Communication method and device
By processing security parameters between AIoT devices and communication networks, the security issues of data transmission of AIoT devices in communication networks are solved, and secure data transmission and integrity verification are achieved.
Patent Information
- Application Number
- PCT/CN2024/086524
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-08
- Publication Date
- 2025-10-16
AI Technical Summary
AIoT devices lack RRC status when accessing the communication network, resulting in the inability to establish data bearer. How to achieve data transmission and ensure transmission security.
By receiving and sending the first PDU that carries security parameters based on AIoT devices for security processing, data integrity verification and encryption processing are achieved to ensure the security of data transmission.
It realizes data transmission between AIoT devices and communication networks, ensuring the security and integrity of data.
Smart Images

Figure CN2024086524_16102025_PF_FP_ABST
Abstract
Description
Communication method and device TECHNICAL FIELD
[0001] The present application relates to the field of communication, and more particularly, to a communication method and device. BACKGROUND
[0002] With the development of technology, there is a demand for Ambient Power-enabled IoT (AIoT) devices to access a communication system or a communication network for data interaction. However, the characteristics of AIoT devices include no RRC (Radio Resource Control) state, and a data bearer cannot be established. Therefore, how to implement data transmission between AIoT devices and a communication network and ensure the security of data transmission becomes a problem to be solved.
[0003] SUMMARY
[0004] Embodiments of the present application provide a communication method and device.
[0005] Embodiments of the present application provide a communication method performed by an AIoT device, comprising:
[0006] receiving a first message, wherein the first message carries a first PDU that is securely processed based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0007] Embodiments of the present application provide a communication method performed by a first device, comprising:
[0008] receiving a third message from a first core network device, wherein the third message carries a first PDU that is securely processed based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data;
[0009] sending a first message to the AIoT device, wherein the first message carries the first PDU.
[0010] Embodiments of the present application provide a communication method performed by a first core network device, comprising:
[0011] sending a third message to the first device, wherein the third message carries a first PDU that is securely processed based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0012] Embodiments of the present application provide an AIoT device, comprising:
[0013] receive a first message, wherein the first message carries a first PDU which is processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0014] The embodiment of the present application provides a first device, comprising:
[0015] receive a third message from the first core network device, wherein the third message carries a first PDU which is processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data; and send a first message to the AIoT device, wherein the first message carries the first PDU.
[0016] The embodiment of the present application provides a first core network device, comprising:
[0017] send a third message to the first device, wherein the third message carries a first PDU which is processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0018] By adopting the above scheme, the first PDU sent to the AIoT device can be processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data, so that the AIoT device can receive data transmitted by a communication network, and the security of the data can be ensured by processing the data based on the security parameter. BRIEF DESCRIPTION OF DRAWINGS
[0019] FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.
[0020] FIG. 2 is a schematic flowchart of a communication method according to an embodiment of the present application.
[0021] FIG. 3 is a schematic flowchart of a communication method according to another embodiment of the present application.
[0022] FIG. 4 is a schematic flowchart of a communication method according to still another embodiment of the present application.
[0023] FIG. 5 is a schematic diagram of calculating a first check code processing according to an embodiment of the present application.
[0024] FIG. 6 is a schematic diagram of calculating a first cipher text data processing according to an embodiment of the present application.
[0025] FIG. 7 is a schematic diagram of a constituent structure of a first PDU according to an embodiment of the present application.
[0026] FIG. 8 is a schematic diagram of calculating a first verification code according to an embodiment of the present application.
[0027] FIG. 9 is a schematic diagram of decrypting first cipher data processing according to an embodiment of the present application.
[0028] FIGS. 10-12 are several schematic flow diagrams of downlink transmission according to embodiments of the present application.
[0029] FIGS. 13 and 14 are several schematic flow diagrams of uplink transmission according to embodiments of the present application.
[0030] FIG. 15 is a schematic block diagram of an AIoT device according to an embodiment of the present application.
[0031] FIG. 16 is a schematic block diagram of a first device according to an embodiment of the present application.
[0032] FIG. 17 is a schematic block diagram of a first core network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0033] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: LTE, LTE-A, NR, evolution of NR, WLAN, WiFi, or other communication systems, etc.
[0034] The embodiments of the present application describe various embodiments in combination with network devices and terminals. The terminals can be mobile or fixed, and the terminals can also be referred to as mobile stations, user units, etc. The terminals can be stations in WLAN, and can be smart terminals, wireless modems, notebook computers, tablet computers, etc. In the embodiments of the present application, the terminals can be VR terminals / AR terminals, industrial control terminals, unmanned driving terminals, remote medical terminals, smart grid terminals, transportation safety terminals, smart city terminals, or wireless terminals of smart homes, etc. As an example but not limitation, in the embodiments of the present application, the terminals can also be wearable devices.
[0035] In the embodiments of the present application, the network devices can be devices for communicating with the terminals. The network devices can be access points in WLAN, can be evolved base stations in LTE, or relay stations, or network devices in vehicle-mounted devices, wearable devices, and NR networks, or network devices in future evolved PLMN networks, or network devices in non-ground networks, etc. As an example but not limitation, in the embodiments of the present application, the network devices can have mobile characteristics, for example, the network devices can be mobile devices.
[0036] For the convenience of understanding the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described as follows, which can be combined with the technical solutions of the embodiments of the present application in any manner as optional solutions, and all of them belong to the protection scope of the embodiments of the present application.
[0037] FIG. 1 illustrates a communication system 100. The communication system includes one network device 110 and two terminals 120. In a possible implementation, the communication system 100 can include multiple network devices 110, and each network device 110 can include other numbers of terminals 120 within its coverage, which are not limited by the embodiments of the present application. In a possible implementation, the communication system 100 can further include a mobility management entity, an access and mobility management function, and other network entities, which are not limited by the embodiments of the present application. The network device can include an access network device and a core network device. That is, the communication system can include multiple core networks for communicating with the access network device. The access network device can be a base station of an LTE, LTE-A, or NR system. For example, the communication system shown in FIG. 1 can include network devices and terminals with communication functions, and can further include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited by the embodiments of the present application.
[0038] AIoT is expected to have a higher number of connections / device density than existing 3GPP IoT technologies, and the complexity and power consumption of devices are lower than existing 3GPP IoT technologies by several orders of magnitude, which can provide clear differentiation and solve use cases and scenarios that cannot be implemented based on existing 3GPP IoT technologies. AIoT has the following characteristics: AIoT devices are divided into two types according to power consumption, i.e., about 1 uw peak power consumption or less than several hundred uw peak power consumption; the service (or service) type of AIoT devices is divided into DT (service terminated at device, Device-terminated) and DO-DTT (DO triggered by DT, Device-originated-device-terminated triggered), which are both triggered by the network; topology 1 (base station and AIoT direct connection) and topology 2 (UE as an intermediate node) in TR 38.848 are supported, there is no RRC state, no mobility (i.e., at least no cell selection / reselection type function), no HARQ (Hybrid Automatic Repeat Request), and no ARQ (Automatic Repeat Request); AIoT devices have no RRC state, i.e., DRB cannot be established, from an end-to-end perspective, data transmission of the user plane is not feasible, and AIoT devices can only support data transmission through signaling.
[0039] FIG. 2 is a schematic flowchart of a communication method performed by an AIoT device according to an embodiment of the present application. The method comprises at least part of the following.
[0040] S210, receiving a first message, wherein the first message carries a first protocol data unit (PDU) processed based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0041] FIG. 3 is a schematic flowchart of a communication method performed by a first device according to an embodiment of the present application. The method comprises at least part of the following.
[0042] S310, receiving a third message from a first core network device, wherein the third message carries a first PDU processed based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0043] S320, sending a first message to the AIoT device, wherein the first message carries the first PDU.
[0044] FIG. 4 is a schematic flowchart of a communication method performed by a first core network device according to an embodiment of the present application. The method comprises at least part of the following.
[0045] S410, sending a third message to a first device, wherein the third message carries a first PDU processed based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0046] The first device can be one of the following: an access network device, a terminal. The access network device can refer to an access network device serving or managing the AIoT device. The terminal can be an intermediate device or a proxy device or a relay device of the AIoT device, i.e., the AIoT device can interact with the device on the network side through the terminal. In some possible examples, the terminal can also be referred to as any one of an Intermediate node, a proxy UE, an intermediate UE, a relay device, an intermediate device, a proxy device, etc.
[0047] Optionally, the first core network device can be a control plane network element, such as an access and mobility management function (AMF).
[0048] Optionally, the first core network device can be an existing core network element in the 5GC but with added AIoT service function.
[0049] Optionally, the first core network device can be a newly added network element in the core network that is dedicated to AIoT (or dedicated to AIoT traffic, or dedicated to AIoT service), and its function is to be responsible for processing the logic of environmental Internet of Things services, such as the first core network device can be any one of AIoT NF (Network Function), or AIoT MF (Management Function), etc. The function of the newly added network element dedicated to AIoT can specifically include but is not limited to at least one of the following: executing AIoT service requests and processing corresponding AIoT specializations; supporting AIoT device inventory and message routing, and ensuring safe operation of AIoT devices when needed; authorizing AIoT service requests; collecting data of AIoT devices and reporting; collecting charging data; managing UDM enhancements of device subscriptions of AIoT devices, which include device IDs, state information of devices, etc., such as the last service node corresponding to the AIoT device, an indication of whether the ID of the AIoT device is valid, whether the AIoT device is permanently disabled, etc.
[0050] The AIoT device can transmit AIoT data (which can include downlink data and uplink data (or uplink feedback)) with the first device and the first core network device. Or, the AIoT device can transmit AIoT data with the 5GC (specifically, the first core network device), such as the AIoT device can transmit data with the first core network device using AIoT, i.e. AIoT dedicated message. The AIoT device and the first core network device need to establish context in advance, such as which can include AIoT device capability, security context and EPS bearer, etc.
[0051] In some possible implementations, the processing of the first core network device can include: receiving a service request message, wherein the service request message carries at least one of the following: the downlink data, the identification of the AIoT device, the identification of the group to which the AIoT device belongs, and a target area, wherein the target area is used to select the first device.
[0052] The service request message can also be referred to as AIoT service request (message).
[0053] The service request message can carry one of the identification of the AIoT device or the identification of the group to which the AIoT device belongs, i.e. both cannot be carried at the same time.
[0054] The identity of the AIoT device can be an original identity of the AIoT device (such as represented as AIoT Device ID) or a temporary (Temp) identity (ID) of the AIoT device.
[0055] The temporary identity of the AIoT device can be respectively generated by the network side (at least including the first core network device, and optionally further including an AF, etc.) and the AIoT device based on the same rule, which can be a protocol provision, or respectively pre-configured by the AIoT device and the network side, or both the AIoT device and the network side by default, and the embodiments are not limited thereto. The update timing of the temporary ID of the AIoT device can be default or protocol provision, such as, in the case of each time sending a certain message carrying the temporary ID of the AIoT device to the AIoT device through the wireless air interface and receiving the response of the AIoT device to the message, the AIoT device and the network side respectively generate the updated temporary ID of the AIoT device based on the same rule to prevent linkability attacks.
[0056] The target area can include one or more tracking areas (TAs, Tracking Area). Any TA can be represented by at least one of the following: a TAC (TA code) corresponding to the TA, a TAI (TA Identity) corresponding to the TA. For example, the target area can be a target area list including one or more TACs (or TAIs).
[0057] The downlink data (DL data) can be DT data (data terminated at the device).
[0058] Optionally, the downlink data can include at least one of a service type (or service operation type) and specific data corresponding to the write command.
[0059] The service type can be used to indicate or for the AIoT device to determine the operation (or type of operation) to be performed. For example, the service type can include one of an inventory message, a read command, and a write command, and the service type can be used to indicate the operation corresponding to any one of the inventory message, the read command, and the write command to be performed by the AIoT device.
[0060] The specific data corresponding to the write command can refer to the specific data (such as application data) that the AIoT device needs to write into the memory when executing the write command.
[0061] For example, the downlink data can include one of an inventory message, a read command, and a write command, and when the downlink data includes the write command, it further includes the specific data corresponding to the write command.
