Communication method, communication apparatus and communication system

By receiving indication information in A-IoT devices to determine whether to generate a key, the complexity and power consumption issues in existing technologies are resolved, achieving a highly efficient and energy-saving solution for security protection.

WO2026032092A1PCT designated stage Publication Date: 2026-02-12HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/111209
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2025-07-29
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing secure activation solutions are complex in environment IoT (A-IoT) scenarios where terminal devices have limited capabilities, leading to increased power consumption, design complexity, and storage latency, making them difficult to apply.

Method used

The system determines whether to generate a key by receiving instruction information, and generates keys only in scenarios requiring security protection, reducing the overhead of computing and storing security parameters.

Benefits of technology

This reduces the device's additional power consumption and design complexity, saving computing and storage resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025111209_12022026_PF_FP_ABST
    Figure CN2025111209_12022026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a communication method and a communication apparatus. The communication method comprises: receiving first indication information, wherein the first indication information is used for indicating a service type of communication between a first device and a second device and / or used for indicating the execution of a security operation, the service type comprises at least one first service, the first service comprises a procedure of completing data transmission on the basis of the security operation, and the security operation comprises encryption protection and / or integrity protection; and on the basis of the first indication information, generating a first key, wherein the first key is used for security protection of communication between the first device and the second device. In the technical solution, the additional power consumption and design complexity of devices can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method, a communication apparatus, and a communication system

[0001] The present application claims priority from the Chinese patent application No. 202411097627.3 filed on August 9, 2024, and entitled "A communication method, a communication apparatus, and a communication system", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication technology, and more particularly, to a communication method, a communication apparatus, and a communication system. BACKGROUND

[0003] In one possible implementation, security activation / security mode control (SMC) can be used to activate the security interaction of information between the terminal side and the network side, including non-access stratum (NAS) SMC and access stratum (AS) SMC. For example, the security activation / SMC process mainly completes the negotiation of the security algorithm used by the terminal side and the network side, and generates the keys required by the corresponding security algorithm based on KASME or KeNB. For example, in the security activation scheme of 5G NR, the security complexity is improved by adding a lot of "intermediate" keys between the network side and the terminal side, which guarantees the security of communication. For example, the "intermediate" keys can include KAUSF, KSEAF, KAMF, KgNB, signaling encryption key KRRCenc, and integrity protection key KRRCint, etc.

[0004] However, the above security activation scheme is relatively complex, for example, a large number of keys need to be generated, updated or stored, and the interaction process of security activation is complex. Therefore, the current security activation scheme is difficult to apply to scenarios such as ambient internet of things (A-IoT) technology, where the terminal device has weak capabilities, otherwise it will bring additional power consumption, design complexity, and large inventory delay to the terminal device with limited capabilities. SUMMARY

[0005] The present application provides a communication method and a communication apparatus, which can reduce the additional power consumption and design complexity of the device.

[0006] In a first aspect, an embodiment of the present application provides a communication method, which can be executed by a first device such as an electronic tag device or an A-IoT terminal device, or can be executed by a module in the first device such as a chip system or a circuit, or can be executed by a logic node, a logic module or software capable of realizing all or part of the functions of the first device, and the present application does not make any limitation in this regard.

[0007] The method comprises: receiving first indication information, the first indication information being used for indicating a service type of communication between the first device and a second device and / or for indicating execution of a security operation, the service type comprising at least one first service, the first service comprising a flow of completing data transmission based on the security operation, the security operation comprising encryption protection and / or integrity protection; and generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

[0008] In the above technical solution, the first device generates the first key only in a scenario where the first device needs to generate the first key, i.e., the first device generates the first key only when the first indication information is received. In a scenario where security protection is not needed, the first device does not receive any indication of security protection, and thus does not generate the first key, thereby saving the first device from the overhead of calculating and storing the first key and other security parameters.

[0009] Optionally, the flow of completing data transmission can comprise uplink data transmission or downlink data transmission between the first device and the second device. When the data transmission between the first device and the second device comprises a third device as an intermediate node, the flow of completing data transmission can also comprise uplink data transmission or downlink data transmission between the first device and the third device.

[0010] Optionally, the security operation can also comprise anti-replay attack or anti-tampering, etc.

[0011] Optionally, in some other cases of the embodiments of the present application, the first device can receive second indication information, the second indication information being used for indicating that the security operation is not executed and / or for indicating that the service type of communication between the first device and the second device does not comprise the first service, i.e., the service of communication between the first device and the second device does not comprise the flow of completing data transmission based on the security operation. Then, the first device can not execute the security operation according to the second indication information. Not executing the security operation can comprise at least one of the following flows: discarding or releasing security parameters, not generating a session key used for data transmission, not encrypting (all or part of) data transmission, and not performing integrity protection on (all or part of) data transmission.

[0012] Optionally, the service type of the communication between the first device and the second device includes, but is not limited to, inventory service, command service, read service, write service, lock service, positioning service, proximity determination service, sensor service, kill or disable service, and device number inventory service. The first service can be one or more of the read service, the write service, the lock service, and the kill or disable service, which have higher security requirements.

[0013] Optionally, the first indication information can also be indicated by security level information or the like to perform a security operation.

[0014] In some implementations, the receiving the first indication information includes receiving a first message for paging, selecting, or triggering at least one device, the at least one device including the first device, the first message including the first indication information.

[0015] The first message can be a paging message, which can include a Paging message or select signaling. The Paging message can be used to instruct the tag to access the reader, or the Paging message can also be used to trigger / instruct the tag to send uplink data, or to trigger / instruct / request the tag to perform any of the following services or processes: paging service, inventory service, command service (such as read, write, kill, lock, etc.), positioning service, and sensor service.

[0016] In some implementations, the generating the first key includes generating the first key after receiving the first message, or receiving a second message for indicating that the first device successfully accesses the third device, and generating the first key.

[0017] In the above technical solution, when the first key is generated after receiving the second message, the temporary storage time of the first key can be reduced, and thus the storage overhead of the first device can be reduced.

[0018] In some implementations, the receiving the first indication information includes sending first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information, and receiving first downlink data including the first indication information.

[0019] In some embodiments, the method further comprises: receiving a first parameter, the first parameter being used for security protection of the first identification information; and sending first uplink data, the first uplink data comprising the first identification information after security protection.

[0020] In some embodiments, the method further comprises: releasing the first key after a first storage time elapses after the first key is generated; or receiving a third message or a fourth message, the third message being used to indicate or trigger a next access opportunity of the first device, and the fourth message being used to indicate to release a stored security parameter and / or key; and releasing the first key.

[0021] Optionally, releasing the first key can be that the first device does not continue to save information related to the first key, or flushes information / caches / memory related to the first key, or discards information related to the first key.

[0022] Optionally, the third message can be a Query message or a QueryRep message. In addition, in some other embodiments of the present application, the third message, such as the Query message or the QueryRep message, can also indicate whether to release the key, such as by indicating through a MAC CE or a MAC header or other AS layer field.

[0023] In the above technical solution, by releasing the first key, the overhead of the first device storing the first key and other security parameters is saved.

[0024] In some embodiments, in the case of releasing the first key after the first storage time elapses, the method further comprises: determining the first storage time according to capability information of the first device; or receiving fourth indication information, the fourth indication information being used to indicate the first storage time.

[0025] In some embodiments, the method further comprises: receiving fifth indication information, the fifth indication information being used to indicate that the first device extends the storage time of the first key.

[0026] Optionally, the fifth indication information can carry a temporary identifier (such as an access stratum identifier (AS ID)), the temporary identifier being used for the second device to schedule the first device multiple times. The fifth indication information can be used to instruct the first device to save the first key after receiving the aforementioned temporary identifier, and the time of saving can be specified by the second device.

[0027] In some embodiments, before the first key is generated, the method further comprises: sending a request message, the request message being used for the first device to request to delay generating the first key.

[0028] In some embodiments, the method further includes receiving an acknowledgement response message for the request message, the acknowledgement response message indicating that the first device is allowed to delay generating the first key; and after a first time period, receiving a re-access indication message or a reschedule indication message, the re-access indication message indicating that the first device re-accesses to a third device, and the reschedule indication message indicating that the third device reschedules the first device.

[0029] In some embodiments, the method further includes receiving a negative response message for the request message, the negative response message indicating that the first device is not allowed to delay generating the first key; and receiving a sixth indication message, the sixth indication message indicating that the first device re-accesses to a third device after a second time period or after a next paging.

[0030] Optionally, the next paging can be determined by identification information carried in the paging message. For example, the identification information can identify whether the paging message is a retransmission paging message (or current service without initiating a new service) or a newly transmitted paging message (initiating a new service). For another example, the next paging can also be identified or associated with a service triggered by the current paging message by a service identifier (or also referred to as a session identifier, a task identifier, etc., and the application does not limit the name of the identifier). For example, a service identifier = 0 represents a current service without initiating a new service, and when the tag receives a paging message carrying a service identifier = 1, it is determined as a new paging or next paging.

[0031] In some embodiments, the first key is used for encryption protection and / or integrity protection.

[0032] In some embodiments, the first device generating the first key includes: receiving a second parameter, the second parameter being a parameter generated by the second device for key generation; and generating the first key according to the second parameter and a third parameter, the third parameter being a parameter generated by the first device for key generation.

[0033] In some embodiments, the first device is an ambient Internet of Things (A-IoT) device.

[0034] In a second aspect, an embodiment of the present application provides a communication method, which can be executed by a second device such as a core network device, or can be executed by a module such as a chip system or a circuit in the second device, or can be executed by a logic node, a logic module or software capable of realizing all or part of the functions of the second device, and the present application does not limit this.

[0035] The method comprises: sending first indication information, the first indication information being used for indicating a service type of communication between the first device and the second device and / or being used for indicating execution of a security operation, the service type comprising at least one first service, the first service comprising a flow of completing data transmission based on the security operation, the security operation comprising encryption protection and / or integrity protection; and generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

[0036] In the technical solution described above, the first device generates the first key only in a scenario where the first device needs to generate the first key, that is, the first device generates the first key only when the first indication information is received. In a scenario where security protection is not needed, the first device does not receive any indication of security protection, and therefore does not generate the first key, thereby saving the first device from the overhead of calculating and storing the first key and other security parameters.

[0037] Optionally, the second device can be a core network device, an access network device such as a base station, or a terminal device, or the second device can also be a server (third party) such as an Internet of Things server.

[0038] In some implementations, the method further comprises: sending third indication information, the third indication information being used for indicating a time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and receiving the third parameter through a first transport block, wherein a time-frequency resource of the first transport block comprises a time-frequency resource of the third parameter.

[0039] In some implementations, the method further comprises: sending seventh indication information, the seventh indication information being used for indicating that a third device sends a second parameter buffered by the third device to the first device, the second parameter being a parameter generated by the second device for key generation.

[0040] In some implementations, the sending of the first indication information comprises: sending a first message, the first message being used for paging, selecting, or triggering at least one device, the at least one device comprising the first device, the first message comprising the first indication information.

[0041] In some implementations, the sending of the first indication information comprises: receiving first uplink data, the first uplink data comprising first identification information of the first device, the first identification information being used by the second device to determine the first indication information; and sending first downlink data, the first downlink data comprising the first indication information.

[0042] In some implementations, the method further comprises: sending a first parameter, the first parameter being used for security protection of the first identification information of the first device; and receiving first uplink data, the first uplink data comprising the first identification information after security protection.

[0043] In some embodiments, the method further includes sending fourth indication information, the fourth indication information being used to indicate the first storage time.

[0044] In some embodiments, the method further includes sending fifth indication information, the fifth indication information being used to indicate that the first device prolongs the storage time of the first key.

[0045] In some embodiments, before generating the first key, the method further includes receiving a request message, the request message being used to request the first device to delay generating the first key.

[0046] In some embodiments, the method further includes sending an acknowledgement message for the request message, the acknowledgement message being used to indicate that the first device is allowed to delay generating the first key.

[0047] In some embodiments, the method further includes sending a negative acknowledgement message for the request message, the negative acknowledgement message being used to indicate that the first device is not allowed to delay generating the first key; and sending sixth indication information, the sixth indication information being used to indicate that the first device re-enters the third device after a second time period elapses or after a next paging message is received.

[0048] The communication method provided by the second aspect has the same explanation and advantages as the communication method provided by the first aspect, which will not be repeated here.

[0049] In the third aspect, the embodiments of the present application provide a communication method, which can be executed by a third device such as a network device, a terminal device or a reader, or can be executed by a module in the third device such as a chip system or a circuit, or can be executed by a logic node, a logic module or software which can realize all or part of the functions of the third device, and the present application does not make any limitation in this regard.

[0050] The method includes receiving third indication information, the third indication information being used to indicate a time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and sending the third parameter through a first transport block, wherein a time-frequency resource of the first transport block includes a time-frequency resource of the third parameter.

[0051] In some embodiments, the method further includes receiving seventh indication information, the seventh indication information being used to indicate that the third device sends a buffered second parameter to the first device, the second parameter being a parameter generated by the second device for key generation; and sending the buffered second parameter to the first device.

[0052] In a fourth aspect, a communication apparatus is provided. The apparatus comprises: a transceiver configured to: receive first indication information, the first indication information being used to indicate a service type of a communication between the first apparatus and a second apparatus, and / or being used to indicate a security operation to be performed, the service type comprising at least one first service, the first service comprising a procedure for completing a data transmission based on the security operation, the security operation comprising ciphering protection and / or integrity protection; and a processing unit configured to: generate, according to the first indication information, a first key, the first key being used for security protection of the communication between the first apparatus and the second apparatus.

[0053] In some embodiments, the transceiver is specifically configured to: receive a first message, the first message being used to page, select or trigger at least one apparatus, the at least one apparatus comprising the first apparatus, the first message comprising the first indication information.

[0054] In some embodiments, the processing unit is specifically configured to: generate the first key after receiving the first message; or, receive a second message, the second message being used to indicate that the first apparatus successfully accesses to a third apparatus; and generate the first key.

[0055] In some embodiments, the processing unit is specifically configured to: send first uplink data, the first uplink data comprising first identification information of the first apparatus, the first identification information being used by the second apparatus to determine the first indication information; and receive first downlink data, the first downlink data comprising the first indication information.

[0056] In some embodiments, the transceiver is further configured to: receive a first parameter, the first parameter being used for security protection of the first identification information of the first apparatus; and send first uplink data, the first uplink data comprising the first identification information after security protection.

[0057] In some embodiments, the processing unit is further configured to: release the first key after a first storage time; or, the transceiver is further configured to receive a third message or a fourth message, the third message being used to indicate or trigger a next access opportunity of the first apparatus, the fourth message being used to indicate to release a stored security parameter and / or key; and the processing unit is further configured to release the first key.

