Information transmission method and apparatus, and storage medium
By using temporary device identifiers instead of device identifiers in the Ambient Internet of Things (AIoT), security issues during the interaction process are resolved, and the security of the interaction process is improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-23
- Publication Date
- 2026-04-02
AI Technical Summary
In the Ambient Internet of Things (AIoT), how can we ensure the security of interactive content during the interaction process and prevent other devices from knowing the specific business execution target?
Temporary device identifiers are used instead of device identifiers. By generating temporary device identifiers based on security keys and one-time values, security during the interaction process is ensured.
This improves the security of the interaction process and prevents other devices from knowing the specific business execution target.
Smart Images

Figure CN2025123431_02042026_PF_FP_ABST
Abstract
Description
Information transmission method and device and storage medium
[0001] The present disclosure claims priority to a Chinese patent application No. 202411387063.7, filed on September 30, 2024, and entitled "Information transmission method and device and storage medium", the entire content of which is incorporated herein by reference. TECHNICAL FIELD
[0002] The present disclosure relates to the field of communication technology, and in particular to an information transmission method, device and storage medium. BACKGROUND
[0003] The ambient internet of things (AIoT) project will study the use of 3rd generation partnership project (3GPP) technology to read passive tags applied to the Internet of Things. The basic idea is to modify the base station and the passive tag, so that the base station can read the data of the modified passive tag and provide the data to the application party.
[0004] For the above process, how to ensure the security of the interaction content in the interaction process is a technical problem to be solved. SUMMARY
[0005] The present disclosure provides an information transmission method, device and storage medium, which ensures the security of the interaction content in the interaction process.
[0006] In a first aspect, an embodiment of the present disclosure provides an information transmission method applied to an AIoT device, the method comprising:
[0007] receiving a first service request message sent by a management entity, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0008] sending a first service response message to the management entity, the first service response message comprising a first device temporary identifier and a device-side one-time value;
[0009] The first device temporary identifier is generated based on a security key, a device identifier of the AIoT device and a first one-time value, the security key is a key related to the service execution object, and the first one-time value comprises the network-side one-time value and / or the device-side one-time value.
[0010] In an implementation manner, the first service response message further comprises a security key identifier.
[0011] and / or;
[0012] The first device temporary identifier is generated based on a security key, a device identifier, and a first nonce, and includes:
[0013] The first device temporary identifier obtained by encrypting the device identifier using the security key and the first nonce.
[0014] In an implementation, the first information includes a service execution object temporary identifier, and the service execution object temporary identifier includes a second device temporary identifier or a device group temporary identifier; wherein,
[0015] The service execution object temporary identifier is generated based on the security key, a service execution object identifier, and the network-side nonce, and the service execution object identifier includes the device identifier or a device group identifier.
[0016] In an implementation, in a case where the service is an instruction, the service execution object temporary identifier is the service execution object identifier, and / or the first device temporary identifier is the device identifier.
[0017] In an implementation, the method further includes:
[0018] receiving configuration information, and the configuration information includes the security key.
[0019] In an implementation, the configuration information further includes a service execution object identifier or a security key identifier, and the service execution object identifier includes a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0020] In a second aspect, an information transmission method is provided, and the method is applied to a management entity and includes:
[0021] sending a first service request message, and the first service request message includes first information and a network-side nonce, and the first information is used to indicate a service execution object;
[0022] receiving a first service response message sent by an environment Internet of Things (AIoT) device, and the first service response message includes a first device temporary identifier and a device-side nonce;
[0023] The first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first nonce, the security key is a key related to a service execution object, and the first nonce includes the network-side nonce and / or the device-side nonce.
[0024] In a third aspect, the embodiments of the present disclosure provide an information transmission method, applied to a subscription or security entity, the method comprising:
[0025] receiving a verification request message sent by a management entity, the verification request message comprising a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier of an AIoT device, and a first one-time value, the security key being a key related to a service execution object, and the first one-time value comprising a network-side one-time value and / or the device-side one-time value;
[0026] sending a verification response message to the management entity, the verification response message comprising a verification result.
[0027] In a fourth aspect, the embodiments of the present disclosure provide an information transmission apparatus, applied to an AIoT device, the apparatus comprising:
[0028] a receiving unit, configured to receive a first service request message sent by a management entity, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0029] a sending unit, configured to send a first service response message to the management entity, the first service response message comprising a first device temporary identifier and a device-side one-time value;
[0030] wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to the service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value.
[0031] In a fifth aspect, the embodiments of the present disclosure provide an information transmission apparatus, applied to a management entity, the apparatus comprising:
[0032] a sending unit, configured to send a first service request message, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0033] a receiving unit, configured to receive a first service response message sent by an environment Internet of Things (AIoT) device, the first service response message comprising a first device temporary identifier and a device-side one-time value;
[0034] wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to the service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value.
[0035] In a sixth aspect, an information transmission apparatus is provided, which is applied to a subscription or security entity, and includes:
[0036] a receiving unit configured to receive a verification request message sent by a management entity, the verification request message including a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier of an AIoT device, and a first one-time value, the security key being a key related to a service execution object, and the first one-time value including a network-side one-time value and / or the device-side one-time value;
[0037] a sending unit configured to send a verification response message to the management entity, the verification response message including a verification result.
[0038] In a seventh aspect, an information transmission apparatus is provided, which is applied to an AIoT device, and includes a memory, a transceiver, and a processor,
[0039] the memory is configured to store a computer program, the transceiver is configured to transceive data under control of the processor, and the processor is configured to read the computer program in the memory and perform the following operations:
[0040] receive a first service request message sent by a management entity, the first service request message including first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0041] send a first service response message to the management entity, the first service response message including a first device temporary identifier and a device-side one-time value;
[0042] wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to the service execution object, and the first one-time value including the network-side one-time value and / or the device-side one-time value.
[0043] In an implementation, the first service response message further includes a security key identifier;
[0044] and / or;
[0045] the processor is configured to perform the following operations:
[0046] the first device temporary identifier is obtained by encrypting the device identifier using the security key and the first one-time value.
[0047] In an implementation, the first information comprises a service execution object temporary identifier, the service execution object temporary identifier comprises a second device temporary identifier or a device group temporary identifier; wherein,
[0048] The service execution object temporary identifier is generated based on the security key, a service execution object identifier and the network-side one-time value, the service execution object identifier comprises the device identifier or the device group identifier.
[0049] In an implementation, in a case where the service is an instruction, the service execution object temporary identifier is the service execution object identifier, and / or the first device temporary identifier is the device identifier.
[0050] In an implementation, the processor is further configured to perform the following operations:
[0051] receiving configuration information, the configuration information comprising the security key.
[0052] In an implementation, the configuration information further comprises a service execution object identifier or a security key identifier, the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0053] In an implementation, the processor is further configured to perform the following operations:
[0054] The memory is configured to store a computer program; the transceiver is configured to transceive data under control of the processor; and the processor is configured to read the computer program in the memory and perform the following operations:
[0055] sending a first service request message, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0056] receiving a first service response message sent by an ambient Internet of Things (AIoT) device, the first service response message comprising a first device temporary identifier and a device-side one-time value;
[0057] The first device temporary identifier is generated based on a security key, a device identifier of the AIoT device and a first one-time value, the security key being a key related to a service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value.
[0058] In an implementation, the processor is further configured to perform the following operations:
[0059] the memory, configured to store a computer program; the transceiver, configured to transceive data under control of the processor; and the processor, configured to read the computer program in the memory and perform the following operations:
[0060] receive a verification request message sent by a management entity, the verification request message comprising a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier of an AIoT device and a first one-time value, the security key being a key related to a service execution object, and the first one-time value comprising a network-side one-time value and / or the device-side one-time value;
[0061] send a verification response message to the management entity, the verification response message comprising a verification result.
[0062] In a tenth aspect, an embodiment of the present disclosure provides a non-transitory readable storage medium, which stores a computer program, the computer program being configured to cause a processor to execute the method in the first aspect.
[0063] In an eleventh aspect, an embodiment of the present disclosure provides a non-transitory readable storage medium, which stores a computer program, the computer program being configured to cause a processor to execute the method in the second aspect.
[0064] In a twelfth aspect, an embodiment of the present disclosure provides a non-transitory readable storage medium, which stores a computer program, the computer program being configured to cause a processor to execute the method in the third aspect.
[0065] In a thirteenth aspect, an embodiment of the present disclosure provides a communication device, which stores a computer program, the computer program being configured to cause a processor to execute the method in the first aspect.
[0066] In a fourteenth aspect, an embodiment of the present disclosure provides a communication device, which stores a computer program, the computer program being configured to cause a processor to execute the method in the second aspect.
[0067] In a fifteenth aspect, an embodiment of the present disclosure provides a communication device, which stores a computer program, the computer program being configured to cause a processor to execute the method in the third aspect.
[0068] The embodiment of the present disclosure provides an information transmission method, device and storage medium. In the method, a management entity sends a first service request message, the first service request message comprising first information and a network-side one-time value, the first information being used for indicating a service execution object; a first service response message sent by an AIoT device is received, the first service response message comprising a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier and the first one-time value, the security key being a key related to the service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value. In the process of AIoT device interaction, the device temporary identifier is used to replace the device identifier, so as to avoid that other devices know the service execution object, and the security of the interaction process is improved.
