Tag authentication method and device and computer program product

By using the concept of group in the Internet of Things system to manage and authenticate tags, and using authentication information verification to generate tag authentication responses, the problem of insufficient authentication of IoT passive tags is solved, and security is improved and contract information storage needs are reduced.

WO2025162156A1PCT designated stage Publication Date: 2025-08-07DATANG MOBILE COMM EQUIP CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/074122
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-04
Filing Date
2025-01-23
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

The lack of effective authentication schemes for IoT passive tags in the prior art leads to insufficient security.

Method used

The concept of group is used to manage the Internet of Things tags, and authenticate by receiving authentication information sent by the authentication entity, including verification of the core network one-time value, the authenticated network element one-time value, the first group member identification and the network element authentication token, etc., to generate a tag authentication response to enhance security.

Benefits of technology

Effective authentication of IoT passive tags has been achieved, the security and credibility of the system have been improved, and the number of contract information stored on the core network has been reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025074122_07082025_PF_FP_ABST
    Figure CN2025074122_07082025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical filed of communications. Disclosed are a tag authentication method and device and a computer program product. The method comprises: receiving a first request sent by an authentication entity, wherein the first request comprises authentication information, the authentication information is generated on the basis of information of a tag group to which a tag belongs, and the tag group comprises one or more tags; and performing authentication on the basis of the first request.
Need to check novelty before this filing date? Find Prior Art

Description

Label authentication method, device, and computer program product

[0001] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on February 4, 2024, with application number 202410158017.3 and application name “Label Authentication Method, Device and Computer Program Product”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] The present disclosure relates to the field of communication technologies, and in particular to a tag authentication method, device, and computer program product. Background Art

[0003] The Ambient Internet of Things (IoT) will explore the use of Third Generation Partnership Projects (3GPP) technologies to read passive tags used in IoT applications. Given the limited capabilities of passive Radio Frequency Identification (RFID) tags, this research will employ simplified architectures and protocols, including security. However, no authentication solutions for IoT passive tags exist. Summary of the Invention

[0004] The embodiments of the present disclosure provide a tag authentication method, device, and computer program product to implement authentication of passive tags of the Internet of Things.

[0005] In a first aspect, an embodiment of the present disclosure provides a tag authentication method, applied to a tag, comprising:

[0006] receiving a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags;

[0007] Authentication is performed according to the first request.

[0008] In some embodiments, the authentication information includes one or more of the following:

[0009] One-time value of the core network;

[0010] One-time value of authentication network element;

[0011] First group member identification;

[0012] Network element authentication token;

[0013] The first anti-replay attack parameter.

[0014] In some embodiments, performing authentication according to the first request includes:

[0015] Verifying the first group member identifier;

[0016] Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier;

[0017] If the verification of the first group member identifier and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0018] In some embodiments, the method further comprises:

[0019] Verifying a first group authentication key according to the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group authentication key is a group authentication key used by the authentication entity when generating the network element authentication token;

[0020] Generating a tag authentication response includes:

[0021] If the verification of the first group member identifier, the verification of the first group authentication key, and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0022] In some embodiments, verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier includes:

[0023] generating a second group of authentication keys based on the group key and the core network one-time value;

[0024] generating a group member authentication key according to the second group authentication key, the authentication network element one-time value, and the first group member identifier;

[0025] The network element authentication token is verified according to the group member authentication key.

[0026] In some embodiments, generating a tag authentication response includes:

[0027] Generate a one-time value for the tag;

[0028] generating a data protection key based on the group member authentication key and the tag one-time value;

[0029] The tag authentication response is generated according to the data protection key.

[0030] In some embodiments, the method further comprises:

[0031] The first anti-replay attack parameter and / or the data protection key in the authentication information is stored.

[0032] In some embodiments, the method further comprises:

[0033] Sending a first response to the authentication entity, wherein the first response includes one or more of the following:

[0034] the tag authentication response;

[0035] The one-time value of the tag.

[0036] In some embodiments, the method further comprises:

[0037] Receive the tag temporary identifier ciphertext sent by the authentication entity, wherein the tag temporary identifier ciphertext includes the tag temporary identifier.

[0038] In some embodiments, the method further comprises:

[0039] Receive group subscription information sent by the contracting entity, where the group subscription information includes one or more of the following:

[0040] Group ID;

[0041] Second group member identification;

[0042] Group key;

[0043] Second anti-replay attack parameter.

[0044] In a second aspect, an embodiment of the present disclosure provides a tag authentication method, which is applied to an authentication entity and includes:

[0045] receiving a first message sent by a contracting entity;

[0046] A first request is sent to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0047] In some embodiments, the first information includes one or more of the following:

[0048] The first set of authentication keys;

[0049] One-time value of the core network;

[0050] The first anti-replay attack parameter.

[0051] In some embodiments, sending the first request to the tag includes:

[0052] Generate a one-time value for the authentication network element;

[0053] generating a group member authentication key according to the first group authentication key, the first group member identifier, and the authentication network element one-time value;

[0054] generating a network element authentication token according to the group member authentication key;

[0055] Send a first request to the tag, wherein the first request includes authentication information, and the authentication information includes one or more of the following:

[0056] The core network one-time value;

[0057] The one-time value of the authentication network element;

[0058] the first group member identifier;

[0059] The network element authentication token;

[0060] The first anti-replay attack parameter.

[0061] In some embodiments, the method further comprises:

[0062] Receive a first response sent by the tag, where the first response includes one or more of the following:

[0063] Tag authentication response;

[0064] Label one-time value.

[0065] In some embodiments, the method further comprises:

[0066] Sending a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

[0067] In some embodiments, the temporary tag identification ciphertext is generated by:

[0068] generating a data protection key based on the group member authentication key of the authentication entity and the tag one-time value;

[0069] verifying the tag authentication response based on the data protection key;

[0070] If the authentication of the tag authentication response is passed, a temporary tag identifier is generated;

[0071] The tag temporary identifier ciphertext is generated using the data protection key and the tag temporary identifier.

[0072] In a third aspect, an embodiment of the present disclosure provides a tag authentication method, which is applied to a contracting entity and includes:

[0073] First information is sent to an authentication entity for sending a first request to a tag, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0074] In some embodiments, the method further comprises:

[0075] Sending group subscription information to the tag, wherein the group subscription information includes one or more of the following:

[0076] Group ID;

[0077] Second group member identification;

[0078] Group key;

[0079] Second anti-replay attack parameter.

[0080] In some embodiments, the method further comprises:

[0081] A first group authentication key is generated according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

[0082] In some embodiments, the first information includes one or more of the following:

[0083] the first set of authentication keys;

[0084] The core network one-time value;

[0085] The first anti-replay attack parameter.

[0086] In a fourth aspect, an embodiment of the present disclosure provides a tag authentication device, which is applied to a tag and includes: a memory, a transceiver, and a processor:

[0087] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0088] receiving a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags;

[0089] Authentication is performed according to the first request.