[0058] In some embodiments, in a case that the first key is released after the first storage time, the processing unit is further configured to: determine the first storage time according to capability information of the first apparatus; or, the transceiver is further configured to receive fourth indication information, the fourth indication information being used to indicate the first storage time.

[0059] In some embodiments, the transceiver is further configured to receive fifth indication information, the fifth indication information being used to instruct the first device to extend the storage time of the first key.

[0060] In some embodiments, before the processing unit generates the first key, the transceiver is further configured to: the method further includes sending a request message, the request message being used to request the first device to delay generating the first key.

[0061] In some embodiments, the transceiver is further configured to: receive an acknowledgement message in response to the request message, the acknowledgement message being used to indicate that the first device is allowed to delay generating the first key; after a first time period, receive a re-entry indication message or a rescheduling indication message, the re-entry indication message being used to instruct the first device to re-enter a third device, the rescheduling indication message being used to instruct the third device to reschedule the first device.

[0062] In some embodiments, the transceiver is further configured to: receive a negative acknowledgement message in response to the request message, the negative acknowledgement being used to indicate that the first device is not allowed to delay generating the first key; receive a sixth indication message, the sixth indication message being used to instruct the first device to re-enter the third device after a second time period or after receiving a next paging message.

[0063] In some embodiments, the processing unit is specifically configured to: receive a second parameter, the second parameter being a parameter generated by the second device for key generation; generate the first key according to the second parameter and a third parameter, the third parameter being a parameter generated by the first device for key generation.

[0064] In some embodiments, the apparatus is an environmental Internet of Things (A-IoT) device.

[0065] In one implementation, the communication apparatus is a first device. When the communication apparatus is a first device, the transceiver can be a transceiver, or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0066] In another implementation, the communication apparatus is a chip, chip system or circuit used in a first device. When the communication apparatus is a chip, chip system or circuit used in a device, the transceiver can be an input / output interface, interface circuit, output circuit, input circuit, pin or related circuit on the chip, chip system or circuit; the processing unit can be at least one processor, processing circuit or logic circuit, etc.

[0067] The explanation and beneficial effects of the communication device provided in the fourth aspect can refer to the communication method shown in the first aspect, and will not be repeated here.

[0068] In the fifth aspect, a communication device is provided. The device comprises: a transceiver configured to: transmit first indication information, the first indication information being used to indicate a service type of communication between a first device and a second device and / or to indicate performing a security operation, the service type comprising at least one first service, the first service comprising a procedure of completing data transmission based on the security operation, the security operation comprising encryption protection and / or integrity protection; and a processing unit configured to: generate a first key according to the first indication information, the first key being used for security protection of the communication between the first device and the second device.

[0069] In some implementations, the transceiver is further configured to: transmit third indication information, the third indication information being used to indicate a time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and receive the third parameter through a first transport block, wherein a time-frequency resource of the first transport block comprises a time-frequency resource of the third parameter.

[0070] In some implementations, the transceiver is further configured to: transmit seventh indication information, the seventh indication information being used to indicate that a third device transmits a buffered second parameter to the first device, the second parameter being a parameter generated by the second device for key generation.

[0071] In some implementations, the transceiver is specifically configured to: transmit a first message, the first message being used to page, select, or trigger at least one device, the at least one device comprising the first device, the first message comprising the first indication information.

[0072] In some implementations, the transceiver is specifically configured to: receive first uplink data, the first uplink data comprising first identification information of the first device, the first identification information being used by the second device to determine the first indication information; and transmit first downlink data, the first downlink data comprising the first indication information.

[0073] In some implementations, the transceiver is further configured to: transmit a first parameter, the first parameter being used for security protection of the first identification information of the first device; and receive first uplink data, the first uplink data comprising the first identification information after security protection.

[0074] In some implementations, the transceiver is further configured to: transmit fourth indication information, the fourth indication information being used to indicate the first storage time.

[0075] In some embodiments, the transceiver is further configured to send fifth indication information, the fifth indication information being used to instruct the first device to prolong the storage time of the first key.

[0076] In some embodiments, before the processing unit generates the first key, the transceiver is further configured to receive a request message, the request message being used to request the first device to delay generating the first key.

[0077] In some embodiments, the transceiver is further configured to send an acknowledgement message for the request message, the acknowledgement message being used to indicate that the first device is allowed to delay generating the first key.

[0078] In some embodiments, the transceiver is further configured to send a negative acknowledgement message for the request message, the negative acknowledgement message being used to indicate that the first device is not allowed to delay generating the first key; and send sixth indication information, the sixth indication information being used to instruct the first device to re-access to the third device after a second time period elapses or after a next paging message is received.

[0079] In one embodiment, the communication apparatus is a second device. When the communication apparatus is a second device, the transceiver can be a transceiver, or an input / output interface; and the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0080] In another embodiment, the communication apparatus is a chip, chip system or circuit used in a second device. When the communication apparatus is a chip, chip system or circuit used in a device, the transceiver can be an input / output interface, interface circuit, output circuit, input circuit, pin or related circuit on the chip, chip system or circuit; and the processing unit can be at least one processor, processing circuit or logic circuit.

[0081] The explanations and advantages of the communication apparatus provided by the fifth aspect can refer to those of the communication method provided by the second aspect, which will not be repeated here.

[0082] In the sixth aspect, a communication apparatus is provided. The apparatus includes a transceiver configured to receive third indication information, the third indication information being used to indicate a time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and transmit the third parameter through a first transport block, wherein a time-frequency resource of the first transport block includes a time-frequency resource of the third parameter.

[0083] In some embodiments, the transceiver is further configured to receive seventh indication information, the seventh indication information being used to indicate that the third device sends the first device a buffered second parameter, the second parameter being a parameter generated by the second device for key generation.

[0084] In one embodiment, the communication apparatus is the third device. When the communication apparatus is the third device, the transceiver can be a transceiver, or the input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0085] In another embodiment, the communication apparatus is a chip, chip system or circuit used in the third device. When the communication apparatus is a chip, chip system or circuit used in the device, the transceiver can be an input / output interface, interface circuit, output circuit, input circuit, pin or related circuit on the chip, chip system or circuit, etc.; the processing unit can be at least one processor, processing circuit or logic circuit, etc.

[0086] The explanations and advantages of the communication apparatus provided in the sixth aspect can refer to the communication method shown in the third aspect, and will not be repeated here.

[0087] In the seventh aspect, a communication apparatus is provided, which includes a memory configured to store a program, and at least one processor configured to execute the computer program or instructions stored in the memory to perform the method provided in the first aspect or any of the implementation manners of the first aspect, or to perform the method provided in the second aspect or any of the implementation manners of the second aspect, or to perform the method provided in the third aspect or any of the implementation manners of the third aspect.

[0088] In one embodiment, the communication apparatus is a device (e.g., the first device, or the second device, or the third device).

[0089] In another embodiment, the apparatus is a chip, chip system or circuit used in the device (e.g., the first device, or the second device, or the third device).

[0090] In the eighth aspect, a processor is provided, which is configured to execute the method provided in the above aspects.

[0091] For the sending and obtaining / receiving operations of the processor, if there is no special description, or if it does not contradict the actual role or inherent logic in the related description, it can be understood as the processor output and receive, input, etc. operations, or can be understood as the sending and receiving operations performed by the radio frequency circuit and the antenna, which are not limited in the present application.

[0092] In a ninth aspect, a computer readable storage medium storing program code for execution by an apparatus is provided, the program code comprising instructions for performing the method provided by the first aspect or any of the implementations of the first aspect, or comprising instructions for performing the method provided by the second aspect or any of the implementations of the second aspect, or comprising instructions for performing the method provided by the third aspect or any of the implementations of the third aspect.

[0093] In a tenth aspect, a computer program product containing instructions, which when executed on a computer, cause the computer to perform the method provided by the first aspect or any of the implementations of the first aspect, or cause the computer to perform the method provided by the second aspect or any of the implementations of the second aspect, or cause the computer to perform the method provided by the third aspect or any of the implementations of the third aspect.

[0094] In an eleventh aspect, a chip system is provided, the chip system comprising a processor and a communication interface, the processor configured to read instructions stored on a memory via the communication interface, and to perform the method provided by the first aspect or any of the implementations of the first aspect, or to perform the method provided by the second aspect or any of the implementations of the second aspect, or to perform the method provided by the third aspect or any of the implementations of the third aspect.

[0095] Optionally, as an implementation form, the chip system further comprises a memory, the memory storing a computer program or instructions, and the processor is configured to execute the computer program or instructions stored in the memory, and when the computer program or instructions are executed, the processor is configured to perform the method provided by the first aspect or any of the implementations of the first aspect, or to perform the method provided by the second aspect or any of the implementations of the second aspect, or to perform the method provided by the third aspect or any of the implementations of the third aspect.

[0096] In a twelfth aspect, a communication system is provided, comprising at least one communication apparatus of the fourth aspect, at least one notification apparatus of the fifth aspect, and at least one notification apparatus of the sixth aspect.

[0097] The beneficial effects of the seventh aspect to the twelfth aspect can be referred to the description of the first aspect to the third aspect. BRIEF DESCRIPTION OF DRAWINGS

[0098] FIG. 1 is a schematic diagram of a communication system according to an embodiment of the present application.

[0099] FIG. 2 is a schematic block diagram of another communication system according to an embodiment of the present application.

[0100] FIG. 3 is a schematic block diagram of another communication system according to an embodiment of the present application.

[0101] FIG. 4 is a schematic diagram of a functional split and protocol layer structure of a network element of an open radio access network (O-RAN) system according to an embodiment of the present application.

[0102] FIG. 5 is a schematic diagram of an architecture of another O-RAN system according to an embodiment of the present application.

[0103] FIG. 6 is a schematic flowchart of an inventory service according to an embodiment of the present application.

[0104] FIG. 7 is a schematic diagram of an architecture of an A-IoT technology according to an embodiment of the present application.

[0105] FIG. 8 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0106] FIG. 9 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0107] FIG. 10 is a schematic diagram of a key generation process according to an embodiment of the present application.

[0108] FIG. 11 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0109] FIG. 12 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0110] FIG. 13 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0111] FIG. 14 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0112] FIG. 15 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0113] FIG. 16 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0114] FIG. 17 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0115] FIG. 18 is a schematic flowchart of another communication method according to an embodiment of the present application.

[0116] FIG. 19 is a schematic structural block diagram of a communication apparatus according to an embodiment of the present application.

[0117] FIG. 20 is a schematic structural block diagram of another communication apparatus according to an embodiment of the present application.

[0118] Figure 21 is a schematic structural block diagram of another communication device provided in an embodiment of this application.

[0119] Figure 22 is a schematic diagram of a chip system provided in an embodiment of this application. Detailed Implementation

[0120] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0121] First, with reference to the accompanying drawings, the communication system and network architecture applicable to the embodiments of this application will be described.

[0122] The technical solutions of this application embodiment can be applied to various communication systems, including but not limited to: Long Term Evolution (LTE) systems, NR systems, and other fifth-generation (5G) communication systems. th This includes various mobile communication systems such as 5G, narrowband Internet of Things (NB-IoT), enhanced machine-type communication (eMTC), enhanced mobile broadband (eMBB), ultra-reliable low-latency communications (URLLC), satellite communication systems, LTE-machine-to-machine (LTE-M) systems, and other systems that evolve after 5G, such as future mobile communication systems.

[0123] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0124] FIG. 1 is a schematic diagram of a communication system 100. As shown in FIG. 1, the communication system 100 includes a radio access network 110 and a core network 120, and optionally, the communication system 100 can further include an Internet 130. The radio access network 110 can include at least one network device (e.g., 111a and 111b in FIG. 1) and at least one terminal device (e.g., 112a-112j in FIG. 1). The terminal device is connected to the network device in a wireless manner. The network device is connected to the core network 120 in a wireless or wired manner. The core network 120 can include one or more core network devices. The core network device and the network device can be independent and different physical devices, or the functions of the core network device and the logical functions of the network device can be integrated on the same physical device, or a physical device can integrate the functions of part of the core network device and part of the network device. The terminal device and the terminal device, and the network device and the network device can be connected to each other in a wired or wireless manner. The terminal device and the terminal device, the network device and the network device, and the terminal device and the network device can communicate with each other in a wireless manner through air interface resources. Exemplarily, the air interface resources can include at least one of time domain resources, frequency domain resources, code resources and space resources. FIG. 1 is only a schematic diagram, and the communication system 100 can further include other network devices, such as wireless relay devices and wireless backhaul devices, which are not shown in FIG. 1.

[0125] The network device can also be referred to as an access network device or an access network node. It can be understood that the name of the device with the function of the network device can be different in systems with different wireless access technologies. For the convenience of description, the apparatus providing wireless communication access function for the terminal device is collectively referred to as a base station in the embodiments of the present application. In the embodiments of the present application, the network device includes but is not limited to various forms of macro base stations (such as 111a in FIG. 1), micro base stations or indoor stations (such as 111b in FIG. 1), pico base stations, small stations, balloon stations, relay stations, access points, etc. Among them, the micro base station can be referred to as a small station. The network device can include an evolved node B (eNB or eNodeB) in LTE, a radio controller in a cloud radio access network (CRAN) scenario, a network device in a future evolved public land mobile network (PLMN), an access point (AP) in a wireless fidelity (WiFi) system, a wireless relay node, a wireless backhaul node, a transmission point (TP) or a transmission reception point (TRP), etc., and can also include a next generation base station node (gNB) or a transmission point (TRP or TP) in a 5G system, one or a group of (including multiple antenna panels) antenna panels of a base station in a 5G system, a network node constituting a gNB or a transmission point, such as a baseband unit (BBU) or a distributed unit (DU), and can also include a network device, server, wearable device or vehicle-mounted device, etc. in a network in a future mobile communication system and the like after 5G. The network device can also be a module or unit that completes the function of the base station, for example, it can be a central unit (CU) or a DU. In addition, the network device can be understood as a general term for all devices (including stations) on the network side, for example, a plurality of stations can be collectively referred to as a network device. The station refers to a transmission node that is actually located at a physical location. In other words, the network device conceptually contains the station.

[0126] In the embodiments of the present application, the apparatus for implementing the function of the network device can be the network device itself, or an apparatus capable of supporting the network device to implement the function, such as a chip system or a chip, which can be installed in the network device. The chip system can be composed of a chip, or can include a chip and other discrete devices.

