Communication method and device

By triggering network-side authentication by sending response messages from AIoT devices, the problem that existing authentication mechanisms cannot be applied to AIoT devices is solved, and the network can verify the authenticity of the content of AIoT devices.

WO2026051034A1PCT designated stage Publication Date: 2026-03-12GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing authentication mechanisms cannot be effectively applied to AIoT devices, causing the network to be unable to trust the authenticity of the content they report.

Method used

After receiving a service request through an AIoT device, it sends a response message to trigger the network-side authentication process, thus enabling the device itself to trigger network-side authentication.

Benefits of technology

This ensures that the network can trust the authenticity of the content reported by AIoT devices, thus achieving effective authentication of AIoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024117585_12032026_PF_FP_ABST
    Figure CN2024117585_12032026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method and device. The method comprises: receiving a first service request from a first network device, wherein the first service request is used for a first AIoT device to execute a first instruction; and sending a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used for triggering authentication of the first AIoT device.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device TECHNICAL FIELD

[0001] The present application relates to the field of communication, and more particularly, to a communication method and device. BACKGROUND

[0002] With the development of technology, AIoT (Ambient Power-enabled IoT) devices have the need to access a communication system or a communication network for data interaction. In existing mechanisms, the authentication of ordinary terminals is usually bidirectional authentication, such as triggering terminal authentication of the network by the network side, and then returning an authentication response from the terminal to the network, and the network authenticates the terminal by calculating and comparing the authentication response. However, due to the particularity of AIoT devices, the existing authentication mechanism cannot be used for AIoT devices. Therefore, how to design an authentication process that is more in line with the characteristics of AIoT devices so as to ensure that the network can trust the authenticity of the AIoT device reporting content has become a problem to be solved.

[0003] SUMMARY

[0004] Embodiments of the present application provide a communication method and device.

[0005] Embodiments of the present application provide a communication method performed by a first AIoT device, comprising:

[0006] receiving a first service request from a first network device, wherein the first service request is used for the first AIoT device to execute a first instruction;

[0007] sending a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0008] Embodiments of the present application provide a communication method performed by a first network device, comprising:

[0009] sending a first service request to a first AIoT device, wherein the first service request is used for the first AIoT device to execute a first instruction;

[0010] receiving a first response message from the first AIoT device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0011] Embodiments of the present application provide a communication method performed by a second network device, comprising:

[0012] receive a second authentication request from the first network device, wherein the second authentication request is used for authenticating the first AIoT device.

[0013] Embodiments of the present application provide a communication method performed by a first AIoT device, comprising:

[0014] receive a third service request from the first network device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is securely protected based on a security parameter.

[0015] Embodiments of the present application provide a communication method performed by a first network device, comprising:

[0016] send a third service request to the first AIoT device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is securely protected based on a security parameter.

[0017] Embodiments of the present application provide a first AIoT device, comprising:

[0018] a first communication unit, configured to receive a first service request from a first network device, wherein the first service request is used for the first AIoT device to perform a first instruction; and send a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0019] Embodiments of the present application provide a first network device, comprising:

[0020] a second communication unit, configured to send a first service request to a first AIoT device, wherein the first service request is used for the first AIoT device to perform a first instruction; and receive a first response message from the first AIoT device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0021] Embodiments of the present application provide a second network device, comprising:

[0022] a third communication unit, configured to receive a second authentication request from a first network device, wherein the second authentication request is used for authenticating a first AIoT device.

[0023] Embodiments of the present application provide a first AIoT device, comprising:

[0024] The first communication unit is configured to receive a third service request from the first network device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is secured based on a security parameter.

[0025] The first network device provided by the embodiments of the present application comprises:

[0026] The second communication unit is configured to send a third service request to the first AIoT device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is secured based on a security parameter.

[0027] By using the above scheme, in the case that the first AIoT device receives the first service request to trigger the execution of the first instruction, the first AIoT device sends the first response message carrying the response content corresponding to the first instruction at the same time, and triggers the network side to authenticate the first AIoT device. In this way, the network side can be triggered by the first AIoT device to authenticate it, so that the authenticity of the content reported by the first AIoT device can be guaranteed. BRIEF DESCRIPTION OF DRAWINGS

[0028] FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0029] FIG. 2 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0030] FIG. 3 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0031] FIG. 4 is a schematic flowchart of a communication method according to still another embodiment of the present application.

[0032] FIG. 5 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0033] FIG. 6 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0034] FIG. 7 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0035] FIG. 8 is a schematic flowchart of a communication process of inventory and / or command service of the first AIoT device according to an embodiment of the present application.

[0036] FIG. 9 is a schematic block diagram of a first AIoT device according to an embodiment of the present application.

[0037] FIG. 10 is a schematic block diagram of a first network device according to an embodiment of the present application.

[0038] FIG. 11 is a schematic block diagram of a second network device according to an embodiment of the present application. DETAILED DESCRIPTION

[0039] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example, LTE, LTE-A, NR, evolution of NR, WLAN, WiFi, or other communication systems, etc.

[0040] The embodiments of the present application describe various embodiments in combination with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminals can be stations in WLAN, and can be smart terminals, wireless modems, notebook computers, tablet computers, etc. In the embodiments of the present application, the terminals can be VR terminals / AR terminals, industrial control terminals, unmanned terminals, remote medical terminals, smart grid terminals, transportation safety terminals, smart city terminals, or wireless terminals of smart homes, etc. As an example but not limitation, in the embodiments of the present application, the terminals can also be wearable devices.

[0041] In the embodiments of the present application, the network devices can be devices for communicating with the terminals. The network devices can be access points in WLAN, can be evolved base stations in LTE, or relay stations, or network devices in vehicle-mounted devices, wearable devices, and NR networks, or network devices in future evolved PLMN networks, or network devices in non-ground networks, etc. As an example but not limitation, in the embodiments of the present application, the network devices can have mobile characteristics, for example, the network devices can be mobile devices.

[0042] In order to facilitate the understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described below. The following related technologies can be combined with the technical solutions of the embodiments of the present application as optional solutions, and all belong to the protection scope of the embodiments of the present application.

[0043] FIG. 1 illustrates a communication system 100. The communication system includes one network device 110 and two terminals 120. In a possible implementation, the communication system 100 can include multiple network devices 110, and each network device 110 can include other numbers of terminals 120 within the coverage of the network device 110, which are not limited in the embodiments of the present application. In a possible implementation, the communication system 100 can further include a mobility management entity, an access and mobility management function, and other network entities, which are not limited in the embodiments of the present application. The network device can include an access network device and a core network device. That is, the communication system can include multiple core networks for communicating with the access network device. The access network device can be a base station of an LTE, LTE-A, or NR system. For example, the communication system shown in FIG. 1 can include network devices and terminals with communication functions, and can further include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited in the embodiments of the present application.

[0044] In the related art, design targets of AIoT devices are given, which are as follows.

[0045] The target power consumption includes two types of peak power consumption of about 1 μW and peak power consumption less than or equal to several hundred μW. When the peak power consumption is about 1 μW, the AIoT device (Ambient IoT device) has an energy storage function, an initial sampling frequency offset (SFO) reaches 10X ppm, there is neither DL (downlink) amplification nor UL (uplink) amplification in the device, and the uplink transmission of the AIoT device is backscattering on an externally provided carrier. When the peak power consumption is less than or equal to several hundred μW, the AIoT device has an energy storage function, an initial sampling frequency offset (SFO) reaches 10X ppm, and there is DL and UL amplification in the device. The uplink transmission of the AIoT device can be generated internally or backscattered on an externally provided carrier.

[0046] The network topology includes Topology 1 and Topology 2. Topology 1: BS (Base station) The AIoT device, that is, the AIoT device directly communicates with the BS in a bidirectional manner, and the communication between the BS and the AIoT device includes ambient Internet of Things data and / or signals. Topology 2: BS Intermediate node AIoT devices, i.e. AIoT devices communicate with intermediate nodes, which can be relays, IAB nodes, UEs, repeaters, etc., in both directions, the intermediate nodes transmit Ambient IoT (referred to as AIoT or A-IoT for short) data and / or signaling between the BS and the AIoT devices. Here, topology 1 combines deployment scenario 1, i.e. AIoT devices are indoors, and the base station refers to a micro base station; topology 2 combines deployment scenario 2, i.e. AIoT devices are indoors, and UEs are indoors, UEs as intermediate nodes are under network control, and the base station refers to a macro base station.

[0047] Fig. 2 is a schematic flowchart of a communication method performed by a first AIoT device according to an embodiment of the application. The method comprises at least part of the following.

[0048] S210, receiving a first service request from a first network device, wherein the first service request is used for the first AIoT device to execute a first instruction;

[0049] S220, sending a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0050] Fig. 3 is a schematic flowchart of a communication method performed by a first network device according to an embodiment of the application. The method comprises at least part of the following.

[0051] S310, sending a first service request to a first AIoT device, wherein the first service request is used for the first AIoT device to execute a first instruction;

[0052] S320, receiving a first response message from the first AIoT device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0053] Fig. 4 is a schematic flowchart of a communication method performed by a second network device according to an embodiment of the application. The method comprises at least part of the following.

[0054] S410, receiving a second authentication request from a first network device, wherein the second authentication request is used to authenticate a first AIoT device.

[0055] The first network device can have AIoT-related functions, such as functions to serve AIoT services, etc.

[0056] Optionally, the first network device can comprise at least one of an AMF (Access and Mobility Management Function), an AIoTF (AIoT Function), or the like. The AIoTF can alternatively be referred to as an AIoT NF (Network Function), or an AIoT MF (Management Function), or the like.

[0057] Optionally, the first network device can comprise a read-write device. The read-write device can comprise at least one of an access network device, a terminal. The terminal can be a terminal with at least one of a relay function, a proxy function, a forwarding function, or the like. The terminal can also be referred to as an intermediate node, or an intermediate UE, or an intermediate device, or a proxy device, or a relay UE, or a relay device, or the like. Here, the possible names thereof are not limited or exhausted.

[0058] The second network device can be a network element with an authentication function. For example, the second network device can be at least one of an authentication function, an authentication network element, an AIoT authentication and authorization function, an AIoT authentication function, or the like.

[0059] The first network device and the second network device can be different entity devices, or can be the same entity device. When the first network device and the second network device are the same entity device, the first network device and the second network device can be two functions or two functional modules in the same entity device. The messages or information transmitted between the first network device and the second network device can be transmitted through an internal interface between the two functions or the two functional modules. The following will not be repeated.

[0060] In some possible implementation manners, the processing of the first network device can comprise receiving a service request of an AF (Application Function).

[0061] Optionally, the first network device receiving the service request of the AF can be that the first network device directly receives the service request of the AF.

[0062] Optionally, the first network device receiving the service request of the AF can be that the first network device receives the service request of the AF from a NEF (Network Exposure Function). The processing of the NEF can comprise receiving the service request of the AF, and sending the service request of the AF to the first network device. The processing of the AF can be that the AF sends the service request of the AF to the NEF.

[0063] The service request of the AF can carry at least one of the following: instruction content indicating an inventory operation, command content (hereinafter referred to as command content) indicating a command operation, an identifier of one or more AIoT devices, a related identifier of an AIoT device group, an identifier of a region where the one or more AIoT devices are located, and a geographic location of the region where the one or more AIoT devices are located.

[0064] The command content can include at least one of the following: reading data, writing data, disabling, enabling, and the like. The disabling refers to disabling of an RF (Radio Frequency) function module of the AIoT device, and the disabling can include at least one of the following: permanent disabling and temporary disabling. The enabling also refers to enabling of the RF function module of the AIoT device.

[0065] It should be noted that the above is only an exemplary description, and in actual processing, the service request of the AF can also carry other content, but here it is not limited or exhaustive.

[0066] In a case where the service request of the AF carries instruction content indicating an inventory operation, and carries at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, an identifier of a region where the one or more AIoT devices are located, and a geographic location of the region where the one or more AIoT devices are located, the service request of the AF can be an inventory service request, and a service scenario triggered or requested based on the service request of the AF can be an Inventory-only scenario.

[0067] In a case where the service request of the AF carries command content (or can carry instruction content indicating an inventory operation and command content), and the service request of the AF further carries at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, an identifier of a region where the one or more AIoT devices are located, and a geographic location of the region where the one or more AIoT devices are located, the service request of the AF can be a command service request (or an inventory and command service request), and a service scenario triggered or requested based on the service request of the AF can be an Inventory and Command scenario.

[0068] After the first network device receives the service request of the AF, the first network device can send a first service request to one or more AIoT devices. The first service request can be used to instruct the one or more AIoT devices to execute a first instruction, and the one or more AIoT devices include a first AIoT device.

[0069] The first instruction can be used for inventory. Specifically, the first instruction can include at least one of the following: instruction content indicating an inventory operation, first identification related information. The first identification related information includes at least one of the following: identification of one or more AIoT devices, related identification of an AIoT device group, identification of an area where the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0070] For example, the identification of the one or more AIoT devices can include only the identification of the first AIoT device.

[0071] The identification of the first AIoT device can include at least one of the following: a permanent identification of the first AIoT device, a temporary identification of the first AIoT device.

[0072] The permanent identification of the first AIoT device can be referred to as the real identification of the first AIoT device, or can be referred to as the long-term identification of the first AIoT device. The permanent identification of the first AIoT device can be at least one of the following: an ID (Identity) of the first AIoT device, an EPC (Electronic Product Code) of the first AIoT device. The ID of the first AIoT device can be simply denoted as first AIoT ID. The EPC of the first AIoT device can also be referred to as the EPC code of the first AIoT device.

[0073] It should also be pointed out that bitmask (bitmask, or MASK) can be issued together with the EPC code (such as in the first service request).

[0074] The temporary identification of the first AIoT device is different from the permanent identification of the first AIoT device, and the embodiment does not limit the composition of the temporary identification.

[0075] For example, the identification of the one or more AIoT devices can include the identification of each AIoT device in the plurality of AIoT devices. The identification of any AIoT device is described as the first AIoT device, and is not described again.

[0076] The related identification of the AIoT device group can include at least one of the following: a group of the AIoT device group (such as denoted as GID), a MASK (mask) of the AIoT device group.

[0077] The MASK of the AIoT device group can be used to find or page a specific group of AIoT devices (i.e., a plurality of AIoT devices in the specific AIoT device group).

[0078] For example, the MASK of the AIoT device group can be a partial identification (Partial of AIoT ID) of each AIoT device in the AIoT device group. The plurality of AIoT devices in the AIoT device group can have a plurality of bits with the same value and the same position in their identifications. The plurality of bits with the same value and the same position can be the same partial identification of the plurality of AIoT devices, and the same partial identification of the plurality of AIoT devices can be the MASK of the AIoT device group. For example, the MASK of the AIoT device group can include a home network ID and / or an ID for identifying a third party, because there can be multiple AIoT devices with the same home network ID and / or the same ID for identifying a third party, and thus the home network ID and / or the ID for identifying a third party can be the MASK of the AIoT device group in which the AIoT devices are located.

[0079] It should be understood that the above is only an example of the MASK of the AIoT device group, and in actual processing, the MASK of the AIoT device group can also be other components, such as a complete AIoT device identification, etc. The present embodiment does not limit or exhaust all possible components of the MASK of the AIoT device group, as long as the MASK of the AIoT device group can be used to find or page a plurality of AIoT devices in the specific AIoT device group.

[0080] The identification of the area in which the one or more AIoT devices are located can be used to find or page one or more AIoT devices located in a specific area, and the one or more AIoT devices include the first AIoT device. For example, the identification of the area can include at least one of the following: one or more TACs (TA codes, tracking area codes), and one or more TAIs (TA identities, tracking area identities).

[0081] Optionally, in addition to the instruction content indicating the inventory operation and the at least one of the first identification related information, the first instruction can also include other content, such as the geographical location of the area in which the one or more AIoT devices are located. The geographical location can be represented by geographical coordinates such as latitude and longitude. The present embodiment does not limit or exhaust all possible contents of the first instruction.

[0082] On the first network device side, the first instruction can be generated based on the service request of the AF.

[0083] In some examples, the service scenario triggered or requested by the service request of the AF is a discarding scenario. In this example, the service request of the AF carries instruction content indicating a discarding operation, and carries at least one of an identifier of one or more AIoT devices, a related identifier of an AIoT device group, an identifier of a region where the one or more AIoT devices are located, and a geographical position of the region where the one or more AIoT devices are located.

[0084] For example, the service request of the AF carries instruction content indicating a discarding operation, and carries at least one of an identifier of one or more AIoT devices, a related identifier of an AIoT device group, and an identifier of a region where the one or more AIoT devices are located. The first network device can determine at least one of the identifier of the one or more AIoT devices, the related identifier of the AIoT device group, and the identifier of the region where the one or more AIoT devices are located as first identification-related information; and generate a first instruction based on the first identification-related information and the instruction content indicating the discarding operation.

[0085] For example, the service request of the AF carries instruction content indicating a discarding operation and a geographical position of a region where one or more AIoT devices are located. The first network device can convert the geographical position of the region where the one or more AIoT devices are located into an identifier of the region where the one or more AIoT devices are located, determine the identifier of the region where the one or more AIoT devices are located as first identification-related information, and generate a first instruction based on the first identification-related information and the instruction content indicating the discarding operation. The specific processing manner of converting the geographical position of the region where the one or more AIoT devices are located into the identifier of the region where the one or more AIoT devices are located is not limited in this embodiment.

