Communication method, device, system, and storage medium

By obtaining security strategies in secure materials, the problem of insufficient communication security of IoT devices powered by environmental energy is solved, and a communication method with low energy consumption and high security is realized.

WO2025160924A1PCT designated stage Publication Date: 2025-08-07BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/075363
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

In the prior art, the Internet of Things devices powered by environmental energy lack effective security strategies and materials when communicating, resulting in insufficient communication security.

Method used

By obtaining security policies in security materials, we determine the security protection methods between devices, including steps such as authentication and authorization, signal transmission and data encryption, to ensure the security of communication.

Benefits of technology

It realizes secure communication between IoT devices powered by environmental energy, reduces communication energy consumption, and improves communication security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024075363_07082025_PF_FP_ABST
    Figure CN2024075363_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present invention relate to the technical field of communications. Disclosed are a communication method, an apparatus, and a computer readable storage medium. The communication method comprises: after authentication and authorization of a first device, acquiring a first security material; and performing secure communication with a second device on the basis of the first security material, wherein the first security material comprises a security policy, and the security policy is used for determining a security protection method for communication between the first device and the second device. The embodiments of the present invention achieve security protection of communication by determining the security protection method for communication between the first device and the second device on the basis of the security policy in the acquired first security material.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device, system and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a communication method, device, system, and storage medium. Background Art

[0002] In the field of communication technology, some Internet of Things (IoT) devices can harvest ambient energy for power. For example, these IoT devices can typically be powered by harvesting radio waves, light, motion, heat, or any other suitable power source.

[0003] Summary of the Invention

[0004] Embodiments of the present disclosure provide a communication method, device, system, and storage medium.

[0005] According to a first aspect of an embodiment of the present disclosure, a communication method is provided. The method is performed by a first device, and the method includes:

[0006] Get first security material;

[0007] securely communicating with a second device based on the first security material;

[0008] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0009] A second aspect of the embodiments of the present disclosure provides a communication method, which is performed by a second device and includes:

[0010] sending a third message to the first device;

[0011] wherein the third message is security-protected based on the first security material;

[0012] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0013] A third aspect of the embodiments of the present disclosure provides a communication method, which is performed by a third device and includes:

[0014] After the first device is authenticated and authorized, sending the first security material to the first device;

[0015] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0016] According to a fourth aspect of the present disclosure, a first device is provided, including:

[0017] a first processing module, configured to obtain first security material and perform secure communication with a second device based on the first security material;

[0018] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0019] According to a fifth aspect of the present disclosure, a second device is provided, including:

[0020] A second transceiver module, configured to send a third message to the first device;

[0021] wherein the third message is security-protected based on the first security material;

[0022] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0023] According to a sixth aspect of the embodiments of the present disclosure, a third device is provided, including:

[0024] A third transceiver module is configured to send the first security material to the first device after the first device is authenticated and authorized;

[0025] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0026] According to a seventh aspect of the embodiments of the present disclosure, a first device is provided, including:

[0027] one or more processors;

[0028] The first device is used to execute an optional implementation of the aforementioned first aspect.

[0029] According to an eighth aspect of the embodiments of the present disclosure, a second device is provided, including:

[0030] one or more processors;

[0031] The second device is used to execute the optional implementation of the aforementioned second aspect.

[0032] According to a ninth aspect of the embodiments of the present disclosure, a third device is provided, including:

[0033] one or more processors;

[0034] The third device is used to execute the optional implementation of the aforementioned third aspect.

[0035] In the tenth aspect of the embodiments of the present disclosure, a communication system is proposed, including: a first device, a second device and a third device, wherein the first device is used to implement the method described in the optional implementation manner of the first aspect, the second device is used to implement the method described in the optional implementation manner of the second aspect, and the third device is used to implement the method described in the optional implementation manner of the third aspect.

[0036] According to the eleventh aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, in which executable instructions are stored. The executable instructions are loaded and executed by the processor to implement the method described in the optional implementation of the aforementioned first aspect, second aspect, or third aspect.

[0037] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0039] FIG1a is a schematic structural diagram of a wireless communication system according to an exemplary embodiment;

[0040] FIG1b is a schematic diagram of a network topology architecture according to an exemplary embodiment;

[0041] FIG2a is a flow chart showing a communication method according to an exemplary embodiment;

[0042] FIG2b is a flow chart showing a communication method according to an exemplary embodiment;

[0043] FIG3a is a flow chart of a communication method according to an embodiment of the present disclosure;

[0044] FIG3 b is a flow chart of a communication method according to an embodiment of the present disclosure;

[0045] FIG3c is a flow chart of a communication method according to an embodiment of the present disclosure;

[0046] FIG4a is a flow chart of a communication method according to an embodiment of the present disclosure;

[0047] FIG4 b is a flow chart of a communication method according to an embodiment of the present disclosure;

[0048] FIG4c is a flow chart of a communication method according to an embodiment of the present disclosure;

[0049] FIG5a is a flow chart of a communication method according to an embodiment of the present disclosure;

[0050] FIG5 b is a flow chart of a communication method according to an embodiment of the present disclosure;

[0051] FIG6a is a schematic structural diagram of a first device proposed in an embodiment of the present disclosure;

[0052] FIG6 b is a schematic structural diagram of a second device proposed in an embodiment of the present disclosure;

[0053] FIG6c is a schematic structural diagram of a third device proposed in an embodiment of the present disclosure;

[0054] FIG7a is a flow chart showing a communication method according to an exemplary embodiment;

[0055] FIG7b is a flow chart showing a communication method according to an exemplary embodiment;

[0056] FIG8a is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure;

[0057] FIG8 b is a schematic structural diagram of a chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0058] The embodiments of the present disclosure provide a communication method, a device, a communication system, and a storage medium.

[0059] In a first aspect, an embodiment of the present disclosure provides a communication method, which is performed by a first device and includes:

[0060] After authentication and authorization, the first device obtains the first security material;

[0061] securely communicating with a second device based on the first security material;

[0062] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0063] In the above embodiment, the security protection method for communication between the first device and the second device is determined based on the security policy in the acquired first security material, thereby achieving security protection for the communication.

[0064] In conjunction with some embodiments of the first aspect, in some embodiments, after authentication and authorization, the first device obtains the first security material, including:

[0065] After being authenticated and authorized by a third device, the first device obtains the first security material sent by the third device.

[0066] In the above embodiment, after being authenticated and authorized by the third device, the first device can obtain the first security material from the third device to provide a guarantee for subsequent secure communication with the second device.

[0067] In conjunction with some embodiments of the first aspect, in some embodiments, obtaining the first security material sent by the third device includes:

[0068] Sending a first message to the third device, where the first message is used to request the third device to authenticate and authorize the first device;

[0069] After being authenticated and authorized by a third device, the first device receives a second message sent by the third device in response to the first message, where the second message carries the first security material;

[0070] The first security material is obtained from the second message.

[0071] In the above embodiment, the first device may request the third device to authenticate and authorize the first device by sending a first message to the third device, and provide a first security material for secure communication with the second device.

[0072] In conjunction with some embodiments of the first aspect, in some embodiments, the first message includes at least one of the following:

[0073] device information of the first device;

[0074] device information of the second device;

[0075] service information used by the second device;

[0076] Information about the group to which the second device belongs.

[0077] In conjunction with some embodiments of the first aspect, in some embodiments, the first safety material further includes at least one of the following:

[0078] Credential information;

[0079] device information of the second device;

[0080] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0081] service information used by the second device;

[0082] Candidate security algorithms.

[0083] In the above embodiments, the first security material is bound to the second device information, or to the device information of the group to which the second device belongs, or to the service information used by the second device, providing different levels of security protection methods.

[0084] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0085] sending a first signal to the second device, wherein the first signal is used to encourage the second device to send a third message;

[0086] A third message sent by the second device is received, wherein the third message is security-protected based on the first security material.

[0087] In the above embodiment, the first device sends the first signal to stimulate the second device to send the third message, so as to complete the communication between the first device and the second device.

[0088] With reference to some embodiments of the first aspect, in some embodiments, the third message includes any one of the following:

[0089] First information, used to indicate a link establishment request;

[0090] data collected by the second device;

[0091] Alternatively, the third message is a link establishment request message.

[0092] In conjunction with some embodiments of the first aspect, in some embodiments, the third message further includes at least one of the following:

[0093] device information of the second device;

[0094] service information used by the second device;

[0095] candidate security algorithms supported by the second device;

[0096] a security policy used by the second device;

[0097] The security verification parameter is used to perform security protection on the third message.

[0098] In the above embodiment, the third message provides the first device with information for determining the first security material, ensuring that the first device can determine the first security material based on the information and perform secure communication with the second device.

[0099] In conjunction with some embodiments of the first aspect, in some embodiments, performing secure communication with the second device based on the first security material includes at least one of the following:

[0100] authenticating the second device based on the first security material;

[0101] The third message is verified based on the first security material.

[0102] In the above embodiment, the method further includes:

[0103] If the second device passes authentication, perform at least one of the following operations:

[0104] Recording device information of the second device;

[0105] recording data collected by the second device;

[0106] sending a fourth message to a third device, where the fourth message carries at least one of device information of the second device and data collected by the second device;

[0107] A fifth message in response to the third message is sent to the second device.

[0108] In the above embodiment, when the second device passes authentication and the third message passes verification, a fifth message is sent to the second device to inform the second device that the third message is successfully received, or to inform the second device of relevant information required for secure communication with the first device.

[0109] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0110] If the third message passes verification and the first message passes verification, a fifth message in response to the third message is sent to the second device.

[0111] In combination with some embodiments of the first aspect, in some embodiments, the fifth message is security-protected based on the first security material.

[0112] In conjunction with some embodiments of the first aspect, in some embodiments, the fifth message carries at least one of the following:

[0113] The first indication information is used to indicate that the third message is successfully received;

[0114] security parameters, used to generate a security context negotiated between the second device and the first device;

[0115] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0116] First security strategy.

[0117] In the above embodiment, when the second device passes authentication and the third message passes verification, a fourth message is sent to the second device to inform the second device that the third message is successfully received, or to inform the second device of relevant information required for secure communication with the first device.

[0118] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0119] Receive data transmitted by the second device, where the data is protected by the negotiated security context.

[0120] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0121] If the second device fails authentication, or the third message fails verification, the third message is rejected or discarded.

[0122] In conjunction with some embodiments of the first aspect, in some embodiments, the security policy includes at least one of the following:

[0123] an integrity protection strategy for communication signals between the first device and the second device;

[0124] a confidentiality protection strategy for communication signals between the first device and the second device;

[0125] an integrity protection policy for user plane data between the first device and the second device;

[0126] A confidentiality protection policy for user plane data between the first device and the second device.

[0127] In the above embodiment, the security policy for protecting integrity and / or confidentiality of signals and / or data is included in the first security material so that the first device can determine the security protection method used for secure communication with the second device.

[0128] In combination with some embodiments of the first aspect, in some embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0129] In a second aspect, an embodiment of the present disclosure provides a communication method, which is performed by a second device and includes:

[0130] sending a third message to the first device;

[0131] wherein the third message is security-protected based on the first security material;

[0132] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0133] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0134] A first signal sent by the first device is received, wherein the first signal is used to stimulate the second device to send the third message.

