Communication method and apparatus, and device and storage medium

By introducing multiple communication nodes into the communication system and utilizing the exchange and derivation of identification information and key information, the problem of secure communication between tag-type devices and readers is solved, the secure transmission and use of key information is achieved, and the security and reliability of the communication system are improved.

WO2025209362A1PCT designated stage Publication Date: 2025-10-09VIVO MOBILE COMM CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/085838
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-03
Filing Date
2025-03-28
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

How to ensure secure communication between tag-type devices and readers, especially how to ensure that keys cannot be derived from other terminals in future communication networks to achieve secure communication.

Method used

By introducing multiple communication nodes in the communication system and utilizing the exchange and derivation of identification information and key information, the authentication and authorization process between communication nodes and devices is realized, ensuring the secure transmission and use of key information.

Benefits of technology

It realizes secure communication between tag-type devices and readers, ensuring that key information is only transmitted and used between authorized devices, and improving the security and reliability of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025085838_09102025_PF_FP_ABST
    Figure CN2025085838_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of communications. Disclosed are a communication method and apparatus, and a device and a storage medium. The communication method in the embodiments of the present application comprises: a first communication node receiving first information from a second communication node, wherein the first information comprises a first identifier related to a first device; and on the basis of at least one of the first information and the type of the second communication node, the first communication node determining to send or not to send eleventh information to the second communication node, wherein the eleventh information comprises at least one of the following: second result information, information related to the first device, and third key information, the second result information indicates at least one of the following: an authentication success or failure, and an authorization success or failure, the third key information is used for performing security protection or security processing on the communication between the second communication node and the first device, and the first device accesses a network by means of the second communication node.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device, equipment and storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese patent application number 202410403757.9 filed in China on April 3, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present application belongs to the field of communication technology, and specifically relates to a communication method, apparatus, device and storage medium. Background Art

[0004] Future communication networks may support service tag (Tag) type devices, similar to Radio Frequency Identification (RFID). Tag type devices may be implemented on terminals, and readers may be either base stations or terminals.

[0005] Terminal readers need to support secure communication between tag-type devices and the reader / writer. Therefore, the reader / writer must obtain the key for communication with the tag-type device. The key is used to send verification information to the network, not to communicate with other terminals. If the network does not send the key to the other terminal, the other terminal cannot derive the key, and inter-terminal communication based on the key is impossible. Therefore, how to ensure secure communication between tag-type devices and readers is an unresolved problem. Summary of the Invention

[0006] The embodiments of the present application provide a communication method, apparatus, device, and storage medium that can solve the problem of how to ensure secure communication between a tag-type device and a reader / writer.

[0007] In a first aspect, a communication method performed by a communication system is provided, the communication system including at least a first communication node, a second communication node, and a third communication node, the method comprising:

[0008] The first communication node receives first information from the second communication node, where the first information includes a first identifier related to the first device;

[0009] The first communication node sends second information to the third communication node, where the second information includes the first identifier, or includes the first identifier and the second identifier; the second identifier indicates the second communication node;

[0010] The third communication node performs at least one of the following:

[0011] In a case where the communication system further includes a fourth communication node, sending third information to the fourth communication node and receiving fourth information from the fourth communication node;

[0012] Sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: second information, fourth information, and seventh information;

[0013] The third information includes at least one of the following: the first identifier and the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device, and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device, and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device, and the first key information;

[0014] The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0015] In a second aspect, a communication method is provided, the method comprising: a first communication node receiving first information from a second communication node, the first information including a first identifier related to a first device;

[0016] The first communication node determines, based on at least one of the first information and the type of the second communication node, whether to send eleventh information to the second communication node, the eleventh information including at least one of the following: second result information, information related to the first device, and third key information;

[0017] Among them, the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0018] According to a third aspect, a communication method is provided, comprising: a third communication node receiving second information from a first communication node, where the second information includes a first identifier related to a first device, or includes the first identifier and a second identifier; the second identifier indicates a second communication node; and the first device accesses a network through the second communication node.

[0019] The third communication node performs at least one of the following:

[0020] sending third information to a fourth communication node, and receiving fourth information from the fourth communication node;

[0021] sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: the second information, the fourth information, and the seventh information;

[0022] The third information includes at least one of the following: the first identifier and the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device, and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device, and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device, and the first key information;

[0023] The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0024] In a fourth aspect, a communication method is provided, the method comprising: a fourth communication node receiving third information from a third communication node, the third information comprising at least one of the following: a first identifier and a third identifier related to a first device;

[0025] The fourth communication node sends fourth information to the third communication node, where the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information;

[0026] Among them, the third identifier is the second identifier, or is obtained based on the second identifier; the second identifier indicates the second communication node; the first device accesses the network through the second communication node; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier.

[0027] According to a fifth aspect, a communication method is provided, the method comprising: a second communication node receiving fourteenth information from a first device, the fourteenth information including a first identifier related to the first device;

[0028] The second communication node sends first information to the first communication node, where the first information includes the first identifier;

[0029] The second communication node receives eleventh information from the first communication node;

[0030] Among them, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0031] According to a sixth aspect, a communication method is provided, the method comprising: a first device sending fourteenth information to a second communication node, the fourteenth information including a first identifier related to the first device;

[0032] The first device receives thirteenth information from the second communication node, where the thirteenth information includes at least one of the following: second result information and information related to the second communication node;

[0033] The first device derives fourth key information based on the thirteenth information, where the fourth key information is used to securely protect or securely process communication between the second communication node and the first device;

[0034] The second result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0035] In a seventh aspect, a communication device is provided, the communication device comprising: a receiving module and an execution module;

[0036] The receiving module is configured to receive first information from the second communication node, where the first information includes a first identifier related to the first device;

[0037] the execution module is configured to determine whether to send or not send eleventh information to the second communication node based on at least one of the first information and the type of the second communication node, the eleventh information including at least one of the following: second result information, information related to the first device, and third key information;

[0038] Among them, the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0039] In an eighth aspect, a communication device is provided, the communication device comprising: a receiving module and an execution module;

[0040] The receiving module is configured to receive second information from the first communication node, where the second information includes a first identifier related to the first device, or includes the first identifier and a second identifier; the second identifier indicates the second communication node; and the first device accesses the network through the second communication node;

[0041] The execution module is configured to execute at least one of the following:

[0042] sending third information to a fourth communication node, and receiving fourth information from the fourth communication node;

[0043] sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: the second information, the fourth information, and the seventh information;

[0044] The third information includes at least one of the following: the first identifier and the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device, and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device, and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device, and the first key information;

[0045] The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0046] In a ninth aspect, a communication device is provided, the communication device comprising: a receiving module and a sending module;

[0047] The receiving module is configured to receive third information from a third communication node, where the third information includes at least one of the following: a first identifier and a third identifier related to the first device;

[0048] The sending module is configured to send fourth information to the third communication node, where the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information;

[0049] Among them, the third identifier is the second identifier, or is obtained based on the second identifier; the second identifier indicates the second communication node; the first device accesses the network through the second communication node; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier.

[0050] In a tenth aspect, a communication device is provided, the communication device comprising: a receiving module and a sending module;

[0051] The receiving module is configured to receive fourteenth information from the first device, where the fourteenth information includes a first identifier related to the first device;

[0052] The sending module is configured to send first information to the first communication node, where the first information includes the first identifier;

[0053] The receiving module is further configured to receive eleventh information from the first communication node;

[0054] Among them, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0055] In an eleventh aspect, a communication device is provided, the communication device comprising: a sending module, a receiving module, and an execution module;

[0056] The sending module is configured to send fourteenth information to the second communication node, where the fourteenth information includes a first identifier related to the first device;

[0057] The receiving module is configured to receive thirteenth information from the second communication node, where the thirteenth information includes at least one of the following: second result information and information related to the second communication node;

[0058] the execution module is configured to derive fourth key information based on the thirteenth information, wherein the fourth key information is used to perform security protection or security processing on the communication between the second communication node and the first device;

[0059] The second result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0060] In the twelfth aspect, a communication device is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, implements the steps of the method described in the second aspect, or implements the steps of the method described in the third aspect, or implements the steps of the method described in the fourth aspect, or implements the steps of the method described in the fifth aspect, or implements the steps of the method described in the sixth aspect.

[0061] In a thirteenth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the communication interface is configured to receive first information from a second communication node, the first information including a first identifier related to the first device. The processor is configured to determine, based on at least one of the first information and a type of the second communication node, whether to send or not send eleventh information to the second communication node, the eleventh information including at least one of the following: second result information, information related to the first device, and third key information; wherein the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process communication between the second communication node and the first device; and the first device accesses a network through the second communication node.

[0062] In a fourteenth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the communication interface is configured to receive second information from a first communication node, the second information including a first identifier associated with the first device, or including the first identifier and a second identifier; the second identifier indicates a second communication node; and the first device accesses a network through the second communication node. The processor is configured to perform at least one of the following:

[0063] sending third information to a fourth communication node, and receiving fourth information from the fourth communication node;

[0064] sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: the second information, the fourth information, and the seventh information;

[0065] Among them, the third information includes at least one of the following: the first identifier, the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device and the first key information; the third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0066] In the fifteenth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the communication interface is used to receive third information from a third communication node, the third information including at least one of the following: a first identifier and a third identifier related to the first device; and send fourth information to the third communication node, the fourth information including at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information; wherein the third identifier is the second identifier, or is obtained based on the second identifier; the second identifier indicates a second communication node; the first device accesses the network through the second communication node; the first result information indicates whether authentication is successful or failed; and the fourth identifier is obtained based on the third identifier.

[0067] In the sixteenth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the communication interface is used to receive fourteenth information from a first device, the fourteenth information including a first identifier related to the first device; send first information to a first communication node, the first information including the first identifier; receive eleventh information from the first communication node; wherein the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0068] In a seventeenth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the communication interface is configured to send fourteenth information to a second communication node, the fourteenth information including a first identifier related to a first device; and receive thirteenth information from the second communication node, the thirteenth information including at least one of the following: second result information and information related to the second communication node. The processor is configured to derive fourth key information based on the thirteenth information, the fourth key information being used to securely protect or securely process communication between the second communication node and the first device; wherein the second result information indicates at least one of the following: authentication success or failure, or authorization success or failure.