[0127] In another possible scenario, a plurality of network devices cooperates to assist a terminal to implement wireless access, and different network devices respectively implement part of functions of a base station. For example, a network device can be a CU, a DU, a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can be included in a same network element, for example, in a BBU. The RU can be included in a radio frequency device or a radio frequency unit, for example, in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0128] In different systems, the CU (or CU-CP and CU-UP), the DU, or the RU can also have different names, but a person skilled in the art can understand their meanings. For example, in an O-RAN system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are taken as examples for description in this application. Any one of the CU (or the CU-CP, the CU-UP), the DU, and the RU in this application can be implemented by means of a software module, a hardware module, or a combination of a software module and a hardware module. The embodiments of this application do not limit the specific technology and the specific device form adopted by the network device.

[0129] The terminal device can be a device providing voice and / or data connectivity to users; the terminal device can also be a device having wireless connection function. The terminal device can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; can also be deployed on water surface (such as ships, etc.); can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal device can also be called user equipment (UE), access terminal, terminal, subscriber unit, user station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, wireless network device, user agent or user apparatus. In the embodiments of the present application, the terminal device includes but is not limited to: cellular phone, mobile phone, wireless data card, wireless modem, pad, laptop computer, notebook computer, palm computer, mobile internet device (MID), computer with wireless transceiver function, cordless phone, session initiation protocol (SIP) phone, smart phone, wireless local loop (WLL) station, personal digital assistant (PDA), handset with wireless communication function, computing device or other device connected to wireless modem, vehicle-mounted device (such as car, bicycle, electric vehicle, airplane, ship, train, high-speed rail, etc.), wearable device (such as smart watch, smart bracelet, pedometer, smart glasses, etc.), satellite terminal, terminal device in Internet of Things or Internet of Vehicles, and any form of terminal in future network, relay user equipment or terminal in future evolved PLMN, etc.The terminal device can also be a virtual reality (VR) device, an augmented reality (AR) device, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (RedCap UE), a machine type communication (MTC) terminal, a terminal device in industrial control, a terminal device in self driving, a terminal device in remote medical treatment, a terminal device in a smart grid, a wireless terminal in transportation safety, a terminal device in a smart city, a terminal device in a smart home, a haptic terminal device, a smart home device (e.g., a refrigerator, a television, an air conditioner, an electricity meter, etc.), a smart robot, a mechanical arm, a plant device, a wireless terminal in self driving, or a flight device (e.g., a smart robot, a hot air balloon, a drone, an airplane), and the like. The terminal device can also be a vehicle device, such as a transport vehicle with wireless communication function, a communication module, a whole vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on board unit (OBU), or a telematics box (T-BOX), and the like. The terminal device can also be other devices with terminal functions, for example, the terminal device can also be a device in device to device (D2D) communication that plays a terminal function. The embodiments of the present application are not limited in this regard.

[0130] In the embodiments of the present application, the device for implementing the function of the terminal device can be a terminal device, or a device capable of supporting the terminal device to implement the function, such as a chip or a chip system, which can be installed in the terminal device. The chip system can be composed of a chip, or can include a chip and other discrete devices. In the technical solutions of the embodiments of the present application, the device for implementing the function of the terminal device is taken as an example of the terminal device. The terminal device can also be referred to as a terminal. The following can take the terminal device as an example of the UE to describe the technical solutions provided by the embodiments of the present application.

[0131] The roles of the base station and the terminal can be relative, for example, the helicopter or the unmanned aerial vehicle 112i in FIG. 1 can be configured as a mobile base station, and for those terminals 112j accessing the wireless access network 110 through 112i, the terminal 112i is a base station; but for the base station 111a, 112i is a terminal, that is, 111a communicates with 112i through a wireless air interface protocol. Of course, 111a and 112i can also communicate through a base station-to-base station interface protocol, and in this case, 112i is also a base station relative to 111a. Therefore, the base station and the terminal can be collectively referred to as a communication device, and 111a and 111b in FIG. 1 can be referred to as a communication device with a base station function, and 112a-112j in FIG. 1 can be referred to as a communication device with a terminal function.

[0132] The network device and the terminal device can communicate through a wireless link. The transmission link from the network device to the terminal device can be referred to as a downlink (DL) or a downlink channel, which is used to transmit a downlink signal. The transmission link from the terminal device to the network device can be referred to as an uplink (UL) or an uplink channel, which is used to transmit an uplink signal. The transmission link from the terminal device to the terminal device can be referred to as a sidelink (SL) or a sidelink channel. In the embodiments of the present application, multiple network devices can send information to multiple different terminal devices and receive information from multiple different terminal devices; multiple network devices can also send information to the same terminal device and receive information from the same terminal device, which is not limited in the present application.

[0133] Optionally, in the embodiments of the present application, if the network device is a reader and the terminal device is an electronic tag device, the "uplink" between the reader and the electronic tag device can be referred to as "DR" or "D2R", and the "uplink signaling" can be replaced by "D2R signaling"; the "downlink" between the reader and the electronic tag device can be referred to as "RD" or "R2D", and the "downlink signaling" can be replaced by "R2D signaling".

[0134] The communication between different devices involved in the embodiments of the present application can mean direct communication between different devices (i.e. without the need for other devices to transfer or forward), or can mean communication between different devices through other devices (i.e. the need for other devices to transfer or forward), or can mean that a functional unit inside a device communicates with other devices through another functional unit. The information between the source and the destination of the information transmission can be processed as necessary, such as format change, digital-to-analog conversion, amplification, or filtering, etc., but the destination can understand the valid information from the source. Similar expressions in the present application can be understood similarly, and will not be repeated here.

[0135] FIG. 2 is a schematic block diagram of another communication system. FIG. 2 takes the communication between a terminal device and a network device as an example.

[0136] As shown in FIG. 2, the terminal device 210 can include a processor 211, a memory 212 and a transceiver 213. Exemplarily, the transceiver 213 can include a transmitter 2131, a receiver 2132 and an antenna 2133. The network device 220 can include a processor 221, a memory 222 and a transceiver 223. Exemplarily, the transceiver 223 can include a transmitter 2231, a receiver 2232 and an antenna 2233. The receiver 2132 can be configured to receive information from the network device 220 through the antenna 2133, and the transmitter 2131 can be configured to send information to the network device 220 through the antenna 2133. The transmitter 2231 can be configured to send information to the terminal device 210 through the antenna 2233, and the receiver 2232 can be configured to receive information from the terminal device 210 through the antenna 2233.

[0137] The network device in the embodiments of the present application can include a chip in the network device. For example, the network device can include the processor 221, the memory 222 and the transceiver 223. The terminal device in the embodiments of the present application can include a chip in the terminal device. For example, the terminal device can include the processor 211, the memory 212 and the transceiver 213.

[0138] FIG. 3 is a schematic block diagram of another communication system. FIG. 3 shows an O-RAN system. The O-RAN system in the embodiments of the present application can include other components than those shown in FIG. 3, or can only include part of the components in FIG. 3.

[0139] Referring to FIG. 3, the network device can communicate with the core network device through a backhaul link 310, and communicate with the terminal device through an air interface. Exemplarily, the BBU in the network device can communicate with the core network device through the backhaul link 310. The RU in the network device can communicate with at least one terminal device through the air interface. The BBU can communicate with at least one RU through a front-haul link 330. Wherein, the BBU and the RU can be co-located or not. Exemplarily, the BBU can include at least one CU and at least one DU. The CU and the DU can communicate through at least one mid-haul link 320.

[0140] FIG. 4 is a schematic diagram of the function division of network elements and the protocol layer structure of an O-RAN system. The O-RAN system in the embodiments of the present application can divide the function of network elements and the protocol layer in part or all of the manners shown in FIG. 4, or in other manners.

[0141] In some examples, the CU can be used to carry logical nodes of an RRC layer, a service data adaptation protocol (SDAP) layer, a packet data convergence protocol (PDCP) layer, and other control functions of the access network device. Illustratively, the CU can be connected to network nodes such as a core network through some interfaces, for example, the interfaces can include an E2 interface and the like. Optionally, the CU has part of the functions of the core network.

[0142] Illustratively, the CU (e.g., a PDCP layer or a layer higher than PDCP) is connected to the DU (e.g., a radio link control (RLC) layer or a layer lower than RLC) through some interfaces, for example, the interfaces can be an F1 interface and the like. In some examples, the above-mentioned interface (e.g., the F1 interface) can provide CP and UP functions, for example, interface management, system information management, UE context management, RRC message transmission, and the like. The F1 interface can adopt an F1 application protocol (F1AP).

[0143] In some examples, the CU can be split into a CU-CP and a CU-UP.

[0144] The CU-CP can be used to carry logical nodes of an RRC layer and a PDCP control plane part (PDCP-C) layer, for implementing control plane functions of the CU. The CU-CP can interact with network elements in the core network for implementing control plane functions. Illustratively, the network element in the core network for implementing control plane functions can be an access and mobility function network element, for example, an access and mobility management (AMF) in a 5G system. Illustratively, the AMF network element can be used to be responsible for mobility management in a mobile network, such as location updating of a terminal device, registration of the terminal device to a network, handover of the terminal device, and the like.

[0145] The CU-UP can be used to carry logical nodes of an SDAP layer and a PDCP user plane part (PDCP-U) layer, for implementing user plane functions of the CU. The CU-UP can interact with network elements in the core network for implementing user plane functions. For example, a user plane function (UPF) in a 5G system can be used to be responsible for forwarding and receiving data in a terminal device.

[0146] The configuration of the above CU or DU is merely an example, and the CU or DU can be configured to have functions as needed. For example, the CU or the DU can be configured to have more protocol layer functions, or the CU or the DU can be configured to have partial processing functions of the protocol layer. For example, partial functions of the RLC layer and functions of the protocol layer above the RLC layer are arranged in the CU, and the remaining functions of the RLC layer and functions of the protocol layer below the RLC layer are arranged in the DU. For another example, the functions of the CU or the DU can be divided according to a service type or other system requirements, for example, according to a delay requirement. For example, functions that require to meet a shorter delay requirement in processing time are arranged in the DU, and functions that do not require to meet the delay requirement are arranged in the CU.

[0147] In some examples, the DU can be used to carry logical nodes of the RLC layer, the medium access control (MAC) layer, the higher physical (Higher PHY) layer, and other functions. In some examples, the DU can control at least one RU. For example, the DU can be connected to the RU through some interfaces, which can be a front-haul interface. In some examples, the Higher PHY layer can include part of the PHY layer processing, such as forward error correction (FEC) encoding, decoding, scrambling, modulation, or demodulation, and other processing functions.

[0148] In some examples, the RU can be used to carry logical nodes of the lower physical (Lower PHY) layer and radio frequency (RF) chain processing. In some examples, the RU can be a TRP, an RRH, or other similar functional entity in the third generation partnership project (3 rd generation partnership project,3GPP). In some examples, the Low PHY layer includes part of the PHY processing, such as fast Fourier transform (FFT), inverse fast Fourier transformation (IFFT), digital beamforming or filtering, and other processing functions. The RU can communicate with one or more UEs through a wireless link.

[0149] The DU and the RU can or can not be co-located. For example, the DU and the RU can exchange control plane and user plane information via a lower-layer split control / user / synchronization-plane (LLS-C / U / S) interface over a fronthaul link. For example, the O-RAN CUS plane in the DU can communicate with the O-RAN CUS plane in the RU over the LLS-C / U / S interface. Illustratively, the LLS-C / U / S can include a LLS-control (C) interface and a LLS-user (U) interface that provide CP and UP, respectively. In some examples, the CP can refer to real-time control between the DU and the RU. The DU and the RU can exchange management information over a LLS-management (M) interface of the fronthaul link, and the M plane can refer to non-real-time management operations between the DU and the RU. For example, the O-RAN M plane in the DU can communicate with the O-RAN M plane in the RU over the LLS-M interface. For another example, the O-RAN M plane in the DU or the RU can communicate with a management system over the LLS-M interface.

[0150] The DU and the RU can cooperate with each other to collectively implement the functionality of the PHY layer. For example, one DU can be connected to one or more RUs. The functionality of the DU and the RU can be configured in multiple ways according to design. For example, the DU can be configured to implement baseband functionality, and the RU can be configured to implement mid- radio frequency functionality. For another example, the DU can be configured to implement high-layer functionality (e.g., high PHY) in the PHY layer, and the RU can be configured to implement low-layer functionality (e.g., low PHY) in the PHY layer or implement the low-layer functionality and radio frequency functionality (e.g., RF chain). The high-layer functionality in the PHY layer can include a portion of the functionality of the PHY layer that is closer to the MAC layer, and the low-layer functionality in the PHY layer can include another portion of the functionality of the PHY layer that is closer to the mid-radio frequency side.

[0151] FIG. 5 is a diagram of an application framework involving a RAN intelligent controller (RIC) in an O-RAN architecture. As shown, the communication system includes a RIC module, which includes a near-real time RIC (near-RT RIC) and a non-real time RIC (Non-RT RIC).

[0152] In some examples, the near-real-time RIC can be used for model training and inference. For example, for training an artificial intelligence (AI) model and using the AI model for inference. The near-real-time RIC can obtain network-side information from RAN nodes (e.g., CUs, CU-CPs, CU-UPs, DUs, and / or RUs) and / or terminal-side information from terminal devices. The information can be used as training data or inference data for the AI model. Optionally, the near-real-time RIC can deliver inference results to RAN nodes and / or terminals. Optionally, the inference results can also be exchanged between CUs and DUs and / or between DUs and RUs, e.g., the near-real-time RIC delivers the inference results to a DU, which then delivers the inference results to RUs.

[0153] In some examples, the non-real-time RIC can be used for model training and inference. For example, for training an AI model and using the AI model for inference. The non-real-time RIC can obtain network-side information from RAN nodes (e.g., CUs, CU-CPs, CU-UPs, DUs, and / or RUs) and / or terminal-side information from terminal devices. The information can be used as training data or inference data for the AI model. The inference results can be delivered to RAN nodes and / or terminals. Optionally, the inference results can also be exchanged between CUs and DUs and / or between DUs and RUs, e.g., the non-real-time RIC delivers the inference results to a DU, which then delivers the inference results to RUs.

[0154] In some examples, the near-real-time RIC and the non-real-time RIC can also be separately provided as a network element. Optionally, the near-real-time RIC and the non-real-time RIC can also be part of other devices, e.g., the near-real-time RIC can be provided in a RAN node (e.g., in a CU or a DU), while the non-real-time RIC can be provided in an OAM, a cloud server, a core network device, or other network devices.

[0155] The network elements in a communication system are connected through interfaces (e.g., NG, Xn) or air interfaces. One or more AI modules can be provided in one or more of the network element nodes, e.g., a core network device, an access network node (RAN node), a terminal, or one or more devices in an OAM. The access network node can be a single RAN node or can include multiple RAN nodes, e.g., including a CU and a DU. The CU and / or the DU can also be provided with one or more AI modules. Optionally, the CU can also be split into a CU-CP and a CU-UP. One or more AI modules can be provided in the CU-CP and / or the CU-UP.

