message name / message type (e.g., Nausf_AmbientIoT_Authentication Request). The device type information may be displayed device type information, such as an Ambient IoT device, an active terminal (e.g., Active device), or a passive terminal (e.g., Passive device). An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information may be indicated as device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting carrier generation or carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0306] In a possible embodiment, it can be indicated by using some fields in the Device ID.
[0307] In a possible embodiment, the AMF may send the owner ID to the AUSF, or the AUSF may obtain the owner ID based on the device ID.
[0308] In another possible embodiment, the AMF may determine the device type based on the field indicating the device type in the device ID and send the device type information to the AUSF.
[0309] S511, AUSF sends a second request message (eg, Nnrf_NFDiscovery Request) to NRF.
[0310] The second request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal. The group identification can indicate the service requester, or the group identification can represent that the selected UDM needs to support authentication and / or authorization of the IoT device of the service requester corresponding to the group identification, and also needs to support the management of the contract data of the IoT device of the service requester corresponding to the group identification, or the group identification can represent that the selected UDM needs to support authentication and / or authorization of the IoT device corresponding to the group identification, and also needs to support the management of the contract data of the IoT device corresponding to the group identification. The indication information indicates that the selected UDM needs to support authentication and / or authorization of the IoT device, and / or needs to support the management of the contract data of the IoT device; or the indication information indicates that the selected UDM needs to support the authentication / authentication algorithm process of the IoT device, and / or needs to support the process of managing the contract data of the IoT device.
[0311] An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Among them, device A may indicate that the terminal does not support energy storage and / or does not support active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting carrier generation or supporting carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0312] Exemplarily, the second request message may include one or more of the following information: NF type information indicating UDM, Owner ID, information indicating Ambient IoT, and device type (for example, active device / passive device), so that the NRF selects the UDM based on the information.
[0313] The AUSF is identified as an Ambient IoT device, and a UDM that supports Ambient IoT device authentication / authorization is selected. The AUSF is identified as an Ambient IoT device in the following ways:
[0314] Method 1: Determine the device as an IoT device based on the Ambient IoT indication information or access technology type, access type, or device type information sent by the AMF (step S510). The device type can be specifically an active device (e.g., active device) or a passive device (e.g., passive device).
[0315] Method 2: Based on the device ID sent by the IoT terminal.
[0316] In a possible implementation, the format and structure of the device ID may indicate an Ambient IoT device.
[0317] In another possible implementation, the device ID includes identification information indicating the service requester (eg, owner ID), and the AUSF selects the UDM according to the owner ID.
[0318] In another possible implementation, the device ID includes information indicating the device type of the IoT terminal. For example, the device ID includes a field indicating whether it is an active device or a passive device.
[0319] The AUSF may obtain one or more of the following information according to the aforementioned implementation methods: Ambient IoT access technology type / device, device type of active / passive device, Owner ID, etc.
[0320] S512, the NRF sends a second response message to the AUSF.
[0321] The second response information includes UDM information. In one possible implementation, the UDM supports authentication and / or authorization of the terminal device corresponding to the service requester indicated by the group identifier in the second request message, or the UDM supports authentication and / or authorization of the terminal device indicated as an Internet of Things device by the indication information in the second request message, or the UDM supports authentication and / or authorization of the terminal device indicated as an active terminal or a passive terminal by the device type information in the second request message. In another possible implementation, the UDM supports management of the contract data of the terminal device corresponding to the service requester indicated by the group identifier in the second request message, or the UDM supports management of the contract data of the terminal device indicated as an Internet of Things device by the indication information in the second request message, or the UDM supports management of the contract data of the terminal device indicated as an active terminal or a passive terminal by the device type information in the second request message.
[0322] For example, UDM identification information (UDM instance ID), FQDN, IP address, etc.
[0323] S513, the AUSF sends a second authentication request message (eg, Nudm_UEAuthentication_Get Request) to the UDM determined in step S512.
[0324] The second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0325] The second authentication message may include device identification (Device ID), Owner ID, Ambient IoT indication information, device type, etc.
[0326] S514, UDM can obtain the contract data according to the device identification and determine the authentication method according to the contract data.
[0327] In one possible implementation, the contract data stored in the UDM is not at the device granularity, that is, it may be at the service requester granularity (that is, obtaining the contract data based on the owner ID), or at the service type (or access technology type) granularity, that is, obtaining the contract data based on the indication information of the Ambient IoT; or at the device type granularity, that is, obtaining the contract data based on the active / passive device.
[0328] The contract data can also be obtained at a granularity based on a combination of the above information, for example, by the service requester and device type. For example, under the same service requester, different device types correspond to different authentication methods or key information, while terminals of the same device type have the same authentication method, key, and other information. Exemplarily, the contract data can be contextual (mutually interchangeable).
[0329] S515: Execute a security authentication process between the network and the IoT terminal.
[0330] In one possible implementation, the authentication process may be performed between the terminal device, AMF, AUSF, and UDM.
[0331] S516: AMF sends a request message to NRF.
[0332] When the IoT terminal is successfully authenticated, the AMF needs to register itself with the UDM as the AMF serving the IoT terminal.
[0333] AMF discovers UDM through NRF; the discovery method is the same as step S511, except that the network function sending the request is AMF, and the device ID can be the decrypted Device ID, which is not repeated here.
[0334] S517: NRF sends UDM information supporting this capability to AMF, such as UDM identification information (UDM instance ID), FQDN, IP address, etc.
[0335] S518, AMF registers itself with UDM as the AMF serving the IoT terminal.
[0336] The AMF provides the UDM with a globally unique AMF identifier (GUAMI).
[0337] In a possible embodiment, the AMF may send AUSF information to the UDM so that the UDM stores the AUSF information that supports the execution of the IoT terminal security process, so that in the event of subsequent mobility, the new AMF may obtain the AUSF information that supports the execution of the security process through the information stored by the UDM.
[0338] S519, AMF sends a registration acceptance message to the IoT terminal.
[0339] This message may include a temporary identity (5G globally unique temporary identity, 5G-GUTI) allocated by the AMF.
[0340] In a possible embodiment, the method 500 may further include:
[0341] S520, AMF can store the selected AUSF, UDM information in the context, so that when there is a new AMF service IoT terminal in the future, the information can be sent to the target AMF through the context migration or context transmission process, so that the target AMF can select AUSF, UDM according to the information without re-executing the above-mentioned NRF discovery process, saving signaling overhead.
[0342] Method 500 adds capability information, service requester information, or device type information corresponding to the IoT device to the execution of network element selection and network element configuration information, so that the selected network element indicates the security process of the terminal.
[0343] According to the solution of the present application, the core network equipment can select network elements such as AUSF and UDM based on the mechanism discovered by NRF, so that the selected AUSF and UDM support the execution of security processes for the IoT terminal, avoiding the situation where the selected AUSF or UDM does not support the security processes of the terminal, resulting in authentication failure and inability to access the network.
[0344] FIG9 is a communication method 600 provided by the present application. The method may include the following steps:
[0345] S6001, AMF obtains third configuration information, which includes a correspondence between authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier indicates a first service requester, and the first support group identifier can also be expressed as a first group identifier, the first group identifier indicates a supported service requester, or the first group identifier can represent that the AUSF supports authentication and / or authentication of the IoT device of the service requester corresponding to the first group identifier, or the first group identifier can represent that the AUSF supports authentication and / or authentication of the IoT device corresponding to the first group identifier. The first support information indicates whether authentication and / or authentication of the IoT device is supported, or the first support information indicates support for authentication and / or authentication of the IoT device. The first support type information can also be expressed as first type information, the first type information is used to indicate the type of device that supports authentication and / or authentication, or the first type information can represent that the AUSF supports authentication and / or authentication of the device type indicated by the first type information.
[0346] Exemplarily, the AMF is configured with a correspondence between one or more of the following information and AUSF information: (1) information indicating the service requester (e.g., owner ID); (2) support for Ambient IoT device authentication; (3) supported device types, such as active / passive devices. The AUSF information may include an AUSF identifier (e.g., AUSF instance ID), a FQDN, or an IP address.
[0347] In one possible embodiment, the AMF is further configured with a correspondence between one or more of the following information and the UDM information: (1) information indicating the service requester (e.g., owner ID); (2) supported Ambient IoT device authentication; and (3) supported device types, such as active / passive devices. The UDM information may include a UDM identifier (e.g., UDM instance ID), a Fully Qualified Domain Name (FQDN), or an IP address.
[0348] AUSF obtains the fifth configuration information, and the fifth configuration information includes the correspondence between the unified data management device information and at least one of the following items: a second support group identifier, a second support information, and a second support type information, wherein the second support group identifier indicates the second service requester, and the second support group identifier can also be expressed as a second group identifier, and the second group identifier indicates the service requester supported by the UDM, or the second group identifier can represent that the UDM supports the management of the contract data of the Internet of Things device of the service requester corresponding to the second group identifier, or the second group identifier can represent that the UDM supports the contract data of the Internet of Things device corresponding to the second group identifier; the second support information indicates whether the UDM supports authentication and / or authentication of the Internet of Things device; the second support type information can also be expressed as a second type of information, and the second type of information is used to indicate the type of device that supports authentication and / or authentication, or the first type of information can represent that the AUSF supports authentication and / or authentication for the device type indicated by the second type of information.
[0349] For example, AUSF can be configured with one or more of the following information corresponding to UDM information: (1) information indicating the service requester (e.g., owner ID); (2) support for Ambient IoT device authentication; (3) supported device types, such as active / passive devices. UDM information can include a UDM identifier (e.g., UDM instance ID), FQDN, or IP address.