[0069] It should be understood that the content described in the foregoing summary part is not intended to define the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0070] In order to more clearly illustrate the technical solutions in the present disclosure or the related art, the following will briefly introduce the drawings needed to be used in the embodiments or the related art description. Obviously, the drawings in the following description are some embodiments of the present disclosure, and other drawings can also be obtained by those skilled in the art without creative labor.
[0071] Fig. 1 is a schematic diagram of the architecture of a complete version of a cellular passive network in the related art;
[0072] Fig. 2 is a schematic diagram of the architecture of a simplified version of a cellular passive network in the related art;
[0073] Fig. 3 is a schematic diagram of a topology architecture of an AIoT system in the related art;
[0074] Fig. 4 is a schematic diagram of another topology architecture of an AIoT system in the related art;
[0075] Fig. 5 is a schematic diagram of an architecture of an AIoT system provided by an embodiment of the present disclosure;
[0076] Fig. 6 is a flowchart of an information transmission method provided by an embodiment of the present disclosure;
[0077] Fig. 7 is a flowchart of an information transmission method provided by an embodiment of the present disclosure;
[0078] Fig. 8 is a flowchart of an information transmission method provided by an embodiment of the present disclosure;
[0079] Fig. 9 is a flowchart of an information transmission method provided by an embodiment of the present disclosure;
[0080] FIG. 10 is a flowchart V of the information transmission method according to an embodiment of the present disclosure;
[0081] FIG. 11 is a flowchart VI of the information transmission method according to an embodiment of the present disclosure;
[0082] FIG. 12 is a flowchart VII of the information transmission method according to an embodiment of the present disclosure;
[0083] FIG. 13 is a flowchart VIII of the information transmission method according to an embodiment of the present disclosure;
[0084] FIG. 14 is a flowchart IX of the information transmission method according to an embodiment of the present disclosure;
[0085] FIG. 15 is a flowchart X of the information transmission method according to an embodiment of the present disclosure;
[0086] FIG. 16 is a flowchart XI of the information transmission method according to an embodiment of the present disclosure;
[0087] FIG. 17 is a flowchart XII of the information transmission method according to an embodiment of the present disclosure;
[0088] FIG. 18 is a flowchart XIII of the information transmission method according to an embodiment of the present disclosure;
[0089] FIG. 19 is a flowchart XIV of the information transmission method according to an embodiment of the present disclosure;
[0090] FIG. 20 is a schematic structural diagram of an information transmission apparatus 10 according to an embodiment of the present disclosure;
[0091] FIG. 21 is a schematic structural diagram of an information transmission apparatus 20 according to an embodiment of the present disclosure;
[0092] FIG. 22 is a schematic structural diagram of an information transmission apparatus 30 according to an embodiment of the present disclosure;
[0093] FIG. 23 is a schematic structural diagram of an information transmission apparatus 40 according to an embodiment of the present disclosure;
[0094] FIG. 24 is a schematic structural diagram of an information transmission apparatus 50 according to an embodiment of the present disclosure;
[0095] FIG. 25 is a schematic structural diagram of an information transmission apparatus 60 according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0096] The term "and / or" in the embodiments of the present disclosure describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after it. The term "at least one" in the embodiments of the present disclosure means one or more, "more" means two or more, and other quantifiers are similar.
[0097] The terms "first", "second", and the like in the embodiments of the present disclosure are only used for description and distinction of the described objects, and do not have order difference, nor represent special limitation of the number of objects in the embodiments of the present disclosure, and cannot constitute any limitation on the embodiments of the present disclosure. For example, the description of "first device temporary identifier" and "second device temporary identifier" is only used to distinguish different device temporary identifiers, and does not represent the difference in size, priority or importance of the two device temporary identifiers.
[0098] In order to clearly describe the technical solutions of the embodiments of the present disclosure, the following briefly introduces the related technologies involved in the present disclosure:
[0099] Currently, two potential cellular passive network architectures based on 3GPP technology are proposed: one is a complete network architecture, that is, based on core network elements, to authenticate, authenticate, and manage the mobility of tags; the other is a simplified network architecture, that is, to sink the core network part of the capability to the proxy node to complete the basic process of local tag identification.
[0100] Among them, the complete version of the network architecture inherits part of the core network elements, as shown in FIG. 1. The user instruction is initiated by the passive Internet of Things server, and after passing through the core network, it is issued to the radio access network (RAN) equipment. The RAN equipment performs inventory and access control operations, and the obtained inventory information, tag data, etc. are handed over to the core network, and through the data opening network element, the reporting to the user platform is completed. Such a network architecture can complete the mobility management of the tag based on the core network elements (such as: access and mobility management function (AMF), unified data management (UDM), session management function (SMF), etc.), and can realize the whole process tracking of the passive tag, and can be applied to scenes such as transportation, logistics, animal husbandry, etc. At the same time, the core network can realize authentication, authorization, charging, encryption, management and control, policy control, etc. The inventory, reading and writing of the tag can be provided by the Internet of Things server or the core network. Such an architecture involves the core network, and the functions are complete, and can realize "whole process and whole network". Since the interaction scene of the passive Internet of Things scene is relatively simple, subsequent optimization of the existing non-access stratum (NAS) layer protocol can be further considered to simplify the tag and core network interaction process.
[0101] The simplified network architecture is a new type of network architecture in which the routing function of the core network is sunk to the edge proxy node in consideration of the lightweight demand of the passive application, and the user instruction is obtained through the interaction between the proxy node and the user application server, so as to schedule the RAN device to complete the inventory and access control and other operations, and forward the tag data reported by the RAN device to the server, as shown in FIG. 2. The proxy node in the figure can also be a small-sized core network sunk to meet the user's demand for cellular communication access of various systems including passive Internet of Things. In this link, the proxy node and the RAN device are bound and belong to localized deployment, so it is suitable for localized applications such as warehouse, home and factory. In addition to the routing function, the proxy node also needs to support the function of middleware to realize the scheduling control of the access network device and the preliminary processing of data. Under this architecture, the authentication, authorization and mobility management of the tag are completed by the user platform side. Due to localized communication, the tag only needs to support the radio resource control (RRC) - media access control (MAC) - physical layer (PHY) three-layer protocol, the function is relatively simple, the power consumption is also relatively low, but the implementation difficulty of charging, encryption, management and control, policy control and other operations is high, and the detailed scheme still needs further research.
[0102] At present, 3GPP AIoT will support two topologies:
[0103] Topology 1, the typical architecture is shown in FIG. 3, including UDM, authentication server function (AUSF), network exposure function (NEF), application function (AF), charging service function (CHF), AMF, environment Internet of Things management function (AIoTMF), RAN device, AIoT device, wherein the RAN device is an AIoT reader.
[0104] Topology 2, the typical architecture is shown in FIG. 4, including UDM, AUSF, NEF, network repository function (NRF), AMF, CHF, AF / application server (AS), user equipment (UE), AIoT device, wherein the UE is an AIoT reader.
[0105] In order to better understand the method provided by the embodiments of the present disclosure, the application scenarios of the embodiments of the present disclosure are first described below.
[0106] FIG. 5 is a schematic diagram of an architecture of an AIoT system provided by the embodiments of the present disclosure, as shown in FIG. 5, which includes an AIoT device, an operating entity, a management entity, a subscription / security entity, and an application system.
[0107] The AIoT device is a device defined by 3GPP, which does not have or only has limited energy storage capability, and can obtain energy by means of wind, light, pressure, wireless signals, etc. in the environment, and has the characteristics of low power consumption, low cost and low complexity. The AIoT device can also be referred to as a passive tag.
[0108] The operating entity is used to discover and perform interactive operations with the tag, and can also be referred to as an AIoT reader. For example, the operating entity can be a base station or a UE, etc.
[0109] The management entity provides communication between the tag and the 3GPP network, and can interact with the application system through the external service interface of the 3GPP system. For example, the management entity can be an AMF or an independent AIoT function (AIoTF). It should be noted that the AIoTF is the same as the AIoTMF in FIG. 3, and the AIoTF and the AIoTMF are only different names of the same device.
[0110] The subscription / security entity is responsible for managing the subscription information of the tag and performing key-related operations. For example, the subscription / security entity can be a UDM.
[0111] The application system is an application system using the AIoT tag defined by 3GPP, which is located outside the 3GPP system. For example, the application system can be an AF / AS.
[0112] It should be noted that the architecture of the AIoT system and the number of devices in the architecture described above are only examples, and the present disclosure does not limit the architecture of the AIoT system and the number of devices in the architecture.
[0113] At present, the basic services for the AIoT device include:
[0114] (1) Inventory: inventory the AIoT device to determine which AIoT devices exist. In the embodiments of the present disclosure, inventory can also be referred to as inventory.
[0115] (2) Command: read and write operations on the AIoT device.