[0086] In some examples, the service scenario triggered or requested by the service request of the AF is a discarding and command scenario.

[0087] The service request of the AF carries command content or can carry instruction content indicating a discarding operation and command content, and carries at least one of an identifier of one or more AIoT devices, a related identifier of an AIoT device group, an identifier of a region where the one or more AIoT devices are located, and a geographical position of the region where the one or more AIoT devices are located.

[0088] In this example, the first network device can first perform a discarding operation, and therefore, the first network device can generate a first instruction for discarding.

[0089] For example, the service request of the AF carries the command content, and carries at least one of the identifier of the one or more AIoT devices, the related identifier of the AIoT device group, and the identifier of the area where the one or more AIoT devices are located. The first network device can determine at least one of the identifier of the one or more AIoT devices, the related identifier of the AIoT device group, and the identifier of the area where the one or more AIoT devices are located as the first identification related information; and generate the first instruction based on the first identification related information and the instruction content indicating the inventory operation.

[0090] For example, the service request of the AF carries the command content or the instruction content indicating the inventory operation and the command content, and carries the geographic location of the area where the one or more AIoT devices are located. The first network device can convert the geographic location of the area where the one or more AIoT devices are located into the identifier of the area where the one or more AIoT devices are located, determine the identifier of the area where the one or more AIoT devices are located as the first identification related information, and generate the first instruction based on the first identification related information and the instruction content indicating the inventory operation.

[0091] Optionally, the first service request can be used only for the first AIoT device to execute the first instruction, which can include the instruction content indicating the inventory operation and the first identification related information, which can include the identifier of the first AIoT device.

[0092] The first service request can be a paging request or an inventory request, or an Inventory (inventory) trigger message, etc., and the message name is not limited here.

[0093] If the first network device includes an AMF and / or an AIOTF, the first network device sending the first service request to the first AIoT device can include: sending the first service request to the first AIoT device by a reader-writer device. The first AIoT device receiving the first service request from the first network device can include: the first AIoT device receiving the first service request from the first network device through the reader-writer device. The first network device can select a base station or a UE as a reader. Here, the way the first network device selects the base station or the UE is not limited in the embodiment. For the case where the reader-writer device is a UE, the first network device sends a message containing an instruction that the UE serves as a reader-writer device to perform paging or inventory (i.e., the first service request) on the AIoT device through a control plane or a user plane connection with the UE.

[0094] The process that the first network device sends the first service request to the first AIoT device through the read-write device can be: the first network device sends the first service request to the read-write device, and sends indication information indicating that the device is the read-write device; after receiving the indication information indicating that the read-write device is the read-write device, the read-write device can send the first service request to the first AIoT device. The message type of the first service request sent by the read-write device can be a broadcast message or a unicast message. That is, the first network device sends the first service request to the AIoT device through the read-write device, and sending the first service request on the read-write device side means instructing the read-write device to perform paging or inventory on a single or multiple AIoT devices.

[0095] If the first network device includes the read-write device, the first network device sending the first service request to the first AIoT device can include directly sending the first service request to the first AIoT device.

[0096] Optionally, the first service request can be used for multiple AIoT devices to execute the first instruction, which can include instruction content indicating an inventory operation and first identification related information, which can include at least one of the following: identification of multiple AIoT devices, related identification of an AIoT device group, and identification of an area where one or more AIoT devices are located.

[0097] If the first network device includes the AMF and / or the AIOTF, the first network device sending the first service request to the first AIoT device can include sending the first service request to multiple AIoT devices through the read-write device, and the multiple AIoT devices include the first AIoT device.

[0098] Taking any one of the multiple AIoT devices as the first AIoT device as an example, the first AIoT device receiving the first service request from the first network device can include the first AIoT device receiving the first service request from the first network device through the read-write device.

[0099] The first service request can also be a paging request or an inventory request. The message type of the first service request sent by the read-write device can be a broadcast message, or a groupcast message, or a multicast message.

[0100] If the first network device includes the read-write device, the first network device sending the first service request to the first AIoT device can include directly broadcasting or groupcasting or multicasting the first service request to the multiple AIoT devices.

[0101] Since each AIoT device in the multiple AIoT devices receives the first service request and processes it in the same way as the first AIoT device, it will not be described one by one, and the following will not be repeated.

[0102] In some possible implementation manners, after the first AIoT device receives the first service request, the following processing can be performed: in a case where it is determined that the first identification related information in the first instruction carried in the first service request matches, the first AIoT device performs the inventory operation (or conducts the inventory operation, or conducts the inventory processing) based on the instruction content of the instruction in the first instruction indicating the inventory operation.

[0103] The manner in which the first AIoT device determines that the first identification related information in the first instruction carried in the first service request matches can include one of the following: in a case where the first identification related information in the first instruction carried in the first service request includes the identification of the first AIoT device, it is determined that the first identification related information in the first instruction carried in the first service request matches; in a case where the first identification related information in the first instruction carried in the first service request includes the related identification of the AIoT device group, and the identification of the group to which the first AIoT device belongs matches the related identification of the AIoT device group, it is determined that the first identification related information in the first instruction carried in the first service request matches; in a case where the first identification related information in the first instruction carried in the first service request includes the identification of one or more regions where AIoT devices are located, and the identification of the region where the first AIoT device is located matches the identification of the one or more regions where AIoT devices are located, it is determined that the first identification related information in the first instruction carried in the first service request matches.

[0104] In addition, after the first AIoT device receives the first service request, the following processing can also be included: in a case where it is determined that the first identification related information in the first instruction carried in the first service request does not match, the first AIoT device ends the processing.

[0105] The specific processing manner in which the first AIoT device performs the inventory operation is not limited in the embodiment. After the first AIoT device performs the inventory operation, the first response message can be sent to the first network device.

[0106] The first response message can carry the response content corresponding to the first instruction. The response content corresponding to the first instruction can include the identification of the first AIoT device.

[0107] The first response message is also used to trigger network authentication of the first AIoT device. The first response message can carry at least one of the following: a first authentication vector for authenticating the first AIoT device, and a first random number, wherein the first authentication vector is calculated based on a first key shared by the first AIoT device and the network and / or the first random number.

[0108] The first response message can be a paging response message or an inventory response message.

[0109] The first key shared by the first AIoT device and the network can be configured according to actual conditions. In a preferred example, the first key can be a root key of the first AIoT device. It should be pointed out that this is only an exemplary illustration. In actual processing, the first key can be other types of keys, as long as the key is shared by the first AIoT device and the network, it can be used as the first key, and the specific possible types of the first key are not limited or enumerated here.

[0110] The network can refer to a general network containing read-write devices, or the network can refer to an NPN (Non-Public Network).

[0111] For example, the network can include a core network side, and the core network device sharing the first key with the first AIoT device can at least include a second network device.

[0112] This embodiment does not limit or enumerate the specific other network devices of the network or the network side that share the first key with the first AIoT device. As long as the first network device can obtain the first key from the local or from other network devices, it is within the protection scope of this embodiment.

[0113] Optionally, the first random number can be generated by the first AIoT device. The way the first AIoT device generates the first random number is not limited in this embodiment.

[0114] Optionally, the first random number can be sent by the first network device to the first AIoT device, for example, the first service request can also carry the first random number. The first random number can be generated by the first network device.

[0115] In an embodiment, the first authentication vector can be calculated based on the first key and the first random number.

[0116] Specifically, the first authentication vector can be calculated by the first AIoT device based on the first key and the first random number using the first calculation method, or the first AIoT device calculates the first key and the first random number using the first calculation method. That is, the key used by the first AIoT device to calculate the first authentication vector is the first key, the input parameter used to calculate the first authentication vector includes the first random number, and the calculation method used to calculate the first authentication vector is the first calculation method.

[0117] The first calculation manner can be configured according to actual conditions, for example, the first calculation manner can be at least one of the following: a first authentication function (for example, it can be an f1 function defined in 3GPP), a second authentication function (for example, it can be an f2 function defined in 3GPP), a third key generation function (for example, it can be an f3 function defined in 3GPP), a fourth key generation function (for example, it can be an f4 function defined in 3GPP), a fifth key generation function (for example, it can be an f5 function defined in 3GPP), a hash algorithm, an AES (Advanced Encryption Standard), an ACSON (Automatically Controlled SONet), a SNOW 3G (Snow Third Generation), a ZUC (ZU Chongzhi), an exclusive or calculation, a direct connection calculation, a KDF (Key Derivation Function), and the like. The present embodiment does not make an exhaustive list.

[0118] For example, the calculation of the first authentication vector can be expressed by the following formula: AUTN_device = f K (RAND_1), where AUTN_device represents the first authentication vector, f is the first calculation manner, K is the root key of the first AIoT device, and RAND_1 is the first random number.

[0119] In one case, the first random number can be generated by the first AIoT device. In this case, the first response message can carry the first authentication vector and the first random number.

[0120] In another case, the first random number can be sent by the first network device to the first AIoT device. In this case, the first response message can only carry the first authentication vector.

[0121] In one embodiment, the first authentication vector can also be calculated based only on the first key. For example, the first authentication vector can be calculated by the first AIoT device based on the first key using the first calculation manner, or the first AIoT device calculates the first key using the first calculation manner. In this embodiment, the first response message can only carry the first authentication vector.

[0122] In some possible implementations, after receiving the first response message from the first AIoT device, the processing of the first network device can further include: sending a second authentication request to a second network device, wherein the second authentication request is used to authenticate the first AIoT device. Correspondingly, the second network device can receive the second authentication request from the first network device.

[0123] The second authentication request can carry at least one of the following: a first authentication vector for authenticating the first AIoT device, the first random number, and an authentication type, wherein the authentication type includes one of the following: one-way authentication and two-way authentication.

[0124] The first authentication vector in the second authentication request can be obtained from the first response message. In the case where the first response message carries the first random number, the first random number is carried in the second authentication request; in the case where the first response message does not carry the first random number, the first random number is not carried in the second authentication request.

[0125] The authentication type (indicator_auth) can refer to the authentication type of the first AIoT device or the authentication type corresponding to the first AIoT device. One-way authentication refers to authenticating the first AIoT device by the network only. Two-way authentication refers to authenticating the first AIoT device by the network and authenticating the network by the first AIoT device. The network (or network side) includes at least the second network device.

[0126] Optionally, in the case where the authentication type is determined by the first network device, the authentication type can also be carried in the second authentication request.

[0127] The manner in which the first network device determines the authentication type corresponding to the first AIoT device can be: in the case where the service scenario triggered or requested by the AF-based service request is an inventory-only scenario, determining that the authentication type corresponding to the first AIoT device is one-way authentication; and in the case where the service scenario triggered or requested by the AF-based service request is an inventory and command scenario, determining that the authentication type corresponding to the first AIoT device is two-way authentication.

[0128] Specifically, for the inventory-only scenario, the first network device can complete the service after collecting the information related to the identifier of the first AIoT device (i.e., the identifier of the first AIoT device carried in the first response message). From the network side, after authenticating the first AIoT device, the network can trust the information contained in the first response message reported by the first AIoT device, and it is unnecessary to trigger the authentication of the network by the first AIoT device. Therefore, in this case, the first network device can determine that the authentication type is one-way authentication.

[0129] For the inventory and command scenario, after receiving the first response message, the first network device can determine that it needs to send a Command request to the first AIoT device based on the AF-based service request, so the network side can trigger the authentication of the network by the first AIoT device, so that the first AIoT device trusts and executes the command issued by the network. Therefore, in this case, the first network device can determine that the authentication type is two-way authentication.

[0130] Alternatively, the authentication type corresponding to the first AIoT device can be configured or default at the first network device side according to actual conditions. For example, the first network device pre-configures the authentication type corresponding to the first AIoT device as one-way authentication or two-way authentication. In this case, the authentication type can also be carried in the second authentication request.

[0131] Alternatively, the authentication type corresponding to the first AIoT device can be default or pre-configured at the second network device, in which case the authentication type can not be carried in the second authentication request.

[0132] The processing of the second network device after receiving the second authentication request can include: calculating a first verification vector based on the first key shared by the first AIoT device and the second network device and / or the first random number; and authenticating the first AIoT device based on the first verification vector and the first authentication vector.

[0133] The second network device calculates the first verification vector in the same way as the first AIoT device calculates the first authentication vector, for example, the first authentication vector can be calculated based on the first key and the first random number using the first calculation method, and correspondingly, the first verification vector can also be calculated based on the first key and the first random number using the first calculation method, which will not be repeated here.

[0134] Authenticating the first AIoT device based on the first verification vector and the first authentication vector can be: in the case that the first verification vector and the first authentication vector are the same, authenticating the first AIoT device successfully; and in the case that the first verification vector and the first authentication vector are different, authenticating the first AIoT device fails.

[0135] The processing of the second network device can also include: in the case that the second network device fails to authenticate the first AIoT device, notifying the first network device of the authentication failure of the first AIoT device and / or ending the processing. Correspondingly, the processing of the first network device can also include: receiving the notification of the authentication failure of the first AIoT device from the second network device, and ending the processing.

[0136] In an embodiment, the authentication type of the first AIoT device is one-way authentication.

[0137] The processing of the second network device can further include: in a case where the authentication of the first AIoT device is successful, notifying the first network device that the authentication of the first AIoT device is successful; or in a case where the authentication of the first AIoT device is successful and the authentication type is one-way authentication, notifying the first network device that the authentication of the first AIoT device is successful. Correspondingly, the processing of the first network device can include: receiving the notification of the successful authentication of the first AIoT device from the second network device.

[0138] The second network device can determine the authentication type as one-way authentication in the following manners: the second network device can determine, by default, that the authentication type corresponding to the first AIoT device is one-way authentication; or in a case where the authentication type is carried in the second authentication request and the authentication type is one-way authentication, the second network device can determine that the authentication type corresponding to the first AIoT device is one-way authentication.

[0139] Optionally, the processing of the second network device can further include: sending, to the first network device, a second key used for protecting messages transmitted between the first AIoT device and the first network device. The processing of the first network device can further include: receiving the second key used for protecting messages transmitted between the first AIoT device and the first network device from the second network device.

[0140] The second key can be derived in the authentication process, and the second key can be denoted as K_autn.

[0141] The input key used by the second network device to derive the second key can be the first key or a subordinate key of the first key; and the input parameter used by the second network device to derive the second key can include at least one of the following: an identifier of the first AIoT device, a third random number, and the like.

[0142] The subordinate key of the first key can be derived from the first key, and the embodiment does not limit the specific derivation manner of the subordinate key of the first key.

[0143] The input parameter used to derive the second key can include at least one of the following: an identifier of the first AIoT device, a third random number, and the like, and can also include other parameters, such as an identifier of the first network device (such as at least one of an Instance ID, a number, an index number, and the like), and the like. The input parameter used to derive the second key is not limited or enumerated herein.

[0144] The calculation manner or calculation function used by the second network device to derive the second key can be configured according to actual conditions, for example, the calculation manner or calculation function used by the second network device to derive the second key can include at least one of the following: the first authentication function, the second authentication function, the third key generation function, the fourth key generation function, the fifth key generation function, the hash algorithm, AES, ACSON, SNOW 3G, ZUC, XOR calculation, direct connection calculation, and KDF.

[0145] Further, the processing of the first AIoT device can further include: deriving, based on the first key shared by the first AIoT device and the network, a second key used for protecting messages transmitted between the first AIoT device and the first network device.

[0146] The input key used by the first AIoT device to derive the second key, the input parameter used by the first AIoT device to derive the second key, and the calculation manner or calculation function used by the first AIoT device to derive the second key should be the same as those of the second network device, and will not be described herein. Since the present embodiment performs one-way authentication, the timing of deriving the second key at the first AIoT device side can be when the first AIoT device sends the first response message or after sending the first response message.

[0147] Optionally, the processing of the first network device after receiving the notification from the second network device that the first AIoT device is successfully authenticated can further include: sending a notification of successful authentication to the first AIoT device. Correspondingly, the processing of the first AIoT device can include: receiving a notification of successful authentication from the first network device. In this case, the first AIoT device can derive the second key after receiving the notification of successful authentication. The present embodiment does not exhaustively enumerate the timing of deriving the second key by the first AIoT device.

[0148] Optionally, the processing of the first network device after receiving the notification from the second network device that the first AIoT device is successfully authenticated can further include: sending a notification of successful authentication to the first AIoT device. Correspondingly, the processing of the first AIoT device can include: receiving a notification of successful authentication from the first network device. In this case, the first AIoT device can derive the second key after receiving the notification of successful authentication. The present embodiment does not exhaustively enumerate the timing of deriving the second key by the first AIoT device.

[0149] If the first network device is an AMF and / or an AIOTF, the first network device sending the response content corresponding to the first instruction to the AF can be: the first network device directly sending the response content corresponding to the first instruction to the AF; or, the first network device sending the response content corresponding to the first instruction to the AF through an NEF. If the first network device is a read-write device, the first network device sending the response content corresponding to the first instruction to the AF can be: the first network device directly sending the response content corresponding to the first instruction to the AF through other core network devices, which can include at least one of an AMF, an AIOTF, an NEF, and the like, and the other core network devices are not limited or enumerated herein.

[0150] In an embodiment, the authentication type for the first AIoT device is bidirectional authentication.

[0151] The processing of the second network device can further include: sending a first authentication request to the first network device, wherein the first authentication request carries at least one of the following: a second authentication vector for authenticating the network, and a second random number, the second authentication vector being calculated based on the first key shared by the first AIoT device and the network and / or the second random number.