[0350] The UDM obtains the fourth configuration information, and the fourth configuration information includes the correspondence between the authentication service device information and at least one of the following items: a first support group identifier, a first support information, and a first support type information, wherein the first support group identifier indicates the first service requester, and the first support group identifier can also be expressed as a first group identifier, and the first group identifier indicates the supported service requester, or the first group identifier can represent that the AUSF supports the authentication and / or authentication of the IoT device of the service requester corresponding to the first group identifier, or the first group identifier can represent that the AUSF supports the authentication and / or authentication of the IoT device corresponding to the first group identifier. The first support information indicates whether the authentication and / or authentication of the IoT device is supported, or the first support information indicates that the authentication and / or authentication of the IoT device is supported. The first support type information can also be expressed as a first type information, and the first type information is used to indicate the type of device that supports authentication and / or authentication, or the first type information can represent that the AUSF supports the authentication and / or authentication of the device type indicated by the first type information.
[0351] Exemplarily, the UDM may be configured with one or more of the following information corresponding to the AUSF information or UDM information: (1) information indicating the service requester (e.g., owner ID); (2) support for Ambient IoT device authentication; (3) supported device types, such as active / passive device.
[0352] In one possible implementation, the corresponding relationship configured by the UDM is not at the terminal device granularity, and can be used by the AMF to obtain information about the AUSF when it subsequently requests subscription data or configuration information from the UDM (see step 604).
[0353] S601: After the terminal device successfully initiates random access, it sends a registration request message to the RAN.
[0354] S602: RAN determines that the device sending the message is an IoT terminal and selects a suitable AMF.
[0355] S603: RAN sends a registration request message from the IoT terminal to AMF.
[0356] The above steps can refer to the description of S505-S507 in method 500, which will not be repeated here.
[0357] S604, AMF determines that it is an Ambient IoT device and selects AUSF that supports Ambient IoT device authentication / authorization.
[0358] The manner in which the AMF determines that the device is an Ambient IoT device may refer to the description in S508.
[0359] In one possible implementation, the AMF selects the AUSF according to the third configuration information (as described in step S6001).
[0360] Exemplarily, the AMF selects the AUSF based on the information indicating the service requester (e.g., owner ID) in the identification information of the terminal device (e.g., device ID) and the corresponding relationship in the third configuration information; or selects the AUSF based on information such as the device type, the Ambient IoT access technology type, and the corresponding relationship. The AUSF supports authentication and / or authorization of the terminal device corresponding to the service requester indicated by the group identifier, or the AUSF supports authentication and / or authorization of the terminal device indicated by the indication information as an IoT device, or the AUSF supports authentication and / or authorization of the terminal device indicated by the device type information as an active terminal or a passive terminal.
[0361] In another possible implementation, the AMF obtains a suitable AUSF from the UDM by interacting with the UDM; the AMF sends a third request message to the UDM, the third request message being used to select an authentication service device, the third request message including at least one of the following: identification information, group identification, indication information, and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal. The group identification may indicate the service requester, or the group identification may indicate that the selected AUSF needs to support authentication and / or authorization of the IoT device of the service requester corresponding to the group identification, or the group identification may indicate that the selected AUSF needs to support authentication and / or authorization of the IoT device corresponding to the group identification; the indication information indicates that the selected AUSF needs to support authentication and / or authentication of the IoT device; or the indication information indicates that the selected AUSF needs to support authentication / authentication algorithm procedures for IoT devices. An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or does not support active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, support for active communication may be understood as support for carrier generation or support for carrier recovery. In another possible implementation, not supporting active communication may be understood as support for passive communication, or may be understood as the need to rely on an external excitation source or an external carrier source for communication.
[0362] Exemplarily, AMF sends a request message to UDM, which includes one or more of Device ID (or information indicating the service requester, such as owner ID), Ambient IoT indication information, and device type (for example, it can be specifically active device / passive device); UDM selects a suitable AUSF based on the fourth configuration information (such as the example of step S6001) and the request message sent by AMF, and sends the AUSF information (such as AUSF identifier, FQDN, IP address, etc.) to AMF.
[0363] S605, AMF sends a first authentication request message (e.g., Nausf_UEAuthentication_Authentication Request) to the selected AUSF.
[0364] The first authentication request message includes a device ID.
[0365] In one possible embodiment, the first authentication request message may include information indicating Ambient IoT and / or device type information. The information indicating Ambient IoT may be a displayed indication, such as Ambient IoT Indication / Indicator, or may be indicated as Ambient IoT via a message name / message type (e.g., Nausf_AmbientIoT_Authentication Request). The device type information may be displayed device type information, such as an Ambient IoT device, an active terminal (e.g., Active device), or a passive terminal (e.g., Passive device). An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information may be indicated as device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting carrier generation or carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0366] In a possible embodiment, the AMF may send the owner ID to the AUSF, or the AUSF may obtain the owner ID based on the device ID.
[0367] In another possible implementation, the AMF may determine the device type based on the field indicating the device type in the device ID and send the device type information to the AUSF.
[0368] S606: AUSF determines that the device is an Ambient IoT device and selects a UDM that supports authentication / authorization of Ambient IoT devices or a UDM that supports managing contract data of IoT devices.
[0369] The method for AUSF to determine that it is an Ambient IoT device can refer to the description in S511 and will not be repeated here.
[0370] The AUSF may obtain one or more of the following information in the above-mentioned manners: Ambient IoT access technology type / device, device type for active / passive device, Owner ID, etc. The AUSF selects the UDM according to the fifth configuration information; for example, the AUSF selects the UDM according to the information indicating the service requester in the device ID (such as the owner ID) and the corresponding relationship in the fifth configuration information; or selects the UDM according to the device type, Ambient IoT access technology type and other information and the corresponding relationship.
[0371] S607, the AUSF sends a second authentication request message (eg, Nudm_UEAuthentication_Get Request) to the UDM determined in step S606.
[0372] The second authentication message may include at least one of the following: device identification (Device ID), owner ID, Ambient IoT indication information, device type, etc.
[0373] S608, UDM can obtain contract data according to the device identification and determine the authentication method according to the contract data.
[0374] In another possible implementation, the contract data stored in the UDM is not at the device granularity, that is, it may be at the service requester granularity (that is, obtaining the contract data based on the owner ID), or at the service type (or access technology type) granularity, that is, obtaining the contract data based on the indication information of the Ambient IoT; or at the device type granularity, that is, obtaining the contract data based on the active / passive device; the contract data may also be at a combination of the above information as granularity, for example, obtaining the contract data at the service requester and device type granularity, for example, under the same service requester, different device types have different corresponding authentication methods or key information, while the terminals of the same device type have the same authentication methods, keys and other information. Exemplarily, the contract data may be contextual (mutually replaceable).
[0375] S609: Execute the security authentication process between the network and the IoT terminal.
[0376] In one possible implementation, the authentication process may be performed between the Ambient IoT device, AMF, AUSF, and UDM.
[0377] S610: AMF discovers UDM according to the third configuration information.
[0378] When the IoT terminal is successfully authenticated, the AMF needs to register itself with the UDM as the AMF serving the IoT terminal; the discovery method is as in step S604.
[0379] S611, AMF registers itself with UDM as the AMF serving the IoT terminal.
[0380] AMF provides GUAMI to UDM, and optionally, AUSF information so that UDM stores AUSF information that supports the execution of the IoT terminal security process. In this way, in the event of subsequent mobility, the new AMF can obtain AUSF information that supports the execution of the security process through the information stored by UDM.
[0381] S612, AMF sends a registration acceptance message to the IoT terminal.
[0382] The message may include a temporary identity (5G globally unique temporary identity, 5G-GUTI) allocated by the AMF.
[0383] In a possible embodiment, the method 600 may further include:
[0384] S613, AMF can store the selected AUSF, UDM information in the context, so that when there is a new AMF service IoT terminal in the future, the information can be sent to the target AMF through the context migration or context transmission process, so that the target AMF can select AUSF, UDM according to the information without re-executing the above-mentioned NRF discovery process, saving signaling overhead.
[0385] According to the solution of the present application, information for selecting network elements is configured through AMF, AUSF, and UDM respectively, so that the network element has the ability to select other core network devices that support the Ambient IoT terminal security process, so that network elements do not need to dynamically execute requests through NRF, which can reduce signaling overhead.
[0386] FIG10 is a communication method 700 provided by the present application. The method may include the following steps:
[0387] S7001, AUSF obtains the sixth configuration information, and the sixth configuration information includes at least one of the following: a third support group identifier, third support information and third support type information, wherein the third support group identifier indicates a third service requester, and the third support group identifier can also be expressed as a third group identifier, and the third group identifier indicates a supported service requester, or, the third group identifier can represent that the NSSAAF supports authentication and / or authorization of the Internet of Things device corresponding to the service requester corresponding to the third group identifier, or, the third group identifier can represent that the NSSAAF supports authentication and / or authorization of the Internet of Things device corresponding to the third group identifier, and the third support information indicates whether the NSSAAF supports authentication and / or authentication of the Internet of Things device, and the third support type information can also be expressed as a third type of information, and the third type of information is used to indicate the type of device that supports authentication and / or authorization, or, the third type of information can represent that the NSSAAF supports authentication and / or authorization of the device type indicated by the third type of information.
[0388] Exemplarily, the AUSF is configured with a correspondence between two or more of the following information: (1) information indicating the service requester (e.g., owner ID); (2) AAA server information (e.g., domain name or address); (3) NSSAAF information (e.g., identifier, FQDN, or IP address). AAA server information may include AAA server identifier, FQDN, or IP address; NSSAAF information may include NSSAAF identifier, FQDN, or IP address. NSSAAF may be an NSSAAF that supports interaction with an AAA server or an NSSAA F that supports interaction with a specific AAA server.