[0062] Specifically, the AIoT typical application scenarios mainly include Inventory (inventory), Command (command), etc., and the Command further includes read (read), Write (write). For example, in the indoor command (rUC4) scenario, the read command is used to instruct the AIoT device to read the application data (such as sensor data) from the memory, and the AIoT device can upload the message content including the application data (such as sensor data) in response to the read command. As for various possible other types of the application data, the embodiments are not limited. The write command is used to write the application data to the memory of the AIoT device, and the message (i.e., the write command) transmitted to the AIoT device can include the application data. Optionally, the AIoT device to be executed in the write command can further include at least one of the address of the AIoT device to write data, the type of the AIoT device to write data, and the like. In the indoor Inventory (rUC1) scenario, the inventory command or the inventory message is used to find the AIoT device (such as reading the identification of the AIoT device) in a specific area, and the AIoT device uploads the message content including the identification of the AIoT device in response to the inventory command or the inventory message.
[0063] Optionally, the service request message can also carry a service type; correspondingly, the downlink data can only include specific data corresponding to the write command.
[0064] Optionally, the service request message can also carry an identification (AF ID) of the AF.
[0065] Optionally, in the case that the service request message is transparent at the core network side, the service request message can be carried by a container between the AIoT device and the AF, and the possible structure of the container is not limited in the embodiments.
[0066] In an example, receiving the service request message can be receiving the service request message from a second core network device. The second core network device can be a NEF (Network Exposure Function).
[0067] The processing of the AF can be: sending a service request message to the NEF. The processing of the NEF can include: receiving the service request message from the AF, checking whether the AF is authorized to request the AIoT service based on the AF ID; in the case of determining that the AF is authorized to request the AIoT service, selecting a first core network device whose AIoT service area matches the target area based on the target area carried in the service request message; and forwarding the service request message to the first core network device. The embodiments are not limited in terms of the way in which the AF generates or sends the service request message or the triggering condition. The first core network device can be one of a plurality of candidate core network devices, and any one of the candidate core network devices can have an AIoT service function and be configured with an AIoT service area.
[0068] For example, the way in which the NEF selects the AMF (or AIoT NF) can be: using the target area (or the target area list) to discover the AMF (or AIoT NF) whose AIoT service area matches the target area from the NRF (Network Repository Function). More specifically, the NEF can send the target area or the target area list to the NRF, and if the NRF determines that the target area matches the AIoT service area of an AMF (or AIoT NF), the NRF returns the information (such as the identifier or index or number of the AMF or AIoT NF) of the AMF (or AIoT NF) to the NEF.
[0069] In an example, the first core network device can receive the service request message from the AF. The AF can perform the following processing: sending the service request message to the first core network device. Optionally, the AF can also perform the processing of discovering the first core network device, and the specific processing manner is similar to the processing of the NEF in the foregoing example, which is not described herein.
[0070] In some possible implementations, after receiving the service request message, the first core network device can generate a first PDU, which can be a PDU that is subjected to security processing based on the security parameter corresponding to the AIoT device.
[0071] The security processing can include integrity protection processing (i.e., integrity protection, which will be referred to as integrity protection hereinafter) and / or encryption processing. Specifically, the first PDU can be a downlink PDU that is subjected to integrity protection processing and / or encryption processing based on the security parameter corresponding to the AIoT device.
[0072] Preferably, the security parameter corresponding to the AIoT device can be a Non Access Stratum (NAS) security parameter corresponding to the AIoT device. On the side of the first core network device, the NAS security parameter corresponding to the AIoT device can be stored in a security context corresponding to the AIoT device. The present embodiment does not limit the process of pre-establishing the NAS security context by the AIoT device and the first core network device.
[0073] Further, the PDU can be a NAS PDU.
[0074] In this case, the first core network device can be a control plane network element such as an AMF, or a core network device (with added AIoT service function) of an existing 5GC; it should be pointed out that the first core network device in this case can also be a network element dedicated to AIoT.
[0075] Optionally, the security parameter corresponding to the AIoT device can be a security parameter of an AIoT related protocol layer corresponding to the AIoT device. For example, on the side of the first core network device, the security parameter of the AIoT related protocol layer corresponding to the AIoT device can also be stored in a security context (which can be referred to as a security context of the AIoT related protocol layer) corresponding to the AIoT device. The present embodiment does not limit the process of pre-establishing the security context of the AIoT related protocol layer by the AIoT device and the first core network device.
[0076] Further, the PDU can be an AIoT related protocol layer PDU.
[0077] The AIoT related protocol layer is different from other protocol layers in the prior art, and can be a newly added protocol layer. The AIoT related protocol layer can also be referred to as an AIoT protocol layer; alternatively, it can be referred to as a non-access layer, which is at least partially different from the NAS in the prior art, and the non-access layer in this case at least supports an AIoT related protocol or service.
[0078] In this case, the first core network device can preferably be a network element dedicated to AIoT.
[0079] In the following description of the embodiments, the security parameter can be a NAS security parameter, the security context can be a NAS security context, and correspondingly, the PDU can be a NAS PDU; or the security parameter can be a security parameter of an AIoT related protocol layer, the security context can be a security context of an AIoT related protocol layer, and correspondingly, the PDU can be an AIoT related protocol layer PDU. The following will not be repeated.
[0080] In one embodiment, the first core network device can only perform the integrity protection processing.
[0081] The first PDU carries a first check code for verifying the integrity, the first check code being calculated based on a perfect protection parameter and the downlink data in the security parameter corresponding to the AIoT device, wherein the perfect protection parameter includes at least one of a perfect protection key and a perfect protection algorithm. The first PDU can also carry the downlink data. The downlink data referred to in this application refers to plaintext downlink data, which will not be repeated below.
[0082] The first core network device can calculate the first check code by taking the perfect protection key corresponding to the AIoT device and the downlink data as first input parameters and calculating the first check code by using the perfect protection algorithm corresponding to the AIoT device.
[0083] Here, the perfect protection key corresponding to the AIOT device is the perfect protection key in the security parameter corresponding to the AIoT device. Specifically, it can be the perfect protection key between the AIoT device and the first core network device, which can be represented as K int , and its length can be 128 bits, or longer or shorter, which is not limited. For example, if the security parameter is a NAS security parameter, the perfect protection key can be a NAS perfect protection key, which can be represented as K NASint . If the security parameter is an AIoT related protocol layer security parameter, the perfect protection key can be an AIoT related protocol layer perfect protection key, which can be represented as K AIoT-int .
[0084] The perfect protection algorithm corresponding to the AIOT device is the perfect protection algorithm (such as NIA) in the security parameter corresponding to the AIoT device, which can be any one of NIA0, 128-NIA1, 128-NIA2, 128-NIA3, etc., which is not exhaustive here. For example, if the security parameter is a NAS security parameter, the perfect protection algorithm can be a NAS perfect protection algorithm. If the security parameter is an AIoT related protocol layer security parameter, the perfect protection algorithm can be an AIoT related protocol layer perfect protection algorithm.
[0085] The first check code can be a first MAC (Message Authentication Codes, message authentication code). The first MAC can also be represented as MAC-I, or first MAC-I, or downlink MAS-I, or -MAC, or first -MAC, or downlink -MAC, etc., which is not exhaustive.
[0086] Optionally, the first input parameter can also include at least one of the following: a first count value (COUNT), a first bearer (BEARER) identifier, and a downlink transmission direction (DIRECTION).
[0087] The first count value can be generated in any manner. The length of the first count value can be configured according to actual conditions, for example, can be 32-bit.
[0088] The first bearer identifier can be an identifier of a bearer used for sending the downlink message. For example, the first bearer identifier can be represented as BEARER (bearer) ID 1. The length of the first bearer identifier can be configured according to actual conditions, for example, can be 5-bit.
[0089] The length of the downlink transmission direction can be configured according to actual conditions, for example, can be 1-bit; the value of the downlink transmission direction can be configured according to actual conditions, for example, can be 1.
[0090] For example, in combination with FIG. 5, the first core network device can calculate the first check code by taking the confidentiality key, the downlink data, the first count value, the first bearer identifier, and the downlink transmission direction as first input parameters, and calculating the first check code based on the perfect secrecy algorithm (NIA in FIG. 5) corresponding to the AIoT device.
[0091] It should be understood that the above is only an exemplary description of calculating the check code, and all possible ways of calculating the check code are not enumerated here.
[0092] In an embodiment, the first core network device can only perform encryption processing.
[0093] The first PDU can carry first cipher text data, which is calculated based on the confidentiality parameter in the security parameter corresponding to the AIoT device and the downlink data, the confidentiality parameter including at least one of a confidentiality key and a confidentiality algorithm. The confidentiality algorithm can also be referred to as an encryption algorithm.
[0094] The process of calculating the first cipher text data can be: taking the confidentiality key corresponding to the AIoT device as a second input parameter, and calculating a first key stream based on the confidentiality algorithm corresponding to the AIoT device and the second input parameter, and calculating the first cipher text data based on the first key stream and the downlink data. The way of calculating the first cipher text data can be configured according to actual conditions, for example, can be exclusive or calculation. The key stream can also be referred to as a KEYSTREAM BLOCK.
[0095] Here, the confidentiality key corresponding to the AIoT device is the confidentiality key in the security parameter corresponding to the AIoT device. The confidentiality key corresponding to the specific AIoT device can be a confidentiality key between the AIoT device and the first core network device, for example, can be K enc, the length of which can be 128 bits, or can be longer or shorter, and is not limited. For example, if the security parameter is a NAS security parameter, the confidentiality key can be a NAS confidentiality key, which can be represented as K NASenc . If the security parameter is an AIoT related protocol layer security parameter, the confidentiality key can be an AIoT related protocol layer confidentiality key, which can be represented as K AIoT-enc .
[0096] The confidentiality algorithm corresponding to the AIOT device is the confidentiality algorithm in the security parameter corresponding to the AIOT device. The confidentiality algorithm corresponding to the AIOT device can be an encryption algorithm (NEA), such as any one of NEA0, 128-NEA1, 128-NEA2, 128-NEA3, etc., which is not exhaustive here. For example, if the security parameter is a NAS security parameter, the confidentiality algorithm can be a NAS confidentiality algorithm. If the security parameter is an AIoT related protocol layer security parameter, the confidentiality algorithm can be an AIoT related protocol layer confidentiality algorithm.
[0097] Optionally, the second input parameter can further include at least one of the following: a second count value, a first bearer identifier, a downlink transmission direction, and a length of the downlink data (which can be represented as LENGTH). The second count value can be the same as the first count value, and the length of the second count value can be configured according to actual conditions, such as 32 bits.
[0098] For example, in combination with FIG. 6, the processing of the first ciphertext data by the first core network device can be that the confidentiality key, the second count value, the first bearer identifier, the downlink transmission direction, and the length of the downlink data are taken as the second input parameter, the second input parameter is calculated based on the confidentiality algorithm (represented as NEA in FIG. 6) corresponding to the AIOT device to obtain a first key stream, and the first key stream and the downlink data are calculated by XOR to obtain the first ciphertext data.
[0099] It should be understood that the above is only an exemplary description of encryption calculation, and all possible encryption calculation methods are not exhaustive here.
[0100] In an embodiment, the first core network device can perform integrity protection processing and encryption processing.
[0101] The first PDU carries a first check code for verifying the integrity, and the first check code is calculated based on an integrity parameter in the security parameter corresponding to the AIOT device and one of the following: the downlink data, the first ciphertext data, wherein the integrity parameter includes at least one of the following: an integrity key, an integrity algorithm. And the first PDU can carry the first ciphertext data.
[0102] In an example, the first core network device calculates the first cipher data first and then calculates the first check code. The first PDU carries the first cipher data, the first check code calculated based on the perfect protection parameter corresponding to the AIoT device and the first cipher data. The difference between calculating the first check code and the foregoing embodiment is that the downlink data in the first input parameter in the foregoing embodiment is replaced by the first cipher data, and other related descriptions are the same as those in the foregoing embodiment, and will not be repeated. The processing of calculating the first cipher data is the same as that in the foregoing example, and will not be repeated.
