Communication method, and device
By generating a first key between the AIoT device and the access network device, the security issue of AIoT devices transmitting private information over the air interface is solved, ensuring message security and privacy protection.
Patent Information
- Application Number
- PCT/CN2024/089264
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-23
- Publication Date
- 2025-10-30
AI Technical Summary
Because AIoT devices lack RRC status, their transmitted privacy information is sent in plaintext over the air interface, causing privacy issues such as connectivity problems. Existing technologies cannot guarantee the security of these messages.
AIoT devices generate a first key with access network devices by transmitting downlink signals broadcast by access network devices, which is used to protect the security of messages transmitted over the air interface.
It ensures the security of AIoT devices transmitting messages over the air interface, avoiding the leakage of privacy information and linkability attacks.
Smart Images

Figure CN2024089264_30102025_PF_FP_ABST
Abstract
Description
Communication methods and devices Technical Field
[0001] This application relates to the field of communications, and more specifically, to a communication method and device. Background Technology
[0002] With technological advancements, Ambient Powered IoT (AIoT) devices require access to communication systems or networks for data interaction. However, AIoT devices are characterized by the lack of RRC (Radio Resource Control) state and the inability to establish data bearers. Because AIoT devices lack RRC state, privacy information (such as the AIoT device ID) transmitted when sending RRC messages (access layer messages) is sent in plaintext over the air, leading to connectivity issues. Therefore, ensuring the security of messages transmitted by AIoT devices over the air becomes a crucial problem to solve.
[0003] Summary of the Invention
[0004] This application provides a communication method and device.
[0005] This application provides a communication method executed by an AIoT device, including:
[0006] A first key is generated between the access network device and the access network device based on one or more first downlink signals broadcast by the access network device.
[0007] This application provides a communication method executed by an access network device, including:
[0008] Broadcast one or more first downlink signals, wherein the one or more first downlink signals are used by the AIoT device to generate a first key with the access network device.
[0009] This application provides an AIoT device, including:
[0010] The first processing unit is configured to generate a first key with the access network device based on one or more first downlink signals broadcast by the access network device.
[0011] This application provides an access network device, including:
[0012] The second communication unit is configured to broadcast one or more first downlink signals, wherein the one or more first downlink signals are used by the AIoT device to generate a first key with the access network device.
[0013] By adopting the above scheme, AIoT devices can generate a first key with access network devices based on the downlink signals broadcast by access network devices. In this way, AIoT devices can use the first key for security protection when transmitting messages with access network devices over the air interface, thereby ensuring the security of messages transmitted by AIoT devices over the air interface. Attached Figure Description
[0014] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.
[0015] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application.
[0016] Figure 3 is a schematic flowchart of a communication method according to another embodiment of this application.
[0017] Figures 4 and 5 are two schematic flowcharts of the communication method according to this application.
[0018] Figure 6 is a schematic block diagram of an AIoT device according to an embodiment of this application.
[0019] Figure 7 is a schematic block diagram of an access network device according to an embodiment of the present application. Detailed Implementation
[0020] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
[0021] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.
[0022] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.
[0023] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.
[0024] Figure 1 exemplarily illustrates a communication system 100. This communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and the coverage area of each network device 110 may include other numbers of terminals 120; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include mobility management entities, access and mobility management functions, and other network entities; this embodiment does not limit this. The network devices may further include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.
[0025] Among related technologies, AIoT is expected to have a connection count / device density that is several orders of magnitude higher than that of existing 3GPP IoT technologies, while the complexity and power consumption of the devices are several orders of magnitude lower than those of existing 3GPP IoT technologies. It can provide a clear differentiation and solve use cases and scenarios that cannot be achieved based on existing 3GPP IoT technologies. AIoT has the following characteristics: AIoT devices are divided into two types based on power consumption: approximately 1uW peak power consumption and less than several hundreduW peak power consumption; AIoT device service types are divided into DT (Device-terminated) and DO-DTT (Device-originated-device-terminated triggered by DT), both triggered by the network; it supports topology 1 (base station and AIoT directly connected) and topology 2 (UE as an intermediate node) in TR38.848, has no RRC state, no mobility (i.e., at least no cell selection / reselection class function), no HARQ (Hybrid Automatic Repeat Request), and no ARQ (Automatic Repeat Request); AIoT devices do not have RRC state, meaning DRB cannot be established. From an end-to-end perspective, user plane data transmission is not feasible, and AIoT devices may only support data transmission via signaling-like methods.
[0026] Because AIoT lacks an RRC state, DRB cannot establish a connection and cannot perform UP plane transmission. Therefore, EDT's CP solution can be reused. However, if EDT's CP solution is reused, AIoT user data is embedded in RRC messages (air interface access layer messages) in NAS-PDU form for secure transmission. Sensitive information that needs to be transmitted in the RRC messages (air interface access layer messages) by AIoT devices (such as user identification, which may include 5G-S-TMSI or AIoT device ID) will be sent in plaintext over the air interface, raising privacy issues such as connectivity problems. While the connectivity attack can be mitigated by reallocating the AIoT device ID, frequent ID allocation also leads to significant energy consumption for AIoT devices. Therefore, ensuring the security of messages transmitted by AIoT devices over the air interface becomes a problem that needs to be solved.
[0027] Figure 2 is a schematic flowchart of a communication method performed by an AIoT device according to an embodiment of this application. The method includes at least a portion of the following.
[0028] S210. Based on one or more first downlink signals broadcast by the access network device, generate a first key with the access network device.
[0029] Figure 3 is a schematic flowchart of a communication method performed by an access network device according to an embodiment of this application. The method includes at least a portion of the following.
[0030] S310. Broadcast one or more first downlink signals, wherein the one or more first downlink signals are used by the AIoT device to generate a first key with the access network device.
[0031] The access network device can refer to an access network device that serves or manages the AIoT device. For example, the access network device can be called a read / write device, or a read / write device corresponding to the AIoT device.
[0032] In some possible examples, the access network device can also be replaced by a terminal (or the read / write device can also be a terminal). This terminal can be an intermediate device, proxy device, or relay device for the AIoT device, meaning the AIoT device can interact with network-side devices through this terminal. In some possible examples, the terminal can also be referred to as an Intermediate node, proxy UE, intermediate UE, relay device, intermediate device, proxy device, etc., any one of these.
[0033] On the access network device side, broadcasting one or more first downlink signals can be: periodically broadcasting multiple downlink signals, wherein the multiple downlink signals include the one or more first downlink signals. The length of the broadcast period for the downlink signals can be configured according to actual conditions, and this embodiment does not limit it.
[0034] The first downlink signal includes: a first downlink synchronization signal or a first downlink reference signal.
[0035] It should be noted that multiple downlink signals can be generated in the same way (e.g., sequences generated using the same sequence generation method). This embodiment does not limit the generation method of each downlink signal. One or more first downlink signals are a subset of the multiple downlink signals. This embodiment uses "first downlink signal" for distinction and description, mainly to indicate that the function of one or more first downlink signals is for generating a first key for AIoT devices, and not to indicate different generation methods of the first downlink signals. For example, taking a first downlink synchronization signal as an example, the access network device can generate multiple downlink synchronization signals in the same way. One or more first downlink synchronization signals are a subset of the multiple downlink synchronization signals, and their function is for generating a first key for AIoT devices, not to indicate different generation methods of the first downlink synchronization signals.
[0036] In some possible implementations, the AIoT device may perform a process of generating a first key with the access network device based on one or more first downlink signals broadcast by the access network device before initiating random access.
[0037] The triggering or determining method for waking up (or powering on) an AIoT device and executing the process of generating the first key can be as follows: The AIoT device is initially connected to a 3GPP system or network, and the device is determined to be woken up and needs to perform the process of generating the first key; or, the location of the AIoT device changes, and the device is manually set to wake up and trigger the process of generating the first key. It should be understood that this is merely an illustrative example, and the triggering or determining method for waking up (or powering on) the AIoT device and executing the process of generating the first key can also be other possible methods, such as being triggered or instructed by the network, or by a third-party server (such as AF) through 5GC, etc. This does not limit or exhaustively list all possible triggering or determining methods for waking up the AIoT device and executing the process of generating the first key.
[0038] In one embodiment, the first downlink signal is a first downlink synchronization signal. The first downlink synchronization signal can be one of the following: a first PSS (Primary Synchronization Signal) or a first SSS (Secondary Synchronization Signal).
[0039] In some preferred examples, the AIoT device generates a first key with the access network device based on one or more first PSSs broadcast by the access network device. In some optional examples, the AIoT device generates a first key with the access network device based on one or more first SSSs broadcast by the access network device.
[0040] AIoT devices also need to achieve downlink time-frequency synchronization and obtain system-related information based on downlink synchronization signals broadcast by access network devices and the Physical Broadcast Channel (PBCH). This system-related information can include the MIB (Master Information Block), and further, it can also include the SIB (System Information Block), other system information (OSI), and so on.
[0041] Specifically, achieving downlink time-frequency synchronization and obtaining system-related information based on the downlink synchronization signal and PBCH broadcast by the access network device can include: detecting the second PSS, second SSS, and second PBCH broadcast by the access network device; obtaining the downlink time-frequency synchronization and PCID (Physical Cell ID) based on the second PSS and second SSS; decoding the received second PBCH to obtain the MIB; and obtaining system-related information such as SIB1 and OSI based on the MIB. This embodiment does not limit the method by which AIoT devices obtain system-related information such as SIB1 and OSI.
[0042] In this embodiment, the number of second PSS, second SSS, and second PBCH detected by the AIoT device is not limited.