[0389] The UDM configuration has a correspondence between two or more of the following information: (1) information indicating the service requester (e.g., owner ID); (2) AAA server information (e.g., domain name or address); (3) NSSAAF information (e.g., identifier, FQDN, or IP address). AAA server information may include AAA server identifier, FQDN, or IP address; NSSAAF information may include NSSAAF identifier, FQDN, or IP address. NSSAAF may be an NSSAAF that supports interaction with an AAA server or an NSSAAF that supports interaction with a specific AAA server.
[0390] The NSSAAF may be configured with a correspondence between two or more of the following information: (1) information indicating the service requester (e.g., owner ID); (2) AAA server information (e.g., domain name or address); (3) NSSAAF information (e.g., identifier, FQDN, or IP address). The AAA server information may include the AAA server identifier, FQDN, or IP address.
[0391] S702: NSSAAF sends sixth configuration information (eg, Nnrf_NFManagement_NFRegister Request or Nnrf_NFManagement_NFUpdate Request) to the NRF.
[0392] The sixth configuration information may include one or more of the following information: network function type (NF type), identification information (such as NF instance ID), FQDN, IP address, network identifier (such as PLMN ID or PLMN ID+NID), wherein the network function type may indicate the authentication and authorization function of a specific network slice (such as NSSAAF); the identification information may be the identifier of NSSAAF, the FQDN may be the FQDN of NSSAAF, and the IP address may be the IP address of NSSAAF; the network identifier may be used to indicate the network where NSSAAF is located or the network to which it belongs / serves.
[0393] In a possible implementation, the sixth configuration information may include information indicating support for Ambient IoT, one or more supported Owner IDs, supported device types (eg, passive devices and / or active devices), and AAA server information.
[0394] The information indicating support for Ambient IoT may be used to indicate support for authentication or certification of the Ambient IoT terminal, or may be used to indicate support for an authentication / certification algorithm or process of the Ambient IoT terminal.
[0395] The supported one or more Owner IDs represent support for executing the authentication / authorization process of one or more terminals (IoT terminals) corresponding to the one or more Owner IDs; wherein the owner ID can be replaced by: identification information indicating the service requester.
[0396] The AAA server information includes the AAA server identifier, domain name (such as FQDN) or IP address.
[0397] S703, the NRF sends result indication information (such as Nnrf_NFManagement_NFRegister Response or Nnrf_NFManagement_NFUpdate Response) to the NSSAAF.
[0398] Exemplarily, when the NRF successfully obtains the information, it may send result indication information indicating success to the NSSAAF.
[0399] S704: After the terminal device successfully initiates random access, it sends a registration request message to the RAN.
[0400] S705: RAN determines that the device sending the message is an IoT terminal and selects a suitable AMF.
[0401] S706: RAN sends a registration request message from the IoT terminal to AMF.
[0402] S707, AMF determines that it is an Ambient IoT device and selects AUSF that supports Ambient IoT device authentication / authorization.
[0403] S708, AMF sends a first authentication request message to the selected AUSF.
[0404] S709: AUSF determines that the device is an Ambient IoT device and selects a UDM that supports Ambient IoT device authentication / authorization.
[0405] S710, AUSF sends a second authentication request message to the UDM determined in step S709.
[0406] S711, UDM can obtain contract data according to the device identification and determine the authentication method according to the contract data.
[0407] The above steps may refer to steps S601-608 in method 600 and will not be repeated here.
[0408] S712, UDM sends a second authentication response message (eg, Nudm_UEAuthentication_Get Response) to AUSF.
[0409] The second authentication response message may include a device identifier (eg, a decrypted identifier) and indication information for authentication to be performed by the AAA server; optionally, it may include NSSAAF information (eg, through which NSSAAFs can interact with the AAA server) and AAA server information.
[0410] S713, AUSF discovers NSSAAF through NRF, and AUSF sends a fifth request message (e.g., Nnrf_NFDiscovery Request) to NRF.
[0411] In one possible implementation, if the response message sent by the UDM in step S712 does not include NSSAAF information, the AUSF discovers the NSSAAF through the NRF. The authentication service device sends a fifth request message to the network storage device, the fifth request message is used to request the discovery of the NSSAAF, the fifth request message is determined based on the first authentication request message, and the fifth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal. The group identifier can indicate the service requester, or the group identifier can indicate that the selected NSSAAF needs to support authentication and / or authorization of the IoT device of the service requester corresponding to the group identifier, or the group identifier can indicate that the selected AUSF needs to support authentication and / or authorization of the IoT device corresponding to the group identifier; the indication information indicates that the selected NSSAAF needs to support authentication and / or authorization of the IoT device; or the indication information indicates that the selected NSSAAF needs to support the authentication / authentication algorithm process of the IoT device. An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Among them, device A may indicate that the terminal does not support energy storage and / or does not support active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting carrier generation or supporting carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0412] Exemplarily, AUSF sends a fifth request message to NRF, which may include one or more of the following information: NF type information indicated as NSSAAF, Owner ID, information indicated as Ambient IoT, and device type (for example, active device / passive device); so that NRF selects NSSAAF based on the information.
[0413] S714, NRF sends fifth response information to AUSF.
[0414] The fifth response information includes at least one of the following: NSSAAF information, AAA server information, etc.; wherein, the NSSAAF information may include an NSSAAF identifier (e.g., NSSAAF Instance ID), an FQDN, and an IP address; the AAA server information may include an AAA server identifier, an FQDN, and an IP address, etc. In one possible implementation, the NSSAAF supports authentication and / or authorization of a terminal device corresponding to a service requester indicated by a group identifier in the fifth request message, or the NSSAAF supports authentication and / or authorization of a terminal device indicated as an IoT device by indication information in the fifth request message, or the NSSAAF supports authentication and / or authorization of a terminal device indicated as an active terminal or a passive terminal by device type information in the fifth request message.
[0415] In another possible implementation, if the response message sent by the UDM in step S712 includes NSSAAF information, the AUSF may interact with the NSSAAF based on the information (ie, steps S713 and S714 may not be executed).
[0416] S715, AUSF sends a third authentication request message (eg, NSSAAF_AIWF_Authentication Request) to NSSAAF.
[0417] In a possible embodiment, the third authentication request message may include a device identifier (eg, a decrypted device ID), Ambient IoT indication information, and a device type (eg, passive / active device); optionally, may include AAA server information.
[0418] In a possible embodiment, the AAA server address may be the second authentication response message sent by UDM in step S712; it may also be configured in AUSF, i.e., the information configured in step S7001; AUSF determines the corresponding AAA server address based on NSSAAF information or owner ID information.
[0419] In another possible embodiment, the fifth response message may come from the NRF; the AUSF sends the AAA server information to the NSSAAF.
[0420] S716: NSSAAF determines the AAA server address.
[0421] In one possible implementation, if the AUSF does not send the AAA server information to the NSSAAF, the NSSAAF may determine the AAA server according to the sixth configuration information.
[0422] In another possible implementation, if the AUSF sends the AAA server information to the NSSAAF in step S715, the NSSAAF may determine the AAA server information based on the information from the AUSF.
[0423] S717: Execute the security authentication process between the network and the IoT terminal.
[0424] In one possible implementation, the authentication process may be performed between the Ambient IoT device, AMF, AUSF, NSSAAF, and AAA server.
[0425] S718: After the IoT terminal is successfully authenticated, the AMF needs to register itself with the UDM as the AMF serving the IoT terminal.
[0426] The AMF discovers the UDM according to the configuration information; the discovery method can be through local configuration (such as step S606 in method 600) or through NRF discovery (such as steps S516 and S517 in method 500).
[0427] S719, AMF registers itself with UDM as the AMF serving the IoT terminal.
[0428] AMF provides GUAMI to UDM, and optionally, AUSF information so that UDM stores AUSF information that supports the execution of the IoT terminal security process. In this way, in the event of subsequent mobility, the new AMF can obtain AUSF information that supports the execution of the security process through the information stored by UDM.
[0429] S720, AMF sends a registration acceptance message to the IoT terminal.
[0430] The message may include a temporary identifier assigned by the AMF (e.g., 5G globally unique temporary identity, 5G-GUTI); optionally, the AMF may store the selected AUSF and UDM information in the context so that when a new AMF service IoT terminal is subsequently available, the information can be sent to the target AMF through the context migration or context transfer process, so that the target AMF can select AUSF and UDM based on the information without having to re-execute the above-mentioned NRF discovery process, saving signaling overhead.
[0431] When the IoT terminal cannot use the identification format such as username@realm, the address of the AAA server can be obtained according to the configuration information or through NRF to complete the terminal security process.
[0432] According to the solution of the present application, AAA server information can be configured on network elements such as AUSF, UDM or NSSAAF, NRF, so that when the IoT terminal uses a new ID identification, it can interact with the AAA server to complete the security process of the IoT terminal.
[0433] FIG11 is a communication method 800 provided by the present application. The method may include the following steps:
[0434] S801, AUSF can send first configuration information to NRF according to steps S501 and S502 in method 500.
[0435] S802 , the UDM may send second configuration information to the NRF according to steps S503 and S504 in method 500 .
[0436] S803, the NSSAAF may send sixth configuration information to the NRF according to steps S702 and S703 of method 700.
[0437] S804, NEF performs configuration.
[0438] In a possible embodiment, NEF may be configured with a correspondence between the following two or more pieces of information: (1) AF information (which can be understood as the service requester); (2) Device ID; (3) Owner ID (or information indicating the service requester); (4) AMF information; (5) AUSF information; (6) UDM information; (7) NSSAAF information; and (8) AAA server information.
