Information interaction method, apparatus, and related device
By exchanging authentication parameters between the first communication node, network nodes, and devices, the problem of AAA functions or AIoT devices being unable to perform authentication operations is solved, thus improving network security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-24
- Publication Date
- 2026-04-02
AI Technical Summary
In existing technologies, AAA functions or AIoT devices are unable to perform authentication operations, leading to cybersecurity vulnerabilities.
The first communication node broadcasts a message carrying authentication parameters and interacts with network nodes and devices to ensure the transmission and processing of authentication parameters, including broadcasting, receiving and sending authentication information to perform authentication operations.
This reduces the number of network nodes or devices that are unable to perform authentication operations, thus improving network security.
Smart Images

Figure CN2025123666_02042026_PF_FP_ABST
Abstract
Description
Information interaction method and device and related equipment
[0001] The present application claims priority to the Chinese patent application No. 202411374456.4, filed on September 29, 2024, and entitled "Information interaction method, device and related equipment", the whole content of which is incorporated herein by reference. TECHNICAL FIELD
[0002] The present application belongs to the field of communication technology, and specifically relates to an information interaction method, device and related equipment. BACKGROUND
[0003] Currently, the information elements in the authentication process are transmitted through non-access layer (NAS) messages, and the initiator of the authentication process can only be a network side device. Generally, the authentication, authorization and accounting (AAA) function can send authentication parameters to an ambient Internet of Things (AIoT) device through a communication node or an access network device, so that the AIoT device can perform an authentication operation based on the authentication parameters, or the AIoT device can send the authentication parameters to the AAA function through the communication node or the access network device, so that the AAA function can perform an authentication operation based on the authentication parameters.
[0004] However, in the related art, there is no provision for how the AAA function sends the authentication parameters to the AIoT device through the communication node or the access network device, and there is no provision for how the AIoT device sends the authentication parameters obtained by performing the authentication operation to the AAA function through the communication node or the access network device, thus, it can cause the AAA function or the AIoT device to be unable to perform the authentication operation, which can cause a network security risk. SUMMARY
[0005] The embodiments of the present application provide an information interaction method, device and related equipment, which can solve the problem that the AAA function or the AIoT device is unable to perform the authentication operation.
[0006] In a first aspect, an information interaction method is provided, which is performed by a first communication node. The method comprises: the first communication node performing a first operation, the first operation comprising at least one of the following: broadcasting a first message; the first message comprising at least one of the following: a paging message, an inventory message, a wake-up message, a low-power physical network AIoT message; the first message carrying a first authentication parameter, the first authentication parameter being used to perform an authentication operation; receiving first information from a first device, sending second information based on the first information to a first network node; the first information comprising a second authentication parameter or identification information, the second information being used to perform an authentication operation or comprising identification information; the second authentication parameter being used to perform an authentication operation; the identification information being used to indicate the first device; receiving third information from the first network node, and sending a third authentication parameter based on the third information to the first device; the third information being used to perform an authentication operation; the third authentication parameter being used to perform an authentication operation.
[0007] In a second aspect, an information interaction method is provided, which is performed by a second network node. The method comprises: the second network node performing at least one of a second operation and a third operation, the second operation comprising at least one of the following: sending fourth information to a first communication node; receiving fourth information from a third network node, and sending the fourth information to the first communication node; receiving first information from a first device, and sending second information based on the first information to a first network node; the first information comprising a second authentication parameter, the second authentication parameter being used to perform an authentication operation, the second information being used to perform an authentication operation; receiving third information sent by the first network node, and sending a third authentication parameter based on the third information to the first device; the third information being used to perform an authentication operation, the third authentication parameter being used to perform an authentication operation; wherein the fourth information comprises at least one of the following: a fourth authentication parameter, used to perform an authentication operation; related information of the first network node; a first token, used to verify an authentication operation; first indication information, used to indicate that the fourth authentication parameter is obtained, or that the fourth authentication parameter can be obtained; fifth information, used to indicate at least one of the following: paging, inventory, wake-up, command, request, AIoT function; the third operation comprises: receiving sixth information from a fourth network node, and performing the second operation based on the sixth information; wherein the sixth information comprises at least one of the following: second indication information; related information of the first network node; first indication information, used to indicate that the fourth authentication parameter is obtained, or that the fourth authentication parameter can be obtained; wherein the second indication information comprises at least one of the following: related information of the third network node; related information of the first device; related information of the first communication node; group identification information; service core network node information; service network information; AIoT capability indication; and indication information indicating whether the second operation is allowed or not allowed.