[0116] To solve the problems in the background art, the present disclosure provides an information transmission method and device and a storage medium, which use a device temporary identifier to replace a device identifier in the process of AIoT device interaction, avoid other devices from knowing specific business execution objects, and improve the security of the interaction process. The method and device are based on the same application concept. Since the principles of the method and device for solving problems are similar, the implementation of the device and the method can be mutually referred to, and the repeated parts will not be described again.
[0117] The technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, and not all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present disclosure.
[0118] FIG. 6 is a flowchart of an information transmission method according to an embodiment of the present disclosure. As shown in FIG. 6, the method includes the following steps.
[0119] S601, the management entity sends a first business request message to the AIoT device, the first business request message including first information and a network-side one-time value, the first information being used to indicate a business execution object.
[0120] In other words, the AIoT device receives the first business request message sent by the management entity.
[0121] All AIoT devices within the communication range of the management entity can receive the first business request message sent by the management entity.
[0122] The first business request message can be a device inventory request message or a device instruction request message.
[0123] The business execution object indicated by the first information can be a single AIoT device, a group of AIoT devices, or all AIoT devices. The first information itself can be used to indicate the business execution object; or an indication information (which can be referred to as device indication information or other names) can be carried in the first information to indicate the business execution object.
[0124] In a possible implementation, the first information can include a business execution object temporary identifier.
[0125] The business execution object temporary identifier can be generated based on a security key, a business execution object identifier, and a network-side one-time value.
[0126] In a case where the service execution object identifier is a device identifier (hereinafter referred to as a device identifier) of an AIoT device, the service execution object temporary identifier is a second device temporary identifier; in a case where the service execution object identifier is a device group identifier (hereinafter referred to as a device group identifier) of a group to which the AIoT device belongs, the service execution object temporary identifier is a device group temporary identifier.
[0127] The security key is a key related to the service execution object. For example, in a case where the first service request message is a device inventory request message and the service execution object is a single AIoT device, the security key can be a key used for device authentication, for example, the security key can be referred to as a device authentication key. In a case where the first service request message is a device inventory request message and the service execution object is a group of AIoT devices, the security key can be a device group security key. In a case where the first service request message is a device inventory request message and the service execution object is all AIoT devices, the security key can be an anonymous group key. In a case where the first service request message is a device instruction request message and the service execution object is a single AIoT device, the security key can be a key used for protecting an instruction, for example, the security key can be referred to as a device instruction key. In a case where the first service request message is a device instruction request message and the service execution object is a group of AIoT devices, the security key can be a key used for protecting a group instruction, for example, the security key can be referred to as a group instruction key. The present disclosure does not limit the name of the security key as long as the function is the same as the security key of the present disclosure.
[0128] The network-side one-time value can refer to a value generated by the network side and used only for one service. The network-side one-time value can also be referred to as a random number or a network-side random number. For example, the network-side one-time value can be a one-time value generated by a subscription / security entity or a one-time value generated by a management entity.
[0129] The management entity can generate the service execution object temporary identifier by itself before sending the first service request message. For example, the management entity can first generate a network-side one-time value, and then generate the service execution object temporary identifier using the network-side one-time value, the security key, and the service execution object identifier. The management entity can also receive the service execution object temporary identifier and the network-side one-time value from other devices (for example, a subscription / security entity).
[0130] The management entity can send the first service request message to the AIoT device after receiving the service request message sent by the application system.
[0131] In a possible implementation, the service execution object temporary identifier can be a service execution object identifier, i.e., the first information includes only the service execution object identifier, and does not include the service execution object temporary identifier. For example, in the case where the service requested by the first service request message is inventory or instruction, the first information can include only the device identifier, and does not include the second device temporary identifier, or the first information can include only the device group identifier, and does not include the device group temporary identifier.
[0132] S602. The AIoT device sends a first service response message to the management entity, the first service response message including the first device temporary identifier and the device-side one-time value, the first device temporary identifier being generated based on the security key, the device identifier, and the first one-time value, and the first one-time value including the network-side one-time value and / or the device-side one-time value.
[0133] In other words, the management entity receives the first service response message sent by the AIoT device.
[0134] The device-side one-time value is a value generated by the AIoT device and used only for one service. The device-side one-time value can also be referred to as a random number or a device-side random number.
[0135] If the service execution object indicated by the first information in the first service request message is all AIoT devices, the first service response message can also carry a security key identifier.
[0136] Before sending the first service response message, the AIoT device generates the device-side one-time value, generates the first device temporary identifier by using the security key, the device identifier, and the first one-time value, and then sends the first service response message.
[0137] In a possible implementation, the AIoT device can encrypt the device identifier by using the security key and the first one-time value to obtain the first device temporary identifier. The AIoT device can also use the security key, the device identifier, and the first one-time value to obtain the first device temporary identifier by using a hash algorithm.
[0138] If the service execution object indicated by the first information in the first service request message is a single AIoT device, all AIoT devices receiving the first service request message need to determine whether the service execution object indicated by the first information is itself, and if so, can generate a device-side one-time value and a first device temporary identifier and send the first service response message to the management entity. If the service execution object indicated by the first information in the first service request message is an AIoT device group, all AIoT devices receiving the first service request message need to determine whether they belong to the AIoT device group indicated by the first information, and if so, can generate a device-side one-time value and a first device temporary identifier and send the first service response message to the management entity. If the service execution object indicated by the first information in the first service request message is all AIoT devices, all AIoT devices receiving the first service request message can generate a device-side one-time value and a first device temporary identifier and send the first service response message to the management entity.
[0139] In a possible implementation, in the case where the service requested by the first service request message is an instruction, the first device temporary identifier can be a device identifier, that is, the first service response message includes the device identifier and the device-side one-time value.
[0140] In the embodiment shown in FIG. 6, the AIoT device uses the first device temporary identifier instead of the device identifier when sending the first service response message, so as to avoid other devices from knowing the specific service execution object, thereby improving the security of the interaction process.
[0141] FIG. 7 is a flowchart of another information transmission method provided by an embodiment of the present disclosure. As shown in FIG. 7, the method includes the following steps.
[0142] S701, the subscription / security entity sends configuration information to the AIoT device, and the configuration information includes a security key.
[0143] In other words, the AIoT device receives the configuration information sent by the subscription / security entity.
[0144] It should be noted that the related description of the security key can be referred to the corresponding description in S601, which will not be repeated here.
[0145] In a possible implementation, the configuration information can further include a service execution object identifier or a security key identifier.
[0146] In the case where the security key is related to a single AIoT device or an AIoT device group, the configuration information can include the security key and the service execution object identifier; in the case where the security key is related to all AIoT devices, the configuration information can include the security key and the security key identifier.
[0147] S702, the management entity sends a first service request message to the AIoT device, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object.
[0148] S703, the AIoT device sends a first service response message to the management entity, the first service response message comprising a first device temporary identifier and a device-side one-time value.
[0149] It should be noted that the execution process of S702 to S703 can refer to the execution process of S601 to S602, which will not be described here.
[0150] The only thing to be explained is that when the first information comprises a service execution object temporary identifier, the AIoT device needs to use the service execution object identifier, the security key and the network-side one-time value to generate a service execution object temporary identifier' in the same way as the network side, and if the service execution object temporary identifier' is the same as the service execution object temporary identifier in the first information, it is determined that the current service is for the AIoT device, and the AIoT device can send the first service response message to the management entity.
[0151] The beneficial effects of the embodiment shown in FIG. 7 are the same as those of the embodiment shown in FIG. 6, which will not be described here.
[0152] In order to facilitate understanding, in the following, the technical solutions of the present disclosure will be described in combination with FIG. 8 and FIG. 9.
[0153] FIG. 8 is a flowchart III of the information transmission method provided by the embodiment of the present disclosure. As shown in FIG. 8, the method comprises:
[0154] S801, the subscription / security entity sends configuration information to the AIoT device, the configuration information comprising a security key and a service execution object identifier.
[0155] S802, the management entity sends a first service request message to the AIoT device, the first service request message comprising first information and a network-side one-time value, the first information comprising a service execution object temporary identifier, and the first information indicating that the service execution object is a single AIoT device or a group of AIoT devices.
[0156] S803, the AIoT device sends a first service response message to the management entity, the first service response message comprising a first device temporary identifier and a device-side one-time value.
[0157] It should be noted that S801 to S803 can refer to the corresponding description in the foregoing embodiments, which will not be described here.
[0158] FIG. 9 is a flowchart IV of the information transmission method provided by the embodiment of the present disclosure. As shown in FIG. 9, the method comprises:
[0159] S901, the subscription / security entity sends configuration information to the AIoT device, the configuration information including a security key and a security key identifier.
[0160] S902, the management entity sends a first service request message to the AIoT device, the first service request message including first information and a network-side one-time value, the first information indicating that a service execution object is all AIoT devices.
[0161] S903, the AIoT device sends a first service response message to the management entity, the first service response message including the security key identifier, a first device temporary identifier, and a device-side one-time value.
[0162] It should be noted that S901 to S903 can refer to the corresponding description in the foregoing embodiments, and will not be described here again.
[0163] It should be noted that in the embodiments shown in FIG. 7 to the embodiments shown in FIG. 9, the operations performed by the subscription / security entity can also be performed by the management entity. That is, the management entity can send the configuration information to the AIoT device, and the AIoT device receives the configuration information sent by the management entity.