[0439] Among them, AF information may include AF identifier, AF domain name (such as AF's FQDN), AF address information (such as IP address); AMF information may include AMF identifier, AMF domain name (such as AMF's FQDN), AMF address information (such as IP address); AUSF information may include AUSF identifier, AUSF domain name (such as AUSF's FQDN), AUSF address information (such as IP address); UDM information may include UDM identifier, UDM domain name (such as UDM's FQDN), UDM address information (such as IP address); NSSAAF information may include NSSAAF identifier, NSSAAF domain name (such as NSSAAF's FQDN), NSSAAF address information (such as IP address); AAA server information may include AAA server identifier, AAA server domain name (such as AAA server's FQDN), AAA server address information (such as IP address).
[0440] S805: The service requester (eg, AF) sends a service request message (eg, Nnef_AmbientIoT_Service Request) to the NEF.
[0441] The service request message may include AF information (such as AF identifier, AF address or AF FQDN), service type (such as inventory, read, write, deactivation or positioning, etc.), location information (which can be used to determine the reader (such as RAN) to perform the service operation), Device ID (range) (optional parameter. If not carried, it can indicate that the service operation is performed on all IoT terminals belonging to the service requester within a specific range), and AAA server information (optional parameter. It can be carried when the security process is performed by the AAA server).
[0442] S806: NEF performs network function (NF) selection according to the service request sent by AF.
[0443] In one possible implementation, the NEF performs one or more NF selections. For example, the NEF may select the AUSF and UDM corresponding to the AF (service requester) based on the information configured in step S804. If the security process requires execution by an AAA server, the NEF may select the NSSAAF and / or AAA server. If the NEF does not configure the information in step S804, it may discover the NF through the NRF in steps S807 and S808.
[0444] S807: NEF sends a request message to NRF.
[0445] The request message is used to request discovery of at least one network function corresponding to the service requester, and the network function is used to perform a service operation on at least one terminal device.
[0446] The request message may include the type of one or more NFs to be discovered, such as one or more of NSSAAF, AUSF, and UDM. The request message may also include a Device ID (range), Ambient IoT indication information, and a device type (e.g., passive / active device), so that the NRF sends the NF corresponding to the service request to the NEF. The NF type may indicate the type of network element to be discovered that performs service operations on the terminal device; the Device ID indicates the terminal device that performs the service operation; the Ambient IoT indication information indicates that the selected NF must support authentication and / or authorization of the IoT device; or, alternatively, the indication information indicates that the selected NF must support authentication / authentication algorithm procedures for the IoT device. An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information may indicate device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication can be understood as supporting carrier generation or supporting carrier recovery. In another possible implementation, not supporting active communication can be understood as supporting passive communication, or can be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0447] In another possible implementation, when the NEF needs to discover multiple NFs, the NEF may respectively perform step S807 and step S808 multiple times to respectively discover different types of NFs.
[0448] S808: The NRF sends the corresponding NF information to the NEF according to the request message.
[0449] The NF information may include the identifier, FQDN or IP address of the NF.
[0450] In one possible implementation, the NF message may include a network function type (NF type), identification information (such as NF instance ID), a fully qualified domain name FQDN of the network function, an IP address, and a network identifier (such as PLMN ID or PLMN ID+NID). Exemplarily, the network function type may be indicated as an authentication service function (such as AUSF); the identification information may be an identifier of the authentication service function, the FQDN may be the FQDN of the authentication service function, and the IP address may be the IP address of the authentication service function; the network identifier may be used to indicate the network where the authentication service function is located or the network to which it belongs / serves. As another example, the network function type may be indicated as a unified data management function (such as UDM); the identification information may be an identifier of the unified data management function, the FQDN may be the FQDN of the unified data management function, and the IP address may be the IP address of the unified data management function; the network identifier may be used to indicate the network where the unified data management function is located or the network to which it belongs / serves. As another example, the network function type can be indicated as the authentication and authorization function of a specific network slice (e.g., NSSAAF); the identification information can be the identifier of NSSAAF, the FQDN is the FQDN of NSSAAF, and the IP address is the IP address of NSSAAF; the network identifier can be used to indicate the network where NSSAAF is located or the network to which it belongs / serves.
[0451] S809, NEF sends a sixth request message to AMF.
[0452] The sixth request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: authentication service device, unified data management device, specific network slice authentication function NSSAAF and AAA server.
[0453] In one possible implementation, the NEF determines the corresponding AMF based on the location information; the service request message sent to the AMF may include AF information, service type, and location information; optionally, it may include NF information discovered by the NEF in steps S806-S808, such as one or more of AUSF information, UDM information, NSSAAF information, and AAA server information, so that the AMF does not need to perform NF selection after the subsequent IoT terminal is accessed, but is pre-selected by the NEF.
[0454] In one possible implementation, if a function that supports the transmission of IoT services in the execution environment is used to perform service processing (for example, processing service request messages / information from the service requester, executing processes related to IoT services in the execution environment, performing access management, security authentication, data transmission, instruction transmission, or performing IoT terminal management functions of IoT terminals), the NEF can select the network function, and the network function sends a request message to the AMF. In one possible implementation, the function can be connected to the access network device, which is equivalent to the access network device having an interface with the function, or can interact with the RAN through the AMF. From the deployment point of view, the function can be co-deployed with the AMF. If the function can be directly connected to the RAN, step 810 can be replaced by the function sending information to the reader (RAN) indicating the triggering of random access of the IoT terminal.
[0455] S810, AMF sends information to the reader (RAN) indicating triggering random access of the IoT terminal.
[0456] For example, random access indication information is sent to the RAN via an N2 message to trigger the RAN to initiate a random access procedure for the IoT terminal. Optionally, information indicating the range of IoT terminals participating in the random access, such as a MASK, may be included. The MASK indicates the range of identifiers of IoT terminals that need to participate in the random access (which can be understood as an identifier prefix; terminals that match the identifier prefix need to participate in the random access procedure).
[0457] S811, the IoT terminal initiates a random access procedure;
[0458] S812: After the IoT terminal successfully initiates random access, it sends a registration request message to the RAN.
[0459] In a possible implementation, the IoT terminal sends an AS message (access stratum message) to the reader / writer, where the AS message includes the registration request message, that is, the registration request message is a NAS message.
[0460] In one possible implementation, the registration request message may include a device identifier (e.g., device ID) and device type information, such as whether the device is an active device or a passive device. The RAN sends the registration request message from the IoT terminal to the AMF.
[0461] S813, AMF sends a first authentication request message (e.g., Nausf_UEAuthentication_Authentication Request) to the selected AUSF.
[0462] AMF selects AUSF, which supports authentication / authorization of Ambient IoT devices.
[0463] In one possible implementation, if the AMF receives AUSF information from the NEF in step S809, the AMF selects the AUSF based on the information.
[0464] The first authentication request message includes a device ID; optionally, it may include information indicating Ambient IoT and / or device type information. The information indicating Ambient IoT may be a displayed indication, such as Ambient IoT Indication / Indicator, or may be indicated as Ambient IoT via a message name / message type (e.g., Nausf_AmbientIoT_Authentication Request). The device type information may be displayed device type information, such as an Ambient IoT device, an active terminal (e.g., Active device), or a passive terminal (e.g., Passive device). An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information may be indicated as device A, device B, or device C. Device A may indicate that the terminal does not support energy storage and / or active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; and device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting carrier generation or carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring reliance on an external excitation source or an external carrier source for communication.
[0465] In another possible implementation, the AMF may determine the device type based on the field indicating the device type in the device ID and send the device type information to the AUSF. In another possible implementation, if the AMF receives one or more of the UDM, NSSAFF, and AAA server information from the NEF in step S809, the AMF may send one or more of the UDM, NSSAFF, and AAA server information to the AUSF.
[0466] S814, AUSF sends a second authentication request message.
[0467] In one possible implementation, if in step S813, AUSF does not receive NSSAAF information (for example, the security process is executed by AUSF / UDM), then when AUSF determines that it is an Ambient IoT device, it selects a UDM that supports Ambient IoT device authentication / authorization.
[0468] In a possible embodiment, AUSF may discover the UDM through NRF (e.g., steps S511 and S512 of method 500), or AUSF may select the UDM based on configuration information (as described in step S6001 of method 600); for example, AUSF selects the UDM based on information indicating the service requester in the device ID (e.g., owner ID) and the corresponding relationship in the configuration information; or selects the UDM based on information such as the device type, the Ambient IoT access technology type, and the corresponding relationship.
[0469] The AUSF sends a second authentication request message to the UDM, which may include one or more of the following information: Device ID, Ambient IoT indication information, device type, etc.
[0470] In another possible implementation, if the AUSF receives NSSAAF information from the AMF (for example, the security process is performed by the AAA server), the AUSF can directly interact with the NSSAAF to send an authentication request message (for example, Nnssaaf_AIWF_Authentication Request) without interacting with the UDM. When the AUSF receives AAA server information from the AMF, the AUSF can send the AAA server information to the NSSAAF.
[0471] S815: Determine the AAA server address.
[0472] If step S814 is performed by the AUSF sending an authentication request message to the NSSAAF, the NSSAAF can obtain the address information of the AAA server in the following ways:
[0473] Method 1: In step S814, the AAA server information is received from the AUSF.
[0474] Method 2: AAA server information configured in method 700.
[0475] S816: Execute the security authentication process between the network and the IoT terminal.
[0476] In one possible implementation, the authentication process can be performed between the Ambient IoT device, AMF, AUSF, NSSAAF, and AAA server (if the security process requires execution by the AAA server).
[0477] In another possible implementation, the authentication process may be performed between the Ambient IoT device, AMF, AUSF, and UDM.
[0478] S817: AMF selects UDM.
[0479] When the IoT terminal is successfully authenticated, AMF needs to register itself with UDM as the AMF serving the IoT terminal; AMF discovers UDM based on the third configuration information.
[0480] S818, AMF registers itself with UDM as the AMF serving the IoT terminal.
