Communication method and apparatus
The management device provides security parameters for terminal equipment for security verification, which simplifies the security authentication process of terminal equipment, solves the problem of excessive power consumption of terminal equipment in the environmental Internet of Things, and realizes low-power safe communication.
Patent Information
- Application Number
- PCT/CN2025/073391
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2025-01-20
- Publication Date
- 2025-07-31
AI Technical Summary
In the environmental Internet of Things, terminal devices consume a lot of power when conducting secure communication with servers, especially when performing operations such as inventory, read, write or inactivated operations, the prior art requires complex interactive processes to cause excessive energy consumption.
The management device receives the server's service request, determines the security parameters of the terminal device, and sends them to the terminal device for security verification, reducing the security verification process of the terminal device, such as using security credentials and freshness parameters to simplify the authentication process.
On the premise of ensuring secure communication, the power consumption of terminal devices is reduced, the accuracy of security verification is improved, and the number of message interactions is reduced.
Smart Images

Figure CN2025073391_31072025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on January 24, 2024, with application number 202410101448.6 and invention name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The embodiments of the present application relate to the field of wireless communications, and in particular to a communication method and apparatus. Background Art
[0004] In the Internet of Things (IoT), terminal devices (e.g., passive or semi-passive tags) do not have their own power supply devices or rely on batteries. Instead, they obtain energy from the environment, for example, through solar energy, radio frequency, wind energy, hydropower, or tidal energy. The terminal devices support data perception, transmission, and distributed computing.
[0005] For example, when a server needs to perform an operation on a terminal device (e.g., an inventory operation, a read operation, a write operation, or a deactivation operation), it can send instructions through the core network device. Currently, to achieve secure communication between terminal devices and core network devices, a relatively complex interaction process (such as two-way authentication and non-access stratum (NAS) security protection) is required, resulting in relatively high power consumption of the terminal device.
[0006] Therefore, in the environmental Internet of Things, when the server needs to perform operations on the terminal device, how to reduce the power consumption of the terminal device is a technical problem that needs to be solved urgently. Summary of the Invention
[0007] The present application provides a communication method and apparatus for reducing the power consumption of a terminal device while achieving secure communication in an environmental Internet of Things when a server needs to operate the terminal device.
[0008] In a first aspect, the present application provides a communication method, which is performed by a management apparatus. The management apparatus may be a management device or a module (e.g., a chip) in the management device. The management device may be, for example, an access network device, an access and mobility management function (AMF), or a tag management function (TMF).
[0009] For the convenience of description, the following description takes the management device as an example.
[0010] The communication method includes: a management device receiving a first service request from a server, the first service request including a first operation type and a first operation range, the first operation type indicating a first operation, and the first operation range being used to identify a first terminal device that performs the first operation. The management device determines security parameters based on an identifier of the first terminal device. The management device sends a first operation request to the first terminal device, the first operation request including the first operation type and security parameters, the security parameters being used to perform a network security check. Exemplarily, the security parameters are used by the first terminal device to perform a network security check.
[0011] In the above technical solution, the management device determines the security parameters based on the identification of the first terminal device, and sends the first operation type and the security parameters to the first terminal device in a message (i.e., the first operation request). After receiving the first operation request, the first terminal device can first perform a security check based on the security parameters, and then execute the first operation indicated by the first operation type. In this way, the terminal device only needs to verify the security parameters, which reduces the security verification process of the terminal device and avoids the terminal device from executing more complex interaction processes (such as two-way authentication and NAS security protection in the prior art). This helps to reduce the power consumption of the terminal device while achieving secure communication.
[0012] In one possible implementation, when the management device determines the security parameters based on the identifier of the first terminal device, the management device may obtain the security credentials of the first terminal device based on the identifier of the first terminal device, and then determine the security parameters based on the security credentials and the freshness parameter of the first terminal device. The security credentials may be a password or a key, and the freshness parameter may be one or more of a random number, a timestamp, and a counter value.
[0013] In the above technical solution, the management device determines the security parameters based on the security credentials and the freshness parameters, wherein the freshness parameters are variable. The management device sends the security parameters to the first terminal device. The security parameters are used by the first terminal device to perform security verification on the network, which helps to improve the accuracy of the security verification, that is, to improve the security of message transmission between the management device and the first terminal device.
[0014] In one possible implementation, the management device further receives a connection request from the first terminal device, the connection request including a freshness parameter. Exemplarily, the connection request also includes an identifier of the first terminal device. Alternatively, the management device further generates the freshness parameter, and the first operation request also includes the freshness parameter.
[0015] In the above technical solution, both the management device and the first terminal device can obtain the freshness parameter, and carry the freshness parameter in the connection request of the first terminal device or the first operation request of the management device, which helps to reduce the number of message interactions.
[0016] The management device may obtain the security credentials of the first terminal device according to the identification of the first terminal device in the following two ways:
[0017] Method 1: The management device stores the correspondence between the identification of the first terminal device and the security credentials. When the management device obtains the security credentials of the first terminal device based on the identification of the first terminal device, it can be specifically that the management device obtains the security credentials of the first terminal device based on the identification of the first terminal device and the stored correspondence between the identification of the first terminal device and the security credentials. Exemplarily, the management device also receives configuration information from the server, and the configuration information includes the correspondence. In the above technical solution, storing the correspondence between the identification of the first terminal device and the security credentials in the management device helps to reduce the number of message interactions.
[0018] Method 2: When the management device obtains the security credentials of the first terminal device based on the identifier of the first terminal device, the management device may specifically send the identifier of the first terminal device to a storage device, which stores the corresponding relationship between the identifier of the first terminal device and the security credentials. The management device receives the security credentials of the first terminal device from the storage device. In the above technical solution, the corresponding relationship between the identifier of the first terminal device and the security credentials is stored in a storage device other than the management device, thereby improving the flexibility of the architecture by separating storage and computing.
[0019] Exemplarily, the management device corresponds to multiple storage devices, each of which stores a correspondence between the terminal device's identifier and security credentials, and the correspondences stored in different storage devices are different, and each storage device corresponds to its own routing information. When the management device sends the identifier of the first terminal device to the storage device, it can specifically be that the management device obtains routing information from the identifier of the first terminal device, determines the storage device corresponding to the routing information (i.e., the target storage device) based on the routing information, and sends the identifier of the first terminal device to the storage device corresponding to the routing information. In the above technical solution, the efficiency of the management device in determining the target storage device is improved by setting the routing information.
[0020] In one possible implementation, after sending the first operation request to the first terminal device, the management device also generates a first service result. The first service result corresponds to the first service request, and the first service result indicates the operation status of the first terminal device for the first operation, wherein the operation status of the first terminal device for the first operation is operation success or operation failure.
[0021] Furthermore, when the first operation is a deactivation operation, the management device or server may identify the third terminal device that failed to be deactivated, and instruct the third terminal device to perform the deactivation operation again, respectively referring to the following two methods:
[0022] In the first approach, after generating the first service result, the management device further receives a second service request from the server. The second service request includes a second operation type and a second operation range. The second operation type indicates the second operation, and the second operation range is used to identify the second terminal device that performs the second operation. Based on the identifier of the second terminal device and the first service result, the management device determines the third terminal device that failed to be deactivated and sends a second operation request to the third terminal device. The second operation request includes the first operation type (equivalent to the deactivation operation type).
[0023] In the above technical solution, the management device can identify the third terminal device that failed to be deactivated based on the identifier of the second terminal device and the result of the first service, without requiring server involvement. This helps improve the management device's efficiency in determining the third terminal device that failed to be deactivated. Furthermore, the management device identifies the third terminal device that failed to be deactivated and instructs it to retry the deactivation operation, thereby improving the deactivation success rate and preventing interference with the operational flow of the entire IoT system caused by terminal devices that should have been deactivated but were not.
[0024] Method 2: After generating the first service result, the management device also sends the first service result to the server. Subsequently, the management device receives a second service request from the server, the second service request includes a second operation type and a second operation range, the second operation type indicates the second operation, and the second operation range is used to determine the second terminal device that performs the second operation, and the management device sends a second service result to the server, the second service result indicates the operation status of the second terminal device for the second operation, and the second service result corresponds to the second service request. Among them, the first service result and the second service result are used to determine the third terminal device that failed to be deactivated, that is, the server can determine the third terminal device that failed to be deactivated based on the first service result and the second service result. Further, the management device receives a third service request from the server, the third service request includes the identifier of the third terminal device and the first operation type. The management device sends a third operation request to the third terminal device, and the third operation request includes the first operation type (equivalent to the deactivation operation type).
[0025] In the above technical solution, the management device receives service requests from the server and sends service results to the server. This eliminates the need to identify third terminal devices that failed to be deactivated, reducing the management device's computational workload. Furthermore, if a server corresponds to multiple management devices, the server can more accurately identify the third terminal device. Furthermore, the server identifies third terminal devices that failed to be deactivated and instructs them to retry the deactivation operation, improving the deactivation success rate and preventing disruption to the overall IoT system's operational flow caused by terminal devices that should have been deactivated but were not.
[0026] In one possible implementation, the management device may also determine the identity of the first terminal device based on the first operating range before determining the security parameters based on the identity of the first terminal device. When the management device is an AMF or TMF, the management device sends an N2 message to the access network device. The N2 message includes a random access indication and / or a first operating range. The random access indication is used to trigger the access network device to send a broadcast message. The broadcast message includes the first operating range. The broadcast message is used to instruct the first terminal device to establish a connection with the access network device. Subsequently, the management device receives a registration request (or connection request) from the first terminal device. The registration request (or connection request) carries the identity of the first terminal device.
[0027] In the above technical solution, when the management device is AMF or TMF, an implementation method is provided for how the management device obtains the identification of the first terminal device, which helps to achieve flexible deployment of core network equipment.
[0028] In a second aspect, the present application provides a communication method, which is executed by a terminal device, which may be a terminal device or a module (e.g., a chip) in the terminal device. For ease of description, the following description takes the terminal device as an example.
[0029] The communication method includes: a terminal device sends an identifier of the terminal device to a management device, wherein the identifier of the terminal device is associated with a security parameter; the terminal device receives a first operation request from the management device, wherein the first operation request includes a first operation type and a security parameter, and the first operation type indicates a first operation; and the terminal device performs the first operation after determining that the network has passed the security check based on the security parameter.
[0030] In one possible implementation, when the terminal device determines that the network has passed the security check based on the security parameters, the terminal device may specifically determine that the network has passed the security check based on the security parameters, the freshness parameters and the security credentials of the terminal device stored in the terminal device.
[0031] Exemplarily, the terminal device determines that the network has passed the security check when the security credentials used to generate security parameters for the management device (or the security credentials obtained by the management device) are the same as the security credentials of the terminal device stored in the terminal device based on the security parameters, freshness parameters and the security credentials of the terminal device stored in the terminal device.
[0032] In one possible implementation, the terminal device further generates a freshness parameter and sends a connection request to the management device, wherein the connection request includes the freshness parameter. Exemplarily, the connection request also includes an identifier of the terminal device. Alternatively, the first operation request also includes the freshness parameter, and the terminal device further obtains the freshness parameter from the first operation request.
[0033] In one possible implementation, the management device is an AMF or TMF, and the terminal device further receives a broadcast message from the access network device, the broadcast message including the first operating scope. Upon determining that the terminal device is included among the target terminal devices indicated by the first operating scope, the terminal device establishes a connection with the access network device and sends a registration request (or connection request) to the management device, the registration request (or connection request) carrying the terminal device's identifier.
[0034] In a third aspect, the present application provides a communication method, which is executed by a service device, which can be a server or a module (e.g., a chip) in the server. The server can be a third-party application function (AF), a services capability server (SCS), an application server (AS), a passive IoT application function (AF), or other device that sends a service request.
[0035] For the convenience of description, the following description takes the service device as an example.
[0036] The communication method includes: a server sending a first service request to a management device, the first service request including a first operation type and a first operation range, the first operation type indicating a first operation, and the first operation range being used to identify a first terminal device that performs the first operation; and the server receiving a first service result from the management device. The first service result indicates an operation status of the first terminal device for the first operation, wherein the operation status of the first terminal device for the first operation is success or failure.
[0037] In one possible implementation, the server sends a second service request to the management device. The second service request includes a second operation type and a second operation range. The second operation type indicates the second operation, and the second operation range is used to determine a second terminal device that performs the second operation. The server receives a second service result from the management device. The second service result indicates an operation status of the second operation by the second terminal device, where the operation status of the second operation by the second terminal device is either a success or a failure.