[0135] With reference to some embodiments of the second aspect, in some embodiments, the third message includes any one of the following:

[0136] First information, used to indicate a link establishment request;

[0137] data collected by the second device;

[0138] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0139] In conjunction with some embodiments of the first aspect, in some embodiments, the third message further includes at least one of the following:

[0140] device information of the second device;

[0141] service information used by the second device;

[0142] candidate security algorithms supported by the second device;

[0143] a security policy used by the second device;

[0144] The security verification parameter is used to perform security protection on the third message.

[0145] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0146] Receive a fifth message sent by the first device in response to the third message.

[0147] In combination with some embodiments of the second aspect, in some embodiments, the fifth message is security protected based on the first security material.

[0148] In conjunction with some embodiments of the second aspect, in some embodiments, the fifth message carries at least one of the following:

[0149] First indication information, used to indicate that the third message is successfully received;

[0150] security parameters, used to generate a security context negotiated between the second device and the first device;

[0151] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0152] First security strategy.

[0153] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0154] Data is transmitted to the first device, the data being protected by the negotiated security context.

[0155] In conjunction with some embodiments of the second aspect, in some embodiments, the security policy includes at least one of the following:

[0156] an integrity protection strategy for communication signals between the first device and the second device;

[0157] a confidentiality protection strategy for communication signals between the first device and the second device;

[0158] an integrity protection policy for user plane data between the first device and the second device;

[0159] A confidentiality protection policy for user plane data between the first device and the second device.

[0160] In combination with some embodiments of the second aspect, in some embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0161] In a third aspect, an embodiment of the present disclosure provides a communication method, which is performed by a third device and includes:

[0162] After the first device is authenticated and authorized, sending the first security material to the first device;

[0163] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0164] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes:

[0165] receiving a first message sent by the first device, where the first message is used to request authentication and authorization for the first device;

[0166] The sending of the first security material to the first device includes:

[0167] After being authenticated and authorized, the first device sends a second message to the first device, where the second message carries the first security material.

[0168] In conjunction with some embodiments of the third aspect, in some embodiments, the first message includes at least one of the following:

[0169] device information of the first device;

[0170] device information of the second device;

[0171] service information used by the second device;

[0172] Information about the group to which the second device belongs.

[0173] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes:

[0174] A fourth message sent by the first device is received, where the fourth message carries at least one of device information of the second device and data collected by the second device.

[0175] In conjunction with some embodiments of the third aspect, in some embodiments, the first safety material further includes at least one of the following:

[0176] Credential information;

[0177] device information of the second device;

[0178] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0179] service information used by the second device;

[0180] Candidate security algorithms.

[0181] In conjunction with some embodiments of the third aspect, in some embodiments, the security policy includes at least one of the following:

[0182] an integrity protection strategy for communication signals between the first device and the second device;

[0183] a confidentiality protection strategy for communication signals between the first device and the second device;

[0184] an integrity protection policy for user plane data between the first device and the second device;

[0185] A confidentiality protection policy for user plane data between the first device and the second device.

[0186] In combination with some embodiments of the third aspect, in some embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0187] In a fourth aspect, an embodiment of the present disclosure provides a first device, including:

[0188] A first processing module is configured to, after the first device is authenticated and authorized, obtain first security material and perform secure communication with the second device based on the first security material;

[0189] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0190] In a fifth aspect, an embodiment of the present disclosure provides a second device, including:

[0191] A second transceiver module, configured to send a third message to the first device;

[0192] wherein the third message is security-protected based on the first security material;

[0193] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0194] In a sixth aspect, an embodiment of the present disclosure provides a third device, including:

[0195] A third transceiver module is configured to send the first security material to the first device after the first device is authenticated and authorized;

[0196] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0197] In a seventh aspect, an embodiment of the present disclosure provides a first device, including:

[0198] one or more processors;

[0199] The first device executes the method described in the optional implementation manner of the first aspect.

[0200] In an eighth aspect, an embodiment of the present disclosure provides a second device, including:

[0201] one or more processors;

[0202] The second device executes the method described in the optional implementation manner of the second aspect.

[0203] In a ninth aspect, an embodiment of the present disclosure provides a third device, including:

[0204] one or more processors;

[0205] The third device is used to execute the method described in the optional implementation manner of the third aspect.

[0206] In the tenth aspect, an embodiment of the present disclosure proposes a communication system, comprising a first device, a second device and a third device, wherein the first device is used to implement the method described in the optional implementation manner of the first aspect, the second device is used to implement the method described in the optional implementation manner of the second aspect, and the third device is used to implement the method described in the optional implementation manner of the third aspect.

[0207] In the eleventh aspect, an embodiment of the present disclosure proposes a storage medium, which stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the optional implementation of the first aspect, the second aspect, or the third aspect.

[0208] In a twelfth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the optional implementation manner of the first aspect or the second aspect.

[0209] In a thirteenth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first or second aspect.

[0210] In a fourteenth aspect, an embodiment of the present disclosure proposes a chip or a chip system, which includes a processing circuit for executing the method described in the optional implementation of the first or second aspect above.

[0211] In a fifteenth aspect, an embodiment of the present disclosure provides a communication method, where the method is performed by a communication system including a first device, a second device, and a third device, and the method includes:

[0212] After the first device is authenticated and authorized, the third device sends a second message to the first device, where the second message includes security material;

[0213] The second device sends a third message to the first device;

[0214] The first device determines, based on the third message, a first security material from the security material included in the second message, and performs secure communication with the second device according to the first security material;

[0215] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0216] It is understandable that the above-mentioned apparatus for random access, communication equipment, communication system, storage medium, program product, and computer program are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here. Among them, the communication equipment can be a terminal or a network device.

[0217] The embodiments of the present disclosure provide a communication method, an apparatus, a communication device, a communication system, and a storage medium.

[0218] In some embodiments, terms such as communication method, information processing method, and random access can be replaced with each other; terms such as device for random access, information processing device, and communication device can be replaced with each other; and terms such as information processing system and communication system can be replaced with each other.

[0219] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the embodiments of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0220] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0221] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the embodiments of the present disclosure.

[0222] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0223] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0224] In some embodiments, the terms "at least one of", "at least one of", "at least one of", "one or more", "a plurality of", "multiple", etc. can be used interchangeably.

[0225] In the embodiments of the present disclosure, descriptions such as “at least one of A, B, C…”, “A and / or B and / or C…”, etc. include the situation where any one of A, B, C… exists alone, and also include any combination of any multiple of A, B, C…, and each situation can exist alone; for example, “at least one of A, B, C” includes the situation where A exists alone, B exists alone, C exists alone, the combination of A and B, the combination of A and C, the combination of B and C, and the combination of A, B, and C; for example, A and / or B includes the situation where A exists alone, B exists alone, and the combination of A and B.

[0226] In some embodiments, descriptions such as "in one case A, in another case B," or "in response to one case A, in response to another case B," may include the following technical solutions depending on the situation: executing A independently of B (in some embodiments, A); executing B independently of A (in some embodiments, B); selectively executing A and B (in some embodiments, selecting between A and B); and executing both A and B (in some embodiments, A and B). The same applies when there are more branches, such as A, B, and C.

[0227] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different. For another example, if the description object is "information", then the "first configuration" and the "second configuration" can be the same information or different information, and their contents can be the same or different.

[0228] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0229] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0230] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0231] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.

[0232] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.

[0233] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.

[0234] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, which can also be referred to as device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it can also be set as a structure in which the terminal has all or part of the functions of the access network device. In addition, languages ​​such as "uplink" and "downlink" can also be replaced with languages ​​corresponding to communication between terminals (for example, "side").

[0235] For example, an uplink channel, a downlink channel, etc. may be replaced by a side channel, and an uplink, a downlink, etc. may be replaced by a side link.

[0236] In some embodiments, terms such as "uplink", "uplink", "physical uplink" can be interchangeable with each other, and terms such as "downlink", "downlink", "physical downlink" can be interchangeable with each other, and terms such as "side", "sidelink", "side communication", "sidelink communication", "direct connection", "direct link", "direct communication", "direct link communication" can be interchangeable with each other.

[0237] In some embodiments, the terms "downlink control information (DCI)", "downlink (DL) assignment", "DL DCI", "uplink (UL) grant", "UL DCI" and the like may be used interchangeably.

[0238] In some embodiments, terms such as "physical downlink shared channel (PDSCH)" and "DL data" can be used interchangeably, and terms such as "physical uplink shared channel (PUSCH)" and "UL data" can be used interchangeably.

[0239] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values ​​(for example, comparison with a predetermined value), but is not limited thereto.

[0240] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0241] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0242] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0243] FIG1a is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.

[0244] As shown in FIG. 1 a , a communication system 100 includes a terminal 101 and a network device 102 .

[0245] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0246] In some embodiments, the network device 102 may include at least one of an access network device and a core network device.

[0247] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network. The network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0248] In some embodiments, the technical solutions of the embodiments of the present disclosure may be applicable to the Open RAN architecture. In this case, the interfaces between or within the network devices involved in the embodiments of the present disclosure may become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.

[0249] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0250] In some embodiments, the access network device may be a single device, or may be multiple devices or a group of devices, each including all or part of a first network element, a second network element, etc. The network element may be virtual or physical. The network device may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0251] In some embodiments, a core network device may be a device including one or more network elements, or may be multiple devices or device groups, each including all or part of the one or more network elements. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0252] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.

[0253] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1a, or a portion thereof, but are not limited thereto. The entities shown in FIG1a are illustrative only. The communication system may include all or a portion of the entities shown in FIG1a, or may include other entities other than those shown in FIG1a. The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0254] The embodiments of the present disclosure may be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), other systems utilizing random access, and next-generation systems based on and extending these systems. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0255] An ambient-powered IoT device is an IoT device powered by energy harvesting, either without a battery or with limited energy storage capabilities (e.g. using capacitors), by harvesting radio waves, light, motion, heat, or any other suitable power source.

[0256] Energy obtained from the environment can drive data transmission and wireless communication of sensing nodes. The current low-power IoT communication chips (such as BLE, LoRa, and NB-IoT) have a transmit and receive power consumption of tens or even hundreds of milliwatts, while the energy obtained by environmental energy harvesting is only at the microwatt level, which is unable to drive these types of nodes. Therefore, a new wireless communication technology is needed to reduce communication energy consumption to tens of microwatts or even less than ten microwatts. Currently, backscatter communication technology is mostly used.

[0257] Backscatter communications is one of the key technologies for building the future Internet of Things (IoT), which is energy-efficient, low-cost, and flexibly deployable. It is also an important means of achieving the "Intelligent Connection of Everything." Backscatter transmission is a technology that can be used.

[0258] Backscatter transmission utilizes the principle of RF signal backscattering to design extremely low-power modulation and transmission technologies. The reader sends a physical layer signal to the Ambient IoT (A-IoT) device. This physical layer signal can be any AC signal, such as a pulse signal.