[0156] The foregoing AI module is used to implement a corresponding AI function. AI modules deployed in different network elements can be the same or different. The model of an AI module can implement different functions according to different parameter configurations. The model of an AI module can be configured based on one or more of the following parameters: a structural parameter (for example, at least one of a number of neural network layers, a neural network width, a connection relationship between layers, a weight of a neuron, an activation function of a neuron, or a bias in the activation function), an input parameter (for example, a type of input parameter and / or a dimension of the input parameter), or an output parameter (for example, a type of output parameter and / or a dimension of the output parameter). The bias in the activation function can also be referred to as a bias of the neural network.

[0157] One AI module can have one or more models. One model can infer an output including one parameter or multiple parameters. The learning process, the training process, or the inference process of different models can be deployed in different nodes or devices, or can be deployed in the same node or device.

[0158] The above-described communication system applicable to the present application is only illustrative, and the communication system applicable to the present application is not limited thereto. Herein, the following will not be described in detail.

[0159] Before introducing the embodiments, the terms related to the present application are described in detail.

[0160] 1. Radio frequency identification (RFID):

[0161] RFID is a kind of automatic identification technology. RFID performs non-contact bidirectional data communication through wireless radio frequency, and reads and writes a recording medium (electronic tag device or radio frequency card) through wireless radio frequency, so as to achieve the purpose of target identification and data exchange. The main application scenario of RFID is identity recognition, and further can be used for data reading and writing. Illustratively, RFID can be applied in logistics and warehousing, such as goods inventory and tracking, high-value goods (such as vaccines) transportation process environment and goods state monitoring, and can also be applied in industrial manufacturing, such as environment and equipment state monitoring.

[0162] A complete RFID system consists of a reader, a tag device, and a data management system. The reader is a device that reads information from a tag device or writes information to a tag device. Depending on the structure and technology used, the reader can be a read / write device, and is the information control and processing center of the RFID system. When the RFID system is in operation, the reader sends radio frequency energy to form an electromagnetic field in a certain area, and the size of the area depends on the transmission power. The tag device in the area is triggered by the reader, sends the data stored therein, or modifies the data stored therein according to the instructions of the reader, and can communicate with a computer network through an interface.

[0163] For ease of description, the tag device is referred to as a "tag" hereinafter.

[0164] The tag can be composed of a transceiver antenna, an AC / DC circuit, a demodulation circuit, a logic control circuit, a memory, and a modulation circuit. The tag has simple functions and generally needs to rely on the excitation of the reader to send information, that is, the tag converts the wireless signal emitted by the reader into energy, and uses the energy to drive itself to work. The tag supports micro-watt or hundred-micro-watt power consumption, and cannot support complex designs. RFID can be divided into three categories according to the power supply mode of the tag, namely passive RFID, active RFID, and semi-active RFID.

[0165] In passive RFID, the tag is temporarily powered by accepting the microwave signal transmitted by the RFID reader and obtaining energy through an electromagnetic induction coil, thereby completing the information exchange. Since the power supply system is omitted, the volume of the passive RFID product can reach centimeter level or even smaller, and the structure is simple, the cost is low, the failure rate is low, and the service life is relatively long. However, the effective identification distance of passive RFID is usually short, and it is generally used for close-range contact identification. Passive RFID mainly works at a low frequency of 125 KHz or 13.56 MKHz.

[0166] Active RFID is powered by an external power supply and actively sends signals to the RFID reader. It has a relatively large volume, a long transmission distance, and a high transmission speed. Active RFID mainly works at a high frequency of 800 MHz, 2.45 GHz, 5.8 GHz, and has the function of simultaneously identifying multiple tags.

[0167] Semi-active RFID is also called low-frequency activation trigger technology. In general, semi-active RFID products are in a dormant state, and only the part of the tag that maintains the data is powered, so the power consumption is small and can be maintained for a long time. When the tag enters the identification range of the radio frequency identification reader, the reader first uses a low-frequency signal to accurately locate, and then uses a high-frequency signal to quickly transmit data.

[0168] Optionally, the reader can adopt a separate architecture, such as being divided into a transceiver unit and an assistance unit. The reader and the tag include a forward link and a reverse link, and the transceiver unit and the assistance unit include a forward uplink and a forward downlink. Among them, the assistance unit is responsible for sending an excitation signal to the tag through the forward link, and the tag responds to the excitation signal after receiving the excitation signal, and sends a reflection signal to the transceiver unit through the reverse link, and the transceiver unit is responsible for generating radio frequency identification related signaling and sending the signaling to the assistance unit, and the assistance unit forwards the signaling on the forward link to realize communication.

[0169] If the RFID is applied to a mobile communication system, such as the aforementioned 5G system, the base station can act as a reader to realize the function of the reader, and the terminal device can act as a tag. In addition, the aforementioned forward link between the transceiver unit and the assistance unit can adopt 5G new radio (NR) transmission technology, that is, when the transceiver unit generates radio frequency identification technology related signaling, it is transmitted to the assistance unit through 5G air interface technology, and the assistance unit forwards the signaling on the forward link.

[0170] The card reader performs basic inventory / access operations such as reading, writing, accessing, and killing the tag according to the instructions of the application server. FIG. 6 is a schematic diagram of a basic inventory process of an RFID according to an embodiment of the present application. As shown in FIG. 6, the basic inventory process of the RFID includes the following steps:

[0171] S610, the reader sends a select signaling to the tag. Correspondingly, the electronic tag device receives the select signaling from the reader.

[0172] The select signaling is used to select one or a group of tags. Specifically, the reader sets the state of a certain session of the inventory flag (inventoried) of the tag that meets the selection condition and / or does not meet the selection condition through the select signaling.

[0173] For example, the inventory flag bit can have four independent sessions, namely session 0 (S0), session 1 (S1), session 2 (S2) and session 3 (S3), and the state of each session can be state A or state B. Specifically, the select signaling also carries the inventory session (inventorySeesion), action (action) and mask (mask) fields. The session corresponding to the tag selected by the select signaling is set. Assuming that the inventorySeesion selects the session S0, the action = 0, and the mask matches, the tag sets the flag bit of S0 to A, that is, performs initial flag bit setting.

[0174] Each flag bit corresponds to a session, and the inventorySeesion specifies which session flag bit is set. The action specifies how to set, for example, action = 1 or 0. If the mask matches after the tag receives the select signaling, the tag sets the session corresponding flag bit to A (action = 1) or B (action = 0). The mask is used to screen which tags are selected, for example, the tag stores a complete 96-bit identifier, and the mask can indicate that the tag with the first 16 bits of 111...111 is selected. If the mask matches, the tag can further set according to the action, and further listens to the query (Query) command behind.

[0175] Optionally, the above-mentioned select signaling can also be a paging (Paging) signaling, which is used to page one or a group of tags.

[0176] S620, the reader sends a query (Query) message to the tag. Correspondingly, the tag receives the Query message from the reader. The query message can also be referred to as a query command.

[0177] The Query message carries the value of the parameter Q, the session, and the inventory flag bit. Assuming that the session is S0 and the inventory flag bit is A, when the session of the tag matches the flag bit, a value between 0 and 2Q-1 is randomly generated according to the parameter Q as the initial value of the counter. The tag determines whether to immediately feed back a random number (RN) to the reader according to the value of the counter. For example, when the counter = 0, the tag feeds back the RN (for example, RN(16), RN(16) is a 16-bit random number) to the reader. When the counter is not 0, the tag does not feed back the RN to the reader. The reader does not receive the RN fed back by the tag within a period of time, and then sends a repeated query (QueryRep) message to the tag.

[0178] Specifically, the subsequently executed steps include two cases, case 1 and case 2.

[0179] Case 1: Counter = 0, and specifically includes S621.

[0180] S621, the tag sends a random number to the reader. Correspondingly, the reader receives the random number from the tag.

[0181] The random number (RN) can be a 16-bit random number or an 8-bit random number, and the embodiments of the present application do not limit this.

[0182] Case 2: Counter is an integer greater than or equal to 1, and specifically includes S622 and S623.

[0183] S622, the reader sends a QueryRep message to the tag. Correspondingly, the tag receives the QueryRep message from the reader. The QueryRep message can also be referred to as a QueryRep command.

[0184] The QueryRep message can not carry content, that is, it can not carry the value of the parameter Q, session, and inventory flag. The number of times of sending the QueryRep message is determined according to the value of counter. Specifically, the tag decrements counter by 1 each time it receives a QueryRep message. Until the value of counter is 0, the tag sends RN to the reader.

[0185] More specifically, the tag can calculate the range of the selectable time slots as [0, 2Q-1] according to the value of the random parameter Q, and randomly assign a value to counter in [0, 2Q-1]. The tag decrements the count value of counter by 1 each time it receives a QueryRep message. When the count value of counter is 0, S623 can be executed.

[0186] Each QueryRep message corresponds to the start or end of an access time slot, that is, the tag represents the end of the previous time slot and the start of the next time slot each time it receives a QueryRep message.

[0187] S623, the tag sends a random number to the reader. Correspondingly, the reader receives the random number from the tag.

[0188] When the count value of counter is 0, the tag sends the random number in the access time slot randomly selected by the tag.

[0189] S630, the reader sends an acknowledged (ACK) message to the tag. Correspondingly, the tag receives the ACK message from the reader.

[0190] In the above process, the reader sends an ACK message to the tag if there is no collision, i.e., the reader only receives the RN sent by one tag.

[0191] S640, the tag sends uplink data to the reader.

[0192] The uplink data can be an electronic product code (EPC).

[0193] S650, the reader sends a QueryRep message to the tag again. Correspondingly, the tag receives the QueryRep message from the reader.

[0194] S660, the tag reverses the state of the inventory flag.

[0195] After the tag receives the QueryRep message, it indicates that the data transmission is successful, and then the tag can reverse the state of the inventory flag. For example, the state of session 0 is set from state A to state B. The tag reverses the state of the inventory flag to prevent the tag that has been inventoried from being inventoried repeatedly, because the subsequent Query message carries the flag A, and the tag with the flag B will not respond to the Query command.

[0196] The QueryRep message can be used to trigger the tag that has not successfully accessed the reader to access the reader. Specifically, the counter value of the tag with the counter value other than 0 is reduced by 1, and the S623 to S660 are repeatedly executed until the counter value is 0, and all tags successfully access the reader.

[0197] 2. Ambient Internet of Things (A-IoT):

[0198] With the development of communication technology, in order to significantly reduce the power consumption and complexity of the internet of things device, the 3rd generation partnership project (3GPP) defines the ambient internet of things (A-IoT) technology. The A-IoT technology refers to the internet of things (IoT) terminal network node without external "energy source", and the internet of things technology using the environment energy for energy supply. On the basis of the foregoing RFID, the ambient internet of things is further extended to Wi-Fi, Bluetooth, UWB, LoRa, 5G and other communication technologies. The A-IoT technology defined by the 3GPP plenary session with extremely low power consumption and extremely low complexity can be understood as the extension of RFID in 3GPP. Among them, the A-IoT technology and RFID have some same principles, such as similar inventory business processes, but more value scenarios will be introduced in 3GPP.

[0199] The A-IoT architecture in the A-IoT technology includes network devices and A-IoT terminal devices, or in other words, the A-IoT based communication system includes network devices and A-IoT terminal devices. In this case, as described in the foregoing RFID, the reader and the tag can be implemented based on the infrastructure in the cellular network. In other words, the reader and the tag can be devices in the cellular network. For example, the function of the reader can be implemented by a network device such as a base station, or can also be implemented by a terminal device. The tag can be implemented by an A-IoT terminal in the cellular network, such as an extremely low power consumption and extremely low complexity internet of things terminal. The network device and the A-IoT terminal device can perform non-contact data communication, so that the network device reads information from the A-IoT terminal device, and / or writes information to be stored into the A-IoT terminal device. For the application range, the A-IoT technology can be applied to logistics, warehousing, industrial manufacturing, identity recognition, or environmental monitoring and other scenarios.

[0200] In the A-IoT technology, one or more services can be exchanged between the reader and the tag. The service types can include, but are not limited to, inventory service, command service, read service, write service, lock service, positioning service, proximity determination service, sensor service, kill or disable service, and device number counting service. The security requirements of the inventory service, read service, proximity determination service, sensor service, and positioning service (e.g., when only a positioning sequence is sent) can be low. The security requirements of the write service, lock service, and kill service can be high, i.e., these services need to be protected by the aforementioned key. If the reader and the tag are attacked when processing the write service, the tag can write incorrect information into the memory. Similarly, if the reader and the tag are attacked when processing the lock service or the kill service, the tag can not work.

[0201] It is worth noting that the service can be replaced by a task, or a session, or a request, or a transaction, or a process, or a procedure, or a service. The name of the service is not limited in the present application. For example, the first service can also be referred to as a first task, and the inventory service can also be referred to as an inventory task, or an inventory request, or an inventory procedure, or an inventory transaction, etc.

[0202] Exemplarily, as shown in FIG. 6, the inventory service is to access the tags (A-IoT terminal devices) in the coverage range by the reader (which can be a base station / terminal). The tag that successfully accesses the reader needs to send its unique identifier (which can be recognized by the network, such as EPC in RFID) to the reader. The positioning service can be to position the location of the tag (A-IoT terminal device) by the reader (which can be a base station / terminal) using some positioning signals. The sensor service is to report the sensor data (such as temperature data) of the tag (A-IoT terminal device) to the reader (which can be a base station / terminal). The write procedure can be to instruct the tag (A-IoT terminal device) to write data into the memory by the reader (which can be a base station / terminal) sending a downlink instruction and data. The lock procedure can be to instruct the tag (A-IoT terminal device) to lock the location of a specified address in the memory by the reader (which can be a base station / terminal) sending a downlink instruction, and the content of the memory segment cannot be changed or read.

[0203] As mentioned above, the communication between different devices can refer to the direct communication between different devices (i.e. without the need of other devices to relay or forward), or can also refer to the communication between different devices through other devices (i.e. with the need of other devices to relay or forward). Exemplarily, FIG. 7 shows a schematic diagram of an A-IoT network architecture provided by the embodiments of the present application. For example, as shown in (a) of FIG. 7, the A-IoT terminal device (i.e. tag) and the network device (i.e. reader) directly communicate with each other. The communication between the network device and the A-IoT terminal device includes A-IoT data and / or signaling. The topology shown in (a) of FIG. 7 includes the network device sending data and / or signaling to the A-IoT terminal device and the network device receiving data and / or signaling from the A-IoT terminal device, i.e. there is uplink / downlink data or signaling transmission / reception between the network device and the A-IoT terminal device. For another example, as shown in (b) of FIG. 7, the A-IoT terminal device and the network device communicate with each other through an intermediate node. In this topology, the intermediate node can be a repeater, an IAB node, a UE, a repeater, etc., and the intermediate node transmits A-IoT data and / or signaling between the A-IoT terminal device and the network device. For another example, as shown in (c) of FIG. 7, the A-IoT terminal device sends data / signaling to the network device and receives data / signaling from the auxiliary node; or the A-IoT terminal device receives data / signaling from the network device and sends data / signaling to the auxiliary node. In this topology, the auxiliary node can be a repeater, an IAB, a UE, a repeater, etc. For another example, as shown in (d) of FIG. 7, the A-IoT terminal device and other terminal devices communicate with each other. The communication between the A-IoT terminal device and other terminal devices includes A-IoT data and / or signaling.