[0008] In a third aspect, a method for information interaction is provided, which is performed by a first network node. The method comprises: based on third indication information related to an AIoT function, the first network node performs at least one of the following: generating third information; generating a first key; generating a fourth authentication parameter; sending the third information to a second network node; sending the first key to the second network node; sending the fourth authentication parameter to the second network node; wherein the third information is used to perform an authentication operation; wherein the first key is used to securely process information interacting with a first device; wherein the fourth authentication parameter is used to perform an authentication operation.
[0009] In a fourth aspect, a method for information interaction is provided, which is performed by a fourth network node. The method comprises: the fourth network node sends sixth information to a second network node, the sixth information comprising at least one of the following: second indication information; related information of a first network node; first indication information indicating that a fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; wherein the fourth authentication parameter is used to perform an authentication operation; wherein the second indication information comprises at least one of the following: related information of a third network node; related information of a first device; related information of a first communication node; group identification information; service core network node information; service network information; AIoT capability indication; indication information indicating whether a second operation is allowed or not; wherein the second operation comprises at least one of the following: sending fourth information to a first communication node; receiving fourth information from a third network node and sending the fourth information to the first communication node; receiving first information from a first device and sending second information to a first network node based on the first information; wherein the first information comprises a second authentication parameter used to perform an authentication operation, and the second information is used to perform an authentication operation; receiving third information sent by a first network node and sending a third authentication parameter to a first device based on the third information; wherein the third information is used to perform an authentication operation, and the third authentication parameter is used to perform an authentication operation; wherein the fourth information comprises at least one of the following: the fourth authentication parameter; related information of the first network node; a first token used to verify an authentication operation; first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; fifth information indicating at least one of the following: paging, inventory, wake-up, command, request, AIoT function.
[0010] In a fifth aspect, an information interaction method is provided, which is performed by a first device, and includes: the first device performing a fourth operation, which includes at least one of the following: receiving a first message carrying a first authentication parameter, which is broadcast by a first communication node; based on the first authentication parameter, sending a second authentication parameter to the first communication node or a second network node or a first network node; the first authentication parameter is used to perform an authentication operation; receiving a second message broadcast by the first communication node; sending second information to the first communication node or the second network node or the first network node; the second information includes the second authentication parameter; wherein the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; wherein the second message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; the second authentication parameter is used to perform an authentication operation.
[0011] In a sixth aspect, an information interaction apparatus is provided, which includes at least one of the following: a receiving module and a sending module. The information interaction apparatus performs a first operation, which includes at least one of the following: the sending module broadcasts a first message; the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; the first message carries a first authentication parameter, which is used to perform an authentication operation; the receiving module receives first information from a first device; the sending module sends second information to a first network node based on the first information received by the receiving module; the first information includes a second authentication parameter or identification information; the second information is used to perform an authentication operation or includes the identification information; the second authentication parameter is used to perform an authentication operation; the identification information is used to indicate the first device; the receiving module receives third information from the first network node; the sending module sends a third authentication parameter to the first device based on the third information received by the receiving module; the third information is used to perform an authentication operation; the third authentication parameter is used to perform an authentication operation.
[0012] In a seventh aspect, an information interaction apparatus is provided, which includes at least one of a sending module and a receiving module. The information interaction apparatus performs at least one of a second operation and a third operation. The second operation includes at least one of the following: the sending module sends fourth information to a first communication node; the receiving module receives fourth information from a third network node, and the sending module sends the fourth information received by the receiving module to the first communication node; the receiving module receives first information from a first device, and the sending module sends second information to a first network node based on the first information received by the receiving module; the first information includes a second authentication parameter used to perform an authentication operation, and the second information is used to perform the authentication operation; the receiving module receives third information sent by the first network node, and the sending module sends a third authentication parameter to the first device based on the third information received by the receiving module; the third information is used to perform the authentication operation, and the third authentication parameter is used to perform the authentication operation; wherein the fourth information includes at least one of the following: a fourth authentication parameter; related information of the first network node; a first token used to verify the authentication operation; and first indication information used to indicate that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; and fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, and AIoT function. The third operation includes: receiving sixth information from a fourth network node, and performing the second operation based on the sixth information; wherein the sixth information includes at least one of the following: second indication information; related information of the first network node; and first indication information used to indicate that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; wherein the second indication information includes at least one of the following: related information of the third network node; related information of the first device; related information of the first communication node; group identification information; service core network node information; service network information; AIoT capability indication; and indication information indicating whether the second operation is allowed or not allowed; and the fourth authentication parameter is used to perform the authentication operation.