[0103] In an example, the first core network device calculates the first check code first and then calculates the first cipher data. The first PDU carries the first cipher data and the first check code calculated based on the downlink data and the perfect protection parameter corresponding to the AIoT device. The related description of calculating the first check code and the processing of calculating the first cipher data are the same as those in the foregoing embodiment, and will not be repeated.
[0104] The first core network device can determine whether to perform perfect protection and / or encryption on the content carried by the first PDU based on a preset rule. The preset rule can be configured according to actual conditions. For example, in the case where the downlink data carried by the first PDU is specifically an inventory message, only perfect protection can be performed without encryption. For example, in the case where the downlink data carried by the first PDU includes a write command and specific data to be written corresponding to the write command, perfect protection and encryption can be performed. The encryption can be performed only on the data to be written. The preset rule is not limited or exhausted here.
[0105] Optionally, the first PDU further carries at least one of the following: first indication information, the first indication information being used to indicate a perfect protection state and / or an encryption state of the first PDU; a first key set identifier (KSI, Key Set Identifier), the first KSI including at least one of the following: a key identifier of the perfect protection key used to calculate the first check code, a key identifier of the confidentiality key used to calculate the first cipher data.
[0106] The first indication information can also be referred to as a first Security head type (security head type) parameter. The position or bit position occupied by the first indication information in the first PDU is not limited in the embodiment. The perfect protection state can refer to whether perfect protection is performed or whether perfect protection is performed. The encryption state can refer to whether encryption is performed, or whether encryption is performed, or whether encryption is performed, or whether part of the data is encrypted.
[0107] For example, the first indication information can be used to indicate the integrity protection status of the first PDU (or the message in which the first PDU is located) by carrying corresponding parameters. For example, the first indication information carries an integrity protection parameter, which can be used to indicate that the integrity protection status of the first PDU (or the message in which the first PDU is located) is integrity protection processing. For example, the first indication information carries integrity protection and encryption parameters, which can be used to indicate that the integrity protection status of the first PDU (or the message in which the first PDU is located) is integrity protection processing, and the encryption status of the first PDU is encryption processing. For example, the first indication information carries an encryption parameter (or part of the encryption parameter), which can be used to indicate that the encryption status is encryption processing. For example, the first indication information carries integrity protection and part of the encryption parameter, which can be used to indicate that the integrity protection status of the first PDU (or the message in which the first PDU is located) is integrity protection processing, and the encryption status is part of the encryption processing.
[0108] For example, the first indication information can be indicated by a downlink status indication field. For example, the first indication information includes a first downlink status indication field used to indicate the integrity protection status of the first PDU. When the value of the first downlink status indication field is a first value, it can be used to indicate that the first PDU is not integrity protected, and when the value is a second value, it can be used to indicate that the first PDU is integrity protected. The first indication information also includes a second downlink status indication field used to indicate the encryption status of the first PDU. When the value of the second downlink status indication field is a third value, it is used to indicate that the first PDU is not encrypted, and when the value is a fourth value, it is used to indicate that the first PDU is encrypted. The first value, the second value, the third value, and the fourth value are all different from each other, and the above values are not limited or exhausted. The position and arrangement of the above two downlink status indication fields in the first indication information are not limited by the embodiment.
[0109] In the case where the first core network device performs integrity protection processing on the first PDU, the first KSI can include a key identifier of the integrity protection key used to calculate the first check code; and / or in the case where the first core network device performs encryption processing (or at least part of the encryption processing) on the downlink data carried in the first PDU, the first KSI can include a key identifier of the confidentiality key used to calculate the first cipher text data.
[0110] Optionally, the first PDU can also carry a first sequence number. The value of the first sequence number can be equal to the second count value and / or equal to the first count value.
[0111] The first sequence number can also be referred to as a first sequence number, which can be the least significant bits (LSB) of a COUNT, and the length of the first sequence number can be 8 bits. For example, in combination with Table 1, the contents of the COUNT can include, from the most significant bit to the least significant bit: 8 zeros, an overflow counter (16 bits), and the first sequence number (8 bits).
[0112] Table 1
[0113] For example, in combination with FIG. 7, the contents of the first PDU in the integrity-protected and encrypted state (i.e., the first NAS PDU) can include a first Security head type parameter, such as an integrity protection parameter, an integrity protection and encryption parameter, or an integrity protection and partial encryption parameter, to indicate the encryption and integrity protection state of the message for the AIoT device. For example, the DL data is an Inventory command, which can not need to be encrypted and only needs to be integrity protected, and thus the first Security head type parameter can be set to integrity protection only (or the integrity protection parameter). The first PDU can also include a first KSI, a first sequence number, first encrypted data, and a first check code.
[0114] In some possible implementations, the first core network device can send, to the first device, a third message carrying the first PDU after generating the first PDU.
[0115] The third message can be any one of the following types: a third paging message (i.e., a paging message sent by the first core network device to the first device), an N2 message, an N2-like message (such as other types of messages), or a newly defined message. This embodiment does not limit or exhaust all possible types of the third message.
[0116] Optionally, the third message can also carry at least one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs, and a time value.
[0117] The type of the identifier carried by the third message is determined based on the service request message. For example, if the service request message carries an identifier of the AIoT device, the third message also carries the identifier of the AIoT device, and vice versa, the third message carries an identifier of a group to which the AIoT device belongs.
[0118] The time value can be generated by the first core network device, and can be denoted as Time Value, which can also be alternatively referred to as a time value, etc.
[0119] Optionally, the third message can further carry at least one of the following: a target area, a first sequence number. It should be noted that if the first PDU carries the first sequence number, the first sequence number does not need to be carried in a position or field other than the first PDU in the third message; if the first PDU does not carry the first sequence number, the first sequence number can be carried in a position or field other than the first PDU in the third message.
[0120] The processing before the first core network device sends the third message to the first device can further include: selecting the first device based on the target area. Taking the first device as an access network device as an example, the access network device located in the target area can be selected based on one or more TACs (or TAIs) included in the target area. Taking the first device as a terminal as an example, a terminal capable of serving as an intermediate device or a proxy device or a relay device located in the target area can be selected based on one or more TACs (or TAIs) included in the target area.
[0121] In some possible implementation manners, the first device receives the third message from the first core network device, and sends the first message to the AIoT device. Correspondingly, the AIoT device receiving the first message can include: receiving the first message from the first device.
[0122] Optionally, in addition to carrying the first PDU, the first message further carries at least one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs, and a time value.
[0123] The content carried by the third message can be at least partially the same as the content carried by the first message. For example, the first message can be completely the same as the content contained in the third message; or the content carried by the first message can be a part of the third message, for example, the identifier of the AIoT device or the identifier of the group to which the AIoT device belongs can not be included, but other content of the third message is included.
[0124] In the case where the first device is an access network device, the first message can be sent through any one of an RRC (Radio Resource Control) message, or any one of a downlink AS (Access Stratum) message containing a message (or PDU), or any one of a newly defined downlink message. In the case where the first device is a terminal, the first message can be sent through any one of a sidelink message.
[0125] It should be understood that if the third message carries the identity of an AIoT device, the first message sent by the first device can be sent through a unicast message, i.e., a message sent for the AIoT device; if the third message carries the identity of the group to which the AIoT device belongs, the first message sent by the first device can be sent through a groupcast or broadcast message, i.e., the first device can broadcast or groupcast the first message to the group to which the AIoT device belongs.
[0126] After the AIoT device receives the first message, the AIoT device can perform integrity verification and / or decryption processing on the first message based on the security parameter corresponding to the AIoT device.
[0127] At the AIoT device side, the security parameter corresponding to the AIoT device can be saved locally on the AIoT device, such as the AIoT device also saving a security context, and the security context saving the security parameter corresponding to the AIoT device. The security parameter saved locally on the AIoT device should be the same as the security parameter corresponding to the AIoT device saved on the first core network device side.
[0128] It should be understood that if the identity carried by the first message is the identity of a group, the AIoT device and other AIoT devices in the group to which the AIoT device belongs can also perform the same processing as the AIoT device, and this embodiment will not be described in detail.
[0129] In an embodiment, in the case of only integrity processing at the first core network device side, the AIoT device only verifies the integrity.
[0130] The first PDU carries downlink data. Moreover, the first PDU carries a first check code used to verify the integrity, and at the AIoT device side, the method further includes: calculating a first verification code based on the integrity protection parameter in the security parameter corresponding to the AIoT device and the downlink data; verifying the integrity of the first message based on the first verification code and the first check code.
[0131] Specifically, the AIoT device can extract the first PDU from the first message, and in the case that the first PDU carries downlink data and a first check code, calculate a first verification code based on the integrity protection parameter in the security parameter corresponding to the AIoT device and the downlink data; verify the integrity of the first message based on the first verification code and the first check code.
[0132] The verifying the integrity of the first message based on the first verification code and the first check code can include at least one of the following: in a case where the first verification code and the first check code are the same, determining that the integrity verification of the first message is successful (or passed); in a case where the first verification code and the first check code are different, determining that the integrity verification of the first message fails (or not passed). Further, in a case where it is determined that the integrity verification of the first message is passed, the AIoT device can extract (or extract and save) the downlink data carried in the first PDU.
[0133] The AIoT device can calculate the first verification code by taking the downlink data and the perfect security key corresponding to the AIoT device as third input parameters, and calculating the third input parameters by using a perfect security algorithm corresponding to the AIoT device.
[0134] The first verification code can be represented as a first XMAC (Expected message authentication code). For example, the first XMAC can also be alternatively represented as a first XMAC-I, or a downlink XMAC-I, or a first X-MAC, or a downlink X-MAC, or an XMAC-I, or an X-MAC, and the like, which is not exhaustive.
[0135] The third input parameters can include the same content as the first input parameters in the foregoing embodiments, and the description is not repeated.
[0136] With reference to FIG. 8, the calculation of the first verification code is exemplarily described by taking the perfect security key as the NAS perfect security key. The NAS perfect security key, the downlink data, the first count value, the downlink transmission direction, and the first bearer identifier are taken as third input parameters, and the third input parameters are calculated based on a perfect security algorithm (such as NIA shown in FIG. 8) corresponding to the AIoT device to obtain the first verification code (such as XMAC-I / X-MAC shown in FIG. 8).
[0137] In an embodiment, in a case where only the encryption processing is performed at the first core network device side, the AIoT device only performs the decryption processing.
[0138] The first PDU carries first cipher data, and the method further includes, at the AIoT device side, decrypting the downlink data based on a confidentiality parameter in the security parameter corresponding to the AIoT device and the first cipher data, wherein the confidentiality parameter includes at least one of a confidentiality key and a confidentiality algorithm. Further, the processing at the AIoT device side can further include saving the downlink data in a case where the decryption of the first PDU is completed.
[0139] Specifically, the AIoT device can extract the first PDU from the first message, and when the first PDU carries the first ciphertext data, decrypt it based on the confidentiality parameters corresponding to the AIoT device and the first ciphertext data to obtain the downlink data.
[0140] The process of decrypting the first ciphertext data can be: using the confidentiality key corresponding to the AIoT device as the fourth input parameter, using the confidentiality algorithm corresponding to the AIoT device to calculate the first decryption key stream for the fourth input parameter, and calculating the downlink data based on the first decryption key stream and the first ciphertext data. The method of calculating the downlink data can be configured according to actual conditions, such as an XOR calculation. The first decryption key stream should be the same as the first key stream generated by the first core network device. The content that the fourth input parameter may contain is similar to the second input parameter in the aforementioned embodiment. The only difference is that the second input parameter contains the length of the downlink data, which is replaced by the length of the first ciphertext data in the fourth input parameter, and no repeated explanation is given.
[0141] In conjunction with Figure 9, taking the confidentiality key as the NAS confidentiality key as an example, the process of decrypting the first ciphertext data is exemplified: the NAS confidentiality key, the second count value, the first bearer identifier, the downlink transmission direction, and the length of the first ciphertext data are used as the fourth input parameter, and the first decryption key stream is calculated based on the confidentiality algorithm corresponding to the AIoT device (for example, NEA in Figure 9), and the first decryption key stream and the first ciphertext data are XORed to obtain the downlink data.