[0204] Exemplarily, the terminal devices in the A-IoT can be divided into three categories: device A, device B and device C.

[0205] 1) device A (similar to passive A-IoT terminal): no energy storage or some low-capacity energy storage, cannot independently generate independent signals, and uses backscatter to transmit signals.

[0206] 2) device B (similar to semi-passive A-IoT terminal): has energy storage, for example, has a capacitor energy storage, but cannot independently generate signals, and uses backscatter to transmit signals. The stored energy can amplify the reflected signals. Optionally, the device B stores energy through a battery.

[0207] 3) device C (similar to active A-IoT terminal): with energy storage, can independently generate signals, and has active radio frequency (RF) elements for transmission.

[0208] 3GPP meetings further defined the following three types of A-IoT devices: device 1, device 2a, and device 2b. Among them, device A can be equivalent to device 1, device B can be equivalent to device 2a, and device C can be equivalent to device 2b. The names of the three types of A-IoT devices are not limited in this application.

[0209] 1) device 1: peak power consumption is about 1 μW, has energy storage function, initial sampling frequency offset (SFO) reaches 10 X parts per million (ppm), cannot amplify downlink (DL) and uplink (UL) signals. It needs to obtain a carrier signal from the outside for backscatter communication to perform uplink transmission.

[0210] 2) device 2a: peak power consumption is less than or equal to a few hundred μW, has energy storage function, initial sampling frequency offset reaches 10 X ppm, can amplify DL and / or UL signals. It needs to obtain a carrier signal from the outside for backscatter communication to perform uplink transmission.

[0211] 3) device 2b: peak power consumption is less than or equal to a few hundred μW, has energy storage function, initial sampling frequency offset reaches 10 X ppm, can amplify DL and / or UL signals. The device can perform uplink transmission without relying on an externally provided carrier.

[0212] For example, the device A / device 1 (or the device B / device 2) has a power consumption of about 1 microwatt (μW), which is very low and leads to a limited storage capacity. In addition, because the electric capacity is maintained for a short time, such as within 1 second, and because the sensitivity is low and the charging energy and the effective signal energy cannot be distinguished, the device cannot receive and transmit signals during the radio frequency charging process, and the charging time can be several seconds or even tens of seconds. The charging-work mode of such a device is as follows: the device is charged to full capacity, and then starts to receive and transmit messages. In addition, such a device has very low power consumption and cost, and the storage capacity is very low. Therefore, the information storage of such a device needs to be strictly considered. The information temporarily stored in the register will be lost after the electric capacity is consumed.

[0213] 3. Security activation / security mode control (SMC):

[0214] At present, the security activation / SMC can be used to activate the secure interaction of information between the terminal side and the network side, including non-access stratum (NAS) SMC and access stratum (AS) SMC. For example, the security activation / SMC process mainly completes the negotiation of the security algorithm used by the terminal side and the network side, and generates the keys required by the corresponding security algorithm based on KASME or KeNB. For example, in the security activation scheme of 5G NR, the security complexity is improved by adding a lot of “intermediate” keys between the network side and the terminal side, and the security of communication is ensured. For example, the “intermediate” keys can include KAUSF, KSEAF, KAMF, KgNB, signaling encryption key KRRCenc, and integrity protection key KRRCint.

[0215] However, as described in the foregoing security activation scheme, the terminal device needs to generate, update, or store a large number of keys, which will bring a large amount of additional storage overhead to the terminal device. The process of the security activation scheme is complex, and multiple interactions are required to complete the security activation, which will bring a large delay to the terminal device. For example, in the A-IoT technology, the power consumption of the A-IoT device is low, and the complexity is low. The current security activation scheme is difficult to be used on the A-IoT terminal device, which will bring additional power consumption, large design complexity, and large inventory delay (for example, the large delay will greatly affect the inventory efficiency of a scene in which a large number of A-IoT terminal devices exist, and the large delay will also cause the energy consumption of the A-IoT terminal device to become large). Similarly, the current security activation scheme is also difficult to be used in other scenes in which the terminal device has weak capabilities. For ease of description, the A-IoT scene is taken as an example of a scene in which the terminal device has weak capabilities in the following description.

[0216] In addition, when the tag receives the paging message sent by the reader, it does not know the specific type of service between the tag and the reader, that is, the tag does not know whether to include the service that needs to be protected, such as the write, lock, and inactivation services described above. Furthermore, at the present stage, whether in a scenario with only inventory services, or in a scenario with inventory services and other services that do not need to be protected, or in a scenario including inventory services and services that need to be protected, the tag will deduce / save / send security keys and related parameters (tens to hundreds of bits).

[0217] In the above two scenarios (that is, the scenario with only inventory services, and the scenario with inventory services and other services that do not need to be protected), the security key is additional stored information, and the temporary storage of the excessive additional security parameter can cause the power consumption of the tag to not meet the low-power consumption requirement, and the increase in the register capacity can also cause an additional large chip area and power consumption overhead. The calculation and deduction of the security key and the security parameter can also cause additional power consumption and additional time delay. The additional time delay can affect the inventory efficiency, and especially in a scenario with a large number of tags (such as 1000 tags serially accessing the reader), the additional time delay can also cause the power of the tag to not be maintained to successfully access the reader, thereby causing the service to fail.

[0218] To solve the above problems, the present application provides a communication method 800, which can save the calculation and storage overhead of the security key and the like. FIG. 8 shows a flowchart of the communication method 800, and as shown in FIG. 8, the communication method 800 can include steps S810, S820, and S830.

[0219] S810: The second device sends first indication information.

[0220] Correspondingly, the first device receives the first indication information. Specifically, the first indication information is used to indicate the type of service between the first device and the second device and / or to indicate the execution of a security operation. The type of service includes at least one first service, and the first service includes a process based on the security operation to complete the data transmission process.

[0221] In an embodiment of the present application, the execution of the security operation can be the processing or operation of encryption protection and / or integrity protection. The purpose is to encrypt and / or integrity protect the uplink and downlink data between the reader and the tag to prevent attacks by attackers. In addition, the execution of the security operation can also be other security protection operations, such as anti-replay attack or anti-tampering.

[0222] In the embodiments of the present application, the data transmission process based on the security operation can be a part of the data transmission process in the first service, which is the process to be executed with the security operation in the service processing. In other words, the part of the data transmission process needs to be executed with the security operation, such as the security protection based on the key, to realize the uplink or downlink transmission. For example, when the first service is the write service, the process of the tag receiving the data to be written from the reader needs to be executed with the security protection based on the security key, otherwise, it will cause the tag to write the error information, which is the aforementioned data transmission process based on the security operation.

[0223] Optionally, the aforementioned data transmission based on the security operation can include the uplink data transmission or the downlink data transmission between the first device and the second device. When the data transmission between the first device and the second device includes the third device as the intermediate node, it can also include the uplink data transmission or the downlink data transmission between the first device and the third device, or it can include the uplink data transmission or the downlink data transmission between the third device and the second device.

[0224] For example, when the first device is the tag, the third device is the reader, and the second device is the core network device, the data transmission between the tag and the core network can include the uplink and downlink data transmission between the tag and the core network device, it can also include the uplink and downlink data transmission between the tag and the reader, and it can also include the uplink and downlink data transmission between the reader and the core network device.

[0225] Optionally, in some other cases of the embodiments of the present application, the second device can send the second indication information, which is used to indicate that the security operation is not executed and / or is used to indicate that the service type of the communication between the first device and the second device does not include the first service, that is, the service of the communication between the first device and the second device does not include the process of the data transmission based on the security operation, or it only includes the process of the data transmission which does not need to be based on the security operation. Correspondingly, the first device can not execute any security operation after receiving the second indication information in this case.

[0226] Exemplarily, not executing the security operation can include at least one of the following processes: discarding or releasing the security parameter, not generating the session key and other security keys for data transmission, not encrypting the (all or part of) data transmission, and not performing the integrity protection on the (all or part of) data transmission.

[0227] Exemplarily, as mentioned above, the service types of the communication between the first device and the second device include, but are not limited to, inventory service, command service, read service, write service, lock service, positioning service, proximity determination service, sensor service, kill or disable service, and device number inventory service. The first service can be one or more of the read service, the write service, the lock service, and the kill or disable service, which have higher requirements for security.

[0228] Those skilled in the art should understand that the data transmission or signaling interaction between the first device and the second device needs to pass through the third device. For example, the third device can directly forward the message of the first device or the second device. For another example, the third device can also process the received message content (such as NAS PDU or MAC SDU) and then send it, such as adding an access layer / air interface header (such as MAC header, physical layer frame header such as preamble, CRC, etc.), or performing physical layer processing such as scrambling, modulation, etc. For another example, the third device can also determine the indication information sent to the first device according to the indication information sent by the second device (different from the indication information sent by the second device).

[0229] The following figures omit some steps of signaling that need to be forwarded by the third device for the sake of simplicity. For example, the first indication information needs to be forwarded by the third device, and the step of forwarding is omitted in the figure for the sake of simplicity. The interaction process between the first device and the third device and the interaction process between the third device and the second device can refer to the description shown in FIG. 7, which is not repeated here. For the sake of description, the following describes the technical solutions of the present application by taking the direct interaction between devices (i.e., without intermediate nodes) as an example.

[0230] In addition, the communication method 800 can be executed by the first device, the second device, and the third device, or can be executed by a module such as a chip system or a circuit in the first device, the second device, and the third device, or can be executed by a logic node, a logic module, or software that can realize all or part of the functions of the first device, the second device, and the third device, and the present application does not limit this.

[0231] In the embodiments of the present application, the first device can be the aforementioned tag (or A-IoT terminal device); the second device can be the aforementioned core network device, or an access network device such as a base station or a terminal device, or the second device can also be a server (third party) such as an Internet of Things server, etc.; and the third device can be a network device, a terminal device or a reader / writer.

[0232] Optionally, the first device can receive a paging message from the third device, and the paging message includes the first indication information. Correspondingly, the second device can send a service request message to the third device, and the service request message includes the first indication information. Optionally, in some other embodiments of the present application, the first device can receive first downlink data from the second device, and the first downlink data includes the first indication information. This part will be described in detail below in combination with embodiments, and thus will not be described here in detail.

[0233] Optionally, in some other cases of the embodiments of the present application, the first indication information can also be determined by the third device from the indication information received from the second device. For example, the second device such as a core network device indicates to the third device that the service type between the first device and the second device includes the first service and / or performs a security operation, and then the third device generates the first indication information according to the indication of the second device and sends the first indication information to the first device through a paging message or first downlink data. Here, the interface (such as NG-AP or XX-AP) between the second device and the third device is different from the interface between the first device and the third device, and thus the format of the message received by the third device from the second device can be different from the format of the message received by the first device from the third device, i.e., the content of the indication information can be different. Then, the third device can generate the first indication information according to other indication information sent by the second device.

[0234] Optionally, in some other cases of the embodiments of the present application, the first indication information can also be determined and generated by the third device itself and sent to the first device through the aforementioned paging message or first downlink data.

[0235] Optionally, the aforementioned paging message can include a Paging message or the select signaling shown in FIG. 6, which is used to page or select or trigger one or more devices. The access trigger message includes a Query message or a QueryRep message, which will be described below.

[0236] Optionally, the Paging message can be used to instruct the tag to access the reader. For example, when the reader is a base station / access network device, the Paging message can be used to instruct the tag to access the network; when the reader is a terminal device, the Paging message can be used to instruct the tag to access the terminal, and optionally, the reader can access the network through the terminal.

[0237] Optionally, the Paging message can also be used to trigger / instruct the tag to send uplink data, or to trigger / instruct / request the tag to perform any of the following services or processes: paging service, inventory service, command service (such as read, write, deactivate, lock, etc.), positioning service, sensing service.

[0238] Optionally, the Paging message can also be referred to as an (initial) trigger message. The Paging message can be triggered by an A-IoT sensing core network node (such as an AMF, or an ambient IoT management function (A-IoT MF), an ambient IoT function (AIoTF), etc.). For example, the A-IoT sensing core network node sends a service request message or a paging message to an A-IoT access network node, and the A-IoT access network node sends the Paging message according to the service request message or the paging message. The service requested by the service request message can be a service related to an application scenario, for example, can be at least one of the following: inventory service, command service, positioning service, sensing service, proximity, read service, write service, deactivate service, lock service, or security service (such as authentication, authorization, registration, etc.), or a new service type defined in the future, without limitation on the specific naming.

[0239] Optionally, the Paging message can also be referred to as an inventory trigger / instruction / request message, or a command trigger / instruction / request message. For example, the inventory trigger / instruction / request message is used to trigger / instruct / request the tag to perform inventory, and the command trigger / instruction / request message is used to trigger / instruct / request the first device to perform command.

[0240] Optionally, the paging message can include identification information for selecting / filtering the communication device, such as device ID, mask, group identification, temporary identification, permanent identification (such as not lost due to power below threshold / running out), temporary identification (such as only maintained for a period of time, such as possibly lost due to power below threshold / running out), access stratum (AS) ID, etc.

[0241] Exemplarily, the first field can be a 1bit, where a value of 0 indicates no security operation (e.g., security OFF) and a value of 1 indicates security operation (e.g., security ON). For another example, the first field can be a service identification information field, i.e., a value of the service identification information field is used to indicate a service type of the communication between the first device and the second device. For example, values of 0-3 of the service identification field correspond to the aforementioned inventory service, positioning service, sensing service and command service (which needs security protection). In an embodiment of the present application, the value of the service identification field can include 3 (and can also include other values corresponding to other services), i.e., the first device and the second device include the command service which has a security protection process.