[0164] FIG. 10 is a flowchart of a method for transmitting information according to an embodiment of the present disclosure. As shown in FIG. 10, the method includes the following steps:
[0165] S1001, the management entity sends a verification request message to the subscription / security entity, the verification request message including a first device temporary identifier and a device-side one-time value.
[0166] In other words, the subscription / security entity receives the verification request message sent by the management entity.
[0167] The related description of the first device temporary identifier and the device-side one-time value can be referred to the corresponding content in S602, and will not be described here again.
[0168] When the service is inventory, the verification request message can be a device identifier authentication request message; when the service is an instruction, the verification request message can be an instruction verification request message.
[0169] When the service execution object is all AIoT devices, the verification request message can further include a security key identifier.
[0170] After receiving the verification request message, the subscription / security entity performs verification. If the verification is passed, S1002 can be performed, and if the verification is not passed, the flow is terminated.
[0171] In a possible implementation, in a case where the service for which the verification request message requests verification is an instruction, the first device temporary identifier can be a device identifier, that is, the verification request message request includes the device identifier and the device-side one-time value.
[0172] S1002, the subscription / or security entity sends a verification response message to the management entity, and the verification response message includes a verification result.
[0173] In other words, the management entity receives the verification response message sent by the subscription / or security entity.
[0174] When the service is inventory, the verification result can be a device identifier; when the service is an instruction, the verification result can be a payload carried by the AIoT device.
[0175] In the embodiment shown in FIG. 10, the management entity uses the first device temporary identifier instead of the device identifier in the process of interacting with the subscription / security entity, so as to avoid other devices from knowing the specific service execution object, and improve the security of the interaction process.
[0176] It should be noted that the embodiment shown in FIG. 10 can be combined with any one of the embodiments shown in FIGS. 6 to 9. Next, an example of combination is given in combination with FIG. 11.
[0177] FIG. 11 is a flowchart of a method for information transmission provided in an embodiment of the present disclosure. As shown in FIG. 10, the method includes the following steps.
[0178] S1101, the management entity sends a first service request message to the AIoT device, and the first service request message includes first information and a network-side one-time value, and the first information is used to indicate a service execution object.
[0179] S1102, the AIoT device sends a first service response message to the management entity, and the first service response message includes a first device temporary identifier and a device-side one-time value.
[0180] It should be noted that the execution process of S1101 to S1102 can refer to the execution process of S601 to S602, which will not be described here.
[0181] S1103, the management entity sends a verification request message to the subscription / security entity, and the verification request message includes the first device temporary identifier and the device-side one-time value.
[0182] S1104, the subscription / or security entity sends a verification response message to the management entity, and the verification response message includes a verification result.
[0183] It should be noted that the execution process of S1103 to S1104 can refer to the execution process of S1001 to S1002, which will not be repeated here. The only thing to note is that if the business execution object is a single AIoT device, the subscription / or security entity can generate a third device temporary identifier using the same method as the AIoT device side after receiving the verification request message using the security key, the device identifier, and the first one-time value. If the third device temporary identifier is the same as the first device temporary identifier, the subscription / or security entity can send a verification response message to the management entity. If the business execution object is a group of AIoT devices or all AIoT devices, the subscription / or security entity can decrypt the first device temporary identifier using the security key and the first one-time value after receiving the verification request message. If the device identifier can be decrypted and the AIoT device indicated by the device identifier belongs to the group of AIoT devices or all AIoT devices, the subscription / or security entity can send a verification response message to the management entity.
[0184] FIG. 12 is a flowchart of a method of information transmission according to an embodiment of the present disclosure. As shown in FIG. 12, the method includes the following steps.
[0185] S1201, the management entity sends an authorization request message to the subscription / or security entity, and the authorization request message includes an AF identifier and second information, and the second information indicates a business execution object.
[0186] In other words, the subscription / or security entity receives the authorization request message sent by the management entity.
[0187] When the business is inventory, the authorization request message can be an inventory authorization request message; when the business is an instruction, the authorization request message can be an instruction authorization request message.
[0188] In one possible implementation, the second information can include a business execution object identifier or indication information, and the indication information indicates that the business execution object is all AIoT devices.
[0189] It should be noted that the second information and the indication information can not be a containing relationship, and the second information can directly indicate the indication information or the second information is the indication information itself.
[0190] After receiving the authorization request message, the subscription / or security entity can check whether the AF corresponding to the AF identifier can perform the corresponding operation according to the AF identifier and the second information. If so, the subscription / or security entity can send an authorization response message to the management entity.
[0191] The management entity can send the authorization request message to the subscription / or security entity after receiving the business request message sent by the AF.
[0192] S1202, the subscription / or security entity sends an authorization response message to the management entity, and the authorization response message includes the network-side one-time value.
[0193] In other words, the management entity receives the authorization response message sent by the subscription / or security entity
[0194] If the service execution object is a single AIoT device or an AIoT device group, the subscription / or security entity can generate the network-side one-time value and send the authorization response message to the management entity after determining that the AF can perform the corresponding operation.
[0195] In the case where the second information includes the service execution object identifier, the authorization response message further includes the service execution object temporary identifier. That is, if the service execution object is a single AIoT device or an AIoT device group, the subscription / or security entity can generate the network-side one-time value, generate the service execution object temporary identifier by using the security key, the service execution object identifier, and the network-side one-time value, and send the authorization response message to the management entity after determining that the AF can perform the corresponding operation.
[0196] In a possible implementation, the service execution object temporary identifier can be the service execution object identifier. For example, in the case where the service is inventory or instruction, the service execution object identifier can be included in the authorization response message, and the service execution object temporary identifier can not be included in the authorization response message, that is, the device identifier can be included in the authorization response message, and the second device temporary identifier can not be included in the authorization response message, or the device group identifier can be included in the authorization response message, and the device group temporary identifier can not be included in the authorization response message.
[0197] In the embodiment shown in FIG. 12, the service execution object temporary identifier can be generated by the subscription / or security entity to replace the service execution object identifier in the interaction process between the management entity and the AIoT device, so as to avoid other devices from knowing the specific service execution object, and improve the security of the interaction process.
[0198] It should be noted that the embodiment shown in FIG. 12 can be combined with any one of the embodiments shown in FIGS. 6 to 9. Hereinafter, an example of the combination is given in combination with FIGS. 13 and 14.
[0199] FIG. 13 is a flowchart of an information transmission method provided by an embodiment of the present disclosure. As shown in FIG. 13, the method includes the following steps.
[0200] S1301, the management entity sends an authorization request message to the subscription / or security entity, and the authorization request message includes the AF identifier and the service execution object identifier.
[0201] S1302, the subscription / or security entity sends an authorization response message to the management entity, and the authorization response message includes the network-side one-time value and the service execution object temporary identifier.
[0202] S1303, the management entity sends a first service request message to the AIoT device, the first service request message comprising the first information and the network-side one-time value, the first information comprising a service execution object temporary identifier, and the first information indicating that the service execution object is a single AIoT device or an AIoT device group.
[0203] S1304, the AIoT device sends a first service response message to the management entity, the first service response message comprising the first device temporary identifier and the device-side one-time value.
[0204] It should be noted that S1301 to S1304 can refer to the corresponding description in the foregoing embodiments, and will not be described here again.
[0205] FIG. 14 is a flowchart IX of an information transmission method according to an embodiment of the present disclosure. As shown in FIG. 14, the method comprises the following steps:
[0206] S1401, the management entity sends an authorization request message to a subscription entity or a security entity, the authorization request message comprising an AF identifier and indication information, and the indication information indicating that the service execution object is all AIoT devices.
[0207] S1402, the subscription entity or the security entity sends an authorization response message to the management entity, the authorization response message comprising the network-side one-time value.
[0208] S1403, the management entity sends a first service request message to the AIoT device, the first service request message comprising the first information and the network-side one-time value, and the first information indicating that the service execution object is all AIoT devices.
[0209] S1404, the AIoT device sends a first service response message to the management entity, the first service response message comprising a security key identifier, the first device temporary identifier and the device-side one-time value.
[0210] It should be noted that S1401 to S1404 can refer to the corresponding description in the foregoing embodiments, and will not be described here again.
[0211] It should be noted that any one of the embodiments shown in FIG. 6 to the embodiments shown in FIG. 9 can be combined with the embodiment shown in FIG. 10 and the embodiment shown in FIG. 12.
[0212] For ease of understanding, the following takes the management entity as an AIoT F and the application system as an AF as an example to illustrate the scheme of the present disclosure.
[0213] Example 1, inventory for a single device
[0214] FIG. 15 is a flowchart X of an information transmission method according to an embodiment of the present disclosure. As shown in FIG. 15, the method comprises the following steps:
[0215] S1501, the subscription / security entity configures a device identifier and a device authentication key (i.e., a security key) for the AIoT device.
[0216] S1502, the AF sends an inventory request message to the AIoT F, the inventory request message containing the device identifier.
[0217] S1503, the AIoT F sends an inventory authorization request message to the subscription / security entity, the inventory authorization request message containing the AF identifier and the device identifier.