[0142] In one embodiment, when security processing and encryption processing are performed on the first core network device side, the AIoT device verifies the integrity and decrypts.
[0143] The first PDU carries a first verification code for verifying the integrity. The method further includes: calculating the first verification code based on a security parameter in the security parameters corresponding to the AIoT device and one of the following: the downlink data and the first ciphertext data, wherein the security parameter includes at least one of the following: a security key and a security algorithm; and verifying the integrity of the first message based on the first verification code and the first verification code. The first PDU carries the first ciphertext data.
[0144] In one example, the first core network device first calculates the first ciphertext data and then calculates the first check code. Accordingly, the AIoT device first calculates the first verification code based on the integrity parameter corresponding to the AIoT device and the first ciphertext data; if the integrity verification of the first message is successful based on the first verification code and the first check code, the downlink data is decrypted based on the confidentiality parameter corresponding to the AIoT device and the first ciphertext data.
[0145] The difference between the first verification code calculation in the present example and the foregoing embodiment is only that the downlink data in the third input parameter is replaced by the first ciphertext data, and other relevant descriptions are the same as those in the foregoing embodiment, and thus are not described herein again. The process of decrypting the first ciphertext data is the same as that in the foregoing example, and thus is not described herein again.
[0146] In an example, the first core network device calculates the first check code before calculating the first ciphertext data. Correspondingly, the AIoT device first decrypts the downlink data based on the confidentiality parameter corresponding to the AIoT device and the first ciphertext data; then calculates the first verification code based on the integrity parameter corresponding to the AIoT device and the downlink data; and verifies the integrity of the first message based on the first verification code and the first check code. The relevant description of calculating the first verification code in the present example and the process of decrypting the first ciphertext data are the same as those in the foregoing example, and thus are not described herein again.
[0147] Optionally, in the case where the first PDU carries the first indication information, the process of the AIoT device can further include: in the case where it is determined based on the first indication information that the first PDU is for integrity protection, the process of verifying the integrity of the first message can be performed; and / or in the case where it is determined based on the first indication information that the first PDU is for encryption, the first PDU can be decrypted.
[0148] Optionally, in the case where the first PDU carries the first KSI, the process of the AIoT device can further include: extracting the key identifier of the integrity key used for calculating the first check code from the second KSI, and determining the integrity key to be used this time based on the key identifier of the integrity key; and / or extracting the key identifier of the confidentiality key used for calculating the first ciphertext data from the first KSI, and determining the confidentiality key to be used this time based on the key identifier of the confidentiality key.
[0149] Optionally, the first PDU can further carry a first sequence number. The AIoT device can take the value of the first sequence number as the second count value, and / or take the value of the first sequence number as the first count value.
[0150] The first message can be sent in one of the following ways: a first paging message, msg2 in a random access procedure, and msg4 in a random access procedure.
[0151] For example, the first message is sent through the first paging message, which can refer to that the first message is at least included in the first paging message, i.e., the first message can be at least part of the content (all or part of the content) of the first paging message. For example, the first paging message only carries the first message, and in this case, the first message can be considered as the first paging message. For another example, the first paging message carries the first message and can carry other content in addition to the first message, and the other content that the first paging message can carry is not limited here.
[0152] The related description of the first message sent through msg2 or msg4 is similar to the description of the first message sent through the first paging message, and is not repeated.
[0153] In some embodiments, the first message can be sent through the first paging message.
[0154] The first device receives the third message from the first core network device, and sends the first message to the AIoT device, which can be that the first device receives the third message from the first core network device, generates the first paging message based on the third message, and sends the first paging message to the AIoT device. Correspondingly, the AIoT device receives the first paging message (at least including the first message) from the first device.
[0155] For example, the first device can be an access network device, and the first message can refer to the first paging message sent by the access network device to the AIoT device. For example, the first device can be a terminal, and the first message can refer to the first paging message sent by the terminal to the AIoT device through the sidelink (or sidelink channel).
[0156] The content carried by the first message can be the same as the content included in the third message.
[0157] After the AIoT device receives the first paging message, the processing can include: in the case that the first paging message carries the identifier of the AIoT device or the identifier of the group in which the AIoT device is located, performing integrity verification and / or decryption processing based on the security parameter pair corresponding to the AIoT device. Specifically, it can include that the AIoT device extracts the identifier carried in the first paging message, judges whether the identifier matches the identifier of the AIoT device itself or the identifier of the group in which the AIoT device is located, and if it matches, performs integrity verification and / or decryption processing on the first paging message based on the security parameter pair corresponding to the AIoT device.
[0158] The AIoT device can also determine the order of matching the identity carried in the first paging message with the identity of the AIoT device itself or the identity of the group in which the AIoT device is located. For example, the AIoT device can first determine whether the identity carried in the first message matches the identity of the AIoT device itself, and if not, then determine whether the identity matches the identity of the group in which the AIoT device is located. This example does not limit or exhaust the order of determination.
[0159] The processing on the AIoT device side can also include ending the processing if the identity carried in the first paging message does not match the identity of the AIoT device or the identity of the group in which the AIoT device is located.
[0160] In some embodiments, the first message is sent in one of msg2 in a random access procedure and msg4 in a random access procedure.
[0161] The processing of the first device further includes sending a second paging message to the AIoT device, where the second paging message carries one of the identity of the AIoT device and the identity of the group in which the AIoT device is located, and receiving msg1 in a random access procedure from the AIoT device. Correspondingly, the processing of the AIoT device can include receiving a second paging message from the first device, where the second paging message carries one of the identity of the AIoT device and the identity of the group in which the AIoT device is located, and sending msg1 in a random access procedure to the first device.
[0162] In this embodiment, the first message is sent in msg2 or msg4, that is, the content carried in msg2 or msg4 includes at least the first message, or the first message can be at least part of the content (all or part of the content) of msg2 or msg4.
[0163] In one example, the first message is sent in msg2 in a random access procedure.
[0164] The first device receives a third message from the first core network device, sends the first message to the AIoT device, specifically can be: the first device receives a third message from the first core network device, stores the content carried by the third message; Extract the identifier of the AIoT device or the identifier of the group where the AIoT device is located in the third message to generate a second paging message, and send the second paging message to the AIoT device; Receive msg1 in the random access process from the AIoT device; Extract the first PDU in the third message to generate msg2 in the random access process, and send msg2 to the AIoT device. Correspondingly, the processing of the AIoT device can include: receiving a second paging message from the first device; Send msg1 in the random access process to the first device; Receive msg2 in the random access process from the first device.
[0165] The AIoT device receives a second paging message from the first device, and sends msg1 in the random access process to the first device, which can include: in the case of carrying the identifier of the AIoT device or the identifier of the group where the AIoT device is located in the second paging message, send msg1 in the random access process to the first device. Specifically, the AIoT device can extract the identifier carried in the second paging message, judge whether the identifier matches the identifier of the AIoT device itself or the identifier of the group where the AIoT device itself is located, and if it matches the identifier of the AIoT device itself or the identifier of the group where the AIoT device itself is located, send msg1 in the random access process to the first device.
[0166] Wherein, in the case of carrying the identifier of the AIoT device in the third message, the second paging message can carry the identifier of the AIoT device; in the case of carrying the identifier of the group where the AIoT device is located in the third message, the second paging message can carry the identifier of the group where the AIoT device is located.
[0167] The AIoT device can also have a sequence for the judgment processing, and the related description is the same as the foregoing embodiments, which will not be repeated.
[0168] The msg1 can carry the preamble (Preamble) selected by the AIoT device, such as AIoT service or business dedicated preamble, etc., which is not limited here. The function of the msg1 is to initiate the random access process.
[0169] Optionally, the first device can add all the content carried by the third message to the first message, which is carried or contained by msg2. Optionally, the first device can add the content in the third message other than the identity of the AIoT device and the identity of the group where the AIoT device is located to the first message, which is carried or contained by msg2. For example, the first message can carry: the first PDU, the time value, the first sequence number, and the like. This is because the identity of the AIoT device or the identity of the group where the AIoT device is located carried in the third message has been extracted and sent in the second paging message, and therefore the first message can no longer carry the related content of the identity.
[0170] In an example, the first message is sent through msg4 in the random access procedure.
[0171] The first device receives the third message from the first core network device, and sends the first message to the AIoT device. Specifically, the first device can receive the third message from the first core network device, extract the identity of the AIoT device or the identity of the group where the AIoT device is located carried in the third message to generate a second paging message, and send the second paging message to the AIoT device. The first device can receive msg1 in the random access procedure from the AIoT device, send msg2 in the random access procedure to the AIoT device, and in the case of receiving msg3 in the random access procedure from the AIoT device, extract the first PDU in the third message to generate msg4 in the random access procedure, and send msg4 to the AIoT device. Correspondingly, the processing of the AIoT device can include: receiving the second paging message from the first device, sending msg1 in the random access procedure to the first device, receiving msg2 in the random access procedure from the first device, sending msg3 in the random access procedure to the first device, and receiving msg4 in the random access procedure from the first device.
[0172] The second paging message is described above, and the first device and the AIoT device process the second paging message in the same way as the above examples, which is not described again. The msg1 is also described above, and the first device and the AIoT device process the msg1 in the same way as the above examples, which is not described again.
[0173] In this example, the msg2 and msg3 can carry the content of the protocol rule. The first message carried or contained by msg4 can contain the content of the first PDU. Optionally, the first device can add all the content carried by the third message to the first message, which is carried or contained by msg4. Optionally, the first device can add the first PDU to the first message, and also add at least one of the following carried by the third message to the first message: the time value, the first sequence number, and the like. Finally, the first message is carried or contained by msg4.
[0174] In some possible implementation manners, the first core network device sends, after generating the first PDU, a first message carrying the first PDU to the AIoT device. Correspondingly, on the AIoT device side, the receiving the first message includes receiving the first message from the first core network device.
[0175] Preferably, the first message can be sent through a downlink NAS message. For example, in the case that the security parameter is a NAS security parameter and the PDU is a NAS PDU, the first message can be sent through a downlink NAS message sent by the first core network device to the AIoT device.
[0176] Alternatively, the first message can be sent through a downlink message of another protocol layer, such as a downlink message of an AIoT-related protocol layer. For example, in the case that the security parameter is an AIoT-related protocol layer security parameter and the PDU is an AIoT-related protocol layer PDU, the first message can be sent through a downlink message of an AIoT-related protocol layer sent by the first core network device to the AIoT device.
[0177] The first message is sent through a downlink NAS message, that is, the content carried by the downlink NAS message at least includes the first message, or the first message can be at least part of the content (all or part of the content) of the downlink NAS message. The first message can be sent through a downlink message of another protocol layer, which is similar to the description of the first message sent through the downlink NAS message, and will not be repeated here.
[0178] The processing of the first core network device before sending the first message can further include sending a fourth paging message to the first device, the fourth paging message carrying one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs. Correspondingly, the processing of the first device can further include receiving the fourth paging message from the first core network device, and sending a second paging message to the AIoT device. The processing of the AIoT device before receiving the first message can further include receiving the second paging message from the first device. The content carried by the fourth paging message and the content carried by the second paging message should be the same.
[0179] After the AIoT device determines that the second paging message carries the identity of the AIoT device or the identity of the group to which the AIoT device belongs, the processing between the AIoT device, the first device, and the first core network device can further include that the AIoT device establishes a complete radio bearer (RB) with the first device, and the first device establishes an N2 connection with the first core network device. The N2 connection can be an N2 connection corresponding to the AIoT device, or an N2 connection corresponding to the RB of the AIoT device. Specifically, the AIoT device can initiate and complete a random access process with the network side, and through the completion of the random access process, the AIoT device establishes a complete RB with the first device, and the first device establishes an N2 connection with the first core network device.
[0180] The first core network device can directly send a first message to the AIoT device after the AIoT device establishes a complete RB with the first device, and the first device establishes an N2 connection with the first core network device. The first message can carry the same content as the previous embodiments, and is not repeated. The processing of the AIoT device after receiving the first message is the same as the previous embodiments, and is not repeated.
[0181] In some possible implementations, the first core network device can not perform integrity protection and encryption.