[0242] Optionally, the first indication information can also indicate the security operation by security level information, etc. For example, a high security level of the communication between the first device and the second device can correspond to the security operation (e.g., security ON), and a low security level of the communication between the first device and the second device can correspond to no security operation (e.g., security OFF). In other words, the second device can configure or indicate whether to perform the security operation according to different security levels of the communication between the first device and the second device, and the first indication information corresponds to a higher security level. For another example, different types of first devices (such as the different types of tags introduced above) can correspond to different security levels, such as a low-capability first device (such as the aforementioned device 1 or device A) can not perform the security operation (such as generating a key for encryption protection and / or integrity protection) by default or after receiving the security OFF indication, and a high-capability first device (such as the aforementioned device 2b or device C) can perform the security operation by default.

[0243] Optionally, in the case where the first indication information is used to indicate the security operation, based on the O-RAN architecture in FIG. 5, the second device can dynamically configure the first indication information based on the RIC (such as using an AI model therein), i.e., dynamically configure the indication of whether the security operation needs to be activated based on the RIC. The RIC can be any network element in the core network device. At this time, the second device can determine whether the security operation needs to be performed currently according to prior information of the first device, and indicate the determination result to the CU in the third device, i.e., the process has an additional step of providing the prior information to the CU by the RIC.

[0244] For example, the RIC can instruct the CU not to perform the security operation when the prior information or the historical data indicates that the first device is an A-IoT terminal device in a sealed warehouse and the sealed warehouse does not support the security operation. For another example, the RIC can instruct the CU not to perform the security operation when the prior information or the historical data indicates that the first device is a low-cost device and the security requirement is low. For another example, the RIC can instruct the CU to perform the security operation, i.e., instruct the CU the first indication information, when the prior information or the historical data indicates that the security requirement of the first device is high.

[0245] Optionally, when the second device needs to interact with multiple devices including the first device, the second device can inventory or trigger a service process for different devices in turns according to the security level of different devices or whether to perform the security operation or the service type. For example, the second device can first inventory or trigger a service process for an A-IoT device with a high security level (or needing to perform a security operation or including a first service in the service type).

[0246] Optionally, as described above for the inventory service, the first device needs to report its identification information to the second device. When the identification information of the first device needs to be encrypted or said privacy protected, the first device can receive a first parameter from the second device to perform privacy protection on the identification information of the first device by using the first parameter. The first parameter is a parameter generated by the second device for identification information privacy protection. The following embodiments will be described in detail, and the description will not be repeated here.

[0247] S820: The first device generates a first key according to the first indication information.

[0248] Correspondingly, in step S830, the second device generates the first key according to the first indication information. That is, as described above for FIG. 8, the first key is a key generated by the first device and the second device in alignment, for example, can be a key generated based on the same one or more parameters, and the generation algorithm (such as an encryption algorithm such as a hash algorithm, an integrity protection algorithm, etc.) is also the same. Specifically, the first key is used for security protection of communication between the first device and the second device, for example, the encryption protection and / or the integrity protection described above.

[0249] In addition, the first device and the second device can save the first key after generating the first key. The saved first key can be used not only for security protection of communication between the first device and the second device in the current access opportunity, but also can be used by the second device for multiple times, that is, the first key can have a long storage time for repeated use by the second device. The first device can release the first key after a period of time to save storage space. Alternatively, the storage time of the first key can be specified by the second device. The scheme of saving the first key will be described in detail below.

[0250] It should be understood that the first indication information is information for instructing the first device to generate the first key, rather than a generation parameter or an input parameter of the first key. In other words, the first indication information can trigger the first device to generate the first key. The generation process of the first key will be described below, that is, the first key is generated according to multiple key generation parameters.

[0251] It should be noted that the first key can also be used for other security protection such as tamper protection between the first device and the second device. The type of security protection is not limited in the present application, and the encryption protection and integrity protection will be described as examples in the embodiments below.

[0252] Alternatively, in some other cases of the embodiments of the present application, if the first device receives the second indication information indicating not to perform the security operation and / or indicating that the service type of communication between the first device and the second device does not include the first service, that is, the service of communication between the first device and the second device does not include the process of completing data transmission based on the security operation, the first device can not perform any security operation. Not performing the security operation can include at least one of the following processes: discarding or releasing the security parameter, not generating the session key and other security keys for data transmission, not encrypting (all or part of) data transmission, and not performing integrity protection (all or part of) data transmission.

[0253] Exemplarily, FIG. 9 shows a schematic flow chart of generating the first key according to an embodiment of the present application. As shown in (a) of FIG. 9, the first device receives the second parameter through step S821, generates the third parameter through step S822 (or the third parameter can also be pre-stored by the first device), and sends the third parameter to the second device through step S823, and then the first device generates the first key based on at least the second parameter and the third parameter through step S824. Correspondingly, the second device generates and sends the second parameter through step S821, receives the third parameter through step S823, and then generates the first key based on at least the second parameter and the third parameter through step S830. That is, the second parameter is a parameter generated by the second device for key generation, and the third parameter is a parameter generated by the first device for key generation.

[0254] Exemplarily, FIG. 10 shows a schematic diagram of a key generation flow according to an embodiment of the present application. As shown in FIG. 10, corresponding to step S821, the reader carries the random number / prior information / fresh number RAND1 (i.e. the aforementioned second parameter) as an input parameter of the security algorithm in a paging message. The RAND1 can be updated each time the paging is performed, so as to ensure that the subsequent security algorithm input parameter has a certain freshness. Corresponding to step S822, the tag needs to temporarily save the RAND1 after receiving the RAND1, and generates a random number / prior information / fresh number RAND2 (i.e. the aforementioned third parameter) (which can also be pre-stored), and then generates RES1 (such as a response or a user / device response) based on at least the RAND1 and the RAND2.

[0255] After that, the tag can perform the inventory / access procedure with the reader as shown in FIG. 6. That is, the tag and the reader interact through the procedure shown in FIG. 6. Corresponding to step S823, the tag sends its ID (which can be encrypted by using the pre-stored key), RES1 (used for the core network device CN to verify the validity of the message), RAND2 (telling the CN the a priori information generated by the electronic tag device, used for subsequent key generation and RES1 verification), and key id (used to indicate which pre-stored key is used by the electronic tag device, and the CN can find the key used by the electronic tag device according to the key id, that is, the pre-stored key mentioned above) to the CN through the first uplink data. Further, corresponding to steps S824 and S830, the tag and the CN can generate (that is, consistently generate and save) the session key for data encryption protection and the security key such as the message authentication code for integrity (MAC-I) MAC-I for integrity protection according to the aforementioned security parameters. The input parameters of the session key at least include RAND2, RAND1, and key id, and the input parameters of the MAC-I can be RAND1, RAND2, etc.

[0256] It is worth noting that the session key can also be called transaction key, group key, service key, etc. The security keys and security parameters shown in FIG. 10 are only examples, and the security keys in the embodiments of the present application can also be parameters with similar functions of Session key or MAC-I. The present application does not limit the names of the keys such as MAC-I, session key, or security parameters such as RAND and RES.

[0257] Finally, as shown in FIG. 8, the uplink and downlink data exchanged between the tag and the core network device CN can be securely protected by the aforementioned Session key and MAC-I. Further, corresponding to step S650, the reader sends the QueryRep message to the tag again. Correspondingly, after receiving the QueryRep message from the reader, the tag indicates that the data transmission is successful, and then the state of the inventory flag can be reversed.

[0258] Alternatively, RAND1 in FIG. 10 can also be used for privacy protection of the ID of the tag, that is, RAND1 can also be used as the first parameter for privacy protection of the identification information of the first device. In this way, in the first uplink data shown in FIG. 10, the tag sends the CN the encrypted or privacy-protected ID.

[0259] As shown in (a) of FIG. 9, in step S823, the first device needs to send the third parameter to the second device through the third device, i.e., the third device needs to schedule the third parameter (the second parameter can be contained in the aforementioned paging message and service request message). Thus, as shown in (b) of FIG. 9, in an embodiment of the present application, if the third device does not know the resource size for scheduling the third parameter, the second device can send third indication information to the third device through step S910, the third indication information being used to indicate the resource size for scheduling the third parameter. Further, the third device can send the third parameter to the second device through a first transport block in step S920 according to the third indication information. The first transport block includes the scheduling resource of the third parameter. Alternatively, in another embodiment of the present application, if the third device knows the scheduling resource size of the third parameter, the step S910 can not be included in the flow shown in (b) of FIG. 9.

[0260] FIG. 11 shows a diagram of a generation timing of the first key according to an embodiment of the present application. Alternatively, as shown in (a) of FIG. 11, if the first indication information is included in the paging message and the paging message includes the aforementioned second parameter, the first device can generate the first key after receiving the paging message. Alternatively, the first device can generate the first key before sending the first uplink data shown in (a) of FIG. 11 (such as reading data or command response information). Alternatively, as shown in (b) of FIG. 11, in another embodiment of the present application, the first device can generate the first key after successfully accessing the third device, such as receiving a msg2 message indicating successful access to the third device. In this way, the temporary storage time of the first key can be reduced, and further, the storage overhead of the first device can be reduced.

[0261] Alternatively, the first device generates the first key in the case that the msg2 message indicates that the contention resolution is successful. At this time, the msg2 shown in FIG. 11 can be associated with the msg1, such as the msg2 containing the same identification information as the msg1 (all or part), or the identification information contained in the msg2 can be generated according to the information of the msg1 through operation, such as the msg2 being obtained by a hash function from the identification information (such as device ID) in the msg1.

[0262] In addition, the msg1 shown in FIG. 11 can also be called an RN, or a random access ID, or a random ID. The msg1 is used for contention resolution, or is used to distinguish different UEs in a random access / contention resolution process. The msg2 shown in FIG. 11 can also be called an ACK, or an Access ID response, or an access response, or a contention resolution identity (UE / device Contention Resolution Identity). The msg2 is used to indicate whether contention resolution is successful, and the ACK is used to associate a device by carrying a contention resolution identity.

[0263] Optionally, if the first device and the second device need to use the first key later, the first device and the second device generate and continuously save the first key until the first device and the second device no longer use the first key. If the first device and the second device use the first key only a small number of times, such as completing a security operation of uplink or downlink transmission only once based on the first key, the first device and the second device can release the first key after using the first key. Similarly, for the security parameters used to generate the first key, such as the second parameter and the third parameter, if the first device and the second device use them only a small number of times, the first device and the second device can release them after use. If the first device and the second device need to use them multiple times, or multiple data transmissions all need the security parameters, the first device and the second device can generate and save the security parameters for a period of time, and then release the security parameters when they are no longer used.

[0264] For example, when the first device and the second device use the first key only a small number of times, after generating the first key, the first device can release the generated first key by a specific storage time or by signaling interaction, so as to reduce the storage time of the first key, and further reduce the storage overhead. For example, releasing the first key can be that the first device does not continue to save the related information of the first key, or flushes the related information / cache / memory of the first key, or discards the information related to the first key. FIG. 12 shows a schematic diagram of releasing the first key by the first device according to an embodiment of the present application.

[0265] Exemplarily, the first device can release the first key after the first storage time. For example, the length of the first storage time can be determined according to the device capability information of the first device, that is, the stronger the capability of the first device, the longer the length of the first storage time, and vice versa. For another example, the length of the first storage time can also be related to the service type between the first device and the second device, for example, when there are more or higher priority services between the first device and the second device that need security protection, the length of the first storage time can be longer. For another example, the second device can indicate the first storage time to the first device, for example, as shown in option 1 in FIG. 12, the second device sends fourth indication information (which can be included in a paging message) to the first device through step S815, and the fourth indication information indicates the first storage time.

[0266] For another example, the first device can release the first key after receiving a specific signaling. For example, as shown in option 2 in FIG. 12, the first device releases the first key through step S860 after receiving a third message in step S840, and the third message can be used to indicate or trigger the next access opportunity of the first device, such as a query (Query) message or a repeated query (QueryRep) message as shown in FIG. 6. In addition, in other embodiments of the present application, the third message such as the query (Query) message or the repeated query (QueryRep) message can also indicate whether to release the key, such as through a MAC CE or a MAC header or other AS layer field indication. For another example, as shown in option 3 in FIG. 12, the first device releases the first key through step S860 after receiving a fourth message in step S850, and the fourth message can be used to instruct the first device to release the stored security parameters and / or keys.

[0267] Optionally, the Query message can also be referred to as an access opportunity indication / trigger (Access round indication / trigger) message, which is used to indicate / trigger at least one access opportunity, such as directly or indirectly indicating the total number of access opportunities, and can also be used to trigger the first access opportunity, or to trigger a new round of access, or to trigger the first device to re-access (re-access) after a failed access / data transmission.

[0268] Optionally, the QueryRep message can also be referred to as an access opportunity indication / trigger (access occasion indication / trigger) message, which is used to indicate / trigger the next access opportunity, and can also be understood as indicating / associating with the boundary (start or end) of an access opportunity.

[0269] The access opportunity can also be referred to as an access occasion, an access slot, etc., and each access opportunity can allow the first device to send an access (request), and / or contention resolution, and / or data transmission, etc.

[0270] Optionally, when the first device and the second device need to use the key multiple times, such as when there is some periodic trigger service between the first device and the second device or the service needs to repeatedly call the security key, the second device can instruct the first device to extend the storage time of the first key to continuously save the first key for a period of time. That is, the first key can be continuously saved for a period of time. FIG. 13 shows a schematic flowchart of extending the storage time of the first key according to an embodiment of the present application. For example, when the first key needs to be used multiple times between the first device and the second device, as shown in FIG. 13, after the first device and the second device generate the first key, the second device can send the fifth indication information to instruct the first device to extend the storage time of the first key or to instruct the extended storage time to be T1. Further, the first device releases the first key after T1.

[0271] Optionally, if the second device schedules the first device across time slots based on the AS ID, the second device can instruct the first device to extend the storage time of the first key through the fifth indication information, or can instruct the first device to release the first key when receiving the signaling carrying the temporary identifier.

[0272] For example, when the first device completes the service, if the second device needs to schedule the first device subsequently, the second device can directly schedule the first device by using a temporary identifier (such as an access stratum identifier (AS ID)). If the second device does not want to reassign or generate security parameters subsequently, the second device can reuse the currently generated security parameters for encryption / integrity protection of the uplink and downlink messages when scheduling the first device subsequently. Therefore, in this case, the first device can save the existing security parameters for a period of time when receiving the aforementioned temporary identifier such as the AS ID. The saving time can be indicated by the second device. For example, the indicated saving time can cover the time of scheduling the first device. For example, if the second device schedules the first device after 10 seconds, the second device can instruct the first device to release the security parameters after >10 seconds.

[0273] Optionally, in some other embodiments of the present application, the first device can request to delay the security operation, such as to delay the generation of the first key. For example, when the power of the first device is insufficient to support the generation of the first key, the first device can request to delay the generation of the first key. At this time, the second device can reply whether to agree to the delay request of the first device after receiving the request of the first device.