[0259] In some embodiments, the physical layer signal is used to provide energy for the Ambient IoT (A-IoT) device to transmit signals. Therefore, the physical layer signal can be referred to as an excitation signal or a trigger signal. For example, since a portion of the excitation signal will be reflected when it reaches the A-IoT device, the A-IoT device can adjust the matching between the receiving antenna and the impedance according to the information to be sent, thereby enhancing the reflection of the incident excitation signal and modulating the sensory data it has acquired onto the reflected signal to complete the transmission of the data. This process is similar to a reflector. Compared with other communication technologies, backscatter transmission does not require a complex RF structure, reducing the use of devices such as power amplifiers, high-precision crystal oscillators, duplexers, and high-precision filters. It also does not require complex baseband processing. Therefore, it can simplify the design of A-IoT devices and significantly reduce the cost of Ambient IoT device nodes. A-IoT devices are IoT devices that work using environmental energy. This environmental energy may include the signal energy of the aforementioned wireless signal, and may also include other environmental capabilities such as geothermal energy and / or light energy. A-IoT devices are devices that use a backscatter transmission mechanism for wireless communication.

[0260] In some embodiments, a network topology architecture for wireless communications between ambient energy devices is implemented based on backscatter technology. For example, in the network topology illustrated in Figure 1b, bidirectional communication is performed between the ambient IoT device and the base station via an intermediate node. For example, the intermediate node can be at least one of a relay, an integrated access backhaul (IAB), a UE, and a repeater. The intermediate node transmits information between the base station and the ambient IoT device.

[0261] Based on the above topology, ambient IoT devices can transmit and report sensor data to the core network (CN) and / or application servers. Before A-IoT devices transmit collected data, they must negotiate a security context with intermediate nodes based on the provided security materials and security policies. However, there is currently no solution for how to provide security policies and security materials.

[0262] Based on the above wireless communication system, various embodiments of the communication method proposed in the present disclosure are described in detail below.

[0263] FIG2a is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2a , the communication method is used in a communication system 100, and the method includes:

[0264] S200 (not shown in the figure): after being authenticated and authorized by the third device, the first device obtains the first security material sent by the third device.

[0265] In some embodiments, the third device can be any one of a core network function (CN NF) entity (for example, a policy control function (PCF), an A-IoT management function (A-IoT MF)), a third-party server (for example, an AAA server, an A-IoT application server (A-IoT AS)).

[0266] In some embodiments, the third device may provide multiple sets of security materials to the first device, where the multiple sets of security materials include the first security material.

[0267] In some embodiments, the first security material is the security material corresponding to the second device, and different second devices may correspond to different first security materials.

[0268] In some embodiments, the name of the security material is not limited, and may be, for example, security information, security data, policy and security material, or second information, etc. The second information may be any information used for security protection and / or security verification.

[0269] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0270] In some embodiments, corresponding security materials are obtained based on device information of a specific second device, or information about a group to which a specific A-IOT device belongs, or service information about a service to which a specific A-IOT device belongs.

[0271] Exemplarily, the security material corresponding to a specific A-IoT device can be obtained based on the ID of the device, or based on the group ID of the group to which the specific A-IoT device belongs, or based on the service ID of the service to which the specific A-IoT device belongs.

[0272] In some embodiments, step S200 may include:

[0273] S200-1. The first device sends a first message to the third device.

[0274] In some embodiments, the first message is used to request the third device to authenticate and authorize the first device.

[0275] In some embodiments, the first message may be an authorization request message, or a security material request message, but the message name is not limited thereto.

[0276] In some embodiments, the first message includes at least one of:

[0277] device information of the first device;

[0278] device information of the second device;

[0279] service information used by the second device;

[0280] Information about the group to which the second device belongs.

[0281] In some embodiments, the device information may include at least one of the following:

[0282] Identification information, indicating equipment;

[0283] Business information, indicating the business involved in the device.

[0284] In some embodiments, the service information used by the second device may include service identification information indicating the service used by the second device.

[0285] For example, the service ID is used when taking inventory of the second device in a specific park, or the service ID is called when obtaining data collected by the second device.

[0286] In some embodiments, the information about the group to which the second device belongs may include identification information of the group, indicating the group to which the second device belongs.

[0287] In some embodiments, the device information of the first device is used to authenticate and authorize the first device.

[0288] In some embodiments, the relevant information of the second device is used to inform the third device that the security material to be provided is related to the second device.

[0289] Optionally, the relevant information of the second device includes at least one of: device information, used service information, and information of the group to which the second device belongs.

[0290] In some embodiments, the third device has the function of performing security authentication, or performing policy and / or security parameter management.

[0291] In some embodiments, the third device authenticates and authorizes the first device based on local configuration.

[0292] In some embodiments, the third device authenticates and authorizes the first device based on a configuration provided by an Operation Administration and Maintenance (OAM) device.

[0293] In some embodiments, the third device authenticates and authorizes the first device based on the subscription data of the first device.

[0294] S200-2. After the first device is authenticated and authorized by the third device, the third device sends a second message to the first device.

[0295] In some embodiments, the second message is a response message to the first message.

[0296] In some embodiments, the first message may be an authorization response message, or a security material response message, but the message name is not limited thereto.

[0297] In some embodiments, the second message may further include: a success message.

[0298] In some embodiments, the success message may indicate that the second device authentication authorization is passed. The second device authentication authorization passing may be understood as the second device authentication authorization is successful.

[0299] In some embodiments, the third device may transmit the first security material to the first device by including it in a second message in response to the first message.

[0300] In some embodiments, the first device receives a second message sent by the third device in response to the first message, and obtains the first security material from the second message.

[0301] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0302] In the above embodiment, the security policy includes at least one of the following:

[0303] an integrity protection strategy for communication signals between the first device and the second device;

[0304] a confidentiality protection strategy for communication signals between the first device and the second device;

[0305] an integrity protection policy for user plane data between the first device and the second device;

[0306] A confidentiality protection policy for user plane data between the first device and the second device.

[0307] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is required protection. Optionally, the security policy is a signal integrity protection policy, and the security policy is configured to require protection.

[0308] In some embodiments, if the privacy (also described as confidentiality) security policy is configured to require protection, the first device is only allowed to establish a connection with the second device using a non-NULL privacy algorithm.

[0309] In some embodiments, if the integrity security policy is configured to require protection, the first device is only allowed to establish a connection with the second device using a non-NULL integrity algorithm.

[0310] In some embodiments, if the confidentiality and integrity security policy is configured to require protection, the first device is only allowed to establish a connection with the second device that uses a non-NULL confidentiality and integrity algorithm.

[0311] In some embodiments, the security policy for determining the security protection method for communication between the first device and the second device is configured to NOT NEEDED protection.

[0312] In some embodiments, if the security policy is configured to not require protection, the first device only establishes a connection without security protection.

[0313] In some embodiments, if the confidentiality security policy is configured to not require protection, the first device only establishes a connection with the second device without security protection.

[0314] In some embodiments, if the integrity security policy is configured to not require protection, the first device only establishes a connection with the second device without security protection.

[0315] In some embodiments, if the confidentiality and integrity security policy is configured to not require protection, the first device simply establishes a connection with the second device without security protection.

[0316] In some embodiments, the security policy for determining a security protection method for communications between the first device and the second device is configured as optional (PREFERRED) protection.

[0317] In some embodiments, if the security policy is configured as optional protection, the first device may attempt to establish a connection with security protection, or accept a connection without security protection. At this time, the first device may negotiate with the second device to determine the specific security protection method, or the first device may determine whether to turn on or off the security policy configured as optional protection.

[0318] In some embodiments, if the confidentiality security policy is configured as optional protection, the first device may determine whether to turn the confidentiality security policy on or off.

[0319] Optionally, if the first device determines to enable the confidentiality security policy, the first device is only allowed to establish a connection with a second device that uses a non-NULL confidentiality algorithm.

[0320] Optionally, if the first device determines to turn off the confidentiality security policy, the first device only establishes a connection without security protection with the second device.

[0321] In some embodiments, if the integrity security policy is configured as optional protection, the first device may determine whether to turn the integrity security policy on or off.

[0322] Optionally, if the first device determines to enable the integrity security policy, the first device is only allowed to establish a connection with a second device that uses a non-NULL integrity algorithm.

[0323] In some embodiments, if the first device determines to turn off the integrity security policy, the first device only establishes a connection without security protection with the second device.

[0324] In the above embodiments, the confidentiality and / or integrity security policy may be a security policy for the communication signal between the first device and the second device, or a security policy for the user plane data between the first device and the second device, or a security policy for the communication signal and user plane data between the first device and the second device.

[0325] In some embodiments, if the third device is a CN NF (eg, PCF, A-IoT MF), the first security material may be pre-provided to the CN NF by the AAA server or the A-IoT AS.

[0326] In some embodiments, the third device may provide a security policy for communicating with the second device by configuring a list of applications / services of the second device that require security protection and a security policy for each second device in the list.

[0327] Optionally, the second device may be an ambient Internet of Things (A-IoT) device.

[0328] S201. A first device sends a first signal to a second device.

[0329] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0330] The term "stimulation" herein may be understood as a trigger. The first signal may be a signal for triggering the second device to send a message. The first signal may also be described as a trigger signal.

[0331] In some embodiments, the first signal may provide wireless transmission energy to the second device, so that the second device uses the energy of the first signal to send a message.

[0332] In some embodiments, the first signal may be a signal that does not carry any information, such as a pulse signal.

[0333] In some embodiments, the first device may broadcast, multicast, or unicast the first signal.

[0334] In some embodiments, assuming that the first device is an access network device and / or a relay device or an auxiliary node at a fixed location, the first signal may be broadcast, multicast, or unicast periodically or irregularly.

[0335] In some embodiments, the first signal is used to motivate the second device to return a third message.

[0336] In some embodiments, the second device receives the first signal.

[0337] S202. The second device sends a third message to the first device.

[0338] In some embodiments, the third message includes data collected by the second device.

[0339] In some embodiments, the data collected by the second device may include business data and / or device data of the second device, but is not limited thereto.

[0340] In some embodiments, the third message may further include at least one of the following:

[0341] device information of the second device;

[0342] service information used by the second device;

[0343] candidate security algorithms supported by the second device;

[0344] a security policy used by the second device;

[0345] The security verification parameter is used to perform security protection on the third message.

[0346] In some embodiments, security protection, for the sender, can be understood as encryption and / or integrity protection of the sent signal and / or data; for the receiver, it can be understood as decryption and / or integrity verification of the received signal and / or data.

[0347] In some embodiments, the second device may utilize the security verification parameter to encrypt or encode the third message, but is not limited thereto.

[0348] In some embodiments, the security algorithm may include an algorithm identifier and / or an algorithm type.

[0349] Optionally, the algorithm type may include but is not limited to an integrity encryption algorithm, a confidentiality encryption algorithm, and / or a scrambling algorithm.

[0350] In some embodiments, the security verification parameter may be a MAC value.

[0351] Optionally, the second device may use a MAC value to protect or encode the third message.

[0352] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0353] In the above embodiments, the first security material may further include at least one of the following:

[0354] Credential information;

[0355] device information of the second device;

[0356] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0357] service information used by the second device;

[0358] Candidate security algorithms.

[0359] In some embodiments, the credential information may include at least one of a root key and a symmetric key.

[0360] In some embodiments, the first security material may include device information of a group of devices. Optionally, the device information of a group of devices may be identification information of a group of devices, such as a set of IDs of the group of devices, or a group ID of the group.

[0361] In some embodiments, the second device may be one of the group of devices.

[0362] In some embodiments, after receiving the third message from the second device, the first device may determine the first security material corresponding to the second device or the group to which the second device belongs from multiple sets of security materials provided by the third device.