[0069] In aspect 18, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in aspect 2 are implemented, or the steps of the method described in aspect 3 are implemented, or the steps of the method described in aspect 4 are implemented, or the steps of the method described in aspect 5 are implemented, or the steps of the method described in aspect 6 are implemented.

[0070] In the nineteenth aspect, a wireless communication system is provided, including: a first communication node, a third communication node, a fourth communication node, a second communication node and a first device, wherein the first communication node can be used to perform the steps of the method described in the second aspect, the third communication node can be used to perform the steps of the method described in the third aspect, the fourth communication node can be used to perform the steps of the method described in the fourth aspect, the second communication node can be used to perform the steps of the method described in the fifth aspect, and the first device can be used to perform the steps of the method described in the sixth aspect.

[0071] In the twentieth aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method as described in the second aspect, or the method as described in the third aspect, or the method as described in the fourth aspect, or the method as described in the fifth aspect, or the method as described in the sixth aspect.

[0072] In aspect 21, a computer program / program product is provided, which is stored in a storage medium, and the program / program product is executed by at least one processor to implement the steps of the communication method described in aspect 2, or the steps of the communication method described in aspect 3, or the steps of the communication method described in aspect 4, or the steps of the communication method described in aspect 5, or the steps of the communication method described in aspect 6.

[0073] In an embodiment of the present application, a first communication node receives first information from a second communication node, including a first identifier associated with the first device, and, based on the first information and at least one of the types of the second communication node, determines whether to send or not send eleventh information to the second communication node, including at least one of the following: second result information, information associated with the first device, and third key information. The third key information is used to securely protect or securely process communication between the second communication node and the first device. Thus, this solution enables communication between the second communication node and the first device based on the key information, ensuring secure communication between the second communication node and the first device. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] FIG1 is a schematic diagram of the architecture of a wireless communication system provided in an embodiment of the present application;

[0075] FIG2 is a flow chart of a communication method according to an embodiment of the present application;

[0076] FIG3 is a second flow chart of a communication method provided in an embodiment of the present application;

[0077] FIG4 is a third flow chart of a communication method provided in an embodiment of the present application;

[0078] FIG5 is a fourth flow chart of a communication method provided in an embodiment of the present application;

[0079] FIG6 is a fifth flow chart of a communication method provided in an embodiment of the present application;

[0080] FIG7 is a sixth flowchart of a communication method provided in an embodiment of the present application;

[0081] FIG8 is a seventh flowchart of a communication method provided in an embodiment of the present application;

[0082] FIG9 is a flowchart of an eighth embodiment of a communication method provided by the present application;

[0083] FIG10 is a ninth flowchart of a communication method provided in an embodiment of the present application;

[0084] FIG11 is a flowchart of a communication method according to an embodiment of the present application;

[0085] FIG12 is a schematic diagram of a structure of a communication device according to an embodiment of the present application;

[0086] FIG13 is a second structural diagram of a communication device provided in an embodiment of the present application;

[0087] FIG14 is a third structural diagram of a communication device provided in an embodiment of the present application;

[0088] FIG15 is a fourth structural diagram of a communication device provided in an embodiment of the present application;

[0089] FIG16 is a fifth structural diagram of a communication device provided in an embodiment of the present application;

[0090] FIG17 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application;

[0091] FIG18 is a schematic diagram of the hardware structure of a terminal provided in an embodiment of the present application;

[0092] FIG19 is a schematic diagram of a hardware structure of a network side device provided in an embodiment of the present application;

[0093] FIG20 is a second schematic diagram of the hardware structure of a network-side device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0094] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0095] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.

[0096] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.

[0097] The terms "at least one" and "at least one of" in this application refer to any one, any two, or a combination of more than two of the objects included. For example, at least one of a, b, and c can be represented by: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two" means two or more, and its meaning is similar to "at least one".

[0098] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) systems. th Generation, 6G) communication system.

[0099] FIG1 is a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), an aircraft (Flight Vehicle), a vehicle-mounted device (VUE), a ship-mounted device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), a game console, a personal computer (PC), an ATM, or a self-service machine, or other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. In addition to the above-mentioned terminal devices, it can also be a chip in the terminal, such as a modem chip, a system-on-chip (SoC). It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device may also be called a radio access network (RAN) device, a radio access network function or a radio access network unit. The access network device may include a base station, a wireless local area network (WLAN) access point (AS) or a wireless fidelity (WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.

[0100] The core network equipment may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (EASDF), unified data management (UDM), unified data repository (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BSF), application function ( Function, AF), etc. It should be noted that in the embodiments of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.

[0101] It should be noted that the following terms are used in this application:

[0102] Global Unique Temporary Identifier (GUTI);

[0103] Subscription Concealed Identifier (SUCI);

[0104] Protocol Data Unit (PDU);

[0105] GPRS Tunnelling Protocol (GTP);

[0106] Tunnel ID;

[0107] Data Network Name (DNN);

[0108] Single Network Slice Selection Assistance Information (S-NSSAI);

[0109] Authentication Server Function (AUSF);

[0110] Network Slice Selection Assistance Function (NSSAAF);

[0111] Network Exposure Function (NEF);

[0112] Authentication, Authorization and Accounting (AAA).

[0113] The communication method provided in the embodiments of the present application is described in detail below through some embodiments and their application scenarios in conjunction with the accompanying drawings.

[0114] The present invention provides a communication method, and Figure 2 shows a flow chart of the communication method provided by the present invention. As shown in Figure 2, the communication method provided by the present invention may include the following steps 201 to 203.

[0115] Step 201: The second communication node sends first information to the first communication node.

[0116] Step 202: The first communication node receives first information from the second communication node.

[0117] In the embodiment of the present application, the above-mentioned first information includes a first identifier related to the first device.

[0118] Optionally, in an embodiment of the present application, the first communication node may be a network function. For example, the first communication node may be a first network function, which may be an AMF, an ambient power-enabled Internet of Things Function (AIoTF), or an SMF.

[0119] Optionally, in an embodiment of the present application, the above-mentioned second communication node may be a terminal device or a base station device.

[0120] Exemplarily, the second communication node is a reader / writer of the first device, and the reader / writer may be a terminal device or a base station device.

[0121] Optionally, in an embodiment of the present application, the first device may include at least one of the following: a tag-type device, an IoT-type device.

[0122] Optionally, in an embodiment of the present application, the first identifier may be an ID (Device Concealed ID, or Device Temporary ID) used to identify the first device, or an anonymous identifier (Anonymous ID). The anonymous identifier does not identify the first device, but includes at least one of the following: business information, service information, business session information (such as AIoT Session ID, PIN ID, etc.), and routing information.

[0123] Optionally, in an embodiment of the present application, the first device may also be an application (APP) on the second communication node. The first identifier may be an anonymous identifier, an application identifier (APP ID) associated with the application, an application layer identifier of the application (such as Log ID, User ID, etc.), or a concealed identifier (Conceal ID), that is, an identifier that has been encrypted or secured.

[0124] Step 203: The first communication node determines whether to send or not send the eleventh information to the second communication node based on the first information and at least one of the types of the second communication node.

[0125] In an embodiment of the present application, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information.

[0126] In an embodiment of the present application, the above-mentioned second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0127] Optionally, in an embodiment of the present application, the type of the second communication node is a terminal, a base station, or a reader. For example, the reader type is a handheld reader or a base station reader, a mobile reader or a fixed reader, a relay reader or a proxy reader, a transparent forwarding reader or a non-transparent forwarding reader, a proxy reader or an audit reader, etc.

[0128] Optionally, in an embodiment of the present application, the third key information is the second key information, or the third key information is derived based on the second key information.

[0129] Optionally, the communication method provided in the embodiment of the present application may further include the following step 204.

[0130] Step 204: The first communication node derives third key information based on the second key information and the twelfth information.

[0131] In an embodiment of the present application, the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, type information of the second communication node, information related to the first device, and anonymous identification information.

[0132] Optionally, in an embodiment of the present application, in combination with Figure 2, as shown in Figure 3, after the above step 202, the communication method provided in the embodiment of the present application further includes the following steps 205 to 208.

[0133] Step 205: The first communication node sends second information to the third communication node.

[0134] Step 206: The third communication node receives second information from the first communication node.

[0135] In the embodiment of the present application, the second information includes a first identifier, or includes a first identifier and a second identifier. The second identifier indicates the second communication node.

[0136] Optionally, in an embodiment of the present application, the above-mentioned second identifier may be the ID of the second communication node, or when the second communication node is a terminal, the second identifier may be a GUTI, SUCI, or may indicate a session, such as a PDU Session ID. When the second communication node is a base station, the second identifier may be a gNB ID, an ID of the second communication node, or a Gateway ID, etc., or may be connection information, such as a GTP Tunnel ID, etc.

[0137] Step 207: The third communication node sends sixth information to the first communication node.

[0138] Step 208: The first communication node receives sixth information from the third communication node.

[0139] In the embodiment of the present application, the sixth information includes at least one of the following: second result information, information related to the first device, and second key information.

[0140] In an embodiment of the present application, the second key information is derived based on the first key information, or the second key information is the first key information.

[0141] Optionally, in the embodiment of the present application, in combination with FIG. 2 , as shown in FIG. 4 , the above step 203 may be specifically implemented through the following step 203a.

[0142] Step 203a: When the second communication node is of the first type, or is not of the second type, the first communication node sends eleventh information to the second communication node.

[0143] In the embodiment of the present application, the first type indicates that the second communication node is a terminal device. The second type indicates that the second communication node is at least one of a base station device and a network function.

[0144] Optionally, in an embodiment of the present application, the above step 203 can be specifically implemented by at least one of the following steps 203b to 203d.

[0145] Step 203b: The first communication node sends eleventh information to the second communication node based on the first identifier, to indicate whether the authorization is successful or failed.

[0146] Step 203c: The first communication node sends eleventh information to the second communication node based on the information related to the second communication node, to indicate whether the authorization is successful or failed.

[0147] Step 203d: The first communication node sends eleventh information to the second communication node based on the first identifier and information related to the second communication node, to indicate whether the authorization is successful or failed.