[0090] In some embodiments, the authentication information includes one or more of the following:

[0091] One-time value of the core network;

[0092] One-time value of authentication network element;

[0093] First group member identification;

[0094] Network element authentication token;

[0095] The first anti-replay attack parameter.

[0096] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0097] Verifying the first group member identifier;

[0098] Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier;

[0099] If the verification of the first group member identifier and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0100] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0101] Verifying a first group authentication key according to the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group authentication key is a group authentication key used by the authentication entity when generating the network element authentication token;

[0102] If the verification of the first group member identifier, the verification of the first group authentication key, and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0103] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0104] generating a second group of authentication keys based on the group key and the core network one-time value;

[0105] generating a group member authentication key according to the second group authentication key, the authentication network element one-time value, and the first group member identifier;

[0106] The network element authentication token is verified according to the group member authentication key.

[0107] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0108] Generate a one-time value for the tag;

[0109] generating a data protection key based on the group member authentication key and the tag one-time value;

[0110] The tag authentication response is generated according to the data protection key.

[0111] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0112] The first anti-replay attack parameter and / or the data protection key in the authentication information is stored.

[0113] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0114] Sending a first response to the authentication entity, wherein the first response includes one or more of the following:

[0115] the tag authentication response;

[0116] The one-time value of the tag.

[0117] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0118] Receive the tag temporary identifier ciphertext sent by the authentication entity, wherein the tag temporary identifier ciphertext includes the tag temporary identifier.

[0119] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0120] Receive group subscription information sent by the contracting entity, where the group subscription information includes one or more of the following:

[0121] Group ID;

[0122] Second group member identification;

[0123] Group key;

[0124] Second anti-replay attack parameter.

[0125] In a fifth aspect, an embodiment of the present disclosure provides a tag authentication device, which is applied to an authentication entity and includes: a memory, a transceiver, and a processor:

[0126] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0127] receiving a first message sent by a contracting entity;

[0128] A first request is sent to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0129] In some embodiments, the first information includes one or more of the following:

[0130] The first set of authentication keys;

[0131] One-time value of the core network;

[0132] The first anti-replay attack parameter.

[0133] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0134] Generate a one-time value for the authentication network element;

[0135] generating a group member authentication key according to the first group authentication key, the first group member identifier, and the authentication network element one-time value;

[0136] generating a network element authentication token according to the group member authentication key;

[0137] Send a first request to the tag, wherein the first request includes authentication information, and the authentication information includes one or more of the following:

[0138] The core network one-time value;

[0139] The one-time value of the authentication network element;

[0140] the first group member identifier;

[0141] The network element authentication token;

[0142] The first anti-replay attack parameter.

[0143] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0144] Receive a first response sent by the tag, where the first response includes one or more of the following:

[0145] Tag authentication response;

[0146] Label one-time value.

[0147] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0148] Sending a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

[0149] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0150] generating a data protection key based on the group member authentication key of the authentication entity and the tag one-time value;

[0151] verifying the tag authentication response based on the data protection key;

[0152] If the authentication of the tag authentication response is passed, a temporary tag identifier is generated;

[0153] The tag temporary identifier ciphertext is generated using the data protection key and the tag temporary identifier.

[0154] In a sixth aspect, an embodiment of the present disclosure provides a tag authentication device, which is applied to a contracting entity and includes: a memory, a transceiver, and a processor:

[0155] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0156] First information is sent to an authentication entity for sending a first request to a tag, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0157] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0158] Sending group subscription information to the tag, wherein the group subscription information includes one or more of the following:

[0159] Group ID;

[0160] Second group member identification;

[0161] Group key;

[0162] Second anti-replay attack parameter.

[0163] In some embodiments, the processor is further configured to read the computer program in the memory and perform the following operations:

[0164] A first group authentication key is generated according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

[0165] In some embodiments, the first information includes one or more of the following:

[0166] the first set of authentication keys;

[0167] The core network one-time value;

[0168] The first anti-replay attack parameter.

[0169] In a seventh aspect, an embodiment of the present disclosure provides a label authentication device, applied to a label, comprising:

[0170] a first receiving unit, configured to receive a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated based on information of a tag group to which the tag belongs, and the tag group includes one or more tags;

[0171] A first authentication unit is configured to perform authentication according to the first request.

[0172] In an eighth aspect, an embodiment of the present disclosure provides a tag authentication device, applied to an authentication entity, comprising:

[0173] A first receiving unit, configured to receive first information sent by a contracting entity;

[0174] The first sending unit is configured to send a first request to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0175] In a ninth aspect, an embodiment of the present disclosure provides a tag authentication device, applied to a contracting entity, comprising:

[0176] The first sending unit is used to send first information to the authentication entity and to send a first request to the tag, wherein the first request includes authentication information, the authentication information is generated according to information of the tag group to which the tag belongs, and the tag group includes one or more tags.

[0177] In a tenth aspect, an embodiment of the present disclosure further provides a processor-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the tag authentication method described above are implemented.

[0178] In an eleventh aspect, an embodiment of the present disclosure further provides a computer program product, comprising computer instructions, which implement the steps in the tag authentication method described above when executed by a processor.

[0179] In the embodiment of the present disclosure, the tag receives the first request sent by the authentication entity and performs authentication according to the first request, thereby achieving authentication of the tag. BRIEF DESCRIPTION OF THE DRAWINGS

[0180] FIG1 is a flowchart of a tag authentication method according to an embodiment of the present disclosure;

[0181] FIG2 is a schematic diagram of a system according to an embodiment of the present disclosure;

[0182] FIG3 is a second flowchart of the tag authentication method provided by an embodiment of the present disclosure;

[0183] FIG4 is a third flowchart of the tag authentication method provided by an embodiment of the present disclosure;

[0184] FIG5 is a fourth flowchart of the tag authentication method provided by an embodiment of the present disclosure;

[0185] FIG6 is a structural diagram of a tag authentication device according to an embodiment of the present disclosure;

[0186] FIG7 is a second structural diagram of the tag authentication device provided in an embodiment of the present disclosure;

[0187] FIG8 is a third structural diagram of a tag authentication device provided in an embodiment of the present disclosure;

[0188] FIG9 is a fourth structural diagram of a tag authentication device provided in an embodiment of the present disclosure;

[0189] FIG10 is a fifth structural diagram of a tag authentication device provided in an embodiment of the present disclosure;

[0190] FIG11 is a sixth structural diagram of the tag authentication device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0191] In the embodiments of the present disclosure, the term "plurality" refers to two or more than two, and other quantifiers are similar thereto.

[0192] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure and not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present disclosure.

[0193] The embodiments of the present disclosure provide a tag authentication method and device for authenticating a tag.

[0194] Among them, the method and the device are based on the same application concept. Since the principles of solving problems by the method and the device are similar, the implementation of the device and the method can refer to each other, and the repeated parts will not be repeated.