[0363] S203: The first device performs secure communication with the second device based on the first security material.

[0364] In some embodiments, a communication signal (also described as a signal, message, etc.) and / or data sent by the first device to the second device is securely protected using a first security material. Optionally, the security protection may include at least one of integrity protection and confidentiality protection.

[0365] In some embodiments, the first device performs security verification on the communication signal (also described as a signal, message, etc.) and / or data from the second device using the first security material. Optionally, the security verification may include at least one of integrity verification and confidentiality verification.

[0366] In some embodiments, if the third message is security-protected (e.g., integrity-protected) based on the first security material, the first device determines the security material corresponding to the second device from the security material provided by the third device based on part of the content in the third message, and then performs integrity verification.

[0367] In some embodiments, if the security protection mode of the third message is integrity protection, the first device needs to verify whether the third message has been tampered with or whether the third message is damaged after receiving the third message.

[0368] In some embodiments, if the security protection mode of the third message is confidentiality protection, the first device needs to verify whether the third message can be correctly decoded / decrypted after receiving the third message.

[0369] In some embodiments, if the third message verification passes, step S204a and / or step S204b are executed.

[0370] S204a. The first device sends a fourth message to the third device.

[0371] In some embodiments, the fourth message includes data received by the first device and / or device information of the second device.

[0372] In some embodiments, the first device records the received data and / or device information of the second device and may report to the third device.

[0373] S204b. The first device sends a fifth message to the second device.

[0374] In some embodiments, the first device sends a fifth message to the second device in response to the third message.

[0375] In some embodiments, the fifth message carries indication information for indicating whether the third message is received successfully or failed.

[0376] Optionally, the fifth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0377] In some embodiments, the fifth message may be an ACK message.

[0378] In the above embodiment, the first device can obtain a preconfigured security policy for determining a security protection method for communicating with the second device based on preconfigured security materials, and when receiving a report message from the second device, it can send a message to the second device carrying first indication information indicating that the report message has been successfully received.

[0379] In some embodiments, the above method may further include: the first device rejecting or discarding the third message.

[0380] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", and "data" can be used interchangeably.

[0381] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0382] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.

[0383] In some embodiments, terms such as "in the case of", "at the time of", "when", "if", and "if" can be used interchangeably.

[0384] The method involved in the embodiment of the present disclosure may include at least one of steps S200 - 1 to S204 b . For example, step S203 can be implemented as an independent embodiment, steps S201, S202, and S203 can be implemented as independent embodiments, steps S201, S202, S203, and S204a can be implemented as independent embodiments, steps S201, S202, S203, and S204b can be implemented as independent embodiments, steps S201, S202, S203, and S206 can be implemented as independent embodiments, steps S200-1, S200-2, S201, S202, S203, and S204a can be implemented as independent embodiments, steps S200-1, S200-2, S201, S202, S203, and S204b can be implemented as independent embodiments, but are not limited to these.

[0385] In some embodiments, steps S201 and S202 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0386] In some embodiments, steps S200 - 1 and S200 - 2 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0387] In some embodiments, step S204a is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0388] In some embodiments, step S204b is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0389] FIG2b is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2b , the communication method is used in a communication system 100, and the method includes:

[0390] S210 (not shown in the figure): after being authenticated and authorized by the third device, the first device obtains the first security material sent by the third device.

[0391] In some embodiments, the third device may be any one of a CN NF (eg, PCF, A-IoT MF), an AAA server, and an A-IoT AS.

[0392] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0393] In some embodiments, step S210 may include:

[0394] S210 - 1. The first device sends a first message to the third device.

[0395] The optional implementation of step S210-1 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0396] In some embodiments, the first message is used to request the third device to authenticate and authorize the first device.

[0397] In some embodiments, the first message may be an authorization request message, or a security material request message, but the message name is not limited thereto.

[0398] In some embodiments, the first message includes at least one of:

[0399] device information of the first device;

[0400] device information of the second device;

[0401] service information used by the second device;

[0402] Information about the group to which the second device belongs.

[0403] In some embodiments, the device information may include at least one of the following:

[0404] Identification information, indicating equipment;

[0405] Business information, indicating the business involved in the device.

[0406] In some embodiments, the service information used by the second device may include service identification information indicating the service used by the second device.

[0407] For example, the service ID is used when taking inventory of the second device in a specific park, or the service ID is called when obtaining data collected by the second device.

[0408] In some embodiments, the information about the group to which the second device belongs may include identification information of the group, indicating the group to which the second device belongs.

[0409] In some embodiments, the device information of the first device is used to authenticate and authorize the first device.

[0410] In some embodiments, the relevant information of the second device is used to inform the third device that the security material to be provided is related to the second device.

[0411] Optionally, the relevant information of the second device includes at least one of: device information, used service information, and information of the group to which the second device belongs.

[0412] S210-2. After the first device is authenticated and authorized by the third device, the third device sends a second message to the first device.

[0413] The optional implementation of step S210-2 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0414] In some embodiments, the second message is a response message to the first message.

[0415] In some embodiments, the first message may be an authorization response message, or a security material response message, but the message name is not limited thereto.

[0416] In some embodiments, the third device may transmit the first security material to the first device by including it in a second message in response to the first message.

[0417] In some embodiments, the first device receives a second message sent by the third device in response to the first message, and obtains the first security material from the second message.

[0418] In the above embodiment, the security policy includes at least one of the following:

[0419] an integrity protection strategy for communication signals between the first device and the second device;

[0420] a confidentiality protection strategy for communication signals between the first device and the second device;

[0421] an integrity protection policy for user plane data between the first device and the second device;

[0422] A confidentiality protection policy for user plane data between the first device and the second device.

[0423] It should be understood that the specific content of the security policy in this embodiment can be found in the relevant part of step S200-2 in FIG. 2a, and will not be repeated here.

[0424] S211. The first device sends a first signal to the second device.

[0425] The optional implementation of step S211 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0426] S212. The second device sends a third message to the first device.

[0427] In some embodiments, the third message includes: first information for indicating a link establishment request.

[0428] In some embodiments, the third message is a link establishment request message.

[0429] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request. Optionally, the first information is used to request to establish a link with the first device.

[0430] In some embodiments, the first information may be carried in a field or information domain of the third message. Optionally, the first information may be indicated by a 1-bit value, for example, a bit value of "1" indicates that the second device requests to establish a link with the first device.

[0431] In some embodiments, the third message further includes at least one of the following:

[0432] device information of the second device;

[0433] service information used by the second device;

[0434] candidate security algorithms supported by the second device;

[0435] a security policy used by the second device;

[0436] The security verification parameter is used to perform security protection on the third message.

[0437] In some embodiments, the device information of the second device may include at least one of the following:

[0438] Identification information, indicating identity information of the second device;

[0439] Service information indicates service information performed between the first device and the second device.

[0440] In some embodiments, the service information used by the second device may include service identification information indicating the service used by the second device.

[0441] For example, the service ID is used when taking inventory of the second device in a specific park, or the service ID is called when obtaining data collected by the second device.

[0442] In some embodiments, the security algorithm may include an algorithm identifier and / or an algorithm type.

[0443] Optionally, the algorithm type may include but is not limited to an integrity encryption algorithm, a confidentiality encryption algorithm, and / or a scrambling algorithm.

[0444] Optionally, the algorithm identifier is used to indicate the algorithm used for integrity protection and / or the algorithm used for confidentiality protection.

[0445] In some embodiments, the security verification parameter may be a MAC value.

[0446] Optionally, the second device may use a MAC value to protect or encode the third message.

[0447] In the above embodiments, the first security material may further include at least one of the following:

[0448] Credential information;

[0449] device information of the second device;

[0450] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0451] service information used by the second device;

[0452] Candidate security algorithms.

[0453] In some embodiments, the credential information may include at least one of a root key and a symmetric key.

[0454] In some embodiments, the first security material may include device information of a group of devices. Optionally, the device information of a group of devices may be identification information of a group of devices, such as a set of IDs of the group of devices, or a group ID of the group.

[0455] In some embodiments, the second device may be one of the group of devices.

[0456] S213: The first device authenticates the second device and / or verifies the third message based on the first security material.

[0457] In some embodiments, the third message may be protected using security verification parameters.

[0458] In some embodiments, if the security verification parameter that can be generated by the first device according to the third message and the first security material is the same as the security verification parameter in the third message, the third message is verified successfully.

[0459] Optionally, if the security protection mode of the third message is integrity protection, the first device needs to verify whether the third message is tampered with or whether the third message is damaged after receiving the third message.

[0460] Exemplarily, if the third message has not been tampered with or damaged, it is determined that the verification is successful (ie, the verification is passed); otherwise, the verification fails (ie, the verification is not passed).

[0461] In some embodiments, if the security protection mode of the third message is confidentiality protection, the first device needs to verify whether the third message can be correctly decoded after receiving the third message.

[0462] Exemplarily, if the third message can be decoded correctly, it is determined that the verification is successful (ie, the verification is passed); otherwise, the verification fails (ie, the verification is not passed).

[0463] In some embodiments, the first device may authenticate whether the second device is a legitimate device based on the device information in the first security material.

[0464] Optionally, if the received device information of the second device is included in the device information included in the first security material, or can be mapped to a device information in the device information of the second device included in the first security material, the second device is determined to be a legal device, that is, the second device is authenticated; otherwise, the authentication fails (that is, the authentication fails), and the second device is determined to be an illegal device (can also be described as an illegal device).

[0465] In some embodiments, if the second device is authenticated as a legitimate device and the third message verification passes, step S214 is executed.

[0466] Optionally, if the received device information of the second device is included in the device information included in the first security material, or can be mapped to a piece of device information of the second device included in the first security material, and the security verification parameter verification passes, step S214 is executed.

[0467] S214. The first device sends a fifth message to the second device.

[0468] In some embodiments, the first device sends a fifth message to the second device in response to the third message.

[0469] In some embodiments, the fifth message carries indication information for indicating whether the third message is received successfully or failed.

[0470] In some embodiments, if the fifth message includes: first indication information for indicating that the third message is successfully received, the fourth message may also include: security parameters for generating a security context negotiated between the second device and the first device.

[0471] Optionally, the fifth message includes success indication information and security parameters used to generate a security context negotiated between the second device and the first device.

[0472] In some embodiments, the fifth message may further include at least one of the following:

[0473] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0474] First security strategy.

[0475] In some embodiments, the security parameters may include, but are not limited to, an algorithm identifier and / or an algorithm length.

[0476] Optionally, the algorithm identifier is used to indicate the algorithm used for integrity protection and / or the algorithm used for confidentiality protection.

[0477] In some embodiments, the first security algorithm can be determined based on the candidate security algorithms supported by the second device and the candidate security algorithms in the first security material, for example: selecting a security algorithm that appears in both the candidate security algorithms supported by the second device and the candidate security algorithms in the first security material.

[0478] In some embodiments, the candidate security algorithms may be ranked from high to low according to their respective priorities.

[0479] In some embodiments, the first security policy may be determined by the first device.

[0480] In some embodiments, the first device may further inform the second device of the security policy determined by the first device, that is, the first security policy.

[0481] Optionally, the first security policy is one of the candidate security policies included in the first security material. For example, the security policy is configured to not require protection, or to require protection.