[0274] FIG. 14 shows a schematic flowchart of delaying performing a security operation by a first device according to an embodiment of the present application. In step S880, the first device sends a request message to a second device, the request message being used to request delaying performing a security operation, such as delaying generating the first key.

[0275] For example, as shown in option 1 of FIG. 14, if the second device agrees to delay performing the security operation by the first device, an acknowledgement message for the request message can be sent in step S891, the acknowledgement message being used to indicate allowing the first device to delay performing the security operation. Then, the first device can perform the security operation, such as generating the first key, after sleeping for a time T2, wherein the T2 can be the maximum time of the service indicated by the second device, or can be determined according to the charging time of the first device, or can be determined according to the capability of the third device.

[0276] Optionally, as shown in FIG. 14, in some other embodiments of the present application, after the time T2, the first device can send a re-access indication message to the third device to re-access to the third device, or the third device sends a reschedule indication message to the first device to reschedule the first device. For example, the reschedule indication message can be the RN 16 or the aforementioned AS ID as shown in FIG. 6, and the reschedule indication message can also carry the security parameter for security protection.

[0277] For another example, as shown in option 2 of FIG. 14, if the second device does not agree to delay performing the security operation by the first device, a denial message for the request message can be sent in step S895, the denial message being used to indicate not allowing the first device to delay performing the security operation. At this time, the second device can send a sixth indication message in step S896 to indicate the first device to re-access to the third device after a second time period, such as T3, or after the next paging. In other words, the first device does not re-access to the third device within the time period T3 or before the next paging.

[0278] For example, the identification information can identify whether the paging message is a retransmission paging message (or the current service without initiating a new service) or a newly transmitted paging message (initiating a new service). For another example, the aforementioned next paging can also be identified or associated with the service triggered by the current paging message by a service identification (or also can be referred to as a session identification, a task identification, etc., and the present application does not limit the identification name), such as service identification = 0 representing the current service without initiating a new service, and when the tag receives a paging message carrying a service identification = 1, it is determined as a new paging or a next paging.

[0279] The second device indicates the reason why the first device does not re-access the third device. In the random access or data transmission process, the first device will fail to access or transmit data, resulting in that the current service is not completed, so the first device will select an access opportunity again to access the third device, such as waiting for the next Query to select an access opportunity. However, in the re-access process of the embodiment of the present application, there is a case that the first device does not support security, but the second device does not allow the first device and the second device to perform no security operation. If the first device does not support or temporarily cannot support security operation, and the second device does not allow the first device without security protection to report the ID or transmit data, then the second device will not allow the first device to transmit data even if the first device re-accesses in the subsequent process, so the first device does not need to re-access, and can only wait for the next new service to re-initiate a new process.

[0280] According to the foregoing, at present, the first device will derive / save / send security key and related parameters (tens to hundreds of bits) regardless of the scenario of only inventory business, the scenario of inventory business and other business that does not need security protection, or the scenario of inventory business and business that needs security protection, which increases the additional storage overhead. In the communication method 800, the first device needs to generate the first key in the scenario of indicating the first device, that is, the first device generates the first key only when the first indication information is received. In the foregoing scenario that does not need security protection, the first device does not receive any indication of security protection, and thus does not generate the first key, thereby saving the overhead of the first device to calculate and store the first key and other security parameters.

[0281] The above describes the steps of the communication method 800 in combination with FIGS. 8 to 14. The specific embodiments of the flow of the communication method 800 will be described in combination with FIGS. 15 to 18. In embodiment 1, the specific flow of the communication method 800 when the first indication information is included in the paging message is described, in embodiment 2, the specific flow of the communication method 800 when the first indication information is included in the first downlink data is described, and in embodiment 3, the specific flow of the first device requesting to delay the execution of the security operation is described.

[0282] Embodiment 1:

[0283] FIG. 15 shows a flowchart of the communication method 800 provided by embodiment 1. In FIG. 15, the first device is taken as an example of a tag (such as an A-IoT terminal device), the second device is taken as an example of a core network device, and the third device is taken as an example of a reader such as a base station. In the flow shown in FIG. 15, the core network device knows whether the tag needs security protection, and thus can directly carry the first indication information through the service request message. The flow shown in FIG. 15 can also be referred to as method 1500.

[0284] As shown in (a) of FIG. 15, corresponding to step S810 in the communication method 800, the core network device sends a service request message to the reader through step S1510, the service request message including the first indication information, and the reader sends a paging message to the tag through step S1515, the paging message including the first indication information.

[0285] In addition, since the tag needs the RAND1 (i.e., the second parameter shown above) to generate the first key, and further corresponding to step S921 shown in FIG. 9, the core network device sends a service request message to the reader through step S1510, the service request message including the RAND1, and the reader sends a paging message to the tag through step S1515, the paging message including the RAND1. That is, both step S910 and step S921 can be implemented through step S1510 and step S1515.

[0286] After that, the tag can finally send its ID to the core network device through the first uplink data through the inventory process as shown in FIG. 6. In addition, since the core network device needs the RAND2 (i.e., the third parameter described above) and the key id to generate the first key, and further corresponding to step S823 shown in FIG. 9, the tag can also send the RES1, the RAND2, and the key id, etc. to the core network device through the first uplink data.

[0287] Alternatively, if the ID of the tag needs to be protected, the tag can also use the RAND1 (i.e., the first parameter described above) to encrypt or protect the privacy of the identification information ID. Further, the ID sent by the tag to the core network device through the first uplink data is the ID after the privacy protection by the RAND1.

[0288] Then, corresponding to steps S820 and S830, the tag and the core network device can generate a session key for encryption protection based on at least the aforementioned RAND1, RAND2, and key id, and can generate a MAC-I for integrity protection based on at least the aforementioned RAND1 and RAND2. Further, as shown in (a) of FIG. 15, the uplink data and / or the downlink data between the tag and the core network device can be encrypted and protected by the aforementioned session key, and can be integrity protected by the aforementioned MAC-I.

[0289] The generation time of the session key and the MAC-I can refer to the description of the process shown in FIG. 11. That is, the generation time of the session key and the MAC-I can be after the tag receives the paging message of step S1515, or can be after the access is successful, i.e., after receiving the A-IoT msg2 message.

[0290] Optionally, corresponding to the flow shown in FIG. 12, after the tag and the core network device generate the first key, the core network device can instruct the tag to release the first key, so as to reduce the temporary storage space of the tag.

[0291] For example, corresponding to step S815 shown in FIG. 12, the fourth indication information can also be included in the service request message and the paging message. That is, the core network device can send, through step S1510, the service request message including the fourth indication information to the reader, and the reader sends, through step S1515, the paging message including the fourth indication information to the tag. The fourth indication information can be used to indicate the storage time T0 of the tag, that is, the tag can release the first key through step S1570 after T0 time after receiving the fourth indication information.

[0292] For another example, corresponding to step S840 shown in FIG. 12, the tag can release the first key through step S1570 after receiving the repeated message or the repeated query message through step S1540. In other words, the repeated query message shown in (a) of FIG. 15 is the third message shown in FIG. 12. For another example, corresponding to step S850 shown in FIG. 12, the tag can release the first key through step S1570 after the reader receives the release signaling from the core network device through step S1550 and the tag receives the release signaling from the reader through step S1560. In other words, the release signaling shown in (a) of FIG. 15 is the fourth message shown in FIG. 12.

[0293] Optionally, corresponding to the flow shown in FIG. 13, after the tag and the core network device generate the first key, the core network device can instruct the tag to extend the storage time of the first key, so as to cope with the periodic triggered service or the service requiring repeated calling of the security key. Corresponding to step S870, as shown in (a) of FIG. 15, the reader receives the fifth indication information from the core network device through step S1575, and the tag receives the fifth indication information from the reader through step S1580. The fifth indication information can be used to instruct the first device to extend the storage time of the first key, and the extended storage time is T1. Further, after the tag receives the fifth indication information, the tag releases the first key through step S1590 after T1 time.

[0294] (a) of FIG. 15 shows a flowchart of the communication method 800, and (b) of FIG. 15 shows a flowchart of the opposite case of the communication method 800, that is, the flowchart when the core network device and the tag do not need security protection.

[0295] As shown in (b) of FIG. 15, the core network device can indicate not to perform the security operation or indicate that the core network device and the tag do not include services requiring a security protection process after the tag through the second indication information. Further, as shown, the first uplink data can only include the ID of the tag and the like. Further, the tag and the core network device do not need to generate the first key, or in other words, do not need to generate any key for security protection. If there is still interaction of uplink data or downlink data between the tag and the core network device, the uplink data or the downlink data at this time also does not need any security parameter or security key protection.

[0296] Optionally, if the ID of the tag needs privacy protection, the service request message sent by the core network device and the paging message sent by the reader can not only include the second indication information, but also include the aforementioned first parameter RAND1 as shown in (a) of FIG. 15.

[0297] By comparing the two cases in FIG. 15, it can be seen that through the communication method 800, in the scenario shown in (b) of FIG. 15, the tag will not generate the first key, that is, the tag does not need to perform derivation and save the first key, and does not need to temporarily store the security parameter for generating the first key. Further, the calculation cost and storage cost of the tag can be reduced.

[0298] Embodiment 2

[0299] FIG. 16 shows a flowchart of the communication method 800 provided by Embodiment 2. In FIG. 16, the first device is taken as a tag (such as an A-IoT terminal device), the second device is taken as a core network device, and the third device is taken as a reader such as a base station. In the flowchart shown in FIG. 16, when inventorying services, the core network device does not know whether the tag needs security protection, so the core network device needs to determine whether the tag needs security protection according to the identification information (ID) reported by the tag. Further, the core network device can directly carry the first indication information through the first downlink data. The flowchart shown in FIG. 16 can also be referred to as method 1600.

[0300] As shown in (a) of FIG. 16, in step S1605, the core network device determines that the tag needs security protection according to the ID reported by the tag, that is, determines the first indication information. Further, corresponding to step S810 shown in FIG. 8, the core network device sends the first downlink data through step S1610, and the first downlink data includes the first indication information.

[0301] Further, corresponding to step S821 shown in FIG. 9, the core network device sends the first downlink data including RAND1 (i.e. the aforementioned second parameter) for generating the first key through step S1610. Correspondingly, corresponding to step S823 shown in FIG. 10, the tag sends the second uplink data including RAND2 (i.e. the aforementioned third parameter) for generating the first key through step S1615. Further, the tag and the core network device can generate the first key such as the session key and the MAC-I for security protection according to at least RAND1 and RAND2.

[0302] The steps for releasing the key and prolonging the storage time of the key can refer to the corresponding description in Embodiment 1. The two processes are not described herein in Embodiment 2.

[0303] Further, in the process shown in (a) of FIG. 16, if the ID reported by the tag needs to be protected by the aforementioned RAND1 (i.e. the aforementioned first parameter). At this time, the RAND1 as the first parameter can be carried in the service request message and the paging message shown in FIG. 16. If the ID reported by the tag does not need to be reported, the core network device can not send the RAND1 as the first parameter. It is worth noting that the RAND1 in the first downlink data is the second parameter, so even if the ID does not need privacy protection, the RAND1 still needs to be included in the first downlink data. In other words, in the process shown in FIG. 16, the RAND1 can be both the first parameter and the second parameter, and the core network device can send the RAND1 twice.

[0304] Alternatively, in order to reduce the temporary storage space of the RAND1 as the first parameter, the tag can discard or release the RAND1 after sending the first uplink data. Wherein, releasing the first key can be that the first device does not continue to save the relevant information of the first key, or flushes the relevant information / cache / memory of the first key, or discards the information related to the first key. After receiving the RAND1 as the second parameter through the first downlink data, the tag can not temporarily save the RAND1 as the second parameter, but can generate the first key according to at least the RAND1 and the RAND2 while receiving the RAND1. In other words, the RAND1 as the second parameter is not temporarily saved at the tag side, and the tag can directly use the received RAND1 as the second parameter to calculate and derive the first key. In this way, the temporary storage space at the tag side can be saved.

[0305] FIG. 16(a) shows a flowchart of the communication method 800, and FIG. 16(b) shows a flowchart of the opposite case of the communication method 800, i.e. the process when the core network device and the tag do not need security protection afterwards.

[0306] As shown in (b) of FIG. 16, when the core network device determines the second indication information according to the ID reported by the tag, that is, the tag and the core network device do not need any security protection, the core network device can not perform any process. That is, the core network device and the tag do not need to generate the first key, or in other words, do not need to generate any key for security protection. If there is still uplink data or downlink data interaction between the tag and the core network device, the uplink data or downlink data at this time also does not need any security parameter or security key protection.

[0307] Optionally, if the ID of the tag needs privacy protection, the service request message sent by the core network device and the paging message sent by the reader can also include the first parameter RAND1 as shown in (a) of FIG. 16.

[0308] By comparing the two cases in FIG. 16, it can be obtained that through the communication method 800, in the scenario shown in (b) of FIG. 16, each tag can indicate whether security protection is needed, or in other words, each tag reports its own ID, so that the core network device can determine whether to perform security operation based on the granularity of each tag. In addition, the tag does not generate the first key, that is, the tag does not need to derive and save the first key, nor needs to temporarily store the security parameter for generating the first key. Further, the calculation cost and storage cost of the tag can be reduced.

[0309] In the process shown in FIG. 16, when RAND1 is used for both the first parameter and the second parameter, the core network device needs to send RAND1 to the tag twice, that is, by sending the service request message and the first downlink data. Alternatively, in some other embodiments of the present application, the reader can cache the RAND1, and then the core network device can only need to send indication information to inform the reader to send RAND1 to the tag.

[0310] FIG. 17 shows a flowchart of another communication method provided by the embodiments of the present application, in which the reader can cache the received RAND1 from the core network device. The flowchart shown in FIG. 17 can also be referred to as method 1700. As shown in FIG. 17, when the core network device sends the RAND1 to the reader through the service request message, the reader can cache the RAND1. When the core network device determines that security protection is needed between the two devices according to the ID of the tag, the core network device can send the seventh indication information to the reader through step S1713, which can be used to indicate that there is data to be transmitted that needs security protection in the future, or to instruct the reader to send the cached RAND1 to the tag. Further, the reader can send the cached RAND1 to the tag through step S1715. The other steps in FIG. 17 can refer to the foregoing description, which will not be described here.

[0311] Embodiment 3

[0312] FIG. 18 shows a flowchart of the communication method 800 provided by embodiment 3. In the flowchart shown in FIG. 18, the tag cannot support the subsequent calculation and derivation of security parameters due to insufficient power and other reasons, and therefore requests the core network device to delay the execution of the security operation such as generating the first key.