[0182] In this case, the first PDU can include downlink data; the first PDU can include first indication information, such as indicating that the first PDU is not integrity protected and encrypted; the first KSI in the first PDU can be empty or can not carry the first KSI; the first PDU can not carry or carry the first sequence number.
[0183] In addition to the first PDU being different from the previous embodiments, the related descriptions of the messages transmitted between the first core network device, the first device, and the AIoT device are the same as those in the previous embodiments, and are not repeated. The processing of the AIoT device after receiving the first message is similar to the previous embodiments, and the difference is that the integrity check and decryption processing are no longer performed, and therefore the description is not repeated.
[0184] Compared with the existing EDT (Early Data Transmission) CP solution in which downlink data is transmitted in the RRC EarlyDataComplete (RRC early data complete) (i.e., msg4, downlink) message for the first time, in the present implementation, since the first message can be sent through the first paging message or msg2, the AIoT device can receive downlink data in advance, thereby reducing signaling overhead, and thus being more suitable for AIoT devices with lower capability and power consumption.
[0185] In some possible implementation, the processing performed by the AIoT device further includes: sending a second message, where the second message carries a second PDU that is processed based on the security parameter corresponding to the AIoT device, and the second PDU is used to determine the uplink data.
[0186] The second PDU can be an uplink PDU that is processed based on the security parameter corresponding to the AIoT device. The second PDU being used to determine the uplink data can mean that the second PDU is used by the first core network device to determine or obtain the uplink data.
[0187] Optionally, the AIoT device can generate uplink data (UL data, Uplink Data) after obtaining the downlink data, where the uplink data can be DO-DTT data, and the uplink data includes feedback content of the AIoT device in response to a command included in the received downlink data. Specifically, the uplink data can include one of the following: an identifier of the AIoT device, data content read by the AIoT device, and an execution result of writing data by the AIoT device. The identifier of the AIoT device can be feedback content of the AIoT device in response to an inventory message included in the downlink data. The data content read by the AIoT device can be feedback data content (for example, can include sensing data, etc.) of the AIoT device in response to a read command included in the downlink data. The execution result of writing data by the AIoT device can be an execution result (for example, writing completion or writing failure, etc.) of the AIoT device in response to a write command included in the downlink data. In this case, the AIoT device can obtain the downlink data in the same manner as any one of the foregoing possible embodiments, and no repeated description is given.
[0188] Optionally, the uplink data can also be data actively reported by the AIoT device, for example, the AIoT device can periodically read data in the memory and actively report, and the period can be preconfigured. Here, the triggering manner of the AIoT device actively reporting data is not limited.
[0189] In an embodiment, the AIoT device can only perform integrity protection processing.
[0190] The second PDU carries a second check code used to verify integrity, where the second check code is calculated based on an integrity parameter in the security parameter corresponding to the AIoT device and the uplink data. In addition, the second PDU can also carry the uplink data.
[0191] The processing of the AIoT device to calculate the second check code can be: taking the integrity key corresponding to the AIoT device and the uplink data as a fifth input parameter, and calculating the second check code by using an integrity algorithm corresponding to the AIoT device on the fifth input parameter.
[0192] The second check code can be a second MAC. Exemplarily, the second MAC can also be alternatively represented as MAC-I (or second MAC-I, or uplink MAC-I) or -MAC (or second -MAC, or uplink -MAC), and the like, which are not exhaustive.
[0193] The fifth input parameter can include at least one of the following in addition to the AIoT device corresponding complete security key and the uplink data: a third count value, a second bearer identifier, and an uplink transmission direction.
[0194] The third count value can be represented as COUNT 3 or a third COUNT, and the generation manner of the third count value is not limited in the embodiment. The length of the third count value can be configured according to actual conditions, for example, can be 32-bit.
[0195] The second bearer identifier can be an identifier of a bearer used for sending the uplink message. For example, the second bearer identifier can be represented as BEARER (bearer) ID 2, or simply represented as BEARER. The length of the second bearer identifier can be configured according to actual conditions, for example, can be 5-bit. The second bearer identifier can be the same as the first bearer identifier.
[0196] The length of the uplink transmission direction can be configured according to actual conditions, for example, can be 1-bit. The value of the uplink transmission direction can be configured according to actual conditions, for example, can be 0.
[0197] In an embodiment, the AIoT device can only perform encryption processing. The second PDU carries second ciphertext data, wherein the second ciphertext data is calculated based on a confidentiality parameter in the security parameter corresponding to the AIoT device and the uplink data.
[0198] The processing of calculating the second ciphertext data by the AIoT device can be: taking the confidentiality key corresponding to the AIoT device as a sixth input parameter, calculating a second key stream by using a confidentiality algorithm corresponding to the AIoT device on the sixth input parameter, and calculating the second ciphertext data based on the second key stream and the uplink data. The calculation manner of the second ciphertext data is exclusive or calculation.
[0199] The sixth input parameter can include at least one of the following in addition to the confidentiality key corresponding to the AIoT device: a fourth count value, a second bearer identifier, an uplink transmission direction, and a length of the uplink data. The fourth count value can be the same as the third count value.
[0200] In an embodiment, the AIoT device can perform integrity processing and encryption processing.
[0201] The second PDU carries a second check code for verifying integrity, wherein the second check code is calculated based on the integrity protection parameter in the security parameter corresponding to the AIoT device and one of the uplink data and the second ciphertext data. The second PDU can carry the second ciphertext data.
[0202] In an example, the AIoT device calculates the second ciphertext data first and then calculates the second check code. The second PDU specifically carries the second ciphertext data and the second check code calculated based on the integrity protection parameter in the security parameter corresponding to the AIoT device and the second ciphertext data. In this example, the difference between calculating the second check code and the foregoing embodiments is that the uplink data in the fifth input parameter is replaced by the second ciphertext data, and other related descriptions are the same as those in the foregoing embodiments and will not be repeated. The process of calculating the second ciphertext data is the same as that in the foregoing example and will not be repeated.
[0203] In an example, the AIoT device calculates the second check code first and then calculates the second ciphertext data. The second PDU specifically carries the second ciphertext data and the second check code calculated based on the integrity protection parameter in the security parameter corresponding to the AIoT device and the uplink data. The related description of calculating the second check code and the process of calculating the second ciphertext data are the same as those in the foregoing embodiments and will not be repeated.
[0204] Optionally, the second PDU further carries at least one of the following: second indication information, the second indication information being used to indicate the integrity protection state and / or the encryption state of the second PDU; and a second KSI, the second KSI including at least one of the following: a key identifier of the integrity protection key used to calculate the second check code, and a key identifier of the confidentiality key used to calculate the second ciphertext data.
[0205] The second indication information can also be referred to as a second Security head type parameter. The position or bit position of the second indication information in the second PDU is not limited in this embodiment. The specific indication manner of the second indication information is similar to that of the first indication information and will not be repeated.
[0206] The related description of the second KSI is also similar to that of the first KSI and will not be repeated.
[0207] Optionally, the second PDU can further carry a second sequence number. The value of the second sequence number can be equal to the third count value and / or can be equal to the fourth count value. The second sequence number is the same as or different from the first sequence number, and both are within the protection scope of this embodiment.
[0208] The composition structure of the second PDU is similar to that of the first PDU and will not be repeated.
[0209] In some embodiments, the second message can carry at least one of the following in addition to the second PDU: the second sequence number, the identity of the AIoT device.
[0210] It should be noted that if the second PDU carries the second sequence number, the second sequence number does not need to be carried in a position or field in the second message other than the second PDU; if the second PDU does not carry the second sequence number, the second sequence number can be carried in a position or field in the second message other than the second PDU.
[0211] Preferably, the identity of the AIoT device carried by the second message can be a temporary identity of the AIoT device.
[0212] In some embodiments, the AIoT device can perform the processing of sending the second message after receiving the first message.
[0213] At the AIoT device side, sending the second message can include sending the second message within a message transmission period, wherein the message transmission period is determined based on the time value carried in the first message.
[0214] In this embodiment, the first message received by the AIoT device carries a time value. Since the AIoT service does not have ARQ and HARQ mechanisms, a time value can be introduced to function as a timestamp to resist denial-of-service caused by replay attacks. The message transmission period can also be referred to as an uplink message transmission period. The AIoT device can determine the message transmission period in the following manner: taking the time value as a starting time, adding an effective duration to the starting time to obtain an ending time, and taking the period between the starting time and the ending time as the message transmission period. The effective duration can also be carried in the first message at the same time as the time value; or the effective duration can be preset, default, or specified by a protocol at the AIoT device.
[0215] At the AIoT device side, the sending of the second message can include one of the following: sending the second message to the first device; sending the second message to the first core network device.
[0216] If the second message is sent to the first device, in the case where the first device is an access network device, the second message can be sent through any one of the following: an RRC message, an uplink AS message containing a message (or PDU), or a newly defined uplink message; in the case where the first device is a terminal, the second message can be sent through any one of the following: a sidelink message.
[0217] In some embodiments, the AIoT device sends a second message to the first device. Correspondingly, the processing of the first device can further include: receiving the second message from the AIoT device, wherein the second message carries a second PDU that is processed based on the security parameter, and the second PDU is used to determine the uplink data; and sending a fourth message to the first core network device, wherein the fourth message carries the second PDU. The processing of the first core network device can further include: receiving the fourth message from the first device, wherein the fourth message carries the second PDU that is processed based on the security parameter, and the second PDU is used to determine the uplink data.
[0218] The fourth message can carry the same content as the second message, and no repeated description is given. The fourth message can be sent through an N2 message or a newly defined message. This embodiment does not limit or exhaust all possible sending modes of the fourth message.
[0219] After the first core network device receives the fourth message, the processing can include: in the case where the fourth message carries the identifier of the AIoT device, performing integrity verification and / or decryption processing based on the security parameter corresponding to the AIoT device. For example, in the case where the identifier carried in the fourth message is the temporary identifier of the AIoT device, the first core network device extracts the identifier carried in the fourth message, and in the case where the identifier matches the temporary identifier of the AIoT device, performs integrity verification and / or decryption processing based on the security parameter corresponding to the AIoT device. In addition, the processing can further include: in the case where the identifier carried in the fourth message does not match the temporary identifier of the AIoT device, ending the processing.
[0220] In one embodiment, the first core network device only verifies the integrity in the case where the AIoT device only performs the integrity protection processing.
[0221] The second PDU carries a second check code used to verify the integrity, and the method further includes: calculating a second verification code based on the integrity protection parameter in the security parameter corresponding to the AIoT device and the uplink data; and verifying the integrity of the fourth message based on the second verification code and the second check code. In addition, the second PDU further carries the uplink data.
[0222] Specifically, the first core network device can extract the second PDU from the fourth message, and in a case where the second PDU carries uplink data and a second check code, calculate a second verification code based on the integrity protection parameter corresponding to the AIoT device and the uplink data; and verify the integrity of the fourth message based on the second verification code and the second check code. Wherein, verifying the integrity of the fourth message based on the second verification code and the second check code can include: in a case where the second verification code and the second check code are the same, determining that the integrity verification of the fourth message is successful; and / or in a case where the second verification code and the second check code are different, determining that the integrity verification of the fourth message fails. Further, in a case where it is determined that the integrity verification of the fourth message is passed, the uplink data carried in the second PDU can be extracted (or obtained).
[0223] The specific process of calculating the second verification code can be: taking the integrity protection key corresponding to the AIoT device and the uplink data as the seventh input parameter, and calculating the second verification code by using the integrity protection algorithm corresponding to the AIoT device on the seventh input parameter. The second verification code can be a second XMAC, and various possible representations of the second verification code are similar to the first verification code, which will not be repeated here. The seventh input parameter can include the same content as the fifth input parameter in the foregoing embodiments, and will not be repeated. The specific process of calculating the second verification code by the first core network device is similar to the description of calculating the first verification code in the foregoing embodiments, and will not be repeated.
[0224] In an embodiment, in a case where only encryption processing is performed at the AIoT device side, the first core network device only performs decryption processing.
[0225] The second PDU carries second ciphertext data, and the method further includes: decrypting the uplink data based on the confidentiality parameter in the security parameter corresponding to the AIoT device and the second ciphertext data.