[0043] In this embodiment, one or more first PSSs and second PSSs are included in multiple PSSs broadcast by the access network device. However, the functions of one or more first PSSs and second PSSs differ on the AIoT device side. The second PSS is used to combine with the second SSS to enable the AIoT device to obtain downlink time-frequency synchronization and PCID, and the one or more first PSSs are used by the AIoT device to generate a first key. Alternatively, one or more first SSSs and second SSSs are included in multiple SSSs broadcast by the access network device. The only difference is that the functions of one or more first SSSs and second SSSs differ on the AIoT device side. The second SSS is used to combine with the second PSS to enable the AIoT device to obtain downlink time-frequency synchronization and PCID, and the one or more first SSSs are used by the AIoT device to generate a first key.
[0044] In some examples, one or more first PSSs and second PSSs occupy different time domain ranges, with the second PSS occupying a time domain range earlier than all the first PSSs; or, one or more first SSSs and second SSSs occupy different time domain ranges, with the second SSS occupying a time domain range earlier than all the first SSSs. In this example, the AIoT device detects the second PSS, second SSS, and second PBCH broadcast by the access network device, obtains downlink time-frequency synchronization and PCID (Physical Cell ID) based on the second PSS and second SSS, decodes the received second PBCH to obtain the MIB, obtains system-related information such as SIB1 and OSI based on the MIB, and then generates a first key based on one or more first PSSs or one or more first SSSs broadcast by the access network device.
[0045] In some examples, one or more first PSSs contain a second PSS; or, one or more first SSSs contain a second SSS. In such examples, the AIoT device detects the second PSS, second SSS, and second PBCH broadcast by the access network device, obtains downlink time-frequency synchronization and PCID (Physical Cell ID) based on the second PSS and second SSS, decodes the received second PBCH to obtain the MIB, and obtains system-related information such as SIB1 and OSI based on the MIB; and, the AIoT device generates a first key based on one or more first PSSs or one or more first SSSs broadcast by the access network device, wherein one or more first PSSs include the second PSS, and one or more first SSSs include the second SSS.
[0046] In one embodiment, the first downlink signal is a first downlink reference signal. The first downlink reference signal can be a first DMRS (Demodulation Reference Signal) or a first CSI-RS (Channel-State-Information Reference Signal) or other downlink RSs. Here, we do not exhaustively list or limit all possible types of the first downlink reference signal.
[0047] Optionally, the first downlink reference signal may be a first DMRS. This first DMRS may be carried or transmitted by the first PBCH.
[0048] The specific processing by which AIoT devices achieve downlink time-frequency synchronization and obtain system-related information based on the downlink synchronization signal and PBCH broadcast by the access network device is the same as in the aforementioned embodiments, and will not be repeated here.
[0049] One or more first PBCHs and second PBCHs are included in multiple PBCHs broadcast by the access network device. On the AIoT device side, the functions of one or more first PBCHs and second PBCHs are different. The second PBCH is used for the AIoT device to obtain system-related information. The first DMRS carried by each of the one or more first PBCHs is used by the AIoT device to generate a first key.
[0050] In some examples, one or more first PBCHs and second PBCHs occupy different time domain ranges, with the second PBCH occupying a time domain range earlier than all the first PBCHs. In such examples, the AIoT device detects the second PSS, second SSS, and second PBCH broadcast by the access network device. Based on the second PSS and second SSS, it obtains downlink time-frequency synchronization and PCID (Physical Cell ID). It decodes the received second PBCH to obtain the MIB. Based on the MIB, it obtains system-related information such as SIB1 and OSI. Then, based on the first DMRS carried by each of the one or more first PBCHs broadcast by the access network device, it generates a first key.
[0051] In some examples, one or more first PBCHs contain a second PBCH. In such examples, the AIoT device detects the second PSS, second SSS, and second PBCH broadcast by the access network device, obtains downlink time-frequency synchronization and PCID (Physical Cell ID) based on the second PSS and second SSS, decodes the received second PBCH to obtain the MIB, and obtains system-related information such as SIB1 and OSI based on the MIB; furthermore, the AIoT device generates a first key based on the first DMRS carried by each of the one or more first PBCHs broadcast by the access network device, wherein the one or more first PBCHs include the second PBCH.
[0052] Optionally, the first downlink reference signal can be a first CSI-RS or an RS in another downlink direction. The process by which the AIoT device generates a first key with the access network device based on one or more CSI-RS or other RS in another downlink direction broadcast by the access network device can be performed after the AIoT device achieves downlink time-frequency synchronization based on the downlink synchronization signal and PBCH broadcast by the access network device and obtains relevant system information.
[0053] An AIoT device generates a first key with an access network device based on one or more first downlink signals broadcast by the access network device. This can include first performing processing to receive and measure each first downlink signal, and then performing processing to generate a first key based on the measurement results of each first downlink signal. In this embodiment, the AIoT device may perform the processing to generate a first key with the access network device based on one or more first downlink signals broadcast by the access network device before initiating random access. Specifically, this means that the timing when the AIoT device starts receiving and measuring the first downlink signals (e.g., starting to receive and measure the first first downlink signal, or starting to receive and measure at least some of the first downlink signals) is before initiating random access. However, it is not limited to the timing when the AIoT device generates or obtains the first key necessarily before initiating random access. The timing when the AIoT device generates or obtains the first key may be before initiating random access, or may be at the same time as initiating random access, or may be after initiating random access (but before receiving the random access response), etc.
[0054] In some embodiments, on the AIoT device side, generating a first key with the access network device based on one or more first downlink signals broadcast by the access network device includes: measuring the one or more first downlink signals broadcast by the access network device to obtain measurement results of the one or more first downlink signals; obtaining one or more quantization reference values based on the measurement results of the one or more first downlink signals; and generating the first key with the access network device based on the one or more quantization reference values. The first key generated by the AIoT device can be represented as K. AIoT .
[0055] It should be noted that the key length of the first key can be pre-configured in both the AIoT device and the access network device, or be the default in both the AIoT device and the access network device, or be specified by the protocol; the length of each quantization reference value should be the same, and also pre-configured in both the AIoT device and the access network device, or be the default in both the AIoT device and the access network device, or be specified by the protocol. Therefore, the AIoT device can determine the number of first downlink signals required to generate the first key based on the key length of the first key and the length of the quantization reference values. For example, if the key length (Keylen) of the first key is equal to 128 and the length of the quantization reference value is 4, then the number of first downlink signals required to generate the first key is equal to the key length (Keylen) of the first key divided by the length of the quantization reference value, which is 32.
[0056] The measurement results of the one or more first downlink signals may include the measurement results of each of the one or more first downlink signals. The measurement results may include at least one of the following: RSSI (Received Signal Strength Indication), amplitude, phase, CSI, etc.
[0057] Taking any first downlink signal as the m-th first downlink signal, and the measurement result including RSSI, where m is an integer greater than or equal to 1, as an example, the AIoT device measures the one or more first downlink signals broadcast by the access network device to obtain the measurement results of the one or more first downlink signals. This can include: the AIoT device performing one or more measurements within the duration of the m-th first downlink signal broadcast by the access network device to obtain one or more strength measurements of the m-th first downlink signal, and obtaining the RSSI of the m-th first downlink signal based on the one or more strength measurements of the m-th first downlink signal. Since the way the AIoT device obtains the RSSI of each first downlink signal is the same as the way it obtains the RSSI of the m-th first downlink signal, it will not be described in detail.
[0058] Here, the AIoT device can perform one or more measurements within the duration of the m-th first downlink signal by following a preset measurement cycle. The length of this measurement cycle can be less than the duration of the first downlink signal. For example, if the duration of the first downlink signal is 1 millisecond, the measurement cycle can be 0.1 milliseconds, 0.05 milliseconds, or longer or shorter. We will not exhaustively list them here.
[0059] In the case where one or more intensity measurements of the m-th first downlink signal include multiple intensity measurements of the m-th first downlink signal, obtaining the RSSI of the m-th first downlink signal based on the multiple intensity measurements of the m-th first downlink signal may include: averaging the multiple intensity measurements of the m-th first downlink signal to obtain the RSSI of the m-th first downlink signal.
[0060] Taking the process of an AIoT device measuring one or more first CSI-RS to obtain measurement results as an example, the AIoT device measures the m-th first CSI-RS broadcast by the access network device, performs channel estimation based on the m-th first CSI-RS, and obtains the CSI and other measurement values of the m-th first CSI-RS as the measurement result of the m-th first CSI-RS. The channel estimation method can be any one of the following: least squares-based channel estimation, maximum likelihood-based channel estimation, Kalman filtering-based channel estimation, etc., without limitation or exhaustive enumeration. It should be understood that this is only an exemplary illustration of an AIoT device measuring CSI-RS. In actual processing, the type of downlink signal measured by the AIoT device is not limited to CSI-RS; it can also be other types of reference signals or other types of downlink signals, but this is not limited or exhaustive.
[0061] It should also be noted that the above is an illustrative example. In actual processing, the measurement results can be at least one of the following, including but not limited to amplitude, phase, CSI measurement value, RSSI, etc., and no limit or exhaustive list is made here.
[0062] In one example, obtaining one or more quantization reference values based on the measurement results of the one or more first downlink signals may refer to obtaining one or more quantization reference values based on the measurement results of the one or more first downlink signals, one or more candidate measurement result intervals, and the candidate quantization value corresponding to each candidate measurement result interval in the one or more candidate measurement result intervals. Generating the first key with the access network device based on the one or more quantization reference values may involve merging the one or more quantization reference values to obtain the first key with the access network device.
[0063] Among them, one or more candidate measurement result intervals, and the candidate quantization value corresponding to each candidate measurement result interval can be pre-configured in both AIoT devices and access network devices, or defaulted in both AIoT devices and access network devices, or specified by the protocol.