[0152] Specifically, the second network device sending the first authentication request to the first network device can be: sending the first authentication request to the first network device in the case that the second network device successfully authenticates the first AIoT device; or sending the first authentication request to the first network device in the case that the second network device successfully authenticates the first AIoT device and the authentication type is bidirectional authentication.

[0153] The second network device determining the authentication type as bidirectional authentication can be: the second network device defaulting that the authentication type corresponding to the first AIoT device is bidirectional authentication; or, in the case that the authentication type is carried in the second authentication request and the authentication type is bidirectional authentication, determining that the authentication type corresponding to the first AIoT device is unidirectional authentication.

[0154] Optionally, the second random number can be different from the first random number.

[0155] For example, the second random number can be generated by the second network device. The way in which the second network device generates the second random number is not limited in the embodiment.

[0156] For another example, the second random number can be sent by the first AIoT device. For example, the first response message can also carry the second random number, and the second authentication request also carries the second random number. In this case, the second random number can be generated by the first AIoT device. The way in which the first AIoT device generates the second random number is not limited in the embodiment.

[0157] Optionally, the second random number can be the same as the first random number.

[0158] In a preferred example, the second authentication vector can be calculated based on the first key and the second random number. Specifically, the second authentication vector can be calculated based on the first key and the second random number by using a second calculation manner. That is, the key used by the second network device to calculate the second authentication vector is the first key, the input parameter used by the second network device to calculate the second authentication vector includes the second random number, and the calculation manner used by the second network device to calculate the second authentication vector is the second calculation manner.

[0159] The second calculation manner can include at least one of the first authentication function, the second authentication function, the third key generation function, the fourth key generation function, the fifth key generation function, a hash algorithm, AES, ACSON, SNOW 3G, ZUC, an exclusive or calculation, a direct connection calculation, and a KDF. The second calculation manner can be the same as or different from the first calculation manner.

[0160] For example, the calculation of the second authentication vector can be expressed by the following formula: AUTN_NW=f’ K (RAND_2), where AUTN_NW represents the second authentication vector, f’ is the second calculation manner, K is the root key of the first AIoT device, and RAND_2 is the second random number.

[0161] In one case, the second random number is different from the first random number.

[0162] If the second random number is generated by the second network device, the first authentication request can carry the second authentication vector and the second random number. If the second random number is different from the first random number and the second random number is sent by the first AIoT device, the first authentication request can only carry the second authentication vector.

[0163] In the present case, the second calculation manner can be the same as or different from the first calculation manner.

[0164] In another case, the second random number is the same as the first random number. The first authentication request can only carry the second authentication vector. It should be noted that in this case, the second calculation manner should be different from the first calculation manner.

[0165] In an optional example, the second authentication vector can also be calculated based on the first key only. For example, the second authentication vector can be calculated based on the first key by using the second calculation manner. In this example, the first authentication request can only carry the second authentication vector, and in this example, the second calculation manner should be different from the first calculation manner.

[0166] The processing of the first network device further includes receiving a first authentication request from the second network device, where the first authentication request carries at least one of the following: a second authentication vector for authenticating a network, and a second random number; and sending the first authentication request to the first AIoT device. The processing of the first AIoT device after sending the first response message further includes receiving a first authentication request from the first network device, where the first authentication request carries at least one of the following: a second authentication vector for authenticating a network, and a second random number.

[0167] The first network device sends the first authentication request to the first AIoT device, which can be that the first network device directly sends the first authentication request to the first AIoT device, or that the first network device sends the first authentication request to the first AIoT device through the read-write device.

[0168] The processing of the first AIoT device can further include: calculating a second verification vector based on the first key shared by the first AIoT device and the network and / or the second random number; and authenticating the network based on the second verification vector and the second authentication vector.

[0169] The first AIoT device calculates the second verification vector in the same way as the second network device calculates the second authentication vector, for example, the second authentication vector can be calculated based on the first key and the second random number in the second calculation manner, and correspondingly, the second verification vector can also be calculated based on the first key and the second random number in the second calculation manner, which will not be repeated here.

[0170] The authentication of the network based on the second verification vector and the second authentication vector can be that the first AIoT device successfully authenticates the network in the case that the second verification vector and the second authentication vector are the same, and the first AIoT device fails to authenticate the network in the case that the second verification vector and the second authentication vector are different. Here, the successful authentication of the network at the first AIoT device side can make the first AIoT device trust the message sent by the network side, and the network can generally refer to the devices in the communication network connected by the first AIoT device, such as at least including the first network device and the like.

[0171] The processing of the first AIoT device can further include: sending a first authentication response to the first network device, wherein the first authentication response is used to indicate the authentication result of the network. Specifically, in the case that the first AIoT device fails to authenticate the network, the first authentication response is used to indicate the authentication result that the first AIoT device fails to authenticate the network. In the case that the first AIoT device successfully authenticates the network, the first authentication response is used to indicate the authentication result that the first AIoT device successfully authenticates the network.

[0172] The processing of the first network device after sending the first authentication request can further include: receiving the first authentication response from the first AIoT device, wherein the first authentication response is used to indicate the authentication result of the network; and sending the first authentication response to the second network device.

[0173] The processing of the second network device can further include: receiving the first authentication response from the first network device.

[0174] The processing of the second network device can further include: sending, to the first network device, a second key for protecting messages transmitted between the first AIoT device and the first network device. The processing of the first network device can further include: receiving, from the second network device, the second key for protecting messages transmitted between the first AIoT device and the first network device.

[0175] The second network device can derive the second key in a case where the second network device receives the first authentication response from the first network device, and the first authentication response indicates that the authentication result of the network is passed. The manner in which the second network device derives the second key is the same as that in the foregoing embodiments, and thus is not repeated here.

[0176] The processing of the first AIoT device can further include: deriving, based on the first key shared by the first AIoT device and the network, a second key for protecting messages transmitted between the first AIoT device and the first network device. The first AIoT device can derive the second key in a case where the first AIoT device successfully authenticates the network. The manner in which the first AIoT device derives the second key is the same as that in the foregoing embodiments, and thus is not repeated here.

[0177] In some possible implementation, in the one-way authentication or the two-way authentication scenario, the first service request sent by the first network device can not be protected, and the first service request can only carry the first instruction. In this implementation, the first instruction and the processing that can be performed by the first network device, the first AIoT device, and the second network device are the same as those in the foregoing embodiments, and thus are not repeated here.

[0178] In some possible implementation, in the one-way authentication or the two-way authentication scenario, the first service request can be a message that is protected based on a security parameter, and the protection can include integrity protection and / or encryption protection.

[0179] In an embodiment, the processing of the first network device further includes: obtaining a security parameter, where the security parameter includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key.

[0180] The security parameter can be a security parameter corresponding to or associated with the first AIoT device, a security parameter corresponding to the first AIoT device being shared or commonly owned by the first AIoT device and the AF, and the first AIoT device can pre-store the security parameter. And / or, the security parameter can be a security parameter corresponding to or associated with a group to which the first AIoT device belongs (hereinafter referred to as a security parameter corresponding to an AIoT device group), the security parameter corresponding to the AIoT device group being shared or commonly owned by each AIoT device in the AIoT device group and the AF, and the first AIoT device (as well as each AIoT device in the group to which it belongs) can pre-store the security parameter.

[0181] Optionally, the identification information can be an identification (ID) of a key. The identification information corresponding to the device key of the first AIoT device can refer to the identification of the device key of the first AIoT device; and the identification information corresponding to the group key can be the identification of the group key.

[0182] Optionally, the identification information can be a NONCE (random number). The NONCE is different from the first random number and the second random number in the foregoing embodiments in function, and the function of the NONCE as identification information is to determine which key or keys to use for related processing.

[0183] The identification information corresponding to the device key of the first AIoT device can refer to a NONCE corresponding to the device key of the first AIoT device. The number of NONCEs corresponding to the device key of the first AIoT device can be one or more, that is, the device key of the first AIoT device can correspond to one or more NONCEs, and any one of the one or more NONCEs can determine the device key of the first AIoT device corresponding to or associated with it; or any one of the one or more NONCEs can determine the first AIoT device corresponding to or associated with it, and then the device key of the first AIoT device can be determined.

[0184] The identification information corresponding to the group key can refer to a NONCE corresponding to the group key. The number of NONCEs corresponding to the group key can be one or more, that is, the group key can correspond to one or more NONCEs, and any one of the one or more NONCEs can determine the group key corresponding to or associated with it; or any one of the one or more NONCEs can determine a group corresponding to or associated with it, and then the group key of the group can be determined.

[0185] It should be noted that the nonce in the actual processing can also be replaced by other names or other parameters, but as long as it can be one or more identification information associated with a certain key, and any one identification information can uniquely determine a key, it is within the protection scope of the embodiment.

[0186] In an example, the security parameter is sent when the AF sends a service request.

[0187] The first network device can obtain the security parameter from the AF at the same time of receiving the service request of the AF. Specifically, the process of obtaining the security parameter by the first network device can be: receiving the service request of the AF and receiving the security parameter from the AF. The security parameter can be carried in the service request of the AF; or the security parameter can not be carried in the service request of the AF but be sent at the same time as the service parameter of the AF.

[0188] In a case, when the AF needs to inventory the first AIoT device and / or needs to send a command to the first AIoT device, the AF can send the security parameter corresponding to the first AIoT device at the same time of sending the service request of the AF to the first network device, wherein the security parameter contains at least one of the following: the device key of the first AIoT device, the group key, the identification information corresponding to the device key of the first AIoT device, and the identification information corresponding to the group key.

[0189] In a case, when the AF needs to inventory multiple AIoT devices and / or needs to send a command to the multiple AIoT devices, the multiple AIoT devices belong to the same group, the AF can send the security parameter corresponding or associated to the AIoT device group at the same time of sending the service request of the AF to the first network device, wherein the security parameter can contain the group key and the identification information corresponding to the group key.

[0190] In a case, when the AF needs to inventory multiple AIoT devices and / or needs to send a command to the multiple AIoT devices, the AF can send the security parameter corresponding to each AIoT device in the multiple AIoT devices at the same time of sending the service request of the AF to the first network device.

[0191] In an example, the AF pre-provides the security parameter to the network, and the first network device obtains the security parameter when needed. The timing of the AF pre-providing the security parameter to the network can be before the AF sends the service request of the AF, and the present example does not limit the timing of the AF providing the security parameter to the network. Specifically, the AF can pre-provide the security parameter to one or more core network devices in the network and store the security parameter in the one or more core network devices.

[0192] In a case, the one or more core network devices can comprise a first network device, and in this case, the first network device obtaining the security parameter can be obtaining the security parameter locally.

[0193] In a case, the one or more core network devices can be other core network devices than the first network device, and in this case, the first network device obtaining the security parameter can be obtaining the security parameter from the other core network devices. The other core network devices can comprise at least one of: a second network device, a third core network device. The third core network device can comprise: a UDM (Unified Data Management) and / or a UDR (Unified Data Repository).

[0194] Here, the timing of the first network device obtaining the security parameter is not limited, as long as it is before the first network device sending the first service request.

[0195] In an embodiment, the first service request carries at least one of: the first instruction, a first message check code for verifying the integrity of the first service request, a first freshness value, first cipher data, and identification information corresponding to a third key. The third key comprises one of: a device key of the first AIoT device shared by the first AIoT device and an AF (Application Function), and a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF.

[0196] The first instruction can contain the same content as the foregoing embodiments, and no repeated description is given.

[0197] The first freshness value can be generated by the first network device, and the manner in which the first network device generates the first freshness value is not limited in this embodiment. For example, the first freshness value can be a random number, such as a fourth random number, and the manner in which the fourth random number is generated is also not limited in this embodiment.

[0198] Optionally, the first service request can be used only for the first AIoT device to execute the first instruction. The first network device can select any one of a device key and a group key of the first AIoT device from the security parameter as the third key.

[0199] Optionally, the first service request is used for multiple AIoT devices to execute the first instruction, and the first service request is a broadcast or groupcast message. The first network device can select a group key from the security parameter as the third key.

[0200] Optionally, the first service request is for the plurality of AIoT devices to execute the first instruction, and the first service request is a unicast message. For the first AIoT device, the first network device can select, from the security parameters, any one of a device key of the first AIoT device and a group key as the third key.

[0201] The identification information corresponding to the third key can be any one of an identifier of the third key or one or more NONCEs corresponding to or associated with the third key.

[0202] The processing at the first network device side further includes at least one of the following: calculating a first message check code based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, the identification information corresponding to the third key, and the first ciphertext data; and calculating the first ciphertext data based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first message check code, the first freshness value, and the identification information corresponding to the third key.

[0203] The processing at the first AIoT device side can include: calculating a first message verification code based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, the first ciphertext data, and the identification information corresponding to the third key; and verifying the integrity of the first service request based on the first message verification code and the first message check code. And / or, the processing at the first AIoT device side can include: decrypting the first ciphertext data based on the third key to obtain at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first message verification code, the first freshness value, and the identification information corresponding to the third key.

[0204] In an example, the first network device only performs integrity protection on the first service request based on the security parameters.

[0205] In the case that the first service request (or paging / Inventory request message) of the downlink contains the permanent identifier of the device, if the identifier is tampered with, it may cause the device to be unable to respond to the paging / Inventory request. Therefore, the present example provides an integrity protection mechanism for the first service request, which can use a group key or a single device key, which is pre-stored between the AF and the first AIoT device and provided to the network side by the AF. In addition, considering that if the first service request cannot resist replay, the attacker can intercept the paging / Inventory request sent by the network and replay it to the first AIoT device multiple times, which may cause the AIoT device to perform multiple responses and run out of power, considering that the AIoT device is extremely simple in form and low in power storage, this attack method has a greater impact on the AIoT device.

[0206] The first message check code can be calculated based on the third key and the first input parameter by using a third calculation method. The first input parameter can include at least part of the content required to be carried by the first service request. The first input parameter can include at least one of the instruction content indicating the inventory operation, the first identifier related information, the first freshness value, and the identification information corresponding to the third key. Preferably, the first input parameter at least includes the first identifier related information.

[0207] The third calculation method can be any calculation method that can calculate a message check code, and the present embodiment is not limited thereto.

[0208] In this example, the first service request can carry at least one of the instruction content indicating the inventory operation, the first identifier related information, the first message check code, the first freshness value, and the identification information corresponding to the third key.

[0209] For example, using the GK (Group Key) as the third key is suitable for the scenario of network inventorying multiple or single devices. The content contained in the first service request is: the information related to the identifier of the first AIoT device downlink ID Info (first identifier related information), the integrity check code MAC (first message check code) calculated by using the GK on the ID info (or the first service request), the first freshness parameter Freshness (selected by the AIoT) used for calculating the MAC, the Nonce (security parameter shared between the AIoT and the AF) used for calculating the MAC, and the key identification GK ID.

[0210] For example, the first AIoT device uses the device key Ktag as the third key, which is applicable to the scenario that the network inventory the first AIoT device. The first service request contains the following information: the information related to the first AIoT device identifier downlink ID Info, the integrity check code MAC calculated by Ktag on ID info (or the first service request), the freshness parameter Freshness (selected by AIoT) used for calculating MAC, the Nonce (shared security parameter between AIOT and AF) used for calculating MAC, and the key identifier Ktag ID.

[0211] It should be noted that the key used to calculate the first message check code can be the third key, and can also be a lower-level key derived from the third key.

[0212] After the first AIoT device receives the first service request, it can calculate the first message verification code, and verify the integrity of the first service request based on the first message verification code and the first message check code. The first AIoT device calculates the first message verification code, and the process of calculating the first message check code by the first network device is the same, and is not repeated.

[0213] On the first AIoT device side, verifying the integrity of the first service request based on the first message verification code and the first message check code can include: in the case that the first message verification code and the first message check code are the same, verifying the integrity of the first service request successfully or passing; in the case that the first message verification code and the first message check code are different, verifying the integrity of the first service request fails or does not pass.

[0214] Further, on the first AIoT device side, in the case that the integrity of the first service request is verified successfully or passed, a first response message is generated and sent to the first network device. The content of the first response message and the subsequent one-way authentication or two-way authentication process are the same as the previous embodiments, and are not repeated.

[0215] In addition, on the first AIoT device side, it can also include: in the case that the integrity of the first service request fails or does not pass, ending the process or sending a response message of integrity verification failure to the first network device.

[0216] In an example, the first network device only encrypts the first service request based on the security parameter.

[0217] Since the first service request carries the specific device identifier, if transmitted in plaintext, it may be intercepted by an attacker, enabling the attacker to track and link the device, and the first AIoT device has a small message transmission range, so the location range of the specific device can be obtained. In particular, for the use case in which the first AIoT device is a personal device (for example, a wearable IoT device). Therefore, the encryption protection mechanism for the first service request is provided in this example, which can use a group key GK or a single device key Ktag.

[0218] In this example, the first service request can carry first ciphertext data and first plaintext data.

[0219] The first ciphertext data can be calculated based on the third key and the second input parameter in a fourth calculation manner. The second input parameter can include at least part of the content required to be carried by the first service request. The second input parameter can include at least one of the instruction content indicating the inventory operation, the first identifier related information, the first freshness value, and the identification information corresponding to the third key. The fourth calculation manner can be any encryption manner, which is not limited in the embodiment. Preferably, the second input parameter at least includes the first identifier related information.