[0226] Specifically, the first core network device can extract the second PDU from the fourth message, and in a case where the second PDU carries second ciphertext data, decrypt the uplink data based on the confidentiality parameter corresponding to the AIoT device and the second ciphertext data.
[0227] The processing of decrypting the second ciphertext data can be: taking the confidentiality key corresponding to the AIoT device as an eighth input parameter, calculating a second decryption key stream by using the confidentiality algorithm corresponding to the AIoT device on the eighth input parameter, and calculating the uplink data based on the second decryption key stream and the second ciphertext data. The eighth input parameter should be the same as the content contained in the sixth input parameter, the only difference being that the length of the uplink data is contained in the sixth input parameter, and the length of the second ciphertext data is replaced in the eighth input parameter. The other parameters are the same as the sixth input parameter, and are not repeated. The specific example of the first core network device decrypting the second ciphertext data is similar to the description of decrypting the first ciphertext data in the foregoing embodiments, and is not repeated.
[0228] In an embodiment, the first core network device verifies the integrity and decrypts the second ciphertext data in the case that the AIoT device has performed the integrity protection processing and the encryption processing.
[0229] The second PDU carries a second check code for verifying the integrity, and the method further includes: calculating a second verification code based on the integrity protection parameter in the security parameter corresponding to the AIoT device and one of the uplink data and the second ciphertext data; and verifying the integrity of the fourth message based on the second verification code and the second check code. The second PDU carries the second ciphertext data.
[0230] In an example, the AIoT device calculates the second ciphertext data first and then calculates the second check code. Correspondingly, the first core network device calculates the second verification code based on the integrity protection parameter corresponding to the AIoT device and the second ciphertext data first; and in the case that the integrity verification of the fourth message is successful based on the second verification code and the second check code, the uplink data is decrypted based on the confidentiality parameter corresponding to the AIoT device and the second ciphertext data. In this example, the difference between the related description of calculating the second verification code and the foregoing embodiments is that the downlink data in the seventh input parameter is replaced by the second ciphertext data, and the other related descriptions are the same as the foregoing embodiments, and thus are not repeated. The processing of decrypting the second ciphertext data is the same as the foregoing example, and thus is not repeated.
[0231] In an example, the AIoT device calculates the second check code first and then calculates the second ciphertext data. Correspondingly, the first core network device decrypts the uplink data based on the confidentiality parameter corresponding to the AIoT device and the second ciphertext data first; then calculates the second verification code based on the integrity protection parameter corresponding to the AIoT device and the uplink data; and verifies the integrity of the fourth message based on the second verification code and the second check code. The related description of calculating the second verification code and the processing of decrypting the second ciphertext data are the same as the foregoing example, and thus are not repeated.
[0232] Further, the first core network device, in a case that the integrity verification is passed and the decryption is completed, saves the uplink data.
[0233] Optionally, in a case that the second PDU carries the second indication information, the processing of the first core network device can include: in a case that it is determined based on the second indication information that the second PDU is integrity protected, the processing of verifying the integrity can be performed; and / or in a case that it is determined based on the second indication information that the second PDU is encrypted, the processing of decryption can be performed.
[0234] Optionally, in a case that the second PDU carries the second KSI, the processing of the first core network device can include: extracting, from the second KSI, a key identifier of the integrity protection key used for calculating the second check code, and determining the integrity protection key based on the key identifier; and / or extracting, from the second KSI, a key identifier of the confidentiality key used for calculating the second cipher text data, and determining the confidentiality key based on the key identifier.
[0235] Optionally, the second PDU can further carry a second sequence number. The first core network device can take a value of the second sequence number as the fourth count value, and / or the first core network device can further take the value of the second sequence number as the third count value.
[0236] In some embodiments, the second message can be sent to the first device. The second message can be sent through msg3 in the random access procedure.
[0237] The second message can be sent through msg3 in the random access procedure, that is, the content carried by msg3 at least includes the second message, or the second message can be at least part of the content of msg3.
[0238] Optionally, the first message is sent through the first paging message, and the second message is sent through msg3. The message transmission process of the AIoT device can be: receiving the first paging message (carrying or including the first message), sending msg1 to the first device; in a case that msg2 sent by the first device is received, sending msg3 (carrying or including the second message) to the first device. Correspondingly, the message transmission process of the first device can include: sending the first paging message to the AIoT device; in a case that msg1 from the AIoT device is received, sending msg2 to the AIoT device; and receiving msg3 sent by the AIoT device.
[0239] Optionally, the first message can be msg2, and the second message can be sent through msg3. The message transmission procedure of the AIoT device can include: receiving a second paging message from the first device, wherein the second paging message carries one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs; sending msg1 in a random access procedure to the first device; and in a case where msg2 (carrying or including the first message) sent by the first device is received, sending msg3 (carrying or including the second message) to the first device. Correspondingly, the processing of the first device for receiving and sending messages can include: sending a second paging message to the AIoT device; in a case where msg1 sent by the AIoT device is received, sending msg2 to the AIoT device; and receiving msg3 sent by the AIoT device.
[0240] In some possible embodiments, the first message is sent through a first paging message, and the second message can be sent to the first device, and the second message can be sent through msg1. The message transmission procedure of the AIoT device can include: receiving the first paging message (carrying or including the first message), and sending msg1 (carrying or including the second message) to the first device. Correspondingly, the processing of the first device for receiving and sending messages can include: sending a first paging message to the AIoT device; and receiving msg1 sent by the AIoT device.
[0241] In some embodiments, the AIoT device sending the second message can be sending the second message to the first core network device.
[0242] Preferably, the second message can be sent through an uplink NAS message. For example, in the case where the aforementioned security parameter is a NAS security parameter and the PDU is a NAS PDU, the second message can be an uplink NAS message sent by the AIoT device to the first core network device. The second message can be sent through an uplink NAS message, that is, the content carried by the uplink NAS message at least includes the second message, or the second message can be at least part of the content of the uplink NAS message.
[0243] Optionally, the second message can also be an uplink message of another protocol layer, such as an uplink message of an AIoT-related protocol layer. For example, in the case where the aforementioned security parameter is an AIoT-related protocol layer security parameter and the PDU is an AIoT-related protocol layer PDU, the second message can be an uplink message of an AIoT-related protocol layer sent by the AIoT device to the first core network device. The related description of the second message as an uplink message of another protocol layer is similar to the description of the second message being sent through an uplink NAS message, and is not repeated here.
[0244] The AIoT device can first receive the first message and then send the second message. The first message can be sent by any one of the first paging message, msg2, msg4, or a downlink message (a downlink NAS message or a downlink message of an AIoT-related protocol layer).
[0245] Before the AIoT device sends the second message, the AIoT device establishes a complete RB with the first device, and the first device establishes an N2 connection with the first core network device. The related descriptions about the establishment of the complete RB and the establishment of the N2 connection are the same as those in the foregoing embodiments, and are not described herein again. The processing of the first core network device after receiving the second message is similar to the processing of the first core network device after receiving the fourth message in the foregoing embodiments, and the difference is that the first core network device can verify the integrity of the second message by verifying the second check code. Other related processing is not described herein again.
[0246] In some possible implementation manners, after obtaining the uplink data of the AIoT device, the first core network device can further perform processing, which can include: sending the uplink data of the AIoT device. Optionally, the sending of the uplink data of the AIoT device can include: sending the uplink data of the AIoT device to the AF through the NEF; or directly sending the uplink data of the AIoT device to the AF.
[0247] In some possible implementation manners, the AIoT device can not perform integrity protection and encryption.
[0248] In this case, the second PDU can contain uplink data (such as plaintext uplink data); the second indication information in the second PDU can be used to indicate that the integrity protection and encryption are not performed; the second KSI in the second PDU can be empty or not carried; and the second PDU can not carry or carry a second sequence number.
[0249] The related descriptions of the messages transmitted between the first core network device, the first device, and the AIoT device are the same as those in the foregoing embodiments, and are not described herein again. The processing of the first core network device is similar to that in the foregoing embodiments, and the difference is that the integrity protection verification and decryption processing are no longer performed, and thus are not described herein again. The present implementation manner can be combined with the related embodiments of the first PDU sent in the foregoing encryption and / or integrity protection, for example, in the case where the downlink performs integrity protection and / or encryption processing, the uplink can not perform integrity protection and encryption.
[0250] The communication method provided by the present application is described in combination with various embodiments, taking the security parameter as the NAS security parameter, the security context as the NAS security context, and the PDU as the NAS PDU as an example.
[0251] Embodiment 1: In combination with FIG. 10, the downlink data is sent in the paging message for the first time, and specifically includes:
[0252] Step 1000: Assuming that the AIoT device and the network (including the AMF or AIoT NF, hereinafter the AMF is taken as an example for brevity) have completed registration and established a NAS security context.
[0253] It should be noted that the AIoT device can return to the CM-IDLE (Connection Management-Idle) mode due to inactivity or energy depletion, etc.; the AIoT device corresponding to the AS security context does not need to be established.
[0254] Step 1001: The AF sends an AIoT service request message to the NEF, which contains but is not limited to: AIoT ID, AF ID, service type (Inventory / Command), and optionally, the message can also include at least one of the following: downlink data (such as can include write command or inventory command, etc.), target area of operation, etc. Optionally, the AIoT ID can be a temporary ID of the AIoT device; optionally, the AIoT ID can also be replaced by the ID of the group to which the AIoT device belongs.
[0255] Step 1002: The NEF checks whether the AF is authorized to request the AIoT service through the UDM, and if the AF is authorized, the NEF discovers the AMF using the information in the AIoT service request message, for example, discovers the AMF (i.e., the first core network device) from the NRF using the target area of operation. If the target area of operation matches the AIoT service area of the AMF, the NRF returns the information of the AMF to the NEF.
[0256] Step 1003: The NEF forwards the AIoT service request message to the selected AMF.
[0257] Step 1004: The AMF selects the RAN (i.e., the first device) according to the target area (such as the TA list); then the AMF performs partial encryption processing (only encrypts the container containing the downlink data, and does not encrypt the plaintext) on the write command or inventory command in the AIoT service request message using the NAS security context (such as K NASenc , NAS encryption algorithm) to obtain first ciphertext data, and calculates a first check code for integrity protection (such as can use K NASint ).
[0258] The encryption algorithm and the related description of the specific encryption processing, and the calculation method of the first check code are the same as those in the foregoing embodiments, and will not be described again. After the first ciphertext data and the first check code are calculated, an encrypted NAS PDU (i.e., the first NAS PDU) can be generated. The composition of the encrypted NAS PDU is the same as that in the foregoing embodiments, and will not be described again.
[0259] It is noted that if the AMF does not store the AIoT corresponding NAS security context, the authentication and security establishment procedure can be triggered first, and then the foregoing steps are performed.
[0260] Step 1005: The AMF sends a Paging message (i.e., the third Paging message in the foregoing embodiment) to the RAN.
[0261] Step 1006: The RAN forwards the Paging message (i.e., the first Paging message in the foregoing embodiment) to the AIoT device through the air interface.
[0262] The Paging message sent by the AMF in step 1005 and the Paging message carried by the RAN through the air interface in step 1006 can be the same, and can include, for example, the AIoT ID, the encrypted NAS-PDU (simplified as [NAS-PDU] in FIG. 10), the time value, and optionally, at least one of the LSB of NAS count (i.e., the first NAS sequence number) and the target area.
[0263] Alternatively, the Paging message in step 1005 can also be a message similar to N2 (e.g., a NAS message) or a newly defined message, and the Paging message in step 1006 can also be an AS message (e.g., an AS message containing a NAS message) or a newly defined message.
[0264] Step 1007: The AIoT device checks the AIoT ID in the Paging message, and if the ID matches, the AIoT device uses the NAS confidentiality key K NASint calculates the first verification code, performs integrity verification on the Paging message based on the first verification code and the first check code, and after the verification is passed, uses the NAS confidentiality key K NASenc decrypts the NAS-PDU to obtain the downlink data DL data sent by the AF or the Command in the downlink data, wherein the decryption process uses the NAS sequence number as the COUNT.