[0064] Any one of the one or more candidate measurement result intervals may include candidate measurement values between the minimum candidate measurement value (inclusive) and the maximum candidate measurement value (exclusive) of the candidate measurement result interval, or may include candidate measurement values between the minimum candidate measurement value (exclusive) and the maximum candidate measurement value (inclusive) of the candidate measurement result interval; different candidate measurement result intervals in one or more candidate measurement result intervals may contain different candidate measurement values, and the candidate measurement values contained in two adjacent candidate measurement result intervals may be continuous.
[0065] The candidate quantization values corresponding to different candidate measurement result intervals within one or more candidate measurement result intervals can be different. Any candidate quantization value can be binary. The length of any candidate quantization value is equal to the length of the quantization reference value, for example, it can be an integer greater than or equal to 2.
[0066] Based on the measurement results of the one or more first downlink signals, one or more candidate measurement result intervals, and the candidate quantization value corresponding to each candidate measurement result interval in the one or more candidate measurement result intervals, one or more quantization reference values are obtained. This can refer to: determining the measurement result interval corresponding to the measurement result of each of the one or more first downlink signals in the one or more candidate measurement result intervals, and using the candidate quantization value corresponding to the measurement result interval of each first downlink signal as the quantization reference value of each first downlink signal.
[0067] It should be understood that the candidate measurement result interval in this example may include at least one of the following: candidate RSSI interval, candidate amplitude interval, candidate phase interval, candidate CSI measurement result interval, etc.
[0068] In one example, the AIoT device obtains one or more quantization reference values based on the measurement results of the one or more first downlink signals. This may include: dividing the difference between the measurement result of each first downlink signal and the measurement average by the measurement standard deviation to obtain the processed measurement result of each first downlink signal; and determining the candidate quantization reference value with the smallest difference between the processed measurement result of each first downlink signal and the candidate quantization reference value from the one or more candidate quantization reference values, and using this candidate quantization reference value as the quantization reference value for each first downlink signal. The measurement average and measurement standard deviation can be calculated by the AIoT device based on the measurement results of all first downlink signals. This embodiment does not limit the calculation method of the measurement average and measurement standard deviation. The one or more candidate quantization reference values can be pre-configured in both the AIoT device and the access network device, or defaulted to by both the AIoT device and the access network device, or specified by the protocol, or determined based on the processed measurement results of all first downlink signals.
[0069] The AIoT device generates a first key with the access network device based on the one or more quantization reference values, including: the AIoT device inputting one or more quantization reference values into a preset classification formula to obtain index values of one or more quantization reference values output by the preset classification formula; determining one or more quantization results based on the index value of each of the one or more quantization reference values; and merging the one or more quantization results to generate the first key with the access network device. Each quantization result has a length of b, where b is an integer greater than or equal to 2.
[0070] The step of determining one or more quantization results based on the index value of each of the one or more quantization reference values can be as follows: based on the quantization mapping relationship, determine the quantization value corresponding to the index value of each of the one or more quantization reference values, and use the quantization value corresponding to the index value of each quantization reference value as one or more quantization results; or, input the index value of each of the one or more quantization reference values into the encoder to obtain the quantization value corresponding to each quantization reference value output by the encoder, and use the quantization value corresponding to the index value of each of the one or more quantization reference values as one or more quantization results.
[0071] Taking any first downlink signal as the m-th first downlink signal and the measurement result including RSSI as an example, the AIoT device divides the difference between the measurement result of each first downlink signal and the average measurement value by the standard deviation of the measurement to obtain the processed measurement result of each first downlink signal. This can include: dividing the difference between the RSSI of the m-th first downlink signal and the average RSSI by the standard deviation of the RSSI to obtain the processed RSSI of the m-th first downlink signal. From one or more candidate quantization reference values, the candidate quantization reference value with the smallest difference between the processed measurement result of each first downlink signal is determined as the quantization reference value of each first downlink signal. This can be done by: based on one or more candidate quantization reference values, determining the candidate quantization reference value with the smallest difference between the processed RSSI of the m-th first downlink signal and the quantization reference value of the m-th first downlink signal.
[0072] For example, suppose there are M first downlink signals, where M is an integer greater than or equal to 2. The RSSIs of the M first downlink signals can form a set, which is represented as... T represents AIoT devices. Let represent the set of RSSIs of the M first downlink signals obtained by the AIoT device. Further, assume the average value of the RSSIs is expressed as... The standard deviation of RSSI is expressed as: The RSSI of the processed m-th downlink signal obtained by the AIoT device can be calculated using the following formula: Let be a set of processed RSSIs of M first downlink signals, where the processed RSSI of the m-th first downlink signal is the processed RSSI of any one of the first downlink signals in this set.
[0073] Taking candidate quantization reference value as candidate strength quantization reference value as an example, one or more candidate strength quantization reference values can be pre-configured in both AIoT devices and access network devices, or are defaulted to in both AIoT devices and access network devices, or are specified by the protocol, or can be determined based on the RSSI after processing of all the first downlink signals.
[0074] The quantization reference value of the m-th first downlink signal obtained above can be expressed by the following formula: argmin represents the value of the variable q that minimizes the objective function. The objective function Q represents the absolute value of the difference between variable q and the processed RSSI of the m-th first downlink signal. KLet Q represent the quantization reference set, where K represents the number of candidate intensity quantization reference values contained in the quantization reference set, and q∈Q. K Indicate that variable q is Q K One of the candidate intensity quantization reference values, This represents the processed RSSI of the m-th first downlink signal. Let m represent the m-th quantization reference value. The final M quantization reference values can be represented as the following set.
[0075] The quantization reference set Q K It can include K candidate intensity quantization reference values, and the quantization reference set Q K For interval A subset within the set. The K candidate intensity quantization reference values are arranged in ascending order, and each candidate intensity quantization reference value has a corresponding index value in the quantization reference set; the interval between any adjacent candidate intensity quantization reference values among the K candidate intensity quantization reference values is the same, and the value of K can be related to the length b of the quantization result of a single first downlink signal, for example, K=2. b Assuming b equals 4, then K equals 16. For example, this quantization reference set can be represented as: Q K ={q1,q1,…,q K}, q1~q K This represents the quantitative reference values for the K candidate strengths.
[0076] The quantization reference set can be determined by the AIoT device based on the RSSI of each first downlink signal. Specifically, it can include: the AIoT device determining the maximum and minimum RSSI from the RSSI of each first downlink signal; dividing the maximum and minimum RSSI into K intervals; selecting the median value in each of the K intervals as K candidate intensity quantization reference values in the quantization reference set, wherein the difference between the maximum and minimum values in different intervals of the K intervals is the same.
[0077] The method by which the AIoT device obtains the index value of the quantization reference value can be as follows: The AIoT device inputs the m-th intensity quantization reference value into a preset classification formula, and obtains the index value of the m-th intensity quantization reference value output by the preset classification formula. The index value can refer to the index value corresponding to the m-th intensity quantization reference value in the intensity quantization reference set. For example, the preset classification formula can be expressed as follows: f1(*) represents the calculation function of the preset classification formula. This represents the m-th intensity quantization reference value, and index1 represents the index value, which is an integer greater than or equal to 1 and less than or equal to K. Since the index value of each intensity quantization reference value is determined in the same way as the index value of this m-th intensity quantization reference value, it will not be described in detail.
[0078] The quantization mapping relationship may include: K candidate index values, and a candidate quantization value corresponding to each of the K candidate index values. This quantization mapping relationship may be preset according to the actual situation.
[0079] The encoder can be a Göreme encoder, for example, it can be represented as g{index1}, where index1 represents the index value of any intensity quantization reference value as input, and g{*} represents the calculation function of the Göreme encoder; that is, in the method of processing with an encoder, any quantization value can be obtained by formula. get.
[0080] The above is an example of quantization-related processing using RSSI as the measurement result. When the measurement result is amplitude, phase, CSI, or other measurement results, the quantization-related processing is similar to the example above, so it will not be described in detail.
[0081] In some possible implementations, on the AIoT device side, the method further includes: sending a key generation request to the access network device during random access, wherein the key generation request is used to instruct the access network device to generate the first key. On the access network device side, the method further includes: receiving a key generation request sent by the AIoT device during random access, wherein the key generation request is used to instruct the access network device to generate the first key.
[0082] In some embodiments, the key generation request is carried (or transmitted) by the Physical Random Access Channel (PRACH).
[0083] The PRACH can also be used to carry or transmit a preamble. This preamble can be determined based on the content carried by SIB1, meaning that the AIoT device can obtain the preamble needed for this use based on SIB1.
[0084] Optionally, the random access can be a four-step random access, where PRACH can be used to carry the key generation request and the preamble included in message 1 (msg1) of the four-step random access. Optionally, the random access can be a two-step random access, where PRACH can be used to carry the key generation request and the preamble included in message A (msgA) of the two-step random access.
[0085] The PRACH can also be used to transmit the reflected signal of the last first downlink signal.
[0086] In this embodiment, the processing of the AIoT device may include: measuring one or more first downlink signals broadcast by the access network device, obtaining measurement results of one or more first downlink signals, sending a PRACH during the random access process to the access network device, wherein the PRACH is used to transmit the reflected signal of the last first downlink signal among the one or more first downlink signals, and the PRACH is used to carry or transmit a key generation request and a preamble; then, based on the measurement results of the one or more first downlink signals, obtaining one or more quantization reference values; and generating the first key between the device and the access network device based on the one or more quantization reference values.