[0313] As shown in FIG. 18, corresponding to step S880 in FIG. 14, the tag can send the A-IoT msg1 (RN16) message through step S1881 of option 1, which includes the request message for requesting to delay the execution of the security operation, or the tag can send the A-IoT msg3 message through step S1885 of option 2, which includes the request message for requesting to delay the execution of the security operation.

[0314] Optionally, when the core network device agrees with the request of the tag, corresponding to step S891 in FIG. 14, the core network device can send the ACK through step S1891 of option 3, that is, the confirmation response message in step S891. And, corresponding to step S892 in FIG. 14, the reader can send the AS ID or RN16 to the tag to reactivate the tag. In other words, the rescheduling message in step S992 can include the aforementioned AS ID or RN16.

[0315] Optionally, when the core network device does not agree with the request of the tag, corresponding to step S895 in FIG. 14, the core network device can send the NACK through step S1895 of option 4, that is, the negative response message in step S895. And, corresponding to step S995 in FIG. 14, the core network device sends the sixth indication information through step S1896 to instruct the tag not to re-access within a certain time period or before the next paging.

[0316] Finally, the device embodiment of the embodiment of the application is introduced.

[0317] In order to realize the functions in the method provided by the application, the communication device such as a terminal device or a base station can include a hardware structure and / or a software module to realize the above-mentioned functions in the form of hardware structure, software module, or hardware structure plus software module. Whether a certain function in the above-mentioned functions is executed in the form of hardware structure, software module, or hardware structure plus software module depends on the specific application of the technical solution and the design constraint conditions.

[0318] FIG. 19 is a schematic block diagram of a communication device 1900 of an embodiment of the application. The communication device 1900 can be a first device such as a tag or an A-IoT terminal device, or the communication device 1800 can be a second device such as a core network device. In addition, the communication device 1900 can also be a chip or a module in the first device or the second device, etc. device, used to realize the method related by the above-mentioned embodiments. The communication device 1900 includes a transceiver unit 1910 and a processing unit 1920. The transceiver unit 1910 is exemplarily introduced as follows.

[0319] The transceiver unit 1910 can include a sending unit and a receiving unit. The sending unit is used to perform the sending action of the communication device, and the receiving unit is used to perform the receiving action of the communication device. For the convenience of description, the sending unit and the receiving unit are combined into one transceiver unit in the embodiments of the application. This is uniformly described here, and will not be repeated hereinafter.

[0320] In some embodiments of the application, the transceiver unit 1910 can also be referred to as a transceiver or a transceiver, etc. It can include an antenna and a radio frequency circuit, wherein the radio frequency circuit can be used for conversion between baseband signals and radio frequency signals and processing of the radio frequency signals, and the antenna can be used for transceiving radio frequency signals in the form of electromagnetic waves. The foregoing radio frequency circuit and the foregoing antenna can be arranged independently of the processor performing baseband processing, that is, as a separately arranged module, for example, in a distributed scenario, the radio frequency circuit and the antenna can be arranged in a radio frequency remote unit (RRU) independently of the communication device, in a remote manner.

[0321] In some other embodiments of the application, the transceiver unit 1910 can also be an input / output interface realized by only input / output circuit.

[0322] When the communication device 1900 is a first device, exemplarily, the transceiver unit 1910 is used to receive first indication information; the processing unit 1920 can be used to generate a first key according to the first indication information.

[0323] When the communication apparatus 1900 is the second device, the transceiver unit 1910 is configured to transmit the first indication information, and the processing unit 1920 is configured to generate the first key according to the first indication information.

[0324] The foregoing merely describes examples. When the communication apparatus 1900 is the first device or the second device, it will be responsible for performing the methods or steps related to the first device and the second device in the foregoing method embodiments.

[0325] Optionally, the communication apparatus 1900 further includes a storage unit (not shown in the figure), which is configured to store programs or codes for performing the foregoing methods.

[0326] FIG. 20 is a schematic block diagram of a communication apparatus 2000 according to an embodiment of the present application. The communication apparatus 2000 includes a processor 2010 and a communication interface 2020, which can be connected to each other through a bus 2030. The communication apparatus 2000 can be the first device or the second device performing the communication method 800.

[0327] Optionally, the communication apparatus 2000 can further include a storage unit 2040. The storage unit 2040 includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or a compact disc read-only memory (CD-ROM), which is configured to store relevant instructions and data.

[0328] The processor 2010 can be one or more central processing units (CPUs). In the case where the processor 2010 is a CPU, the CPU can be a single-core CPU or a multi-core CPU.

[0329] The communication interface 2020 can include the foregoing antenna and the foregoing radio frequency circuit. The radio frequency circuit can be configured to convert a baseband signal and a radio frequency signal and process the radio frequency signal, and the antenna can be configured to transceive a radio frequency signal in the form of an electromagnetic wave. The foregoing radio frequency circuit and the foregoing antenna can be arranged independently of the processor performing baseband processing, that is, as a separately arranged module. For example, in a distributed scenario, the radio frequency circuit and the antenna can be arranged in a remote radio unit (RRU) independently of the communication apparatus, that is, in a pull-away manner.

[0330] When the communication apparatus 2000 is the first device, the communication interface 2020 is configured to receive the first indication information, and the processor 2010 is configured to generate the first key according to the first indication information.

[0331] When the communication apparatus 2000 is the second device, the communication interface 2020 is configured to send the first indication information, and the processor 2010 is configured to generate the first key according to the first indication information.

[0332] The above description is only exemplary. When the communication apparatus 2000 is the first device or the second device, it will be responsible for performing the methods or steps related to the first device or the second device in the foregoing method embodiments.

[0333] The above description is only exemplary. The specific content can be referred to the content shown in the foregoing method embodiments. The implementation of each operation of FIG. 20 can also correspond to the description of the corresponding method embodiments shown in FIG. 8 to FIG. 14.

[0334] The apparatus embodiments shown in FIG. 19 and FIG. 20 are used to implement the content shown in FIG. 8 to FIG. 14. The specific execution steps and methods of the apparatus shown in FIG. 19 and FIG. 20 can be referred to the content shown in the foregoing method embodiments.

[0335] FIG. 21 is a schematic block diagram of a communication apparatus 2100 according to an embodiment of the present application. The communication apparatus 2100 is configured to implement the functions of the first device or the second device. The communication apparatus 2100 can be a chip in the first device or the second device.

[0336] The communication apparatus 2100 includes an input / output interface 2120 and a processor 2110. The input / output interface 2120 can be an input / output circuit. The processor 2110 can be a signal processor, a chip, or other integrated circuits that can implement the method of the present application. The input / output interface 2120 is configured to input or output signals or data.

[0337] For example, when the communication apparatus 2100 is the first device, the input / output interface 2120 is configured to receive the first indication information, and the processor 2110 is configured to generate the first key.

[0338] For example, when the communication apparatus 2100 is the second device, the input / output interface 2120 is configured to send the first indication information, and the processor 2110 is configured to generate the first key.

[0339] In one possible implementation, the processor 2110 implements the functions of the first device or the second device by executing the instructions stored in the memory.

[0340] Optionally, the communication apparatus 2100 further includes a memory.

[0341] Optionally, the processor and the memory are integrated together.

[0342] Optionally, the memory is outside the communication apparatus 2100.

[0343] In a possible implementation, the processor 2110 can be a logic circuit, and the processor 2110 inputs / outputs messages or signaling through the input / output interface 2120. The logic circuit can be a signal processor, a chip, or other integrated circuits that can implement the method of the embodiments of the present application.

[0344] The above description of the communication apparatus 2100 is only exemplary, and the communication apparatus 2100 can be used to execute the method described in the foregoing embodiments. Details can be referred to the description of the foregoing method embodiments, which will not be repeated here.

[0345] Optionally, the memory is outside the communication apparatus 2100.

[0346] In a possible implementation, the apparatus 2100 can be a chip system 2100.

[0347] FIG. 22 is a schematic diagram of a chip system 2200 provided by the embodiments of the present application. The chip system 2200 (or also referred to as a processing system) includes a logic circuit 2210 (i.e., a processor 2110) and an input / output interface 2220.

[0348] The logic circuit 2210 can be a processing circuit in the chip system 2200. The logic circuit 2210 can be coupled to a storage unit, invoke instructions in the storage unit, so that the chip system 2200 can implement the method and function of each embodiment of the present application. The input / output interface 2220 can be an input / output circuit in the chip system 2200, output information processed by the chip system 2200, or input data or signaling information to be processed by the chip system 2200 for processing.

[0349] As an option, the chip system 2200 is configured to implement the operations performed by the first device or the second device in the above method embodiments.

[0350] For example, the input / output interface 2220 is configured to implement the sending and / or receiving operations performed by the first device or the second device in the above method embodiments.

[0351] The above description of the communication apparatus is only exemplary, and the communication apparatus can be used to execute the method described in the foregoing embodiments. Details can be referred to the description of the foregoing method embodiments, which will not be repeated here.

[0352] The application further provides a chip comprising a processor, configured to invoke and run instructions stored in a memory, so that a communication device installed with the chip performs the method in any of the examples.

[0353] The application further provides a chip comprising an input interface, an output interface and a processor, which are connected through internal connection paths, and the processor is configured to execute code in a memory, and when the code is executed, the processor is configured to perform the method in any of the examples. Optionally, the chip further comprises a memory configured to store a computer program or code.

[0354] The application further provides a processor configured to be coupled with a memory, and configured to perform the method and function in any of the embodiments involving a first device and a second device.

[0355] The application provides a computer program product comprising instructions, when the computer program product is run on a computer, the method of the foregoing embodiments is implemented.

[0356] The application further provides a computer program, when the computer program is run on a computer, the method of the foregoing embodiments is implemented.

[0357] The application further provides a computer readable storage medium, which stores a computer program, when the computer program is executed by a computer, the method of the foregoing embodiments is implemented.

[0358] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0359] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0360] In several embodiments provided in the present application, the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely illustrative. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0361] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the technical solutions of the embodiments of the present application.

[0362] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be a physically independent unit, or two or more units can be integrated in one unit.

[0363] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the parts that make contributions to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, and various other media that can store program codes.

[0364] The above description is merely a specific implementation of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any changes or replacements easily thought of by those skilled in the art within the technical range disclosed in the embodiments of the present application should be covered in the protection scope of the embodiments of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method comprises: receiving first indication information, the first indication information being used for indicating a service type of communication between a first device and a second device and / or for indicating performing a security operation, the service type comprising at least one first service, the first service comprising a procedure of completing data transmission based on the security operation, the security operation comprising encryption protection and / or integrity protection; generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

2. The method of claim 1, wherein, The receiving the first indication information comprises: receiving a first message, the first message being used for paging, selecting or triggering at least one device, the at least one device comprising the first device, the first message comprising the first indication information.

3. The method of claim 2, wherein, The generating the first key comprises: generating the first key after receiving the first message; or receiving a second message, the second message being used for indicating that the first device successfully accesses a third device; generating the first key.

4. The method of claim 1, wherein, The receiving the first indication information comprises: sending first uplink data, the first uplink data comprising first identification information of the first device, the first identification information being used for the second device to determine the first indication information; receiving first downlink data, the first downlink data comprising the first indication information.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: receiving a first parameter, the first parameter being used for security protection of the first identification information of the first device; sending first uplink data, the first uplink data comprising the first identification information after security protection.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: releasing the first key after generating the first key and through a first storage time; or receiving a third message or a fourth message, the third message being used for indicating or triggering a next access opportunity of the first device, the fourth message being used for indicating releasing a stored security parameter and / or key; releasing the first key.

7. The method according to any one of claims 1 to 6, characterized in that, The method further comprises: receiving fifth indication information, the fifth indication information being used for indicating that the first device prolongs a storage time of the first key.

8. A communication method characterized by comprising: The method comprises: sending first indication information, the first indication information being used for indicating a service type of communication between a first device and a second device and / or for indicating performing a security operation, the service type comprising at least one first service, the first service comprising a procedure of completing data transmission based on the security operation, the security operation comprising encryption protection and / or integrity protection; generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

9. The method of claim 8, wherein, The method further comprises: sending third indication information, the third indication information being used for indicating a time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; receiving the third parameter through a first transport block, wherein a time-frequency resource of the first transport block comprises a time-frequency resource of the third parameter.

10. The method according to claim 8 or 9, characterized in that, The method further comprises: sending seventh indication information, the seventh indication information being used for instructing the third device to send a second parameter cached to the first device, the second parameter being a parameter generated by the second device for key generation.

11. The method according to any one of claims 8 to 10, characterized in that, The sending of the first indication information comprises: sending a first message, the first message being used for paging, selecting or triggering at least one device, the at least one device comprising the first device, the first message comprising the first indication information.

12. The method according to any one of claims 8 to 11, characterized in that, The sending of the first indication information comprises: receiving first uplink data, the first uplink data comprising first identification information of the first device, the first identification information being used by the second device to determine the first indication information; sending first downlink data, the first downlink data comprising the first indication information.

13. The method according to any one of claims 8 to 12, characterized in that, The method further comprises: sending a first parameter, the first parameter being used for security protection of the first identification information of the first device; receiving first uplink data, the first uplink data comprising the first identification information after security protection.

14. The method according to any one of claims 8 to 13, characterized in that, The method further comprises: sending fifth indication information, the fifth indication information being used for instructing the first device to extend a storage time of the first key.

15. A communications device, characterized by The communication apparatus comprises units for implementing the method according to any one of claims 1 to 7.

16. A communications device, characterized by The communication apparatus comprises units for implementing the method according to any one of claims 8 to 14.

17. A communications device, characterized by comprises: a processor, coupled to a memory, for reading and executing instructions and / or program codes in the memory to perform the method according to any one of claims 1 to 7.

18. A communications device, characterized by comprises: a processor, coupled to a memory, for reading and executing instructions and / or program codes in the memory to perform the method according to any one of claims 8 to 14.

19. A communication system, characterized by comprises at least one communication apparatus according to claim 15 and at least one communication apparatus according to claim 16.

20. A chip system, characterized by comprises: a logic circuit, coupled to an input / output interface, for transmitting data through the input / output interface to perform the method according to any one of claims 1 to 7 or to perform the method according to any one of claims 8 to 14.

21. A computer readable medium characterized by The computer readable medium stores computer program codes which, when executed on a communication apparatus, cause the communication apparatus to perform the method according to any one of claims 1 to 7 or to perform the method according to any one of claims 8 to 14.

22. A computer program product, characterised in that, comprises computer program codes which, when executed, implement the method according to any one of claims 1 to 7 or implement the method according to any one of claims 8 to 14.

Citation Information

Patent Citations

  • Integrity protection key management method and device

    CN110035432A

  • Information sending method, key generation method and device

    CN110225517A

  • Wireless network authentication method and core network element, access network element and terminal

    WO2016180145A1