[0481] AMF provides GUAMI to UDM, and optionally, AUSF information so that UDM stores AUSF information that supports the execution of the IoT terminal security process. In this way, in the event of subsequent mobility, the new AMF can obtain AUSF information that supports the execution of the security process through the information stored by UDM.
[0482] S819, AMF sends a registration acceptance message to the IoT terminal, which may include a temporary identifier assigned by the AMF (for example, 5Gglobally unique temporary identity, 5G-GUTI); optionally, the AMF may store the selected AUSF and UDM information in the context, so that when there is a new AMF serving IoT terminal in the future, the information can be sent to the target AMF through the context migration or context transfer process, so that the target AMF can select AUSF and UDM according to the information without re-executing the above-mentioned NRF discovery process, saving signaling overhead.
[0483] S820, AMF can send information (such as identification, stored data, etc.) from one or more IoT terminals to NEF.
[0484] In a possible embodiment, it is sent through a Namf_AmbientIoT_service response message.
[0485] S821, NEF sends information of the IoT terminal (such as identification, stored data, etc.) to AF (service requester).
[0486] In a possible embodiment, it is sent through a Nnef_AmbientIoT_Service response message.
[0487] When the access process of the IoT terminal is triggered by the service requester, the network elements involved in the subsequent process can be determined in advance, for example, by NEF, so that when the AMF receives a registration request (or access request) from the IoT terminal, it can directly select the appropriate network element to execute the process based on the network element information provided by NEF. This eliminates the need for the entire 5GC to perform enhancements and function upgrades. It only requires the NEF to perform network element selection, reducing the required new configuration.
[0488] According to the solution of this application, the core network is enabled to optimize and adapt the NF selection for the access process of the IoT terminal, and the core network equipment is enabled to select the appropriate NF to execute the security process according to the service request or the characteristics and capabilities of the IoT terminal.
[0489] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application; any sequential arrangement that can realize the function of each step should be within the scope of protection of this application.
[0490] It should be understood that the above embodiments may be implemented individually or in combination according to the functions and internal logic of each step in the embodiments.
[0491] According to the aforementioned method, FIG12 is a schematic diagram of a communication device 900 provided in an embodiment of the present application.
[0492] As shown in FIG12 , the apparatus 900 may include modules or units corresponding to the methods / operations / steps / actions described in methods 500 to 800. The modules or units may be implemented as hardware circuits, software, or a combination of hardware circuits and software. In one possible implementation, the apparatus may include an interface unit 910 and a processing unit 920.
[0493] In one possible design, the apparatus 900 may correspond to the mobility management device in the above embodiment.
[0494] In a possible embodiment, the device 900 includes an interface unit 910, which is used to obtain a first message, the first message including identification information of a terminal device, the first message indicating the device type of the terminal device, and the terminal device accessing the network using Internet of Things access technology; a processing unit 920, which is used to select an authentication service device based on the first message, and the authentication service device supports authentication and / or authorization of devices that access the network using Internet of Things access technology; the interface unit 910 is also used to send a first authentication request message to the authentication service device, the first authentication request message including identification information of the terminal device, and the first authentication request message is used to request authentication and / or authorization of the terminal device.
[0495] In one possible implementation, the first message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, and the mobile management device determines that the terminal device is an Internet of Things device based on the first message; the processing unit 920 is also used to determine that the terminal device is an Internet of Things device based on the first message, and select an authentication service device that supports authentication and / or authorization of the Internet of Things device.
[0496] In one possible embodiment, the interface unit 910 is used to send a first request message to the network storage device according to the first message, where the first request message is used to request the discovery of an authentication service device, and the first request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the interface unit 910 is also used to obtain a first response information from the network storage device, where the first response information includes identification information and / or address information of the authentication service device; the processing unit 920 is used to select an authentication service device according to the first response information.
[0497] In one possible implementation, the first response information is determined based on the first request message and the first configuration information of the authentication service device, the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication.
[0498] In one possible embodiment, the interface unit 910 is used to send a second request message to the network storage device, the second request message is used to request the discovery of a unified data management device, and the second request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the interface unit 910 is used to obtain a second response message from the network storage device, the second response information includes identification information and / or address information of the unified data management device; the processing unit 920 is used to determine the unified data management device based on the second response message.
[0499] In one possible embodiment, the second response information is determined based on the second request information and the second configuration information of the unified data management device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier indicates support for the corresponding second business requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second business requester, the second support information indicates whether management of the contract data of the Internet of Things device is supported, and the second support type information is used to indicate the device type corresponding to the terminal device supported by the unified data management device for managing contract data.
[0500] In one possible implementation, the processing unit 920 is used to select an authentication service device based on the first message and third configuration information, the third configuration information includes a correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication.
[0501] In one possible implementation, the interface unit 910 is used to send a third request message to the unified data management device, where the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information, and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the interface unit 910 is also used to obtain third response information from the unified data management device, where the third response information includes identification information and / or address information of the authentication service device; the processing unit 920 is used to select the authentication service device based on the third response information.
[0502] In one possible implementation, the third response information is determined based on the third request information and the fourth configuration information, and the fourth configuration information includes the correspondence between the authentication service device information and at least one of the following items: a first support group identifier, first support information, and first support type information, the second support group identifier corresponds to the second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device whose contract data the unified data management device supports managing.
[0503] In one possible embodiment, the processing unit 920 is used to determine the unified data management device based on the first message and the third configuration information, and the third configuration information includes the correspondence between the unified data management device information and at least one of the following items: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second business requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second business requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device whose contract data the unified data management device supports managing.
[0504] In one possible implementation, the interface unit 910 is used to send a registration request message to the unified data management device, where the registration request message includes identification information of the mobile management device and identification information and / or address information of the authentication service device. The registration request message indicates the mobile management device and authentication service device of the service terminal device.
[0505] In a possible implementation, the apparatus 900 may further include a storage unit 930 configured to store identification information of the authentication service device and / or identification information of the unified data management device.
[0506] In one possible embodiment, the interface unit 910 is used to obtain a sixth request message from the network open function, the sixth request message includes network function information, the network function information includes identification information and / or address information of at least one of the following devices: authentication service device, unified data management device, specific network slice authentication function NSAAF and AAA server; the processing unit 920 is used to select the authentication service device and / or unified data management device according to the first message and the sixth request message.
[0507] In one possible implementation, the first authentication request message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The processing unit 920 is used to determine that the terminal device is an Internet of Things device based on the first authentication request message.
[0508] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the mobility management device in the above-mentioned method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0509] In one possible design, the apparatus 900 may correspond to the authentication service device in the above embodiment.
[0510] In a possible embodiment, the device 900 includes an interface unit 910, which is used to receive a first authentication request message from a mobile management device, the first authentication request message includes identification information of the terminal device, and the first authentication request message is used to request authentication and / or authorization of the terminal device, and the terminal device accesses the network using Internet of Things access technology.
[0511] In one possible implementation, the processing unit 920 is used to determine a unified data management device based on the first authentication request message, and the unified data management device supports authentication and / or authorization of devices that access the network using Internet of Things access technology; the interface unit 910 is used to send a second authentication request message to the unified data management device, and the second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0512] In one possible implementation, the first authentication request message includes terminal device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The second authentication request message includes at least one of the following: identification information, group identification, indication information and device type information, the group identification is included in the identification information, and the group identification indicates the service requester corresponding to the terminal device.
[0513] In one possible implementation, the interface unit 910 is used to send first configuration information to the network storage device, where the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to a first service requester, the authentication service device supports authentication and / or authentication of a terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of an IoT device is supported, and the first support type information is used to indicate the type of devices that the authentication service device supports for authentication and / or authentication.
[0514] In one possible embodiment, the interface unit 910 is used to send a fourth request message to the network storage device based on the first authentication request message, the fourth request message is used to request the discovery of a unified data management device, and the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit 910 is also used to obtain a fourth response information from the network storage device, the fourth response information includes identification information and / or address information of the unified data device; the processing unit 920 is used to determine the unified data management device based on the fourth response information.
[0515] In one possible embodiment, the fourth response information is determined based on the fourth request message and the second configuration information of the unified data management device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device whose contract data the unified data management device supports managing.
[0516] In one possible implementation, the processing unit 920 is used to determine a unified data management device based on the first authentication information and the fifth configuration information, the fifth configuration information including a correspondence between the unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device whose contract data the unified data management device supports managing.
[0517] In one possible embodiment, the interface unit 910 is used to obtain a second authentication response message from the unified data management device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0518] In one possible embodiment, the interface unit 910 is used to send a fifth request message to the network storage device, where the fifth request message is used to request the discovery of NSSAAF, and the fifth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit 910 is also used to obtain fifth response information from the network storage device, where the fifth response information includes identification information and / or address information of the NSSAAF, and identification information and / or address information of the AAA server; the processing unit 920 is used to determine the NSSAAF based on the fifth response information.
[0519] In one possible embodiment, the fifth response information is determined based on the fifth request message and the sixth configuration information of NSSAAF, and the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information, wherein the third support group identifier corresponds to the third service requester, and NSSAAF supports authentication and / or authorization of the terminal device corresponding to the third service requester. The third support information indicates whether NSSAAF supports authentication and / or authentication of IoT devices, and the third support type information is used to indicate the type of device that NSSAAF supports authentication and / or authorization.
[0520] In one possible embodiment, the first authentication request message includes specific network slice authentication function NSSAAF information and / or AAA server information, and the NSSAAF information indicates the NSSAAF used to perform authentication and / or authentication; the interface unit 910 is used to send a third authentication request message to the NSSAAF, and the third authentication request message includes at least one of the following: device identification, indication information, device type information and AAA server information, wherein the indication information indicates that the terminal device is an Internet of Things device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes the identification information and / or address information of the AAA server.