[0087] Accordingly, after receiving the key generation request sent by the AIoT device during random access, the access network device may further include: obtaining the channel estimation result corresponding to the AIoT device based on the PRACH; obtaining the estimation measurement result of the one or more first downlink signals on the AIoT device based on the channel estimation result and the one or more first downlink signals; and generating the first key based on the estimation measurement result of the one or more first downlink signals on the AIoT device. The first key generated by the access network device can also be represented as K. Reader It should be noted that the embodiments in this application are only for the purpose of distinguishing whether the first key is generated in the AIoT device and the access network device, so different representations are used for the first key generated by the AIoT device and the first key generated by the access network device. In actual processing, the aforementioned K Reader and K AIoT The same method can also be used to represent it, for example, it can be represented as K. PHY Here, we will no longer limit or exhaust all possible representations of the first key.
[0088] The process of obtaining the channel estimation result corresponding to the AIoT device based on the PRACH may include: determining one or more first downlink signals received by the AIoT device based on the reception time (or reception moment) of the PRACH; and obtaining the channel estimation result corresponding to the AIoT device based on the reception strength of the PRACH and the transmission strength of the last first downlink signal among the one or more first downlink signals.
[0089] Specifically, determining one or more first downlink signals received by the AIoT device based on the PRACH reception time can be achieved by: determining the one or more first downlink signals received by the AIoT device based on the PRACH reception time and the number of first downlink signals required to generate the first key. Here, the method for determining the number of first downlink signals required to generate the first key is the same as that for the AIoT device and will not be elaborated further.
[0090] Based on the received strength of PRACH and the transmitted strength of the last first downlink signal, the channel estimation result corresponding to the AIoT device can be obtained. This can be achieved by subtracting the received strength of PRACH from the transmitted strength of the last first downlink signal and then dividing by two. It should be understood that this is merely an exemplary method for calculating the channel estimation result. In actual processing, other methods can also be used to obtain the channel estimation result corresponding to the AIoT device; however, these are not limited or exhaustively listed here.
[0091] Based on the channel estimation result and the one or more first downlink signals, the estimated measurement result of the one or more first downlink signals in the AIoT device can be obtained. This can refer to calculating the estimated measurement result of each first downlink signal in the AIoT device based on the transmission parameters of the one or more first downlink signals and the channel estimation result. The transmission parameters of the first downlink signals can be locally stored in the access network device, and the transmission parameters can include at least one of transmission strength, transmission phase, and transmission amplitude. The content type that the estimated measurement result may contain should be the same as the content type that the measurement result may contain in the foregoing embodiments, such as at least one of the estimated RSSI, estimated amplitude, estimated phase, estimated CSI, etc., which will not be elaborated here.
[0092] For example, calculating the estimated measurement result of each first downlink signal in the AIoT device based on the transmission parameters and channel estimation results of one or more first downlink signals may include: subtracting the channel estimation result from the transmission parameters of each of the one or more first downlink signals to obtain the estimated measurement result of each first downlink signal in the AIoT device. This is merely an illustrative example; in actual processing, there may be other methods for calculating the estimated measurement result of each first downlink signal in the AIoT device based on the transmission parameters and channel estimation results of one or more first downlink signals, which are not limited or exhaustively listed here.
[0093] The specific processing method for generating the first key based on the estimated measurement results of the one or more first downlink signals in the AIoT device should be similar to the processing method for generating the first key based on the measurement results of the one or more first downlink signals in the previous embodiment, except that the executing entity is changed to the access network device, so it will not be described again.
[0094] In one embodiment, on the AIoT device side, sending a key generation request to the access network device during random access includes: sending one or more PRACHs to the access network device during random access, wherein the number of the one or more PRACHs is the same as the number of the one or more first downlink signals, and at least one PRACH among the one or more PRACHs is used to carry the key generation request. On the access network device side, receiving the key generation request sent by the AIoT device during random access includes: receiving one or more PRACHs sent by the AIoT device during random access, wherein the number of the one or more PRACHs is the same as the number of the one or more first downlink signals, and at least one PRACH among the one or more PRACHs is used to carry the key generation request.
[0095] Each of the one or more PRACHs can also be used to carry or transmit a preamble.
[0096] Optionally, the random access can be a four-step random access, where any one or more PRACHs can be used to carry a key generation request, and each PRACH is used to carry or transmit the preamble included in message 1 (msg1) of the four-step random access. Optionally, the random access can be a two-step random access, where any one or more PRACHs can be used to carry a key generation request, and each PRACH is used to carry or transmit the preamble included in message A (msgA) of the two-step random access.
[0097] In this embodiment, the one or more PRACHs can be used to transmit reflected signals of one or more first downlink signals. Preferably, the last PRACH of the one or more PRACHs can be used to carry the key generation request.
[0098] The processing of the AIoT device may include: measuring one or more first downlink signals broadcast by the access network device, obtaining measurement results of one or more first downlink signals, sending one or more PRACHs in the random access process to the access network device, wherein the one or more PRACHs are used to transmit reflected signals of the one or more first downlink signals, each of the one or more PRACHs is used to transmit a preamble, and the last of the one or more PRACHs (or may be one or more other PRACHs) is used to transmit a key generation request; obtaining one or more quantization reference values based on the measurement results of the one or more first downlink signals; and generating the first key between the device and the access network device based on the one or more quantization reference values.
[0099] Accordingly, after receiving the key generation request sent by the AIoT device during random access, the access network device may further include: obtaining the channel estimation result corresponding to the AIoT device based on at least one of the one or more PRACHs; obtaining the estimation measurement result of the one or more first downlink signals in the AIoT device based on the channel estimation result and the one or more PRACHs; and generating the first key based on the estimation measurement result of the one or more first downlink signals in the AIoT device.
[0100] The step of obtaining the channel estimation result corresponding to the AIoT device based on at least one of the one or more PRACHs may include: taking any one of the one or more PRACHs as the first PRACH, and obtaining the channel estimation result corresponding to the AIoT device based on the received strength of the first PRACH and the transmitted strength of the first downlink signal corresponding to the first PRACH. Here, the first downlink signal corresponding to the first PRACH may refer to the last first downlink signal transmitted before receiving the first PRACH.
[0101] Based on the received strength of the first PRACH and the transmitted strength of the first downlink signal corresponding to the first PRACH, the channel estimation result corresponding to the AIoT device can be obtained. This can be achieved by subtracting the received strength of the first PRACH from the transmitted strength of the first downlink signal corresponding to the first PRACH, and then dividing by two. It should be understood that this is merely an exemplary processing method for calculating the channel estimation result. In actual processing, other methods can also be used to obtain the channel estimation result corresponding to the AIoT device; however, these are not limited or exhaustively described here.
[0102] Optionally, obtaining the estimated measurement results of the one or more first downlink signals in the AIoT device based on the channel estimation results and the one or more PRACHs may include: obtaining the first downlink signal corresponding to each PRACH based on the reception time (or reception moment) of each PRACH in the one or more PRACHs; and calculating the estimated measurement results of each first downlink signal in the AIoT device based on the transmission parameters of the one or more first downlink signals and the channel estimation results.
[0103] Optionally, obtaining the estimated measurement results of the one or more first downlink signals in the AIoT device based on the channel estimation results and the one or more PRACHs may include: obtaining the estimated measurement results of the one or more first downlink signals corresponding to the one or more PRACHs in the AIoT device based on the reception parameters of the one or more PRACHs and the channel estimation results. The reception parameters may include at least one of reception strength, transmission phase, and transmission amplitude.
[0104] For example, obtaining the estimated measurement results of one or more first downlink signals corresponding to one or more PRACHs in the AIoT device based on the reception parameters and channel estimation results of the one or more PRACHs can include: increasing the reception parameters of the one or more PRACHs by half of the channel estimation results to obtain the estimated measurement results of one or more first downlink signals corresponding to one or more PRACHs in the AIoT device. This is only an illustrative example. In actual processing, there are other ways to obtain the estimated measurement results of one or more first downlink signals corresponding to one or more PRACHs in the AIoT device based on the reception parameters and channel estimation results of the one or more PRACHs. These methods are not limited or exhaustively listed here.
[0105] In some embodiments, after the access network device generates the first key, the following processing may be performed: sending a random access response to the AIoT device, wherein the random access response carries a key generation response, the key generation response being used by the AIoT device to determine that the access network device has generated the first key. The processing on the AIoT device side further includes: receiving a random access response from the access network device, wherein the random access response carries a key generation response, the key generation response being used to determine that the access network device has generated the first key.
[0106] In some embodiments, after the access network device generates a first key or sends a random access response carrying a key generation response, the processing of the access network device may further include: deriving at least one of the following based on the first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device. Similarly, after the AIoT device generates a first key or receives a random access response carrying a key generation response, the processing may further include: deriving at least one of the following based on the first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device.
[0107] Here, the processing method for deriving the integrity key between the AIoT device and the access network device based on the first key may include: deriving the integrity key between the AIoT device and the access network device based on the first key and integrity key generation parameters. The integrity key generation parameters may include the following content, which is not limited in this embodiment. For example, they may include at least one of the following: the identifier of the AIoT device, the identifier of the access network device, a first freshness value, etc. The specific derivation method of the integrity key can use algorithms such as AES-128; the method of calculating the integrity key is not limited or exhaustively described here. As long as the integrity key is the same in the access network device and the AIoT device, it is within the protection scope of this embodiment.
[0108] The processing method for deriving a confidentiality key between the AIoT device and the access network device based on the first key may include: deriving a confidentiality key between the AIoT device and the access network device based on the first key and confidentiality key generation parameters. The content that the confidentiality key generation parameters may include is not limited in this embodiment; for example, it may include at least one of the following: the identifier of the AIoT device, the identifier of the access network device, a second freshness value, etc. Whether the second freshness value is the same as or different from the first freshness value is not limited in this embodiment. The specific derivation method of the confidentiality key is not limited in this embodiment. As long as the confidentiality key is the same in the access network device and the AIoT device, and the confidentiality key is different from the integrity key, it is within the protection scope of this embodiment.