[0148] Optionally, in an embodiment of the present application, the information related to the above-mentioned second communication node includes at least one of the following: the identifier of the second communication node, connection information, connection tunnel information, location information and session information (such as PDU Session identifier, DNN, S-NSSAI).

[0149] An embodiment of the present application provides a communication method in which a first communication node receives first information from a second communication node, including a first identifier associated with a first device, and, based on the first information and at least one of the types of the second communication node, determines whether to send or not send eleventh information to the second communication node, including at least one of the following: second result information, information associated with the first device, and third key information, wherein the third key information is used to securely protect or securely process communication between the second communication node and the first device. Thus, this solution enables communication between the second communication node and the first device based on the key information, thereby ensuring secure communication between the second communication node and the first device.

[0150] The present invention provides a communication method, and Figure 5 shows a flow chart of the communication method provided by the present invention. As shown in Figure 5, the communication method provided by the present invention may include the following steps 301 to 303.

[0151] Step 301: The first communication node sends second information to the third communication node.

[0152] Step 302: The third communication node receives second information from the first communication node.

[0153] In an embodiment of the present application, the second information includes a first identifier related to the first device, or includes a first identifier and a second identifier. The second identifier indicates a second communication node. The first device accesses the network through the second communication node.

[0154] Step 303: The third communication node performs at least one of the following:

[0155] sending third information to a fourth communication node, and receiving fourth information from the fourth communication node;

[0156] The sixth information is sent to the first communication node based on the fifth information.

[0157] In an embodiment of the present application, the fifth information includes at least one of the following: the second information, the fourth information and the seventh information.

[0158] In this embodiment of the present application, the third information includes at least one of the following: a first identifier and a third identifier. The fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information. The sixth information includes at least one of the following: second result information, information related to the first device, and second key information. The seventh information includes at least one of the following: third result information, a third identifier, information related to the first device, and first key information.

[0159] In an embodiment of the present application, the third identifier is the second identifier, or is obtained based on the second identifier. The first result information indicates whether the authentication succeeded or failed. The fourth identifier is obtained based on the third identifier. The second key information is the first key information, or the second key information is derived based on the first key information. The second result information indicates at least one of the following: authentication succeeded or failed, or authorization succeeded or failed. The third result information indicates at least one of the following: authentication succeeded or failed, or authorization succeeded or failed.

[0160] Optionally, in the embodiment of the present application, the third communication node is a network function. For example, the third communication node may be a second network function, and the second network function may be an AUSF.

[0161] Optionally, in an embodiment of the present application, the above-mentioned first communication node is a network function.

[0162] Optionally, the communication method provided in the embodiment of the present application may further include the following step 304.

[0163] Step 304: The third communication node derives second key information based on the first key information and the twelfth information.

[0164] In an embodiment of the present application, the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, type information of the second communication node, information related to the first device, and anonymous identification information.

[0165] Optionally, in an embodiment of the present application, “the third communication node sends the sixth information to the first communication node based on the fifth information” in the above step 303 can be specifically implemented by at least one of the following steps 303a to 303c.

[0166] Step 303a: The third communication node sends sixth information to the first communication node based on the first identifier, to indicate whether the authorization is successful or failed.

[0167] Step 303b: The third communication node sends sixth information to the first communication node based on the second identifier, to indicate whether the authorization is successful or failed.

[0168] Step 303c: The third communication node sends sixth information to the first communication node based on the first identifier and the second identifier, to indicate whether the authorization is successful or failed.

[0169] Optionally, in the embodiment of the present application, the above step 303b can be specifically implemented by at least one of the following steps 303b1 and 303b2.

[0170] Step 303b1: The third communication node sends sixth information to the first communication node based on the relationship between the second identifier and the specific function.

[0171] Step 303b2: The third communication node sends sixth information to the first communication node based on the relationship between the second identifier and the specific service.

[0172] Optionally, in an embodiment of the present application, in combination with Figure 5, as shown in Figure 6, after the above step 302, the communication method provided in the embodiment of the present application further includes the following steps 305 to 308.

[0173] Step 305: The third communication node sends eighth information to the fifth communication node based on the second information.

[0174] Step 306: The fifth communication node receives eighth information from the third communication node.

[0175] In an embodiment of the present application, the eighth information includes the first identifier, or includes the first identifier and the third identifier.

[0176] Step 307: The fifth communication node sends seventh information to the third communication node.

[0177] Step 308: The third communication node receives seventh information from the fifth communication node.

[0178] Optionally, in an embodiment of the present application, the fifth communication node may be a third network function, and the third network function may be a UDM.

[0179] An embodiment of the present application provides a communication method, in which a third communication node can receive second information from a first communication node, including a first identifier related to a first device, or including a first identifier and a second identifier, with the second identifier indicating the second communication node, and then perform at least one of the following: sending third information to a fourth communication node, receiving fourth information from the fourth communication node, and sending sixth information to the first communication node based on the fifth information; the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information; the sixth information includes at least one of the following: second result information, information related to the first device, and second key information; and the seventh information includes at least one of the following: third result information, a third identifier, information related to the first device, and first key information. In this way, this solution enables the second communication node and the first device to communicate based on key information, ensuring secure communication between the second communication node and the first device.

[0180] The present invention provides a communication method, and Figure 7 shows a flow chart of the communication method provided by the present invention. As shown in Figure 7, the communication method provided by the present invention may include the following steps 401 to 404.

[0181] Step 401: The third communication node sends third information to the fourth communication node.

[0182] Step 402: The fourth communication node receives third information from the third communication node.

[0183] In the embodiment of the present application, the third information includes at least one of the following: a first identifier and a third identifier related to the first device.

[0184] Optionally, in the embodiment of the present application, the fourth communication node is a network function. For example, the fourth communication node may be a fourth network function, which may be NSSAAF, NEF, or AAA.

[0185] Optionally, in an embodiment of the present application, the above-mentioned third communication node is a network function.

[0186] Step 403: The fourth communication node sends fourth information to the third communication node.

[0187] Step 404: The third communication node receives fourth information from the fourth communication node.

[0188] In an embodiment of the present application, the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information.

[0189] In this embodiment of the present application, the third identifier is the second identifier, or is obtained based on the second identifier. The second identifier indicates the second communication node. The first device accesses the network through the second communication node. The first result information indicates whether the authentication succeeded or failed. The fourth identifier is obtained based on the third identifier.

[0190] Optionally, in an embodiment of the present application, after the above step 402, the communication method provided in the embodiment of the present application further includes the following step 405.

[0191] Step 405: The fourth communication node performs the first operation based on the third information.

[0192] In the embodiment of the present application, the above-mentioned first operation includes at least one of the following: authorization operation and authentication operation.

[0193] An embodiment of the present application provides a communication method in which a fourth communication node receives third information from a third communication node and sends fourth information to the third communication node. The fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information. Thus, this solution enables communication between the second communication node and the first device based on the key information, ensuring secure communication between the second communication node and the first device.

[0194] The present invention provides a communication method, and Figure 8 shows a flow chart of the communication method provided by the present invention. As shown in Figure 8, the communication method provided by the present invention may include the following steps 501 to 506.

[0195] Step 501: The first device sends fourteenth information to the second communication node.

[0196] Step 502: The second communication node receives fourteenth information from the first device.

[0197] In the embodiment of the present application, the fourteenth information includes a first identifier related to the first device.

[0198] Optionally, in an embodiment of the present application, the above-mentioned second communication node is a terminal device or a base station device.

[0199] Optionally, in an embodiment of the present application, the above-mentioned first device includes at least one of the following: a tag-type device, an Internet of Things (IoT)-type device.

[0200] Step 503: The second communication node sends first information to the first communication node.

[0201] Step 504: The first communication node receives first information from the second communication node.

[0202] In an embodiment of the present application, the above-mentioned first information includes a first identifier.

[0203] Step 505: The first communication node sends eleventh information to the second communication node.

[0204] Step 506: The second communication node receives eleventh information from the first communication node.

[0205] In an embodiment of the present application, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information. The second result information indicates at least one of the following: authentication success or failure, or authorization success or failure. The third key information is used to securely protect or securely process communication between the second communication node and the first device. The first device accesses the network through the second communication node.

[0206] Optionally, in an embodiment of the present application, the first identifier is an anonymous identifier.

[0207] Optionally, in an embodiment of the present application, the information related to the first device includes at least one of the following: identification information, type information, identification mask information, and partial content of identification information.

[0208] Optionally, in an embodiment of the present application, the above-mentioned security protection includes at least one of the following: encryption, integrity protection, and generation of a verification code.

[0209] Optionally, in an embodiment of the present application, the above security processing includes at least one of the following: decryption, integrity verification, and verification code verification.

[0210] Optionally, the communication method provided in the embodiment of the present application may further include the following step 507.

[0211] Step 507: The second communication node derives fourth key information based on the eleventh information.

[0212] In an embodiment of the present application, the fourth key information is used to securely protect or securely process the communication between the second communication node and the first device.

[0213] Optionally, in the embodiment of the present application, the above step 507 can be specifically implemented through the following step 507a.

[0214] Step 507a: The second communication node derives fourth key information based on the third key information and the twelfth information.

[0215] In an embodiment of the present application, the above-mentioned twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

[0216] Optionally, in an embodiment of the present application, the above-mentioned first information also includes information related to the second communication node, and the information related to the second communication node includes at least one of the following: identification, connection information, connection tunnel information, location information and session information of the second communication node.

[0217] An embodiment of the present application provides a communication method in which a second communication node receives fourteenth information from a first device, sends first information to the first communication node, and then receives eleventh information from the first communication node. The eleventh information includes at least one of the following: second result information, information related to the first device, and third key information. The third key information is used to securely protect or securely process communication between the second communication node and the first device. Thus, this solution enables communication between the second communication node and the first device based on key information, ensuring secure communication between the second communication node and the first device.

[0218] The present invention provides a communication method, and Figure 9 shows a flow chart of the communication method provided by the present invention. As shown in Figure 9, the communication method provided by the present invention may include the following steps 601 to 605.

[0219] Step 601: The first device sends fourteenth information to the second communication node.

[0220] Step 602: The second communication node receives fourteenth information from the first device.

[0221] In the embodiment of the present application, the fourteenth information includes a first identifier related to the first device.

[0222] Optionally, in an embodiment of the present application, the above-mentioned second communication node is a terminal device or a base station device.