[0038] In one possible implementation, when the first operation type is a deactivation operation type, that is, when the first operation is a deactivation operation, the server further determines, based on the first service result and the second service result, a third terminal device that failed to be deactivated. The server sends a third service request to the management device, where the third service request includes an identifier of the third terminal device and the first operation type.
[0039] In a fourth aspect, an embodiment of the present application provides a communication device, which has the function of implementing the management device in the above-mentioned first aspect or any possible implementation of the first aspect, or has the function of implementing the terminal device in the above-mentioned second aspect or any possible implementation of the second aspect, or has the function of implementing the service device in the above-mentioned third aspect or any possible implementation of the third aspect.
[0040] The functions of the above-mentioned communication device can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules, units or means corresponding to the above-mentioned functions.
[0041] In one possible implementation, the structure of the device includes a processing module and a transceiver module, wherein the processing module is configured to support the device in performing the corresponding functions of the management device in the first aspect or any one of the implementations of the first aspect, or in performing the corresponding functions of the terminal device in the second aspect or any one of the implementations of the second aspect, or in performing the corresponding functions of the service device in the third aspect or any one of the implementations of the third aspect. The transceiver module is used to support communication between the device and other communication devices. For example, when the device is a management device, it can receive a first service request from a server. The communication device may also include a storage module, which is coupled to the processing module and stores program instructions and data necessary for the device. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory. The memory may be integrated with the processor or may be set separately from the processor.
[0042] In another possible implementation, the structure of the device includes a processor and may also include a memory. The processor is coupled to the memory and can be used to execute computer program instructions stored in the memory, so that the device performs the corresponding functions of the management device in the first aspect or any possible implementation of the first aspect, or performs the corresponding functions of the terminal device in the second aspect or any possible implementation of the second aspect, or performs the corresponding functions of the service device in the third aspect or any possible implementation of the third aspect. Optionally, the device also includes a communication interface, and the processor is coupled to the communication interface. When the device is a management device, a terminal device or a server, the communication interface can be a transceiver or an input / output interface; when the device is a chip included in the management device, the terminal device or the server, the communication interface can be the input / output interface of the chip. Optionally, the transceiver can be a transceiver circuit, and the input / output interface can be an input / output circuit.
[0043] In the fifth aspect, an embodiment of the present application provides a chip system, comprising: a processor and a memory, the processor being coupled to the memory, the memory being used to store programs or instructions, and when the programs or instructions are executed by the processor, the chip system executes the corresponding functions of the management device in the above-mentioned first aspect or any possible implementation of the first aspect, or executes the corresponding functions of the terminal device in the above-mentioned second aspect or any possible implementation of the second aspect, or executes the corresponding functions of the service device in the above-mentioned third aspect or any possible implementation of the third aspect.
[0044] Optionally, the chip system further includes an interface circuit for transmitting interactive code instructions to the processor.
[0045] Optionally, there may be one or more processors in the chip system, and the processor may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0046] Optionally, the memory in the chip system may be one or more. The memory may be integrated with the processor or provided separately from the processor. Exemplarily, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or provided on different chips.
[0047] In a sixth aspect, the present application provides a computer-readable storage medium, which stores a computer program or instruction. When the computer program or instruction is executed by a communication device, the communication device performs the corresponding function of the management device in the above-mentioned first aspect or any possible implementation of the first aspect, or performs the corresponding function of the terminal device in the above-mentioned second aspect or any possible implementation of the second aspect, or performs the corresponding function of the service device in the above-mentioned third aspect or any possible implementation of the third aspect.
[0048] In the seventh aspect, the present application provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a communication device, it executes the corresponding functions of the management device in the above-mentioned first aspect or any possible implementation of the first aspect, or executes the corresponding functions of the terminal device in the above-mentioned second aspect or any possible implementation of the second aspect, or executes the corresponding functions of the service device in the above-mentioned third aspect or any possible implementation of the third aspect.
[0049] In an eighth aspect, an embodiment of the present application provides a communication system, the communication system including one or more of the following devices:
[0050] The management device in the above-mentioned first aspect or any possible implementation of the first aspect, the terminal device in the above-mentioned second aspect or any possible implementation of the second aspect, and the service device in the above-mentioned third aspect or any possible implementation of the third aspect.
[0051] The technical effects that can be achieved in any of the second to eighth aspects mentioned above can refer to the description of the beneficial effects in the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] FIG1 is a schematic diagram of a communication system architecture provided by this application;
[0053] FIG2 is a schematic diagram of the architecture of a radio frequency system provided by the present application;
[0054] FIG3 is a schematic diagram of an Internet of Things scenario provided by this application;
[0055] FIG4 is a schematic diagram of a process of a server performing an operation on a terminal device;
[0056] FIG5 is a flow chart of the first communication method provided by the present application;
[0057] FIG6 is a flow chart of a second communication method provided by the present application;
[0058] FIG7 is a flow chart of a third communication method provided by this application;
[0059] FIG8 is a schematic structural diagram of a communication device provided by the present application;
[0060] FIG9 is a schematic structural diagram of yet another communication device provided in this application. DETAILED DESCRIPTION
[0061] The following first explains the relevant technical features involved in the embodiments of the present application. It should be noted that these explanations are intended to make the embodiments of the present application easier to understand and should not be regarded as limiting the scope of protection claimed by the present application.
[0062] FIG1 exemplarily shows a schematic diagram of the architecture of a communication system, which includes terminal equipment, (radio) access network (R)AN) equipment, core network equipment and data network (DN).
[0063] Among them, the core network equipment may include one or more of the following: access and mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), authentication server function (AUSF), unified data management (UDM), unified data repository (UDR), network exposure function (NEF), and security anchor function (SEAF).
[0064] The devices in this application may also be referred to as network elements, functional entities, nodes, etc.
[0065] The following is a brief introduction to the devices shown in Figure 1:
[0066] 1. Terminal equipment: This term can be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. Terminal equipment can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearables, smart transportation, and smart cities. When used in IoT scenarios, terminal equipment can specifically include environmental IoT terminal devices, sensors, electricity meters, water meters, and unmanned aerial vehicles (UAVs) with communication capabilities. Furthermore, AIoT terminal devices can be considered low-power devices, such as passive or semi-passive tags. As a possible classification, AIoT terminal devices can be categorized as microwatt-level, hundred-microwatt-level, and milliwatt-level.
[0067] 2. (Wireless) access network equipment: used to provide network access functions for authorized terminal devices in a specific area, and can use transmission tunnels with different service qualities according to the level of the terminal device, business requirements, etc. The (wireless) access network equipment can manage wireless resources, provide access services for terminal devices, and then complete the forwarding of control signals and data between the terminal device and the core network. The (wireless) access network equipment can also be understood as a base station in a traditional network. Exemplarily, the (wireless) access network equipment in the embodiment of the present application can be any communication device with wireless transceiver functions for communicating with the terminal device. The (wireless) access network equipment includes but is not limited to an evolved Node B (eNB), a gNB in a 5G system, or a transmission point (TRP or TP), or one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or it can also be a network node constituting a gNB or a transmission point, such as a baseband unit (BBU) or a distributed unit (DU), or it can also be a pole station, a micro base station, a macro station, an integrated access and backhaul (IAB) node, etc. Furthermore, in the IoT scenario, the (wireless) access network device can also serve as a reader to read data from or write data to the terminal device. For ease of description, the following takes the (wireless) access network device as a base station as an example.
[0068] 3. UPF: Used for forwarding and receiving data in terminal devices. For example, the UPF can receive data from the DN and send it to the terminal device via the base station. The UPF can also receive data from the terminal device via the base station and forward it to the DN. The transmission resources and scheduling functions within the UPF that serve terminal devices are managed and controlled by the SMF.
[0069] 4. AMF: Manages access control and mobility of terminal devices. For example, the AMF can be responsible for terminal device registration, mobility management, tracking area update procedures, reachability detection, SMF selection, and mobile state transition management. Furthermore, in IoT scenarios, the AMF can receive service requests from servers and perform operations corresponding to the service requests on terminal devices based on the service requests, or instruct the base station to perform operations corresponding to the service requests on the terminal devices.
[0070] 5. SMF: used for session management of terminal devices (including session establishment, modification and release), selection and reselection of UPF, allocation of Internet Protocol (IP) addresses of terminal devices, and quality of service (QoS) control.
[0071] 6. NEF: used to enable 3GPP to securely provide network service capabilities to third-party application functions (AF) (for example, service capability servers (SCS), application servers (AS), etc.).
[0072] 7. PCF: A unified policy framework used to guide network behavior and provide policy rule information for control plane functions (such as AMF, SMF, etc.).
[0073] 8. SEAF is responsible for initiating authentication requests to AUSF and completing the network-side authentication of the terminal device during the authentication and key agreement (AKA) process. Optionally, SEAF is part of AMF.
[0074] 9. UDM: used to handle terminal device identification, access authentication, registration, and mobility management.
[0075] 10. AUSF: Used for authentication services, generating keys to achieve two-way authentication of terminal devices, and supporting a unified authentication framework.
[0076] 11. UDR: used to store UDM contract information, PCF policy information, etc.
[0077] 12. DN: A DN is a network outside of a carrier network. A carrier network can connect to multiple DNs, and a variety of services can be deployed on the DN, providing data and / or voice services to terminal devices. For example, in an IoT scenario, a DN is the private network of a smart factory. Sensors installed in the workshop of the smart factory can be terminal devices (i.e., IoT devices). Servers are deployed in the DN to control the sensors.
[0078] In Figure 1, Nausf, Nnef, Npcf, Nudm, Nseaf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface sequence numbers. The meanings of these interface sequence numbers can be found in the 3GPP standard protocol and are not limited here.
[0079] It should be added that the technical solution provided in this application can be applied to various communication systems, such as: fifth generation (5G) or new radio (NR) system, long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, etc. The technical solution provided in this application can also be applied to future communication systems, such as the sixth generation mobile communication system. It can be understood that the names of the devices in other systems may be the same as or different from the names of the devices in the communication system shown in Figure 1. For example, AMF may also be called AMF in the future communication system, or other names, and UDM may also be called UDM in the future communication system, or other names, etc., which are not limited by this application. For the convenience of description, AMF, SMF, NEF, PCF, UDM, UPF, SEAF, AUSF, etc. are used as examples in the following embodiments.
[0080] FIG2 is a schematic diagram of the architecture of a radio frequency system provided by this application. Specifically, the radio frequency system may be a radio frequency identification (RFID) system. The radio frequency system includes a reader and a tag, and the reader and the tag perform contactless, two-way data communication via radio frequency. For example, the reader uses radio frequency to read and write to the tag.
[0081] There are three ways for a reader to read and write tags: Method 1: When the tag enters the effective recognition range of the reader, the tag receives the radio frequency signal sent by the reader and uses the energy obtained from the radio frequency signal to send information to the reader; Method 2: The tag can store some electrical energy through solar energy, wind energy, etc., so that the tag can actively send the information stored in the tag to the reader; Method 3: The tag is equipped with an active radio frequency component for transmitting data, and does not need to obtain electrical energy through solar energy, wind energy, etc., and the tag can actively send the information stored in the tag to the reader. Among them, the tag in Method 1 can be called a passive tag, the tag in Method 2 can be called a semi-passive tag or a semi-active tag, and the tag in Method 3 can be called an active tag.
[0082] Exemplarily, the above-mentioned radio frequency system may be used in the following scenarios:
[0083] 1. Warehouse / Transportation / Supplies: Tags are embedded or affixed to goods, and the tags contain relevant information about the goods. Furthermore, readers can automatically capture the relevant information from the tags, allowing managers to query the relevant information through the readers. This helps reduce the risk of goods being discarded or stolen, and improves the speed and accuracy of goods delivery, preventing cross-selling and counterfeiting.
[0084] 2. Fixed asset management: Places with large assets or valuable items, such as libraries, art galleries, and museums, require comprehensive management procedures and rigorous protection measures. These items can be labeled with relevant information. If there are any unusual changes in the storage information of these items, management personnel can be notified as soon as possible and take appropriate measures.
[0085] As shown in Figure 3, an exemplary scenario diagram of the Internet of Things provided in this application mainly includes a terminal device, a base station, an AMF, and a server. Of course, the Internet of Things scenario may also include other devices. For details, please refer to the description of the relevant embodiment of Figure 1.