[0109] In some embodiments, the key generation response may include at least one of the following: a key correction instruction or a security algorithm instruction.
[0110] The key correction indication, also known as the key negotiation indication, can be used by the AIoT device to correct the first key and obtain the same second key as the access network device.
[0111] For example, the key correction indication (or key negotiation indication) may be generated when the access network device needs to adjust the first key. Whether the first key needs to be adjusted and the specific adjustment method may be determined by the access network device according to a pre-configured key adjustment strategy. This embodiment does not limit the key-related strategy.
[0112] If the key generation response includes a key correction instruction, then after the access network device generates the first key, it may include: adjusting the first key based on the key correction instruction to obtain an adjusted first key. Correspondingly, the processing after the AIoT device generates the first key may include: upon receiving a key generation response including the key correction instruction, adjusting the first key based on the key correction instruction to obtain an adjusted first key.
[0113] For example, the key correction indication may include an offset, which can be an offset of one or more specified bits, such as an offset of 1 for one or more specified bits. That is, if the value of a specified bit in the first key is 0, the value is increased by the offset of 1 to obtain the adjusted value of 1. For example, if the key correction indication is an offset of 1 for odd-numbered bits, then if the value of an odd-numbered bit in the first key is 1, the value is increased by 1 to obtain the adjusted value of 0 for that odd-numbered bit. The above is only an illustrative example. The generation method of the key correction indication, the specific content of the key correction indication, and the processing method of the access network device and the AIoT device adjusting the first key based on the key correction indication to obtain the adjusted first key are not limited to the possibilities in the above examples. This embodiment does not limit or exhaustively list them.
[0114] After the access network device generates the adjusted first key or sends a random access response carrying a key generation response, the processing of the access network device may further include: deriving at least one of the following based on the adjusted first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device. Similarly, after the AIoT device generates the adjusted first key, the processing may further include: deriving at least one of the following based on the adjusted first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device. The difference between the processing of deriving the security key and the confidentiality key by the AIoT device and the access network device lies only in replacing the first key in the aforementioned embodiments with the adjusted first key; the remaining related descriptions are the same as in the aforementioned embodiments, and therefore will not be repeated.
[0115] The security algorithm indication can be used by AIoT devices to determine the integrity protection algorithm (hereinafter referred to as the integrity protection algorithm) and / or the confidentiality algorithm (or encryption algorithm). For example, the security algorithm may simply include the identification or description information of the integrity protection algorithm (hereinafter referred to as the integrity protection algorithm) and / or the identification or description information of the confidentiality algorithm (or encryption algorithm), etc.
[0116] In some embodiments, the AIoT device sending a key generation request to the access network device during random access includes: after receiving a random access response from the access network device and before sending msg3 to the access network device during the random access process, sending the key generation request to the access network device via an uplink channel. Correspondingly, the access network device receiving the key generation request sent by the AIoT device during random access includes: after sending a random access response to the AIoT device during the random access process and before receiving msg3 from the AIoT device, receiving the key generation request from the AIoT device via an uplink channel.
[0117] The random access response carries channel indication information for determining the resource locations of the uplink and downlink channels. This channel indication information may include: the time-domain and / or frequency-domain resource locations of the uplink channel, and / or the time-domain and / or frequency-domain resource locations of the downlink channel. The uplink channel refers to the channel used by the AIoT device to transmit a key generation request to the access network device, and the downlink channel refers to the channel used by the access network device to transmit a key generation response to the AIoT device. Whether the uplink and downlink channels can also be used to transmit other types of information between the AIoT device and the access network device is not limited or exhaustively described in this embodiment. The uplink channel can be any type of uplink channel, such as PUSCH, PUCCH, etc., and is not limited or exhaustively described here. Similarly, the type of downlink channel is not limited or exhaustively described.
[0118] The method by which the access network device determines the channel indication information is not limited in this embodiment. The resource location may include time-domain resource location and / or frequency-domain resource location.
[0119] Optionally, the random access response may also carry a key generation instruction to instruct the AIoT device to generate a first key.
[0120] After powering on or waking up, AIoT devices can first achieve downlink time-frequency synchronization and obtain system-related information based on the downlink synchronization signal and PBCH broadcast by the access network device. The specific processing of achieving downlink time-frequency synchronization and obtaining system-related information based on the downlink synchronization signal and PBCH broadcast by the access network device is the same as in the aforementioned embodiments and will not be repeated here.
[0121] After obtaining system-related information, the AIoT device can perform the following processing: sending a PRACH during the random access process to the access network device. This PRACH is used to carry or transmit a preamble. Correspondingly, the access network device's processing can include: receiving the PRACH from the AIoT device during the random access process performed by the AIoT device. The method for obtaining the preamble is the same as in the aforementioned embodiments and will not be described again.
[0122] Preferably, the random access can be a four-step random access, and correspondingly, the PRACH can be used to carry the preamble included in message 1 (msg1) in the four-step random access.
[0123] After receiving a PRACH from an AIoT device, the access network device can send a random access response during the random access process to the AIoT device. This random access response carries channel indication information for the AIoT device to determine the resource locations of the uplink and downlink channels. The timing for the AIoT device to perform the process of generating a first key with the access network device based on one or more first downlink signals broadcast by the access network device can be after receiving the random access response from the access network device and before sending msg3 to the access network device.
[0124] In one example, the first downlink signal is a first downlink synchronization signal (such as a first PSS or a first SSS). The description of the first downlink synchronization signal is the same as in the previous embodiments and will not be repeated.
[0125] In this example, after receiving a random access response, the AIoT device may continue to perform the process of generating a first key with the access network device based on one or more first PSSs or first SSSs broadcast by the access network device. That is, the AIoT device restarts the detection of the first PSS or first SSS, but the first PSS or first SSS is not used for downlink time-frequency synchronization, but only for generating the first key.
[0126] In one example, the first downlink signal is a first downlink reference signal (such as a first DMRS or a first CSI-RS). The relevant description of the first downlink reference signal is the same as in the previous embodiments and will not be repeated.
[0127] In this example, after receiving a random access response, the AIoT device may continue to perform the process of generating a first key with the access network device based on one or more first DMRS carried or transmitted by one or more first PBCHs broadcast by the access network device. That is, the AIoT device restarts the detection of the first PBCH, but the first PBCH is not used to obtain system-related information; it only uses the first DMRS carried by the first PBCH to generate the first key.
[0128] Preferably, the first downlink reference signal can be a first CSI-RS or an RS in another downlink direction. The process by which the AIoT device generates a first key with the access network device based on one or more CSI-RS or other downlink direction RS broadcast by the access network device is the same as in the previous example and will not be described again.
[0129] On the AIoT device side, generating a first key with the access network device based on one or more first downlink signals broadcast by the access network device may include: measuring the one or more first downlink signals broadcast by the access network device to obtain measurement results of the one or more first downlink signals; obtaining one or more quantization reference values based on the measurement results of the one or more first downlink signals; and generating the first key with the access network device based on the one or more quantization reference values. The specific processing for generating the first key by the AIoT device is the same as in the aforementioned embodiments and will not be repeated here.
[0130] The timing of the AIoT device sending a key generation request to the access network device via the uplink channel can be before it finishes receiving the last first downlink signal and before sending msg3 during the random access process to the access network device.
[0131] The uplink channel can transmit or carry the reflected signal of the last first downlink signal, which is used to transmit the key generation request. That is, the processing of the AIoT device can include: measuring one or more first downlink signals broadcast by the access network device, obtaining measurement results for one or more first downlink signals, and transmitting the reflected signal of the last first downlink signal through the uplink channel, which is used to transmit the key generation request; then, based on the measurement results of the one or more first downlink signals, obtaining one or more quantization reference values; and generating the first key with the access network device based on the one or more quantization reference values.
[0132] Accordingly, after receiving the key generation request sent by the AIoT device during random access, the access network device may further include: obtaining the channel estimation result corresponding to the AIoT device based on the key generation request; obtaining the estimation measurement result of the one or more first downlink signals on the AIoT device based on the channel estimation result and the one or more first downlink signals; and generating the first key based on the estimation measurement result of the one or more first downlink signals on the AIoT device.
[0133] The step of obtaining the channel estimation result corresponding to the AIoT device based on the key generation request may include: determining one or more first downlink signals received by the AIoT device based on the uplink channel reception time (or reception time) of the reflected signal carrying the key generation request; and obtaining the channel estimation result corresponding to the AIoT device based on the reception strength of the reflected signal and the transmission strength of the last first downlink signal among the one or more first downlink signals.
[0134] Specifically, determining one or more first downlink signals received by the AIoT device based on the uplink channel reception time of the reflected signal carrying the key generation request can be: determining one or more first downlink signals received by the AIoT device based on the uplink channel reception time of the reflected signal carrying the key generation request and the number of first downlink signals required to generate the first key; or, determining one or more downlink signals between the transmission time of the random access response and the reception time of the uplink channel carrying the reflected signal carrying the key generation request as one or more first downlink signals received by the AIoT device.
[0135] Based on the received strength of the reflected signal and the transmitted strength of the last of one or more first downlink signals, the channel estimation result corresponding to the AIoT device can be obtained. This can be achieved by subtracting the received strength of the reflected signal from the transmitted strength of the last first downlink signal and then dividing by two. It should be understood that this is merely an exemplary method for calculating the channel estimation result. In actual processing, other methods can also be used to obtain the channel estimation result corresponding to the AIoT device; however, these are not limited or exhaustively described here.