[0223] Optionally, in an embodiment of the present application, the above-mentioned first device includes at least one of the following: a tag-type device, an Internet of Things (IoT)-type device.

[0224] Optionally, in an embodiment of the present application, the first identifier is an anonymous identifier.

[0225] Step 603: The second communication node sends thirteenth information to the first device.

[0226] Step 604: The first device receives thirteenth information from the second communication node.

[0227] In an embodiment of the present application, the thirteenth information includes at least one of the following: second result information, and information related to the second communication node.

[0228] Optionally, in an embodiment of the present application, the information related to the above-mentioned second communication node includes at least one of the following: an identifier of the second communication node, connection information, connection tunnel information, location information and session information.

[0229] Step 605: The first device derives fourth key information based on the thirteenth information.

[0230] In an embodiment of the present application, the fourth key information is used to securely protect or securely process the communication between the second communication node and the first device.

[0231] In the embodiment of the present application, the second result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0232] Optionally, in an embodiment of the present application, the above-mentioned security protection includes at least one of the following: encryption, integrity protection, and generation of a verification code.

[0233] Optionally, in an embodiment of the present application, the above security processing includes at least one of the following: decryption, integrity verification, and verification code verification.

[0234] Optionally, in an embodiment of the present application, the above step 605 can be specifically implemented through the following step 605a.

[0235] Step 605a: The first device derives fourth key information based on the third key information and the twelfth information.

[0236] In an embodiment of the present application, the above-mentioned twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

[0237] Optionally, in an embodiment of the present application, the identification information related to the second communication node includes at least one of the following: identification information used to indicate the second communication node, and an anonymous identification.

[0238] Optionally, in an embodiment of the present application, the information related to the first device includes at least one of the following: identification information, type information, identification mask information, and partial content of identification information.

[0239] An embodiment of the present application provides a communication method in which a first device sends fourteenth information to a second communication node, receives thirteenth information from the second communication node, and then derives fourth key information based on the thirteenth information. The fourth key information is used to securely protect or securely process communication between the second communication node and the first device. Thus, this solution enables communication between the second communication node and the first device based on the key information, thereby ensuring secure communication between the second communication node and the first device.

[0240] The embodiment of the present application provides a communication method performed by a communication system, the communication system including at least a first communication node, a second communication node, and a third communication node. As shown in FIG10 , the communication method includes the following steps 701 to 705 .

[0241] Step 701: The second communication node sends first information to the first communication node.

[0242] Step 702: The first communication node receives first information from the second communication node.

[0243] In the embodiment of the present application, the above-mentioned first information includes a first identifier related to the first device.

[0244] Step 703: The first communication node sends second information to the third communication node.

[0245] Step 704: The third communication node receives second information from the first communication node.

[0246] In the embodiment of the present application, the second information includes a first identifier, or includes a first identifier and a second identifier. The second identifier indicates the second communication node.

[0247] Step 705: The third communication node performs at least one of the following:

[0248] In a case where the communication system further includes a fourth communication node, sending third information to the fourth communication node and receiving fourth information from the fourth communication node;

[0249] The sixth information is sent to the first communication node based on the fifth information.

[0250] In an embodiment of the present application, the fifth information includes at least one of the following: second information, fourth information, and seventh information.

[0251] In this embodiment of the present application, the third information includes at least one of the following: a first identifier and a third identifier. The fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information. The sixth information includes at least one of the following: second result information, information related to the first device, and second key information. The seventh information includes at least one of the following: third result information, a third identifier, information related to the first device, and first key information.

[0252] The third identifier is the second identifier, or is obtained based on the second identifier. The first result information indicates whether authentication succeeded or failed. The fourth identifier is obtained based on the third identifier. The second key information is the first key information, or the second key information is derived from the first key information. The second result information indicates at least one of the following: authentication succeeded or failed, or authorization succeeded or failed. The third result information indicates at least one of the following: authentication succeeded or failed, or authorization succeeded or failed.

[0253] Optionally, in the embodiment of the present application, the communication system further includes a fifth communication node. The communication method provided in the embodiment of the present application includes the following steps 706 and 707.

[0254] Step 706: The third communication node sends eighth information to the fifth communication node based on the second information.

[0255] In an embodiment of the present application, the eighth information includes the first identifier, or includes the first identifier and the third identifier.

[0256] Step 707: The third communication node receives seventh information from the fifth communication node.

[0257] Optionally, in the embodiment of the present application, the communication system further includes a fifth communication node. The communication method provided in the embodiment of the present application includes the following steps 708 and 709.

[0258] Step 708: The third communication node sends ninth information to the fifth communication node.

[0259] In an embodiment of the present application, the ninth information includes the first identifier and the third identifier, or includes the first identifier and the fourth identifier.

[0260] Step 709: The third communication node receives tenth information from the fifth communication node.

[0261] In the embodiment of the present application, the tenth information includes at least one of the following: first result information and information related to the first device.

[0262] Optionally, the communication method provided in the embodiment of the present application includes the following step 710.

[0263] Step 710: The first communication node determines whether to send or not send eleventh information to the second communication node based on the first information and at least one of the types of the second communication node.

[0264] In an embodiment of the present application, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information. The third key information is used to securely protect or securely process communication between the second communication node and the first device. The first device accesses the network through the second communication node.

[0265] Optionally, the communication method provided in the embodiment of the present application includes the following step 711.

[0266] Step 711: The first communication node derives third key information based on the second key information and the twelfth information.

[0267] In an embodiment of the present application, the above-mentioned twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

[0268] Optionally, the communication method provided in the embodiment of the present application includes the following steps 712 and 713.

[0269] Step 712: The second communication node sends thirteenth information to the first device.

[0270] In an embodiment of the present application, the thirteenth information includes at least one of the following: second result information, and information related to the second communication node.

[0271] Step 713: The first device derives fourth key information based on the thirteenth information.

[0272] In an embodiment of the present application, the fourth key information is used to securely protect or securely process the communication between the second communication node and the first device.

[0273] Exemplarily, the interaction process of the communication method provided in the embodiment of the present application is described below through specific implementation methods.

[0274] As shown in FIG11 , the communication method provided in the embodiment of the present application includes the following steps 21 to 40 .

[0275] It should be noted that this embodiment is illustrated by taking the above-mentioned first communication node as the first network function (such as AMF, AIoTF or SMF), the second communication node as the reader / writer, the third communication node as the second network function (such as AUSF), the fourth communication node as the fourth network function (such as NSSAAF, NEF or AAA), and the fifth communication node as the third network function (such as UDM) as an example.

[0276] Prerequisite: The first device (which can be called Device) and the authentication server (such as UDM, AAA, AuC, etc.) know each other a common fifth key (such as a shared / symmetric key KEY, or the public key of both parties, or the public key of one party), such as pre-configured in the first device and the authentication server, or obtained through other servers (such as Device / AAA obtain each other's public key from the Authentication Center). The authentication server does not need to know its own public key (for example, after AAA generates a public-private key pair, it sends the public key to the Authentication Center and then deletes the locally stored public key. After that, AAA no longer knows the public key. The Device can obtain the AAA's public key from the Authentication Center to interact with AAA to complete key calculation - such as the mechanism of public-private exchange and public-private key calculation of session keys)

[0277] Optionally (after completing the AIoT-related solutions, it was found that it is also applicable to PIN, UIA and some Avatar services), the first device can be an application (APP) on the second communication node (such as a terminal or base station - not called Gateway or reader at this time), and the first identifier can be an anonymous identifier or an application identifier (APP ID) related to the application or the application layer identifier of the application (such as LogID, User ID, etc.), or a hidden identifier (Conceal ID) - that is, the identifier is encrypted and / or protected.

[0278] The second communication node can also be an IoT device reader / writer, a gateway UE, or a terminal, or a base station. Hereinafter, "reader / writer or terminal" will be used to refer to the "second communication node," and "Device" will be used to refer to the "first device."

[0279] Step 21: The first device sends fourteenth information to the reader / writer, where the fourteenth information includes a first identifier related to the first device.

[0280] Optionally, in an embodiment of the present application, the first device may send a first identifier to a second communication node (such as a terminal or base station) through an external connection mechanism (such as wireless, wired, WiFi, Bluetooth, PC5, Sidelink, RFID air interface, etc.), such as an ID that identifies the Device (Device Concealed ID - DCI, or Device Temporary ID - DTI), or an anonymous identifier (Anonymous ID). The anonymous identifier does not identify the first device, but only includes business information, service information, business session information (such as AIoT Session ID, PIN ID, etc.) and / or routing information.

[0281] Optionally, in an embodiment of the present application, the first device may also send indication information to the second communication node (through an external connection mechanism or an internal information interaction mechanism) to trigger the following step 22.

[0282] Step 22: The reader sends first information to the first network function, where the first information includes a first identifier.

[0283] Optionally, in an embodiment of the present application, the above-mentioned first information may further include a second identifier, wherein the second identifier indicates a reader / writer, such as a reader / writer ID, or when the reader / writer is a terminal, the second identifier may be GUTI, SUCI, or may indicate a session, such as a PDU Session ID; when the reader / writer is a base station, the second identifier may be a gNB ID, a reader / writer ID or a Gateway ID, etc., or may be connection information, such as a GTP Tunnel ID, etc.

[0284] Optionally, in an embodiment of the present application, the first identifier may be received from the first device, or may not be received from the first device (for example, an anonymous identifier).

[0285] Step 23: The first network function sends second information to the second network function, where the second information includes the first identifier, or includes the first identifier and the second identifier.

[0286] The second identifier indicates the second communication node. The second identifier can be the identifier of the second communication node, or can be obtained based on the identifier of the second communication node, or can be the second identifier. For example, when the reader is a base station and the second identifier is the gNB ID, the third identifier can be the reader ID.

[0287] Step 24: The second network function sends eighth information to the third network function, where the eighth information includes the first identifier, or includes the first identifier and the third identifier.

[0288] Step 25: The third network function performs an authorization operation based on the eighth information.