[0086] In one possible example, the terminal device and the base station are equivalent to the tag and the reader in FIG2 , respectively.
[0087] A server, also known as an operation requester, is used to operate a terminal device. Specifically, a server can be an AF, SCS, AS, passive IoT application function (passive IoT AF), or other device that sends service requests. A server can belong to or be managed by a user class, which can include an enterprise, tenant, third party, or company, and this application does not limit this.
[0088] Furthermore, the server can perform different operations on the terminal device. The following are some common operations:
[0089] 1. Inventory operation (also known as inventory operation), that is, taking inventory of existing terminal devices, can also be understood as obtaining the identification of terminal devices. Each terminal device will have its own identification. The identification of the terminal device can be assigned by the enterprise or by the operator. In one possible implementation, the identification of the terminal device can be a globally unique code - such as an electronic product code (EPC), or it can be a temporary identification or an identification that is not globally unique. In the process of the inventory operation, the server can send a service request for inventory to the AMF. The service request includes an inventory range, that is, it is used to indicate which range of terminal devices needs to be inventoried. The inventory range is, for example, the identification range of the terminal device, the area range, etc. The AMF determines the identification of the terminal device within the inventory range and sends the identification of the terminal device within the inventory range to the server.
[0090] 2. Read operation, i.e. reading data from the terminal device. The terminal device may have a storage function, and the storage area of the terminal device may store data. If the server wishes to perform a read operation on the terminal device, it will send a service request for the read operation to the AMF. The AMF will perform a read operation on the terminal device based on the service request, and then the AMF will read the target data from the storage area of the terminal device and send the target data to the server. Alternatively, the AMF will instruct the base station to perform a read operation on the terminal device, and then obtain the target data read by the base station from the base station and send the target data to the server.
[0091] 3. Write operation, i.e. writing data to the terminal device. The server may send a service request for a write operation to the AMF, which includes the target data to be written to the terminal device. The AMF performs a write operation on the terminal device to write the target data to the storage area of the terminal device; alternatively, the AMF instructs the base station to perform a write operation on the terminal device to write the target data to the storage area of the terminal device.
[0092] 4. Deactivation (or invalidation) operation: This operation deactivates (or invalidates) the terminal device. The server can send a service request for deactivation to the AMF, which includes the identifier of the target terminal device. The AMF performs the deactivation operation on the target terminal device based on the service request. It is understood that after the target terminal device is deactivated, it cannot be inventoried or subjected to other operations.
[0093] FIG4 is a schematic diagram of a flow chart of a server performing an operation on a terminal device in the prior art:
[0094] Step 401: The server sends a service request to the AMF. Correspondingly, the AMF receives the service request from the server.
[0095] The service request includes an operation type and an operation scope. The operation type indicates a read operation, a write operation, or a deactivation operation, among others. The operation scope identifies the target terminal device, that is, the terminal device on which the operation is to be performed. For example, the operation scope may be one or more of the target terminal device's identifier, the target terminal device's location, or the target terminal device's group identifier, which are not limited herein.
[0096] In step 402, the AMF sends an N2 message to the base station. Accordingly, the base station receives the N2 message from the AMF.
[0097] The N2 message includes a random access indication and / or an operating range. The random access indication is used to trigger the base station to send a broadcast message to enable the target terminal device to perform random access.
[0098] Step 403: The base station sends a broadcast message according to the random access indication.
[0099] The broadcast message includes an operating range, and is used to instruct the target terminal device to establish a connection with the base station. It is understood that the broadcast message can be received by multiple terminal devices. When a terminal device determines that it is the target terminal device based on the operating range, it establishes a connection with the base station. When a terminal device determines that it is not the target terminal device based on the operating range, it does not respond or refuses to establish a connection with the base station. Furthermore, the target terminal device can be one or more, that is, each target terminal device can establish a connection with the base station and send a registration request to the AMF. The following steps 404 to 410 are explained using one target terminal device as an example, and other target terminal devices are similar.
[0100] Step 404: The target terminal device establishes a connection with the base station through random access.
[0101] In step 405, the target terminal device sends a registration request to the AMF. The AMF receives the registration request from the target terminal device. The registration request carries the target terminal device's identifier and the target terminal device's security capabilities. The target terminal device's security capabilities indicate one or more security protection algorithms that the target terminal device supports.
[0102] In this application, the security protection algorithm may include an encryption algorithm and / or an integrity protection algorithm.
[0103] In step 406, the AMF initiates an authentication process with the AUSF to implement mutual security verification between the AMF and the target terminal device. It should be understood that this authentication process involves the target terminal device, SEAF, AUSF, UDM, etc., and the target terminal device needs to transmit messages with the SEAF and generate keys. For the specific authentication process, please refer to the description of the 5G AKA process in 3GPP.
[0104] In step 407, the AMF sends a non-access stratum security mode command (NAS SMC) to the target terminal device. In response, the target terminal device receives the NAS SMC from the AMF. The NAS SMC includes the security protection algorithm selected by the AMF based on the security capabilities of the target terminal device (that is, the security protection algorithm negotiated between the AMF and the target terminal device). The NAS SMC also includes the NAS MAC, which is used by the target terminal device to verify the NAS SMC.
[0105] In step 408, after the target terminal device verifies the NAS SMC, it sends a NAS security mode command complete (SMP) to the AMF. In addition, the target terminal device and the AMF each use the security protection algorithm they negotiated as part of their respective NAS security contexts. That is, the target terminal device maintains a local NAS security context, which is used by the target terminal device to protect NAS messages transmitted between the target terminal device and the AMF. The AMF also maintains a local NAS security context, which is used by the AMF to protect NAS messages transmitted between the target terminal device and the AMF.
[0106] In step 409, the AMF sends an operation request to the target terminal device. The target terminal device receives the operation request from the AMF. The operation request includes the operation type. The operation request is specifically a NAS message, which is protected based on the NAS security contexts of the AMF and the target terminal device.
[0107] Step 410: After the target terminal device verifies the operation request and passes it, it performs the operation according to the operation type.
[0108] Optionally, the AMF also sends a registration accept to the target terminal device. Optionally, the AMF also sends a service result to the server, which carries the identifier of the target terminal device.
[0109] It should be noted that the AMF may have functions related to tag management. Alternatively, the tag management-related functions may be implemented as a separate network element, referred to as the tag management function (TMF). In other words, the AMF and TMF are deployed separately. The AMF in the embodiment of FIG. 4 can be replaced with TMF to understand the process of the server performing operations on the terminal device.
[0110] During the authentication process, the target device needs to exchange messages with SEAF to generate keys, among other things. After authentication, the target device needs to maintain the NAS security context, which consumes a significant amount of energy. Currently, 3GPP protocols have introduced the concept of ambient IoT devices. If the target device is part of the ambient IoT, it may not have sufficient energy to complete the authentication process and maintain the NAS security context.
[0111] In order to solve the above problem, the present application provides a communication method for reducing the energy consumption of a target terminal device during the process of a server performing an operation on the target terminal device. Furthermore, the target terminal device can specifically be a terminal device of the environmental Internet of Things.
[0112] The communication method can be interactively executed by a management device, a service device, and a terminal device. The management device can be a management device or a module (such as a chip) within the management device. The service device can be a server or a module (such as a chip) within the server. The terminal device can be a terminal device or a module (such as a chip) within the terminal device. Optionally, the communication method can also involve a storage device, which can be a storage device or a module (such as a chip) within the storage device.
[0113] Furthermore, the management device may specifically be a base station, AMF, or TMF. The storage device may specifically be a base station, OAM, TMF, or UDM. For the specific forms of the management device and storage device, please refer to the descriptions in the relevant embodiments of Implementations 1 to 5 below.
[0114] For ease of description, the following description uses management devices, servers, terminal devices, and storage devices as examples.
[0115] FIG5 is a flow chart of the first communication method provided by this application:
[0116] Step 501: The server sends a first service request to a management device.
[0117] Correspondingly, the management device receives the first service request from the server.
[0118] The first service request includes a first operation type and a first operation range.
[0119] The first operation type may be used to indicate a first operation. For example, if the first operation type is a read operation type, the first operation is a read operation; if the first operation type is a write operation type, the first operation is a write operation; if the first operation type is a kill operation type, the first operation is a kill operation, etc.
[0120] The first operating range is used to determine the target terminal device for performing the first operation, and the target terminal device may be one or more. Exemplarily, the first operating range includes the identifier of the target terminal device; or, the first operating range includes an identifier range, which is used to indicate that the terminal device whose identifier is within the identifier range is the target terminal device, and the identifier range is, for example, 0001 to 1000; or, the first operating range includes a group identifier (group ID), which is used to indicate that the terminal device whose group identifier is the group identifier is the target terminal device, and the group identifier is, for example, group ID1; or, the first operating range includes an area identifier, which is used to indicate that the terminal device located in the area corresponding to the area identifier is the target terminal device, and the area identifier is, for example, Pudong New Area, Shanghai. In this application, the target terminal device determined based on the first operating range may be referred to as the first terminal device.
[0121] Optionally, after step 501, the management device further determines the identifier of the first terminal device according to the first operating range.
[0122] In one specific implementation, the management device sends a first operating range. The first operating range can be received by multiple terminal devices. When a terminal device determines that it is the first terminal device based on the first operating range, it sends the first terminal device's identifier to the management device; when a terminal device determines that it is not the first terminal device based on the first operating range, it does not send the first terminal device's identifier to the management device.
[0123] Exemplarily, the first terminal device further generates a first freshness parameter and sends the first freshness parameter to the management device. The first freshness parameter may specifically be one or more of a random number, a timestamp, and a counter value.
[0124] Exemplarily, the first terminal device carries the identifier of the first terminal device and the first freshness parameter in the same message and sends it to the management device. The message may be a connection request, which is used to request to establish a connection between the first terminal device and the management device. The message may also be a registration request, which is used for the first terminal device to request to register with the management device. Alternatively, the first terminal device may carry the identifier of the first terminal device and the first freshness parameter in different messages and send them to the management device. For example, the first terminal device carries the identifier of the first terminal device in a connection request (or registration request) and carries the first freshness parameter in a subsequent uplink message.
[0125] Step 502: The management device determines a first security parameter according to the identifier of the first terminal device.
[0126] Specifically, it may include the following steps in step 502a and step 502b:
[0127] Step 502a: The management device obtains the security credentials of the first terminal device according to the identification of the first terminal device.
[0128] The security credential may specifically be a password or a key. In this application, the security credential of the first terminal device obtained by the management device based on the identification of the first terminal device may be recorded as the first security credential, the password of the first terminal device obtained may be recorded as the first password, and the key of the first terminal device obtained may be recorded as the first key.
[0129] The management device obtains the first security credential based on the identification of the first terminal device. Specifically, there are two implementation methods:
[0130] Implementation A: The management device stores a correspondence between the identifier of the first terminal device and the first security credential.
[0131] That is, the management device may determine the first security credential according to the identifier of the first terminal device and the locally stored correspondence between the identifier of the first terminal device and the first security credential.
[0132] There are two examples of how the management device stores the correspondence between the identifier of the first terminal device and the first security credential:
[0133] Example 1: The management device stores the correspondence between the identifiers of M terminal devices and M security credentials, wherein the identifiers of the terminal devices and the security credentials are in a one-to-one correspondence, the M terminal devices include the first terminal device, and M is a positive integer.
[0134] For example, M = 100, and the management device stores ID1 to ID100, as well as security credentials 1 to 100 corresponding to ID1 to ID100, respectively. For example, the data format stored in the management device is {ID1, security credential 1}, {ID2, security credential 2}, ..., {ID99, security credential 99}, {ID100, security credential 100}. ID1 to ID100 are the identifiers of terminal devices 1 to 100, respectively. Furthermore, when the identifier of the first terminal device is ID3, the management device can determine security credential 3 based on ID3.
[0135] Example 2: The management device stores the correspondence between the identifiers of M terminal devices and N security credentials, where M and N are both positive integers, and M is greater than N. That is, there is a situation where the identifiers of multiple terminal devices correspond to one security credential, and the M terminal devices include the first terminal device.