[0136] The specific processing method for obtaining the estimated measurement results of the one or more first downlink signals in the AIoT device based on the channel estimation results and the one or more first downlink signals, and the specific processing method for generating the first key based on the estimated measurement results of the one or more first downlink signals in the AIoT device, are the same as in the previous embodiments, and therefore will not be described again.
[0137] In some embodiments, after the access network device generates the first key, the following processing may be performed: sending a key generation response to the AIoT device via a downlink channel, wherein the key generation response is used by the AIoT device to determine that the access network device has generated the first key. The processing on the AIoT device side further includes: receiving a key generation response from the access network device via a downlink channel, wherein the key generation response is used to determine that the access network device has generated the first key.
[0138] The description of the resource location of this downlink channel is the same as that in the previous embodiments, and will not be repeated here.
[0139] After receiving the key generation response on the AIoT device side, at least one of the following can be derived based on the first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device. Similarly, after the AIoT device generates the first key or receives a random access response carrying the key generation response, it may also include: deriving at least one of the following based on the first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device.
[0140] In some embodiments, the key generation response may include at least one of the following: a key correction instruction or a security algorithm instruction.
[0141] Regarding the above embodiments, the processing of the derived integrity key and / or confidentiality key of the AIoT device and the processing of the derived integrity key and / or confidentiality key of the access network device are the same as those in the aforementioned embodiments, and will not be repeated here.
[0142] In some possible implementations, the processing by the AIoT device after deriving the integrity key and / or confidentiality key may further include: sending a first RRC (Radio Resource Control) message to the access network device, wherein the first RRC message is an uplink RRC message securely protected based on at least one of the integrity key between the AIoT device and the access network device and the confidentiality key between the AIoT device and the access network device. The processing by the access network device may further include: receiving the first RRC message from the AIoT device.
[0143] The first RRC message can be msg3 during the random access process, or it can be an uplink RRC message sent after completing the two-step random access.
[0144] The first RRC message may include: a first integrity check code and uplink plaintext data; or uplink ciphertext data; or a first integrity check code and uplink ciphertext data.
[0145] The uplink plaintext data may include at least one of the following: the identifier of the AIoT device, key parameters, and a first Protocol Data Unit (PDU) containing small data. The identifier of the AIoT device can be a newly defined AIoT device ID (or simply AIoT ID) or a 5G-S-TMSI. The first PDU can be a first NAS PDU (or a NAS message containing small data) or a PDU from another protocol layer. Key parameters may include sensitive information such as a third fresh value, which can be a NAS count (COUNT) or other values, and is not exhaustively listed. It should be noted that the content included in the uplink plaintext data is illustrative, and this embodiment does not limit or exhaustively list all possible contents included in the uplink plaintext data.
[0146] The first integrity check code can be calculated from uplink plaintext or ciphertext data based on the integrity key and integrity algorithm. This integrity algorithm can be pre-configured by both the access network device and the AIoT device, or it can be determined based on a security algorithm instruction, or be a default algorithm, or be specified by the protocol. The specific calculation method for the first integrity check code and other possible parameters are not limited here.
[0147] The uplink ciphertext data can be obtained by encrypting uplink plaintext data based on a confidentiality key and a confidentiality algorithm. This confidentiality algorithm can be pre-configured by both the access network device and the AIoT device, or it can be determined based on a security algorithm instruction, a default value, or a protocol-defined value. The specific calculation method for the uplink ciphertext data and other parameters that may be used are not limited here.
[0148] The processing of the access network device after receiving the first RRC message from the AIoT device may also include one of the following:
[0149] When the first RRC message carries uplink plaintext data and the first integrity verification code, the first integrity verification code is calculated based on the uplink plaintext data and the integrity key, and the integrity of the first RRC message is verified based on the first integrity verification code and the first integrity verification code.
[0150] If the first RRC message carries uplink ciphertext data, the uplink ciphertext data is decrypted using the confidentiality key to obtain the uplink plaintext data;
[0151] When the first RRC message carries uplink ciphertext data and a first integrity verification code, the first integrity verification code is calculated based on the uplink ciphertext data and the integrity key. If the integrity of the first RRC message is verified based on the first integrity verification code and the first integrity verification code, the uplink ciphertext data is decrypted based on the confidentiality key to obtain the uplink plaintext data.
[0152] When the first RRC message carries uplink ciphertext data and a first integrity verification code, the uplink ciphertext data is decrypted based on the confidentiality key to obtain uplink plaintext data. The first integrity verification code is calculated based on the uplink plaintext data and the integrity key. The integrity of the first RRC message is verified based on the first integrity verification code and the first integrity verification code.
[0153] Based on the first integrity verification code and the first integrity check code, verifying the integrity of the first RRC message can be done as follows: if the first integrity verification code and the first integrity check code are the same, the integrity verification of the first RRC message is determined to be successful; and / or, if the first integrity verification code and the first integrity check code are different, the integrity verification of the first RRC message is determined to be unsuccessful. Furthermore, if the first RRC message carries uplink plaintext data and the first integrity check code, and the access network device determines that the integrity verification of the first RRC message is successful if the first integrity verification code and the first integrity check code are the same, then it extracts the uplink plaintext data.
[0154] The method by which access network devices calculate the first integrity verification code based on uplink plaintext data and the integrity key should be the same as the method used by AIoT devices, and will not be elaborated further. Similarly, the method by which access network devices calculate the first integrity verification code based on uplink ciphertext data and the integrity key should be the same as the method used by AIoT devices, and will not be elaborated further.
[0155] The processing of uplink plaintext data obtained by decryption by access network devices should correspond to the method of calculating uplink ciphertext data by AIoT devices, and will not be elaborated upon here.
[0156] After receiving the uplink plaintext data, the access network device may further include: sending the uplink plaintext data to the core network device, which may be carried by an N2 message. The core network device may also send the uplink plaintext data to the AF; the processing of the core network device is not limited or exhaustively described here.
[0157] In some embodiments, the processing by the access network device after receiving the uplink plaintext data may further include: sending a second RRC message to the AIoT device, wherein the second RRC message is a downlink RRC message securely protected based on at least one of a integrity key between the AIoT device and the access network device and a confidentiality key between the AIoT device and the access network device. The processing by the AIoT device may further include: receiving the second RRC message from the access network device.
[0158] The second RRC message can be msg4 during the random access process, or it can be a downlink RRC message sent after the two-step random access is completed.
[0159] The second RRC message may include: a second integrity check code and downlink plaintext data; or downlink ciphertext data; or a second integrity check code and downlink ciphertext data.
[0160] The processing of the access network device may further include: receiving downlink plaintext data from the core network device, which may be carried by an N2 message. The core network device may refer to any type of core network device in 5GC, such as an AMF (Access and Mobility Management Function) and / or an AIoTF (AIoT Function), but this embodiment does not limit it.
[0161] The downlink plaintext data may include at least one of the following: a command to the AIoT device (such as an inventory command, a write command, a read command, etc.), data content written to the AIoT device, the identifier of the AIoT device, a second Protocol Data Unit (PDU), and a second count value. The second PDU may be a second NAS PDU or a PDU from another protocol layer. The second count value may be a NAS count value (COUNT) or another type of count value. It should be noted that the above descriptions of the AIoT device identifier, the second PDU, and the second count value are merely illustrative, and the content included in the downlink plaintext data is also illustrative. This embodiment does not limit or exhaustively list all possible contents included in the downlink plaintext data.
[0162] The second integrity verification code can be calculated from downlink plaintext data or downlink ciphertext data based on the integrity key and integrity algorithm. The integrity algorithm can be pre-configured by both the access network device and the AIoT device, or it can be determined by the access network device and indicated to the AIoT device through a security algorithm, or it can be the default algorithm, or it can be specified by the protocol. As long as the AIoT device and the access network device are consistent, it is within the protection scope of this embodiment. The specific calculation method of the second integrity verification code and other possible parameters are not limited here.
[0163] The downlink ciphertext data can be obtained by encrypting downlink plaintext data based on a confidentiality key and a confidentiality algorithm. This confidentiality algorithm can be pre-configured by both the access network device and the AIoT device, or it can be determined by the access network device and instructed to the AIoT device through a secure algorithm, or it can be the default algorithm, or it can be specified by the protocol. As long as the AIoT device and the access network device are consistent, it is within the protection scope of this embodiment. The specific calculation method for the downlink ciphertext data and other parameters that may be used are not limited here.
[0164] The processing of the AIoT device after receiving the second RRC message from the access network device may also include one of the following:
[0165] When the second RRC message carries downlink plaintext data and a second integrity verification code, the second integrity verification code is calculated based on the downlink plaintext data and the integrity key. Based on the second integrity verification code and the second integrity verification code, the integrity of the second RRC message is verified.
[0166] In the case where the second RRC message carries downlink ciphertext data, the downlink ciphertext data is decrypted using the confidentiality key to obtain the downlink plaintext data;
[0167] When the second RRC message carries downlink ciphertext data and a second integrity verification code, the second integrity verification code is calculated based on the downlink ciphertext data and the integrity key. If the integrity of the second RRC message is verified based on the second integrity verification code and the second integrity verification code, the downlink ciphertext data is decrypted based on the confidentiality key to obtain the downlink plaintext data.
[0168] When the second RRC message carries downlink ciphertext data and a second integrity verification code, the downlink ciphertext data is decrypted using the confidentiality key to obtain downlink plaintext data. The second integrity verification code is calculated based on the downlink plaintext data and the integrity key. The integrity of the second RRC message is verified based on the second integrity verification code and the second integrity verification code.