[0482] Optionally, the first security policy can be determined based on the security policy used by the second device and the candidate security policy in the first security material. For example, if a candidate security policy in the first security material and the security policy used by the second device are both configured as optional protection, the first device can determine whether to enable the security policy.

[0483] In some embodiments, if one of the candidate security policies in the first security material is the integrity security policy of the user plane data between the first device and the second device, and the security policy used by the second device is the integrity security policy of the user plane data between the second device and the first device, and the integrity security policy of the user plane data is configured as optional protection, the first device can determine whether to enable the integrity security policy of the user plane data.

[0484] Optionally, if the first device determines to enable the integrity security policy for the user plane data, the first device is only allowed to establish a connection with the second device that uses a non-NULL integrity algorithm.

[0485] In some embodiments, the first device may respond to the second device with an ACK message. Alternatively, the first device may send an ACK message to the second device to inform the second device that the third message is successfully received.

[0486] In some embodiments, the ACK message is security-protected based on the first security material. Optionally, the ACK is protected or encoded by the first security material.

[0487] S215: The second device transmits data to the first device by using the negotiated security context.

[0488] In some embodiments, the second device may generate a security context negotiated between the second device and the first device based on the security parameters in the fifth message, and transmit UL data by using the negotiated security context.

[0489] In some embodiments, the above method may further include: the first device rejecting or discarding the third message.

[0490] In some embodiments, if the received device information of the second device is not included in the device information included in the first security material, or cannot be mapped to one of the device information of the second device included in the first security material, the second device is an illegal device (also described as an illegal device), so the third message is rejected or discarded.

[0491] In some embodiments, if the security verification parameter fails to be verified (ie, the verification fails), the third message is rejected or discarded.

[0492] Optionally, the security verification parameter can be a MAC value, which is generated based on the third message and security material. If the third message is tampered with or damaged, the same MAC value as in the third message cannot be generated, thereby determining that the security verification parameter verification has failed.

[0493] In some embodiments, if the received device information of the second device is not included in the device information included in the first security material, or cannot be mapped to one of the device information of the second device included in the first security material, and the security verification parameter verification fails, the third message is rejected or discarded.

[0494] The method involved in the embodiments of the present disclosure may include at least one of steps S210-1 to S215. For example, step S213 can be implemented as an independent embodiment, steps S211, S212, and S213 can be implemented as independent embodiments, steps S211, S212, S213, and S214 can be implemented as independent embodiments, steps S210-1, S210-2, S211, S212, and S213 can be implemented as independent embodiments, and steps S210-1, S210-2, S211, S212, S213, and S214 can be implemented as independent embodiments, but are not limited thereto.

[0495] In some embodiments, steps S211 and S212 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0496] In some embodiments, steps S210 - 1 and S210 - 2 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0497] In some embodiments, step S214 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0498] In some embodiments, step S215 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0499] FIG3a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3a, the communication method can be executed by a first device, and the method includes:

[0500] S301. Send a first message to a third device.

[0501] The optional implementation of step S301 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0502] In some embodiments, the first message is used to request the third device to authenticate and authorize the first device.

[0503] In some embodiments, the first message may be an authorization request message, or a security material request message, but the message name is not limited thereto.

[0504] In some embodiments, the first message includes at least one of:

[0505] device information of the first device;

[0506] device information of the second device;

[0507] service information used by the second device;

[0508] Information about the group to which the second device belongs.

[0509] S302: Receive a second message sent by a third device.

[0510] The optional implementation of step S302 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0511] In some embodiments, the first device receives a second message sent by the third device in response to the first message, and obtains the first security material from the second message.

[0512] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0513] In the above embodiment, the security policy includes at least one of the following:

[0514] an integrity protection strategy for communication signals between the first device and the second device;

[0515] a confidentiality protection strategy for communication signals between the first device and the second device;

[0516] an integrity protection policy for user plane data between the first device and the second device;

[0517] A confidentiality protection policy for user plane data between the first device and the second device.

[0518] It should be understood that the specific content of the security policy in this embodiment can be found in the relevant part of step S200-2 in FIG. 2a, and will not be repeated here.

[0519] S303: Send a first signal to the second device.

[0520] The optional implementation of step S303 can refer to the optional implementation of step S201 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0521] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0522] S304: Receive a third message sent by the second device.

[0523] The optional implementation of step S304 can refer to the optional implementation of step S202 in FIG. 2 a and other related parts in the embodiment involved in FIG. 2 a , which will not be described in detail here.

[0524] In some embodiments, the third message includes data collected by the second device.

[0525] In some embodiments, the third message may further include at least one of the following:

[0526] device information of the second device;

[0527] service information used by the second device;

[0528] candidate security algorithms supported by the second device;

[0529] a security policy used by the second device;

[0530] The security verification parameter is used to perform security protection on the third message.

[0531] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0532] S305: The first device performs secure communication with the second device based on the first security material.

[0533] The optional implementation of step S305 can refer to the optional implementation of step S203 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0534] In some embodiments, the first security material may further include at least one of the following:

[0535] Credential information;

[0536] device information of the second device;

[0537] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0538] service information used by the second device;

[0539] Candidate security algorithms.

[0540] In this embodiment, the specific content of the security policy can refer to the relevant content in the embodiment involved in the optional implementation of step S203 in Figure 2a, and will not be repeated here.

[0541] S306: Send a fifth message to the second device, and / or send a fourth message to the third device.

[0542] The optional implementation of step S306 can refer to the optional implementation of steps S204a and S204b in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0543] In some embodiments, the fourth message includes data received by the first device and / or device information of the second device.

[0544] In some embodiments, the fifth message carries indication information for indicating whether the third message is received successfully or failed.

[0545] Optionally, the fifth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0546] In some embodiments, the above method may further include: rejecting or discarding the third message.

[0547] In some embodiments, if the third message fails verification, the third message may be rejected or discarded.

[0548] FIG3b is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3b , the communication method may be executed by a first device, and the method includes:

[0549] S311. Send a first message to a third device.

[0550] The optional implementation of step S311 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0551] In some embodiments, the first message is used to request the third device to authenticate and authorize the first device.

[0552] In some embodiments, the first message may be an authorization request message, or a security material request message, but the message name is not limited thereto.

[0553] In some embodiments, the first message includes at least one of:

[0554] device information of the first device;

[0555] device information of the second device;

[0556] service information used by the second device;

[0557] Information about the group to which the second device belongs.

[0558] S312: Receive a second message sent by a third device.

[0559] The optional implementation of step S312 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0560] In some embodiments, the first device receives a second message sent by the third device in response to the first message, and obtains the first security material from the second message.

[0561] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0562] In the above embodiment, the security policy includes at least one of the following:

[0563] an integrity protection strategy for communication signals between the first device and the second device;

[0564] a confidentiality protection strategy for communication signals between the first device and the second device;

[0565] an integrity protection policy for user plane data between the first device and the second device;

[0566] A confidentiality protection policy for user plane data between the first device and the second device.

[0567] It should be understood that the specific content of the security policy in this embodiment can be found in the relevant part of step S200-2 in FIG. 2a, and will not be repeated here.

[0568] S313. Send a first signal to the second device.

[0569] The optional implementation of step S313 can refer to the optional implementation of step S201 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0570] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0571] S314. Receive a third message sent by the second device.

[0572] The optional implementation of step S314 can refer to the optional implementation of step S212 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0573] In some embodiments, the third message includes: first information for indicating a link establishment request.

[0574] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request.

[0575] In some embodiments, the first information may be carried in a field or information domain in the third message.

[0576] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0577] In some embodiments, the third message may further include at least one of the following:

[0578] device information of the second device;

[0579] service information used by the second device;

[0580] candidate security algorithms supported by the second device;

[0581] a security policy used by the second device;

[0582] The security verification parameter is used to perform security protection on the third message.

[0583] S315: The first device authenticates the second device and / or verifies the third message based on the first security material.

[0584] The optional implementation of step S315 can refer to the optional implementation of step S213 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0585] In this embodiment, the specific contents of the first security material and the security policy can be found in the optional implementation of step S203 in FIG. 2a or the optional implementation of step S213 in FIG. 2b and the related contents involved, which will not be repeated here.

[0586] S316. Send a fifth message to the second device.

[0587] The optional implementation of step S316 can refer to the optional implementation of step S214 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0588] In some embodiments, the fifth message carries indication information for indicating whether the third message is received successfully or failed.

[0589] In some embodiments, if the fifth message includes: first indication information for indicating that the third message is successfully received, the fifth message may also include: security parameters for generating a security context negotiated between the second device and the first device.

[0590] In some embodiments, the fifth message may further include at least one of the following:

[0591] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0592] First security strategy.

[0593] S317: Receive data sent by the second device.

[0594] The optional implementation of step S317 can refer to the optional implementation of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0595] In some embodiments, the above method may further include: rejecting or discarding the third message.

[0596] In some embodiments, if the second device is authenticated as an illegal device and / or the third message fails verification, the third message may be rejected or discarded.

[0597] Figure 3c is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 3c, the communication method can be performed by a first device, and the method includes:

[0598] S321. After authentication and authorization, the first device obtains the first security material.

[0599] In some embodiments, the first security material includes a security policy, where the security policy is used to determine a security protection method for communication between the first device and the second device.

[0600] In some embodiments, after being authenticated and authorized by a third device, the first device obtains the first security material sent by the third device.

[0601] In some embodiments, the third device may be any one of a CN NF, an AAA server, and an A-IoT AS.

[0602] In some embodiments, obtaining the first security material sent by the third device includes:

[0603] Sending a first message to the third device, where the first message is used to request the third device to authenticate and authorize the first device;

[0604] After being authenticated and authorized by a third device, the first device receives a second message sent by the third device in response to the first message, where the second message carries the first security material;

[0605] The first security material is obtained from the second message.

[0606] In some embodiments, the first message includes at least one of the following:

[0607] device information of the first device;

[0608] device information of the second device;

[0609] service information used by the second device;

[0610] Information about the group to which the second device belongs.

[0611] The above optional implementation methods can refer to the optional implementation methods of step S200-1 and step S200-2 in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0612] In some embodiments, the method further comprises:

[0613] sending a first signal to the second device, wherein the first signal is used to encourage the second device to send a third message;

[0614] A third message sent by the second device is received, wherein the third message is security-protected based on the first security material.

[0615] In some embodiments, the first security material further comprises at least one of the following:

[0616] Credential information;

[0617] device information of the second device;

[0618] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0619] service information used by the second device;

[0620] Candidate security algorithms.

[0621] In some embodiments, the third message includes any of the following:

[0622] First information, used to indicate a link establishment request;

[0623] The second device collects data.

[0624] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0625] In some embodiments, the third message further includes at least one of the following:

[0626] device information of the second device;

[0627] service information used by the second device;

[0628] candidate security algorithms supported by the second device;

[0629] a security policy used by the second device;

[0630] The security verification parameter is used to perform security protection on the third message.

[0631] The above optional implementation methods can refer to the optional implementation methods of step S201 and step S202 in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0632] S322: Perform secure communication with a second device based on the first security material.

[0633] The optional implementation of step S322 can refer to the optional implementation of step S203 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0634] In some embodiments, securely communicating with the second device based on the first security material includes at least one of the following:

[0635] authenticating the second device based on the first security material;

[0636] The third message is verified based on the first security material.