[0013] In an eighth aspect, an information interaction apparatus is provided, which includes a processing module. The processing module is configured to perform at least one of the following based on third indication information related to an AIoT function: generate third information; generate a first key; generate a fourth authentication parameter; send the third information to a second network node; send the first key to the second network node; and send the fourth authentication parameter to the second network node; wherein the third information is used to perform an authentication operation; the first key is used to securely process information interacted with a first device; and the fourth authentication parameter is used to perform the authentication operation.
[0014] In a ninth aspect, an information interaction apparatus is provided, and the information interaction apparatus includes a sending module. The sending module is configured to send sixth information to a second network node, the sixth information including at least one of the following: second indication information; related information of a first network node; and first indication information indicating that a fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained, the fourth authentication parameter being used to perform an authentication operation. The second indication information includes at least one of the following: related information of a third network node; related information of a first device; related information of a first communication node; group identification information; service core network node information; service network information; AIoT capability indication; and indication information indicating whether a second operation is allowed or not, the second operation including at least one of the following: sending fourth information to the first communication node; receiving fourth information from the third network node and sending the fourth information to the first communication node; receiving first information from the first device and sending second information to the first network node based on the first information, the first information including a second authentication parameter used to perform the authentication operation, and the second information being used to perform the authentication operation; and receiving third information sent by the first network node and sending a third authentication parameter to the first device based on the third information, the third information being used to perform the authentication operation, and the third authentication parameter being used to perform the authentication operation. The fourth information includes at least one of the following: the fourth authentication parameter; the related information of the first network node; a first token used to verify the authentication operation; the first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; and fifth information indicating at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.
[0015] In a tenth aspect, an information interaction apparatus is provided, and the information interaction apparatus includes at least one of the following: a receiving module and a sending module. The information interaction apparatus performs a fourth operation including at least one of the following: the receiving module receives a first message carrying a first authentication parameter broadcast by a first communication node, and the sending module sends a second authentication parameter to the first communication node, a second network node, or a first network node based on the first authentication parameter received by the receiving module, the first authentication parameter being used to perform an authentication operation; and the receiving module receives a second message broadcast by the first communication node, and the sending module sends second information to the first communication node, the second network node, or the first network node, the second information including a second authentication parameter. The first message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message. The second message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message. The second authentication parameter is used to perform the authentication operation.
[0016] In an eleventh aspect, an information interaction apparatus is provided, which is configured to perform the steps of the method according to the first aspect, or implement the steps of the method according to the second aspect, or implement the steps of the method according to the third aspect, or implement the steps of the method according to the fourth aspect, or implement the steps of the method according to the fifth aspect.
[0017] In a twelfth aspect, a terminal is provided, which includes a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions being executed by the processor to implement the steps of the method according to the first aspect, or implement the steps of the method according to the fifth aspect.
[0018] In a thirteenth aspect, a terminal is provided, which includes a processor and a communication interface, wherein the terminal performs a first operation, which includes at least one of the following: the communication interface broadcasts a first message; the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first message carries a first authentication parameter, which is used to perform an authentication operation; the communication interface receives first information from a first device, and sends second information to a first network node based on the first information; the first information includes a second authentication parameter or identification information, and the second information is used to perform an authentication operation or includes identification information; the second authentication parameter is used to perform an authentication operation; the identification information is used to indicate the first device; the communication interface receives third information from the first network node, and sends a third authentication parameter to the first device based on the third information; the third information is used to perform an authentication operation; and the third authentication parameter is used to perform an authentication operation. Alternatively, the terminal performs a fourth operation, which includes at least one of the following: the communication interface receives a first message broadcast by a first communication node, the first message carrying a first authentication parameter; based on the first authentication parameter, the communication interface sends a second authentication parameter to the first communication node or a second network node or the first network node; the first authentication parameter is used to perform an authentication operation; the communication interface receives a second message broadcast by the first communication node, and sends second information to the first communication node or the second network node or the first network node; the second information includes a second authentication parameter; wherein the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; wherein the second message includes at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; and wherein the second authentication parameter is used to perform an authentication operation.