[0218] S1504, the subscription / security entity checks whether the AF can perform the operation according to the AF identifier and the device identifier. If allowed, a network-side nonce is generated; a second device temporary identifier is generated using the device authentication key (i.e., the security key) of the AIoT device, the device identifier, and the network-side nonce; and the second device temporary identifier and the network-side nonce are returned to the AIoT F.
[0219] S1505, the AIoT F sends a device inventory request message (i.e., a first service request message) to the AIoT device, the device inventory request message containing device indication information, the second device temporary identifier, and the network-side nonce. The device indication information indicates that the current service is for a single device.
[0220] S1506, the AIoT device uses its device authentication key (i.e., the security key), the device identifier, and the network-side nonce to calculate a device temporary identifier' in the same way as the network side. If the device temporary identifier' is the same as the second device temporary identifier, the device determines that the current service is an inventory for it. The device continues to generate a device-side nonce; generates a first device temporary identifier using the device authentication key (i.e., the security key) of the device, the device identifier, and a first nonce, the first nonce including the network-side nonce and / or the device-side nonce; and returns the first device temporary identifier and the device-side nonce to the AIoT F.
[0221] S1507, the AIoT F sends a device identifier authentication request message to the subscription / security entity, the device identifier authentication request message containing the first device temporary identifier and the device-side nonce.
[0222] S1508, the subscription / security entity generates a third device temporary identifier using the same method and parameters as the AIoT device. If the third device temporary identifier is the same as the first device temporary identifier, it is determined to be a response of the target AIoT device. The subscription / security entity returns the device identifier authentication result to the AIoT F.
[0223] S1509, the AIoT F returns the device inventory result to the AF.
[0224] Example 2, inventory for a group of devices
[0225] FIG. 16 is a flowchart XI I of the information transmission method according to an embodiment of the present disclosure. As shown in FIG. 16, the method comprises:
[0226] S1601, the subscription / security entity configures the device group identity and the device group security key (i.e., security key) for the AIoT device.
[0227] S1602, the AF sends an inventory request message to the AIoT F, wherein the inventory request message contains the device group identity.
[0228] S1603, the AIoT F sends an inventory authorization request message to the subscription / security entity, wherein the inventory authorization request message contains the AF identity and the device group identity.
[0229] S1604, the subscription / security entity checks whether the AF can perform the operation according to the AF identity and the device group identity. If allowed, a network nonce is generated; a device group temporary identity is generated by using the device group security key (i.e., security key) of the AIoT device, the device group identity and the network nonce; the device group temporary identity and the network nonce are returned to the AIoT F.
[0230] S1605, the AIoT F sends a device inventory request message (i.e., first service request message) to the AIoT device, wherein the device inventory request message contains the device indication information, the device group temporary identity and the network nonce. The device indication information indicates that the service is for a device group.
[0231] S1606, the AIoT device calculates the device group temporary identity' by using the device group security key (i.e., security key) of the AIoT device, the device group identity and the network nonce, in the same way as the network side. If the device group temporary identity' is the same as the device group temporary identity, the device determines that the service is for the group to which the device belongs. The device continues to generate a device nonce; the device identity is processed securely by using the device group security key (i.e., security key) and the first nonce to obtain the ciphertext first device temporary identity of the device identity, wherein the first nonce includes the network nonce and / or the device nonce; the first device temporary identity and the device nonce are returned to the AIoT F.
[0232] S1607, the AIoT F sends a device identity authentication request message to the subscription / security entity, wherein the device identity authentication request message contains the first device temporary identity and the device nonce.
[0233] S1608, the subscription / security entity performs corresponding cryptographic operation on the first device temporary identifier using the same key and parameters as the AIoT device, obtains the device identifier, and checks whether the device corresponding to the device identifier is a group member. If yes, the subscription / security entity returns the device identifier authentication result to the AIoT F.
[0234] S1609, the AIoT F continues to inventory other group member devices.
[0235] S1610, the AIoT F returns the device inventory result to the AF.
[0236] Example 3, inventory for all devices
[0237] FIG. 17 is a flowchart XII of the information transmission method provided by the embodiments of the present disclosure. As shown in FIG. 17, the method comprises:
[0238] S1701, the subscription / security entity configures the device anonymous group key identifier (i.e., the security key identifier) and the anonymous group key (i.e., the security key) to the AIoT device.
[0239] S1702, the AF sends an inventory request message to the AIoT F, and the inventory request message indicates that the service execution object is all devices.
[0240] S1703, the AIoT F sends an inventory authorization request message to the subscription / security entity, and the inventory authorization request message contains the AF identifier and the indication information, and the indication information indicates that the service execution object is all devices.
[0241] S1704, the subscription / security entity checks whether the AF can perform the operation according to the AF identifier and the indication information. If allowed, a network-side nonce is generated; and the network-side nonce is returned to the AIoT F.
[0242] S1705, the AIoT F sends a device inventory request message (i.e., a first service request message) to the AIoT device, and the device inventory request message contains the first information and the network-side nonce. The first information indicates that the current service is for inventory of all devices.
[0243] S1706, the AIoT device determines that the current service is for inventory of all devices according to the first information. The device continues to generate a device-side nonce; performs security processing on the device identifier using the anonymous group key (i.e., the security key) and the first nonce to obtain the ciphertext first device temporary identifier of the device identifier, and the first nonce includes the network-side nonce and / or the device-side nonce; and returns the first device temporary identifier and the device-side nonce to the AIoT F.
[0244] S1707. The AIoTF sends a device identity authentication request message to the subscription / security entity, where the device identity authentication request message contains the first device temporary identity and the device-side one-time value.
[0245] S1708. The subscription / security entity performs corresponding cryptographic operations on the first device temporary identity using the same key and parameters as the AIoT device, to obtain a device identity. The subscription / security entity returns the device identity authentication result to the AIoTF.
[0246] S1709. The AIoTF continues to inventory other devices.
[0247] S1710. The AIoTF returns the device inventory result to the AF.
[0248] Example 4. Instructions for a single device
[0249] FIG. 18 is a flowchart of a method of information transmission according to an embodiment of the present disclosure. As shown in FIG. 18, the method includes the following steps:
[0250] S1801. The subscription / security entity configures a device identity and a device instruction key (i.e., a security key) for an AIoT device.
[0251] S1802. The AF sends an instruction request message to the AIoTF, where the instruction request message contains a device identity and a payload 1.
[0252] S1803. The AIoTF sends an instruction authorization request message to the subscription / security entity, where the instruction authorization request message contains an AF identity, a device identity, and a payload 1.
[0253] S1804. The subscription / security entity checks whether the AF can perform this operation according to the AF identity and the device identity. If allowed, a network-side one-time value is generated; a second device temporary identity is generated using the device instruction key (i.e., the security key) of the AIoT device, the device identity, and the network-side one-time value (based on system design, this step can also not be performed, and the real device identity can be used directly); the payload 1 is protected for confidentiality using the device instruction key (i.e., the security key) of the AIoT device and the network-side one-time value, to obtain a payload 1'; the instruction is protected for integrity using the device instruction key (i.e., the security key) of the AIoT device and the network-side one-time value, i.e., a message authentication code (MAC) 1 is generated; and the second device temporary identity, the network-side one-time value, the payload 1', and the MAC 1 are returned to the AIoTF.
[0254] S1805. The AIoTF sends a device instruction request message (i.e., a first service request message) to the AIoT device, where the device instruction request message includes device indication information, a second device temporary identifier, a network-side nonce, a payload 1', and a MAC 1. The device indication information indicates that the service is for a single device.
[0255] S1806. The AIoT device uses its device instruction key (i.e., a security key), a device identifier, and a network-side nonce to calculate a device temporary identifier' using the same method as the network side. If the device temporary identifier' is the same as the second device temporary identifier, the device determines that the service is for it (if the device identifier is used directly, the device identifier is used directly for matching). The device uses the same method as the network side to verify the MAC 1 value and decrypt the ciphertext. If the verification is passed, it proves that the instruction is valid, and the instruction is executed. If the instruction needs to be replied, a device-side nonce is continued to be generated; a first device temporary identifier is generated using the device instruction key (i.e., the security key) of the device, the device identifier, and the first nonce (based on system design, the real device identifier can also be used directly without performing this step), where the first nonce includes the network-side nonce and / or the device-side nonce; the payload 2 is confidentially protected using the device instruction key (i.e., the security key) of the device and the first nonce to obtain a payload 2'; the instruction is integrity-protected using the device instruction key (i.e., the security key) of the device and the first nonce, i.e., a MAC 2 is generated; and the first device temporary identifier, the device-side nonce, the payload 2', and the MAC 2 are returned to the AIoTF.
[0256] S1807. The AIoTF sends an instruction authentication request message to the subscription / security entity, where the instruction authentication request message includes the first device temporary identifier, the device-side nonce, the payload 2', and the MAC 2.
[0257] S1808. The subscription / security entity generates a third device temporary identifier using the same method and parameters as the AIoT device. If the third device temporary identifier is the same as the first device temporary identifier, it is determined that it is the response of the target AIoT device. The subscription / security entity uses the same method as the device to verify and decrypt the message, and returns the decryption result to the AIoTF.