[0289] In an embodiment of the present application, the third network function performs a first authorization operation based on the third identifier, or based on the third identifier and the first identifier, to determine whether the terminal is allowed to serve a specific service / function (Feature) (such as AIoT service / function, PIoT service / function, PIN service / function, UIA service / function, etc. - such service / function is related to the communication between the first device in the non-network and the second communication node in the non-network, or is related to the first device accessing the 3GPP network or 3GPP service through the second communication node), and / or, whether to allow participation in the service / application corresponding to the first identifier (for example, when the first identifier includes AF ID / name, Domain name, its corresponding service / application), and / or, whether to allow the service session corresponding to the first identifier (for example, when the first identifier includes a service session identifier - such as AIoT Session ID, PIN ID, DNN, S-NSSAI, APN, etc., its corresponding session), and / or, whether to allow the service of the Device corresponding to the first identifier.

[0290] Optionally, the third network function performs the above-mentioned decision / first authorization operation based on the contract information corresponding to the third identifier.

[0291] Step 26: The third network function sends the first authorization information to the second network function.

[0292] The first authorization information includes at least one of result information (such as success or failure), external authentication indication, first identifier, third identifier, fourth identifier, business / function information, service / application information, session information, and type information.

[0293] The fourth identifier is obtained based on the third identifier, such as GPSI. If the reader is a base station, the fourth identifier can be a reader ID or an external reader ID.

[0294] It should be noted that the first authorization information here may correspond to the seventh information described in the above embodiment.

[0295] Step 27: The second network function sends third information to the fourth network function, where the third information includes at least one of the following: the first identifier and the third identifier.

[0296] Optionally, in the embodiment of the present application, the second network function may further send at least one of an authentication indication and a fourth identifier.

[0297] Optionally, in an embodiment of the present application, the second network function may send the above information based on the first authorization indication. If the first authorization information includes a failure indication (such as the result information indicating failure), stop executing this step and subsequent steps.

[0298] Step 28: The fourth network function performs an authorization operation based on the third information.

[0299] In an embodiment of the present application, the fourth network function may perform a second authorization operation based on the third identifier or the fourth identifier, or based on the third identifier (or the fourth identifier) ​​and the first identifier to determine whether the terminal indicated by the third identifier or the fourth identifier is allowed to participate in the service / application, and / or whether the service and the corresponding business session are allowed, and / or whether the service is allowed to the device indicated by the first identifier.

[0300] Step 29: The fourth network function (if step 27 is executed) / the third network function (if step 27 is not executed) performs authentication interaction with the first device, authenticates the first device, and obtains a fifth identifier.

[0301] The fifth identifier indicates the first device.

[0302] If the third network function or the fourth network function has performed an authentication operation on the first device (Device), step 29 may not be performed. For example, if the Device loses the context due to power failure or other reasons, it will initiate the operation of step 21, but the third network function or the fourth network function may not perform step 29 on it.

[0303] Optionally, the third network function or the fourth network function performs step 29 based on the authentication indication or the first identifier (the description based on the first identifier is the same as the subsequent description of the second network function deciding whether to send the authentication indication based on the first identifier).

[0304] Optionally, the second network function may not send an authentication indication to the third network function when it is learned that the Device does not need to be authenticated. For example, the second network function decides not to send an authentication indication to the third network function based on the first identifier. For example, the first identifier includes business / service information, and the business information is an Avatar business or the service information is a service for providing an Avatar business (the relevant authentication process has been completed at the application layer).

[0305] Optionally, the fourth network function performs this step based on the second authorization operation result of step 28, or the third network function performs this step based on the first authorization operation result of step 25, for example, if successful, then the step is performed, otherwise not performed.

[0306] Optionally, in this step, the Device calculates the first key KEY#1 based on the fifth key.

[0307] Step 30: The fourth network function (if step 27 is executed) / the third network function (if step 27 is not executed) performs a third authorization operation based on the fifth identifier and the fourth identifier to determine whether the identifier association is established.

[0308] For example, it is determined whether the terminal indicated by the fourth identifier is allowed to serve the device indicated by the fifth identifier.

[0309] Step 31: The fourth network function (if step 27 is executed) / the third network function (if step 27 is not executed) indicates at least one of the first authentication information and the second authorization information to the second network function.

[0310] The first authentication information includes at least one of the result information, the first key KEY#1, the fifth identifier, and the fourth identifier; the second authorization information includes at least one of the third result information (e.g., success or failure), the first key KEY#1, the fifth identifier, the fourth identifier, and type information. The first key KEY#1 is generated based on the fifth key information, e.g., derived from the fifth key information, or calculated based on a public-private key scheme of the fifth key information.

[0311] It should be noted that at least one of the first authentication information and the second authorization information corresponds to the fourth information described in the above embodiment.

[0312] It should be noted that the following steps 32 to 34 are performed when step 27 is performed.

[0313] Step 32: The second network function performs a third authorization operation based on the fifth identifier and the third identifier or the fourth identifier to determine whether the identifier association is established.

[0314] For example, it is determined whether the terminal indicated by the fourth identifier is allowed to serve the device indicated by the fifth identifier.

[0315] Optionally, the second network function sends the fifth identifier and the third identifier or the fourth identifier to the third network function to request authorization information. (Corresponding to the ninth information described in the above embodiment)

[0316] Optionally, the second network function sends a fifth identifier and the third identifier or the fourth identifier to a fifth network function (such as a PCF) to indicate association or authorization information. Optionally, it can be sent after obtaining authorization information from the third network function.

[0317] Optionally, the fifth network function saves the association relationship.

[0318] Optionally, the second network function performs this step and subsequent steps based on the second authorization information, such as when the third result information indicates that the authorization is successful.

[0319] Step 33: The third network function performs a third authorization operation based on the fifth identifier and the third identifier or the fourth identifier to determine whether the identifier association is established.

[0320] For example, it is determined whether the UE indicated by the fourth identifier is allowed to serve the Device indicated by the fifth identifier.

[0321] Step 34: The third network function sends third authorization information to the second network function, including at least one of type information and result information.

[0322] It should be noted that the third authorization information corresponds to the tenth information described in the above embodiment.

[0323] Step 35: The second network function sends at least one of the second authentication information, the first authorization information (such as Feature OK), the second authorization information (such as the fifth identifier), the third authorization information (such as Association OK), and the fourth authorization information (such as the second key) to the first network function.

[0324] The second authentication information includes the first authentication information (such as the first key) or result information, and the fourth authorization information includes at least one of the result information, the second key, the fifth identifier, and the type information. The second key KEY#2 is derived based on the first key.

[0325] It should be noted that the above step 35 corresponds to “the third communication node sending the sixth information to the first communication node based on the fifth information” described in the above embodiment.

[0326] Step 36: The first network function determines the type information of the second communication node.

[0327] For example, whether it is a terminal or a base station, the type of reader / writer - such as a handheld reader / writer or a base station reader / writer, a mobile reader / writer or a fixed reader / writer, a relay reader / writer or a proxy reader / writer, a transparent forwarding reader / writer or a non-transparent forwarding reader / writer, a proxy reader / writer or an audit reader / writer, etc.

[0328] Step 37: The first network function sends eleventh information to the reader, including at least one of the second authentication information, the second authorization information, the third authorization information, the fourth authorization information, and the fifth authorization information (such as the third key).

[0329] The fifth authorization information includes at least one of the result information, the third key, and the fifth identifier.

[0330] The third key KEY#3 is derived based on the fifth key information KEY, the first key KEY#1 or the second key KEY#2, for example, based on KEY#2, or based on KEY#2 and business information (such as "AIoT", "Ambient IoT", "PIoT", "Passive IoT", "PIN", "Personal IoT Network", "UIA", "UUI5", "eUUI5", "User ID", etc.), reader information (such as at least one of the second identifier, the third identifier, and the fourth identifier), distinguishing information / category identifier (such as the algorithm type distinguisher is set to UE reader), device information (such as at least one of the first identifier and the fifth identifier), and at least one of the anonymous identifiers.

[0331] Optionally, the reader / writer derives a fourth key based on the third key.

[0332] Optionally, the first network function sends the eleventh information based on the type information, for example, the transparent forwarding reader only sends the result information, the audit reader only sends the fifth identifier, the proxy reader only sends the key (including at least one of the first key, the second key and the third key), and the audit and proxy reader sends the fifth identifier and the key.

[0333] Optionally, the first network function performs security protection on part or all of the content in the eleventh information based on the type information, including encryption and / or integrity protection.

[0334] It should be noted that this corresponds to the above embodiment in which the first communication node determines whether to send or not to send the eleventh information to the second communication node based on the first information and at least one of the types of the second communication node.

[0335] Step 38: The reader sends thirteenth information to the Device, including at least one of the result information and the reader information.

[0336] It should be noted that this corresponds to the second communication node sending the thirteenth information to the first device as described in the above embodiment.

[0337] Step 39: The first device derives fourth key information based on the thirteenth information.

[0338] The fourth key information is used to securely protect or securely process the communication between the second communication node and the first device.

[0339] In this embodiment of the present application, the device may generate the first key based on the fifth key and at least one of the following: whether authentication (step 29) was performed or not performed, and the thirteenth message. For example, if authentication in step 29 was not performed and the result information in the thirteenth message indicates success, the first key is calculated based on the fifth key.

[0340] Optionally, the device derives a second key based on the first key, and optionally derives a third key based on the fifth key information, the first key, or the second key, wherein the derivation of the third key is the same as described in step 37.

[0341] Optionally, the device derives a fourth key based on the third key.

[0342] The key derivation scheme in steps 37 and 39 above can also be applied to derive KEY#1 from KEY, derive KEY#2 from KEY#1, and derive the fourth key from KEY#3.

[0343] Step 40: The device and the reader or the device and the first network function perform security protection on the information exchanged through the reader based on the third key or the fourth key, including encryption and / or integrity protection.

[0344] It should be noted that, in the above steps, when the first device is an APP in the second communication node, the interaction between the two nodes is an internal behavior of the equipment / network entity / node.

[0345] Each of the above-mentioned method embodiments, or various possible implementation methods in each method embodiment, can be executed separately, or any two or more of them can be executed in combination with each other. The specific implementation can be determined according to actual usage requirements, and the embodiments of this application do not limit this.

[0346] The communication method provided in the embodiment of the present application can be executed by a communication device. In the embodiment of the present application, the communication device provided in the embodiment of the present application is described by taking the communication method executed by the communication device as an example.