[0265] Step 1008: The AIoT device selects a random access preamble (i.e., msg1) and initiates a random access procedure to the RAN.
[0266] Step 1009: The RAN returns a random access response (i.e., msg2).
[0267] Optionally, steps 1010-1012 can also be performed, as follows:
[0268] Step 1010: If the AF needs the AIOT device to feedback ACK, the AIoT device sends the ACK to the RAN through an AS message.
[0269] Step 1011: The RAN sends the ACK to the AMF through an N2 message.
[0270] Step 1012: The AMF forwards the AIoT service response carrying the ACK to the AF through an NEF.
[0271] The AS message of step 1010 and the N2 message of step 1011 above can be replaced by other newly defined messages.
[0272] Embodiment 2: In combination with FIG. 11, the downlink data is sent earliest in msg2 of the RA procedure, specifically including:
[0273] Steps 1100-1105 are the same as steps 1000-1005 of Embodiment 1, and will not be repeated.
[0274] Step 1106: The RAN stores the encrypted NAS-PDU and the time value, and sends a paging message carrying only the UE ID to the AIoT device (i.e., the second paging message in the foregoing embodiment).
[0275] Step 1107: The AIoT device checks the AIoT ID in the paging message, and if the ID matches, selects a random access preamble preamble and initiates a random access procedure to the RAN (i.e., sends msg1).
[0276] Step 1108: The RAN returns a random access response (i.e., msg3) to the AIoT, carrying the encrypted NAS-PDU (simplified as [NAS-PDU] in FIG. 11), the time value. Optionally, a first sequence number (such as NAS COUNT) can also be carried.
[0277] Step 1109: After receiving the random access response message, the AIoT verifies the first check code and decrypts the downlink data in the NAS-PDU. The processing of verifying the first check code and decrypting the downlink data is the same as step 1007 of Embodiment 1, and will not be repeated.
[0278] Steps 1110-1112 are the same as steps 1010-1012 of the foregoing Embodiment 1, and will not be repeated.
[0279] Embodiment 3: In combination with FIG. 12, after the RB and N2 connection are completely established, the downlink data is sent in the downlink NAS transmission message, specifically including:
[0280] Steps 1200-1204 are the same as steps 1000-1004 of Embodiment 1, and are not repeated here.
[0281] Step 1205: The AMF sends a paging to the RAN, which carries only the AIoT ID (i.e., the fourth paging message in the foregoing embodiment).
[0282] Step 1206: The RAN forwards the paging message to the AIoT device over the air interface, which contains the AIoT ID (i.e., the second paging message in the foregoing embodiment).
[0283] Step 1207: The AIoT and the RAN establish a radio bearer.
[0284] Step 1208: The RAN and the AMF establish an N2 connection.
[0285] Step 1209: The AMF sends a DL NAS TRANSPORT message (downlink NAS message) to the AIoT device, which contains the AIoT ID, the encrypted NAS-PDU (illustrated as [NAS-PDU] in FIG. 12), a time value, and optionally, a first NAS sequence number. It should be understood that the message in step 1209 can also be replaced by other newly defined non-access stratum messages.
[0286] Step 1210: After receiving the downlink NAS message, the AIoT verifies the first check code and decrypts the downlink data in the NAS-PDU. The processing of verifying the first check code and decrypting the downlink data is the same as that in step 1007 of Embodiment 1, and is not repeated here. Here, the message in step 1210 can also be a newly defined non-access stratum message.
[0287] Steps 1211-1213 are the same as steps 1010-1012 of the foregoing Embodiment 1, and are not repeated here.
[0288] Embodiment 4, uplink data is sent in the msg3 message, as shown in FIG. 13, which specifically includes:
[0289] Step 1300 is the same as step 1000 of Embodiment 1, and is not repeated here.
[0290] Step 1301: The AF sends an AIoT service request message to the NEF, which contains but is not limited to: an AIoT ID, an AF ID, a service operation type, and optionally, at least one of the following: downlink data (such as read data or read commands), a target area (TA), and the like.
[0291] Step 1302 is the same as step 1002 of Embodiment 1, and is not repeated here.
[0292] Step 1303: The NEF forwards the AIoT service request message to the selected AMF.
[0293] Step 1304: The AMF selects a RAN according to the target area.
[0294] Step 1305: The AMF sends a Paging message to the RAN.
[0295] Step 1306: The RAN forwards the Paging message to the AIoT device through the air interface.
[0296] The Paging message sent by the AMF in step 1305 and the Paging message transmitted by the RAN through the air interface can carry the same content, such as the AIoT ID, the service type, and the time value.
[0297] It should be noted that if the service type needs to be encrypted and protected, the encryption and / or integrity protection can be performed in the manner of embodiment 1, and the description is not repeated.
[0298] Step 1307: The AIoT device reads the content of the Paging message, selects a random access preamble, and initiates a random access procedure to the RAN. The AIoT device reading the content of the Paging message can include the process of determining whether the AIoT ID matches, which is not described in detail.
[0299] Step 1308: The RAN returns a random access response message.
[0300] Step 1309: The AIoT device performs uplink data (such as data read based on a read command, which can include measured sensor data, location information, etc.) or feedback of the AIoT ID (inventory message (or inventory service)) according to the service operation type: using the NAS security context (such as the NAS confidentiality key K NASenc , the NAS encryption algorithm) to perform partial encryption processing on the uplink data or the AIoT ID to obtain second ciphertext data (i.e., only the container (UL data or ID) containing the uplink data is encrypted, and the non-plaintext is not encrypted), and using the NAS integrity protection key K NASint to calculate a second check code to protect the integrity of the sent message. The way of calculating the second check code and calculating the second ciphertext data is the same as the foregoing embodiments, and is not described in detail.
[0301] Step 1310: The AIoT device sends the encrypted NAS-PDU (illustrated as [NAS-PDU] in FIG. 13) to the RAN through an RRC message within a limited time according to the time value, and the RRC message can also include: the NAS COUNT value, and the AIoT temporary ID.
[0302] Step 1311: The RAN transparently forwards the N2 message to the AMF, which contains the encrypted NAS-PDU ([NAS-PDU]), and can also include: the NAS COUNT value (COUNT), the AIoT temporary ID. The RRC message in step 1310 and the N2 message in step 1311 can also be newly defined messages.
[0303] Step 1312: The AMF receives the N2 message forwarded by the RAN, and if the AIoT temporary ID matches the locally saved AIoT temporary ID, the AMF calculates a second verification code using the NAS confidentiality key KNASint, performs integrity verification based on the second verification code and the second check code, and after verification, performs decryption processing using the NAS confidentiality key KNASenc to obtain the uplink data (such as the uplink data reported in response to the read command) sent by the AIoT device (or obtains the AIoT ID reported by the AIoT device in response to the inventory message). The processing of the AMF to verify the integrity and the decryption processing are the same as in the foregoing embodiments, and will not be repeated here.
[0304] Step 1313: The AMF carries the obtained UL data (or AIoT ID) of the AIoT device in the AIoT service response and sends it to the AF through the NEF.
[0305] Embodiment 5: After the complete establishment of the RB and the N2 connection, the uplink data is sent in the UL NAS TRANSPORT message (uplink NAS message), as shown in FIG. 14, which includes:
[0306] Steps 1400-1406 are the same as steps 1300-1306 of Embodiment 4, and will not be repeated here.
[0307] Step 1407: The AIoT and the RAN establish a radio bearer.
[0308] Step 1408: The RAN and the AMF establish an N2 connection.
[0309] Step 1409 is the same as step 1309 of Embodiment 4, and will not be repeated here.
[0310] Step 1410: The AIoT device sends the encrypted NAS-PDU ([NAS-PDU]) to the RAN through the uplink NAS message within a limited time according to the time value, and the message can also include: the NAS COUNT value (COUNT), the AIoT temporary ID. The message in this step 1410 can also be replaced by a newly defined non-access layer message.
[0311] Steps 1411-1412 are the same as steps 1312-1313 of Embodiment 4, and will not be repeated here.
[0312] It should be noted that the AMF in Embodiments 1-5 above can be replaced by an AIoT NF, and the RAN can also be replaced by a UE, i.e., a terminal.
[0313] In the related art, an AIoT device cannot establish a connection for a DRB, cannot perform transmission on a UP, and needs to perform data transmission through signaling due to the lack of an RRC state. In some solutions to the communication between an AIoT device and a mobile communication network, it is proposed that a part of the EDT CP solution can be reused, and in the EDT CP solution, user data is transmitted earliest in msg3 and msg4, but the AIoT device has lower capability and power consumption, and thus a transmission scheme suitable for AIoT needs to be redesigned to ensure data transmission safety and reduce signaling overhead.
[0314] By adopting the scheme provided in the application, the first PDU sent to the AIoT device can be processed based on the security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data. In this way, the AIoT device can receive data transmitted by the communication network and perform security processing based on the security parameter to ensure the safety of the data.
[0315] Further, in the scheme provided in the embodiment, downlink data can be transmitted earliest through the first PDU carried in the paging message, and uplink data can be transmitted earliest through the second PDU carried in msg3, and the AIoT device can achieve transmission of uplink and downlink data without switching to an RRC connected state, thereby reducing the signaling overhead of the AIoT device for transmitting data by transmitting downlink data and / or uplink data in advance. In addition, in the scheme provided in the embodiment, the integrity protection state and / or the encryption state can be defined through the indication information carried in the first PDU or the second PDU, so that the service-related data of the AIoT can be flexibly encrypted (or partially encrypted) and / or integrity protected. Moreover, by adding a time value acting as a timestamp in the message sent to the AIoT device, the generated message is linked to the current session, which can resist denial-of-service attacks and the like.
[0316] FIG. 15 is a schematic diagram of the composition structure of an AIoT device according to an embodiment of the application, which includes:
[0317] The first communication unit 1501 is configured to receive a first message, wherein the first message carries a first PDU processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
[0318] The first PDU carries a first check code for verifying integrity, and the AIoT device further includes a first processing unit 1502 configured to calculate a first verification code based on a perfect protection parameter in the security parameter corresponding to the AIoT device and one of the downlink data and the first cipher text data, wherein the perfect protection parameter includes at least one of a perfect protection key and a perfect protection algorithm, and verify the integrity of the first message based on the first verification code and the first check code.
[0319] The first PDU further carries the downlink data.
[0320] The first PDU carries first cipher text data, and the first processing unit is configured to decrypt the downlink data based on a confidentiality parameter in the security parameter corresponding to the AIoT device and the first cipher text data, wherein the confidentiality parameter includes at least one of a confidentiality key and a confidentiality algorithm.
[0321] The first PDU further carries at least one of first indication information and a first key set identifier KSI, wherein the first indication information is used to indicate a perfect protection state and / or an encryption state of the first PDU, and the first KSI includes at least one of a key identifier of the perfect protection key used to calculate the first check code and a key identifier of the confidentiality key used to calculate the first cipher text data.
[0322] The first message further carries at least one of an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs, and a time value.
[0323] The first communication unit is configured to receive the first message from the first device.
[0324] The first message is sent in one of a first paging message, msg2 in a random access procedure, and msg4 in a random access procedure.
[0325] The first communication unit is configured to receive the first message from the first core network device.
[0326] The first communication unit is configured to send a second message, wherein the second message carries a second PDU that is securely processed based on a security parameter corresponding to the AIoT device, and the second PDU is used to determine uplink data.
[0327] The second PDU carries a second check code for verifying integrity, wherein the second check code is calculated based on a perfect protection parameter in the security parameter corresponding to the AIoT device and one of the uplink data and the second cipher text data.
[0328] The second PDU further carries the uplink data.
[0329] The second PDU carries second cipher data, wherein the second cipher data is calculated based on a confidentiality parameter in the security parameter corresponding to the AIoT device and the uplink data.
[0330] The second PDU further carries at least one of the following: second indication information, the second indication information being used to indicate a perfect integrity state and / or an encryption state of the second PDU; a second KSI, the second KSI including at least one of the following: a key identifier of the perfect integrity key used to calculate a second check code, a key identifier of the confidentiality key used to calculate the second cipher data.