[0195] Referring to FIG1 , FIG1 is a flowchart of a tag authentication method provided by an embodiment of the present disclosure, which is applied to a tag, as shown in FIG1 , and includes the following steps:

[0196] Step 101: Receive a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0197] In the embodiments of the present disclosure, a tag may also be referred to as a passive IoT device, a user equipment (UE), a terminal, etc.

[0198] IoT connections feature a large number of connected devices with similar attributes, making them well-suited for group management. For example, devices with the same customer, quality of service (QoS), and policy tags can be grouped together, significantly reducing the number of similar contract information.

[0199] As shown in Figure 2, it is a schematic diagram of the system architecture of an embodiment of the present disclosure. The system may include: a tag, an application system, an authentication entity / operation entity, and a contracting entity. Among them:

[0200] Tags: IoT devices or active or passive tags attached to IoT devices. Security-related data and operations are implemented in the security module to implement security premises and security logic.

[0201] Subscription Entity: The entity that stores group subscription data. In the 3GPP core network, this can be implemented by the Home Subscriber Server (HSS) of the 4th Generation mobile communication technology (4G) or the Unified Data Management (UDM) of the 5th Generation mobile communication technology (5G).

[0202] Authentication entity / operation entity: An entity that interacts with tags to authenticate and securely operate them. In 3GPP systems, this can be implemented by the 4G evolved Node B (eNB) or Mobility Management Entity (MME), and the 5G New Radio (NR) Node B (gNB) or Access and Mobility Management Function (AMF) / Security Anchor Function (SEAF) / Authentication Server Function (AUSF).

[0203] Application system: This is an IoT application system. In the 3GPP system, it can interact with the authentication entity / operation entity through the Network Exposure Function (NEF) or User Plane Function (UPF) and interact with IoT devices.

[0204] In this step, the authentication information is generated based on the information of the tag group to which the tag belongs. It can be understood that the authentication information of a certain tag can be generated based on the information of the tag group to which the tag belongs. The information of the tag group includes but is not limited to the group identifier, group member identifier, etc.

[0205] In the embodiment of the present disclosure, the authentication information includes one or more of the following:

[0206] The core network one-time value can be understood as a value used only once, such as a random number;

[0207] The one-time value of the authentication network element can be understood as a value used only once, such as a random number;

[0208] The first group member identifier (ID);

[0209] Network element authentication token;

[0210] The first anti-replay attack parameter can be understood as a value that changes in a regular sequence.

[0211] Step 102: Perform authentication according to the first request.

[0212] During the authentication process, the tag can be authenticated as follows:

[0213] (1) Verify the first group member identifier.

[0214] The tag stores the group member identifier locally. Therefore, the tag can compare the locally stored group member identifier with the first group member identifier. If the two are consistent, it can be considered that the verification of the first group member identifier has been passed. Otherwise, it is considered that the verification of the first group member identifier has not been passed.

[0215] (2) Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier.

[0216] When verifying the network element authentication token, verification may be performed in combination with one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier.

[0217] For example, a second group authentication key can be generated based on the group key and the core network one-time value; a group member authentication key can be generated based on the second group authentication key, the authentication network element one-time value and the first group member identifier; and the network element authentication token can be verified based on the group member authentication key.

[0218] In some embodiments, the second set of authentication keys may be generated in conjunction with the first anti-replay attack parameter. When verifying the network element authentication token based on the group member authentication key, in some embodiments, verification may also be performed in conjunction with related parameters, such as an authentication device identifier. If verification passes, the authentication entity is deemed to possess the second set of authentication keys.

[0219] For another example, the network element authentication token may be verified based on only one of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier. For example, the network element authentication token may be verified based on the group key stored in the tag, such as by decrypting the network element authentication token using the group key stored in the tag. If decryption is successful, the network element authentication token is considered to have been authenticated; otherwise, the authentication is considered to have failed.

[0220] There is no strict order between (1) and (2).

[0221] (3) If the verification of the first group member identifier and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0222] In some embodiments, in order to further increase security, the tag may also verify the first group of authentication keys based on the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group of authentication keys is the group authentication key used by the authentication entity when generating the network element authentication token. The second anti-replay attack parameter may be obtained from the contracting entity. If the first anti-replay attack parameter matches the second anti-replay attack parameter, it is judged that the first group of authentication keys has not expired, otherwise the first group of authentication keys may be considered expired. For example, if the first anti-replay attack parameter and the second anti-replay attack parameter are random numbers that increase in sequence, and the value of the first anti-replay attack parameter is less than the value of the second anti-replay attack parameter, it is judged that the first group of authentication keys has not expired, otherwise the first group of authentication keys may be considered expired.

[0223] Correspondingly, in this step, if the first group member identifier is verified, the first group authentication key is verified, and the network element authentication token is verified, a tag authentication response is generated.

[0224] In the process of generating the tag authentication response, a tag one-time value is generated, a data protection key is generated based on the group member authentication key and the tag one-time value, and then the tag authentication response is generated based on the data protection key.

[0225] In some embodiments, the tag may further store the first anti-replay attack parameter and / or the data protection key in the authentication information.

[0226] It can be seen from the above description that in the embodiment of the present disclosure, the tag receives the first request sent by the authentication entity and performs authentication according to the first request, thereby achieving authentication of the tag.

[0227] Based on the above embodiment, the tag may further send a first response to the authentication entity, where the first response includes one or more of the following:

[0228] the tag authentication response;

[0229] The one-time value of the tag.

[0230] On the basis of the above embodiment, the tag may further receive a tag temporary identification ciphertext sent by the authentication entity, wherein the tag temporary identification ciphertext includes a tag temporary identification (ID).

[0231] Afterwards, the tag can use the tag temporary ID and data protection key to protect the interaction data.

[0232] In some embodiments, the tag may further receive group subscription information sent by a contracting entity, wherein the group subscription information includes one or more of the following:

[0233] Group ID;

[0234] Second group member identification;

[0235] Group key: used to generate the group authentication key. The group member authentication key can be derived based on the group authentication key and group member identifier.

[0236] Second anti-replay attack parameter: a value that changes in a regular sequence and can be used to generate a group authentication key. The tag uses this value to determine whether a group authentication key has been used.

[0237] Referring to FIG3 , FIG3 is a flowchart of a tag authentication method provided by an embodiment of the present disclosure, which is applied to an authentication entity and includes the following steps:

[0238] Step 301: Receive first information sent by a contracting entity.

[0239] The first information includes one or more of the following:

[0240] The first set of authentication keys;

[0241] One-time value of the core network;

[0242] The first anti-replay attack parameter.

[0243] Among them, the explanation of the core network one-time value and the first anti-replay attack parameter can refer to the description of the aforementioned method embodiment.

[0244] Step 302: Send a first request to the tag based on the first information, wherein the first request includes authentication information, and the authentication information is generated based on information of the tag group to which the tag belongs, and the tag group includes one or more tags.