[0637] In some embodiments, the method further comprises:

[0638] If the second device passes authentication, perform at least one of the following operations:

[0639] Recording device information of the second device;

[0640] recording data collected by the second device;

[0641] sending a fourth message to a third device, where the fourth message carries at least one of device information of the second device and data collected by the second device;

[0642] A fifth message in response to the third message is sent to the second device.

[0643] The above optional implementation methods can refer to the optional implementation methods of steps S204a and S204b in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0644] In some embodiments, the method further comprises:

[0645] If the second device is authenticated and the third message is verified, a fifth message is sent to the second device in response to the third message.

[0646] The above optional implementation method can refer to the optional implementation method of step S214 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0647] In some embodiments, the fifth message is security-protected based on the first security material.

[0648] In some embodiments, the fifth message carries at least one of the following:

[0649] First indication information, used to indicate that the third message is successfully received;

[0650] security parameters, used to generate a security context negotiated between the second device and the first device;

[0651] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0652] First security strategy.

[0653] In some embodiments, the method further comprises:

[0654] Receive data transmitted by the second device, where the data is protected by the negotiated security context.

[0655] The above optional implementation method can refer to the optional implementation method of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0656] In some embodiments, the method further comprises:

[0657] If the second device fails authentication, or the third message fails verification, the third message is rejected or discarded.

[0658] In the above embodiment, the security policy includes at least one of the following:

[0659] an integrity protection strategy for communication signals between the first device and the second device;

[0660] a confidentiality protection strategy for communication signals between the first device and the second device;

[0661] an integrity protection policy for user plane data between the first device and the second device;

[0662] A confidentiality protection policy for user plane data between the first device and the second device.

[0663] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is protection required.

[0664] FIG4a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4a , the communication method may be performed by a second device, and the method includes:

[0665] S401: Receive a first signal sent by a first device.

[0666] The optional implementation of step S401 can refer to the optional implementation of step S201 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0667] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0668] S402: Send a third message to the first device.

[0669] The optional implementation of step S402 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0670] In some embodiments, the third message includes data collected by the second device.

[0671] In some embodiments, the third message may further include at least one of the following:

[0672] device information of the second device;

[0673] service information used by the second device;

[0674] candidate security algorithms supported by the second device;

[0675] a security policy used by the second device;

[0676] The security verification parameter is used to perform security protection on the third message.

[0677] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0678] In some embodiments, the third message is security-protected based on the first security material.

[0679] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0680] S403: Receive a fifth message sent by the first device.

[0681] The optional implementation of step S403 can refer to the optional implementation of step S204 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0682] In some embodiments, the fifth message carries indication information for indicating whether the third message is received successfully or failed.

[0683] Optionally, the fifth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0684] FIG4 b is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4 b , the communication method may be performed by a second device, and the method includes:

[0685] S411. Receive a first signal sent by a first device.

[0686] The optional implementation of step S411 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0687] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0688] S412: Send a third message to the first device.

[0689] The optional implementation of step S412 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0690] In some embodiments, the third message includes: first information for indicating a link establishment request.

[0691] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request.

[0692] In some embodiments, the first information may be carried in a field or information domain in the third message.

[0693] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0694] In some embodiments, the third message may further include at least one of the following:

[0695] device information of the second device;

[0696] service information used by the second device;

[0697] candidate security algorithms supported by the second device;

[0698] a security policy used by the second device;

[0699] The security verification parameter is used to perform security protection on the third message.

[0700] In some embodiments, the third message is security-protected based on the first security material.

[0701] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0702] S413. Receive a fifth message sent by the first device.

[0703] The optional implementation of step S413 can refer to the optional implementation of step S214 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0704] In some embodiments, the fifth message carries indication information for indicating whether the third message is received successfully or failed.

[0705] In some embodiments, if the fifth message includes: first indication information for indicating that the third message is successfully received, the fifth message may also include: security parameters for generating a security context negotiated between the second device and the first device.

[0706] In some embodiments, the fifth message may further include at least one of the following:

[0707] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0708] First security strategy.

[0709] S414: Transmit data to the first device.

[0710] The optional implementation of step S414 can refer to the optional implementation of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0711] In some embodiments, the second device may generate a security context negotiated between the second device and the first device based on the security parameters in the fifth message.

[0712] In some embodiments, the second device may transmit UL data by using the negotiated security context.

[0713] Figure 4c is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 4c, the method involved in the embodiment of the present disclosure is performed by the second device, and the method includes:

[0714] S421. Send a third message to the first device.

[0715] In some embodiments, the third message is security-protected based on the first security material.

[0716] The optional implementation of step S421 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0717] In some embodiments, the first security material includes a security policy, where the security policy is used to determine a security protection method for communication between the first device and the second device.

[0718] In some embodiments, it further includes:

[0719] A first signal sent by the first device is received, wherein the first signal is used to stimulate the second device to send the third message.

[0720] For the optional implementation of the above optional embodiment, reference may be made to the optional implementation of step S201 in FIG. 2 a and other related parts of the embodiment involved in FIG. 2 a , which will not be described in detail here.

[0721] In some embodiments, the third message includes any of the following:

[0722] First information, used to indicate a link establishment request;

[0723] The second device collects data.

[0724] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0725] In some embodiments, the third message further includes at least one of the following:

[0726] device information of the second device;

[0727] service information used by the second device;

[0728] candidate security algorithms supported by the second device;

[0729] a security policy used by the second device;

[0730] The security verification parameter is used to perform security protection on the third message.

[0731] In some embodiments, it further includes:

[0732] Receive a fifth message sent by the first device in response to the third message.

[0733] For the optional implementation of the above optional embodiment, reference may be made to the optional implementation of step S204b of FIG. 2a and other related parts of the embodiment involved in FIG. 2a , which will not be described in detail here.

[0734] Alternatively, the above optional implementation method can refer to the optional implementation method of step S214 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0735] In some embodiments, the fifth message is security-protected based on the first security material.

[0736] In some embodiments, the fifth message carries at least one of the following:

[0737] First indication information, used to indicate that the third message is successfully received;

[0738] security parameters, used to generate a security context negotiated between the second device and the first device;

[0739] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0740] First security strategy.

[0741] In some embodiments, the method further comprises:

[0742] Data is transmitted to the first device, the data being protected by the negotiated security context.

[0743] The above optional implementation method can refer to the optional implementation method of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0744] In the above embodiment, the security policy includes at least one of the following:

[0745] an integrity protection strategy for communication signals between the first device and the second device;

[0746] a confidentiality protection strategy for communication signals between the first device and the second device;

[0747] an integrity protection policy for user plane data between the first device and the second device;

[0748] A confidentiality protection policy for user plane data between the first device and the second device.

[0749] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is protection required.

[0750] Figure 5a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 5a, the communication method can be performed by a third device, and the method includes:

[0751] S501: Receive a first message sent by a first device.

[0752] The optional implementation of step S501 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0753] In some embodiments, the first message is used to request the third device to authenticate and authorize the first device.

[0754] In some embodiments, the first message may be an authorization request message, or a security material request message, but the message name is not limited thereto.

[0755] In this embodiment, the first message may include at least one of the following information:

[0756] device information of the first device;

[0757] device information of the second device;

[0758] service information used by the second device;

[0759] Information about the group to which the second device belongs.

[0760] S502: Send a second message to the first device.

[0761] The optional implementation of step S502 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0762] In some embodiments, the second message carries the first security material.

[0763] In some embodiments, the third device may transmit the first security material to the first device by including it in a second message in response to the first message.

[0764] In this embodiment, the specific contents of the first security material and the security policy can be found in the optional implementation of step S203 in FIG. 2a or the optional implementation of step S213 in FIG. 2b and the related contents involved, which will not be repeated here.

[0765] In some embodiments, the above method may further include:

[0766] Receive a fourth message sent by the second device.

[0767] The above optional implementation manner can refer to the optional implementation manner of step S204a in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0768] In some embodiments, the fourth message includes data received by the first device and / or device information of the second device.

[0769] FIG5b is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG5b, the method according to the embodiment of the present disclosure is used for a third device, and the method includes:

[0770] S511: After the first device is authenticated and authorized, send first security material to the first device.

[0771] The optional implementation of step S511 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0772] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0773] In some embodiments, it further includes:

[0774] receiving a first message sent by the first device, where the first message is used to request authentication and authorization for the first device;

[0775] The above step S511 may include:

[0776] After being authenticated and authorized, the first device sends a second message to the first device, where the second message carries the first security material.

[0777] The above optional implementation methods can refer to the optional implementation methods of step S200-1 and step S200-2 in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0778] In some embodiments, the first message includes at least one of the following:

[0779] device information of the first device;

[0780] device information of the second device;

[0781] service information used by the second device;

[0782] Information about the group to which the second device belongs.

[0783] In some embodiments, it further includes:

[0784] A fourth message sent by the first device is received, where the fourth message carries at least one of device information of the second device and data collected by the second device.

[0785] The above optional implementation manner can refer to the optional implementation manner of step S204a in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0786] In the above embodiment, the first security material further includes at least one of the following:

[0787] Credential information;

[0788] device information of the second device;

[0789] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0790] service information used by the second device;

[0791] Candidate security algorithms.

[0792] In the above embodiment, the security policy includes at least one of the following:

[0793] an integrity protection strategy for communication signals between the first device and the second device;

[0794] a confidentiality protection strategy for communication signals between the first device and the second device;

[0795] an integrity protection policy for user plane data between the first device and the second device;

[0796] A confidentiality protection policy for user plane data between the first device and the second device.

[0797] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is protection required.

[0798] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0799] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units or modules are realized by designing the logical relationship of the elements in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be implemented by a programmable logic device (PLD), taking a field programmable gate array (FPGA) as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, thereby realizing the functions of some or all of the above units or modules.

[0800] All units or modules of the above devices can be implemented in the form of software called by the processor, or in the form of hardware circuits, or partially implemented in the form of software called by the processor, and the remaining part implemented in the form of hardware circuits. In the embodiment of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0801] FIG6 a is a schematic diagram of the structure of a first device according to an embodiment of the present disclosure. As shown in FIG6 a , the first device may include at least one of a first transceiver module 611 and a first processing module 612 .

[0802] In some embodiments, the first processing module 612 is configured to, after the first device is authenticated and authorized, obtain first security material and perform secure communication with the second device based on the first security material;

[0803] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0804] In some optional embodiments, the first processing module 612 is specifically configured to obtain the first security material sent by the third device after the first device is authenticated and authorized by the third device.

[0805] In some optional embodiments, the first transceiver module 611 is used to: send a first message to the third device, where the first message is used to request the third device to authenticate and authorize the first device; after the first device is authenticated and authorized by the third device, the first device receives a second message sent by the third device in response to the first message, where the second message carries the first security material; the first processing module 612 is used to obtain the first security material from the second message.

[0806] In some optional embodiments, the first message includes at least one of the following:

[0807] device information of the first device;

[0808] device information of the second device;

[0809] service information used by the second device;

[0810] Information about the group to which the second device belongs.

[0811] In some optional embodiments, the first security material includes at least one of the following:

[0812] Credential information;

[0813] device information of the second device;

[0814] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0815] service information used by the second device;

[0816] Candidate security algorithms.