[0220] The first plaintext data at least includes the identification information corresponding to the third key, so that the receiving end (the first AIoT device) can identify or determine which key to use for decryption. It should be pointed out that the identification information corresponding to the third key is included in the first plaintext data, which does not mean that the identification information of the third key cannot be encrypted. The identification information corresponding to the third key can be encrypted and included in the first plaintext data.

[0221] For example, the following parameters are encrypted using the group key GK as the third key to generate the first ciphertext data: downlink ID info (or paging / Inventory request message), freshness parameter Freshness (selected by AIoT), and Nonce (a security parameter shared between AIOT and AF, which can be identified by the first AIoT device). The plaintext form (first plaintext data) is Nonce or key identifier GK ID.

[0222] For another example, the following parameters are encrypted using the single device key Ktag as the third key to generate the first ciphertext data: downlink ID info (or paging / Inventory request message), freshness parameter Freshness (selected by AIoT), and Nonce (a security parameter shared between AIOT and AF, which can be identified by the first AIoT device). The plaintext form (first plaintext data) is Nonce or key identifier Ktag ID.

[0223] The first AIoT device can decrypt the first ciphertext data based on the third key after receiving the first service request. The processing of the first AIoT device decrypting the first ciphertext data should correspond to the processing of the first network device calculating the first ciphertext data, and is not described again.

[0224] On the first AIoT device side, after the first identification-related information is decrypted, it can further include: in a case where it is determined that the first identification-related information in the first instruction carried by the first service request matches, generating and sending a first response message to the first network device. The content of the first response message and the subsequent one-way authentication or two-way authentication processing are the same as the foregoing embodiments, and are not repeated.

[0225] In addition, on the first AIoT device side, it can further include: in a case where it is determined that the first identification-related information in the first instruction carried by the first service request does not match, ending the processing.

[0226] In an example, the first network device performs integrity protection and encryption protection on the first service request based on the security parameter. The execution order of the integrity protection and the encryption protection can be to perform integrity protection first and then encryption protection, or to perform encryption protection first and then integrity protection.

[0227] In one case, the first network device can first calculate the first message check code and then calculate the first ciphertext data. The first message check code can be calculated based on the third key and the first input parameter using the third calculation method, and the related description of the first input parameter is the same as the foregoing embodiments, and is not described again. The first ciphertext data can be calculated based on the third key and the second input parameter using the fourth calculation method, and the second input parameter can include at least one of the following: the instruction content indicating the inventory operation, the first identification-related information, the first message check code, the first freshness value, and the identification information corresponding to the third key.

[0228] The first message check code can be included in the second input parameter; the first ciphertext data is definitely not included in the first input parameter.

[0229] In this case, the first service request message can carry the first ciphertext data and the first plaintext data. The first plaintext data at least includes the identification information corresponding to the third key. Here, all possible contents of the first service request carrying the first ciphertext data and / or the first plaintext data are not exhausted.

[0230] In this case, after receiving the first service request, the first AIoT device can first decrypt the first ciphertext data and then verify the first message check code. The processing of the first AIoT device decrypting the first ciphertext data is the same as the foregoing embodiments and will not be repeated. On the first AIoT device side, the first message check code can be calculated in a case where it is determined that the first identification related information in the first instruction carried by the first service request matches. The processing of the first AIoT device calculating the first message check code should be the same as the processing of the first network device calculating the first message check code, and will not be repeated. The processing of verifying the integrity of the first service request is the same as the foregoing embodiments and will not be repeated.

[0231] The first AIoT device can generate and send a first response message to the first network device in a case where the verification of the integrity of the first service request is successful or passed. The content of the first response message and the subsequent processing of one-way authentication or two-way authentication are the same as the foregoing embodiments and will not be repeated.

[0232] In another case, the first network device can first calculate the first ciphertext data and then calculate the first message check code. The first ciphertext data can be calculated based on a third key and a second input parameter in a second calculation manner. The second input parameter can include at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, and identification information corresponding to the third key. The first message check code can be calculated based on the third key and a first input parameter in a first calculation manner. The first input parameter can include at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, identification information corresponding to the third key, and the first ciphertext data.

[0233] The difference from the foregoing case is that the second input parameter does not necessarily include the first message check code in this case. The first input parameter can include the first ciphertext data.

[0234] In this case, the first service request message can also carry the first ciphertext data and the first plaintext data. Here, all possible contents of the first service request carrying the first ciphertext data and / or the first plaintext data are not enumerated.

[0235] In this case, after receiving the first service request, the first AIoT device can first verify the first message check code, and then decrypt the first ciphertext data. The first AIoT device decrypts the first ciphertext data, which can be executed in the case where the integrity of the first service request is verified to be passed or successful. The processing of calculating the first message check code at the first AIoT device side should be the same as the processing of calculating the first message check code at the first network device, and is not repeated; the processing of verifying the integrity of the first service request based on the first message check code and the first message check code is the same as the previous embodiment, and the processing of the first AIoT device decrypting the first ciphertext data is the same as the previous embodiment, and is not repeated.

[0236] At the first AIoT device side, after decrypting the first identification related information, it can further include: in the case where it is determined that the first identification related information in the first instruction carried by the first service request matches, generating and sending a first response message to the first network device. The content of the first response message and the subsequent one-way authentication or two-way authentication processing are the same as the previous embodiment, and are not repeated.

[0237] In addition, at the first AIoT device side, it can further include: in the case where the integrity verification of the first service request fails or does not pass, ending the processing or sending a response message of integrity verification failure to the first network device; and / or in the case where it is determined that the first identification related information in the first instruction carried by the first service request does not match, ending the processing.

[0238] In some possible implementations, in the case where the authentication type of the first AIoT device is two-way authentication, the processing at the first network device side can further include: sending a second service request to the first AIoT device, wherein the second service request is used for the first AIoT device to execute a second instruction. Correspondingly, the processing of the first AIoT device can further include: receiving a second service request from the first network device, wherein the second service request is used for the first AIoT device to execute a second instruction.

[0239] The second service request can be a message that is protected by security, and the security protection can include integrity protection and / or encryption protection.

[0240] The second service request carries at least one of the following: the second instruction, a second message authentication code for verifying integrity of the second service request, a second freshness value, identification information corresponding to a fourth key, and second cipher text data, wherein the fourth key includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF, and a second key for protecting a message transmitted between the first AIoT device and the first network device.

[0241] The second instruction includes at least one of the following: command content and second identification related information, wherein the command content includes at least one of the following: read data, write data, disable, and enable, and the second identification related information includes at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, and an identifier of an area to which the one or more AIoT devices belong, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0242] The processing at the first network device side further includes at least one of the following: calculating the second message authentication code based on the fourth key and at least one of the following: the command content, the second identification related information, the second freshness value, the identification information corresponding to the fourth key, and the second cipher text data; and calculating the second cipher text data based on the fourth key and at least one of the following: the command content, the second identification related information, the second freshness value, the identification information corresponding to the fourth key, and the second message authentication code.

[0243] The processing at the first AIoT device side can include: calculating a second message authentication code based on the fourth key and at least one of the following: the command content, the second identification related information, the second freshness value, the identification information corresponding to the fourth key, and the second cipher text data; and verifying the integrity of the second service request based on the second message authentication code and the second message authentication code. And / or, the processing at the first AIoT device side can include: decrypting the second cipher text data based on the fourth key to obtain at least one of the following: the command content, the second identification related information, the second freshness value, the identification information corresponding to the fourth key, and the second message authentication code.

[0244] The second instruction can be generated based on a service request of the AF at the first network device side.

[0245] For example, the service request of the AF carries the command content, and carries at least one of the identifier of the one or more AIoT devices, the related identifier of the AIoT device group, and the identifier of the area where the one or more AIoT devices are located. The first network device can determine at least one of the identifier of the one or more AIoT devices, the related identifier of the AIoT device group, and the identifier of the area where the one or more AIoT devices are located as the second identification-related information; and generate the second instruction based on the second identification-related information and the command content.

[0246] For example, the service request of the AF carries the command content, and carries the geographic position of the area where the one or more AIoT devices are located. The first network device can convert the geographic position of the area where the one or more AIoT devices are located into the identifier of the area where the one or more AIoT devices are located, determine the identifier of the area where the one or more AIoT devices are located as the second identification-related information, and generate the second instruction based on the second identification-related information and the command content.

[0247] Optionally, the second service request can be used only for the first AIoT device to execute the second instruction, which can include the command content and the second identification-related information, and the second identification-related information can include the identifier of the first AIoT device.

[0248] Optionally, the second service request can be used for multiple AIoT devices to execute the second instruction, which can include the command content and the second identification-related information, and the second identification-related information can include at least one of the identifier of the multiple AIoT devices, the related identifier of the AIoT device group, and the identifier of the area where the one or more AIoT devices are located. Since each of the multiple AIoT devices receives the second service request and the processing thereafter is the same as the first AIoT device, it will not be repeated here.

[0249] The second fresh value can be generated by the first network device, and the first network device can generate the second fresh value in any manner, which is not limited in the embodiment. The second fresh value is different from the first fresh value. For example, the second fresh value can be a random number, such as the fifth random number.

[0250] In an embodiment, the second service request can be sent at the same time as the first authentication request at the side of the first network device.

[0251] On the side of the first network device, the first authentication request and the second service request can be carried in a same message, for example, in a same downlink message (or downlink NAS (Non-Access Stratum) message).

[0252] In this embodiment, since the second key has not been derived, the first network device needs to use the key in the security parameter as the fourth key.

[0253] Optionally, the first authentication request is directed to the first AIoT device, and the second service request can also be used only for the first AIoT device to execute the second instruction. The first network device can select any one of the device key and the group key of the first AIoT device from the security parameter as the fourth key.

[0254] Optionally, although the first authentication request is directed to the first AIoT device, the first network device can perform authentication processing with multiple AIoT devices at the same time, and thus multiple second service requests corresponding to the multiple AIoT devices respectively can be generated. In this case, the first network device can select the group key from the security parameter as the fourth key, that is, the first network device can no longer select the keys corresponding to different AIoT devices multiple times, but can use the group key in the security parameter as the fourth key uniformly.

[0255] In an example, the first network device only performs integrity protection on the second service request.

[0256] The second message verification code can be calculated based on the fourth key and a third input parameter in a fifth calculation manner. The third input parameter can include at least part of the content required to be carried by the second service request. The third input parameter can include at least one of the command content, the second identification related information, the second freshness value, and the identification information corresponding to the fourth key. Preferably, the third input parameter at least includes the second identification related information.

[0257] The fifth calculation manner can be any calculation manner that can calculate a message verification code. The fifth calculation manner can be the same as or different from the third calculation manner, which is not limited in this embodiment.

[0258] In this example, the second service request can carry at least one of the second message verification code, the command content, the second identification related information, the second freshness value, and the identification information corresponding to the fourth key.

[0259] The first AIoT device can calculate the second message verification code after receiving the second service request, and verify the integrity of the second service request based on the second message verification code and the second message check code.

[0260] In this embodiment, the second service request is sent at the same time as the first authentication request, and on the first AIoT device side, the process of calculating the second message verification code can be performed again after the first AIoT device successfully authenticates the network.

[0261] The first AIoT device calculates the second message verification code, and the process of calculating the second message check code by the first network device is the same, and is not repeated.

[0262] The first AIoT device can determine the fourth key based on the identification information corresponding to the fourth key.

[0263] It should be pointed out that the first AIoT device can calculate the second message verification code in the case of determining that the second identification related information carried in the second instruction of the second service request matches. The way of determining that the second identification related information carried in the second instruction of the second service request matches is the same as the way of determining that the first identification related information carried in the first instruction of the first service request matches, and is not repeated.

[0264] On the first AIoT device side, verifying the integrity of the second service request based on the second message verification code and the second message check code can include: in the case that the second message verification code and the second message check code are the same, verifying the integrity of the second service request successfully or passing; in the case that the second message verification code and the second message check code are different, verifying the integrity of the second service request fails or does not pass.

[0265] Further, on the first AIoT device side, the second instruction can be executed in the case that the integrity of the second service request is verified successfully or passed. The specific processing and command content of the first AIoT device executing the second instruction are related, for example, the command content is to read data, and the first AIoT device executes the processing of reading data, and the specific data or type of data to be read can be indicated in the command content of reading data, and this embodiment is not limited. For example, the command content is to write data, and the first AIoT device executes the processing of writing data, and the specific data or type of data to be written can be indicated in the command content of writing data, and this embodiment is not limited. Here, all the processing that the first AIoT device can perform based on the command content is not enumerated or enumerated.

[0266] In addition, on the first AIoT device side, the second instruction can be executed only when the integrity of the second service request is verified.

[0267] In an example, the first network device only encrypts the second service request.

[0268] In this example, the second service request can carry second ciphertext data and second plaintext data.

[0269] The second ciphertext data can be calculated based on a fourth key and a fourth input parameter in a sixth calculation manner. The fourth input parameter can include at least part of the content required to be carried by the second service request. The fourth input parameter can include at least one of the command content, the second identification related information, the second freshness value, and the identification information corresponding to the fourth key. The sixth calculation manner can be any encryption manner. The sixth calculation manner can be the same as or different from the fourth calculation manner, which is not limited in the present embodiment.

[0270] Preferably, the fourth input parameter at least includes the second identification related information, that is, the second identification related information in the second service request is at least encrypted.

[0271] The second plaintext data at least includes the identification information corresponding to the fourth key, so that the receiving end (the first AIoT device) can identify or determine which key to use for decryption. It should be pointed out that the identification information corresponding to the fourth key is included in the second plaintext data, and it does not mean that the identification information corresponding to the fourth key cannot be encrypted. The identification information corresponding to the fourth key can be encrypted and included in the second plaintext data.

[0272] For example, if the fourth input parameter includes the command content, the second identification related information, the second freshness value, and the identification information corresponding to the fourth key. The second service request can carry the second ciphertext data, and the second plaintext data carried by the second service request can include the identification information corresponding to the fourth key. The above is only an exemplary description of the second service request carrying the second ciphertext data and / or the second plaintext data, which is not exhausted here.

[0273] The first AIoT device decrypts the second ciphertext data based on the fourth key after receiving the second service request.

[0274] The second service request in the embodiment is sent at the same time as the first authentication request, and on the first AIoT device side, the processing of decrypting the second ciphertext data based on the fourth key can be performed again in the case that the first AIoT device successfully authenticates the network.

[0275] On the first AIoT device side, after obtaining the second identity-related information by decryption, the processing based on the command content in the second instruction can be further included in the case that the second identity-related information in the second instruction carried by the second service request is determined to match.

[0276] In addition, on the first AIoT device side, the second instruction can not be executed in the case that the first identity-related information in the first instruction carried by the first service request is determined not to match, and / or the second instruction can not be executed in the case that the first AIoT device fails to authenticate the network.

[0277] In an example, the first network device performs integrity protection and encryption protection on the second service request.

[0278] In a case, the first network device can calculate the second message authentication code first and then calculate the second ciphertext data. The calculation process of the second message authentication code is the same as in the foregoing embodiments and is not repeated here. The second ciphertext data can be calculated based on the fourth key and the fourth input parameter in a sixth calculation manner. The fourth input parameter can include at least one of the command content, the second identity-related information, the second freshness value, the identification information corresponding to the fourth key, and the second message authentication code.

[0279] The fourth input parameter can include the second message authentication code, and the third input parameter does not include the second ciphertext data.

[0280] In this case, the second service request message can carry the second ciphertext data and second plaintext data, and the second plaintext data at least includes the identification information of the fourth key.

[0281] In this case, the second service request in the embodiment is sent at the same time as the first authentication request, and on the first AIoT device side, the processing of decrypting the second ciphertext data based on the fourth key can be performed again in the case that the first AIoT device successfully authenticates the network.

[0282] At the first AIoT device side, the second message verification code can be calculated in a case where it is determined that the second identification related information matches the second identification in the second instruction carried by the second service request. The process of calculating the second message verification code at the first AIoT device side should be the same as the process of calculating the second message verification code at the first network device, and is not described herein again. The process of verifying the integrity of the second service request is the same as that in the foregoing embodiments, and is not described herein again.

[0283] The first AIoT device can execute the second instruction in a case where the verification of the integrity of the second service request is successful or passed.

[0284] In another case, the first network device can calculate the second ciphertext data and then calculate the second message verification code. The second ciphertext data can be calculated based on the fourth key and a fourth input parameter in a sixth calculation manner. The fourth input parameter can include at least one of the following: command content, the second identification related information, the second freshness value, and identification information corresponding to the fourth key. The second message verification code can be calculated based on the fourth key and a third input parameter in a fifth calculation manner. The third input parameter can include at least one of the following: command content, the second identification related information, the second freshness value, identification information corresponding to the fourth key, and the second ciphertext data.

[0285] The difference between the above case and the present case is that the fourth input parameter does not necessarily include the first message verification code in the present case; and the third input parameter can include the second ciphertext data.

[0286] In this case, the second service request in the present embodiment is sent at the same time as the first authentication request, and the first AIoT device can calculate the second message verification code and decrypt the second ciphertext data in a case where the first AIoT device is authenticated by the network successfully. The first AIoT device can verify the second message verification code and then decrypt the second ciphertext data. Here, the first AIoT device can decrypt the second ciphertext data based on the fourth key in a case where the verification of the integrity of the first service request is passed or successful.

[0287] The process of calculating the second message verification code at the first AIoT device side should be the same as the process of calculating the first message verification code at the second network device, and is not described herein again. The process of verifying the integrity of the second service request is the same as that in the foregoing embodiments, and is not described herein again. The process of decrypting the second ciphertext data by the first AIoT device is the same as that in the foregoing embodiments, and is not described herein again.