[0245] In this step, the authentication entity generates a one-time authentication network element value, generates a group member authentication key based on the first group authentication key, the first group member identifier (which can be provided by the core network or an external application system), and the one-time authentication network element value, and generates a network element authentication token based on the group member authentication key. The authentication entity then sends a first request to the tag, where the authentication information includes one or more of the following:

[0246] The core network one-time value;

[0247] The one-time value of the authentication network element;

[0248] the first group member identifier;

[0249] The network element authentication token;

[0250] The first anti-replay attack parameter.

[0251] When generating the group member authentication key, other parameters may also be combined, such as the identifier of the authentication entity.

[0252] In the embodiment of the present disclosure, the tag receives the first request sent by the authentication entity and performs authentication according to the first request, thereby achieving authentication of the tag.

[0253] In some embodiments, the authentication entity may further receive a first response sent by the tag, wherein the first response includes one or more of the following:

[0254] Tag authentication response;

[0255] Label one-time value.

[0256] In some embodiments, the authentication entity may further send a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

[0257] The temporary tag identification ciphertext is generated in the following way:

[0258] Generate a data protection key based on the group member authentication key of the authentication entity and the one-time value of the tag; verify the tag authentication response based on the data protection key; if the authentication of the tag authentication response is passed, generate a tag temporary identifier; use the data protection key and the tag temporary identifier to generate the tag temporary identifier ciphertext.

[0259] Referring to FIG4 , FIG4 is a flowchart of a tag authentication method provided by an embodiment of the present disclosure, which is applied to a contracting entity and includes the following steps:

[0260] Step 401: Send first information to an authentication entity for sending a first request to a tag, wherein the first request includes authentication information, and the authentication information is generated based on information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0261] In some embodiments, the contracting entity may also generate a first group authentication key according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

[0262] The first information includes one or more of the following:

[0263] the first set of authentication keys;

[0264] The core network one-time value;

[0265] The first anti-replay attack parameter.

[0266] In the embodiment of the present disclosure, the tag receives the first request sent by the authentication entity and performs authentication according to the first request, thereby achieving authentication of the tag.

[0267] In some embodiments, the contracting entity may further send group contracting information to the tag, where the group contracting information includes one or more of the following:

[0268] Group ID;

[0269] Second group member identification;

[0270] Group key;

[0271] Second anti-replay attack parameter.

[0272] The implementation process of the embodiment of the present disclosure is described in detail below.

[0273] In the system shown in Figure 2, IoT devices with similar attributes are grouped together, and contract information is managed on a group basis. Groups can also be constructed based on Electronic Product Codes (EPCs). For example, all tags with EPC vendor code A can be grouped together, or all tags with EPC batch code B can be grouped together, with the EPC code used as the group member identifier.

[0274] The tag is uniquely identified by the group ID and the group member ID. The tag stores the group ID (eg, user equipment (UE) ID), device ID (group member ID) and group key.

[0275] The contracting entity randomly generates a group authentication key based on the group key and provides it to the authentication entity;

[0276] The authentication entity generates a tag authentication key using the group authentication key and the device identifier;

[0277] After the authentication entity successfully authenticates the tag, it assigns a temporary identifier to the tag and binds it to the data protection key generated during the authentication process. The operating entity and the tag then use the temporary identifier and data protection key to communicate securely over the air interface.

[0278] In the tag, security (authentication) data and security (authentication) operations are stored and executed in the tag security module, which can prevent illegal tampering of key data, thereby ensuring the trustworthiness and security of the entire system.

[0279] Through the above method, the amount of label subscription information that needs to be stored in the core network can be effectively reduced.

[0280] Referring to FIG5 , FIG5 is a process diagram of an embodiment of the present disclosure, which may include:

[0281] Step 501: The contracting entity (e.g., UDM) generates group contract information, which includes:

[0282] Group ID(UE-ID);

[0283] Group key: used to generate the group authentication key. The group member authentication key can be derived based on the group authentication key and group member identifier.

[0284] Group member ID list (optional);

[0285] Anti-replay attack initial parameter (optional): A value that changes in a regular sequence and can be used to generate the group authentication key. The tag uses this value to determine whether a group authentication key has been used.

[0286] Step 502: When the tag is initialized, the contracting entity (core network) writes the following information into the tag's security module (Universal Subscriber Identity Module, USIM):

[0287] Group ID;

[0288] Group member ID;

[0289] Group key;

[0290] Initial parameters for anti-replay attack (optional).

[0291] Step 503: The contracting entity generates a group authentication key using the following parameters:

[0292] Group key;

[0293] Core network one-time value: a value (e.g., a random number) generated to dynamically generate a group authentication key and used only once;

[0294] Anti-replay attack parameter (optional): a value that changes regularly and is used only once.

[0295] Step 504: The contracting entity provides the group authentication key, the core network one-time value, and the anti-replay attack parameter (optional) to the authentication entity.

[0296] Step 505: The authentication entity performs the following operations to authenticate a specific tag:

[0297] (1) Generate a one-time value for the authentication network element;

[0298] (2) Generate a group member authentication key using the group authentication key, the group member ID (which may be provided by the core network or an external application system), the authentication network element one-time value, and / or other parameters (e.g., the identity of the authentication entity);

[0299] (3) Generate a network element authentication token, which is used to authenticate the security credentials of the authentication entity and can be generated by the group member authentication key and related parameters.

[0300] Step 506: The authentication entity sends an authentication request to the tag and provides the following parameters to the tag:

[0301] One-time value of the core network;

[0302] Anti-replay attack parameters (optional);

[0303] One-time value of authentication network element;

[0304] Group member ID;

[0305] Network element authentication token.

[0306] Step 507: After receiving the tag authentication request sent by the authentication entity, the tag performs the following operations:

[0307] (1) Verify whether the group member ID in the authentication request is consistent with the group member ID stored in this tag; if consistent, continue to perform the following operations;

[0308] (2) Compare the locally stored anti-replay attack parameters with the received anti-replay attack parameters to determine whether the group authentication key has expired. If not, continue to perform the following operations; (optional)

[0309] Generate a group authentication key using the group key, the received core network one-time value, and the anti-replay attack parameter (optional).

[0310] Generate a group member authentication key using the generated group authentication key, the received group member ID, and the authentication network element one-time value;

[0311] The network element authentication token is verified using the group member authentication key and related parameters (such as the authentication entity ID). If the verification is successful, it proves that the authentication entity possesses the group authentication key, and then continues to perform the following operations;

[0312] (3) Generate a one-time value for the tag;

[0313] (4) Generate a data protection key using the group member authentication key and the tag one-time value;

[0314] (5) Generate a tag authentication response using the data protection key and related parameters.

[0315] In some embodiments, the tag may also store the data protection key and the anti-replay attack parameter received in step 506 .

[0316] Step 508: The tag sends a tag authentication response to the authentication entity, which includes the following parameters:

[0317] Tag authentication response;

[0318] Label one-time value.

[0319] Step 509: After receiving the tag authentication response sent by the tag, the authentication entity performs the following operations:

[0320] (1) Generate a data protection key using the group member authentication key and the tag one-time value;

[0321] (2) Verify the tag authentication response using the data protection key and related parameters;

[0322] (3) After the tag passes the authentication, a temporary ID is generated for it;

[0323] (4) Generate the tag temporary ID ciphertext (confidentiality protection and / or integrity protection) using the data protection key.