[0019] In a fourteenth aspect, a network-side device is provided, comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions, when executed by the processor, implement the steps of the method according to the first aspect, or implement the steps of the method according to the second aspect, or implement the steps of the method according to the third aspect, or implement the steps of the method according to the fourth aspect.
[0020] In a fifteenth aspect, a network-side device is provided, comprising a processor and a communication interface, wherein the network-side device performs a first operation, the first operation comprising at least one of the following: the communication interface broadcasts a first message; the first message comprises at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first message carries a first authentication parameter, the first authentication parameter being used to perform an authentication operation; the communication interface receives first information from a first device, sends second information based on the first information to a first network node; the first information comprises a second authentication parameter or identification information, the second information being used to perform an authentication operation or comprising identification information; the second authentication parameter is used to perform an authentication operation; the identification information is used to indicate the first device; the communication interface receives third information from the first network node, sends a third authentication parameter based on the third information to the first device; the third information is used to perform an authentication operation; the third authentication parameter is used to perform an authentication operation. Alternatively, the network-side device performs at least one of a second operation and a third operation: the second operation comprises: the communication interface sends fourth information to a first communication node; the communication interface receives fourth information from a third network node, sends the fourth information to the first communication node; the communication interface receives first information from a first device, sends second information based on the first information to a first network node; the first information comprises a second authentication parameter, the second authentication parameter being used to perform an authentication operation, the second information being used to perform an authentication operation; the communication interface receives third information sent from the first network node, sends a third authentication parameter based on the third information to the first device; the third information is used to perform an authentication operation, the third authentication parameter is used to perform an authentication operation; wherein the fourth information comprises at least one of the following: a fourth authentication parameter; related information of the first network node; a first token used to verify an authentication operation; first indication information used to indicate that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, AIoT function; the third operation comprises: receiving sixth information from a fourth network node, performing the second operation based on the sixth information; wherein the sixth information comprises at least one of the following: second indication information; related information of the first network node; first indication information used to indicate that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; wherein the second indication information comprises at least one of the following: related information of the third network node; related information of the first device; related information of the first communication node; group identification information; service core network node information; service network information; AIoT capability indication; indication information indicating whether the second operation is allowed or not allowed; wherein the fourth authentication parameter is used to perform an authentication operation.Alternatively, the processor performs at least one of the following based on the third indication information related to the AIoT function: generating third information; generating a first key; generating a fourth authentication parameter; sending the third information to the second network node; sending the first key to the second network node; sending the fourth authentication parameter to the second network node; wherein the third information is used to perform an authentication operation; wherein the first key is used to securely process information interacting with the first device; wherein the fourth authentication parameter is used to perform an authentication operation. Alternatively, the communication interface sends sixth information to the second network node, the sixth information including at least one of the following: the second indication information; related information of the first network node; the first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; wherein the second indication information includes at least one of the following: related information of the third network node; related information of the first device; related information of the first communication node; group identification information; service core network node information; service network information; AIoT capability indication; indication information indicating whether the second operation is allowed or not allowed; wherein the second operation includes at least one of the following: sending fourth information to the first communication node; receiving the fourth information from the third network node and sending the fourth information to the first communication node; receiving first information from the first device and sending second information to the first network node based on the first information; wherein the first information includes a second authentication parameter used to perform an authentication operation, and the second information is used to perform an authentication operation; receiving third information sent by the first network node and sending a third authentication parameter to the first device based on the third information; wherein the third information is used to perform an authentication operation, and the third authentication parameter is used to perform an authentication operation; wherein the fourth information includes at least one of the following: the fourth authentication parameter; related information of the first network node; a first token used to verify an authentication operation; the first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; fifth information indicating at least one of the following: paging, inventory, wake-up, command, request, AIoT function.