[0169] Specifically, verifying the integrity of the second RRC message based on the second integrity verification code and the second integrity check code can include: if the second integrity verification code and the second integrity check code are the same, determining that the verification of the integrity of the second RRC message is successful; and / or, if the second integrity verification code and the second integrity check code are different, determining that the verification of the integrity of the second RRC message has failed. Furthermore, if the second RRC message carries downlink plaintext data and the second integrity check code, and the AIoT device determines that the verification of the integrity of the second RRC message is successful, it directly extracts the downlink plaintext data.
[0170] The above-described processing of the AIoT device after receiving the second RRC message is similar to the processing of the access network device after receiving the first RRC message in the previous embodiment, and will not be described in detail.
[0171] The communication method provided in this application embodiment will be described below with reference to Figure 4, specifically including:
[0172] Step 400: The read / write device (e.g., access network equipment such as a base station) periodically sends downlink synchronization signals PSS / SSS. In addition, the read / write device can also broadcast PBCH (e.g., PBCH may include MIB, etc.) and PDCH (e.g., it may carry SIB, such as SIB1 and OSI, etc.).
[0173] Step 401: The AIoT device detects PSS and SSS to obtain downlink time-frequency synchronization and PCID, then decodes PBCH to obtain MIB and other system information; the AIoT device measures one or more downlink reference signals (e.g., DMRS) to obtain the RSSI of one or more downlink reference signals; based on the RSSI of one or more downlink reference signals, the AIoT device generates the AIoT terminal key K. AIoT (i.e., the first key generated by the AIoT device in the aforementioned embodiment).
[0174] Here, the AIoT device generates the key K for the AIoT terminal based on the RSSI of one or more downlink reference signals. AIoT The processing is the same as in the aforementioned embodiments, and this embodiment does not limit the quantization methods involved. Furthermore, the AIoT device's measurement of RSSI can be replaced by measuring other content. For example, if the AIoT device has strong capabilities, it can also perform channel estimation to obtain measurements such as CSI. Here, we do not limit or exhaustively list all possible types of content that the AIoT device can measure.
[0175] Step 402: The AIoT device selects a preamble based on the SIB information and sends a PRACH.
[0176] Step 403: The read / write device performs channel estimation based on the PRACH sent by the AIoT device to obtain the estimated RSSI of the AIoT device; based on the estimated RSSI (or other channel characteristic values), it generates the key K for the Reader end. Reader (i.e., the first key generated by the access network device in the aforementioned embodiment).
[0177] Step 404: The read / write device sends a Random Access Response (RAR) message through the PDSCH channel. The RAR message may include a key negotiation indication, and optionally a security algorithm indication. For example, the key negotiation indication may instruct the AIoT device to use the offset sent by the Reader for key correction; the security algorithm indication (or air interface security algorithm indication) is used to instruct the AIoT device to use a certain algorithm as the initial air interface security algorithm, such as AES, etc.
[0178] Step 405: Based on the negotiated physical layer key (i.e., the adjusted first key in the aforementioned embodiment), the AIoT device derives the integrity protection key (hereinafter referred to as the integrity protection key) and the encryption key. Based on the integrity protection key, the encryption key (and the security algorithm indication (or pre-shared security algorithm)), the AIoT device's ID, key parameters (such as NAS COUNT), and NAS messages containing small data (uplink NAS-PDU) are encrypted and protected for integrity. An encrypted and integrity-protected uplink RRC message is generated and sent to the read / write device. For example, the uplink RRC message may contain the AIoT device's ID, uplink NAS-PDU, NAS COUNT, and the first MAC (i.e., the first integrity check code).
[0179] The NAS-PDU can be securely protected or insecurely protected, depending on whether the AIoT has a NAS security context. The calculation parameters used during encryption and integrity calculations can include NAS COUNT.
[0180] Step 406: Based on the negotiated physical layer key (i.e., the adjusted first key in the aforementioned embodiment), the read / write device derives the integrity key and encryption key, and uses the integrity key and encryption key to perform integrity verification and decryption on the uplink RRC message to obtain the AIoT device ID, uplink NAS-PDU, and NAS COUNT.
[0181] Step 407: The read / write device sends the decrypted NAS-PDU, ID, and other information as uplink data (or uplink plaintext data) to the core network device (5GC), such as AMF / AIoTF, via N2 message (or a newly defined message).
[0182] Step 408: If the core network device (5GC) writes downlink data to the AIoT device, it sends the data to the read / write device via an N2 message.
[0183] Step 409: The read / write device, based on the integrity protection key and encryption key, and the corresponding security algorithm, encrypts and protects the AIoT device's ID and downlink NAS-PDU messages (NAS-PDUs containing downlink data), generates and sends an encrypted and integrity-protected downlink RRC message to the AIoT device. This downlink RRC message includes the AIoT ID, downlink NAS-PDU, NAS COUNT, and a second MAC (i.e., a second integrity verification code). Here, the calculation parameters used during encryption and integrity protection calculations may include the NAS COUNT, which can be updated using a hop-by-hop increment method.
[0184] Step 410: The AIoT device performs integrity verification and decryption on the received downlink RRC message based on the integrity key and encryption key, and obtains information such as AIoT ID and downlink NAS-PDU.
[0185] The communication method provided in this application embodiment will be described again below with reference to Figure 5, specifically including:
[0186] Step 500 is the same as step 400, and will not be described in detail.
[0187] Step 501: The AIoT device detects PSS and SSS to obtain downlink time-frequency synchronization and PCID, then decodes PBCH to obtain MIB and other system information; based on the SIB information, it selects a preamble to send PRACH.
[0188] Step 502: The reading and writing device allocates channel information and sends it to the AIoT device through a random access response. The random access response includes a key generation instruction and channel indication information. The channel indication information is used by the AIoT device to determine the resource locations of the uplink channel and the downlink channel, and the key generation instruction is used to instruct the AIoT device to generate a physical layer key (first key).
[0189] Step 503: The AIoT device measures one or more downlink reference signals based on the received random access response, and obtains the RSSI of one or more downlink reference signals; the AIoT device quantizes based on the RSSI of one or more downlink reference signals to generate the AIoT device's key K. AIoT (i.e., the first key generated by the AIoT device in the aforementioned embodiment).
[0190] Step 504: AIoT sends a key generation request based on the channel indication information. The key generation request can be sent via an uplink channel, which can be PUSCH, PUCCH, or any type of uplink channel. The uplink channel is determined based on the channel indication information. The key generation request can be transmitted via the backscattered signal (reflected signal) of the downlink reference signal carried by the uplink channel.
[0191] Step 505: Based on the key generation request sent by the AIoT device, the read / write device measures one or more measurement reference signals (for example, the read / write device can obtain the transmission parameters of the downlink reference signal used by the AIoT device to generate the key), performs channel estimation, and obtains the estimated RSSI for the AIoT device; based on the estimated RSSI (or other channel characteristic values), the read / write device generates the key K. Reader (i.e., the first key generated by the access network device in the aforementioned embodiment).
[0192] Step 506: The read / write device sends a key generation response, which may include a key negotiation instruction and optionally a security algorithm instruction. This key generation response can be sent via a downlink channel.
[0193] Steps 507 to 513 are the same as steps 405 to 410, and will not be repeated here.
[0194] The solution provided in this application embodiment allows the AIoT device to generate a first key with the access network device based on the downlink signal broadcast by the access network device. In this way, the AIoT device can use the first key for security protection when transmitting messages with the access network device over the air interface, thereby ensuring the security of messages transmitted by the AIoT device over the air interface.
[0195] Furthermore, the solution provided in this application allows the AIoT device to generate a first key by measuring the downlink synchronization signal before random access. This first key can be generated by the access network device via PRACH during the random access process, or via a designated uplink channel during the random access process (after receiving the random access response but before sending msg3). Additionally, the access network device can instruct the AIoT device to perform key negotiation via the random access response (RAR) (or via the downlink channel before receiving msg3), thereby ensuring key consistency between the AIoT device and the access network device. Furthermore, the AIoT device and the access network device use the first key to further derive an integrity protection key and / or a confidentiality key, enabling encryption and integrity protection of the RRC message containing the user identifier and NAS message. This allows the AIoT device to achieve secure protection of the AS message during the initial access phase, preventing the leakage of sensitive information such as user identification (e.g., 5G-S-TMSI) and key parameters (e.g., fresh value) during communication.
[0196] Figure 6 is a schematic diagram of the composition structure of an AIoT device according to an embodiment of this application, including:
[0197] The first processing unit 601 is used to generate a first key with the access network device based on one or more first downlink signals broadcast by the access network device.
[0198] The first processing unit is configured to measure the one or more first downlink signals broadcast by the access network device, and obtain measurement results of the one or more first downlink signals; based on the measurement results of the one or more first downlink signals, obtain one or more quantization reference values; and based on the one or more quantization reference values, generate the first key between the access network device and the access network device.
[0199] First downlink synchronization signal or first downlink reference signal.
[0200] As shown in Figure 6, the AIoT device also includes:
[0201] The first communication unit 602 is used to send a key generation request to the access network device during random access, wherein the key generation request is used to instruct the access network device to generate the first key.
[0202] The key generation request is carried by the Physical Random Access Channel (PRACH).
[0203] The first communication unit is configured to send one or more PRACHs to the access network device during random access, wherein the number of the one or more PRACHs is the same as the number of the one or more first downlink signals, and at least one of the one or more PRACHs is used to carry the key generation request.
[0204] The first communication unit is configured to receive a random access response from the access network device, wherein the random access response carries a key generation response, and the key generation response is used to determine that the access network device generates the first key.