[0136] For example, M=100, N=50, and the management device stores ID1 to ID100, as well as security credential 1 corresponding to ID1 and ID2, security credential 2 corresponding to ID3 and ID4, ..., security credential 49 corresponding to ID97 and ID98, and security credential 50 corresponding to ID99 and ID100. For example, the data format stored in the management device is {{ID1, ID2}, security credential 1}, {{ID3, ID4}, security credential 2}, ..., {{ID97, ID98}, security credential 49}, {{ID99, ID100}, security credential 50}. Furthermore, when the identifier of the first terminal device is ID3 or ID4, the management device can determine security credential 2 based on ID3 or ID4.
[0137] For the convenience of description, in this application, the correspondence between the identifiers of M terminal devices and M security credentials in the management device, or the correspondence between the identifiers of M terminal devices and N security credentials, may be referred to as a correspondence. In this application, the management device is pre-configured with a correspondence, which is determined by the operator. Alternatively, the correspondence in the management device comes from a configuration device, such as an NEF, an AMF, or a server. Exemplarily, the management device receives configuration information from the configuration device, the configuration information includes a correspondence, and the management device saves the correspondence. The configuration process may occur before step 502.
[0138] Implementation B: The storage device stores a correspondence between the identifier of the first terminal device and the first security credential. The management device requests the first security credential from the storage device according to the identifier of the first terminal device.
[0139] Exemplarily, the management device sends the identifier of the first terminal device to the storage device. The storage device determines the first security credential based on the identifier of the first terminal device and the locally stored correspondence between the identifier of the first terminal device and the first security credential. The storage device sends the first security credential to the management device. Exemplarily, the management device sends a security credential request to the storage device, the security credential request including the identifier of the first terminal device; and the storage device sends a security credential response to the management device, the security credential response including the first security credential.
[0140] Exemplarily, a management device is connected to multiple storage devices, and the management device selects a target storage device from the multiple storage devices, and then requests the first security credential from the target storage device. When the management device selects the target storage device, specifically, the following examples a and b may be used:
[0141] In Example a, different storage devices correspond to different routing information. The identifier of the first terminal device includes first routing information, which is used to indicate a target storage device among multiple storage devices. Accordingly, the management device obtains the first routing information from the identifier of the first terminal device and selects a target storage device from the multiple storage devices based on the first routing information and the routing information corresponding to each of the multiple storage devices.
[0142] For example, routing information is 3-bit indication information, routing information 000 corresponds to storage device 0, routing information 001 corresponds to storage device 1, etc. When the first routing information obtained by the management device from the identifier of the first terminal device is 000, it is determined that storage device 0 is the target storage device, and the first security credential is requested from storage device 0; when the first routing information obtained by the management device from the identifier of the first terminal device is 001, it is determined that storage device 1 is the target storage device, and the first security credential is requested from storage device 1, etc.
[0143] In example b, the management device stores a binding relationship between the terminal device identifier and the storage device identifier. The management device can select a target storage device from multiple storage devices based on the first terminal device identifier and the binding relationship between the terminal device identifier and the storage device identifier.
[0144] For example, the management device stores IDs 1 to 100, including ID 1 of storage device 1, which is bound to ID 1 and ID 50, and ID 2 of storage device 2, which is bound to ID 51 and ID 100. When the management device determines that the ID of the first terminal device is ID 5, it determines that storage device 1 is the target storage device and requests the first security credential from storage device 1. When the management device determines that the ID of the first terminal device is ID 54, it determines that storage device 2 is the target storage device and requests the first security credential from storage device 2, etc.
[0145] In one possible example, the storage device stores correspondences between M terminal device identifiers and M security credentials, where the terminal device identifiers and security credentials are in a one-to-one correspondence, and M is a positive integer. In another possible example, the storage device stores correspondences between M terminal device identifiers and N security credentials, where multiple terminal device identifiers correspond to one security credential, M and N are both positive integers, and M is greater than N. For details, see the description of managing device storage correspondences in Implementation A above.
[0146] For the convenience of description, in this application, the correspondence between the identifiers of M terminal devices and M security credentials in the storage device, or the correspondence between the identifiers of M terminal devices and N security credentials, may also be referred to as a correspondence. In this application, the storage device is pre-configured with a correspondence, which is determined by the operator. Alternatively, the correspondence in the storage device comes from a configuration device, such as an NEF, an AMF, or a server. Exemplarily, the storage device receives configuration information from the configuration device, the configuration information includes a correspondence, and the storage device saves the correspondence. The configuration process may occur before step 502.
[0147] Step 502b: The management device determines a first security parameter according to the security credential of the first terminal device (ie, the first security credential).
[0148] In a first implementation, the first security credential is specifically a first password, and the management device uses the first password as a first security parameter, or uses a portion of the first password as the first security parameter.
[0149] In a second implementation, the first security credential is specifically a first password or a first key. The management device determines the first security parameter according to the first security credential and the first freshness parameter.
[0150] Specific examples include the following: Example 1: The management device performs an XOR operation on the first password and the first freshness parameter to obtain the first security parameter; Example 2: The management device combines the first password and the first freshness parameter to obtain a string, and then performs a hash calculation on the string to obtain the first security parameter; Example 3: The management device inputs the first key and the first freshness parameter into a security protection algorithm to obtain the first security parameter. Of course, the first password in Examples 1 to 3 above can also be replaced with a portion of the first password.
[0151] Among them, the first freshness parameter can be generated by the first terminal device and sent to the management device (see description in step 501), or generated by the management device itself. When the management device generates the first freshness parameter, the management device may also send the first freshness parameter to the first terminal device. Exemplarily, the first freshness parameter may be carried in the first operation request of the following step 503. In the above example 1, the management device may receive the first freshness parameter from the first terminal device, thereby avoiding the first freshness parameter and the first security parameter being included in one message, causing the leakage of the first password; in the above example 2 or example 3, the management device may receive the first freshness parameter from the first terminal device, or the management device may generate the first freshness parameter by itself and send the first freshness parameter to the first terminal device.
[0152] Step 503: The management device sends a first operation request to the first terminal device.
[0153] Correspondingly, the first terminal device receives the first operation request from the management device.
[0154] The first operation request includes a first operation type and a first security parameter, and the first security parameter is used to perform a security check on the network. Exemplarily, the first security parameter is used by the first terminal device to perform a security check on the network.
[0155] In one possible embodiment, the first operation request further includes a first operation parameter. Exemplarily, when the first operation indicated by the first operation type is a write operation, the first operation parameter is target data to be written to the storage area of the first terminal device; when the first operation indicated by the first operation type is a read operation, the first operation parameter is a query field used to query the target data in the storage area of the first terminal device.
[0156] Step 504: The first terminal device determines that the network passes the security check based on the first security parameter.
[0157] Furthermore, when the first terminal device determines that the network has passed the security check based on the first security parameter, the first terminal device performs the first operation; when the first terminal device determines that the network has not passed the security check based on the first security parameter, the first terminal device does not perform the first operation.
[0158] In one possible approach, the first terminal device stores the security credentials of the first terminal device. The first terminal device determines whether the network has passed the security verification based on the first security parameter. Specifically, the first terminal device determines whether the network has passed the security verification based on the first security parameter and the security credentials stored by the first terminal device. Exemplarily, the first terminal device determines the security credentials obtained by the management device based on the first security parameter. If it is determined that the security credentials obtained by the management device are the same as the security credentials stored by the first terminal device, the network is considered to have passed the security verification; if it is determined that the security credentials obtained by the management device are different from the security credentials stored by the first terminal device, the network is considered to have failed the security verification. In another exemplary embodiment, the first terminal device determines a security parameter (referred to as security parameter A) based on the security credentials stored by the first terminal device. If the first terminal device determines that security parameter A is the same as the first security parameter, the security credentials obtained by the management device are determined to be the same as the security credentials stored by the first terminal device, and the network is considered to have passed the security verification; if the first terminal device determines that security parameter A is different from the first security parameter, the security credentials obtained by the management device are determined to be different from the security credentials stored by the first terminal device, and the network is considered to have failed the security verification.
[0159] The first terminal device stores the security credentials of the first terminal device. Specifically, there are two examples as follows: Example (A): The first terminal device is pre-configured with the security credentials of the first terminal device. For example, before the first terminal device leaves the factory, the operator burns the security credentials of the first terminal device into the storage area of the first terminal device. Example (B): The security credentials of the first terminal device come from a configuration device. The configuration device is, for example, an NEF, an AMF, or a server. For example, the first terminal device receives configuration information from the configuration device, and the configuration information includes the security credentials of the first terminal device. The configuration process may occur before step 504. Optionally, the first terminal device also stores an identifier of the first terminal device. The configuration method of the identifier of the first terminal device is similar to the configuration method of the security credentials of the first terminal device.
[0160] The security credential may specifically be a password or a key. In this application, the security credential of the first terminal device stored in the first terminal device may be referred to as security credential one, the password of the first terminal device stored in the first terminal device may be referred to as password one, and the key of the first terminal device stored in the first terminal device may be referred to as key one.
[0161] The following examples provide two specific implementations of the first terminal device determining whether the network passes the security verification based on the first security parameter and the first security credential:
[0162] The first implementation method corresponds to the first implementation method in step 502b.
[0163] The first security credential is specifically the first password, and the first security credential is specifically the first password.
[0164] In the case where the first security parameter is the first password, if the first terminal device determines that the first security parameter is the same as password one, it is determined that the network has passed the security verification (i.e., the verification is successful); if the first terminal device determines that the first security parameter is different from password one, it is determined that the network has not passed the security verification (i.e., the verification failed); in the case where the first security parameter is a partial password in the first password, if the first terminal device determines that the first security parameter is the same as the partial password in password one, it is determined that the network has passed the security verification; if the first terminal device determines that the first security parameter is different from the partial password in password one, it is determined that the network has passed the security verification.
[0165] It is understood that the management device also stores a target position (referred to as the first target position), which is used to instruct the management device to select bits x1 to x2 in the first password as the first security parameter when using a portion of the first password as the first security parameter, where x1 and x2 are positive integers. Similarly, the first terminal device also stores a target position (referred to as target position one). When the first terminal device determines whether the first security parameter is the portion of the password in password one, it also determines whether the first security parameter is the same as the portion of the password in password one based on target position one, that is, whether the first security parameter is the same as bits x1' to x2' in password one, where x1' and x2' are positive integers.
[0166] For example, the method for configuring the target location 1 in the first terminal device can refer to the method for configuring the security credential 1 in the first terminal device. The method for configuring the first target location in the management device can refer to the method for configuring the corresponding relationship in the management device. Of course, the first target location can also be configured in the storage device. The method for configuring the first target location in the storage device can refer to the method for configuring the corresponding relationship in the storage device. The management device can obtain not only the first security credential from the storage device, but also the first target location from the storage device.
[0167] The second implementation method corresponds to the second implementation method in step 502b.
[0168] The first security credential is specifically a first password, and the first security credential is specifically password 1. Alternatively, the first security credential is specifically a first key, and the first security credential is specifically key 1. The first security parameter is determined based on the first security credential and the first freshness parameter.
[0169] The first terminal device determines whether the network passes the security verification (i.e., the verification succeeds or fails) based on the first security credential, the first freshness parameter, and the first security parameter. Specific examples include the following:
[0170] In example (1), the first terminal device performs an XOR operation on the first security parameter and the first freshness parameter to obtain a result (equivalent to the first password obtained by the management device). If the first terminal device determines that the obtained result is the same as password one, it determines that the network has passed the security check; if the first terminal device determines that the obtained result is different from password one, it determines that the network has not passed the security check.
[0171] In example (2), the first terminal device combines the password 1 and the first freshness parameter to obtain a character string, and then performs a hash calculation on the character string to obtain a result (equivalent to the security parameter A determined by the first terminal device). When the first terminal device determines that the obtained result is the same as the first security parameter, it determines that the network has passed the security verification; when the first terminal device determines that the obtained result is different from the first security parameter, it determines that the network has not passed the security verification.
[0172] In example (3), the first terminal device inputs key 1 and the first freshness parameter into the security protection algorithm to obtain a result (equivalent to the security parameter A determined by the first terminal device). When the first terminal device determines that the obtained result is the same as the first security parameter, it determines that the network has passed the security verification; when the first terminal device determines that the obtained result is different from the first security parameter, it determines that the network has not passed the security verification.
[0173] In this application, "same" can be replaced by "matching", "matching", "equal", etc. The first and second implementations above are merely examples of possible ways for the first terminal device to determine whether the network has passed the security check based on the first security parameter. Of course, this application may also include other possible ways, which will not be listed one by one.