[0288] At the first AIoT device side, after the second identification related information is decrypted, the following process can be further included: in a case where it is determined that the second identification related information matches the second identification carried by the second service request, the second instruction can be executed.

[0289] In addition, on the first AIoT device side, the following can also be included: in the case of at least one of the following: failure of verification of the integrity of the second service request, failure of authentication of the network, and determination that the information related to the second identity carried by the second service request does not match, the second instruction is not executed.

[0290] In an embodiment, the second service request can be sent after completion of the two-way authentication.

[0291] The processing of the first network device can be: receiving a first authentication response from the first AIoT device, and in the case where the first authentication response indicates that the authentication result for the network is authentication passed, sending a second service request to the first AIoT device.

[0292] In this embodiment, the first network device can also obtain a second key before sending the second service request. Therefore, in this embodiment, the second key can be used as the fourth key, and the identification information of the second key can be the identity of the second key, i.e., the identification information of the fourth key is the key identity.

[0293] The processing of the first network device for calculating the second message check code and / or calculating the second ciphertext data and the processing order thereof can be the same as in the foregoing embodiments, and thus will not be repeated.

[0294] The processing after receiving the second service request on the first AIoT device side is different from the foregoing embodiments only in that the first AIoT device no longer needs to perform authentication processing. The related processing and order thereof performed by the first AIoT device, such as verification of the second message check code and / or decryption of the second key data, are the same as in the foregoing embodiments, and thus will not be repeated.

[0295] On the first AIoT device side, the following can also be included: in the case where the integrity of the second service request is verified, and / or in the case where the information related to the second identity carried by the second service request is determined to match, the second instruction is executed. In addition, the following can also be included: in the case where the integrity of the second service request is not verified, and / or in the case where the information related to the second identity carried by the second service request is determined not to match, the second instruction is not executed.

[0296] In some possible implementation, after executing the second instruction, the first AIoT device can further include: sending a second response message to the first network device, where the second response message is used to indicate the response content corresponding to the second instruction. Correspondingly, the processing of the first network device can further include: receiving the second response message from the first AIoT device. After receiving the second response message, the processing of the first network device can include one of the following: sending at least one of the following to the application function AF: the identifier of the first AIoT device, the response content corresponding to the second instruction; sending the second response message to the application function AF.

[0297] The first AIoT device can perform security protection on the second response message, which can include integrity protection and / or encryption protection.

[0298] The second response message carries at least one of the following: the response content corresponding to the second instruction, the identifier of the first AIoT device, a third message authentication code used to verify the integrity of the second response message, a third freshness value, third cipher data, and identification information corresponding to a fifth key, where the fifth key includes one of the following: a second key used to protect messages transmitted between the first AIoT device and the first network device, and a sixth key used to protect messages transmitted between the first AIoT device and the application function AF.

[0299] The first AIoT device further includes at least one of the following: calculating the third message authentication code based on the fifth key and at least one of the following: the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the third cipher data, and the identification information corresponding to the fifth key; and calculating the third cipher data based on the fifth key and at least one of the following: the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the identification information corresponding to the fifth key, and the third message authentication code.

[0300] The processing of the first network device further includes: calculating the third message authentication code based on the second key and at least one of the following: the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the third cipher data, and the identification information corresponding to the fifth key; and verifying the integrity of the second response message based on the third message authentication code and the third message authentication code. And / or, the processing of the first network device further includes: decrypting the third cipher data based on the second key to obtain at least one of the following: the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the identification information corresponding to the second key, and the third message authentication code.

[0301] The response content corresponding to the second instruction is obtained from the command content of the second instruction executed by the first AIoT device, and the data or information that the response content can contain is related to the command content included in the second instruction. This embodiment is not limited.

[0302] The third freshness value can be generated by the first AIoT device, and the manner of generating the third freshness value is not limited in this embodiment. The third freshness value is different from the first freshness value and the second freshness value.

[0303] Since the first AIoT device completes the authentication of the network and the authentication is successful before sending the second response message, the second key can be obtained on the side of the first AIoT device.

[0304] The sixth key can be pre-configured or saved in the first AIoT device. The sixth key can be represented as K_e2e, indicating that the sixth key is used for transmitting messages between the first AIoT device and the AF.

[0305] In an embodiment, the first AIoT device receives the second service request and the first authentication request at the same time. Accordingly, the first AIoT device can send the second response message and the first authentication response at the same time. The first authentication response can be used to indicate the authentication result that the first AIoT device successfully authenticates the network. The first AIoT device sends the second response message and the first authentication response can be carried in the same message, such as in the same uplink message (or uplink NAS message).

[0306] In an example, the second response message can only be integrity protected.

[0307] The third message authentication code can be calculated based on the fifth key and the fifth input parameter using the seventh calculation method. The fifth input parameter can include at least part of the content required to be carried by the second response message. The fifth input parameter can include at least one of the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, and the identification information corresponding to the fifth key. Preferably, the fifth input parameter at least includes the identifier of the first AIoT device.

[0308] The seventh calculation method can be any calculation method that can calculate a message authentication code. The seventh calculation method can be the same as or different from the fifth calculation method, and can be the same as or different from the third calculation method. This embodiment is not limited.

[0309] In this example, the second response message can carry at least one of the response content corresponding to the second instruction, the identifier of the first AIoT device, the third message authentication code, the third freshness value, and the identification information corresponding to the fifth key.

[0310] Optionally, if the fifth key is the second key, after the first network device simultaneously receives the second response message and the first authentication response, on the first network device side, in a case where it is determined that the first AIoT device is authenticated to the network successfully based on the first authentication response, the processing of calculating the third message verification code is further performed.

[0311] The first network device can calculate the third message verification code based on the second key and at least one of the following: verify the integrity of the second response message based on the third message verification code and the third message check code. The processing of calculating the third message verification code by the first network device should be the same as the processing of calculating the third message check code by the first AIoT device, and is not described in detail.

[0312] On the first network device side, verifying the integrity of the second response message based on the third message verification code and the third message check code can include: in a case where the third message verification code and the third message check code are the same, verifying that the integrity of the second response message is successful or passed; in a case where the third message verification code and the third message check code are different, verifying that the integrity of the second response message fails or does not pass.

[0313] Further, on the first network device side, in a case where the integrity of the second response message is verified to be successful or passed, the first network device can send at least one of the following to an application function (AF): the identifier of the first AIoT device, the response content corresponding to the second instruction. In addition, on the first network device side, it can also include: in a case where the integrity of the second response message is verified to fail or not to pass, ending the processing.

[0314] Optionally, if the fifth key is the sixth key, after the first network device simultaneously receives the second response message and the first authentication response, on the first network device side, in a case where it is determined that the first AIoT device is authenticated to the network successfully based on the first authentication response, the first network device can send the second response message to the application function (AF). In this case, the AF can perform integrity verification on the second response message, which is not described in detail here.

[0315] In an example, the second response message can only be encrypted for protection.

[0316] In this example, the second response message can carry third ciphertext data and third plaintext data.

[0317] The third ciphertext data can be calculated based on the fifth key and a sixth input parameter in an eighth calculation manner. The sixth input parameter can include at least part of the content required to be carried by the second response message. The sixth input parameter can include at least one of the response content corresponding to the second instruction, the identifier of the first AIoT device, a third freshness value, and identification information corresponding to the fifth key. The eighth calculation manner can be any encryption manner. The eighth calculation manner can be the same as or different from the sixth calculation manner and can be the same as or different from the fourth calculation manner, which is not limited in the embodiment.

[0318] Preferably, the sixth input parameter at least includes the identifier of the first AIoT device, that is, the identifier of the first AIoT device is at least encrypted and protected.

[0319] The third plaintext data at least includes the identification information corresponding to the fifth key, so that the receiving end can identify or determine which key to use for decryption.

[0320] Optionally, if the fifth key is the second key, the first network device can perform the decryption process after receiving the second response message and the first authentication response at the same time. The decryption process is performed at the first network device side in a case where it is determined that the first AIoT device is successfully authenticated by the network based on the first authentication response.

[0321] The decryption process of the third ciphertext data by the first network device corresponds to the process of calculating the third ciphertext data by the first AIoT device, which is not described herein.

[0322] After the identifier of the first AIoT device and the response content corresponding to the second instruction are decrypted at the first network device side, the first network device can further send at least one of the identifier of the first AIoT device and the response content corresponding to the second instruction to an application function (AF).

[0323] Optionally, if the fifth key is the sixth key, the first network device can send the second response message to the AF after receiving the second response message and the first authentication response at the same time. In this case, the AF can decrypt the second response message, which is not described herein.

[0324] In an example, the second response message can be integrity protected and encrypted.

[0325] In one case, the first AIoT device can calculate the third message check code first and then calculate the third ciphertext data. The calculation of the third message check code is the same as the foregoing embodiments, and thus is not described herein again. The third ciphertext data can be calculated based on the fifth key and a sixth input parameter in the eighth calculation manner. The sixth input parameter can include at least part of the content required to be carried by the second response message. The sixth input parameter can include at least one of the response content corresponding to the second instruction, the identifier of the first AIoT device, the third freshness value, the identification information corresponding to the fifth key, and the third message check code.

[0326] The third message check code can be included in the sixth input parameter, and the third ciphertext data can not be included in the fifth input parameter.

[0327] In this case, the second response message can carry the third ciphertext data and third plaintext data. The third plaintext data at least includes the identification information of the fifth key.

[0328] Optionally, if the fifth key is the second key, after the first network device receives the second response message and the first authentication response, the first network device can decrypt the third ciphertext data first and then verify the third message check code, on the condition that it is determined that the first AIoT device is authenticated to the network successfully based on the first authentication response. The decryption of the third ciphertext data is the same as the foregoing embodiments, and thus is not described herein again.

[0329] On the first network device side, at least one of the identifier of the first AIoT device and the response content corresponding to the second instruction can be sent to the application function (AF) on the condition that the integrity of the second service request is verified successfully or passed.

[0330] In another case, the first AIoT device can calculate the third ciphertext data first and then calculate the third message check code. The third ciphertext data can be calculated based on the fifth key and a sixth input parameter in the eighth calculation manner. The sixth input parameter can include at least part of the content required to be carried by the second response message. The sixth input parameter can include at least one of the response content corresponding to the second instruction, the identifier of the first AIoT device, the third freshness value, and the identification information corresponding to the fifth key. The third message check code can be calculated based on the fifth key and a fifth input parameter in the seventh calculation manner. The fifth input parameter can include at least part of the content required to be carried by the second response message. The fifth input parameter can include at least one of the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the identification information corresponding to the fifth key, and the third ciphertext data.

[0331] Different from the above case, the third message check code is not included in the sixth input parameter in this case; and the fifth input parameter can include the third ciphertext data.

[0332] Optionally, if the fifth key is the second key, after the first network device receives the second response message and the first authentication response, the first network device can verify the third message check code and decrypt the third ciphertext data based on the first authentication response determining that the first AIoT device is authenticated to the network successfully. Here, the first network device can decrypt the third ciphertext data based on the second key in the case that the integrity of the second response message is verified to be passed or successful.

[0333] On the side of the first network device, it can also include: in the case that the integrity of the second response message is verified to be successful, sending the following at least one to an application function (AF): the identifier of the first AIoT device, the response content corresponding to the second instruction.

[0334] Optionally, if the fifth key is the sixth key, after the first network device receives the second response message and the first authentication response, the first network device can send the second response message to the application function (AF) based on the first authentication response determining that the first AIoT device is authenticated to the network successfully. In this case, the AF can decrypt and verify the integrity of the second response message, which is not described here.

[0335] The following will be described in combination with FIG. 5, taking the first network device as an AMF or an AIOTF (denoted as AIoTF / AMF in FIG. 5) and the second network device as an authentication function as an example.

[0336] The scenario provided in FIG. 5 is that the first AIoT device has received a first service request (i.e., a first service request carrying a first instruction) for inventory, and then the first AIoT device reports the identifier of the AIoT device by sending an uplink message, and at the same time, the uplink message triggers the network to authenticate the first AIoT device. Different from the existing mechanism (4G, 5G) in which the UE initially authenticates the network and then the network authenticates the device, the present solution proposes a way of first authenticating the first AIoT device by the network and then optionally authenticating the network by the first AIoT device. Specifically, it includes:

[0337] Step 501, the first AIoT device returns a first response message to the AIoT F / AMF, which can be a paging / Inventory response message, and the first response message contains a first authentication vector AUTN_device calculated by the first AIoT device, which is calculated using the root key of the first AIoT device for authentication and the first random number RAND_1. In addition, the first response message can also carry the response content corresponding to the first instruction (such as the identifier of the first AIoT device).

[0338] The calculation method of the authentication parameter AUTN_device can be similar to the calculation method of RES in the existing authentication mechanism of UE, that is, AUTN_device=fK(RAND); wherein f is an algorithm used for authentication, and K is the root key of the AIOT device.

[0339] It should be pointed out that before step 501, the first AIoT device can receive a first service request, which is not shown in the example for the sake of brevity.

[0340] The first response message returned by the first AIoT device to the AIoT F / AMF can be that the first AIoT device returns the first response message to the AIoT F / AMF through the read-write device. For example, the first AIoT device sends the first response message to the read-write device, and then the read-write device (Reader) returns AUTN_device and the first random number RAND_1 to the AIoT F / AMF.

[0341] Step 502, the AIoT F / AMF sends a message (i.e. a second authentication request) to the authentication network element of the first AIoT device, triggering the authentication of the first AIoT device.

[0342] The authentication can be one-way, because for the Inventory-only scenario, the network can complete the service after collecting the information related to the identifier of the first AIoT device, and from the network side, after authenticating the first AIoT device, the network can trust the information (such as the device identifier) contained in the paging / Inventory response message reported by the first AIoT device, and there is no need to trigger the authentication of the AIoT device to the network.

[0343] Or the authentication is two-way, because for the Inventory and Command scenario, the network side will send a Command request to the AIoT device based on the service request of the AF, so the network side can make the first AIoT device authenticate the network, so that the first AIoT device trusts and executes the command issued by the network;

[0344] The trigger request can include the type of AIoT authentication, i.e., indicator_auth, to indicate one-way authentication or two-way authentication.

[0345] At step 503, the authentication network element first calculates AUTN_device' based on RAND_1 and verifies whether it is equal to the received AUTN_device. If the verification is successful, the network side successfully authenticates the first AIoT device, so that the information (such as the identifier of the first AIoT device) contained in the paging / Inventory response message reported by the first AIoT device can be trusted.

[0346] If the authentication type is two-way authentication, the authentication network element further performs step 504, in which the authentication network element calculates a second authentication vector AUTN_NW. This parameter is calculated using the root key of the first AIoT device and a second random number RAND_2 (which can be sent by the first AIoT device or reselected by the authentication network element).

[0347] The calculation method of the authentication parameter AUTN_NW can be similar to the calculation method of MAC in the existing authentication mechanism of UE, i.e., AUTN_NW = f'K(RAND); where f' is an algorithm used in another authentication, and K is the root key of the AIOT device.

[0348] At step 505, the authentication network element returns the authentication request (i.e., the first authentication request in the foregoing embodiment) to the AIoTF / AMF, carrying the second authentication vector AUTN_NW and the second random number.

[0349] At step 506, the AIoTF / AMF sends an authentication request to the first AIoT device. Specifically, the AIoTF / AMF sends an authentication request to the first AIoT device through a reader / writer device. For example, the AIoTF / AMF sends an authentication request to the reader / writer device, and then the reader / writer device (Reader) returns AUTN_NW and the second random number to the AIoTF / AMF.

[0350] At step 507, the first AIoT device first calculates AUTN_NW' based on RAND_2 and verifies whether it is equal to the received AUTN_NW. If the verification is successful, the AIoT device successfully authenticates the network side, so that the information (such as various commands) contained in the paging / Inventory / Command request message issued by the network can be trusted.

[0351] At step 508, the first AIoT device returns an ACK authentication confirmation to the network.

[0352] Specifically, as shown in FIG. 5, the first AIoT device sends the ACK authentication confirmation to the read-write device, the read-write device sends the ACK authentication confirmation to the AIOTF / AMF, and the AIOTF / AMF sends the ACK authentication confirmation to the authentication function.

[0353] Optionally, in step 506, the message sent by the AIoTF / AMF to the first AIoT device can also contain a Command request (i.e., a second instruction), and then the first AIoT device executes the command of the network side according to the content in the Command request after successfully authenticating the network side.

[0354] Correspondingly, in step 508, if the first AIoT device has data to return, the first AIoT device can also return the data, and the data can be protected. The data can be an inventory response or a response to a command service.

[0355] In this case, the device on the network side can also send the inventory response or the response to the command service to the AF, which is shown in FIG. 5 as the authentication function sending the inventory response or the response to the command service to the AF. In actual processing, the AIOTF / AMF can also send the inventory response or the response to the command service to the AF.

[0356] Taking the data in the Command response message as an example, the first AIoT device can use the key K_autn (second key) derived from the root key after authentication or the key K_e2e (sixth key) shared with the AF for protecting end-to-end information to securely protect the command response message. K_autn is generated by the authentication process of the first AIOT device and the root key. The input key for generating the key can be K or a subordinate key of K; the input parameters can include the identifier of the AIOT device, a random number RAND, and the like. K_e2e is shared between the AIOT device and the AF and is pre-stored on the AIOT device.