[0205] The first communication unit is configured to send the key generation request to the access network device via the uplink channel after receiving the random access response from the access network device during the random access process and before sending msg3 to the access network device.
[0206] The first communication unit is configured to receive a key generation response from the access network device via a downlink channel, wherein the key generation response is used to determine that the access network device generates the first key.
[0207] The random access response carries channel indication information for determining the resource locations of the uplink and downlink channels.
[0208] The first processing unit is configured to derive at least one of the following based on the first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device.
[0209] Figure 7 is a schematic diagram of the composition structure of an access network device according to an embodiment of this application, including:
[0210] The second communication unit 701 is used to broadcast one or more first downlink signals, wherein the one or more first downlink signals are used by the environmental Internet of Things (AIoT) device to generate a first key with the access network device.
[0211] The first downlink signal includes: a first downlink synchronization signal or a first downlink reference signal.
[0212] The second communication unit is configured to receive a key generation request sent by the AIoT device during random access, wherein the key generation request is used to instruct the access network device to generate the first key.
[0213] The key generation request is carried by the Physical Random Access Channel (PRACH).
[0214] As shown in Figure 7, the access network device further includes:
[0215] The second processing unit 702 is configured to obtain the channel estimation result corresponding to the AIoT device based on the PRACH; obtain the estimation measurement result of the one or more first downlink signals in the AIoT device based on the channel estimation result and the one or more first downlink signals; and generate the first key based on the estimation measurement result of the one or more first downlink signals in the AIoT device.
[0216] The second communication unit is configured to receive one or more PRACHs sent by the AIoT device during random access, wherein the number of the one or more PRACHs is the same as the number of the one or more first downlink signals, and at least one of the one or more PRACHs is used to carry the key generation request.
[0217] The second processing unit is configured to obtain a channel estimation result corresponding to the AIoT device based on at least one of the one or more PRACHs; obtain an estimation measurement result of the one or more first downlink signals in the AIoT device based on the channel estimation result and the one or more PRACHs; and generate the first key based on the estimation measurement result of the one or more first downlink signals in the AIoT device.
[0218] The second communication unit is configured to send a random access response to the AIoT device, wherein the random access response carries a key generation response, and the key generation response is used by the AIoT device to determine that the access network device generates the first key.
[0219] The second communication unit is configured to receive the key generation request from the AIoT device via an uplink channel after sending a random access response to the AIoT device during the random access process and before receiving msg3 from the AIoT device.
[0220] The second processing unit is configured to obtain a channel estimation result corresponding to the AIoT device based on the key generation request; obtain an estimation measurement result of the one or more first downlink signals in the AIoT device based on the channel estimation result and the one or more first downlink signals; and generate the first key based on the estimation measurement result of the one or more first downlink signals in the AIoT device.
[0221] The second communication unit is configured to send a key generation response to the AIoT device via a downlink channel, wherein the key generation response is used by the AIoT device to determine that the access network device has generated the first key.
[0222] The random access response carries channel indication information for the AIoT device to determine the resource locations of the uplink and downlink channels.
[0223] The second processing unit is configured to obtain one or more quantized estimates based on the estimated measurement results of the one or more first downlink signals in the AIoT device; and generate the first key based on the one or more quantized estimates.
[0224] The second processing unit is configured to derive at least one of the following based on the first key: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device.
[0225] The device in this application embodiment can realize the corresponding functions of the various devices in the foregoing communication method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).
[0226] It should be understood that the sequence number of each process in the various embodiments of this application does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The above descriptions are merely specific embodiments of this application, and the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method performed by an environmental Internet of Things (AIoT) device, comprising: A first key is generated between the access network device and the access network device based on one or more first downlink signals broadcast by the access network device.
2. The method according to claim 1, wherein, The generation of a first key with the access network device based on one or more first downlink signals broadcast by the access network device includes: Measure the one or more first downlink signals broadcast by the access network device to obtain the measurement results of the one or more first downlink signals; Based on the measurement results of the one or more first downlink signals, one or more quantization reference values are obtained; Based on the one or more quantization reference values, a first key is generated between the device and the access network device.
3. The method according to claim 1 or 2, wherein, The first downlink signal includes: a first downlink synchronization signal or a first downlink reference signal.
4. The method according to any one of claims 1-3, wherein, The method further includes: During random access, a key generation request is sent to the access network device, wherein the key generation request is used to instruct the access network device to generate the first key.
5. The method according to claim 4, wherein, The key generation request is carried by the Physical Random Access Channel (PRACH).
6. The method according to claim 4, wherein, Sending a key generation request to the access network device during the random access process includes: During random access, one or more PRACHs are sent to the access network device, wherein the number of the one or more PRACHs is the same as the number of the one or more first downlink signals, and at least one of the one or more PRACHs is used to carry the key generation request.
7. The method according to claim 5 or 6, wherein, The method further includes: The system receives a random access response from the access network device, wherein the random access response carries a key generation response, and the key generation response is used to determine whether the access network device generates the first key.
8. The method according to claim 4, wherein, Sending a key generation request to the access network device during the random access process includes: After receiving the random access response from the access network device during the random access process and before sending msg3 to the access network device, the key generation request is sent to the access network device via the uplink channel.
9. The method according to claim 8, wherein, The method further includes: The access network device receives a key generation response via a downlink channel, wherein the key generation response is used to determine that the access network device generates the first key.
10. The method according to claim 9, wherein, The random access response carries channel indication information for determining the resource locations of the uplink and downlink channels.
11. The method according to any one of claims 1-10, wherein, The method further includes: Based on the first key, at least one of the following can be derived: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device.
12. A communication method performed by an access network device, comprising: Broadcast one or more first downlink signals, wherein the one or more first downlink signals are used by the environmental Internet of Things (AIoT) device to generate a first key with the access network device.
13. The method according to claim 12, wherein, The first downlink signal includes: a first downlink synchronization signal or a first downlink reference signal.
14. The method according to claim 12 or 13, wherein, The method further includes: The system receives a key generation request sent by the AIoT device during random access, wherein the key generation request is used to instruct the access network device to generate the first key.
15. The method according to claim 14, wherein, The key generation request is carried by the Physical Random Access Channel (PRACH).
16. The method according to claim 15, wherein, The method further includes: Based on the PRACH, the channel estimation result corresponding to the AIoT device is obtained; Based on the channel estimation results and the one or more first downlink signals, the estimated measurement results of the one or more first downlink signals in the AIoT device are obtained; The first key is generated based on the estimated measurement results of the one or more first downlink signals in the AIoT device.
17. The method of claim 14, wherein, The step of receiving the key generation request sent by the AIoT device during the random access process includes: Receive one or more PRACH messages sent by the AIoT device during the random access process, wherein the one or more PRACH messages... The number is the same as the number of the one or more first downlink signals, and at least one of the one or more PRACHs is used to carry the key generation request.
18. The method according to claim 17, wherein, The method further includes: Based on at least one of the one or more PRACHs, the channel estimation result corresponding to the AIoT device is obtained; Based on the channel estimation results and the one or more PRACHs, the estimated measurement results of the one or more first downlink signals in the AIoT device are obtained; The first key is generated based on the estimated measurement results of the one or more first downlink signals in the AIoT device.
19. The method according to claim 16 or 18, wherein, The method further includes: A random access response is sent to the AIoT device, wherein the random access response carries a key generation response, and the key generation response is used by the AIoT device to determine that the access network device generates the first key.
20. The method of claim 14, wherein, The step of receiving the key generation request sent by the AIoT device during the random access process includes: After sending a random access response to the AIoT device during the random access process and before receiving msg3 from the AIoT device, the key generation request from the AIoT device is received via the uplink channel.
21. The method according to claim 20, wherein, The method further includes: Based on the key generation request, the channel estimation result corresponding to the AIoT device is obtained; Based on the channel estimation results and the one or more first downlink signals, the estimated measurement results of the one or more first downlink signals in the AIoT device are obtained; The first key is generated based on the estimated measurement results of the one or more first downlink signals in the AIoT device.
22. The method according to claim 21, wherein, The method further includes: A key generation response is sent to the AIoT device via a downlink channel, wherein the key generation response is used by the AIoT device to determine that the access network device has generated the first key.
23. The method according to claim 22, wherein, The random access response carries channel indication information for the AIoT device to determine the resource locations of the uplink and downlink channels.
24. The method according to any one of claims 16, 18, 19, 21-23, wherein, The process of generating the first key based on the estimated measurement results of the one or more first downlink signals in the AIoT device includes: Based on the estimated measurement results of the one or more first downlink signals in the AIoT device, one or more quantized estimates are obtained; The first key is generated based on the one or more quantization estimates.
25. The method according to any one of claims 16, 18, 19, 21-24, wherein, The method further includes: Based on the first key, at least one of the following can be derived: a security key between the AIoT device and the access network device, and a confidentiality key between the AIoT device and the access network device.
26. An environmental Internet of Things (AIoT) device, comprising: The first processing unit is configured to generate a first key with the access network device based on one or more first downlink signals broadcast by the access network device.
27. An access network device, comprising: The second communication unit is used to broadcast one or more first downlink signals, wherein the one or more first downlink signals are used by the environmental Internet of Things (AIoT) device to generate a first key with the access network device.
Citation Information
Patent Citations
Key updating method, device and equipment
CN110868294A
Method and apparatus for identifying security key in next generation mobile communication system
CN112740731A
Internet of Things security authentication method, device and system based on identification cryptographic algorithm
CN114928491A
HARDWARE IDENTIFICATION-BASED SECURITY AUTHENTICATION SERVICE FOR IoT DEVICES
US20180338242A1
Use of encryption for secure communication exchanges
US7788491B1