[0521] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the authentication service device in the above-mentioned method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0522] In one possible design, the apparatus 900 may correspond to the unified data management device in the above embodiment.
[0523] In a possible embodiment, the device 900 includes an interface unit 910, which is used to receive a second authentication request message from an authentication service device, the second authentication request message includes at least one of the following: identification information, group identification, indication information and device type information of the terminal device, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; a processing unit 920, which is used to determine an authentication method based on the second authentication request message, and the authentication method is used to authenticate and / or authenticate the terminal device.
[0524] In one possible embodiment, the interface unit 910 is used to send second configuration information to the network storage device, and the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
[0525] In one possible implementation, the interface unit 910 is configured to receive a third request message from the mobile management device, the third request message being used to select an authentication service device, the third request message including at least one of the following: identification information, a group identifier, indication information, and device type information, wherein the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the processing unit 920 is configured to select an authentication service device according to the third request information and the fourth configuration information, the fourth configuration information including The correspondence between the authentication service device information and at least one of the following items: a first support group identifier, first support information and first support type information, wherein the first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of the Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication; the interface unit 910 is used to send a third response information to the mobile management device, and the third response information includes the identification information and / or address information of the authentication service device.
[0526] In one possible embodiment, the interface unit 910 is used to send a second authentication response message to the authentication service device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0527] In one possible implementation, the interface unit 910 is used to receive a registration request message from a mobile management device, where the registration request message includes identification information of the mobile management device and identification information and / or address information of an authentication service device, and the registration request message indicates the mobile management device and authentication service device that serve the terminal device.
[0528] In a possible implementation, the apparatus 900 includes a storage unit 930 configured to store identification information of the authentication service device.
[0529] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the unified data management device in the above-mentioned method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0530] In one possible design, the apparatus 900 may correspond to the network open function device in the above embodiment.
[0531] In a possible embodiment, the device 900 includes an interface unit 910, which is used to receive a service request message from a service requester, the service request message is used to perform service operations on at least one terminal device corresponding to the service requester, and the network open function determines the network function information based on the service request message, and the network function corresponding to the network function information is used to perform authentication and / or authorization on at least one terminal device; the interface unit 910 is also used to send a service request message to a mobile management device, the service request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: authentication service device, unified data management device, specific network slice authentication and authorization function NSSAAF and AAA server.
[0532] In one possible design, the apparatus 900 may correspond to the terminal device in the above embodiment.
[0533] In a possible embodiment, the device 900 includes an interface unit 910, which is used to send a registration request message to the reader. The terminal device accesses the network using Internet of Things access technology. The registration request message includes identification information and / or device type of the terminal device. The device type information indicates whether the terminal device is an active terminal or a passive terminal.
[0534] In one possible design, the apparatus 900 may correspond to the reader / writer device in the above embodiment.
[0535] In a possible embodiment, the device 900 includes an interface unit 910, which is used to receive a registration request message from a terminal device, where the terminal device accesses the network using the Internet of Things access technology, and the registration request message includes identification information and / or device type of the terminal device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the interface unit 910 is also used to send a first message to a mobile management device, where the first message includes identification information of the terminal device, and the first message indicates the device type of the terminal device. The first message is used to determine an authentication service device, and the authentication service device supports authentication and / or authorization of devices that access the network using the Internet of Things access technology.
[0536] In one possible design, the apparatus 900 may correspond to the network storage device in the above embodiment.
[0537] In a possible embodiment, the apparatus 900 includes an interface unit 910, configured to receive first configuration information from an authentication service device, the first configuration information including at least one of the following: a first supported group identifier, first support information, and first support type information, wherein the first supported group identifier corresponds to a first service requester, the authentication service device supports authentication and / or authentication of a terminal device corresponding to the first service requester, the first support information indicates whether authentication and / or authentication of an Internet of Things device is supported, and the first support type information is used to indicate the type of device that the authentication service device supports for authentication and / or authentication; the interface unit 910 is further configured to receive a first request message from a mobile management device, the first request message including at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit 920 is configured to discover the authentication service device according to the first request message and the first configuration information; the interface unit 910 is configured to send a first response message to the mobile management device, the first response information including identification information and / or address information of the authentication service device.
[0538] In one possible implementation, the interface unit 910 is used to receive second configuration information from the unified data management device, where the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to a second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the contract data; the interface unit 910 is also used to receive a second request message from the mobile management device, where the second request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit 920 is used to discover the authentication service device based on the second request message and the second configuration information; the interface unit 910 is used to send a second response message to the mobile management device, where the second response information includes the identification information and / or address information of the unified data management device.
[0539] In one possible implementation, the interface unit 910 is used to receive second configuration information from the unified data management device, where the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to a second service requester, the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester, the second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device, and the second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the contract data; the interface unit 910 is also used to receive a second request message from the mobile management device, where the second request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit 920 is used to discover the authentication service device based on the second request message and the second configuration information; the interface unit 910 is used to send a second response message to the mobile management device, where the second response information includes the identification information and / or address information of the unified data management device.
[0540] In one possible implementation, the interface unit 910 is used to receive a fourth request message from the authentication service device, where the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal; the processing unit 920 is used to discover the authentication service device based on the fourth request message and the second configuration information; the interface unit 910 is used to send a fourth response message to the authentication service device, where the fourth response information includes identification information and / or address information of the unified data management device.
[0541] In one possible implementation, the interface unit 910 is used to receive sixth configuration information from the authentication and authorization function NSSAAF of a specific network slice, where the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information, wherein the third support group identifier indicates a service requester supported by the NSSAAF, the third support information corresponds to the third service requester, the NSSAAF supports authentication and / or authorization of the terminal device corresponding to the third service requester, and the third support type information is used to indicate the type of device that the NSSAAF supports for authentication and / or authorization; the interface unit 910 is also used For receiving a fifth request message from the authentication service device, the fifth request message includes at least one of the following: a group identifier, indication information and device type information, wherein the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; a processing unit 920 is used to discover the authentication service device according to the fifth request message and the sixth configuration information; an interface unit 910 is used to send a fifth response information to the authentication service device, the fifth response information includes the identification information and / or address information of the NSSAAF, and the identification information and / or address information of the AAA server.
[0542] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the network storage device in the above-mentioned method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0543] According to the aforementioned method, FIG13 is a schematic diagram of a communication device 1000 provided in an embodiment of the present application.
[0544] The apparatus 1000 may include a processor 1010 (i.e., an example of a processing unit). In one possible implementation, the apparatus 1000 further includes a memory 1020. The memory 1020 is configured to store instructions, and the processor 1010 is configured to execute the instructions stored in the memory 1020, so that the apparatus 1000 implements the steps performed by the communication device in methods 500-800.
[0545] In one possible implementation, the device 1000 may further include an interface 1030 (i.e., an example of an interface unit module). Furthermore, the processor 1010, memory 1020, and interface 1030 may communicate with each other through internal connection paths to transmit control and / or data signals. The memory 1020 is used to store computer programs, and the processor 1010 may be used to call and execute the computer programs from the memory 1020 to control the interface 1030 to receive or send signals. The memory 1020 may be integrated into the processor 1010 or may be provided separately from the processor 1010.
[0546] In one possible implementation, if the communication apparatus 1000 is a communication device, the interface 1030 is a receiver or a transmitter. The receiver and the transmitter may be the same or different physical entities. When they are the same physical entity, they may be collectively referred to as a transceiver.
[0547] In a possible implementation, if the communication device 1000 is a chip or a circuit, the interface 1030 is an input interface or the interface 1030 is an output interface.
[0548] As an implementation, the function of the interface 1030 may be implemented by a transceiver circuit or a dedicated transceiver chip. The processor 1010 may be implemented by a dedicated processing chip, a processing circuit, a processor, or a general-purpose chip.
[0549] As another implementation, it is possible to use a general-purpose computer to implement the communication device provided in the embodiments of the present application. Specifically, the program code that implements the functions of the processor 1010 and the interface 1030 is stored in the memory 1020, and the general-purpose processor implements the functions of the processor 1010 and the interface 1030 by executing the code in the memory 1020.
[0550] For the concepts, explanations, detailed descriptions and other steps involved in the device 1000 and related to the technical solutions provided in the embodiments of the present application, please refer to the descriptions of these contents in the aforementioned methods or other embodiments, and will not be repeated here.
[0551] An embodiment of the present application further provides a computer-readable storage medium on which computer instructions for implementing the methods executed by various devices in the above method embodiments are stored.
[0552] For example, when the computer program is executed by a computer, the computer can implement the methods executed by various devices in the above method embodiments.
[0553] An embodiment of the present application further provides a computer program product comprising instructions, which, when executed by a computer, enables the computer to implement the methods executed by various devices in the above method embodiments.
[0554] An embodiment of the present application further provides a communication system, which includes various devices in the above embodiments.
[0555] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.
[0556] It should be understood that in the embodiments of the present application, the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0557] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0558] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital versatile disc (DVD)), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0559] It should be understood that the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0560] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0561] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. Those skilled in the art will clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. On the other hand, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, which may be electrical, mechanical or other forms.
[0562] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, the functional units in the various embodiments of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. If the functions are implemented in the form of software functional units and sold or used as independent products, they may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the portion that contributes to the prior art, or the portion of the technical solution, may be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard drive, a read-only memory, a random access memory, a magnetic disk, or an optical disk.
[0563] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: include: The mobile management device obtains a first message, where the first message includes identification information of a terminal device, the first message indicates a device type of the terminal device, and the terminal device accesses a network using an Internet of Things access technology; The mobile management device selects an authentication service device according to the first message, and the authentication service device supports authentication and / or authentication of a terminal device that accesses a network using the Internet of Things access technology; The mobile management device sends a first authentication request message to the authentication service device, where the first authentication request message includes identification information of the terminal device, and the first authentication request message is used to request authentication and / or authorization to be performed on the terminal device.