[0357] By using the above scheme, in the case where the first AIoT device receives the first service request and triggers the execution of the first instruction, the network side authenticates the first AIoT device at the same time when the first AIoT device sends the first response message carrying the response content corresponding to the first instruction. In this way, the network side can be triggered to authenticate the first AIoT device by the first AIoT device, so as to ensure that the network can trust the authenticity of the content reported by the first AIoT device.

[0358] Further, the network side can trigger a two-way authentication after the first AIoT device is authenticated, so that the first AIoT device authenticates the network, thereby enabling the first AIoT device to trust and execute the commands issued by the network, avoiding the problem that the AIoT device in the related art may be attacked by using false commands.

[0359] FIG. 6 is a schematic flowchart of a communication method performed by a first AIoT device according to an embodiment of the present application. The method includes at least part of the following.

[0360] S610, receiving a third service request from the first network device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is securely protected based on a security parameter.

[0361] FIG. 7 is a schematic flowchart of a communication method performed by a first network device according to an embodiment of the present application. The method includes at least part of the following.

[0362] S710, sending a third service request to the first AIoT device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is securely protected based on a security parameter.

[0363] The possible device types or functions of the first network device are the same as those in the foregoing embodiments, such as at least one of AMF, AIoTF, and read-write device, and details are not repeated here.

[0364] In some possible implementation manners, the processing of the first network device can include receiving a service request of an AF. The related description of the service request of the AF received by the first network device, and the related description of the content possibly carried by the service request of the AF are the same as those in the foregoing embodiments, and thus are not repeated.

[0365] In some possible implementation manners, the processing of the first network device can further include obtaining a security parameter. The security parameter includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function AF, a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key.

[0366] On the first network device side, the processing of obtaining the security parameter is the same as that in the foregoing embodiments, and thus is not repeated. The specific description of the content included in the security parameter is also the same as that in the foregoing embodiments, and thus is not repeated.

[0367] The third service request is securely protected based on security parameters, which can include integrity protection and / or encryption protection.

[0368] The third service request carries at least one of the following: instruction content indicating an inventory operation, command content indicating a command operation, identification related information, a fourth message authentication code for verifying the integrity of the third service request, a fourth freshness value, fourth cipher data, and identification information corresponding to a seventh key, wherein the command content includes at least one of the following: read data, write data, disable, and enable, and the seventh key includes one of the following: a device key of the first AIoT device and the group key.

[0369] The third service request can not simultaneously carry the instruction content indicating the inventory operation and the command content indicating the command operation. The third service request carrying the instruction content indicating the inventory operation or the command content indicating the command operation can be determined based on the service request of the AF.

[0370] Optionally, the service scenario triggered or requested by the service request of the AF is an inventory-only scenario. In this example, the service request of the AF carries the instruction content indicating the inventory operation, and the third service request is used for the first AIoT device (or multiple AIoT devices including the first AIoT device) to determine to perform the inventory operation.

[0371] In this case, the third service request can carry the instruction content indicating the inventory operation, and can also carry at least one of the following: identification related information, a fourth message authentication code for verifying the integrity of the third service request, a fourth freshness value, fourth cipher data, and identification information corresponding to a seventh key.

[0372] Optionally, the service scenario triggered or requested by the service request of the AF is an inventory and command scenario. The service request of the AF carries the command content (or can carry the instruction content indicating the inventory operation and the command content).

[0373] In this case, the first network device can perform the processing of sending the third service request twice in succession.

[0374] When the third service request is sent for the first time, the third service request is used for the first AIoT device (or multiple AIoT devices including the first AIoT device) to determine to perform the inventory operation, and the third service request can carry the instruction content indicating the inventory operation, and can also carry at least one of the following: identification related information, a fourth message authentication code for verifying the integrity of the third service request, a fourth freshness value, fourth cipher data, and identification information corresponding to a seventh key.

[0375] When the third service request is sent for the second time, the third service request is used for the first AIoT device (or a plurality of AIoT devices containing the first AIoT device) to determine an operation corresponding to the command content to be executed, the third service request can carry the command content indicating the operation, and can further carry at least one of the following: identification-related information, a fourth message authentication code used for verifying the integrity of the third service request, a fourth freshness value, fourth cipher data, and identification information corresponding to the seventh key.

[0376] The identification-related information includes at least one of the following: identification of one or more AIoT devices, related identification of an AIoT device group, and identification of an area where the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0377] The identification-related information can be determined based on the service request of the AF. The manner of determining the identification-related information is similar to the manner of determining the first identification-related information or the second identification-related information in the foregoing embodiments, and thus will not be described herein.

[0378] The fourth freshness value can be generated by the first network device, and the manner in which the first network device generates the fourth freshness value is not limited in the embodiment.

[0379] Optionally, the third service request can be used only for the first AIoT device to determine the operation to be executed. The first network device can select, from the security parameters, any one of a device key of the first AIoT device and a group key as the seventh key.

[0380] Optionally, the third service request is used for a plurality of AIoT devices to determine the operation to be executed, and the third service request is a broadcast or groupcast message. The first network device can select, from the security parameters, a group key as the seventh key.

[0381] Optionally, the third service request is used for a plurality of AIoT devices to determine the operation to be executed, and the third service request is a unicast message. For the first AIoT device, the first network device can select, from the security parameters, any one of a device key of the first AIoT device and a group key as the seventh key.

[0382] The identification information corresponding to the seventh key can be any one of an identification of the seventh key or one or more NONCEs corresponding to or associated with the seventh key.

[0383] The processing of the first network device can further include at least one of the following: calculating the fourth message authentication code based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identity-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth ciphertext data; and calculating the fourth ciphertext data based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identity-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth message authentication code.

[0384] Correspondingly, the processing of the first AIoT device after receiving the third service request can further include: calculating a fourth message authentication code based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identity-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth ciphertext data; and verifying the integrity of the third service request based on the fourth message authentication code and the fourth message authentication code.

[0385] The processing of the first AIoT device after receiving the third service request can further include: decrypting the fourth ciphertext data based on the seventh key to obtain at least one of the following: the instruction content indicating the inventory operation, the command content, the identity-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth message authentication code.

[0386] On the first AIoT device side, the security parameter can be pre-configured or pre-stored.

[0387] In an example, the first network device only performs integrity protection on the third service request.

[0388] The fourth message authentication code can be calculated based on the seventh key and a seventh input parameter in a seventh calculation manner. The seventh input parameter can include at least part of the content required to be carried by the third service request. Preferably, the seventh input parameter can include the identity-related information. Optionally, the seventh input parameter can include the identity-related information and at least one of the following: the instruction content of the inventory operation, the command content, the fourth freshness value, and the identification information corresponding to the seventh key. It should be pointed out that the seventh input parameter can not simultaneously include the instruction content of the inventory operation and the command content.

[0389] The seventh calculation manner can be any calculation manner that can calculate a message authentication code, and the present embodiment does not make any limitation.

[0390] The first AIoT device calculates the fourth message verification code after receiving the third service request. The process of calculating the fourth message verification code is the same as that of the first network device calculating the fourth message verification code, and is not described again.

[0391] The first AIoT device can determine the seventh key based on the identification information corresponding to the seventh key.

[0392] It should be pointed out that the first AIoT device can calculate the fourth message verification code in the case of determining that the identification related information carried by the third service request matches. The way of determining that the identification related information carried by the third service request matches is the same as the way of determining that the first identification related information in the first instruction carried by the first service request matches, and is not described again.

[0393] On the first AIoT device side, based on the fourth message verification code and the fourth message verification code, the integrity of the fourth service request is verified. The description of verifying the integrity of the first service request based on the first message verification code and the first message verification code in the foregoing embodiment is the same, and is not described again.

[0394] Further, on the first AIoT device side, the instruction content or command content indicating the inventory operation carried by the third service request can be executed in the case of successfully verifying the integrity of the third service request. The content executed by the first AIoT device based on the instruction content indicating the inventory operation, or the specific process executed based on the command content, is similar to the foregoing embodiment, and is not described again.

[0395] In addition, on the first AIoT device side, it can also include: in the case of failing to verify the integrity of the third service request, the instruction content or command content indicating the inventory operation carried by the third service request is not executed.

[0396] In an example, the first network device only encrypts the third service request.

[0397] In this example, the third service request can carry fourth ciphertext data and fourth plaintext data.

[0398] The fourth ciphertext data can be calculated based on the seventh key and an eighth input parameter in an eighth calculation manner. The eighth input parameter can include at least part of the content required to be carried by the second service request. Preferably, the eighth input parameter at least includes the identification-related information, that is, at least the identification-related information in the third service request is encrypted and protected. Optionally, in addition to the identification-related information, the eighth input parameter can also include at least one of the instruction content of the inventory operation, the command content, the fourth freshness value, and the identification information corresponding to the seventh key. The eighth calculation manner can be any encryption manner, which is not limited in the embodiment.

[0399] Irrespective of whether the instruction content of the inventory operation or the command content is in the fourth plaintext data or the fourth ciphertext data, the instruction content of the inventory operation or the command content can not be simultaneously included in the third service request.

[0400] The fourth plaintext data can at least include the identification information corresponding to the seventh key, so that the receiving end (the first AIoT device) can identify or determine which key to use for decryption. It should be pointed out that the identification information corresponding to the seventh key is included in the fourth plaintext data, and it does not mean that the identification information corresponding to the seventh key cannot be encrypted. The identification information corresponding to the seventh key can be encrypted and included in the fourth plaintext data.

[0401] The processing of decrypting the fourth ciphertext data based on the seventh key by the first AIoT device after receiving the third service request corresponds to the manner of calculating the fourth ciphertext data, and is not described herein.

[0402] On the side of the first AIoT device, after the identification-related information is decrypted, the following processing can be further included: in a case where it is determined that the identification-related information carried by the third service request matches, the instruction content or the command content of the inventory operation carried by the third service request is executed.

[0403] In addition, on the side of the first AIoT device, the following processing can be further included: in a case where it is determined that the identification-related information carried by the third service request does not match, the instruction content or the command content of the inventory operation carried by the third service request is not executed.

[0404] In an example, the first network device performs integrity protection and encryption protection on the third service request.

[0405] In a case, the first network device can first calculate the fourth message authentication code and then calculate the fourth ciphertext data. In this case, the eighth input parameter used to calculate the fourth ciphertext data can include the fourth message authentication code; the seventh input parameter used to calculate the fourth message authentication code does not include the fourth ciphertext data.

[0406] In the case, the second service request message can carry the second ciphertext data and the second plaintext data, and the second plaintext data at least includes the identification information of the fourth key.

[0407] The first AIoT device can first decrypt the fourth ciphertext data, then calculate the fourth message authentication code, and then verify the integrity of the third service request based on the fourth message authentication code and the fourth message check code.

[0408] The first AIoT device decrypts the fourth ciphertext data in the same way as the previous embodiments, and will not be repeated.

[0409] On the first AIoT device side, the fourth message authentication code can be calculated if it is determined that the identification related information carried by the third service request matches. The process of calculating the fourth message authentication code on the first AIoT device side should be the same as the process of calculating the fourth message check code on the first network device, and will not be repeated; the process of verifying the integrity of the third service request is the same as the previous embodiments, and will not be repeated.

[0410] The first AIoT device can execute the instruction content or command content indicating the inventory operation carried by the third service request if the verification of the integrity of the third service request is successful or passed.

[0411] In another case, the first network device can first calculate the fourth ciphertext data and then calculate the fourth message check code. The difference between this case and the previous case is that the eighth input parameter used to calculate the fourth ciphertext data does not necessarily include the fourth message check code in this case; the seventh input parameter used to calculate the fourth message check code can include the fourth ciphertext data.

[0412] The first AIoT device can first verify the fourth message check code and then decrypt the fourth ciphertext data. On the first AIoT device side, after decrypting the identification related information, it can also include: executing the instruction content or command content indicating the inventory operation carried by the third service request if it is determined that the identification related information carried by the third service request matches.

[0413] In some possible implementations, after the first AIoT device executes the instruction content or command content indicating the inventory operation carried by the third service request, it can also include: sending a third response message to the first network device, wherein the third response message is used to indicate the execution result of the first AIoT device, and the third response message is securely protected based on the security parameter. Correspondingly, the process of the first network device can also include: receiving the third response message from the first AIoT device.

[0414] The security protection can include integrity protection and / or encryption protection.

[0415] The third response message carries at least one of the following: an execution result of the first AIoT device, an identifier of the first AIoT device, a fifth message authentication code for verifying integrity of the third response message, fifth ciphertext data, a fifth freshness value, and identification information corresponding to an eighth key. The eighth key includes one of the following: a device key of the first AIoT device and the group key.

[0416] The first AIoT device further includes at least one of the following: calculating the fifth message authentication code based on the eighth key and at least one of the following: the execution result of the first AIoT device, the identifier of the first AIoT device, the fifth freshness value, the fifth ciphertext data, and the identification information corresponding to the eighth key; and calculating the fifth ciphertext data based on the eighth key and at least one of the following: the execution result of the first AIoT device, the identifier of the first AIoT device, the fifth freshness value, the fifth message authentication code, and the identification information corresponding to the eighth key.

[0417] The execution result of the first AIoT device can be a result obtained by the first AIoT device performing an inventory operation based on instruction content indicating the inventory operation, and can include, for example, an identifier of the first AIoT device. Alternatively, the execution result of the first AIoT device can be a result obtained by the first AIoT device performing an operation corresponding to command content based on the command content.

[0418] The fifth freshness value can be generated by the first AIoT device. The manner of generating the fifth freshness value is not limited in this embodiment, and the fifth freshness value is different from the fourth freshness value.

[0419] The eighth key can be determined by the first AIoT device from a security parameter. The eighth key can be the same as or different from the seventh key. For example, the seventh key can be the group key, and the eighth key can be the device key of the first AIoT device.

[0420] In an example, only the third response message is integrity protected.

[0421] Since the third response message in the uplink contains the identification of the specific device, tampering of the message can cause the AIoTF to collect incorrect device identification information, the AF to obtain incorrect inventory results, or if the network wants to further execute the Command, the AIoTF holding the incorrect device identification cannot find the AIoT device to execute the Command process, thereby causing service failure. Therefore, a complete integrity protection mechanism is given for the uplink message returned by the first AIoT device to the AIoTF, which can use a group key GK or use a single device key Ktag. In addition, considering that if the uplink message cannot resist replay, the attacker can intercept the response message sent by the first AIoT device and replay it to the AIoTF multiple times. Since the number of AIoT devices is large, replay attacks can cause depletion of AIoTF network resources and failure to perform AIoT services.

[0422] The fifth message authentication code can be calculated based on the eighth key and a ninth input parameter using a ninth calculation method. The ninth input parameter can include at least part of the content required to be carried by the third response message. Preferably, the ninth input parameter can include the identification of the first AIoT device.

[0423] The ninth calculation method can be any calculation method that can calculate a message authentication code, and the present embodiment is not limited thereto.

[0424] For example, using a group key GK or a single device key Ktag as the eighth key, the content contained in the third response message is: information related to the identification of the first AIoT device uplink ID Info (identification related information), the integrity verification code MAC (i.e. the fifth message authentication code) calculated using GK / Ktag on uplink ID info (or paging / Inventory response message), Freshness (selected by the AIoT device) for calculating MAC, Nonce for calculating MAC.

[0425] The processing of the first network device to calculate the fifth message authentication code after receiving the third response message should be the same as the processing of calculating the fifth message authentication code, and is not described in detail.

[0426] The first network device can determine the eighth key based on the identification information corresponding to the eighth key.

[0427] On the first AIoT device side, based on the fifth message authentication code and the fifth message authentication code, the integrity of the third response message is verified, which is the same as the description of verifying the integrity of the second response message in the foregoing embodiments, and is not described in detail.

[0428] Further, on the first network device side, the method further includes: in a case where the integrity of the third response message is verified to be successful, sending, to an application function (AF), at least one of the following: an identifier of the first AIoT device, and an execution result of the first AIoT device.

[0429] In an example, only the third response message is encrypted.

[0430] Since the uplink third response message carries the identifier of a specific device, if plaintext transmission is used, an attacker may eavesdrop on the device identifier, thereby being able to track and link the device, and the message transmission range of the first AIoT device is small, so the location range of a specific device can be obtained, especially in the use case where the first AIoT device is a personal device (for example, a wearable IoT). Therefore, the encryption protection mechanism of the uplink first is provided here, which can use a group key GK or use a single device key Ktag as an eighth key for encryption and / or decryption.

[0431] In this example, the third response message can carry fifth ciphertext data and fifth plaintext data.

[0432] The fifth ciphertext data can be calculated based on the eighth key and a tenth input parameter by using a tenth calculation manner. The tenth input parameter can include at least part of the content required to be carried by the third response message. Preferably, the tenth input parameter at least includes the identifier of the first AIoT device. The tenth calculation manner can be any encryption manner, which is not limited in the embodiment.

[0433] The fifth plaintext data at least includes identification information corresponding to the eighth key, so that the receiving end can identify or determine which key to use for decryption. It should be pointed out that the identification information corresponding to the eighth key is included in the fifth plaintext data, which does not mean that the identification information corresponding to the eighth key cannot be encrypted. The identification information corresponding to the eighth key can be encrypted and included in the fifth plaintext data.