[0258] S1809. The AIoTF returns the instruction result (i.e., a service result) to the AF.
[0259] Example 5. Instruction for a group of devices
[0260] FIG. 19 is a flowchart XIV of an information transmission method provided by an embodiment of the present disclosure. As shown in FIG. 19, the method includes:
[0261] S1901, the subscription / security entity configures the device group identifier and the device group instruction key (i.e., security key) for the AIoT device.
[0262] S1902, the AF sends an instruction request message to the AIoT F, wherein the instruction request message contains the device group identifier and the payload 1.
[0263] S1903, the AIoT F sends an instruction authorization request message to the subscription / security entity, wherein the instruction authorization request message contains the AF identifier, the device group identifier and the payload 1.
[0264] S1904, the subscription / security entity checks whether the AF can perform the operation according to the AF identifier and the device group identifier. If allowed, a network nonce is generated; a device group temporary identifier is generated by using the device group instruction key (i.e., security key) of the AIoT device, the device group identifier and the network nonce (according to the system design, this step can also not be performed, and the real device group identifier is directly used); the payload 1 is confidentially protected by using the device group instruction key (i.e., security key) of the AIoT device and the network nonce, and the payload 1' is obtained; the instruction is integrity-protected by using the device group instruction key (i.e., security key) of the AIoT device and the network nonce, and the message authentication code (MAC) 1 is generated; the device group temporary identifier, the network nonce, the payload 1' and the MAC 1 are returned to the AIoT F.
[0265] S1905, the AIoT F sends a device instruction request message (i.e., first service request message) to the AIoT device, wherein the device instruction request message contains the device indication information, the device group temporary identifier, the network nonce, the payload 1' and the MAC 1. The device indication information indicates that the service is for a device group.
[0266] S1906, The AIoT device uses its device group instruction key (i.e., security key), device group identifier, and network-side one-time value to calculate a device group temporary identifier' in the same way as the network side. If the device group temporary identifier' is the same as the device group temporary identifier, the device determines that the current service is an instruction for the group to which it belongs (if the device identifier is directly matched using the device group identifier). The device verifies the MAC1 value and decrypts the ciphertext in the same way as the network side. If the verification is passed, it proves that the instruction is valid, and the instruction is executed. If a response to the instruction is required, the device-side one-time value is continued to be generated; the device identifier is subjected to a cryptographic operation using the device group instruction key (i.e., security key) of the device and the first one-time value to obtain the ciphertext first device temporary identifier of the device identifier (based on system design, the real device identifier can also be directly used without performing this step), and the first one-time value includes the network-side one-time value and / or the device-side one-time value; the payload 2 is subjected to confidentiality protection using the device group instruction key (i.e., security key) of the device and the first one-time value to obtain the payload 2'; the instruction is subjected to integrity protection using the device group instruction key (i.e., security key) of the device and the first one-time value, that is, MAC2 is generated; and the first device temporary identifier, device-side one-time value, payload 2', and MAC2 are returned to the AIoTF.
[0267] S1907, The AIoTF sends an instruction authentication request message to the subscription / security entity, and the instruction authentication request message includes the first device temporary identifier, device-side one-time value, payload 2', and MAC2.
[0268] S1908, The subscription / security entity performs a corresponding cryptographic operation on the first device temporary identifier using the same key and parameter as the AIoT device to obtain the device identifier, and checks whether the device corresponding to the device identifier is a group member. If yes, the subscription / security entity verifies and decrypts the message using the same key and parameter as the device, and returns the decryption result to the AIoTF.
[0269] S1909, The AIoTF continues to process other group member devices.
[0270] S1910, The AIoTF returns the instruction result (i.e., service result) to the AF.
[0271] The disclosed scheme provides a detailed security solution for the service process supported by the AIoT device from the two scenarios of a single device and a group of devices, and realizes the device authentication and data communication security capability. The disclosed scheme adopts a lightweight security technical solution and considers the privacy protection of the device identifier. The disclosed scheme is designed based on the stateless assumption of the AIoT device service process, and is more in line with the service scenario of the AIoT device.
[0272] FIG. 20 is a structural schematic diagram of an information transmission device 10 provided by an embodiment of the present disclosure. As shown in FIG. 20, the device 10 includes a memory 11, a transceiver 12, and a processor 13.
[0273] The memory 11 is configured to store a computer program; the transceiver 12 is configured to transceive data under control of the processor 13; and the processor 13 is configured to read the computer program stored in the memory 11 and perform the following operations:
[0274] receiving a first service request message sent by a management entity, the first service request message including first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0275] sending a first service response message to the management entity, the first service response message including a first device temporary identifier and a device-side one-time value;
[0276] The first device temporary identifier is generated based on a security key, a device identifier of an AIoT device, and a first one-time value, the security key is a key related to the service execution object, and the first one-time value includes the network-side one-time value and / or the device-side one-time value.
[0277] In an implementation manner, the first service response message further includes a security key identifier.
[0278] and / or;
[0279] The processor 13 is configured to perform the following operations:
[0280] The first device temporary identifier is obtained by encrypting the device identifier using the security key and the first one-time value.
[0281] In an implementation manner, the first information includes a service execution object temporary identifier, the service execution object temporary identifier including a second device temporary identifier or a device group temporary identifier; wherein
[0282] The service execution object temporary identifier is generated based on a security key, a service execution object identifier, and a network-side one-time value, and the service execution object identifier includes a device identifier or a device group identifier.
[0283] In an implementation manner, in a case where the service is an instruction, the service execution object temporary identifier is the service execution object identifier, and / or the first device temporary identifier is the device identifier.
[0284] The processor 13 is further configured to perform the following operations:
[0285] receiving configuration information, the configuration information including the security key.
[0286] In an implementation, the configuration information further includes a service execution object identifier or a security key identifier, the service execution object identifier including a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0287] The bus architecture can include any number of interconnecting buses and bridges, wired or wireless, coupled to various circuits of the storage device 10, including one or more processors represented by processor 13 and memory represented by memory 11. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators and power management circuits, which are well known in the art and thus, not described further herein. The bus interface provides an interface. The transceiver 12 can be a plurality of elements, including a transmitter and a receiver, providing a means of communicating with various other apparatus over a transmission medium, including wireless channels, wired channels, optical cables, and the like. The processor 13 is responsible for managing the bus architecture and general processing, with the memory 11 storing data used by the processor 13 in the execution of operations.
[0288] Optionally, the processor 13 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or a complex programmable logic device (CPLD), and the processor can also adopt a multi-core architecture.
[0289] The processor 13 is configured to perform all the method steps of the management entity of the embodiments of the disclosure by invoking the computer program stored in the memory 11 according to the executable instructions obtained. The processor 13 and the memory 11 can also be physically arranged separately.
[0290] It should be noted that the above information transmission device 10 provided by the embodiments of the disclosure can implement all the method steps of the AIoT device in the above method embodiments and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments are not described here.
[0291] FIG. 21 is a structural schematic diagram of an information transmission device 20 provided by the embodiments of the disclosure. As shown in FIG. 21, the device 20 includes a memory 21, a transceiver 22 and a processor 23,
[0292] The memory 21 is configured to store a computer program; the transceiver 22 is configured to transceive data under the control of the processor 23; the processor 23 is configured to read the computer program in the memory 21 and perform the following operations:
[0293] sending a first service request message, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0294] receiving a first service response message sent by an environmental AIoT device, the first service response message comprising a first device temporary identifier and a device-side one-time value;
[0295] The first device temporary identifier is generated based on a security key, a device identifier of the AIoT device and the first one-time value, the security key is a key related to the service execution object, and the first one-time value comprises the network-side one-time value and / or the device-side one-time value.
[0296] In an implementation manner, the first service response message further comprises a security key identifier, and / or the first device temporary identifier is obtained by encrypting the device identifier using the security key and the first one-time value.
[0297] In an implementation manner, the first information comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier.
[0298] The processor 23 is further configured to perform the following operations:
[0299] generating a service execution object temporary identifier based on a security key, a service execution object identifier and a network-side one-time value, the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0300] In an implementation manner, the processor 23 is further configured to perform the following operations:
[0301] sending configuration information to the AIoT device, the configuration information comprising the security key.
[0302] In an implementation manner, the configuration information further comprises the service execution object identifier or a security key identifier, the service execution object identifier comprising the device identifier of the AIoT device or the device group identifier of the group to which the AIoT device belongs.
[0303] In an implementation manner, the processor 23 is further configured to perform the following operations:
[0304] sending a verification request message to a subscription or security entity, the verification request message comprising information carried in the first service response message; and / or,
[0305] receive a verification response message sent by the subscription or security entity, the verification response message comprising a verification result.
[0306] In an implementation, the processor 23 is further configured to perform the following operations:
[0307] send an authorization request message to the subscription or security entity, the authorization request message comprising an application function, AF, identity and second information, the second information comprising a service execution object identity or indication information, the indication information indicating that the service execution object is all AIoT devices, and the service execution object identity comprising a device identity of an AIoT device or a device group identity of a group to which the AIoT device belongs; and / or,
[0308] receive an authorization response message sent by the subscription or security entity, the authorization response message comprising a network-side one-time value.