[0817] In some optional embodiments, the first transceiver module 611 is also used to: send a first signal to the second device, wherein the first signal is used to stimulate the second device to send a third message; receive a third message sent by the second device, wherein the third message is security-protected based on the first security material.

[0818] In some optional embodiments, the third message includes first information for indicating a link establishment request; and / or, data collected by the second device; or, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0819] In some optional embodiments, the third message further includes at least one of the following:

[0820] device information of the second device;

[0821] service information used by the second device;

[0822] candidate security algorithms supported by the second device;

[0823] a security policy used by the second device;

[0824] The security verification parameter is used to perform security protection on the third message.

[0825] In some optional embodiments, the first processing module 612 is specifically configured to perform at least one of the following:

[0826] authenticating the second device based on the first security material;

[0827] Verify the first message according to the first security material:

[0828] In some optional embodiments, the first processing module 612 is also used to: if the second device passes the authentication, record the device information of the second device and / or the data collected by the second device; the first processing module 611 is also used to: if the second device passes the authentication, send a fourth message to the third device, and / or send a fifth message to the second device in response to the third message, wherein the fourth message carries at least one of the device information of the second device and the data collected by the second device.

[0829] In some optional embodiments, the first transceiver module 611 is further configured to: if the third message passes verification and the first message passes verification, send a fifth message in response to the third message to the second device.

[0830] In some optional embodiments, the fifth message is security-protected based on the first security material.

[0831] In some optional embodiments, the fifth message carries at least one of the following:

[0832] first indication information, used to indicate that the first message is successfully received;

[0833] security parameters, used to generate a security context negotiated between the second device and the first device;

[0834] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0835] First security strategy.

[0836] In some optional embodiments, the first transceiver module 611 is further configured to: receive data transmitted by the second device, where the data is protected by the negotiated security context.

[0837] In some optional embodiments, the first processing module 612 is further configured to: reject or discard the third message if the second device fails authentication or the first message fails verification.

[0838] In some optional embodiments, the security policy includes at least one of the following:

[0839] an integrity protection strategy for communication signals between the first device and the second device;

[0840] a confidentiality protection strategy for communication signals between the first device and the second device;

[0841] an integrity protection policy for user plane data between the first device and the second device;

[0842] A confidentiality protection policy for user plane data between the first device and the second device.

[0843] In some optional embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0844] FIG6 b is a schematic diagram of the structure of the second device proposed in an embodiment of the present disclosure. As shown in FIG6 b , the second device includes at least one of a second transceiver module 621 and a second processing module 622 .

[0845] In some embodiments, the second transceiver module 621 is configured to send a third message to the first device;

[0846] wherein the third message is security-protected based on the first security material;

[0847] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0848] In some optional embodiments, the second transceiver module 621 is further used to: receive a first signal sent by the first device, wherein the first signal is used to stimulate the second device to send the third message.

[0849] In some optional embodiments, the third message includes any one of the following:

[0850] First information, used to indicate a link establishment request;

[0851] data collected by the second device;

[0852] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0853] In some optional embodiments, the third message further includes at least one of the following:

[0854] device information of the second device;

[0855] service information used by the second device;

[0856] candidate security algorithms supported by the second device;

[0857] a security policy used by the second device;

[0858] The security verification parameter is used to perform security protection on the third message.

[0859] In some optional embodiments, the second transceiver module 621 is further configured to receive a fifth message sent by the first device in response to the third message.

[0860] In some optional embodiments, the fifth message is security-protected based on the first security material.

[0861] In some optional embodiments, the fifth message carries at least one of the following:

[0862] First indication information, used to indicate that the third message is successfully received;

[0863] security parameters, used to generate a security context negotiated between the second device and the first device;

[0864] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0865] First security strategy.

[0866] In some optional embodiments, the second transceiver module 621 is further configured to: transmit data to the first device, where the data is protected by the negotiated security context.

[0867] In some optional embodiments, the security policy includes at least one of the following:

[0868] an integrity protection strategy for communication signals between the first device and the second device;

[0869] a confidentiality protection strategy for communication signals between the first device and the second device;

[0870] an integrity protection policy for user plane data between the first device and the second device;

[0871] A confidentiality protection policy for user plane data between the first device and the second device.

[0872] In some optional embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0873] FIG6c is a schematic diagram of the structure of the third device proposed in an embodiment of the present disclosure. As shown in FIG6c, the third device includes: at least one of a third transceiver module 631 and a third processing module 632.

[0874] In some embodiments, the third transceiver module 631 is configured to send the first security material to the first device after the first device is authenticated and authorized;

[0875] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0876] In some optional embodiments, the third transceiver module 631 is also used to: receive a first message sent by the first device, the first message is used to request authentication and authorization of the first device; after the first device is authenticated and authorized, the second message is sent to the first device, and the second message carries the first security material.

[0877] In some optional embodiments, the first message includes at least one of the following:

[0878] device information of the first device;

[0879] device information of the second device;

[0880] service information used by the second device;

[0881] Information about the group to which the second device belongs.

[0882] In some optional embodiments, the third transceiver module 631 is further used to: receive a fourth message sent by the first device, where the fourth message carries at least one of the device information of the second device and the data collected by the second device.

[0883] In some optional embodiments, the first security material further includes at least one of the following:

[0884] Credential information;

[0885] device information of the second device;

[0886] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0887] service information used by the second device;

[0888] Candidate security algorithms.

[0889] In some optional embodiments, the security policy includes at least one of the following:

[0890] an integrity protection strategy for communication signals between the first device and the second device;

[0891] a confidentiality protection strategy for communication signals between the first device and the second device;

[0892] an integrity protection policy for user plane data between the first device and the second device;

[0893] A confidentiality protection policy for user plane data between the first device and the second device.

[0894] In some optional embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0895] The present disclosure also provides an optional implementation scheme, using a terminal (hereinafter referred to as UE) as an intermediate node. It is assumed that the A-IoT device is pre-configured with security materials for device authentication and message protection (which may correspond to the first security material mentioned above).

[0896] In an optional embodiment, the method shown in FIG7a includes the following steps:

[0897] S701. UE authentication and authorization are performed between the UE and the CN NF or AAA server or A-IoT AS (which may correspond to the third device mentioned above).

[0898] The implementation of step S701 can refer to the optional implementation of step S200-1 and step S200-2 in Figure 2a, which will not be repeated here.

[0899] In some embodiments, once the UE is authenticated and authorized, the security material used by the A-IoT device is provided to the UE.

[0900] In some embodiments, the security material may include: A-IoT device ID, relevant credentials and relevant security policies.

[0901] In some embodiments, the UE may utilize the provided security material to authenticate the A-IoT device and verify received messages.

[0902] In some embodiments, the AAA server or A-IoT AS may pre-provision security policies and other necessary parameters to the CN NF.

[0903] In some embodiments, the provided security material (which may correspond to the first security material above) may be associated with a group of A-IoT devices. In this case, all A-IoT device IDs in the group are provided to the UE.

[0904] S702. The UE sends an excitation signal (which may correspond to the first signal mentioned above) to the A-IoT device (which may correspond to the second device mentioned above).

[0905] In some embodiments, the UE may send an unmodulated excitation signal and wait for a reply message from the A-IoT device.

[0906] S703. The A-IoT device sends a report message to the UE (which may correspond to the third message above).

[0907] Once the A-IoT device receives the excitation signal, it reflects the backscattered signal and forms an initial device message (eg, a report message, which may include a data report message or an identity report message), which is protected or encoded by the first security material.

[0908] Optionally, the initial device message may include: the ID of the A-IoT device, the data collected by the A-IoT device, and the MAC value (which may correspond to the security verification parameters mentioned above).

[0909] S704: The UE verifies the received message by using the provided security material (which may correspond to the first security material mentioned above).

[0910] In some embodiments, if the device ID of the received A-IoT device is included in the ID of the A-IoT device included in the provided first security material, or can be mapped to an ID of an A-IoT device in the ID of the A-IoT device included in the provided first security material, and the MAC value verification is passed, the UE records the received data and / or A-IoT device ID, and can report to the CN NF or A-IoT AS.

[0911] Otherwise, the UE discards the report message.

[0912] In another optional embodiment, the method shown in FIG7b includes the following steps:

[0913] S711. UE authentication and authorization are performed between the UE and the CN NF or AAA server or A-IoT AS (which may correspond to the third device mentioned above).

[0914] The implementation of step S711 can refer to the optional implementation of step S200-1 and step S200-2 in Figure 2a, which will not be repeated here.

[0915] In some embodiments, once the UE is authenticated and authorized, the security material used by the A-IoT device is provided to the UE.

[0916] In some embodiments, the security material may include: A-IoT device ID, relevant credentials and relevant security policies.

[0917] In some embodiments, the UE may utilize the provided security material to authenticate the A-IoT device and verify received messages.

[0918] In some embodiments, the AAA server or A-IoT AS may pre-provision security policies and other necessary parameters to the CN NF.

[0919] In some embodiments, the provided security material (which may correspond to the first security material above) may be associated with a group of A-IoT devices. In this case, all A-IoT device IDs in the group are provided to the UE.

[0920] S712. The UE sends an excitation signal (which may correspond to the first signal mentioned above) to the A-IoT device (which may correspond to the second device mentioned above).

[0921] In some embodiments, the UE may send an unmodulated excitation signal and wait for a reply message from the A-IoT device.

[0922] S713. The A-IoT device sends a request message to the UE (which may correspond to the third message above).

[0923] Once the A-IoT device receives the excitation signal, it reflects the backscattered signal and forms an initial device message (eg, a service request message or a link establishment request message), which is protected or encoded by the first security material.

[0924] Optionally, if the initial device message can include: A-IoT device ID and MAC value (which can correspond to the security verification parameters mentioned above).

[0925] S714. The UE verifies the received message by using the provided security material (which may correspond to the first security material mentioned above).

[0926] S715. The UE sends an ACK message (which may correspond to the fifth message above) in response to the A-IoT device to the A-IoT device.

[0927] In some embodiments, if the device ID of the received A-IoT device is included in the ID of the A-IoT device included in the provided first security material, or can be mapped to an ID of an A-IoT device among the IDs of the A-IoT devices included in the provided first security material, and the MAC value is verified, the UE can respond to the AIoT device with an ACK message.

[0928] Otherwise, the UE discards the report message.

[0929] In some embodiments, the ACK message may include security parameters used to generate a security context negotiated between the AIoT device and the UE.

[0930] In some embodiments, the ACK message is security-protected based on the first security material. Optionally, the ACK is protected or encoded by the first security material.

[0931] S716 : The A-IoT device transmits data to the UE by using the negotiated security context.

[0932] In some embodiments, once the A-IoT device receives the ACK message, it can generate a security context negotiated between the A-IoT device and the UE based on the security parameters in the ACK message, and transmit UL data by using the negotiated security context.

[0933] In the above embodiments, the CN (e.g., PCF or AIoT MF) or AAA server or A-IoT AS can provide a security policy for communicating with the ambient IoT devices by configuring a list of ambient IoT applications or services that require security protection, and a security policy for each ambient IoT in the list.