[0347] FIG12 shows a possible structural diagram of a communication device involved in an embodiment of the present application. As shown in FIG12 , a communication device 40 may include: a receiving module 41 and an executing module 42 .

[0348] The receiving module 41 is configured to receive first information from the second communication node, where the first information includes a first identifier related to the first device.

[0349] The execution module 42 is used to determine whether to send or not send the eleventh information to the second communication node based on the first information and at least one of the types of the second communication node, where the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information.

[0350] Among them, the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0351] In one possible implementation, the communication device 40 further includes a sending module. The sending module is configured to send second information to the third communication node after the receiving module 41 receives the first information from the second communication node, where the second information includes the first identifier, or includes the first identifier and the second identifier; the second identifier indicates the second communication node.

[0352] The receiving module 41 is further configured to receive sixth information from the third communication node, where the sixth information includes at least one of the following: second result information, information related to the first device, and second key information.

[0353] The second key information is derived based on the first key information, or the second key information is the first key information.

[0354] In a possible implementation, the execution module 42 is specifically configured to send the eleventh information to the second communication node when the second communication node is of the first type or is not of the second type;

[0355] Among them, the first type indicates that the second communication node is a terminal device; the second type indicates that the second communication node is at least one of a base station device and a network function.

[0356] In a possible implementation, the third key information is the second key information, or the third key information is derived based on the second key information.

[0357] In one possible implementation, the above-mentioned execution module 42 is also used to derive third key information based on the second key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, type information of the second communication node, information related to the first device, and anonymous identification information.

[0358] In a possible implementation, the execution module 42 is specifically configured to perform at least one of the following:

[0359] Based on the first identifier, sending eleventh information to the second communication node to indicate success or failure of the authorization;

[0360] sending, based on the information related to the second communication node, eleventh information to the second communication node, indicating success or failure of the authorization;

[0361] Based on the first identifier and information related to the second communication node, eleventh information is sent to the second communication node to indicate whether the authorization is successful or failed.

[0362] In a possible implementation, the information related to the second communication node includes at least one of the following: an identifier of the second communication node, connection information, connection tunnel information, location information, and session information.

[0363] In a possible implementation, the first communication node is a network function; or,

[0364] The above-mentioned second communication node is a terminal device or a base station device.

[0365] An embodiment of the present application provides a communication device that can receive first information from a second communication node, including a first identifier associated with a first device, and, based on the first information and at least one of the types of the second communication node, determine whether to send or not send eleventh information to the second communication node, including at least one of the following: second result information, information associated with the first device, and third key information, where the third key information is used to securely protect or securely process communication between the second communication node and the first device. Thus, this solution enables communication between the second communication node and the first device based on the key information, ensuring secure communication between the second communication node and the first device.

[0366] The communication device provided in the embodiment of the present application can implement the various processes implemented in the above-mentioned communication method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0367] FIG13 shows a possible structural diagram of a communication device involved in an embodiment of the present application. As shown in FIG13 , a communication device 50 may include: a receiving module 51 and an executing module 52 .

[0368] Among them, the receiving module 51 is used to receive second information from the first communication node, the second information includes a first identifier related to the first device, or includes a first identifier and a second identifier; the second identifier indicates the second communication node; the first device accesses the network through the second communication node.

[0369] The execution module 52 is configured to execute at least one of the following:

[0370] sending third information to a fourth communication node, and receiving fourth information from the fourth communication node;

[0371] The sixth information is sent to the first communication node based on the fifth information, where the fifth information includes at least one of the following: the second information, the fourth information, and the seventh information.

[0372] The third information includes at least one of the following: a first identifier and a third identifier; the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information; the sixth information includes at least one of the following: second result information, information related to the first device, and second key information; the seventh information includes at least one of the following: third result information, a third identifier, information related to the first device, and first key information;

[0373] The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0374] In a possible implementation, the execution module 52 is specifically configured to perform at least one of the following:

[0375] Based on the first identifier, sending sixth information to the first communication node to indicate success or failure of the authorization;

[0376] Based on the second identifier, sending sixth information to the first communication node to indicate whether the authorization is successful or failed;

[0377] Based on the first identifier and the second identifier, sixth information is sent to the first communication node to indicate whether the authorization is successful or failed.

[0378] In a possible implementation, the execution module 52 is specifically configured to perform at least one of the following:

[0379] Sending sixth information to the first communication node based on a relationship between the second identifier and the specific function;

[0380] Based on the relationship between the second identifier and the specific service, sixth information is sent to the first communication node.

[0381] In one possible implementation, the communication device 50 further includes a sending module configured to send, after the receiving module 51 receives the second information from the first communication node, eighth information to the fifth communication node based on the second information, where the eighth information includes the first identifier, or includes the first identifier and the third identifier.

[0382] The receiving module 51 is further configured to receive seventh information from the fifth communication node.

[0383] In one possible implementation, the above-mentioned execution module 52 is also used to derive second key information based on the first key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, type information of the second communication node, information related to the first device, and anonymous identification information.

[0384] In a possible implementation, the third communication node and the first communication node are both network functions.

[0385] An embodiment of the present application provides a communication device that can receive second information from a first communication node, including a first identifier related to a first device, or including a first identifier and a second identifier, with the second identifier indicating the second communication node, and then perform at least one of the following: sending third information to a fourth communication node, receiving fourth information from the fourth communication node, and sending sixth information to the first communication node based on the fifth information; the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information; the sixth information includes at least one of the following: second result information, information related to the first device, and second key information; and the seventh information includes at least one of the following: third result information, a third identifier, information related to the first device, and first key information. In this way, this solution enables the second communication node and the first device to communicate based on key information, thereby ensuring secure communication between the second communication node and the first device.

[0386] The communication device provided in the embodiment of the present application can implement the various processes implemented in the above-mentioned communication method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0387] FIG14 shows a possible structural diagram of a communication device involved in an embodiment of the present application. As shown in FIG14 , a communication device 60 may include: a receiving module 61 and a sending module 62 .

[0388] The receiving module 61 is configured to receive third information from a third communication node, where the third information includes at least one of the following: a first identifier and a third identifier related to the first device.

[0389] The sending module 62 is configured to send fourth information to the third communication node, where the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information.

[0390] Among them, the third identifier is the second identifier, or is obtained based on the second identifier; the second identifier indicates the second communication node; the first device accesses the network through the second communication node; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier.

[0391] In a possible implementation, the communication device 60 further includes an execution module configured to execute a first operation based on the third information, where the first operation includes at least one of the following: an authorization operation and an authentication operation.

[0392] In a possible implementation, the fourth communication node and the third communication node are both network functions.

[0393] An embodiment of the present application provides a communication device that can receive third information from a third communication node and send fourth information to the third communication node. The fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information. Thus, this solution enables communication between the second communication node and the first device based on the key information, ensuring secure communication between the second communication node and the first device.

[0394] The communication device provided in the embodiment of the present application can implement the various processes implemented in the above-mentioned communication method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0395] FIG15 shows a possible structural diagram of a communication device involved in an embodiment of the present application. As shown in FIG15 , a communication device 70 may include: a receiving module 71 and a sending module 72 .

[0396] The receiving module 71 is configured to receive fourteenth information from the first device, where the fourteenth information includes a first identifier related to the first device.

[0397] The sending module 72 is configured to send first information to the first communication node, where the first information includes a first identifier.

[0398] The receiving module 71 is further configured to receive eleventh information from the first communication node.

[0399] Among them, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

[0400] In a possible implementation, the communication apparatus 70 further includes an execution module configured to derive fourth key information based on the eleventh information, where the fourth key information is used to securely protect or securely process communication between the second communication node and the first device.

[0401] In one possible implementation, the above-mentioned execution module is specifically used to derive fourth key information based on the third key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

[0402] In a possible implementation, the information related to the first device includes at least one of the following: identification information, type information, identification mask information, and partial content of identification information.

[0403] In a possible implementation, the first identifier is an anonymous identifier; or,

[0404] The above-mentioned first information also includes information related to the second communication node, and the information related to the second communication node includes at least one of the following: an identifier of the second communication node, connection information, connection tunnel information, location information, and session information.

[0405] In one possible implementation, the security protection includes at least one of the following: encryption, integrity protection, and verification code generation; or the security processing includes at least one of the following: decryption, integrity verification, and verification code verification.

[0406] In a possible implementation, the second communication node is a terminal device or a base station device; or,

[0407] The first device includes at least one of the following: a tag-type device, an IoT-type device.

[0408] An embodiment of the present application provides a communication device that can receive fourteenth information from a first device, send first information to a first communication node, and then receive eleventh information from the first communication node. The eleventh information includes at least one of the following: second result information, information related to the first device, and third key information. The third key information is used to securely protect or securely process communication between the second communication node and the first device. In this way, this solution enables communication between the second communication node and the first device based on the key information, thereby ensuring secure communication between the second communication node and the first device.

[0409] The communication device provided in the embodiment of the present application can implement the various processes implemented in the above-mentioned communication method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0410] The communication device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a terminal or other device other than a terminal. For example, the terminal can include but is not limited to the types of terminal 11 listed above, and the other device can be a server, a network attached storage (NAS), etc., which is not specifically limited in the embodiments of the present application.

[0411] FIG16 shows a possible structural diagram of a communication device involved in an embodiment of the present application. As shown in FIG16 , the communication device 80 may include: a sending module 81 , a receiving module 82 , and an executing module 83 .

[0412] The sending module 81 is configured to send fourteenth information to the second communication node, where the fourteenth information includes a first identifier related to the first device.

[0413] The receiving module 82 is configured to receive thirteenth information from the second communication node, where the thirteenth information includes at least one of the following: second result information and information related to the second communication node.

[0414] The execution module 83 is used to derive fourth key information based on the thirteenth information, and the fourth key information is used to perform security protection or security processing on the communication between the second communication node and the first device.

[0415] The second result information indicates at least one of the following: authentication success or failure, authorization success or failure.

[0416] In a possible implementation, the first identifier is an anonymous identifier; or,

[0417] The information related to the second communication node includes at least one of the following: an identifier of the second communication node, connection information, connection tunnel information, location information, and session information.