[0324] If the authentication entity and the operation entity are not the same entity, the authentication entity may provide the tag temporary ID and the data protection key to the operation entity.

[0325] Step 510: The authentication entity provides the tag with a temporary ID ciphertext including the temporary ID.

[0326] Step 511: The tag stores the temporary tag ID.

[0327] Step 512: Use the tag temporary ID and the data protection key to protect the interaction data.

[0328] As can be seen from the above description, in this embodiment, the concept of groups is used to organize common tags into a group, and the generated subscription information describes this group. In this way, the core network only needs to store the group's subscription information and group member information, which can greatly reduce the amount of subscription information for tags.

[0329] The technical solution provided by the embodiment of the present disclosure can be applicable to a variety of systems, especially 5G systems. For example, the applicable system can be a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) general packet radio service (GPRS) system, a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a universal mobile telecommunication system (UMTS), a world-wide interoperability for microwave access (WiMAX) system, a 5G new air interface (NR) system, etc. These various systems include terminal equipment and network equipment. The system may also include a core network part, such as an evolved packet system (EPS), a 5G system (5GS), etc.

[0330] The terminal device involved in the embodiments of the present disclosure may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connection function, or other processing devices connected to a wireless modem. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device may be called User Equipment (UE). A wireless terminal device can communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device may be a mobile terminal device, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal device. For example, it may be a portable, pocket-sized, handheld, computer-built-in or vehicle-mounted mobile device that exchanges voice and / or data with a radio access network. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), and other devices. The wireless terminal device may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, or a user device, but is not limited in the embodiments of the present disclosure.

[0331] The network device involved in the embodiments of the present disclosure may be a base station, which may include multiple cells providing services to terminals. Depending on the specific application scenario, the base station may also be called an access point, or may be a device in an access network that communicates with a wireless terminal device through one or more sectors on an air interface, or may be called another name. The network device may be used to interchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, wherein the rest of the access network may include an Internet Protocol (IP) communication network. The network device may also coordinate the attribute management of the air interface. For example, the network device involved in the embodiments of the present disclosure may be a base transceiver station (BTS) in the Global System for Mobile communications (GSM) or code division multiple access (CDMA), a network device (NodeB) in wide-band code division multiple access (WCDMA), an evolutionary Node B (eNB or e-NodeB) in the long term evolution (LTE) system, a 5G base station (gNB) in the 5G network architecture (next generation system), a home evolved Node B (HeNB), a relay node, a femto, a pico, etc., and is not limited in the embodiments of the present disclosure. In some network structures, the network device may include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit may also be geographically separated.

[0332] Network devices and terminal devices can each use one or more antennas for Multiple Input Multiple Output (MIMO) transmission. MIMO transmission can be single-user MIMO (SU-MIMO) or multi-user MIMO (MU-MIMO). Depending on the configuration and number of antenna combinations, MIMO transmission can be two-dimensional MIMO (2D-MIMO), three-dimensional MIMO (3D-MIMO), full-dimensional MIMO (FD-MIMO), or massive MIMO. It can also use diversity transmission, precoding, or beamforming.

[0333] As shown in FIG6 , the tag authentication device according to an embodiment of the present disclosure, applied to an authentication entity, includes: a processor 600 configured to read a program in a memory 620 and execute the following process:

[0334] receiving a first message sent by a contracting entity;

[0335] A first request is sent to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0336] The transceiver 610 is configured to receive and send data under the control of the processor 600 .

[0337] In FIG6 , the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 600 and memory represented by memory 620. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 610 may be a plurality of components, i.e., including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium. The processor 600 is responsible for managing the bus architecture and general processing, and the memory 620 may store data used by the processor 600 when performing operations.

[0338] The processor 600 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0339] The processor 600 is responsible for managing the bus architecture and general processing, and the memory 620 can store data used by the processor 600 when performing operations.

[0340] In some embodiments, the first information includes one or more of the following:

[0341] The first set of authentication keys;

[0342] One-time value of the core network;

[0343] The first anti-replay attack parameter.

[0344] The processor 600 is further configured to read the program and execute the following steps:

[0345] Generate a one-time value for the authentication network element;

[0346] generating a group member authentication key according to the first group authentication key, the first group member identifier, and the authentication network element one-time value;

[0347] generating a network element authentication token according to the group member authentication key;

[0348] Send a first request to the tag, wherein the first request includes authentication information, and the authentication information includes one or more of the following:

[0349] The core network one-time value;

[0350] The one-time value of the authentication network element;

[0351] the first group member identifier;

[0352] The network element authentication token;

[0353] The first anti-replay attack parameter.

[0354] The processor 600 is further configured to read the program and execute the following steps:

[0355] Receive a first response sent by the tag, where the first response includes one or more of the following:

[0356] Tag authentication response;

[0357] Label one-time value.

[0358] The processor 600 is further configured to read the program and execute the following steps:

[0359] Sending a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

[0360] The processor 600 is further configured to read the program and execute the following steps:

[0361] generating a data protection key based on the group member authentication key of the authentication entity and the tag one-time value;

[0362] verifying the tag authentication response based on the data protection key;

[0363] If the authentication of the tag authentication response is passed, a temporary tag identifier is generated;

[0364] The tag temporary identifier ciphertext is generated using the data protection key and the tag temporary identifier.

[0365] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0366] As shown in FIG7 , the tag authentication device according to an embodiment of the present disclosure, applied to a contracting entity, includes: a processor 700 configured to read a program in a memory 720 and execute the following process:

[0367] First information is sent to an authentication entity for sending a first request to a tag, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0368] The transceiver 710 is configured to receive and send data under the control of the processor 700 .

[0369] In FIG7 , the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 700 and memory represented by memory 720. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 710 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium. The processor 700 is responsible for managing the bus architecture and general processing, and the memory 720 may store data used by the processor 700 when performing operations.

[0370] The processor 700 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0371] The processor 700 is responsible for managing the bus architecture and general processing, and the memory 720 can store data used by the processor 700 when performing operations.

[0372] The processor 700 is further configured to read the program and execute the following steps:

[0373] Sending group subscription information to the tag, wherein the group subscription information includes one or more of the following:

[0374] Group ID;

[0375] Second group member identification;

[0376] Group key;

[0377] Second anti-replay attack parameter.

[0378] The processor 700 is further configured to read the program and execute the following steps:

[0379] A first group authentication key is generated according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

[0380] In some embodiments, the first information includes one or more of the following:

[0381] the first set of authentication keys;

[0382] The core network one-time value;

[0383] The first anti-replay attack parameter.

[0384] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0385] As shown in FIG8 , the tag authentication device according to an embodiment of the present disclosure, applied to a tag, includes: a processor 800 configured to read a program in a memory 820 and execute the following process:

[0386] receiving a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags;

[0387] Authentication is performed according to the first request.