[0434] For example, the group key GK or the single device key Ktag is used as the eighth key, and the fifth plaintext data generated by encrypting the following parameters includes: uplink ID info (or paging / Inventory request message), freshness parameter Freshness (selected by the AIoT device), and nonce (a security parameter shared between the AIOT and the AF, which can be identified by the AIoT device). The plaintext form, i.e., the fifth plaintext data, includes the nonce or the key identifier GK / Ktag ID.

[0435] The decryption processing of the first network device should correspond to the encryption processing of the first AIoT device, and the embodiment will not be described in detail. After decryption, the first network device can further include: sending at least one of the following to the application function AF: the identifier of the first AIoT device, the execution result of the first AIoT device.

[0436] In an example, the third response message is integrity protected and ciphered.

[0437] In one case, the fifth message check code can be calculated first, and then the fifth cipher data is calculated. In this case, the input parameters for calculating the fifth cipher data can include the fifth message check code; the input parameters for calculating the fifth message check code must not include the fifth cipher data.

[0438] The first network device can first decrypt the fifth cipher data, then calculate the fifth message authentication code, and then verify the integrity of the third response message based on the fifth message authentication code and the fifth message check code. Here, the decryption processing of the first network device, the calculation of the fifth message authentication code, and the verification of the integrity of the third response message will not be described in detail.

[0439] The first network device can be in the case where the integrity of the third response message is verified successfully or passed, and at least one of the following is sent to the application function AF: the identifier of the first AIoT device, the execution result of the first AIoT device.

[0440] In another case, the fifth cipher data can be calculated first, and then the fifth message check code is calculated. Different from the above case, in this case, the input parameters for calculating the fifth cipher data must not include the fifth message check code; the input parameters for calculating the fifth message check code can include the fifth cipher data.

[0441] The first network device can first verify the fifth message check code, and then decrypt the fifth cipher data in the case where the integrity of the third response message is verified successfully. On the first network device side, after decryption, it can further include: sending at least one of the following to the application function AF: the identifier of the first AIoT device, the execution result of the first AIoT device.

[0442] In combination with FIG. 8, the communication process in the AIoT Inventory service and the Command service will be exemplarily described taking the first network device as an example, which can be an AMF or an AIOTF (represented as AIoTF in FIG. 8).

[0443] Step 801, the AF sends an AIoT Inventory service or Command service request (i.e., the service request of the AF in the foregoing embodiment) to the AIoTF through the NEF.

[0444] Step 802, the AIoTF selects a base station or a UE as a Reader. Here, the manner in which the AIoTF selects the base station or the UE is not limited in the embodiment.

[0445] Step 803, the AIoTF sends a paging request message or an Inventory request message (i.e., the third service request) to the Reader, which is a message instructing the Reader to perform paging or Inventory on a single or multiple AIoT devices. (The message can also be a paging or Inventory trigger message, and the message name is not limited here.)

[0446] For the case where the Reader is a UE, the AIoTF sends a message to the UE through a control plane or a user plane connection, which contains an instruction for the UE to perform paging or Inventory on the first AIoT device as a Reader.

[0447] Step 804, the Reader sends a paging or Inventory request to the first AIoT device, which can be a broadcast message similar to the existing paging message.

[0448] Step 805, the first AIoT device checks whether the device identifier carried in the received paging or Inventory request matches its own device identifier, and returns a paging or Inventory response (i.e., the third response message) if they match.

[0449] Step 806, the Reader returns a paging or Inventory response (i.e., the third response message) to the AIoTF. If there is no subsequent operation, step 807 is performed, in which the AIoTF returns an Inventory service or Command service response to the AF.

[0450] By adopting the above scheme, when the first AIoT device receives the third service request for triggering it to perform a corresponding operation, the third service request can be secured based on a security parameter. In this way, the message transmitted between the first AIoT device and the network side can be protected, and the security of the device identifier can be guaranteed when the message content involves the device identifier.

[0451] Further, in the related art, in the initial Inventory process, the first AIoT device cannot obtain a temporary identifier because the registration process is not performed, so the network and the AIoT device cannot protect the permanent identifier of the first AIoT device using the temporary identifier. And because the authentication between the AIoT device and the network is not performed, the initial Inventory (also known as paging) process cannot be protected using the security context generated after authentication. Therefore, the above scheme proposes to protect the security of the messages transmitted between the first AIoT device and the network by using security parameters to protect the messages transmitted between the first AIoT device and the network side.

[0452] Fig. 9 is a schematic diagram of the composition structure of the first AIoT device according to an embodiment of the present application, which includes:

[0453] The first communication unit 901 is configured to receive a first service request from a first network device, wherein the first service request is used to execute a first instruction by the first AIoT device; and send a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0454] The first response message carries at least one of the following: a first authentication vector for authenticating the first AIoT device, and a first random number, wherein the first authentication vector is calculated based on a first key shared by the first AIoT device and the network and / or the first random number.

[0455] The first communication unit is configured to receive a first authentication request from the first network device, wherein the first authentication request carries at least one of the following: a second authentication vector for authenticating the network, and a second random number.

[0456] As shown in Fig. 9, the first AIoT device further includes:

[0457] The first processing unit 902 is configured to calculate a second authentication vector based on a first key shared by the first AIoT device and the network and / or a second random number; and authenticate the network based on the second authentication vector and the second authentication vector.

[0458] The first communication unit is configured to send a first authentication response to the first network device, wherein the first authentication response is used to indicate the authentication result of the network.

[0459] The first processing unit is configured to derive a second key for protecting messages transmitted between the first AIoT device and the first network device based on a first key shared by the first AIoT device and the network.

[0460] The first service request carries at least one of the following: the first instruction, a first message authentication code for verifying integrity of the first service request, a first freshness value, first cipher data, and identification information corresponding to a third key, wherein the third key includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), or a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF.

[0461] The first instruction includes at least one of the following: instruction content indicating an inventory operation, and first identification-related information, wherein the first identification-related information includes at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, or an identifier of an area to which the one or more AIoT devices belong, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0462] The first processing unit is configured to calculate a first message authentication code based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification-related information, the first freshness value, the first cipher data, and the identification information corresponding to the third key, and verify integrity of the first service request based on the first message authentication code and the first message authentication code.

[0463] The first processing unit is configured to decrypt, based on the third key, the first cipher data to obtain at least one of the following: the instruction content indicating the inventory operation, the first identification-related information, the first message authentication code, the first freshness value, and the identification information corresponding to the third key.

[0464] The first communication unit is configured to receive a second service request from the first network device, wherein the second service request is used to execute a second instruction by the first AIoT device.

[0465] The second service request carries at least one of the following: the second instruction, a second message authentication code for verifying integrity of the second service request, a second freshness value, identification information corresponding to a fourth key, and second cipher data, wherein the fourth key includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), or a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF, or a second key used to protect a message transmitted between the first AIoT device and the first network device.

[0466] The second instruction includes at least one of the following: command content, and second identification related information, wherein the command content includes at least one of the following: read data, write data, disable, and enable, and the second identification related information includes at least one of the following: identification of one or more AIoT devices, related identification of an AIoT device group, and identification of an area where the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0467] The first processing unit is configured to calculate a second message authentication code based on the fourth key and at least one of the following: the command content, the second identification related information, the second freshness value, identification information corresponding to the fourth key, and the second ciphertext data, and verify integrity of the second service request based on the second message authentication code and a second message check code.

[0468] The first processing unit is configured to decrypt the second ciphertext data based on the fourth key to obtain at least one of the following: the command content, the second identification related information, the second freshness value, identification information corresponding to the fourth key, and the second message check code.

[0469] The first communication unit is configured to send a second response message to the first network device, wherein the second response message is used to indicate response content corresponding to the second instruction.

[0470] The second response message carries at least one of the following: response content corresponding to the second instruction, identification of the first AIoT device, a third message check code used to verify integrity of the second response message, a third freshness value, third ciphertext data, and identification information corresponding to a fifth key, wherein the fifth key includes one of the following: a second key used to protect a message transmitted between the first AIoT device and the first network device, and a sixth key used to protect a message transmitted between the first AIoT device and an application function (AF).

[0471] The first processing unit is configured to perform at least one of the following: calculate the third message check code based on the fifth key and at least one of the following: identification of the first AIoT device, response content corresponding to the second instruction, the third freshness value, the third ciphertext data, and identification information corresponding to the fifth key; and calculate the third ciphertext data based on the fifth key and at least one of the following: identification of the first AIoT device, response content corresponding to the second instruction, the third freshness value, identification information corresponding to the fifth key, and the third message check code.

[0472] Fig. 10 is a schematic diagram of a constituent structure of a first network device according to an embodiment of the present application, comprising:

[0473] The second communication unit 1001 is configured to send a first service request to the first AIoT device, wherein the first service request is used to instruct the first AIoT device to execute a first instruction; and receive a first response message from the first AIoT device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device.

[0474] The first response message carries at least one of the following: a first authentication vector used to authenticate the first AIoT device, and a first random number.

[0475] The second communication unit is configured to send a second authentication request to a second network device, wherein the second authentication request is used to authenticate the first AIoT device.

[0476] The second authentication request carries at least one of the following: the first authentication vector, the first random number, and an authentication type, wherein the authentication type includes one of the following: one-way authentication and two-way authentication.

[0477] The second communication unit is configured to receive a first authentication request from the second network device, wherein the first authentication request carries at least one of the following: a second authentication vector used to authenticate a network, and a second random number; and send the first authentication request to the first AIoT device.

[0478] The second communication unit is configured to receive a first authentication response from the first AIoT device, wherein the first authentication response is used to indicate an authentication result for the network; and send the first authentication response to the second network device.

[0479] The second communication unit is configured to receive a second key from the second network device, wherein the second key is used to protect messages transmitted between the first AIoT device and the first network device.

[0480] The first service request carries at least one of the following: the first instruction, a first message check code used to verify integrity of the first service request, a first freshness value, identification information corresponding to a third key, and first cipher text data, wherein the third key includes one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), and a group key of a group in which the first AIoT device is located, shared by the first AIoT device and the AF.

[0481] The first instruction includes at least one of the following: instruction content indicating the inventory operation, first identification related information, wherein the first identification related information includes at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, an identifier of a region where the one or more AIoT devices are located, the AIoT device group including the one or more AIoT devices, and the one or more AIoT devices including the first AIoT device.

[0482] As shown in FIG. 10, the first network device further includes a second processing unit 1002 configured to perform at least one of the following: calculating the first message check code based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, identification information corresponding to the third key, and the first ciphertext data; and calculating the first ciphertext data based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first message check code, the first freshness value, and identification information corresponding to the third key.

[0483] The second communication unit is configured to send a second service request to the first AIoT device, wherein the second service request is used for the first AIoT device to execute a second instruction.

[0484] The second service request carries at least one of the following: the second instruction, a second message check code used for verifying integrity of the second service request, a second freshness value, identification information corresponding to a fourth key, and second ciphertext data, wherein the fourth key includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF, and a second key used for protecting a message transmitted between the first AIoT device and the first network device.

[0485] The second instruction includes at least one of the following: command content and second identification related information, wherein the command content includes at least one of the following: reading data, writing data, disabling, and enabling, and the second identification related information includes at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, and an identifier of a region where the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0486] The second processing unit is configured to perform at least one of the following: calculating the second message check code based on the fourth key and at least one of the following: the command content, the second identity-related information, the second freshness value, the identification information corresponding to the fourth key, and the second ciphertext data; and calculating the second ciphertext data based on the fourth key and at least one of the following: the command content, the second identity-related information, the second freshness value, the identification information corresponding to the fourth key, and the second message check code.

[0487] The second communication unit is configured to obtain a security parameter, where the security parameter includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key.

[0488] The second communication unit is configured to receive a second response message from the first AIoT device, where the second response message is used to indicate a response content corresponding to the second instruction.

[0489] The second response message carries at least one of the following: the response content corresponding to the second instruction, an identity of the first AIoT device, a third message check code used to verify the integrity of the second response message, a third freshness value, third ciphertext data, and identification information corresponding to a fifth key, where the fifth key includes one of the following: a second key used to protect a message transmitted between the first AIoT device and the first network device, and a sixth key used to protect a message transmitted between the first AIoT device and an application function (AF).

[0490] The second processing unit is configured to calculate the third message verification code based on the second key and at least one of the following: the identity of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the third ciphertext data, and the identification information corresponding to the fifth key; and verify the integrity of the second response message based on the third message verification code and the third message check code.

[0491] The second processing unit is configured to decrypt the third ciphertext data based on the second key to obtain at least one of the following: the identity of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the identification information corresponding to the second key, and the third message verification code.

[0492] The second communication unit is configured to perform one of the following: sending, to an application function (AF), at least one of the following: an identifier of the first AIoT device, and response content corresponding to the second instruction; or sending, to the application function (AF), the second response message.

[0493] FIG. 11 is a schematic diagram of a constituent structure of a second network device according to an embodiment of the present application, including:

[0494] The third communication unit 1101 is configured to receive a second authentication request from the first network device, where the second authentication request is used to authenticate the first AIoT device.

[0495] The second authentication request carries at least one of the following: a first authentication vector used to authenticate the first AIoT device, a first random number, and an authentication type, where the authentication type includes one of the following: one-way authentication and two-way authentication.

[0496] As shown in FIG. 11, the second network device further includes:

[0497] The third processing unit 1102 is configured to calculate a first verification vector based on a first key shared by the first AIoT device and the network and / or the first random number, and authenticate the first AIoT device based on the first verification vector and the first authentication vector.

[0498] The third communication unit is configured to send, to the first network device, a first authentication request carrying at least one of the following: a second authentication vector used to authenticate the network, and a second random number, where the second authentication vector is calculated based on a first key shared by the first AIoT device and the network and / or the second random number.

[0499] The third communication unit is configured to send, to the first network device, a second key used to protect messages transmitted between the first AIoT device and the first network device.

[0500] The first AIoT device according to an embodiment of the present application includes:

[0501] The first communication unit is configured to receive a third service request from the first network device, where the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is securely protected based on a security parameter.

[0502] The security parameter includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key.

[0503] The third service request carries at least one of the following: instruction content indicating an inventory operation, command content indicating a command operation, identification related information, a fourth message authentication code for verifying integrity of the third service request, a fourth freshness value, fourth cipher text data, and identification information corresponding to a seventh key, wherein the command content includes at least one of the following: read data, write data, disable, and enable, and the seventh key includes one of the following: a device key of the first AIoT device and the group key.

[0504] The first AIoT device further includes a first processing unit configured to: calculate a fourth message authentication code based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identification related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth cipher text data; and verify integrity of the third service request based on the fourth message authentication code and the fourth message authentication code.

[0505] The first processing unit is configured to decrypt the fourth cipher text data based on the seventh key to obtain at least one of the following: the instruction content indicating the inventory operation, the command content, the identification related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth message authentication code.

[0506] The identification related information includes at least one of the following: identification of one or more AIoT devices, identification of an AIoT device group, and information of an area in which the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0507] The first communication unit is configured to send a third response message to the first network device, wherein the third response message is used to indicate an execution result of the first AIoT device, and the third response message is secured based on the security parameter.

[0508] The third response message carries at least one of the following: an execution result of the first AIoT device, an identifier of the first AIoT device, a fifth message check code for verifying integrity of the third response message, fifth ciphertext data, a fifth freshness value, and identification information corresponding to an eighth key, wherein the eighth key includes one of the following: a device key of the first AIoT device and the group key.

[0509] The first processing unit is configured to perform at least one of the following: calculating the fifth message check code based on the eighth key and at least one of the following: the execution result of the first AIoT device, the identifier of the first AIoT device, the fifth freshness value, the fifth ciphertext data, and the identification information corresponding to the eighth key; and calculating the fifth ciphertext data based on the eighth key and at least one of the following: the execution result of the first AIoT device, the identifier of the first AIoT device, the fifth freshness value, the fifth message check code, and the identification information corresponding to the eighth key.

[0510] The first network device according to an embodiment of the present application comprises:

[0511] The second communication unit is configured to send a third service request to the first AIoT device, wherein the third service request is used for the first AIoT device to determine an operation to be performed, and the third service request is secured based on a security parameter.

[0512] The second communication unit is configured to obtain a security parameter, wherein the security parameter includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key.

[0513] The third service request carries at least one of the following: instruction content indicating a check operation, command content indicating a command operation, identification information, a fourth message check code for verifying integrity of the third service request, a fourth freshness value, identification information corresponding to a seventh key, and fourth ciphertext data, wherein the command content includes at least one of the following: reading data, writing data, disabling, and enabling, and the seventh key includes one of the following: a device key of the first AIoT device and the group key.

[0514] The first network device further includes a second processing unit configured to perform at least one of the following: calculating the fourth message authentication code based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identity-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth ciphertext data; and calculating the fourth ciphertext data based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identity-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth message authentication code.

[0515] The identity-related information includes at least one of the following: an identity of one or more AIoT devices, a related identity of an AIoT device group, and an identity of an area in which the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device.

[0516] The second communication unit is configured to receive a third response message from the first AIoT device, wherein the third response message is used to indicate an execution result of the first AIoT device, and the third response message is securely protected based on the security parameter.

[0517] The third response message carries at least one of the following: the execution result of the first AIoT device, the identity of the first AIoT device, a fifth message authentication code used to verify the integrity of the third response message, fifth ciphertext data, a fifth freshness value, and identification information corresponding to an eighth key, wherein the eighth key includes at least one of the following: a device key of the first AIoT device and the group key.