[0174] Step 505: The first terminal device performs a first operation.
[0175] For example, when the first operation indicated by the first operation type is a write operation, the first terminal device may write the target data to the storage area of the first terminal device based on the target data in the first operation request. When the first operation indicated by the first operation type is a read operation, the first terminal device may query the target data from the storage area of the first terminal device based on the query field in the first operation request. When the first operation indicated by the first operation type is a kill operation, the first terminal device performs the kill operation.
[0176] It should be noted that in step 504 above, the first terminal device performs a network security check based on the first security parameter. To further enhance security, the management device may also perform a security check on the first terminal device. In one possible example, the first terminal device determines security parameter one based on security credential one and freshness parameter one, and sends security parameter one to the management device.
[0177] Specifically, there are the following examples (a) and (b):
[0178] In example (a), the first security credential is specifically the first password, and security credential one is specifically password one. The first terminal device combines password one with freshness parameter one to obtain a string, then performs a hash calculation on the string to obtain security parameter one. The first terminal device sends security parameter one to the management device. Accordingly, the management device combines the first password and freshness parameter one to obtain a string, then performs a hash calculation on the string to obtain a result. If the management device determines that the obtained result is the same as security parameter one, it determines that the first terminal device has passed the security verification; if the management device determines that the obtained result is different from security parameter one, it determines that the first terminal device has failed the security verification.
[0179] In example (b), the first security credential is specifically the first key, and security credential one is specifically key one. The first terminal device inputs key one and freshness parameter one into the security protection algorithm to obtain security parameter one, and the first terminal device sends security parameter one to the management device. Accordingly, the management device inputs the first key and freshness parameter one into the security protection algorithm to obtain a result. If the management device determines that the obtained result is the same as security parameter one, the management device determines that the first terminal device has passed the security verification; if the management device determines that the obtained result is different from security parameter one, the management device determines that the first terminal device has failed the security verification.
[0180] The freshness parameter 1 may be the first freshness parameter, or may be different from the first freshness parameter. The freshness parameter 1 may be generated by the first terminal device and sent to the management device, or may be generated by the management device and sent to the first terminal device.
[0181] Of course, the password one in the above examples (a) to (b) can also be replaced by part of the password one.
[0182] Optionally, when the management device determines that the first terminal device fails the security check, the first terminal device is determined to be an untrusted terminal device, and subsequent operations may not be performed on the first terminal device, or the first terminal device may be removed from the target terminal devices.
[0183] Step 506: The first terminal device sends the first operation result to the management device.
[0184] Correspondingly, the management device receives the first operation result from the first terminal device.
[0185] The first operation result is used to indicate the operation status of the first terminal device for the first operation. The operation status of the first terminal device for the first operation is operation success or operation failure. That is, the first operation result is used to indicate whether the first terminal device successfully performs the first operation. For example, when the first terminal device determines that the network has passed the security verification based on the first security parameter, the first operation result is specifically operation success; when the first terminal device determines that the network has not passed the security verification based on the first security parameter, the first operation result is specifically operation failure.
[0186] Alternatively, the first operation result indicates whether the network has passed security verification. For example, when the first terminal device determines, based on the first security parameter, that the network has passed security verification, the first operation result is specifically a verification success; when the first terminal device determines, based on the first security parameter, that the network has failed security verification, the first operation result is specifically a verification failure. A successful verification is equivalent to a successful operation, while a failed verification is equivalent to a failed operation. For ease of description, the following uses successful and failed operations as examples.
[0187] The first terminal device can be one or more. In one example, each first terminal device sends a first operation result (i.e., operation success or operation failure) to the management device. In another example, the first terminal device whose operation is successful sends the first operation result (i.e., operation success) to the management device, while the first terminal device whose operation fails does not send the first operation result (i.e., operation failure) to the management device. In another example, the first terminal device whose operation fails sends the first operation result (i.e., operation failure) to the management device, while the first terminal device whose operation is successful does not send the first operation result (i.e., operation success) to the management device.
[0188] Furthermore, when the first operation is a write operation, the first terminal device may further send a storage location to the management device. The storage location is specifically the storage location where the target data is written to the storage area of the first terminal device. Exemplarily, the first operation result and the storage location are included in a single message, such as a first operation response. When the first operation indicated by the first operation type is a read operation, the first terminal device may further send the target data to the management device. Exemplarily, the first operation result and the target data are included in a single message, such as a first operation response.
[0189] Step 507: The management device sends the first service result to the server.
[0190] Correspondingly, the server receives the first service result from the management device.
[0191] Exemplarily, before the management device sends the first service result to the server, it generates a first service result based on the first operation result of each first terminal device (i.e., operation success or operation failure). For example, the management device receives the operation success or operation failure of each first terminal device and generates the first service result; or, based on the operation success of one or more first terminal devices, determines the first operation result of each first terminal device and then generates the first service result; or, based on the operation failure of one or more first terminal devices, determines the first operation result of each first terminal device and then generates the first service result. Here, the management device can obtain the identification of the first terminal device in the above step 501, and even if the management device only receives the first operation results of some of the first terminal devices, the management device can still generate the first service result.
[0192] The first service result is used to indicate the operational status of each first terminal device for the first operation. The first service result can be expressed in various forms: Example A: The first service result includes Service Result 1 and / or Service Result 2, where Service Result 1 includes the identifier of the first terminal device that successfully performed the first operation, and Service Result 2 includes the identifier of the first terminal device that failed the first operation. Example B: The first service result includes the identifier of the first terminal device and the operational status of the first terminal device for the first operation.
[0193] Furthermore, the server receives the first service result from the management device. Optionally, the server maintains historical service results, and the server can update the historical service results according to the first service result from the management device.
[0194] In one possible example, the historical service results include identifiers of one or more terminal devices and the operating status of the one or more terminal devices. For example, each terminal device may have one or more operating statuses, i.e., different operation types correspond to different operating statuses, such as write success or write failure for a write operation, read success or read failure for a read operation, and kill success or kill failure for a kill operation.
[0195] Furthermore, each operation status can also correspond to an operation time. For example, the historical service results include the identifiers ID1 to ID5 for terminal devices 1 to 5. Terminal device 1 sequentially performed a write operation and a deactivation operation. The operation status corresponding to ID1 is write success and deactivation success. Write success corresponds to operation time t1, and deactivation success corresponds to operation time t2, where t1 is earlier than t2. Terminal devices 2 and 3 performed a read operation. The operation status corresponding to ID2 and ID3 is read success, and read success corresponds to operation time t3. Terminal devices 4 and 5 did not perform any operation, that is, the operation status corresponding to ID4 and ID5 is null.
[0196] Furthermore, the first service result received by the server includes "ID2 and ID3, and the operation status (deactivation success) and operation time (t4) corresponding to ID2 and ID3 respectively". Then, the server can update the historical service result according to the first service result, and obtain that the operation status corresponding to ID2 and ID3 is read success, the operation time is t3, and the operation status is deactivation success, and the operation time is t4.
[0197] Alternatively, the storage device may maintain historical service results, and the management device may further send a first service result to the storage device, where the first service result indicates the operating status of the first terminal device for the first operation, and the storage device may update the local historical service results based on the first service result. Optionally, the management device may store the first service result; or, after sending the first service result to the server or to the storage device, the management device may delete the locally stored first service result.
[0198] It should be added that step 506 and step 507 are optional steps. In one possible example, after the first terminal device performs the first operation, the present process ends; or, when the first terminal device determines that the network has not passed the security check, the present process ends. In another possible example, after the first terminal device performs the first operation, or when the first terminal device determines that the network has not passed the security check, the first terminal device does not send the first operation result to the management device, and the management device sends the first service result to the server based on the first operation request sent to the first terminal device. Exemplarily, after sending the first operation request to the first terminal device, the management device deems that the operation of the first terminal device is successful. Furthermore, the management device generates the first service result based on the identifier of the first terminal device that successfully performed the operation. This method helps to reduce the energy consumption of the first terminal device. At this time, it is only necessary to limit step 507 to occur after step 503.
[0199] When the first operation indicated by the first operation type is a write operation, the management device may further send a storage location to the server. The storage location is specifically the storage location where the target data is written to the storage area of the first terminal device. Exemplarily, the first service result and the storage location are included in a single message, such as a first service response. When the first operation indicated by the first operation type is a read operation, the management device may further send the target data to the server. Exemplarily, the first service result and the target data are included in a single message, such as a first service response.
[0200] It should be noted that, in the scenario where the first operation is a deactivation operation, the following situations 1 to 3 may result in the first terminal device being recorded as successfully deactivated despite not being successfully deactivated. In situation 1, a pseudo-base station or pseudo-terminal device may impersonate the first terminal device and send an operation success message to the management device. In situation 2, the first terminal device may send an operation success message to the management device after successfully verifying the network but failing to perform the deactivation operation. In situation 3, the management device considers the first terminal device's operation successful after sending the first operation request to the first terminal device.
[0201] To this end, this application provides the following method (1) and method (2) to solve the above problems.
[0202] In method (1), the management device identifies, based on subsequent operations, a first terminal device whose operation status is that the deactivation is successful but the deactivation actually fails, and instructs the first terminal device to re-perform the deactivation operation. See FIG6 for an exemplary flow diagram of the second communication method.
[0203] Method (2): The server identifies the first terminal device whose operation status is successful but actually failed to be deactivated based on subsequent operations, and instructs the first terminal device to re-perform the deactivation operation. See the flowchart of the third communication method provided in Figure 7.
[0204] It can be understood that the second communication method and the third communication method are two parallel schemes. Optionally, the second communication method or the third communication method occurs after the first communication method.
[0205] To facilitate description and understanding of this solution, the first operation type is referred to as the inactivation operation type, and the first operation is referred to as the inactivation operation.
[0206] FIG6 is a flow chart of the second communication method exemplarily provided in this application:
[0207] Step 601: The server sends a second service request to the management device. Correspondingly, the management device receives the second service request from the server.
[0208] The second service request includes a second operation type and a second operation range.
[0209] The second operation type is the same as or different from the deactivation operation type. The second operation type may be used to indicate a second operation. For example, if the second operation type is a read operation type, the second operation is a read operation; if the second operation type is a write operation type, the second operation is a write operation; if the second operation type is a deactivation operation type, the second operation is a deactivation operation, etc.
[0210] The second operating scope is used to determine the target terminal device for executing the second operation, which may be one or more target terminal devices. Exemplarily, the second operating scope includes the identifier of the target terminal device; or the second operating scope includes an identifier range, indicating that terminal devices whose identifiers are within the identifier range are target terminal devices; or the second operating scope includes a group identifier, indicating that terminal devices whose group identifiers are the group identifiers are target terminal devices; or the second operating scope includes an area identifier, indicating that terminal devices within the area corresponding to the area identifier are target terminal devices. The second operating scope may be the same as or different from the first operating scope.
[0211] In this application, the target terminal device determined based on the second operating range may be referred to as a second terminal device.
[0212] Optionally, after step 601, the management device obtains the identifier of the second terminal device according to the second operating range.
[0213] In a specific implementation, the management device sends a second operating range. The second operating range can be received by multiple terminal devices. When a terminal device determines that it is a second terminal device based on the second operating range, the identifier of the second terminal device is sent to the management device; when a terminal device determines that it is not a second terminal device based on the second operating range, the identifier of the second terminal device is not sent to the management device. Optionally, the second terminal device also generates a second freshness parameter and sends the second freshness parameter to the management device. Optionally, the second terminal device may carry the identifier of the second terminal device and the second freshness parameter in the same message and send it to the management device. The message may be a connection request or a registration request. Alternatively, the second terminal device may carry the identifier of the second terminal device and the second freshness parameter in different messages and send them to the management device. For a specific implementation, please refer to the description in step 501 about the management device obtaining the identifier of the first terminal device based on the first operating range.
[0214] Step 602: The management device determines the third terminal device that failed to be deactivated based on the identifier of the second terminal device and the first service result.