[0388] The transceiver 810 is configured to receive and send data under the control of the processor 800 .

[0389] In FIG8 , the bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors represented by processor 800 and memory represented by memory 820, linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 810 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium. For different user devices, the user interface 830 may also be an interface capable of connecting external or internal devices as required, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, and the like.

[0390] The processor 800 is responsible for managing the bus architecture and general processing, and the memory 820 can store data used by the processor 800 when performing operations.

[0391] The processor 800 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0392] The processor calls the computer program stored in the memory to execute any of the methods provided by the embodiments of the present disclosure according to the obtained executable instructions. The processor and the memory can also be arranged physically separately.

[0393] In some embodiments, the authentication information includes one or more of the following:

[0394] One-time value of the core network;

[0395] One-time value of authentication network element;

[0396] First group member identification;

[0397] Network element authentication token;

[0398] The first anti-replay attack parameter.

[0399] The processor 800 is further configured to read the program and execute the following steps:

[0400] Verifying the first group member identifier;

[0401] Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier;

[0402] If the verification of the first group member identifier and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0403] The processor 800 is further configured to read the program and execute the following steps:

[0404] Verifying a first group authentication key according to the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group authentication key is a group authentication key used by the authentication entity when generating the network element authentication token;

[0405] If the verification of the first group member identifier, the verification of the first group authentication key, and the verification of the network element authentication token are successful, a tag authentication response is generated.

[0406] The processor 800 is further configured to read the program and execute the following steps:

[0407] generating a second group of authentication keys based on the group key and the core network one-time value;

[0408] generating a group member authentication key according to the second group authentication key, the authentication network element one-time value, and the first group member identifier;

[0409] The network element authentication token is verified according to the group member authentication key.

[0410] The processor 800 is further configured to read the program and execute the following steps:

[0411] Generate a one-time value for the tag;

[0412] generating a data protection key based on the group member authentication key and the tag one-time value;

[0413] The tag authentication response is generated according to the data protection key.

[0414] The processor 800 is further configured to read the program and execute the following steps:

[0415] The first anti-replay attack parameter and / or the data protection key in the authentication information is stored.

[0416] The processor 800 is further configured to read the program and execute the following steps:

[0417] Sending a first response to the authentication entity, wherein the first response includes one or more of the following:

[0418] the tag authentication response;

[0419] The one-time value of the tag.

[0420] The processor 800 is further configured to read the program and execute the following steps:

[0421] Receive the tag temporary identifier ciphertext sent by the authentication entity, wherein the tag temporary identifier ciphertext includes the tag temporary identifier.

[0422] The processor 800 is further configured to read the program and execute the following steps:

[0423] Receive group subscription information sent by the contracting entity, where the group subscription information includes one or more of the following:

[0424] Group ID;

[0425] Second group member identification;

[0426] Group key;

[0427] Second anti-replay attack parameter.

[0428] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0429] As shown in FIG9 , the label authentication device according to an embodiment of the present disclosure, applied to a label, includes:

[0430] A first receiving unit 901 is configured to receive a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated based on information of a tag group to which the tag belongs, and the tag group includes one or more tags;

[0431] The first authentication unit 902 is configured to perform authentication according to the first request.

[0432] The authentication information includes one or more of the following:

[0433] One-time value of the core network;

[0434] One-time value of authentication network element;

[0435] First group member identification;

[0436] Network element authentication token;

[0437] The first anti-replay attack parameter.

[0438] In some embodiments, the first authentication unit 902 may include:

[0439] A first verification subunit, configured to verify the first group member identifier;

[0440] a second verification subunit, configured to verify the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier;

[0441] The first generating subunit is configured to generate a tag authentication response if the first group member identifier and the network element authentication token are verified successfully.

[0442] In some embodiments, the first authentication unit 902 may further include:

[0443] A third verification subunit, configured to verify a first group authentication key according to the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group authentication key is a group authentication key used by the authentication entity when generating the network element authentication token;

[0444] The first generating subunit is further configured to generate a tag authentication response if the first group member identifier is verified, the first group authentication key is verified, and the network element authentication token is verified.

[0445] In some embodiments, the second verification subunit is further configured to:

[0446] generating a second group of authentication keys based on the group key and the core network one-time value;

[0447] generating a group member authentication key according to the second group authentication key, the authentication network element one-time value, and the first group member identifier;

[0448] The network element authentication token is verified according to the group member authentication key.

[0449] In some embodiments, the first generating subunit is further configured to:

[0450] Generate a one-time value for the tag;

[0451] generating a data protection key based on the group member authentication key and the tag one-time value;

[0452] The tag authentication response is generated according to the data protection key.

[0453] In some embodiments, the apparatus may further comprise:

[0454] A storage unit is used to store the first anti-replay attack parameter and / or the data protection key in the authentication information.

[0455] In some embodiments, the apparatus may further comprise:

[0456] A first sending unit is configured to send a first response to the authentication entity, wherein the first response includes one or more of the following:

[0457] the tag authentication response;

[0458] The one-time value of the tag.

[0459] In some embodiments, the apparatus may further comprise:

[0460] The second receiving unit is configured to receive the tag temporary identifier ciphertext sent by the authentication entity, wherein the tag temporary identifier ciphertext includes the tag temporary identifier.

[0461] In some embodiments, the apparatus may further comprise:

[0462] The third receiving unit is configured to receive group subscription information sent by the subscription entity, where the group subscription information includes one or more of the following:

[0463] Group ID;

[0464] Second group member identification;

[0465] Group key;

[0466] Second anti-replay attack parameter.

[0467] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0468] As shown in FIG10 , the tag authentication device according to an embodiment of the present disclosure, applied to an authentication entity, includes:

[0469] The first receiving unit 1001 is configured to receive first information sent by a contracting entity;

[0470] The first sending unit 1002 is configured to send a first request to the tag according to the first information, wherein the first request includes authentication information, and the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

[0471] The first information includes one or more of the following:

[0472] The first set of authentication keys;

[0473] One-time value of the core network;

[0474] The first anti-replay attack parameter.

[0475] In some embodiments, the first sending unit 1002 is further configured to:

[0476] Generate a one-time value for the authentication network element;

[0477] generating a group member authentication key according to the first group authentication key, the first group member identifier, and the authentication network element one-time value;

[0478] generating a network element authentication token according to the group member authentication key;

[0479] Send a first request to the tag, wherein the first request includes authentication information, and the authentication information includes one or more of the following:

[0480] The core network one-time value;

[0481] The one-time value of the authentication network element;

[0482] the first group member identifier;

[0483] The network element authentication token;

[0484] The first anti-replay attack parameter.

[0485] In some embodiments, the apparatus may further comprise:

[0486] A second receiving unit is configured to receive a first response sent by the tag, wherein the first response includes one or more of the following:

[0487] Tag authentication response;

[0488] Label one-time value.