[0021] In a sixteenth aspect, a readable storage medium is provided, and the readable storage medium stores a program or instructions, which, when executed by a processor, implement the steps of the method of the first aspect, or implement the steps of the method of the second aspect, or implement the steps of the method of the third aspect, or implement the steps of the method of the fourth aspect, or implement the steps of the method of the fifth aspect.
[0022] In a seventeenth aspect, a wireless communication system is provided, comprising: a first communication node operable to perform the steps of the method of the first aspect, a second network node operable to perform the steps of the method of the second aspect, a first network node operable to perform the steps of the method of the third aspect, a fourth network node operable to perform the steps of the method of the fourth aspect, and a first device operable to perform the steps of the method of the fifth aspect.
[0023] In an eighteenth aspect, a chip is provided, comprising a processor and a communication interface, the communication interface and the processor are coupled, the processor is configured to run programs or instructions, to implement the steps of the method of the first aspect, or to implement the steps of the method of the second aspect, or to implement the steps of the method of the third aspect, or to implement the steps of the method of the fourth aspect, or to implement the steps of the method of the fifth aspect.
[0024] In a nineteenth aspect, a computer program / program product is provided, stored in a storage medium, the computer program / program product is executed by at least one processor to implement the steps of the method of the first aspect, or to implement the steps of the method of the second aspect, or to implement the steps of the method of the third aspect, or to implement the steps of the method of the fourth aspect, or to implement the steps of the method of the fifth aspect.
[0025] In the embodiments of the present application, since it is specified in the embodiments of the present application that the first communication node can broadcast the first message, and / or receive the first information from the first device, send the second information to the first network node based on the first information, and / or receive the third information from the first network node, send the third authentication parameter to the first device based on the third information, to transmit the first authentication parameter and / or the second authentication parameter and / or the third authentication parameter for performing the authentication operation, therefore, it can reduce the situation that the network node (such as AAA function) or the device (such as AIoT device) cannot perform the authentication operation, thus, the network security can be improved.
[0026] In the embodiments of the present application, since it is specified in the embodiments of the present application that the second network node can send the fourth information to the first communication node, the first communication node can learn the fourth authentication parameter and / or the related information of the first network node and / or the first token and / or the first indication information, so that the first communication node can accurately learn the fourth authentication parameter, and / or accurately interact with the first network node, and / or use the same first token as other network nodes for verification, thereby reducing the situation that the first communication device cannot perform authentication operation, and / or cannot send authentication parameter to the first network node, and / or cannot interact with other network nodes; and / or receiving the fourth information from the third network node, sending the fourth information to the first communication node, thereby avoiding the situation that the second network node cannot learn the fourth information, and the first communication node can accurately learn the fourth authentication parameter, and / or accurately interact with the first network node, and / or use the same first token as other network nodes for verification, thereby reducing the situation that the first communication device cannot perform authentication operation, and / or cannot send authentication parameter to the first network node, and / or cannot interact with other network nodes; and / or receiving the third information sent by the first network node, and sending the third authentication parameter to the first device based on the third information, thereby ensuring that the first device can obtain the third authentication parameter for performing authentication operation. And / or, since it is specified in the embodiments of the present application that the second network node can obtain the sixth information from the fourth network node and perform the second operation based on the sixth information, the situation that the second network node cannot perform the second operation due to not learning some information in the sixth information can be avoided. Thus, the situation that the network node (such as AAA function) or device (such as AIoT device) cannot perform authentication operation can be reduced, and thus the network security can be improved.
[0027] In the embodiments of the present application, since the first network node can generate the third information based on the third indication information related to the AIoT function, the situation that the authentication operation cannot be performed due to the failure to generate the third information can be avoided; and / or the first key is generated based on the third indication information related to the AIoT function, so the situation that the authentication operation fails due to the failure to securely process the information interacting with the first device can be avoided; and / or the fourth authentication parameter is generated based on the third indication information related to the AIoT function, so the situation that the other network nodes cannot obtain the fourth authentication parameter can be avoided to avoid the situation that the authentication operation cannot be performed; and / or the third information is sent to the second network node based on the third indication information related to the AIoT function, so the situation that the second network node cannot perform the authentication operation due to the failure to receive the third information can be avoided; and / or the first key is sent to the second network node based on the third indication information related to the AIoT function, so the situation that the second network node cannot perform the authentication operation due to the failure to securely process the information interacting with the first device can be avoided; and / or the fourth authentication parameter is sent to the second network node based on the third indication information related to the AIoT function, so the situation that the second network node cannot obtain the fourth authentication parameter can be avoided to avoid the situation that the authentication operation cannot be performed; thereby the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, and thus the network security can be improved.