[0418] In one possible implementation, the above-mentioned execution module 83 is specifically used to derive the fourth key information based on the third key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

[0419] In a possible implementation, the identification information related to the second communication node includes at least one of the following: identification information indicating the second communication node, an anonymous identifier; or

[0420] The information related to the first device includes at least one of the following: identification information, type information, identification mask information, and partial content of identification information.

[0421] In one possible implementation, the security protection includes at least one of the following: encryption, integrity protection, and verification code generation; or the security processing includes at least one of the following: decryption, integrity verification, and verification code verification.

[0422] In a possible implementation, the second communication node is a terminal device or a base station device; or,

[0423] The first device includes at least one of the following: a tag-type device, an IoT-type device.

[0424] An embodiment of the present application provides a communication device that can send fourteenth information to a second communication node, receive thirteenth information from the second communication node, and then derive fourth key information based on the thirteenth information. The fourth key information is used to securely protect or securely process communication between the second communication node and a first device. Thus, this solution enables communication between the second communication node and the first device based on the key information, thereby ensuring secure communication between the second communication node and the first device.

[0425] The communication device provided in the embodiment of the present application can implement the various processes implemented in the above-mentioned communication method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0426] As shown in Figure 17, an embodiment of the present application further provides a communication device 5000, including a processor 5001 and a memory 5002, wherein the memory 5002 stores a program or instruction that can be run on the processor 5001. For example, when the communication device 5000 is a terminal, the program or instruction is executed by the processor 5001 to implement the various steps of the above-mentioned second communication node side and first device side method embodiments, and can achieve the same technical effect. To avoid repetition, they are not described here. When the communication device 5000 is a network side device, the program or instruction is executed by the processor 5001 to implement the various steps of the above-mentioned second communication node side, first communication node side, third communication node side, and fourth communication node side method embodiments, and can achieve the same technical effect. To avoid repetition, they are not described here.

[0427] It should be noted that in the embodiments of the present application, the first communication node, the third communication node, and the fourth communication node may be network-side devices, such as core network devices. The second communication node may be a terminal or a network-side device, such as an access network device (base station). The first device may be a terminal.

[0428] The present application also provides a terminal including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps in the above-described communication method embodiment. This terminal embodiment corresponds to the above-described second communication node side or first device side method embodiment, and each implementation process and implementation method of the above-described method embodiment can be applied to this terminal embodiment and can achieve the same technical effect. Specifically, Figure 18 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.

[0429] The terminal 7000 includes but is not limited to: a radio frequency unit 7001, a network module 7002, an audio output unit 7003, an input unit 7004, a sensor 7005, a display unit 7006, a user input unit 7007, an interface unit 7008, a memory 7009 and at least some of the components of the processor 7010.

[0430] Those skilled in the art will appreciate that the terminal 7000 may also include a power supply (such as a battery) to power various components. The power supply may be logically connected to the processor 7010 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The terminal structure shown in FIG18 does not limit the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be described in detail here.

[0431] It should be understood that in an embodiment of the present application, the input unit 7004 may include a graphics processing unit (GPU) 70041 and a microphone 70042, and the graphics processor 70041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 7006 may include a display panel 70061, and the display panel 70061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 7007 includes a touch panel 70071 and at least one of other input devices 70072. The touch panel 70071 is also called a touch screen. The touch panel 70071 may include two parts: a touch detection device and a touch controller. Other input devices 70072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and an operating stick, which will not be repeated here.

[0432] In the embodiment of the present application, after receiving downlink data from a network-side device, the RF unit 7001 may transmit the data to the processor 7010 for processing. Furthermore, the RF unit 7001 may send uplink data to the network-side device. Typically, the RF unit 7001 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.

[0433] The memory 7009 can be used to store software programs or instructions and various data. The memory 7009 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 7009 may include a volatile memory or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 7009 in the embodiment of the present application includes, but is not limited to, these and any other suitable types of memory.

[0434] The processor 7010 may include one or more processing units. Optionally, the processor 7010 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into the processor 7010.

[0435] The terminal provided in the embodiment of the present application can implement the various processes implemented in the above-mentioned method embodiment and achieve the same technical effect. The implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the above-mentioned communication method embodiment. To avoid repetition, it will not be repeated here.

[0436] The present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the above-mentioned communication method embodiment. This network-side device embodiment corresponds to the above-mentioned second communication node side, first communication node side, third communication node side, or fourth communication node side method embodiment, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to this network-side device embodiment and can achieve the same technical effect.

[0437] Specifically, embodiments of the present application also provide a network-side device. As shown in Figure 19, the network-side device 600 includes an antenna 601, a radio frequency device 602, a baseband device 603, a processor 604, and a memory 605. Antenna 601 is connected to radio frequency device 602. In the uplink direction, radio frequency device 602 receives information via antenna 601 and sends the received information to baseband device 603 for processing. In the downlink direction, baseband device 603 processes the information to be transmitted and sends it to radio frequency device 602. Radio frequency device 602 processes the received information and then sends it through antenna 601.

[0438] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 603 , which includes a baseband processor.

[0439] The baseband device 603 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 19, one of which is, for example, a baseband processor, which is connected to the memory 605 through a bus interface to call the program in the memory 605 and execute the network device operations shown in the above method embodiment.

[0440] The network side device may further include a network interface 606, which is, for example, a Common Public Radio Interface (CPRI).

[0441] Specifically, the network side device 600 of an embodiment of the present invention also includes: instructions or programs stored in the memory 605 and executable on the processor 604. The processor 604 calls the instructions or programs in the memory 605 to execute the methods executed by the modules shown in the above embodiment and achieve the same technical effect. To avoid repetition, they will not be elaborated here.

[0442] The network side device provided in the embodiment of the present application can implement the various processes implemented in the above method embodiment and achieve the same technical effect. The implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the above communication method embodiment. To avoid repetition, it will not be repeated here.

[0443] Specifically, the embodiment of the present application further provides a network side device. As shown in FIG20 , the network side device 1700 includes: a processor 1701, a network interface 1702, and a memory 1703. The network interface 1702 is, for example, a common public radio interface (CPRI).

[0444] Specifically, the network side device 1700 of the embodiment of the present application also includes: instructions or programs stored in the memory 1703 and executable on the processor 1701. The processor 1701 calls the instructions or programs in the memory 1703 to execute the methods executed by the modules shown in the above embodiment and achieve the same technical effect. To avoid repetition, they will not be elaborated here.

[0445] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned communication method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0446] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.

[0447] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned communication method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0448] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0449] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned communication method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0450] An embodiment of the present application also provides a communication system, including: a first communication device and a second communication device, wherein the first communication device can be used to execute the steps of the communication method described above, and the second communication device can be used to execute the steps of the communication method described above.

[0451] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0452] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.

[0453] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.

Claims

1. A communication method performed by a communication system, the communication system comprising at least a first communication node, a second communication node, and a third communication node, the method comprising: The first communication node receives first information from the second communication node, where the first information includes a first identifier related to the first device; The first communication node sends second information to the third communication node, where the second information includes the first identifier, or includes the first identifier and the second identifier; the second identifier indicates the second communication node; The third communication node performs at least one of the following: In a case where the communication system further includes a fourth communication node, sending third information to the fourth communication node and receiving fourth information from the fourth communication node; Sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: second information, fourth information, and seventh information; The third information includes at least one of the following: the first identifier and the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device, and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device, and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device, and the first key information; The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

2. The method according to claim 1, wherein The communication system further includes a fifth communication node, and the method further includes: The third communication node sends eighth information to the fifth communication node based on the second information, where the eighth information includes the first identifier, or includes the first identifier and the third identifier; The third communication node receives the seventh information from the fifth communication node.

3. The method according to claim 1 or 2, wherein: The communication system further includes a fifth communication node, and the method further includes: The third communication node sends ninth information to the fifth communication node, where the ninth information includes the first identifier and the third identifier, or includes the first identifier and the fourth identifier; The third communication node receives tenth information from the fifth communication node, where the tenth information includes at least one of the following: the first result information and information related to the first device.

4. The method according to any one of claims 1 to 3, wherein Also includes: The first communication node determines, based on at least one of the first information and the type of the second communication node, whether to send eleventh information to the second communication node, where the eleventh information includes at least one of the following: the second result information, information related to the first device, and third key information; the third key information is used to perform security protection or security processing on communication between the second communication node and the first device; The first device accesses a network through the second communication node.

5. The method according to claim 4, wherein Also includes: The first communication node derives the third key information based on the second key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

6. The method according to any one of claims 1 to 5, wherein Also includes: The second communication node sends thirteenth information to the first device, where the thirteenth information includes at least one of the following: the second result information and information related to the second communication node; The first device derives fourth key information based on the thirteenth information, and the fourth key information is used to securely protect or securely process communication between the second communication node and the first device.

7. A communication method, comprising: The first communication node receives first information from the second communication node, where the first information includes a first identifier related to the first device; The first communication node determines, based on at least one of the first information and the type of the second communication node, whether to send eleventh information to the second communication node, the eleventh information including at least one of the following: second result information, information related to the first device, and third key information; Among them, the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

8. The method according to claim 7, wherein: After the first communication node receives the first information from the second communication node, the method further includes: The first communication node sends second information to a third communication node, where the second information includes the first identifier, or includes the first identifier and the second identifier; the second identifier indicates the second communication node; The first communication node receives sixth information from the third communication node, where the sixth information includes at least one of the following: the second result information, information related to the first device, and second key information; The second key information is derived based on the first key information, or the second key information is the first key information.

9. The method according to claim 7 or 8, wherein The first communication node determining, based on the type of the second communication node, whether to send or not to send eleventh information to the second communication node, includes: When the second communication node is of the first type, or is not of the second type, the first communication node sends the eleventh information to the second communication node; Among them, the first type indicates that the second communication node is a terminal device; the second type indicates that the second communication node is at least one of a base station device and a network function.

10. The method according to any one of claims 7 to 9, wherein The third key information is the second key information, or the third key information is derived based on the second key information.

11. The method according to claim 10, wherein: The method further comprises: The first communication node derives the third key information based on the second key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, type information of the second communication node, information related to the first device, and anonymous identification information.