2. The method according to claim 1, characterized in that The first message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, and the mobile management device selects an authentication service device according to the first message, including: The mobile management device determines that the terminal device is an Internet of Things device based on the first message, and selects an authentication service device that supports authentication and / or authorization of the Internet of Things device.
3. The method according to claim 1 or 2, characterized in that: Selecting an authentication service device according to the first message includes: The mobile management device sends a first request message to the network storage device according to the first message, the first request message is used to request to discover the authentication service device, and the first request message includes at least one of the following: a group identifier, indication information, and device type information, wherein: The group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The mobile management device obtains first response information from the network storage device, where the first response information includes identification information and / or address information of the authentication service device; The mobile management device selects the authentication service device according to the first response information.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: The mobile management device sends a second request message to the network storage device, the second request message is used to request to discover the unified data management device, the second request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein: The group identifier is included in the identifier information, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The mobile management device obtains a second response message from the network storage device, where the second response message includes identification information and / or address information of the unified data management device; The mobile management device selects a unified data management device according to the second response message.
5. The method according to claim 1 or 2, characterized in that: Selecting an authentication service device according to the first message includes: The mobile management device selects an authentication service device according to the first message and the third configuration information, wherein the third configuration information includes a correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein: The authentication service device information includes the identification and / or address information of the authentication service device. The first support group identification corresponds to the first service requester. The authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester. The first support information indicates whether authentication and / or authentication of Internet of Things devices is supported. The first support type information indicates the type of devices that the authentication service device supports for authentication and / or authentication.
6. The method according to claim 1 or 2, characterized in that: Selecting an authentication service device according to the first message includes: The mobile management device sends a third request message to the unified data management device, the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information, and device type information, wherein: The group identifier is included in the identifier information, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The mobile management device obtains third response information from the unified data management device, where the third response information includes identification information and / or address information of the authentication service device; The mobile management device selects the authentication service device according to the third response information.
7. The method according to claim 5 or 6, characterized in that: The method further comprises: The mobile management device selects a unified data management device based on the first message and the third configuration information, and the third configuration information includes a correspondence between the unified data management device information and at least one of the following items: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to a second service requester, and the unified data management device supports managing the contract data of a terminal device corresponding to the second service requester, and the second support information indicates whether the unified data management device supports managing the contract data of an Internet of Things device, and the second support type information is used to indicate a device type corresponding to a terminal device whose contract data the unified data management device supports managing.
8. The method according to claim 4 or 7, characterized in that: The method further comprises: The mobile management device sends a registration request message to the unified data management device, the registration request message including the identification information of the mobile management device and the identification information and / or address information of the authentication service device, and the registration request message indicates the mobile management device and the authentication service device serving the terminal device.
9. The method according to any one of claims 4 to 8, characterized in that: The method further includes: the mobile management device storing identification information of the authentication service device and / or identification information of the unified data management device.
10. The method according to claim 1 or 2, characterized in that: Selecting an authentication service device according to the first message includes: The mobility management device obtains a sixth request message from the network open function, where the sixth request message includes network function information, where the network function information includes identification information and / or address information of at least one of the following devices: an authentication service device, a unified data management device, a specific network slice authentication function NSAAF, and an AAA server; The mobile management device selects the authentication service device and / or the unified data management device according to the first message and the sixth request message.
11. A communication method, characterized in that: include: The authentication service device receives a first authentication request message from a mobile management device, wherein the first authentication request message includes identification information of a terminal device, and the first authentication request message is used to request authentication and / or authorization of the terminal device, wherein the terminal device accesses a network using Internet of Things access technology.
12. The method according to claim 11, characterized in that The first authentication request message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device, and the method further includes: The authentication service device selects the terminal device as an Internet of Things device according to the first authentication request message.
13. The method according to claim 11 or 12, characterized in that: The method comprises: The authentication service device selects a unified data management device according to the first authentication request message, and the unified data management device supports authentication and / or authentication of devices that access the network using the Internet of Things access technology; The authentication service device sends a second authentication request message to the unified data management device, where the second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
14. The method according to claim 13, characterized in that The second authentication request message includes at least one of the following: identification information of the terminal device, a group identifier, the indication information and the device type information, the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal.
15. The method according to any one of claims 11 to 14, characterized in that The method further comprises: The authentication service device sends first configuration information to the network storage device, wherein the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein: The first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information is used to indicate whether the authentication service device supports authentication and / or authentication of Internet of Things devices, and the first support type information is used to indicate the type of devices that the authentication service device supports for authentication and / or authentication.
16. The method according to any one of claims 13 to 15, characterized in that The authentication service device selects a unified data management device according to the first authentication request message, including: The authentication service device sends a fourth request message to the network storage device according to the first authentication request message, wherein the fourth request message is used to request discovery of a unified data management device, and the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein: The group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The authentication service device obtains fourth response information from the network storage device, where the fourth response information includes identification information and / or address information of the unified data device; The authentication service device selects a unified data management device according to the fourth response information.
17. The method according to any one of claims 13 to 15, characterized in that The authentication service device selects a unified data management device according to the first authentication request message, including: The authentication service device selects a unified data management device according to the first authentication information and fifth configuration information, wherein the fifth configuration information includes a correspondence between unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein: The second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device. The second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
18. The method according to claim 17, characterized in that The method further comprises: The authentication service device obtains a second authentication response message from the unified data management device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
19. The method according to claim 11, characterized in that The method further comprises: The authentication service device sends a fifth request message to the network storage device, the fifth request message is used to request to discover NSSAAF, and the fifth request message includes at least one of the following: group identification, indication information and device type information, wherein, The group identifier is included in the identifier information, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The authentication service device obtains fifth response information from the network storage device, where the fifth response information includes at least one of the following: identification information and / or address information of the NSSAAF, identification information and / or address information of the AAA server; The authentication service device selects NSSAAF according to the fifth response information.
20. The method according to claim 11, characterized in that The first authentication request message includes specific network slice authentication function NSSAAF information and / or AAA server information, and the NSSAAF information indicates the NSSAAF used to perform authentication and / or authentication; the method includes: The authentication service device sends a third authentication request message to the NSSAAF, wherein the third authentication request message includes at least one of the following: a device identifier, indication information, device type information, and the AAA server information, wherein: The indication information indicates that the terminal device is an Internet of Things device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes identification information and / or address information of the AAA server.
21. A communication method, characterized in that: include: The unified data management device receives a second authentication request message from the authentication service device, wherein the second authentication request message includes at least one of the following: identification information, a group identification, indication information, and device type information of a terminal device, wherein the group identification is included in the identification information, the group identification indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The unified data management device determines an authentication method according to the second authentication request message, and the authentication method is used to authenticate and / or authorize the terminal device.
22. The method according to claim 21, characterized in that The method further includes: the unified data management device sends second configuration information to the network storage device, the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein: The second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device. The second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
23. The method according to claim 21 or 22, characterized in that The method further comprises: The unified data management device receives a third request message from the mobile management device, the third request message is used to select the authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The unified data management device selects an authentication service device according to the third request information and the fourth configuration information, wherein the fourth configuration information includes a correspondence between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein the first support group identifier corresponds to a first service requester, the authentication service device supports performing authentication and / or authentication on a terminal device corresponding to the first service requester to indicate the supported service requester, the first support information indicates whether authentication and / or authentication of an Internet of Things device is supported, and the first support type information is used to indicate a device type that supports authentication and / or authentication; The unified data management device sends third response information to the mobile management device, where the third response information includes identification information and / or address information of the authentication service device.
24. The method according to claim 21 or 22, characterized in that The method further comprises: The unified data management device sends a second authentication response message to the authentication service device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
25. The method according to any one of claims 21 to 24, characterized in that The method further comprises: The unified data management device receives a registration request message from a mobile management device, the registration request message including identification information of the mobile management device and identification information and / or address information of the authentication service device, and the registration request message indicates the mobile management device and authentication service device serving the terminal device.
26. The method according to claim 25, characterized in that The method further includes: the unified data management device storing identification information of the authentication service device.
27. A communication method, characterized in that: include: The network open function receives a service request message from a service requester, wherein the service request message is used to perform a service operation on at least one terminal device corresponding to the service requester; The network open function determines network function information according to the service request message, and the network function corresponding to the network function information is used to perform authentication and / or authorization on the at least one terminal device; The network open function sends a sixth request message to the mobile management device, and the sixth request message includes the network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: authentication service device, unified data management device, specific network slice authentication function NSSAAF and AAA server.
28. A communication device, characterized in that: The device includes: An interface unit, configured to obtain a first message, wherein the first message includes identification information of a terminal device, the first message indicates a device type of the terminal device, and the terminal device accesses a network using an Internet of Things access technology; A processing unit, configured to select an authentication service device according to the first message, wherein the authentication service device supports authentication and / or authorization of a terminal device that accesses a network using the Internet of Things access technology; The interface unit is further used to send a first authentication request message to the authentication service device, where the first authentication request message includes identification information of the terminal device, and the first authentication request message is used to request authentication and / or authorization to be performed on the terminal device.
29. The device according to claim 28, characterized in that The first message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, and the processing unit is used to select an authentication service device according to the first message, including: The processing unit is used to determine that the terminal device is an Internet of Things device according to the first message, and select an authentication service device that supports authentication and / or authorization of the Internet of Things device.
30. The device according to claim 28 or 29, characterized in that The processing unit selects an authentication service device according to the first message, including: The interface unit is used to send a first request message to the network storage device according to the first message, the first request message is used to request to discover the authentication service device, and the first request message includes at least one of the following: a group identifier, indication information, and device type information, wherein: The group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The interface unit is further used to obtain first response information from the network storage device, wherein the first response information includes identification information and / or address information of the authentication service device; The processing unit is used to select the authentication service device according to the first response information.