[0215] The third terminal device meets condition 1, where the operational status of the third terminal device recorded in the first service result includes successful deactivation; and meets condition 2, where the management device obtains the identifier of the third terminal device in step 602. In other words, the third terminal device is the intersection of the first and second terminal devices. To explain, assuming a terminal device has already been successfully deactivated in the embodiment related to FIG5 , the management device will not obtain the identifier of the second terminal device when obtaining the identifier of the second terminal device based on the second operational range. For example, when the management device sends the second operational range, the terminal device that has already been successfully deactivated cannot receive the second operational range and will not send the identifier of the terminal device to the management device. Based on the above analysis, it can be seen that once the management device determines that the operational status of a terminal device in the first service result includes successful deactivation, and then sends the terminal device's identifier to the management device, it indicates that the operational status (successful deactivation) of the terminal device indicated by the first service result is incorrect. The determined terminal device is the third terminal device.
[0216] The third terminal device can be one or more. For example, the first service result includes ID1, ID2, and ID3; and the operation statuses corresponding to ID1, ID2, and ID3 all indicate successful deactivation, which means that the first terminal device is the terminal device corresponding to ID1, ID2, and ID3. After step 601, the management device determines that the second terminal device includes the terminal devices corresponding to ID2, ID3, and ID4, which means that the second terminal device performing the second operation determined based on the second operation range is the terminal device corresponding to ID2, ID3, and ID4. The intersection of the first terminal device and the second terminal device (that is, the third terminal device): the terminal devices corresponding to ID2 and ID3 are the ones for which the first operation (deactivation) failed.
[0217] Based on whether the first service result is stored in the management device, the following implementations are divided into implementation mode a and implementation mode b:
[0218] Implementation a: When the management device stores the first service result, if the management device determines that the operation status corresponding to the identifier of the second terminal device recorded in the first service result includes successful deactivation, the management device determines that the second terminal device is the third terminal device.
[0219] In implementation b, if the management device does not store the first service result, the management device sends the identifier of the second terminal device to the server. If the server determines that the operation status corresponding to the identifier of the second terminal device recorded in the historical service results includes successful deactivation, the server sends Instruction 1 to the management device. Instruction 1 is used to indicate that the second terminal device is a third terminal device. Alternatively, the present application may include the management device sending the identifier of the second terminal device to a storage device, and the storage device sending Instruction 1 to the management device based on the identifier of the second terminal device and the historical service results. For specific implementation, see the previous description of the server sending Instruction 1 to the management device.
[0220] In addition, the management device may not determine the third terminal device that failed to be deactivated based on the identifier of the second terminal device and the first service result, that is, the operating status corresponding to the identifier of the second terminal device received by the management device in the first service result does not include successful deactivation.
[0221] Step 603: The management device sends a second operation request to the third terminal device.
[0222] Correspondingly, the third terminal device receives the second operation request from the management device.
[0223] The second operation request includes a deactivation operation type. It is understood that the second operation request is specifically used to deactivate the third terminal device. This deactivation operation type may be different from the second operation type in step 601. The second operation request in steps 603 to 606 may also be referred to as a deactivation operation request, the second operation result as a deactivation operation result, and the second service result as a deactivation service result.
[0224] When there are multiple third terminal devices, the management device may send the second operation request to each of the multiple third terminal devices.
[0225] Optionally, the management device may also determine a second security parameter based on the identifier of the third terminal device, and include the second security parameter in the second operation request. The second security parameter is used to verify the network. Exemplarily, the second security parameter is used by the third terminal device to verify the network. Accordingly, the third terminal device receives the second operation request from the management device, and performs a security verification on the network based on the second security parameter in the second operation request. After determining that the network has passed the security verification, the third terminal device performs a deactivation operation. For details, please refer to the description in steps 502 to 505 above. The "first terminal device" in steps 502 to 505 above can be replaced with "third terminal device", the "first security parameter" can be replaced with "second security parameter", and the "first operation request" can be replaced with "second operation request".
[0226] Step 604: The third terminal device performs a deactivation operation.
[0227] Step 605: The third terminal device sends the second operation result to the management device.
[0228] Correspondingly, the management device receives the second operation result from the third terminal device.
[0229] The second operation result is used to indicate the operation status of the deactivation operation by the third terminal device, wherein the operation status of the deactivation operation by the third terminal device is deactivation success or deactivation failure. Alternatively, the second operation result is used to indicate whether the third terminal device determines that the network has passed the security check.
[0230] When there are multiple third terminal devices, each third terminal device sends the second operation result (i.e., inactivation success or inactivation failure) to the management device. Alternatively, a third terminal device that successfully inactivates sends the second operation result (i.e., inactivation success) to the management device, while a third terminal device that fails in inactivation does not send the second operation result (i.e., inactivation failure) to the management device. Alternatively, a third terminal device that fails in inactivation sends the second operation result (i.e., inactivation failure) to the management device, while a third terminal device that successfully inactivates does not send the second operation result (i.e., inactivation success) to the management device.
[0231] Step 606: The management device sends the second service result to the server.
[0232] Correspondingly, the server receives the second service result from the management device.
[0233] Exemplarily, the management device generates a second service result according to the second operation result of each third terminal device (ie, inactivation success or inactivation failure), and sends the second service result to the server.
[0234] The second service result is used to indicate the operational status of each third terminal device for the deactivation operation. The second service result includes service result 3 and / or service result 4. Service result 3 includes the identifier of the third terminal device for which deactivation was successful, and service result 4 includes the identifier of the third terminal device for which deactivation failed. Alternatively, the second service result includes the identifier of the third terminal device and the operational status of the third terminal device (i.e., deactivation success or failure). For an explanation of the second service result, refer to the description of the first service result above.
[0235] Optionally, the server maintains historical service results, and the server may also update the historical service results according to the second service result from the management device. Specific implementation can refer to the description in step 507 above.
[0236] It should be noted that steps 605 and 606 are optional steps. In one possible example, after the third terminal device performs the deactivation operation, the present process ends; or, when the third terminal device determines that the network has not passed the security check, the present process ends. In another possible example, after the third terminal device performs the deactivation operation, or when the third terminal device determines that the network has not passed the security check, the third terminal device does not send the second operation result to the management device, and the management device sends the second service result to the server based on the second operation request sent to the third terminal device. Exemplarily, after sending the second operation request to the third terminal device, the management device deems that the third terminal device has been successfully deactivated. Furthermore, the management device generates the second service result based on the identifier of the third terminal device that has been successfully deactivated. This method helps to reduce energy consumption of the third terminal device.
[0237] Furthermore, it should be noted that step 602 can also be considered as the management device obtaining the identifier of each second terminal device and determining, based on the identifier of the second terminal device and the first service result, whether the second terminal device is a third terminal device. Specifically, the management device determines whether the operating status of the second terminal device in the first service result includes a successful deactivation. If the management device determines that the second terminal device is a third terminal device, it determines that the second terminal device needs to be reactivated, and then proceeds to step 603.
[0238] When the management device determines that there is no need to reactivate the second terminal device, the management device can determine the second security parameter based on the identifier of the second terminal device and send a second operation request to the second terminal device. The second operation request includes the second operation type and the second security parameter in step 601. The second terminal device receives the second operation request, determines that the network has passed the security check based on the second security parameter, and then performs the second operation. Optionally, the second terminal device also sends the second operation result to the management device. Optionally, the management device also sends the second service result to the server. This implementation method can be understood by referring to the description in steps 502 to 507 above, and "first" can be replaced with "second".
[0239] In the embodiment related to Figure 6 above, the management device identifies the third terminal device that failed to be deactivated, and then instructs the third terminal device to re-perform the deactivation operation, thereby improving the success rate of deactivation and preventing some terminal devices that should have been deactivated but were not actually deactivated from interfering with the operation process of the entire Internet of Things system.
[0240] FIG7 is a flow chart of the third communication method exemplarily provided in this application:
[0241] Step 701: The server sends a second service request to the management device. Correspondingly, the management device receives the second service request from the server.
[0242] Step 702: The management device determines a second security parameter according to the identifier of the second terminal device.
[0243] Step 703: The management device sends a second operation request to the second terminal device. The second operation request includes a second operation type and a second security parameter. The second security parameter is used to perform security verification on the network.
[0244] Step 704: The second terminal device determines that the network passes the security check based on the second security parameter.
[0245] Step 705: The second terminal device performs a second operation.
[0246] Step 706: The second terminal device sends the second operation result to the management device. Correspondingly, the management device receives the second operation result from the second terminal device.
[0247] Step 707: The management device sends the second service result to the server. Correspondingly, the server receives the second service result from the management device.
[0248] For details not described in step 701 to step 707, please refer to the description of the above steps 501 to step 507. "First" can be replaced with "second" for better understanding.
[0249] In this embodiment, steps 706 and 506 are optional, while steps 707 and 507 are mandatory. That is, the first terminal device may not need to send the first operation result to the management device, and / or the second terminal device may not need to send the second operation result to the management device, but the management device needs to send the first service result and the second service result to the server.
[0250] Step 708: The server determines the third terminal device that failed to be deactivated based on the first service result and the second service result.
[0251] The third terminal device meets condition a, and the operating status of the third terminal device recorded in the first service result includes successful deactivation; and meets condition b, and the operating status of the third terminal device is recorded in the second service result. That is, the third terminal device is the intersection of the first and second terminal devices. To explain, assuming a terminal device has already been successfully deactivated in the embodiment related to Figure 5, the management device will not obtain the terminal device's identifier when obtaining the terminal device's identifier based on the second operating range. The management device will not send a second operation request to the terminal device, nor will it receive the second operation result of the terminal device, nor send a second service result to the server based on the second operation result of the terminal device. Based on the above analysis, it can be seen that once the server determines that the operating status of a terminal device in the first service result includes successful deactivation, and the second service result also includes the operating status of the terminal device, it indicates that the operating status of the terminal device indicated by the first service result (successful deactivation) is incorrect. The terminal device thus determined is the third terminal device.
[0252] In a specific implementation, the server stores the first service result and the second service result. When the server determines a terminal device that meets the above conditions a and b based on the first service result and the second service result, the terminal device is used as the third terminal device.
[0253] The third terminal device can be one or more. For example, the first service result includes ID1, ID2, and ID3; and the operation statuses corresponding to ID1, ID2, and ID3 all indicate successful deactivation, that is, the first terminal device is the terminal device corresponding to ID1, ID2, and ID3 respectively. The second service result includes ID2, ID3, and ID4; and the operation statuses corresponding to ID2, ID3, and ID4 all indicate successful write, that is, the second terminal device performing the second operation is the terminal device corresponding to ID2, ID3, and ID4 respectively. The intersection of the first terminal device and the second terminal device (that is, the third terminal device): the terminal devices corresponding to ID2 and ID3 are the terminal devices whose first operation (deactivation) failed.
[0254] Step 709: The server sends a third service request to the management device. Correspondingly, the management device receives the third service request from the server. The third service request includes the identifier of the third terminal device and the deactivation operation type.
[0255] It can be understood that the difference between the third service request and the first service request (or the second service request) is that the third service request can directly carry the identifier of the third terminal device, and thus the management device can obtain the identifier of the third terminal device without sending the operation range.
[0256] Step 710: The management device sends a third operation request to the third terminal device, where the third operation request includes a deactivation operation type.
[0257] There may be one or more third terminal devices, and the management device may send a third operation request to the one or more third terminal devices respectively.
[0258] Optionally, the management device may also determine a third security parameter based on the identifier of the third terminal device, and include the third security parameter in the third operation request. The third security parameter is used to verify the network. Exemplarily, the third security parameter is used by the third terminal device to verify the network. Accordingly, the third terminal device receives the third operation request from the management device, performs a security verification on the network based on the third security parameter in the third operation request, and after determining that the network has passed the security verification, the third terminal device performs a deactivation operation. For details, please refer to the description in steps 502 to 505 above. The "first terminal device" in steps 502 to 505 above can be replaced with "third terminal device", the "first security parameter" can be replaced with "third security parameter", and the "first operation request" can be replaced with "third operation request".
[0259] Step 711: The third terminal device performs a deactivation operation.
[0260] Step 712: The third terminal device sends the third operation result to the management device.
[0261] Correspondingly, the management device receives the third operation result from the third terminal device.
[0262] Step 713: The management device sends the third service result to the server.
[0263] Among them, the content not described in detail in step 712 and step 713 can be understood by referring to the description in step 605 and step 606, and the "second operation result" can be replaced by the "third operation result" and the "second service result" can be replaced by the "third service result".
[0264] In the embodiment related to Figure 7 above, the server identifies the third terminal device that failed to be deactivated, and then instructs the third terminal device to re-perform the deactivation operation, thereby improving the success rate of deactivation and preventing some terminal devices that should have been deactivated but were not actually deactivated from interfering with the operation process of the entire Internet of Things system.