12. The method according to any one of claims 7 to 11, wherein The first communication node determines, based on the first information, whether to send or not to send eleventh information to the second communication node, including at least one of the following: The first communication node sends the eleventh information to the second communication node based on the first identifier, to indicate whether the authorization is successful or failed; The first communication node sends the eleventh information to the second communication node based on the information related to the second communication node, so as to indicate whether the authorization is successful or failed; The first communication node sends the eleventh information to the second communication node based on the first identifier and information related to the second communication node, so as to indicate whether the authorization is successful or failed.

13. The method according to any one of claims 7 to 12, wherein: The information related to the second communication node includes at least one of the following: an identifier, connection information, connection tunnel information, location information, and session information of the second communication node.

14. The method according to any one of claims 7 to 13, wherein The first communication node is a network function; or, The second communication node is a terminal device or a base station device.

15. A communication method, comprising: The third communication node receives second information from the first communication node, where the second information includes a first identifier related to the first device, or includes the first identifier and a second identifier; the second identifier indicates the second communication node; and the first device accesses the network through the second communication node. The third communication node performs at least one of the following: sending third information to a fourth communication node, and receiving fourth information from the fourth communication node; sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: the second information, the fourth information, and the seventh information; The third information includes at least one of the following: the first identifier and the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device, and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device, and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device, and the first key information; The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

16. The method according to claim 15, wherein The third communication node sends sixth information to the first communication node based on the fifth information, including at least one of the following: The third communication node sends the sixth information to the first communication node based on the first identifier, so as to indicate whether the authorization is successful or failed; The third communication node sends the sixth information to the first communication node based on the second identifier, so as to indicate whether the authorization is successful or failed; The third communication node sends the sixth information to the first communication node based on the first identifier and the second identifier, to indicate whether the authorization is successful or failed.

17. The method according to claim 16, wherein: The third communication node sends the sixth information to the first communication node based on the second identifier, including at least one of the following: The third communication node sends the sixth information to the first communication node based on the relationship between the second identifier and the specific function; The third communication node sends the sixth information to the first communication node based on the relationship between the second identifier and the specific service.

18. The method according to any one of claims 15 to 17, wherein After the third communication node receives the second information from the first communication node, the method further includes: The third communication node sends eighth information to the fifth communication node based on the second information, where the eighth information includes the first identifier, or includes the first identifier and the third identifier; The third communication node receives the seventh information from the fifth communication node.

19. The method according to any one of claims 15 to 18, wherein The method further comprises: The third communication node derives the second key information based on the first key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, type information of the second communication node, information related to the first device, and anonymous identification information.

20. The method according to any one of claims 15 to 19, wherein The third communication node and the first communication node both have network functions.

21. A communication method, comprising: The fourth communication node receives third information from the third communication node, where the third information includes at least one of the following: a first identifier and a third identifier related to the first device; The fourth communication node sends fourth information to the third communication node, where the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information; Among them, the third identifier is the second identifier, or is obtained based on the second identifier; the second identifier indicates the second communication node; the first device accesses the network through the second communication node; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier.

22. The method according to claim 21, wherein The method further comprises: The fourth communication node performs a first operation based on the third information, where the first operation includes at least one of the following: an authorization operation and an authentication operation.

23. The method according to claim 21 or 22, wherein The fourth communication node and the third communication node are both network functions.

24. A communication method, comprising: The second communication node receives fourteenth information from the first device, where the fourteenth information includes a first identifier related to the first device; The second communication node sends first information to the first communication node, where the first information includes the first identifier; The second communication node receives eleventh information from the first communication node; Among them, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

25. The method according to claim 24, wherein The method further comprises: The second communication node derives fourth key information based on the eleventh information, and the fourth key information is used to securely protect or securely process communication between the second communication node and the first device.

26. The method according to claim 25, wherein The second communication node derives fourth key information based on the eleventh information, including: The second communication node derives the fourth key information based on the third key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

27. The method according to any one of claims 24 to 26, wherein The information related to the first device includes at least one of the following: identification information, type information, identification mask information, and partial content of identification information.

28. The method according to any one of claims 24 to 27, wherein The first identifier is an anonymous identifier; or, The first information also includes information related to the second communication node, and the information related to the second communication node includes at least one of the following: an identifier, connection information, connection tunnel information, location information, and session information of the second communication node.

29. The method according to any one of claims 24 to 28, wherein The security protection includes at least one of the following: encryption, integrity protection, and generation of verification code; or, The security processing includes at least one of the following: decryption, integrity check, and verification code check.

30. The method according to any one of claims 24 to 29, wherein The second communication node is a terminal device or a base station device; or, The first device includes at least one of the following: a tag-type device, an Internet of Things (IoT)-type device.

31. A communication method, comprising: The first device sends fourteenth information to the second communication node, where the fourteenth information includes a first identifier related to the first device; The first device receives thirteenth information from the second communication node, where the thirteenth information includes at least one of the following: second result information and information related to the second communication node; The first device derives fourth key information based on the thirteenth information, where the fourth key information is used to securely protect or securely process communication between the second communication node and the first device; The second result information indicates at least one of the following: authentication success or failure, authorization success or failure.

32. The method according to claim 31, wherein The first identifier is an anonymous identifier; or, The information related to the second communication node includes at least one of the following: an identifier, connection information, connection tunnel information, location information, and session information of the second communication node.

33. The method according to claim 31 or 32, wherein The first device derives fourth key information based on the thirteenth information, including: The first device derives the fourth key information based on the third key information and the twelfth information, and the twelfth information includes at least one of the following: business information, function information, identification information related to the second communication node, algorithm differentiation information, type information of the second communication node, information related to the first device, and anonymous identification information.

34. The method according to claim 33, wherein The identification information related to the second communication node includes at least one of the following: identification information for indicating the second communication node, an anonymous identifier; or, The information related to the first device includes at least one of the following: identification information, type information, identification mask information, and partial content of identification information.

35. The method according to any one of claims 31 to 34, wherein The security protection includes at least one of the following: encryption, integrity protection, and generation of verification code; or, The security processing includes at least one of the following: decryption, integrity check, and verification code check.

36. The method according to any one of claims 31 to 35, wherein The second communication node is a terminal device or a base station device; or, The first device includes at least one of the following: a tag-type device, an Internet of Things (IoT)-type device.

37. A communication device comprising: Receiving module and executing module; The receiving module is configured to receive first information from the second communication node, where the first information includes a first identifier related to the first device; the execution module is configured to determine whether to send or not send eleventh information to the second communication node based on at least one of the first information and the type of the second communication node, the eleventh information including at least one of the following: second result information, information related to the first device, and third key information; Among them, the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

38. A communication device comprising: Receiving module and executing module; The receiving module is configured to receive second information from the first communication node, where the second information includes a first identifier related to the first device, or includes the first identifier and a second identifier; the second identifier indicates the second communication node; and the first device accesses the network through the second communication node; The execution module is configured to execute at least one of the following: sending third information to a fourth communication node, and receiving fourth information from the fourth communication node; sending sixth information to the first communication node based on fifth information, where the fifth information includes at least one of the following: the second information, the fourth information, and the seventh information; The third information includes at least one of the following: the first identifier and the third identifier; the fourth information includes at least one of the following: the first result information, the fourth identifier, the information related to the first device, and the first key information; the sixth information includes at least one of the following: the second result information, the information related to the first device, and the second key information; the seventh information includes at least one of the following: the third result information, the third identifier, the information related to the first device, and the first key information; The third identifier is the second identifier, or is obtained based on the second identifier; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier; the second key information is the first key information, or the second key information is derived based on the first key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third result information indicates at least one of the following: authentication success or failure, authorization success or failure.

39. A communication device comprising: Receiving module and sending module; The receiving module is configured to receive third information from a third communication node, where the third information includes at least one of the following: a first identifier and a third identifier related to the first device; The sending module is configured to send fourth information to the third communication node, where the fourth information includes at least one of the following: first result information, a fourth identifier, information related to the first device, and first key information; Among them, the third identifier is the second identifier, or is obtained based on the second identifier; the second identifier indicates the second communication node; the first device accesses the network through the second communication node; the first result information indicates whether the authentication is successful or failed; the fourth identifier is obtained based on the third identifier.

40. A communication device comprising: Receiving module and sending module; The receiving module is configured to receive fourteenth information from the first device, where the fourteenth information includes a first identifier related to the first device; The sending module is configured to send first information to the first communication node, where the first information includes the first identifier; The receiving module is further configured to receive eleventh information from the first communication node; Among them, the eleventh information includes at least one of the following: second result information, information related to the first device, and third key information; the second result information indicates at least one of the following: authentication success or failure, authorization success or failure; the third key information is used to securely protect or securely process the communication between the second communication node and the first device; the first device accesses the network through the second communication node.

41. A communication device comprising: Sending module, receiving module and execution module; The sending module is configured to send fourteenth information to the second communication node, where the fourteenth information includes a first identifier related to the first device; The receiving module is configured to receive thirteenth information from the second communication node, where the thirteenth information includes at least one of the following: second result information and information related to the second communication node; the execution module is configured to derive fourth key information based on the thirteenth information, wherein the fourth key information is used to perform security protection or security processing on the communication between the second communication node and the first device; The second result information indicates at least one of the following: authentication success or failure, authorization success or failure.

42. A communication device comprising a processor and a memory, the memory storing a program or instruction that can be run on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the communication method according to any one of claims 7 to 14, or implements the steps of the communication method according to any one of claims 15 to 20, or implements the steps of the communication method according to any one of claims 21 to 23, or implements the steps of the communication method according to any one of claims 24 to 30, or implements the steps of the communication method according to any one of claims 31 to 36.

43. A readable storage medium storing a program or instruction, wherein the program or instruction, when executed by a processor, implements the communication method according to any one of claims 7 to 14, or implements the steps of the communication method according to any one of claims 15 to 20, or implements the steps of the communication method according to any one of claims 21 to 23, or implements the steps of the communication method according to any one of claims 24 to 30, or implements the steps of the communication method according to any one of claims 31 to 36.

Citation Information

Patent Citations

  • Equipment node authentication method, device and system

    CN111092820A

  • Signing method and device, communication equipment, Internet of Things equipment and network element

    CN116980876A

  • Label management method and related device

    CN117461339A

  • Narrowband internet-of-things (NB-IOT) enhacements

    WO2018175249A1

  • Communication method and apparatus

    WO2023142815A1