[0489] In some embodiments, the apparatus may further comprise:

[0490] The second sending unit is configured to send a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

[0491] In some embodiments, the temporary tag identification ciphertext is generated by:

[0492] generating a data protection key based on the group member authentication key of the authentication entity and the tag one-time value;

[0493] verifying the tag authentication response based on the data protection key;

[0494] If the authentication of the tag authentication response is passed, a temporary tag identifier is generated;

[0495] The tag temporary identifier ciphertext is generated using the data protection key and the tag temporary identifier.

[0496] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0497] As shown in FIG11 , the label authentication device according to an embodiment of the present disclosure, applied to a contracting entity, includes:

[0498] The first sending unit 1101 is used to send first information to the authentication entity, and is used to send a first request to the tag, wherein the first request includes authentication information, and the authentication information is generated according to information of the tag group to which the tag belongs, and the tag group includes one or more tags.

[0499] In some embodiments, the apparatus may further comprise:

[0500] A second sending unit is configured to send group subscription information to the tag, where the group subscription information includes one or more of the following:

[0501] Group ID;

[0502] Second group member identification;

[0503] Group key;

[0504] Second anti-replay attack parameter.

[0505] In some embodiments, the apparatus may further comprise:

[0506] The first generating unit is configured to generate a first group authentication key according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

[0507] In some embodiments, the first information includes one or more of the following:

[0508] the first set of authentication keys;

[0509] The core network one-time value;

[0510] The first anti-replay attack parameter.

[0511] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0512] It should be noted that the division of units in the embodiments of the present disclosure is schematic and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0513] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a computer software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0514] An embodiment of the present disclosure further provides a communication device, comprising: a memory, a processor, and a program stored in the memory and executable on the processor, wherein the processor implements the steps in the tag authentication method described above when executing the program.

[0515] The embodiment of the present disclosure also provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, the various processes of the above-mentioned label authentication method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, they are not repeated here.

[0516] The present disclosure also provides a processor-readable storage medium, on which a program is stored. When the program is executed by the processor, each process of the above-mentioned tag authentication method embodiment is implemented, and the same technical effect is achieved. To avoid repetition, it is not repeated here. The readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as a floppy disk, a hard disk, a magnetic tape, a magneto-optical disk (MO), etc.), optical storage (such as a compact disc (CD), a digital video disc (DVD), a Blu-ray disc (BD), a high-definition versatile disc (HVD), etc.), and semiconductor storage (such as ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), non-volatile memory (NAND (Non-volatile Memory Device) FLASH), solid-state drives (SSD), etc.).

[0517] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0518] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, disk, CD-ROM), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present disclosure.

[0519] It should be noted that it should be understood that the division of the above modules is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. Moreover, these modules can all be implemented in the form of software called by a processing element; or they can all be implemented in the form of hardware; or some modules can be implemented in the form of software called by a processing element, and some modules can be implemented in the form of hardware. For example, the determination module can be a separately established processing element, or it can be integrated into a chip of the above-mentioned device. In addition, it can also be stored in the memory of the above-mentioned device in the form of program code, and called by a processing element of the above-mentioned device to perform the functions of the above-mentioned determination module. The implementation of other modules is similar. In addition, these modules can all or partly be integrated together, or they can be implemented independently. The processing element described here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed by the hardware integrated logic circuit in the processor element or by instructions in the form of software.

[0520] For example, each module, unit, sub-unit or sub-module may be one or more integrated circuits configured to implement the above method, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs). For another example, when a module is implemented by scheduling program code through a processing element, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0521] The terms "first," "second," and the like in the specification and claims of the present disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present disclosure described herein may be implemented in a sequence other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device that includes a series of steps or units need not be limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or devices. In addition, the use of "and / or" in the specification and claims to indicate at least one of the connected objects, for example, A and / or B and / or C, means that seven situations are included: A alone, B alone, C alone, both A and B present, both B and C present, both A and C present, and all A, B, and C present. Similarly, the use of "at least one of A and B" in the specification and claims should be understood to mean "A alone, B alone, or both A and B present."

[0522] The embodiments of the present disclosure are described above in conjunction with the accompanying drawings, but the present disclosure is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present disclosure, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present disclosure and the claims, all of which are protected by the present disclosure.

Claims

1. A tag authentication method, the method being applied to a tag, comprising: receiving a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags; Authentication is performed according to the first request.

2. The method according to claim 1, wherein The authentication information includes one or more of the following: One-time value of the core network; One-time value of authentication network element; First group member identification; Network element authentication token; The first anti-replay attack parameter.

3. The method according to claim 2, wherein: Performing authentication according to the first request includes: Verifying the first group member identifier; Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier; If the verification of the first group member identifier and the verification of the network element authentication token are successful, a tag authentication response is generated.

4. The method according to claim 3, wherein: The method further comprises: Verifying a first group authentication key according to the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group authentication key is a group authentication key used by the authentication entity when generating the network element authentication token; Generating a tag authentication response includes: If the verification of the first group member identifier, the verification of the first group authentication key, and the verification of the network element authentication token are successful, a tag authentication response is generated.

5. The method according to claim 3 or 4, wherein: Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier, includes: generating a second group of authentication keys based on the group key and the core network one-time value; generating a group member authentication key according to the second group authentication key, the authentication network element one-time value, and the first group member identifier; The network element authentication token is verified according to the group member authentication key.

6. The method according to claim 5, wherein: Generating a tag authentication response includes: Generate a one-time value for the tag; generating a data protection key based on the group member authentication key and the tag one-time value; The tag authentication response is generated according to the data protection key.

7. The method according to claim 6, wherein: The method further comprises: The first anti-replay attack parameter and / or the data protection key in the authentication information is stored.

8. The method according to claim 6, wherein: The method further comprises: Sending a first response to the authentication entity, wherein the first response includes one or more of the following: the tag authentication response; The one-time value of the tag.

9. The method according to claim 8, wherein The method further comprises: Receive the tag temporary identifier ciphertext sent by the authentication entity, wherein the tag temporary identifier ciphertext includes the tag temporary identifier.

10. The method according to claim 1, wherein The method further comprises: Receive group subscription information sent by the contracting entity, where the group subscription information includes one or more of the following: Group ID; Second group member identification; Group key; Second anti-replay attack parameter.

11. A tag authentication method, applied to an authentication entity, comprising: receiving a first message sent by a contracting entity; A first request is sent to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

12. The method according to claim 11, wherein The first information includes one or more of the following: The first set of authentication keys; One-time value of the core network; The first anti-replay attack parameter.

13. The method according to claim 12, wherein: The sending of the first request to the tag includes: Generate a one-time value for the authentication network element; generating a group member authentication key according to the first group authentication key, the first group member identifier, and the authentication network element one-time value; generating a network element authentication token according to the group member authentication key; Send a first request to the tag, wherein the first request includes authentication information, and the authentication information includes one or more of the following: The core network one-time value; The one-time value of the authentication network element; the first group member identifier; The network element authentication token; The first anti-replay attack parameter.