[0265] In the embodiments related to Figures 5 to 7 above, the management device can specifically be a base station, AMF, or TMF. The storage device is optional and can specifically be a base station, OAM, TMF, or UDM. The following examples provide various forms of management devices (or management devices and storage devices), as well as specific implementations of each form as applied to Figure 5. The following description focuses on the differences from the embodiment related to Figure 5. For any content not described in the following embodiments, refer to the description of the embodiment related to Figure 5 above.
[0266] Furthermore, the difference between Figure 6 (or Figure 7) and Figure 5 is that Figure 6 (or Figure 7) operates on the second terminal device (or third terminal device), and the "first terminal device" in the following embodiments can be replaced with "second terminal device (or third terminal device)" to understand the specific implementation method of each specific form applied to Figure 6 (or Figure 7).
[0267] In implementation method 1, the management device is a base station and there is no storage device.
[0268] Exemplarily, the base station can also be considered as the reader in FIG. 2 , and the terminal device can be considered as the tag in FIG. 2 .
[0269] In step 501, the server sends a first service request to the base station. Specifically, the server may send the first service request to the base station via the UPF. Alternatively, the server may send the first service request to the base station via the UPF, SMF, and AMF in sequence. In step 507, the base station sends the first service result to the server in a similar manner as in step 501, except that the message is transmitted in a different direction.
[0270] In the above step 501, the base station obtains the identification of the first terminal device according to the first operating range. Specifically, it can be divided into steps a and b:
[0271] In step a, the base station sends a broadcast message. Exemplarily, the broadcast message may be a selection command message. The broadcast message includes a first operating range and is used to instruct the first terminal device to establish a connection with the base station. It will be understood that when the base station sends a broadcast message, the broadcast message may be received by multiple terminal devices. When a terminal device determines that it is the first terminal device based on the first operating range, it establishes a connection with the base station. When a terminal device determines that it is not the first terminal device based on the first operating range, it does not respond or refuses to establish a connection with the base station.
[0272] Step b: The first terminal device sends an identifier of the first terminal device to the base station, and establishes a connection with the base station through a random access method.
[0273] In the above step 502, the base station determines the first security parameter based on the identifier of the first terminal device. Specifically, the base station may store the correspondence between the identifier of the first terminal device and the first security credential. The base station determines the first security credential based on the correspondence between the identifier of the first terminal device and the first security credential, as well as the identifier of the first terminal device, and then determines the first security parameter based on the first security credential.
[0274] Exemplarily, before step 502, the base station receives configuration information from the configuration device, the configuration information carrying the correspondence between the identifier of the first terminal device and the first security credential, and the base station stores the correspondence between the identifier of the first terminal device and the first security credential. For example, if the configuration device is a server, the server first sends the configuration information to the NEF (or AMF), and the NEF (or AMF) then sends the configuration information to the base station. For another example, if the configuration device is the NEF (or AMF), the NEF (or AMF) sends the configuration information to the base station.
[0275] In implementation method 2, the management device is the base station and the storage device is the OAM.
[0276] For example, the base station can be considered as the reader in FIG2 , and the terminal device can be considered as the tag in FIG2 .
[0277] For the specific implementation of step 501 and step 507, please refer to the description in the above implementation method 1.
[0278] In step 502, the base station determines the first security parameter based on the identifier of the first terminal device. Specifically, the OAM may store a correspondence between the identifier of the first terminal device and the first security credential. The base station sends the identifier of the first terminal device to the OAM. The OAM determines the first security credential based on the identifier of the first terminal device and the locally stored correspondence between the identifier of the first terminal device and the first security credential, and sends the first security credential to the base station. Subsequently, the base station determines the first security parameter based on the first security credential.
[0279] Exemplarily, before step 502, the OAM receives configuration information from the configuration device. The configuration information carries a correspondence between the identifier of the first terminal device and the first security credential. The OAM stores the correspondence between the identifier of the first terminal device and the first security credential. For example, if the configuration device is a server, the server first sends the configuration information to the NEF, which then sends the configuration information to the OAM. For another example, if the configuration device is the NEF, the NEF sends the configuration information to the OAM.
[0280] Implementation 3: The management device is an AMF or TMF, and there is no storage device. For ease of description, the following uses the AMF as an example. When the management device is a TMF, "AMF" in the following description can be replaced with "TMF".
[0281] For example, the base station can be considered as the reader in FIG2 , and the terminal device can be considered as the tag in FIG2 .
[0282] In the above step 501, the server sends a first service request to the AMF. Specifically, the server sends the first service request to the AMF, or the server sends the first service request to the AMF through a control plane device, where the control plane device can be, for example, NEF, SMF, PCF, UDM, network slice and independent non-public network authentication and authorization function (network slice-specific and SNPN authentication and authorization function, NSSAAF). In the above step 507, the way in which the AMF sends the first service result to the server is similar to step 501, except that the transmission direction of the message is different.
[0283] In the above step 501, the AMF obtains the identifier of the first terminal device according to the first operating range, which can be specifically divided into steps a to d:
[0284] In step a, the AMF sends an N2 message to the base station, and the base station receives the N2 message from the AMF.
[0285] Among them, the N2 message includes a random access indication and / or a first operating range, the first operating range is used to determine the first terminal device, and the random access indication is used to trigger the base station to send a broadcast message so that the first terminal device performs random access.
[0286] In step b, the base station sends a broadcast message according to the random access indication. For example, the broadcast message may be a selection command message.
[0287] The broadcast message includes a first operating range, and the broadcast message is used to instruct the first terminal device to establish a connection with the base station.
[0288] It can be understood that the base station sends a broadcast message, which can be received by multiple terminal devices. When a terminal device determines that it is the first terminal device based on the first operating range, it establishes a connection with the base station; when a terminal device determines that it is not the first terminal device based on the first operating range, it does not respond or refuses to establish a connection with the base station.
[0289] The first operating scope in the first service request may be the same as or different from the first operating scope in the broadcast message. The first operating scope in the first service request may be recorded as the first operating scope 1, and the first operating scope in the broadcast message may be recorded as the first operating scope 2. For example, the first operating scope 1 is the location of the first terminal device, and the first operating scope 2 is the identifier of the first terminal device determined by the AMF based on the first operating scope 1; or, the first operating scope 1 is the group identifier of the first terminal device, and the first operating scope 2 is the identifier of the first terminal device determined by the AMF based on the first operating scope 1; or, the first operating scope 1 is the area identifier of the first terminal device, and the first operating scope 2 is the identifier of the first terminal device determined by the AMF based on the first operating scope 1, etc.
[0290] Step c: The first terminal device establishes a connection with the base station through random access.
[0291] In step d, the first terminal device sends a registration request to the AMF. In response, the AMF receives the registration request from the first terminal device. The registration request carries the identifier of the first terminal device. Alternatively, the term "registration request" can be replaced with "connection request."
[0292] The first terminal device sends a registration request to the AMF. Specifically, the first terminal device may directly send a registration request to the AMF, and the registration request is a NAS message; or the first terminal device first sends a first request to the base station, and the base station then sends a second request to the AMF, the first request is an air interface message, and the second request is an N2 message, and both the first request and the second request carry an identifier of the first terminal device. In this application, the air interface message may comply with the radio resource control (RRC) protocol, and the air interface message may also be referred to as an RRC message. The N2 message may comply with the next generation application protocol (NGAP), and the N2 message may also be referred to as an NGAP message.
[0293] In the above step 502, the AMF determines the first security parameter based on the identifier of the first terminal device. Specifically, the AMF may store the correspondence between the identifier of the first terminal device and the first security credential. The AMF determines the first security credential based on the correspondence between the identifier of the first terminal device and the first security credential, as well as the identifier of the first terminal device, and then determines the first security parameter based on the first security credential.
[0294] In step 503, the AMF sends the first operation request to the first terminal device. Specifically, the AMF may send the first operation request to the first terminal device, for example, the first operation request being a NAS message; or the AMF may send the first operation request to the base station, which in turn sends the first operation request to the first terminal device, for example, the first operation request sent by the AMF to the base station being an N2 message, and the first operation request sent by the base station to the first terminal device being an air interface message. In step 506, the first terminal device sends the first operation result to the AMF in a similar manner to step 503, except that the message transmission direction is different.
[0295] Implementation method 4: The management device is AMF and the storage device is TMF. Here, AMF and TMF are deployed separately.
[0296] For example, the base station can be considered as the reader in FIG2 , and the terminal device can be considered as the tag in FIG2 .
[0297] For the specific implementation of step 501, step 503, step 506 and step 507, please refer to the description in the above implementation method 3.
[0298] In step 502, the AMF determines the first security parameter based on the identifier of the first terminal device. Specifically, the TMF may store a correspondence between the identifier of the first terminal device and the first security credential. The AMF sends the identifier of the first terminal device to the TMF. The TMF determines the first security credential based on the identifier of the first terminal device and the locally stored correspondence between the identifier of the first terminal device and the first security credential. The TMF then sends the first security credential to the AMF. Subsequently, the AMF determines the first security parameter based on the first security credential.
[0299] Exemplarily, before step 502, the TMF receives configuration information from the configuration device. The configuration information carries the correspondence between the identifier of the first terminal device and the first security credential. The TMF then stores the correspondence between the identifier of the first terminal device and the first security credential. For example, if the configuration device is a server, the server first sends the configuration information to the NEF (or AMF), which then sends the configuration information to the TMF. For another example, if the configuration device is the NEF, the NEF sends the configuration information to the TMF.
[0300] Implementation 5: The management device is AMF or TMF, and the storage device is UDM. For ease of description, the following uses the AMF as an example. When the management device is TMF, "AMF" in the following description can be replaced with "TMF".
[0301] For example, the base station can be considered as the reader in FIG2 , and the terminal device can be considered as the tag in FIG2 .
[0302] For the specific implementation of step 501, step 503, step 506 and step 507, please refer to the description in the above implementation method 3.
[0303] In step 502, when the AMF determines the first security parameter based on the identifier of the first terminal device, specifically, the UDM may store a correspondence between the identifier of the first terminal device and the first security credential. The AMF sends the identifier of the first terminal device to the UDM. The UDM determines the first security credential based on the identifier of the first terminal device and the locally stored correspondence between the identifier of the first terminal device and the first security credential. The UDM then sends the first security credential to the AMF. Subsequently, the AMF determines the first security parameter based on the first security credential.
[0304] Exemplarily, before step 502, the UDM receives configuration information from the configuration device. The configuration information carries the correspondence between the identifier of the first terminal device and the first security credential. The UDM then stores the correspondence between the identifier of the first terminal device and the first security credential. For example, if the configuration device is a server, the server first sends the configuration information to the NEF (or AMF), which then sends the configuration information to the UDM. For another example, if the configuration device is the NEF, the NEF sends the configuration information to the UDM.
[0305] The step numbers of the various flow charts described in the method embodiments shown in Figures 5 to 7 are only an example of the execution process and do not constitute a restriction on the order of execution of the steps. There is no strict execution order between the steps that have no temporal dependency on each other in the embodiments of the present application. Not all the steps shown in the various flow charts are steps that must be executed. Some steps can be deleted based on actual needs on the basis of each flow chart, or other possible steps can be added based on actual needs on the basis of each flow chart. The method embodiments shown in Figures 5 to 7, as well as implementation methods 1 to 5 all focus on describing the differences between the various embodiments. Except for the differences, other contents can be referenced to each other; in addition, in the same embodiment, different implementation methods or different examples can also be referenced to each other.
[0306] Based on the above content and the same concept, Figures 8 and 9 are schematic diagrams of the structures of possible communication devices provided by this application. These communication devices can be used to implement the functions of the management device, terminal device, or service device in the above method embodiments, thereby also achieving the beneficial effects of the above method embodiments.
[0307] As shown in FIG8 , the communication device 800 includes a processing module 801 and a transceiver module 802 .
[0308] When the communication device 800 is used to implement the functions of the management device in the method embodiments shown in FIG5 to FIG7:
[0309] The transceiver module 802 is configured to receive a first service request from a server. The first service request includes a first operation type and a first operation range. The first operation type indicates a first operation, and the first operation range is used to determine a first terminal device to perform the first operation. The processing module 801 is configured to determine security parameters based on the identifier of the first terminal device. The transceiver module 802 is further configured to send the first operation request to the first terminal device. The first operation request includes the first operation type and security parameters. The security parameters are used to perform network security verification.