[0028] In the embodiments of the present application, since the fourth network node can send the second indication information to the second network node to indicate at least one of the related information of the third network node, the related information of the first device, the related information of the first communication node, the group identifier information, the service core network node information, the service network information, the AIoT capability indication, and the indication information of whether to allow the second operation to the second network node, the second network node can select a suitable network node or communication node to perform the authentication operation, so that the situation that the authentication operation cannot be performed can be avoided; and / or, since the fourth network node can send the related information of the first network node to the second network node, the second network node can accurately interact with the first network node based on the related information of the first network node to transmit the authentication parameter, so that the situation that the authentication operation cannot be performed due to the failure to transmit the authentication parameter can be avoided; and / or, since the fourth network node can send the first indication information to the second network node to indicate that the second network node acquires the fourth authentication parameter or that the second network node can acquire the fourth authentication parameter, the second network node can timely and accurately acquire the fourth authentication parameter based on which the authentication operation is performed, so that the situation that the authentication operation cannot be performed can be avoided; thereby, the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, and thus the network security can be improved.
[0029] In the embodiments of the present application, since the first device can receive the first message carrying the first authentication parameter broadcast by the first communication node, and send the second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter, the situation that the first device cannot determine to which device to send the second authentication parameter can be avoided, so that the situation that the authentication operation cannot be performed can be avoided; and / or, since the first device can receive the second message broadcast by the first communication node, and send the second information to the first communication node or the second network node or the first network node, the situation that the first device cannot determine when to send the second information to the first communication node or the second network node or the first network node can be avoided, so that the situation that the authentication operation cannot be performed can be avoided; thereby, the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, and thus the network security can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0030] FIG. 1 is a block diagram of a wireless communication system according to an embodiment of the present application;
[0031] FIG. 2 is a flow diagram of an information interaction method according to an embodiment of the present application;
[0032] FIG. 3 is a flow diagram of a second embodiment of the information interaction method according to the present application;
[0033] FIG. 4 is a flow diagram of a third embodiment of the information interaction method according to the present application;
[0034] FIG. 5 is a flow diagram of a fourth embodiment of the information interaction method according to the present application;
[0035] FIG. 6 is a flow diagram of a fifth embodiment of the information interaction method according to the present application;
[0036] FIG. 7 is a flow diagram of a sixth embodiment of the information interaction method according to the present application;
[0037] FIG. 8 is a flow diagram of a seventh embodiment of the information interaction method according to the present application;
[0038] FIG. 9 is a flow diagram of an eighth embodiment of the information interaction method according to the present application;
[0039] FIG. 10 is a flow diagram of a ninth embodiment of the information interaction method according to the present application;
[0040] FIG. 11 is a flow diagram of a tenth embodiment of the information interaction method according to the present application;
[0041] FIG. 12 is a flow diagram of an eleventh embodiment of the information interaction method according to the present application;
[0042] FIG. 13 is a flow diagram of a twelfth embodiment of the information interaction method according to the present application;
[0043] FIG. 14 is a flow diagram of a thirteenth embodiment of the information interaction method according to the present application;
[0044] FIG. 15 is a flow diagram of a fourteenth embodiment of the information interaction method according to the present application;
[0045] FIG. 16 is a structural diagram of an information interaction apparatus according to the present application;
[0046] FIG. 17 is a structural diagram of an information interaction apparatus according to the present application;
[0047] FIG. 18 is a structural diagram of an information interaction apparatus according to the present application;
[0048] FIG. 19 is a structural diagram of an information interaction apparatus according to the present application;
[0049] FIG. 20 is a structural diagram of an information interaction apparatus according to the present application;
[0050] FIG. 21 is a hardware structure diagram of a communication device according to the present application;
[0051] FIG. 22 is a schematic diagram of a hardware structure of a terminal according to an embodiment of the present application;
[0052] FIG. 23 is a schematic diagram of a hardware structure of a network-side device according to an embodiment of the present application;
[0053] FIG. 24 is another schematic diagram of a hardware structure of a network-side device according to an embodiment of the present application. DETAILED DESCRIPTION
[0054] The technical solutions in the embodiments of the present application will be clearly described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some, but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art belong to the scope of protection of the present application.