[0309] In an implementation, when the second information comprises the service execution object identity, the authorization response message further comprises a service execution object temporary identity, the service execution object temporary identity comprising a second device temporary identity or a device group temporary identity.
[0310] In an implementation, when the service is an instruction, the service execution object temporary identity is replaced by the service execution object identity, and / or the first device temporary identity is replaced by the device identity.
[0311] In FIG. 21, the description of the bus architecture can refer to the related content described in FIG. 20, which will not be repeated here.
[0312] Optionally, the processor 23 can be a CPU, an ASIC, an FPGA, or a CPLD. The processor can also adopt a multi-core architecture.
[0313] It should be noted that the above information transmission device 20 provided by the present disclosure can implement all method steps implemented by the management entity in the above method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the present embodiment as the method embodiments will not be repeated here.
[0314] FIG. 22 is a structural schematic diagram of an information transmission device 30 provided by an embodiment of the present disclosure. As shown in FIG. 22, the device 30 comprises a memory 31, a transceiver 32, and a processor 33,
[0315] The memory 31 is configured to store a computer program; the transceiver 32 is configured to transceive data under the control of the processor 33; and the processor 33 is configured to read the computer program in the memory 31 and perform the following operations:
[0316] receive a verification request message sent by the management entity, the verification request message comprising a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to a service execution object, the first one-time value comprising a network-side one-time value and / or a device-side one-time value;
[0317] send a verification response message to the management entity, the verification response message comprising a verification result.
[0318] In an implementation, the verification request message further comprises a security key identifier; and / or, the first device temporary identifier is obtained by encrypting the device identifier using the security key and the first one-time value.
[0319] In an implementation, the processor 33 is further configured to perform the following operation:
[0320] receive an authorization request message sent by the management entity, the authorization request message comprising an AF identifier and second information, the second information comprising a service execution object identifier or indication information, the indication information indicating that the service execution object is all AIoT devices, the service execution object identifier comprising a device identifier of an AIoT device or a device group identifier of a group to which the AIoT device belongs; and / or,
[0321] send an authorization response message to the management entity, the authorization response message comprising the network-side one-time value.
[0322] In an implementation, in a case where the second information comprises the service execution object identifier, the authorization response message further comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier.
[0323] The processor 33 is further configured to perform the following operation:
[0324] generate the service execution object temporary identifier based on the security key, the service execution object identifier, and the network-side one-time value.
[0325] In an implementation, the processor 33 is further configured to perform the following operation:
[0326] send configuration information to the AIoT device, the configuration information comprising the security key.
[0327] In an implementation, the configuration information further comprises the service execution object identifier or a security key identifier, the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0328] In FIG. 22, the bus architecture can also refer to the related content described in FIG. 20, which will not be described here.
[0329] Optionally, the processor 33 can be a CPU, an ASIC, an FPGA or a CPLD. The processor can also adopt a multi-core architecture.
[0330] It should be noted that the above information transmission device 30 provided by the present disclosure can implement all the method steps implemented by the subscription / security entity device in the above method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described here again.
[0331] FIG. 23 is a structural schematic diagram of an information transmission device 40 provided by an embodiment of the present disclosure. As shown in FIG. 23, the device 40 includes:
[0332] The receiving unit 41 is configured to receive a first service request message sent by a management entity, the first service request message including first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0333] The sending unit 42 is configured to send a first service response message to the management entity, the first service response message including a first device temporary identifier and a device-side one-time value.
[0334] The first device temporary identifier is generated based on a security key, a device identifier of an AIoT device and the first one-time value, the security key being a key related to the service execution object, and the first one-time value including the network-side one-time value and / or the device-side one-time value.
[0335] In an embodiment, the first service response message further includes a security key identifier.
[0336] And / or
[0337] The device 40 further includes a processing unit 43 configured to encrypt the device identifier by using the security key and the first one-time value to obtain the first device temporary identifier.
[0338] In an embodiment, the first information includes a service execution object temporary identifier, the service execution object temporary identifier including a second device temporary identifier or a device group temporary identifier; wherein
[0339] The service execution object temporary identifier is generated based on a security key, a service execution object identifier and a network-side one-time value, the service execution object identifier including a device identifier or a device group identifier.
[0340] In an embodiment, in the case where the service is an instruction, the service execution object temporary identifier is the service execution object identifier, and / or the first device temporary identifier is the device identifier.
[0341] In an embodiment, the receiving unit 41 is further configured to:
[0342] receiving configuration information, the configuration information comprising a security key.
[0343] In an embodiment, the configuration information further comprises a service execution object identifier or a security key identifier, the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0344] It should be noted that the above information transmission apparatus 40 provided by the present disclosure can realize all method steps implemented by the AIoT device in the above method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described here again.
[0345] FIG. 24 is a structural schematic diagram of an information transmission apparatus 50 provided by an embodiment of the present disclosure. As shown in FIG. 24, the apparatus 50 comprises:
[0346] a sending unit 51 configured to send a first service request message, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object;
[0347] a receiving unit 52 configured to receive a first service response message sent by an environment Internet of Things (AIoT) device, the first service response message comprising a first device temporary identifier and a device-side one-time value;
[0348] The first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to the service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value.
[0349] In an embodiment, the first service response message further comprises a security key identifier, and / or the first device temporary identifier is obtained by encrypting the device identifier using the security key and the first one-time value.
[0350] In an embodiment, the first information comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier.
[0351] The apparatus 50 further comprises a processing unit 53 configured to generate a service execution object temporary identifier based on a security key, a service execution object identifier, and a network-side one-time value, the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0352] In an embodiment, the sending unit 51 is further configured to:
[0353] The configuration information is sent to the AIoT device, and the configuration information includes a security key.
[0354] In an implementation, the configuration information further includes a service execution object identifier or a security key identifier, and the service execution object identifier includes a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0355] In an implementation, the sending unit 51 is further configured to send, to the subscription or security entity, a verification request message, and the verification request message includes the information carried in the first service response message; and / or,
[0356] The receiving unit 52 is further configured to receive a verification response message sent by the subscription or security entity, and the verification response message includes a verification result.
[0357] In an implementation, the sending unit 51 is further configured to send, to the subscription or security entity, an authorization request message, and the authorization request message includes an application function (AF) identifier and second information, and the second information includes a service execution object identifier or indication information, the indication information indicates that the service execution object is all AIoT devices, and the service execution object identifier includes a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs; and / or,
[0358] The receiving unit 52 is further configured to receive an authorization response message sent by the subscription or security entity, and the authorization response message includes a network-side one-time value.
[0359] In an implementation, when the second information includes the service execution object identifier, the authorization response message further includes a service execution object temporary identifier, and the service execution object temporary identifier includes a second device temporary identifier or a device group temporary identifier.
[0360] It should be noted that the above information transmission apparatus 50 provided by the disclosure can implement all the method steps implemented by the management entity in the above method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described here.
[0361] FIG. 25 is a structural schematic diagram of an information transmission apparatus 60 provided by an embodiment of the disclosure. As shown in FIG. 25, the apparatus 60 includes:
[0362] The receiving unit 61 is configured to receive a verification request message sent by the management entity, and the verification request message includes a first device temporary identifier and a device-side one-time value, the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key is a key related to a service execution object, and the first one-time value includes a network-side one-time value and / or a device-side one-time value;
[0363] The sending unit 62 is configured to send a verification response message to the management entity, the verification response message comprising a verification result.
[0364] In an embodiment, the verification request message further comprises a security key identifier; and / or, the first device temporary identifier is obtained by encrypting the device identifier using the security key and the first one-time value.
[0365] In an embodiment, the receiving unit 61 is further configured to receive an authorization request message sent by the management entity, the authorization request message comprising an AF identifier and second information, the second information comprising a service execution object identifier or indication information, the service execution object identifier comprising a device identifier of an AIoT device or a device group identifier of a group to which the AIoT device belongs; and / or,
[0366] The sending unit 62 is further configured to send an authorization response message to the management entity, the authorization response message comprising a network-side one-time value.
[0367] In an embodiment, when the second information comprises the service execution object identifier, the authorization response message further comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier.
[0368] The apparatus 60 further comprises a processing unit 63 configured to:
[0369] generate the service execution object temporary identifier based on the security key, the service execution object identifier, and the network-side one-time value.
[0370] In an embodiment, the sending unit 62 is further configured to send configuration information to the AIoT device, the configuration information comprising the security key.
[0371] In an embodiment, the configuration information further comprises the service execution object identifier or the security key identifier, the service execution object identifier comprising a device identifier of an AIoT device or a device group identifier of a group to which the AIoT device belongs.
[0372] It is to be noted that the above information transmission apparatus 60 provided by the present disclosure can implement all the method steps implemented by the subscription / security entity in the above method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the present embodiment as the method embodiments will not be described here.
[0373] It should be noted that the division of the units in the embodiments of the present disclosure is illustrative, and is only a logical function division. In actual implementation, another division manner can be used. In addition, each functional unit in each embodiment of the present disclosure can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0374] When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on such understanding, the technical solutions of the present disclosure, essentially or in part, or all or part of the technical solutions, can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the methods described in the various embodiments of the present disclosure. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and various other media that can store program codes.