[0310] In one possible implementation, when the processing module 801 determines the security parameters based on the identification of the first terminal device, it is specifically used to obtain the security credentials of the first terminal device based on the identification of the first terminal device, and to determine the security parameters based on the security credentials and freshness parameters of the first terminal device.
[0311] In a possible implementation, the transceiver module 802 is further configured to receive a connection request from the first terminal device, the connection request including the freshness parameter. Alternatively, the processing module 801 is further configured to generate the freshness parameter, the first operation request including the freshness parameter.
[0312] When the processing module 801 obtains the security credentials of the first terminal device based on the identifier of the first terminal device, there are two specific methods: Method 1, the management device stores the correspondence between the identifier of the first terminal device and the security credentials, and the processing module 801 is specifically used to obtain the security credentials of the first terminal device based on the identifier of the first terminal device and the correspondence. Exemplarily, the transceiver module 802 is also used to receive configuration information from the server, and the configuration information includes the correspondence. Method 2, the processing module 801 is specifically used to control the transceiver module 802 to send the identifier of the first terminal device to the storage device, and to receive the security credentials of the first terminal device from the storage device, and the storage device stores the correspondence between the identifier of the first terminal device and the security credentials. Exemplarily, when the processing module 801 controls the transceiver module 802 to send the identifier of the first terminal device to the storage device, it is specifically used to obtain routing information from the identifier of the first terminal device, determine the storage device corresponding to the routing information based on the routing information, and control the transceiver module 802 to send the identifier of the first terminal device to the storage device corresponding to the routing information.
[0313] In a possible implementation, after the transceiver module 802 sends the first operation request to the first terminal device, the processing module 801 is further configured to generate a first service result, where the first service result indicates an operation status of the first terminal device for the first operation.
[0314] When the first operation is a deactivation operation, the management device or server may identify the third terminal device that failed to be deactivated, and instruct the third terminal device to perform the deactivation operation again, which may be done in the following two ways:
[0315] Method 1: After the processing module 801 generates the first service result, the transceiver module 802 is further used to receive a second service request from the server, where the second service request includes a second operation type and a second operation range. The processing module 801 is further used to determine the third terminal device that failed to be deactivated based on the identifier of the second terminal device and the first service result; the transceiver module 802 is further used to send a second operation request to the third terminal device, where the second operation request includes the first operation type. Method 2: After the processing module 801 generates the first service result, the transceiver module 802 is further used to send the first service result to the server, where the first service result corresponds to the first service request. The transceiver module 802 is further used to receive a second service request from the server and send a second service result to the server, where the second service result corresponds to the second service request. Furthermore, the transceiver module 802 is also used to receive a third service request from the server, the third service request including the identifier of the third terminal device and the first operation type, and to send a third operation request to the third terminal device, the third operation request including the first operation type, and the first service result and the second service result are used to determine the third terminal device that failed to be deactivated.
[0316] When the communication device 800 is used to implement the functions of the terminal device in the method embodiments shown in FIG5 to FIG7:
[0317] The transceiver module 802 is used to send the identifier of the terminal device to the management device, where the identifier of the terminal device is associated with the security parameters; and to receive a first operation request from the management device, where the first operation request includes a first operation type and security parameters, where the first operation type indicates a first operation; the processing module 801 is used to perform the first operation after determining that the network has passed the security check based on the security parameters.
[0318] In a possible implementation, when determining that the network passes the security check according to the security parameters, the processing module 801 is specifically configured to determine that the network passes the security check according to the security parameters, the security credentials of the terminal device, and the freshness parameter.
[0319] In one possible implementation, the processing module 801 is further configured to generate a freshness parameter, and the transceiver module 802 is further configured to send a connection request to the management device, wherein the connection request includes the freshness parameter. Alternatively, the first operation request also includes the freshness parameter, and the processing module 801 is further configured to obtain the freshness parameter from the first operation request.
[0320] When the communication device 800 is used to implement the function of the service device of the method embodiment shown in Figures 5 to 7:
[0321] The transceiver module 802 is configured to send a first service request to the management device and receive a first service result from the management device. In one possible implementation, the transceiver module 802 is further configured to send a second service request to the management device and receive a second service result from the management device. In one possible implementation, when the first operation type is a deactivation operation type, that is, when the first operation is a deactivation operation, the processing module 801 is configured to determine, based on the first service result and the second service result, a third terminal device that failed to be deactivated, and control the transceiver module 802 to send a third service request to the management device.
[0322] FIG9 shows an apparatus 900 provided in an embodiment of the present application. The apparatus shown in FIG9 may be a hardware circuit implementation of the apparatus shown in FIG8 . This apparatus can be used in the flowcharts shown above to perform the functions of the management apparatus, terminal apparatus, or service apparatus in the aforementioned method embodiments. For ease of illustration, FIG9 only illustrates the main components of the apparatus.
[0323] The device 900 shown in FIG9 includes a communication interface 910, a processor 920, and a memory 930, wherein the memory 930 is used to store program instructions and / or data. The processor 920 may operate in conjunction with the memory 930. The processor 920 may execute program instructions stored in the memory 930. When the instructions or program stored in the memory 930 are executed, the processor 920 is used to perform the operations performed by the processing module 801 in the above embodiment, and the communication interface 910 is used to perform the operations performed by the transceiver module 802 in the above embodiment.
[0324] The memory 930 is coupled to the processor 920. In the embodiments of the present application, coupling refers to an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between the devices, units, or modules. At least one of the memories 930 may be included in the processor 920.
[0325] In the embodiments of the present application, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface. In the embodiments of the present application, when the communication interface is a transceiver, the transceiver may include an independent receiver or an independent transmitter; or a transceiver or communication interface that integrates transceiver functions.
[0326] Device 900 may also include a communication line 940. Communication interface 910, processor 920, and memory 930 may be interconnected via communication line 940; communication line 940 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Communication line 940 may be classified as an address bus, a data bus, a control bus, and the like. For ease of illustration, FIG9 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.
[0327] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor. The method steps in the embodiments of the present application may be implemented in hardware or by a processor executing software instructions. The software instructions may be composed of corresponding software modules, which may be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, removable hard disks, compact disc read-only memory (CD-ROMs), or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be an integral part of the processor. The processor and storage medium may be located in an application-specific integrated circuit (ASIC). Alternatively, the ASIC may be located in a management device, a terminal device, or a server. Alternatively, the processor and storage medium may be located as discrete components in a management device, a terminal device, or a server.
[0328] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, all or part of the processes or functions of the embodiments of the present application are performed. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media, such as floppy disks, hard disks, or magnetic tapes; optical media, such as digital video disks; or semiconductor media, such as solid-state drives. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0329] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of this application, the character " / " indicates that the previous and next associated objects are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.
[0330] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.
Claims
1. A communication method, characterized in that, Including: Receiving a first service request from a server, where the first service request includes a first operation type and a first operation scope, the first operation type indicates a first operation, and the first operation scope is used to determine a first terminal device for executing the first operation; Determining a security parameter according to the identifier of the first terminal device; Sending a first operation request to the first terminal device, where the first operation request includes the first operation type and the security parameter, and the security parameter is used to perform a security check on the network.
2. The method according to claim 1, wherein The determining the security parameter according to the identifier of the first terminal device includes: Obtaining a security credential of the first terminal device according to the identifier of the first terminal device, where the security credential includes a password or a key; Determining the security parameter according to the security credential and a freshness parameter of the first terminal device.
3. The method according to claim 2, wherein It further includes: Receiving a connection request from the first terminal device, where the connection request includes the freshness parameter; Or, generating the freshness parameter, and the freshness parameter is further included in the first operation request.
4. The method according to any one of claims 1 to 3, characterized in that, The obtaining the security credential of the first terminal device according to the identifier of the first terminal device includes: Obtaining the security credential of the first terminal device according to the correspondence between the identifier of the first terminal device and the stored identifier and security credential of the first terminal device.
5. The method according to claim 4, characterized in that It further includes: Receiving configuration information from the server, where the configuration information includes the correspondence.
6. The method according to any one of claims 1-3, characterized in that, The obtaining the security credential of the first terminal device according to the identifier of the first terminal device includes: Sending the identifier of the first terminal device to a storage device, where the storage device stores the correspondence between the identifier of the first terminal device and the security credential; Receiving the security credential of the first terminal device from the storage device.
7. The method according to claim 6, characterized in that, The sending the identifier of the first terminal device to the storage device includes: Obtaining routing information from the identifier of the first terminal device; Determining a storage device corresponding to the routing information according to the routing information; Sending the identifier of the first terminal device to the storage device corresponding to the routing information.
8. The method according to any one of claims 1-7, characterized in that After sending the first operation request to the first terminal device, it further includes: Generating a first service result, where the first service result indicates an operation state of the first terminal device for the first operation, and where the operation state of the first terminal device for the first operation is operation success or operation failure.
9. The method according to claim 8, wherein The first operation is an inactivation operation; After generating the first service result, it further includes: Receiving a second service request from the server, where the second service request includes a second operation type and a second operation scope, the second operation type indicates a second operation, and the second operation scope is used to determine a second terminal device for executing the second operation; Determining a third terminal device with inactivation failure according to the identifier of the second terminal device and the first service result, and sending a second operation request to the third terminal device, where the second operation request includes the first operation type.
10. The method according to claim 8, wherein The first operation is an inactivation operation; After generating the first service result, it further includes: Send the first service result to the server; Receive a second service request from the server, where the second service request includes a second operation type and a second operation scope, the second operation type indicates a second operation, and the second operation scope is used to determine a second terminal device for executing the second operation; Send a second service result to the server, where the second service result indicates the operation status of the second terminal device for the second operation, and the first service result and the second service result are used to determine a third terminal device with inactivation failure; Receive a third service request from the server, where the third service request includes an identifier of the third terminal device and the first operation type; Send a third operation request to the third terminal device, where the third operation request includes the first operation type.
11. The method according to claim 10, wherein Further includes: Receive the first service result and the second service result from a management device; Determine the third terminal device with inactivation failure according to the first service result and the second service result; Send the third service request to the management device.
12. A communication method, characterized in that, Includes: Send an identifier of a terminal device to a management device, where the identifier of the terminal device is associated with a security parameter; Receive a first operation request from the management device, where the first operation request includes a first operation type and the security parameter, and the first operation type indicates a first operation; Execute the first operation after determining that the network passes security verification according to the security parameter.
13. The method according to claim 12, wherein The determining that the network passes security verification according to the security parameter includes: Determine that the network passes security verification according to the security parameter, a freshness parameter, and a stored security credential of the terminal device; Wherein, the security credential includes a password or a key.
14. The method according to claim 13, wherein Further includes: Generate the freshness parameter, and send a connection request to the management device, where the connection request includes the freshness parameter; Or, the first operation request further includes the freshness parameter.
15. A communication device, characterized in that, Includes a module for executing the method according to any one of claims 1 to 10, or a module for executing the method according to claim 11, or a module for executing the method according to any one of claims 12 to 14.
16. A communication device, characterized in that, Includes a processor and an interface circuit, where the interface circuit is used to receive a signal from another communication device outside the communication device and transmit it to the processor or send a signal from the processor to another communication device outside the communication device, and the processor implements the method according to any one of claims 1 to 10, or the method according to claim 11, or the method according to any one of claims 12 to 14 through logic circuits or by executing code instructions.
17. A computer-readable storage medium, characterized in that, A computer program or instruction is stored in the storage medium, and when the computer program or instruction is executed by a communication device, the method according to any one of claims 1 to 10, or the method according to claim 11, or the method according to any one of claims 12 to 14 is implemented.
18. A communication system, characterized in that, Includes one or more of the following devices: A management device, a terminal device, and a service device; Among them, the management device is used to execute the method described in any one of claims 1 to 10, the service device is used to execute the method described in claim 11, and the terminal device is used to execute the method described in any one of claims 12 to 14.
19. A computer program product, characterized in that, It includes: A computer program or instruction, which, when executed by a communication device, implements the method described in any one of claims 1 to 10, or the method described in claim 11, or the method described in any one of claims 12 to 14.
Citation Information
Patent Citations
Terminal management method and device
CN116321083A
Communication method, device and system
CN116528216A
Security verification method and device
CN116996874A
Information processing system, log-in management device, log-in management method, and log-in management program
JP2010128828A