14. The method according to claim 11, wherein The method further comprises: Receive a first response sent by the tag, where the first response includes one or more of the following: Tag authentication response; Label one-time value.

15. The method according to claim 14, wherein The method further comprises: Sending a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

16. The method according to claim 15, wherein The temporary tag identification ciphertext is generated in the following way: generating a data protection key based on the group member authentication key of the authentication entity and the tag one-time value; verifying the tag authentication response based on the data protection key; If the authentication of the tag authentication response is passed, a temporary tag identifier is generated; The tag temporary identifier ciphertext is generated using the data protection key and the tag temporary identifier.

17. A tag authentication method, applied to a contracting entity, comprising: First information is sent to an authentication entity for sending a first request to a tag, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

18. The method according to claim 17, wherein The method further comprises: Sending group subscription information to the tag, wherein the group subscription information includes one or more of the following: Group ID; Second group member identification; Group key; Second anti-replay attack parameter.

19. The method according to claim 17, wherein The method further comprises: A first group authentication key is generated according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

20. The method according to claim 19, wherein The first information includes one or more of the following: the first set of authentication keys; The core network one-time value; The first anti-replay attack parameter.

21. A label authentication device, applied to a label, comprising: Memory, transceiver, processor: Memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: receiving a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags; Authentication is performed according to the first request.

22. The device according to claim 21, wherein The authentication information includes one or more of the following: One-time value of the core network; One-time value of authentication network element; First group member identification; Network element authentication token; The first anti-replay attack parameter.

23. The device according to claim 22, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Verifying the first group member identifier; Verifying the network element authentication token according to one or more of the group key stored in the tag, the core network one-time value, the authentication network element one-time value, and the first group member identifier; If the verification of the first group member identifier and the verification of the network element authentication token are successful, a tag authentication response is generated.

24. The device according to claim 23, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Verifying a first group authentication key according to the first anti-replay attack parameter and the second anti-replay attack parameter stored in the tag, wherein the first group authentication key is a group authentication key used by the authentication entity when generating the network element authentication token; If the verification of the first group member identifier, the verification of the first group authentication key, and the verification of the network element authentication token are successful, a tag authentication response is generated.

25. The device according to claim 23 or 24, wherein The processor is further configured to read the computer program in the memory and perform the following operations: generating a second group of authentication keys based on the group key and the core network one-time value; generating a group member authentication key according to the second group authentication key, the authentication network element one-time value, and the first group member identifier; The network element authentication token is verified according to the group member authentication key.

26. The device according to claim 25, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Generate a one-time value for the tag; generating a data protection key based on the group member authentication key and the tag one-time value; The tag authentication response is generated according to the data protection key.

27. The device according to claim 26, wherein The processor is further configured to read the computer program in the memory and perform the following operations: The first anti-replay attack parameter and / or the data protection key in the authentication information is stored.

28. The apparatus according to claim 26, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Sending a first response to the authentication entity, wherein the first response includes one or more of the following: the tag authentication response; The one-time value of the tag.

29. The apparatus according to claim 28, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Receive the tag temporary identifier ciphertext sent by the authentication entity, wherein the tag temporary identifier ciphertext includes the tag temporary identifier.

30. The apparatus according to claim 21, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Receive group subscription information sent by the contracting entity, where the group subscription information includes one or more of the following: Group ID; Second group member identification; Group key; Second anti-replay attack parameter.

31. A tag authentication device, used for authenticating an entity, comprising: Memory, transceiver, processor: memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: receiving a first message sent by a contracting entity; A first request is sent to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

32. The apparatus according to claim 31, wherein The first information includes one or more of the following: The first set of authentication keys; One-time value of the core network; The first anti-replay attack parameter.

33. The apparatus according to claim 32, wherein The processor is further configured to read the computer program in the memory and perform the following operations: Generate a one-time value for the authentication network element; generating a group member authentication key according to the first group authentication key, the first group member identifier, and the authentication network element one-time value; generating a network element authentication token according to the group member authentication key; Send a first request to the tag, wherein the first request includes authentication information, and the authentication information includes one or more of the following: The core network one-time value; The one-time value of the authentication network element; the first group member identifier; The network element authentication token; The first anti-replay attack parameter.

34. The apparatus of claim 31 , wherein: The processor is further configured to read the computer program in the memory and perform the following operations: Receive a first response sent by the tag, where the first response includes one or more of the following: Tag authentication response; Label one-time value.

35. The apparatus of claim 34, wherein: The processor is further configured to read the computer program in the memory and perform the following operations: Sending a tag temporary identification ciphertext to the tag, wherein the tag temporary identification ciphertext includes the tag temporary identification.

36. The apparatus of claim 35, wherein: The temporary tag identification ciphertext is generated in the following way: generating a data protection key based on the group member authentication key of the authentication entity and the tag one-time value; verifying the tag authentication response based on the data protection key; If the authentication of the tag authentication response is passed, a temporary tag identifier is generated; The tag temporary identifier ciphertext is generated using the data protection key and the tag temporary identifier.

37. A label authentication device, applied to a contracting entity, comprising: Memory, transceiver, processor: Memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: First information is sent to an authentication entity for sending a first request to a tag, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

38. The apparatus according to claim 37, wherein The processor is further configured to read the program and execute the following steps: Sending group subscription information to the tag, wherein the group subscription information includes one or more of the following: Group ID; Second group member identification; Group key; Second anti-replay attack parameter.

39. The apparatus of claim 37, wherein: The processor is further configured to read the program and execute the following steps: A first group authentication key is generated according to one or more of a group key of the tag group to which the tag belongs, a core network one-time value, and a first anti-replay attack parameter.

40. The apparatus of claim 39, wherein The first information includes one or more of the following: the first set of authentication keys; The core network one-time value; The first anti-replay attack parameter.

41. A label authentication device, applied to a label, comprising: a first receiving unit, configured to receive a first request sent by an authentication entity, wherein the first request includes authentication information, the authentication information is generated based on information of a tag group to which the tag belongs, and the tag group includes one or more tags; A first authentication unit is configured to perform authentication according to the first request.

42. A tag authentication device, used for authenticating an entity, comprising: A first receiving unit, configured to receive first information sent by a contracting entity; The first sending unit is configured to send a first request to the tag according to the first information, wherein the first request includes authentication information, the authentication information is generated according to information of a tag group to which the tag belongs, and the tag group includes one or more tags.

43. A label authentication device, applied to a contracting entity, comprising: The first sending unit is used to send first information to the authentication entity and to send a first request to the tag, wherein the first request includes authentication information, the authentication information is generated according to information of the tag group to which the tag belongs, and the tag group includes one or more tags.

44. A computer program product comprising computer instructions, which, when executed by a processor, implement the method according to any one of claims 1 to 20.

Citation Information

Patent Citations

  • Authentication method and communication device

    CN116686314A

  • Authentication Mechanism for 5G Technologies

    US20170264439A1

  • Authentication Mechanism for 5G Technologies

    US20180013568A1

  • Security verification method and apparatus, and terminal

    WO2023004788A1