[0375] The embodiments of the present disclosure also provide a non-transitory readable storage medium, which stores a computer program. The computer program is used to make a processor execute all method steps of the management entity in the above method embodiments.
[0376] The embodiments of the present disclosure also provide a non-transitory readable storage medium, which stores a computer program. The computer program is used to make a processor execute all method steps of the AIoT device in the above method embodiments.
[0377] The embodiments of the present disclosure also provide a non-transitory readable storage medium, which stores a computer program. The computer program is used to make a processor execute all method steps of the subscription / security entity in the above method embodiments.
[0378] The non-transitory readable storage medium can be any available medium or data storage device that can be accessed by a computer, including but not limited to a magnetic storage (such as a floppy disk, a hard disk, a magnetic tape, a magneto-optical disk (MO), etc.), an optical storage (such as a CD, a DVD, a BD, a HVD, etc.), and a semiconductor storage (such as a ROM, an EPROM, an EEPROM, a non-volatile memory (NAND FLASH), a solid state disk (SSD)), etc.
[0379] The embodiment of the present disclosure further provides a computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of the above method embodiments.
[0380] Those skilled in the art will appreciate that embodiments of the present disclosure can be provided as methods, systems, or computer program products. Accordingly, the present disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present disclosure can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, and optical storage) embodying computer-usable program code.
[0381] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer executable instructions. These computer executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce the functions specified in the flowchart one or more flows and / or block diagram one or more blocks.
[0382] These processor executable instructions can also be stored in a processor readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the processor readable memory produce a manufactured product comprising instruction means, which implements the functions specified in the flowchart one or more flows and / or block diagram one or more blocks.
[0383] These processor executable instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide steps for implementing the functions specified in the flowchart one or more flows and / or block diagram one or more blocks.
[0384] Obviously, those skilled in the art can make various modifications and variations to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if these modifications and variations of the present disclosure fall within the scope of the claims of the present disclosure and their equivalent technologies, the present disclosure is also intended to include these modifications and variations.
Claims
1. A method of information transmission, wherein, Applied to an environmental Internet of Things (AIoT) device, the method comprises: receiving a first service request message sent by a management entity, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object; sending a first service response message to the management entity, the first service response message comprising a first device temporary identifier and a device-side one-time value; wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to the service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value.
2. The method of claim 1, wherein, the first service response message further comprises a security key identifier; and / or; the first device temporary identifier is generated based on the security key, the device identifier, and the first one-time value, comprising: the first device temporary identifier obtained by encrypting the device identifier of the AIoT device using the security key and the first one-time value.
3. The method of claim 1 or 2, wherein, the first information comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier.
4. The method of claim 3, wherein, in the case of a service being an instruction, the service execution object temporary identifier is a service execution object identifier, and / or the first device temporary identifier is the device identifier; wherein the service execution object identifier comprises the device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
5. The method of claim 1, wherein, the method further comprises: receiving configuration information, the configuration information comprising the security key.
6. The method of claim 5, wherein, the configuration information further comprises a service execution object identifier or a security key identifier, the service execution object identifier comprising the device identifier of the AIoT device or the device group identifier of the group to which the AIoT device belongs.
7. An information transmission method, wherein, applied to a management entity, the method comprises: sending a first service request message, the first service request message comprising first information and a network-side one-time value, the first information being used to indicate a service execution object; receiving a first service response message sent by an environmental Internet of Things (AIoT) device, the first service response message comprising a first device temporary identifier and a device-side one-time value; wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key being a key related to the service execution object, and the first one-time value comprising the network-side one-time value and / or the device-side one-time value.
8. The method of claim 7, wherein, the first service response message further comprises a security key identifier.
9. The method of claim 7 or 8, wherein, the first information comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier; the method further comprises: generating a service execution object temporary identifier based on the security key, a service execution object identifier, and the network-side one-time value, wherein the service execution object identifier comprises a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
10. The method of claim 7, wherein, the method further comprises: The configuration information comprises a security key.
11. The method of claim 10, wherein, The configuration information further comprises a service execution object identifier or a security key identifier, the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
12. The method according to any one of claims 7-11, wherein, The method further comprises: sending, to a subscription or security entity, a verification request message, the verification request message comprising information carried in the first service response message; and / or, receiving a verification response message sent by the subscription or security entity, the verification response message comprising a verification result.
13. The method according to any one of claims 7-12, wherein, The method further comprises: sending, to the subscription or security entity, an authorization request message, the authorization request message comprising an application function (AF) identifier and second information, the second information comprising a service execution object identifier or indication information, the indication information indicating that the service execution object is all AIoT devices, and the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs; and / or, receiving an authorization response message sent by the subscription or security entity, the authorization response message comprising a network-side one-time value.
14. The method of claim 13, wherein, In a case where the second information comprises the service execution object identifier, the authorization response message further comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier.
15. An information transmission method, wherein, The method comprises: receiving, from a management entity, a verification request message, the verification request message comprising a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier of an AIoT device, and a first one-time value, the security key being a key related to a service execution object, and the first one-time value comprising a network-side one-time value and / or the device-side one-time value; sending, to the management entity, a verification response message, the verification response message comprising a verification result.
16. The method of claim 15, wherein, The verification request message further comprises a security key identifier.
17. The method of claim 15 or 16, wherein, The method further comprises: receiving, from a management entity, an authorization request message, the authorization request message comprising an application function (AF) identifier and second information, the second information comprising a service execution object identifier or indication information, the indication information indicating that the service execution object is all AIoT devices, and the service execution object identifier comprising a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs; and / or, sending, to the management entity, an authorization response message, the authorization response message comprising a network-side one-time value.
18. The method of claim 17, wherein, In a case where the second information comprises the service execution object identifier, the authorization response message further comprises a service execution object temporary identifier, the service execution object temporary identifier comprising a second device temporary identifier or a device group temporary identifier. The method further comprises: generating the service execution object temporary identifier based on the security key, the service execution object identifier, and the network-side one-time value.
19. The method of claim 15, wherein, The method further comprises: sending, to an environment Internet of Things (AIoT) device, configuration information, the configuration information comprising the security key.
20. The method of claim 19, wherein, The configuration information further includes a service execution object identifier or a security key identifier, and the service execution object identifier includes a device identifier of the AIoT device or a device group identifier of a group to which the AIoT device belongs.
21. An information transmission apparatus, wherein, The device is applied to an environmental Internet of Things (AIoT) device and includes: a receiving unit configured to receive a first service request message sent by a management entity, the first service request message including first information and a network-side one-time value, and the first information being used to indicate a service execution object; a sending unit configured to send a first service response message to the management entity, the first service response message including a first device temporary identifier and a device-side one-time value; wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key is a key related to the service execution object, and the first one-time value includes the network-side one-time value and / or the device-side one-time value.
22. An information transmission apparatus, wherein, The device is applied to a management entity and includes: a sending unit configured to send a first service request message, the first service request message including first information and a network-side one-time value, and the first information being used to indicate a service execution object; a receiving unit configured to receive a first service response message sent by an environmental Internet of Things (AIoT) device, the first service response message including a first device temporary identifier and a device-side one-time value; wherein the first device temporary identifier is generated based on a security key, a device identifier of the AIoT device, and a first one-time value, the security key is a key related to the service execution object, and the first one-time value includes the network-side one-time value and / or the device-side one-time value.
23. An information transmission apparatus, wherein, The device is applied to a subscription or security entity and includes: a receiving unit configured to receive a verification request message sent by a management entity, the verification request message including a first device temporary identifier and a device-side one-time value, the first device temporary identifier being generated based on a security key, a device identifier of an AIoT device, and a first one-time value, the security key being a key related to a service execution object, and the first one-time value including a network-side one-time value and / or the device-side one-time value; a sending unit configured to send a verification response message to the management entity, the verification response message including a verification result.
24. An information transmission apparatus, wherein, The device is applied to an environmental Internet of Things (AIoT) device and includes a memory, a transceiver, and a processor, the memory is configured to store a computer program, the transceiver is configured to transceive data under control of the processor, and the processor is configured to read the computer program in the memory and perform the method in any one of claims 1-6.
25. An information transmission apparatus, wherein, The device is applied to a management entity and includes a memory, a transceiver, and a processor, the memory is configured to store a computer program, the transceiver is configured to transceive data under control of the processor, and the processor is configured to read the computer program in the memory and perform the method in any one of claims 7-14.
26. An information transmission apparatus, wherein, The device is applied to a subscription or security entity and includes a memory, a transceiver, and a processor, The memory is configured to store a computer program; the transceiver is configured to transceive data under control of the processor; and the processor is configured to read the computer program in the memory and perform the method of any one of claims 15-20.
Citation Information
Patent Citations
Communication method and device and readable storage medium
CN117544947A
Data verification method and related equipment
CN118524112A
Information transmission method and device and storage medium
CN118612723A
Method of wireless security communication using physical layer shared security key in ambient internet-of-things network and related devices
WO2024119030A1