31. The device according to any one of claims 28 to 30, characterized in that The interface unit is further used to send a second request message to the network storage device, the second request message is used to request to discover the unified data management device, the second request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein: The group identifier is included in the identifier information, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The interface unit is further used to obtain a second response message from the network storage device, wherein the second response message includes identification information and / or address information of the unified data management device; The processing unit is further configured to select a unified data management device according to the second response message.
32. The device according to claim 28 or 29, characterized in that The processing unit is used to select an authentication service device according to the first message, including: The processing unit is used to select an authentication service device according to the first message and third configuration information, wherein the third configuration information includes a correspondence between authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information, wherein: The authentication service device information includes the identification and / or address information of the authentication service device. The first support group identification corresponds to the first service requester. The authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester. The first support information indicates whether authentication and / or authentication of Internet of Things devices is supported. The first support type information indicates the type of devices that the authentication service device supports for authentication and / or authentication.
33. The device according to claim 28 or 29, characterized in that The processing unit is used to select an authentication service device according to the first message, including: The interface unit is used to send a third request message to the unified data management device, the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein: The group identifier is included in the identifier information, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The interface unit is further used to obtain third response information from the unified data management device, wherein the third response information includes identification information and / or address information of the authentication service device; The processing unit is used for selecting the authentication service device according to the third response information.
34. The device according to claim 32 or 33, characterized in that The processing unit is used to select a unified data management device according to the first message and the third configuration information, and the third configuration information includes a correspondence between the unified data management device information and at least one of the following items: a second support group identifier, second support information, and second support type information, wherein the second support group identifier corresponds to a second service requester, and the unified data management device supports managing the contract data of a terminal device corresponding to the second service requester, and the second support information indicates whether the unified data management device supports managing the contract data of an Internet of Things device, and the second support type information is used to indicate a device type corresponding to a terminal device whose contract data the unified data management device supports managing.
35. The device according to claim 31 or 34, characterized in that The interface unit is used to send a registration request message to the unified data management device, the registration request message including the identification information of the mobile management device and the identification information and / or address information of the authentication service device, and the registration request message indicates the mobile management device and authentication service device serving the terminal device.
36. The device according to any one of claims 31 to 35, characterized in that The apparatus further comprises: a storage unit, configured to store identification information of the authentication service device and / or identification information of the unified data management device.
37. The device according to claim 28 or 29, characterized in that The processing unit is used to select an authentication service device according to the first message, including: The interface unit is used to obtain a sixth request message from the network open function, where the sixth request message includes network function information, where the network function information includes identification information and / or address information of at least one of the following devices: an authentication service device, a unified data management device, a specific network slice authentication function NSAAF, and an AAA server; The processing unit is used to select the authentication service device and / or the unified data management device according to the first message and the sixth request message.
38. A communication device, characterized in that: The device comprises: The interface unit is used to receive a first authentication request message from a mobile management device, wherein the first authentication request message includes identification information of a terminal device, and the first authentication request message is used to request authentication and / or authorization of the terminal device, wherein the terminal device accesses a network using Internet of Things access technology.
39. The device according to claim 38, characterized in that The first authentication request message includes device type information and / or indication information, the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an Internet of Things device, and the apparatus further includes: A processing unit is used to select the terminal device as an Internet of Things device according to the first authentication request message.
40. The device according to claim 38 or 39, characterized in that The processing unit is used to select a unified data management device according to the first authentication request message, and the unified data management device supports authentication and / or authentication of a device that accesses a network using the Internet of Things access technology; The interface unit is used to send a second authentication request message to the unified data management device, and the second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
41. The device according to claim 40, characterized in that The second authentication request message includes at least one of the following: identification information of the terminal device, a group identifier, the indication information and the device type information, the group identifier is included in the identification information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal.
42. The device according to any one of claims 38 to 41, characterized in that The interface unit is used to send first configuration information to the network storage device, wherein the first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information, wherein: The first support group identifier corresponds to the first service requester, the authentication service device supports authentication and / or authentication of the terminal device corresponding to the first service requester, the first support information is used to indicate whether the authentication service device supports authentication and / or authentication of Internet of Things devices, and the first support type information is used to indicate the type of devices that the authentication service device supports for authentication and / or authentication.
43. The device according to any one of claims 40 to 42, characterized in that The processing unit is used to select a unified data management device according to the first authentication request message, including: The interface unit is used to send a fourth request message to the network storage device according to the first authentication request message, the fourth request message is used to request to discover a unified data management device, and the fourth request message includes at least one of the following: a group identifier, indication information, and device type information, wherein: The group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The interface unit is used to obtain fourth response information from the network storage device, and the fourth response information includes identification information and / or address information of the unified data device; The processing unit is used for selecting a unified data management device according to the fourth response information.
44. The device according to any one of claims 40 to 42, characterized in that The processing unit is used to select a unified data management device according to the first authentication request message, including: The processing unit is used to select a unified data management device according to the first authentication information and fifth configuration information, wherein the fifth configuration information includes a correspondence between unified data management device information and at least one of the following: a second support group identifier, second support information, and second support type information, wherein: The second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device. The second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
45. The device according to claim 44, characterized in that The interface unit is used to obtain a second authentication response message from the unified data management device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
46. The device according to claim 38, characterized in that The interface unit is used to send a fifth request message to the network storage device, the fifth request message is used to request to discover NSSAAF, and the fifth request message includes at least one of the following: group identification, indication information and device type information, wherein, The group identifier is included in the identifier information, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The interface unit is used to obtain fifth response information from the network storage device, and the fifth response information includes at least one of the following: identification information and / or address information of the NSSAAF, identification information and / or address information of the AAA server; The processing unit is used to select NSSAAF according to the fifth response information.
47. The device according to claim 38, characterized in that The first authentication request message includes specific network slice authentication function NSSAAF information and / or AAA server information, and the NSSAAF information indicates the NSSAAF used to perform authentication and / or authentication; The interface unit is used to send a third authentication request message to the NSSAAF, wherein the third authentication request message includes at least one of the following: a device identifier, indication information, device type information, and the AAA server information, wherein: The indication information indicates that the terminal device is an Internet of Things device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes identification information and / or address information of the AAA server.
48. A communication device, characterized in that: The device comprises: The interface unit is configured to receive a second authentication request message from an authentication service device, wherein the second authentication request message includes at least one of the following: identification information, a group identification, indication information, and device type information of a terminal device, wherein the group identification is included in the identification information, the group identification indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; A processing unit is used to determine an authentication method according to the second authentication request message, and the authentication method is used to authenticate and / or authorize the terminal device.
49. The device according to claim 48, characterized in that The interface unit is used to send second configuration information to the network storage device, wherein the second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information, wherein: The second support group identifier corresponds to the second service requester, and the unified data management device supports managing the contract data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the contract data of the Internet of Things device. The second support type information is used to indicate the device type corresponding to the terminal device that the unified data management device supports managing the contract data.
50. The device according to claim 48 or 49, characterized in that The interface unit is used to receive a third request message from the mobile management device, the third request message is used to select the authentication service device, and the third request message includes at least one of the following: identification information, group identification, indication information and device type information, wherein the group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The processing unit is used to select an authentication service device according to the third request information and the fourth configuration information, the fourth configuration information including the corresponding relationship between the authentication service device information and at least one of the following: a first support group identifier, first support information and first support type information, wherein the first support group identifier corresponds to a first service requester, the authentication service device supports the authentication and / or authentication of a terminal device corresponding to the first service requester to indicate the supported service requester, the first support information indicates whether authentication and / or authentication of an Internet of Things device is supported, and the first support type information is used to indicate the type of device that supports authentication and / or authentication; The interface unit is further configured to send third response information to the mobile management device, where the third response information includes identification information and / or address information of the authentication service device.
51. The device according to claim 48 or 49, characterized in that The interface unit is used to send a second authentication response message to the authentication service device, and the second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
52. The device according to any one of claims 48 to 51, characterized in that The interface unit is used to receive a registration request message from a mobile management device, the registration request message including identification information of the mobile management device and identification information and / or address information of the authentication service device, and the registration request message indicates the mobile management device and authentication service device serving the terminal device.
53. The device according to claim 52, characterized in that The apparatus further comprises: a storage unit, configured to store identification information of the authentication service device.
54. A communication device, characterized in that: The device comprises: An interface unit, configured to receive a service request message from a service requester, wherein the service request message is used to perform a service operation on at least one terminal device corresponding to the service requester; a processing unit, configured to determine network function information according to the service request message, wherein the network function corresponding to the network function information is used to perform authentication and / or authorization on the at least one terminal device; The interface unit is also used to send a sixth request message to the mobile management device, and the sixth request message includes the network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: authentication service device, unified data management device, specific network slice authentication function NSSAAF and AAA server.
55. A communication device, characterized in that: include: A processor, wherein the processor is used to execute a program or an instruction so that the device performs the method according to any one of claims 1 to 10, or the device performs the method according to any one of claims 11 to 20, or the device performs the method according to any one of claims 21 to 26, or the device performs the method according to claim 27.
56. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is run on a computer, the computer executes the method as described in any one of claims 1 to 10, or the method as described in any one of claims 11 to 20, or the method as described in any one of claims 21 to 26, or the method as described in claim 27.
Citation Information
Patent Citations
Communication method and device
CN120166397A
Extended authentication method of Internet of Things system
CN108737381A
Communication method, device and system, terminal device, core network device and medium
CN116941260A
Internet of Things system access security processing method
CN117061164A
Authentication in a personal area network
GB202300043D0