[0331] The first communication unit is configured to send the second message in a message transmission period, wherein the message transmission period is determined based on a time value carried in the first message.
[0332] The second message is sent through msg3 in a random access process.
[0333] FIG. 16 is a schematic diagram of the composition structure of a first device according to an embodiment of the present application, including:
[0334] The second communication unit is configured to receive a third message from the first core network device, wherein the third message carries a first PDU that is securely processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data; and send a first message to the AIoT device, wherein the first message carries the first PDU.
[0335] The third message further carries at least one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs, and the time value.
[0336] The first message further carries at least one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs, and a time value.
[0337] The first message is sent through one of the following: a first paging message, msg2 in a random access process, and msg4 in a random access process.
[0338] The second communication unit is configured to receive a second message from the AIoT device, wherein the second message carries a second PDU that is securely processed based on the security parameter, and the second PDU is used to determine uplink data; and send a fourth message to the first core network device, wherein the fourth message carries the second PDU.
[0339] The second message is sent through msg3 in a random access process.
[0340] Fig. 17 is a schematic diagram of a constituent structure of a first core network device according to an embodiment of the present application, comprising:
[0341] The third communication unit 1701 is configured to send a third message to the first device, wherein the third message carries a first PDU that is processed based on a security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine the downlink data.
[0342] The first PDU carries a first check code for verifying integrity, and the first check code is calculated based on a perfect protection parameter in the security parameter corresponding to the AIoT device and one of the downlink data and first cipher data, wherein the perfect protection parameter comprises at least one of a perfect protection key and a perfect protection algorithm.
[0343] The first PDU further carries the downlink data.
[0344] The first PDU carries first cipher data, and the first cipher data is calculated based on a confidentiality parameter in the security parameter corresponding to the AIoT device and the downlink data, wherein the confidentiality parameter comprises at least one of a confidentiality key and a confidentiality algorithm.
[0345] The first PDU further carries at least one of the following: first indication information, the first indication information being used to indicate a perfect protection state and / or an encryption state of the first PDU; and a first key set identifier KSI, the first KSI comprising at least one of a key identifier of the perfect protection key used to calculate the first check code and a key identifier of the confidentiality key used to calculate the first cipher data.
[0346] The third message further carries at least one of the following: an identifier of the AIoT device, an identifier of a group to which the AIoT device belongs, and a time value.
[0347] The third communication unit is configured to receive a service request message, wherein the service request message carries at least one of the following: the downlink data, the identifier of the AIoT device, the identifier of the group to which the AIoT device belongs, and a target area, wherein the target area is used to select the first device.
[0348] The third communication unit is configured to receive a fourth message from the first device, wherein the fourth message carries a second PDU that is processed based on the security parameter, and the second PDU is used to determine uplink data.
[0349] The second PDU carries a second check code for verifying integrity, and the first core network device further includes a third processing unit 1702 configured to calculate a second verification code based on a perfect protection parameter in the security parameter corresponding to the AIoT device and one of the uplink data and the second cipher text data, and verify the integrity of the fourth message based on the second verification code and the second check code.
[0350] The second PDU further carries the uplink data.
[0351] The second PDU carries second cipher text data, and the third processing unit is configured to decrypt the uplink data based on a confidentiality parameter in the security parameter corresponding to the AIoT device and the second cipher text data.
[0352] The second PDU further carries at least one of second indication information and a second KSI, the second indication information being used to indicate a perfect protection state and / or an encryption state of the second PDU, and the second KSI including at least one of a key identifier of the perfect protection key used to calculate the second check code and a key identifier of the confidentiality key used to calculate the second cipher text data.
[0353] The device of the embodiments of the present application can realize the corresponding functions of each device in the communication method embodiments described above. The processes, functions, implementation manners and advantages of each module (sub-module, unit or component, etc.) in the device can be referred to the corresponding description in the method embodiments, which will not be described here. It should be noted that the functions described with respect to each module (sub-module, unit or component, etc.) in the device of the embodiments of the present application can be realized by different modules (sub-modules, units or components, etc.), or by the same module (sub-module, unit or component, etc.).
[0354] It should be understood that the size of the serial number of each process in the various embodiments of the present application does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here. The above only describes the specific implementation of the present application, and the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A communication method performed by an AIoT device, comprising: Receive a first message, wherein the first message carries a first protocol data unit (PDU) for security processing based on security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
2. The method according to claim 1, wherein The first PDU carries a first check code for verifying integrity, and the method further includes: Calculate a first verification code based on a security parameter in the security parameters corresponding to the AIoT device and one of the following: the downlink data and the first ciphertext data, wherein the security parameter includes at least one of the following: a security key and a security algorithm; The integrity of the first message is verified based on the first verification code and the first check code.
3. The method according to claim 2, wherein: The first PDU also carries the downlink data.
4. The method according to claim 1 or 2, wherein: The first PDU carries first ciphertext data, and the method further includes: Based on the confidentiality parameter in the security parameter corresponding to the AIoT device and the first ciphertext data, the downlink data is decrypted to obtain the downlink data, wherein the confidentiality parameter includes at least one of the following: a confidentiality key and a confidentiality algorithm.
5. The method according to any one of claims 2 to 4, wherein: The first PDU also carries at least one of the following: First indication information, where the first indication information is used to indicate a security status and / or encryption status of the first PDU; A first key set identifier KSI, where the first KSI includes at least one of the following: a key identifier for a security key used to calculate a first check code, and a key identifier for a confidentiality key used to calculate the first ciphertext data.
6. The method according to any one of claims 1 to 5, wherein: The first message also carries at least one of the following: an identifier of the AIoT device, an identifier of the group to which the AIoT device belongs, and a time value.
7. The method according to any one of claims 1 to 6, wherein: The receiving the first message includes: The first message is received from a first device.
8. The method according to any one of claims 1 to 7, wherein: The first message is sent in one of the following ways: a first paging message, msg2 in a random access process, or msg4 in a random access process.
9. The method according to any one of claims 1 to 6, wherein: The receiving the first message includes: Receive the first message from the first core network device.
10. The method according to any one of claims 1 to 9, wherein: The method further comprises: Send a second message, wherein the second message carries a second PDU that is securely processed based on the security parameters corresponding to the AIoT device, and the second PDU is used to determine uplink data.
11. The method according to claim 10, wherein: The second PDU carries a second check code for verifying integrity, wherein the second check code is calculated based on the integrity parameter in the security parameters corresponding to the AIoT device and one of the following: the uplink data and the second ciphertext data.
12. The method according to claim 11, wherein The second PDU also carries the uplink data.
13. The method according to claim 10 or 11, wherein: The second PDU carries second ciphertext data, wherein the second ciphertext data is calculated based on the confidentiality parameter in the security parameter corresponding to the AIoT device and the uplink data.
14. The method according to any one of claims 10 to 13, wherein: The second PDU also carries at least one of the following: Second indication information, where the second indication information is used to indicate a security status and / or encryption status of the second PDU; The second KSI includes at least one of the following: a key identifier for calculating a security key for the second check code, and a key identifier for calculating a confidentiality key for the second ciphertext data.
15. The method according to any one of claims 10 to 14, wherein: The sending of the second message includes: The second message is sent within a message transmission period, wherein the message transmission period is determined based on a time value carried in the first message.
16. The method according to any one of claims 10 to 15, wherein: The second message is sent via msg3 in the random access process.
17. A communication method performed by a first device, comprising: Receive a third message from the first core network device, wherein the third message carries a first protocol data unit (PDU) for security processing based on a non-access layer security parameter corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data; A first message is sent to the AIoT device, where the first message carries the first PDU.
18. The method according to claim 17, wherein The third message also carries at least one of the following: an identifier of the AIoT device, an identifier of the group to which the AIoT device belongs, and a time value.
19. The method according to claim 17 or 18, wherein The first message also carries at least one of the following: an identifier of the AIoT device, an identifier of the group to which the AIoT device belongs, and a time value.
20. The method according to any one of claims 17 to 19, wherein: The first message is sent in one of the following ways: a first paging message, msg2 in a random access process, or msg4 in a random access process.
21. The method according to any one of claims 17 to 20, wherein: The method further comprises: receiving a second message from the AIoT device, wherein the second message carries a second PDU that is securely processed based on the security parameter, and the second PDU is used to determine uplink data; Send a fourth message to the first core network device, wherein the fourth message carries the second PDU.
22. The method according to claim 21, wherein The second message is sent via msg3 in the random access process.
23. A communication method performed by a first core network device, comprising: A third message is sent to the first device, wherein the third message carries a first protocol data unit (PDU) for security processing based on the non-access layer security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
24. The method according to claim 23, wherein The first PDU carries a first check code for verifying integrity, and the first check code is calculated based on the security parameter in the security parameter corresponding to the AIoT device and one of the following: the downlink data, the first ciphertext data, wherein the security parameter includes at least one of the following: a security key, a security algorithm.
25. The method according to claim 24, wherein The first PDU also carries the downlink data.
26. The method according to claim 23 or 24, wherein The first PDU carries first ciphertext data, which is calculated based on the confidentiality parameters in the security parameters corresponding to the AIoT device and the downlink data. The confidentiality parameters include at least one of the following: a confidentiality key and a confidentiality algorithm.
27. The method according to any one of claims 24 to 26, wherein: The first PDU also carries at least one of the following: First indication information, where the first indication information is used to indicate a security status and / or encryption status of the first PDU; A first key set identifier KSI, where the first KSI includes at least one of the following: a key identifier for a security key used to calculate a first check code, and a key identifier for a confidentiality key used to calculate the first ciphertext data.
28. The method according to any one of claims 23 to 27, wherein: The third message also carries at least one of the following: an identifier of the AIoT device, an identifier of the group to which the AIoT device belongs, and a time value.
29. The method according to any one of claims 23 to 28, wherein: The method further comprises: Receive a service request message, wherein the service request message carries at least one of the following: the downlink data, the identifier of the AIoT device, the identifier of the group to which the AIoT device belongs, and a target area, wherein the target area is used to select the first device.
30. The method according to any one of claims 23 to 29, wherein: The method further comprises: A fourth message is received from the first device, wherein the fourth message carries a second PDU that is security-processed based on the security parameter, and the second PDU is used to determine uplink data.
31. The method according to claim 30, wherein The second PDU carries a second check code for verifying integrity, and the method further includes: Calculate a second verification code based on the integrity parameter in the security parameter corresponding to the AIoT device and one of the following: the uplink data and the second ciphertext data; The integrity of the fourth message is verified based on the second verification code and the second check code.
32. The method according to claim 31, wherein The second PDU also carries the uplink data.
33. The method according to claim 30 or 31, wherein The second PDU carries second ciphertext data, and the method further includes: Based on the confidentiality parameter in the security parameter corresponding to the AIoT device and the second ciphertext data, the uplink data is decrypted to obtain the uplink data.
34. The method according to any one of claims 30 to 33, wherein: The second PDU also carries at least one of the following: Second indication information, where the second indication information is used to indicate a security status and / or encryption status of the second PDU; The second KSI includes at least one of the following: a key identifier for calculating a security key for the second check code, and a key identifier for calculating a confidentiality key for the second ciphertext data.
35. An AIoT device, comprising: A first communication unit is used to receive a first message, wherein the first message carries a first protocol data unit PDU that is securely processed based on the non-access layer security parameters corresponding to the AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
36. A first device comprising: The second communication unit is used to receive a third message from the first core network device, wherein the third message carries a first protocol data unit PDU that is securely processed based on the non-access layer security parameters corresponding to the environmental Internet of Things AIoT device, and the first PDU is used by the AIoT device to determine downlink data; and send a first message to the AIoT device, wherein the first message carries the first PDU.
37. A first core network device, comprising: The third communication unit is used to send a third message to the first device, wherein the third message carries a first protocol data unit PDU that is securely processed based on the non-access layer security parameters corresponding to the environmental Internet of Things AIoT device, and the first PDU is used by the AIoT device to determine downlink data.
Citation Information
Patent Citations
Communication node, data transmission method and storage medium
CN115866013A
Information processing method and device, communication equipment and storage medium
CN117643029A
Initial security activation for medium access control layer
WO2023175378A1