[0934] In some embodiments, the security policy is configured as follows:

[0935] Signal integrity protection: required

[0936] Signal confidentiality protection: required / optional (PREFERRED) / not needed (NOT NEEDED)

[0937] User plane integrity protection: Required / Preferred / Not required

[0938] User plane confidentiality protection: Required / Preferred / Not required

[0939] Here, "required" means that the UE will accept the connection only if a non-NULL confidentiality or integrity algorithm is used to protect the communication between the UE and the ambient IoT.

[0940] “Not required” means that the UE can only establish a connection without security protection.

[0941] "Optional" means that the UE may attempt to establish a connection with security protection, but may accept a connection without security protection. One use of optional protection is to enable security policy to be changed without updating all involved UEs at the same time.

[0942] In some embodiments, there are several scenarios for setting security policies:

[0943] 1. If the security policy is provided by PCF, the configuration data of the security policy should be provided during the service authorization and information provision process.

[0944] 2. If the AIoTMF provides security policies through the control plane or user plane, the configuration data of the security policies should be provided during the authorization process of the Ambient IoT intermediate nodes.

[0945] 3. If the security policy is provided by the AAA server / A-IoT AS, the configuration data of the security policy should be provided at the application layer.

[0946] Figure 8a is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0947] As shown in Figure 8a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, baseband chip, terminal device, terminal device chip, DU or CU, etc.), execute programs, and process program data. The processor 8101 is used to call instructions to enable the communication device 8100 to perform any of the above methods.

[0948] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps such as sending and / or receiving in the above method (for example, at least one of steps S200-1, S200-2, S201, S202, S204a, S204b shown in FIG2a, and steps S210-1, S210-2, S211, S212, S214, and S215 shown in FIG2b, but not limited thereto), and the processor 8101 performs at least one of the other steps (for example, at least one of step S203 shown in FIG2a and step S213 shown in FIG2b, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be replaced with each other, terms such as transmitter, transmitting unit, transmitter, and transmitting circuit can be replaced with each other, and terms such as receiver, receiving unit, receiver, and receiving circuit can be replaced with each other.

[0949] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may be located outside the communication device 8100.

[0950] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.

[0951] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0952] The communication device 8100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 8100 described in the embodiment of the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8a. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0953] FIG8b is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, reference can be made to the schematic diagram of the structure of the chip 8200 shown in FIG8b, but the present disclosure is not limited thereto.

[0954] The chip 8200 includes one or more processors 8201. The chip 8200 is configured to execute any of the above methods.

[0955] In some embodiments, chip 8200 further includes one or more interface circuits 8202. Optionally, terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 8200 further includes one or more memories 8203 for storing data. Optionally, all or part of memory 8203 may be located outside chip 8200. Optionally, interface circuit 8202 is connected to memory 8203 and may be used to receive data from memory 8203 or other devices, or may be used to send data to memory 8203 or other devices. For example, interface circuit 8202 may read data stored in memory 8203 and send the data to processor 8201.

[0956] In some embodiments, the interface circuit 8202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., at least one of steps S200-1, S200-2, S201, S202, S204a, S204b shown in FIG. 2a , and steps S210-1, S210-2, S211, S212, S214, and S215 shown in FIG. 2b , but not limited thereto). The interface circuit 8202 performing the communication steps such as sending and / or receiving in the above method, for example, means that the interface circuit 8202 performs data exchange between the processor 8201, the chip 8200, the memory 8203, or the transceiver device. In some embodiments, the processor 8201 performs at least one of the other steps (e.g., at least one of step S203 shown in FIG. 2a and step S213 shown in FIG. 2b , but not limited thereto).

[0957] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0958] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

[0959] The technical solutions described in the embodiments of the present disclosure can be arbitrarily combined without conflict.

[0960] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow from the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.

[0961] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A communication method, characterized in that: The method is performed by a first device and includes: After authentication and authorization, the first device obtains the first security material; securely communicating with a second device based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

2. The method according to claim 1, characterized in that After authentication and authorization, the first device obtains the first security material, including: After being authenticated and authorized by a third device, the first device obtains the first security material sent by the third device.

3. The method according to claim 2, characterized in that Acquiring the first security material sent by the third device includes: Sending a first message to the third device, where the first message is used to request the third device to authenticate and authorize the first device; After being authenticated and authorized by a third device, the first device receives a second message sent by the third device in response to the first message, where the second message carries the first security material; The first security material is obtained from the second message.

4. The method according to claim 3, characterized in that The first message includes at least one of the following: device information of the first device; device information of the second device; service information used by the second device; Information about the group to which the second device belongs.

5. The method according to any one of claims 1 to 4, characterized in that The first safety material includes at least one of the following: Credential information; device information of the second device; Device information of a group of devices, wherein the second device is one of the devices in the group; service information used by the second device; Candidate security algorithms.

6. The method according to claim 5, characterized in that Also includes: sending a first signal to the second device, wherein the first signal is used to encourage the second device to send a third message; A third message sent by the second device is received, wherein the third message is security-protected based on the first security material.

7. The method according to claim 6, characterized in that The third message includes first information for indicating a link establishment request; and / or data collected by the second device; Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

8. The method according to claim 7, characterized in that The third message further includes at least one of the following: device information of the second device; service information used by the second device; candidate security algorithms supported by the second device; a security policy used by the second device; The security verification parameter is used to perform security protection on the third message.

9. The method according to claim 7 or 8, characterized in that The secure communication with the second device based on the first security material includes at least one of the following: authenticating the second device based on the first security material; The first message is verified based on the first security material.

10. The method according to claim 9, characterized in that The method further comprises: If the second device passes authentication, perform at least one of the following operations: Recording device information of the second device; recording data collected by the second device; sending a fourth message to a third device, where the fourth message carries at least one of device information of the second device and data collected by the second device; A fifth message in response to the third message is sent to the second device.

11. The method according to claim 9, characterized in that The method further comprises: If the third message passes verification and the first message passes verification, a fifth message in response to the third message is sent to the second device.

12. The method according to claim 10 or 11, characterized in that The fifth message is security-protected based on the first security material.

13. The method according to claim 10 or 11, characterized in that The fifth message carries at least one of the following: first indication information, used to indicate that the first message is successfully received; security parameters, used to generate a security context negotiated between the second device and the first device; a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material; First security strategy.

14. The method according to claim 13, wherein: The method further comprises: Receive data transmitted by the second device, where the data is protected by the negotiated security context.

15. The method according to claim 9, characterized in that The method further comprises: If the second device authentication fails, or the first message verification fails, the third message is rejected or discarded.

16. The method according to any one of claims 1 to 15, characterized in that The security policy includes at least one of the following: an integrity protection strategy for communication signals between the first device and the second device; a confidentiality protection strategy for communication signals between the first device and the second device; an integrity protection policy for user plane data between the first device and the second device; A confidentiality protection policy for user plane data between the first device and the second device.

17. The method according to claim 16, characterized in that The integrity protection policy of the communication signal between the first device and the second device is that protection is required.

18. A communication method, characterized in that: The method is performed by a second device, and includes: sending a third message to the first device; wherein the third message is security-protected based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

19. The method according to claim 17, wherein Also includes: A first signal sent by the first device is received, wherein the first signal is used to stimulate the second device to send the third message.

20. The method according to claim 18 or 19, characterized in that The third message includes any one of the following: First information, used to indicate a link establishment request; data collected by the second device; Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

21. The method according to claim 20, characterized in that The third message further includes at least one of the following: device information of the second device; service information used by the second device; candidate security algorithms supported by the second device; a security policy used by the second device; The security verification parameter is used to perform security protection on the third message.

22. The method according to any one of claims 18 to 21, characterized in that Also includes: Receive a fifth message sent by the first device in response to the third message.

23. The method according to claim 22, characterized in that The fifth message is security-protected based on the first security material.

24. The method according to claim 22 or 23, characterized in that The fifth message carries at least one of the following: First indication information, used to indicate that the third message is successfully received; security parameters, used to generate a security context negotiated between the second device and the first device; a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material; First security strategy.

25. The method according to claim 24, characterized in that The method further comprises: Data is transmitted to the first device, the data being protected by the negotiated security context.

26. The method according to any one of claims 18 to 25, characterized in that The security policy includes at least one of the following: an integrity protection strategy for communication signals between the first device and the second device; a confidentiality protection strategy for communication signals between the first device and the second device; an integrity protection policy for user plane data between the first device and the second device; A confidentiality protection policy for user plane data between the first device and the second device.

27. The method according to claim 26, characterized in that The integrity protection policy of the communication signal between the first device and the second device is that protection is required.

28. A communication method, characterized in that: The method is performed by a third device, and includes: After the first device is authenticated and authorized, sending the first security material to the first device; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

29. The method according to claim 28, characterized in that Also includes: receiving a first message sent by the first device, where the first message is used to request authentication and authorization for the first device; After being authenticated and authorized, the first device sends a second message to the first device, where the second message carries the first security material.

30. The method according to claim 29, wherein The first message includes at least one of the following: device information of the first device; device information of the second device; service information used by the second device; Information about the group to which the second device belongs.

31. The method according to any one of claims 28 to 30, characterized in that Also includes: A fourth message sent by the first device is received, where the fourth message carries at least one of device information of the second device and data collected by the second device.

32. The method according to any one of claims 28 to 31, characterized in that The first security material further includes at least one of the following: Credential information; device information of the second device; Device information of a group of devices, wherein the second device is one of the devices in the group; service information used by the second device; Candidate security algorithms.

33. The method according to any one of claims 28 to 32, characterized in that The security policy includes at least one of the following: an integrity protection strategy for communication signals between the first device and the second device; a confidentiality protection strategy for communication signals between the first device and the second device; an integrity protection policy for user plane data between the first device and the second device; A confidentiality protection policy for user plane data between the first device and the second device.

34. The method according to claim 33, wherein The integrity protection policy of the communication signal between the first device and the second device is that protection is required.

35. A communication method, characterized in that: The method is performed by a communication system, the communication system including a first device, a second device, and a third device, and the method includes: After the first device is authenticated and authorized, the third device sends a second message to the first device, where the second message includes security material; The second device sends a third message to the first device; The first device determines, based on the third message, a first security material from the security material included in the second message, and performs secure communication with the second device according to the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

36. A first device, characterized in that include: A first processing module is configured to, after the first device is authenticated and authorized, obtain first security material and perform secure communication with the second device based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

37. A second device, characterized in that: include: A second transceiver module, configured to send a third message to the first device; wherein the third message is security-protected based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

38. A third device, characterized in that: include: a third transceiver module, configured to send the first security material to the first device after the first device is authenticated and authorized; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

39. A first device, characterized in that include: one or more processors; The first device is configured to execute the communication method described in any one of claims 1 to 17.

40. A second device, characterized in that include: one or more processors; The second device is configured to execute the communication method described in any one of claims 18 to 27.

41. A third device, characterized in that: include: one or more processors; The third device is configured to execute the communication method described in any one of claims 28 to 34.

42. A computer-readable storage medium having a computer program stored thereon, characterized in that: The computer-readable storage medium stores executable instructions, which are loaded and executed by the processor to implement the communication method described in any one of claims 1 to 17, or claims 18 to 27, or claims 28 to 34.

Citation Information

Patent Citations

  • Information processing method and device, communication system and storage medium

    CN117121526A

  • Communication method and device, communication equipment, communication system and storage medium

    CN117136574A

  • Wireless communication method and apparatus

    WO2022147838A1

  • Security protection method and communication apparatus

    WO2023213191A1