[0518] The second processing unit is configured to calculate a fifth message authentication code based on the eighth key and at least one of the following: the execution result of the first AIoT device, the identity of the first AIoT device, the fifth freshness value, the fifth ciphertext data, and the identification information corresponding to the eighth key; and verify the integrity of the third response message based on the fifth message authentication code and the fifth message authentication code.

[0519] The second processing unit is configured to decrypt the fifth ciphertext data based on the eighth key to obtain at least one of the following: the execution result of the first AIoT device, the identity of the first AIoT device, the fifth freshness value, the fifth message authentication code, and the identification information corresponding to the eighth key.

[0520] The device of the embodiments of the present application can realize the corresponding functions of each device in the foregoing communication method embodiments. The processes, functions, implementation manners and advantages of each module (sub-module, unit or component, etc.) in the device can be referred to the corresponding description in the foregoing method embodiments, and will not be described herein. It should be noted that the functions described with respect to each module (sub-module, unit or component, etc.) in the device of the embodiments of the present application can be realized by different modules (sub-modules, units or components, etc.), or can be realized by the same module (sub-module, unit or component, etc.).

[0521] It should be understood that the magnitude of the serial number of each process in the various embodiments of the present application does not mean the order of execution. The execution order of each process should be determined according to its function and inherent logic. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the system, device and unit described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be described herein. The above is merely a specific implementation of the present application, and the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

A communication method performed by a first AIoT device, comprising: receiving a first service request from a first network device, wherein the first service request is used for the first AIoT device to execute a first instruction; sending a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device. The method of claim 1, wherein, The first response message carries at least one of the following: a first authentication vector used to authenticate the first AIoT device, a first random number, wherein the first authentication vector is calculated based on a first key shared by the first AIoT device and a network and / or the first random number. The method according to claim 1 or 2, further comprising: receiving a first authentication request from the first network device, wherein the first authentication request carries at least one of the following: a second authentication vector used to authenticate a network, a second random number. The method according to claim 3, further comprising: calculating a second authentication vector based on a first key shared by the first AIoT device and the network and / or the second random number; authenticating the network based on the second authentication vector and the second authentication vector. The method according to claim 3 or 4, further comprising: sending a first authentication response to the first network device, wherein the first authentication response is used to indicate an authentication result of the network. The method according to any one of claims 1-5, further comprising: deriving a second key used to protect a message transmitted between the first AIoT device and the first network device based on a first key shared by the first AIoT device and a network. The method according to any one of claims 1 to 6, wherein The first service request carries at least one of the following: the first instruction, a first message authentication code used to verify integrity of the first service request, a first freshness value, first cipher data, and identification information corresponding to a third key, wherein the third key comprises one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), and a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF. The method of claim 7, wherein, The first instruction comprises at least one of the following: instruction content indicating an inventory operation, and first identification related information, wherein the first identification related information comprises at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, and an identifier of an area in which the one or more AIoT devices are located, wherein the AIoT device group comprises the one or more AIoT devices, and the one or more AIoT devices comprise the first AIoT device. The method according to claim 8, further comprising: calculating a first message authentication code based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, the first cipher data, and the identification information corresponding to the third key. verify integrity of the first service request based on the first message authentication code and the first message check code. The method of claim 8 or 9, further comprising: decrypt the first cipher data based on the third key to obtain at least one of the instruction content indicating the inventory operation, the first identification related information, the first message authentication code, the first freshness value, and identification information corresponding to the third key. The method of any of claims 3-6, further comprising: receive a second service request from the first network device, wherein the second service request is for the first AIoT device to execute a second instruction. The method of claim 11, wherein, The second service request carries at least one of the second instruction, a second message check code for verifying integrity of the second service request, a second freshness value, identification information corresponding to a fourth key, and second cipher data, wherein the fourth key comprises at least one of a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF, and a second key for protecting messages transmitted between the first AIoT device and the first network device. The method of claim 12, wherein, The second instruction comprises at least one of command content and second identification related information, wherein the command content comprises at least one of read data, write data, disable, and enable, and the second identification related information comprises at least one of an identifier of one or more AIoT devices, a related identifier of an AIoT device group, and an identifier of an area in which the one or more AIoT devices are located, wherein the AIoT device group comprises the one or more AIoT devices, and the one or more AIoT devices comprise the first AIoT device. The method of claim 13, further comprising: calculating a second message authentication code based on the fourth key and at least one of the command content, the second identification related information, the second freshness value, the identification information corresponding to the fourth key, and the second cipher data; verify integrity of the second service request based on the second message authentication code and the second message check code. The method of claim 13 or 14, further comprising: decrypt the second cipher data based on the fourth key to obtain at least one of the command content, the second identification related information, the second freshness value, the identification information corresponding to the fourth key, and the second message check code. The method of any of claims 11-15, further comprising: send a second response message to the first network device, wherein the second response message is used to indicate response content corresponding to the second instruction. The method of claim 16, wherein, The second response message carries at least one of the following: response content corresponding to the second instruction, an identifier of the first AIoT device, a third message authentication code for verifying integrity of the second response message, a third freshness value, third ciphertext data, and identification information corresponding to a fifth key, wherein the fifth key includes one of the following: a second key for protecting messages transmitted between the first AIoT device and the first network device, and a sixth key for protecting messages transmitted between the first AIoT device and an application function (AF). The method of claim 17, further comprising at least one of: calculating the third message authentication code based on the fifth key and at least one of the following: the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the third ciphertext data, and the identification information corresponding to the fifth key; calculating the third ciphertext data based on the fifth key and at least one of the following: the identifier of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the identification information corresponding to the fifth key, and the third message authentication code. A communication method performed by a first network device, comprising: sending a first service request to a first AIoT device, wherein the first service request is used for the first AIoT device to execute a first instruction; receiving a first response message from the first AIoT device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device. The method of claim 19, wherein, The first response message carries at least one of the following: a first authentication vector for authenticating the first AIoT device, and a first random number. The method of claim 20, further comprising: sending a second authentication request to a second network device, wherein the second authentication request is used to authenticate the first AIoT device. The method of claim 21, wherein, The second authentication request carries at least one of the following: the first authentication vector, the first random number, and an authentication type, wherein the authentication type includes one of the following: one-way authentication and two-way authentication. The method of claim 21 or 22, further comprising: receiving a first authentication request from the second network device, wherein the first authentication request carries at least one of the following: a second authentication vector for authenticating a network, and a second random number; sending the first authentication request to the first AIoT device. The method of claim 23, further comprising: receiving a first authentication response from the first AIoT device, wherein the first authentication response is used to indicate an authentication result for the network; sending the first authentication response to the second network device. The method of any one of claims 21-24, further comprising: receiving a second key from the second network device, wherein the second key is used to protect messages transmitted between the first AIoT device and the first network device. The method of any one of claims 19-25, wherein, The first service request carries at least one of the following: the first instruction, a first message authentication code for verifying integrity of the first service request, a first freshness value, identification information corresponding to a third key, and first cipher text data, wherein the third key includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), or a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF. The method of claim 26, wherein, The first instruction includes at least one of the following: instruction content indicating an inventory operation, and first identification related information, wherein the first identification related information includes at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, or an identifier of an area to which the one or more AIoT devices belong, the AIoT device group including the one or more AIoT devices, and the one or more AIoT devices including the first AIoT device. The method of claim 27, further comprising at least one of the following: calculating the first message authentication code based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first freshness value, the identification information corresponding to the third key, or the first cipher text data; calculating the first cipher text data based on the third key and at least one of the following: the instruction content indicating the inventory operation, the first identification related information, the first message authentication code, the first freshness value, or the identification information corresponding to the third key. The method of any of claims 23-25, further comprising: sending a second service request to the first AIoT device, wherein the second service request is used for the first AIoT device to execute a second instruction. The second service request carries at least one of the following: the second instruction, a second message authentication code for verifying integrity of the second service request, a second freshness value, identification information corresponding to a fourth key, and second cipher text data, wherein the fourth key includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), or a group key of a group to which the first AIoT device belongs shared by the first AIoT device and the AF, or a second key used for protecting messages transmitted between the first AIoT device and the first network device. The method of claim 29, wherein, The second instruction includes at least one of the following: command content and second identification related information, wherein the command content includes at least one of the following: reading data, writing data, disabling, and enabling, and the second identification related information includes at least one of the following: an identifier of one or more AIoT devices, a related identifier of an AIoT device group, or an identifier of an area to which the one or more AIoT devices belong, the AIoT device group including the one or more AIoT devices, and the one or more AIoT devices including the first AIoT device. The method of claim 30, wherein, The method of claim 31, further comprising at least one of the following: ​ compute the second message authentication code based on the fourth key and at least one of the following: the command content, the second identity-related information, the second freshness value, the identification information corresponding to the fourth key, the second cipher-text data; compute the second cipher-text data based on the fourth key and at least one of the following: the command content, the second identity-related information, the second freshness value, the identification information corresponding to the fourth key, the second message authentication code. The method of any of claims 19-32, further comprising: obtaining a security parameter, wherein the security parameter comprises at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key. The method of any of claims 29-32, further comprising: receiving a second response message from the first AIoT device, wherein the second response message is used to indicate response content corresponding to the second instruction. The method of claim 34, wherein, The second response message carries at least one of the following: the response content corresponding to the second instruction, an identity of the first AIoT device, a third message authentication code used to verify integrity of the second response message, a third freshness value, third cipher-text data, and identification information corresponding to a fifth key, wherein the fifth key comprises one of the following: a second key used to protect messages transmitted between the first AIoT device and the first network device, and a sixth key used to protect messages transmitted between the first AIoT device and an application function (AF). The method of claim 35, further comprising: computing the third message authentication code based on the second key and at least one of the following: the identity of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the third cipher-text data, and the identification information corresponding to the fifth key; verifying integrity of the second response message based on the third message authentication code and the third message authentication code. The method of claim 35 or 36, further comprising: decrypting the third cipher-text data based on the second key to obtain at least one of the following: the identity of the first AIoT device, the response content corresponding to the second instruction, the third freshness value, the identification information corresponding to the second key, and the third message authentication code. The method of any of claims 35-37, further comprising one of the following: sending at least one of the following to an application function (AF): the identity of the first AIoT device, and the response content corresponding to the second instruction; sending the second response message to the application function (AF). A communication method performed by a second network device, comprising: receiving a second authentication request from a first network device, wherein the second authentication request is used to authenticate a first AIoT device. The method of claim 39, wherein, The second authentication request carries at least one of the following: a first authentication vector for authenticating the first AIoT device, a first random number, an authentication type, wherein the authentication type includes one of the following: one-way authentication, two-way authentication. The method of claim 40, further comprising: calculating a first verification vector based on the first key shared by the first AIoT device and the network and / or the first random number; authenticating the first AIoT device based on the first verification vector and the first authentication vector. The method of any one of claims 39-41, further comprising: sending a first authentication request to the first network device, wherein the first authentication request carries at least one of the following: a second authentication vector for authenticating the network, a second random number, the second authentication vector being calculated based on the first key shared by the first AIoT device and the network and / or the second random number. The method of any one of claims 39-42, further comprising: sending a second key to the first network device for protecting messages transmitted between the first AIoT device and the first network device. A communication method performed by a first AIoT device, comprising: receiving a third service request from a first network device, wherein the third service request is for the first AIoT device to determine an operation to perform, and the third service request is securely protected based on a security parameter. The security parameter includes at least one of the following: a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group in which the first AIoT device is located shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, and identification information corresponding to the group key. The method of claim 44, wherein, The third service request carries at least one of the following: instruction content indicating an inventory operation, command content indicating a command operation, identification-related information, a fourth message authentication code for verifying integrity of the third service request, a fourth freshness value, fourth cipher text data, and identification information corresponding to a seventh key, wherein the command content includes at least one of the following: reading data, writing data, disabling, and enabling, and the seventh key includes one of the following: the device key of the first AIoT device and the group key. The method of claim 45, wherein, The method of claim 46, further comprising: calculating a fourth message authentication code based on the seventh key and at least one of the following: the instruction content indicating the inventory operation, the command content, the identification-related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth cipher text data; verifying integrity of the third service request based on the fourth message authentication code and the fourth message authentication code. The method of claim 46 or 47, further comprising: ​ decrypt the fourth cipher-text data based on the seventh key to obtain at least one of the instruction content indicating the inventory operation, the command content, the identification related information, the fourth freshness value, identification information corresponding to the seventh key, or the fourth message authentication code. The method of any one of claims 46-48, wherein, The identification related information includes at least one of an identity of one or more AIoT devices, an identity of an AIoT device group, or information of an area where the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device. The method of any of claims 45-49, further comprising: sending, to the first network device, a third response message, wherein the third response message is used to indicate an execution result of the first AIoT device, and the third response message is secured based on the security parameter. The method of claim 50, wherein, The third response message carries at least one of the execution result of the first AIoT device, an identity of the first AIoT device, a fifth message authentication code used to verify integrity of the third response message, fifth cipher-text data, a fifth freshness value, or identification information corresponding to an eighth key, wherein the eighth key includes one of a device key of the first AIoT device or the group key. The method of claim 51, further comprising at least one of: calculating the fifth message authentication code based on the eighth key and at least one of the execution result of the first AIoT device, the identity of the first AIoT device, the fifth freshness value, the fifth cipher-text data, or the identification information corresponding to the eighth key; calculating the fifth cipher-text data based on the eighth key and at least one of the execution result of the first AIoT device, the identity of the first AIoT device, the fifth freshness value, the fifth message authentication code, or the identification information corresponding to the eighth key. A communication method performed by a first network device, comprising: sending, to a first AIoT device, a third service request, wherein the third service request is used for the first AIoT device to determine an operation to be executed, and the third service request is secured based on a security parameter. The method of claim 53, further comprising: obtaining a security parameter, wherein the security parameter includes at least one of a device key of the first AIoT device shared by the first AIoT device and an application function (AF), a group key of a group where the first AIoT device is located shared by the first AIoT device and the AF, identification information corresponding to the device key of the first AIoT device, or identification information corresponding to the group key. The method of claim 54, wherein, The third service request carries at least one of the following: instruction content indicating a check operation, command content indicating a command operation, identification related information, a fourth message authentication code for verifying integrity of the third service request, a fourth freshness value, identification information corresponding to a seventh key, and fourth cipher text data, wherein the command content includes at least one of the following: reading data, writing data, disabling, and enabling, and the seventh key includes one of the following: a device key of the first AIoT device and the group key. The method of claim 55, further comprising at least one of: calculating the fourth message authentication code based on the seventh key and at least one of the following: the instruction content indicating the check operation, the command content, the identification related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth cipher text data; calculating the fourth cipher text data based on the seventh key and at least one of the following: the instruction content indicating the check operation, the command content, the identification related information, the fourth freshness value, the identification information corresponding to the seventh key, and the fourth message authentication code. The method of claim 55 or 56, wherein, The identification related information includes at least one of the following: identification of one or more AIoT devices, related identification of an AIoT device group, and identification of an area where the one or more AIoT devices are located, wherein the AIoT device group includes the one or more AIoT devices, and the one or more AIoT devices include the first AIoT device. The method of any of claims 53-57, further comprising: receiving a third response message from the first AIoT device, wherein the third response message is used to indicate an execution result of the first AIoT device, and the third response message is securely protected based on the security parameter. The method of claim 58, wherein, The third response message carries at least one of the following: the execution result of the first AIoT device, identification of the first AIoT device, a fifth message authentication code for verifying integrity of the third response message, fifth cipher text data, a fifth freshness value, and identification information corresponding to an eighth key, wherein the eighth key includes one of the following: a device key of the first AIoT device and the group key. The method of claim 59, further comprising: calculating a fifth message authentication code based on the eighth key and at least one of the following: the execution result of the first AIoT device, the identification of the first AIoT device, the fifth freshness value, the fifth cipher text data, and the identification information corresponding to the eighth key; verifying integrity of the third response message based on the fifth message authentication code and the fifth message authentication code. The method of claim 59 or 60, further comprising: decrypting the fifth cipher text data based on the eighth key to obtain at least one of the following: the execution result of the first AIoT device, the identification of the first AIoT device, the fifth freshness value, the fifth message authentication code, and the identification information corresponding to the eighth key. A first AIoT device, comprising: The first communication unit is configured to receive a first service request from the first network device, wherein the first service request is used for the first AIoT device to execute a first instruction; and send a first response message to the first network device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device. A first network device comprises: The second communication unit is configured to send a first service request to the first AIoT device, wherein the first service request is used for the first AIoT device to execute a first instruction; and receive a first response message from the first AIoT device, wherein the first response message carries response content corresponding to the first instruction, and the first response message is used to trigger authentication of the first AIoT device. A second network device comprises: The third communication unit is configured to receive a second authentication request from the first network device, wherein the second authentication request is used to authenticate the first AIoT device. A first AIoT device comprises: The first communication unit is configured to receive a third service request from the first network device, wherein the third service request is used for the first AIoT device to determine an operation to be executed, and the third service request is securely protected based on a security parameter. A first network device comprises: The second communication unit is configured to send a third service request to the first AIoT device, wherein the third service request is used for the first AIoT device to determine an operation to be executed, and the third service request is securely protected based on a security parameter.

Citation Information

Patent Citations

  • Neural network model stealing defense method in AIoT scene

    CN110941855A

  • Data transmission method and device, communication equipment and communication system

    CN118283546A

  • Data transmission method, device, equipment, communication system and medium

    CN118283629A

  • Secure access for 5g IoT devices and services

    US20210368341A1