[0055] The terms "first", "second", and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than that illustrated or described herein, and the objects distinguished by "first", "second" are generally a category and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in the present application means at least one of the connected objects. For example, the protection scope of "A or B" at least covers three schemes, namely, scheme one: including A and not including B; scheme two: including B and not including A; scheme three: including A and including B. In addition, the terms "A and / or B", "at least one of A and B", "at least one of A or B" also at least cover the above three schemes, respectively. The character " / " generally represents that the objects before and after are in an "or" relationship.
[0056] The term "indication" in the present application can be a direct indication (or explicit indication) or an indirect indication (or implicit indication). The direct indication can be understood as that the sender explicitly informs the receiver of specific information, operations to be performed or requested results, etc. in the indication sent by the sender. The indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or judges and determines the operations to be performed or the requested results according to the judgment result.
[0057] It is worth noting that the technology described in the embodiments of the present application is not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used in the above-mentioned systems and radio technologies, as well as in other systems and radio technologies. The following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th Generation (6G) communication systems. th
[0058] FIG. 1 shows a block diagram of a wireless communication system to which embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a terminal-side device such as a mobile phone, a Tablet Personal Computer, a Laptop Computer, a notebook computer, a Personal Digital Assistant (PDA), a palmtop computer, a netbook, an Ultra-mobile Personal Computer (UMPC), a Mobile Internet Device (MID), an Augmented Reality (AR) device, a Virtual Reality (VR) device, a robot, a wearable device, a flight vehicle, a Vehicle User Equipment (VUE), a shipboard device, a Pedestrian User Equipment (PUE), a smart home (a home device with a wireless communication function such as a refrigerator, a television, a washing machine, or furniture), a game console, a Personal Computer (PC), a kiosk, or a self-service machine. The wearable device includes a smart watch, a smart bracelet, a smart earphone, smart glasses, smart jewelry (a smart bracelet, a smart necklace, a smart ring, a smart necklace, a smart anklet, a smart necklace, etc.), a smart wristband, smart clothes, etc. The vehicle-mounted device can also be referred to as a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip, or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 can include an access network device or a core network device. The access network device can also be referred to as a Radio Access Network (RAN) device, a radio access network function, or a radio access network unit. The access network device can include a base station, a Wireless Local Area Network (WLAN) Access Point (AP), or a Wireless Fidelity (WiFi) node, etc.The base station can be referred to as a Node B (NB), an evolved Node B (eNB), a next generation Node B (gNB), a New Radio Node B (NR Node B), an access point, a relay station (RBS), a serving base station (SBS), a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home Node B (HNB), a home evolved Node B, a transmit / receive point (TRP), or some other suitable terminology in the art, and is not limited to a particular technical terminology, provided that the same technical effect is achieved. It should be noted that in the embodiments of the present application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
[0059] The core network device can also be referred to as a core network node, a core network function, or a core network network element, etc., which includes but is not limited to at least one of the following: a mobility management entity (MME), an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a policy control function (PCF), a policy and charging rules function (PCRF), an edge application server discovery function (EASDF), a unified data management (UDM), a unified data repository (UDR), a home subscriber server (HSS), a centralized network configuration (CNC), a network repository function (NRF), a network exposure function (NEF), a local NEF (L-NEF), a binding support function (BSF), an application function (AF), a location management function (LMF), a gateway mobile location center (GMLC), a network data analytics function (NWDAF), etc. It should be noted that only the core network device in the NR system is taken as an example for introduction in the embodiments of the present application, and the specific type of the core network device is not limited. If the name of the core network device mentioned in the embodiments of the present application changes in the subsequent protocol version (for example, 6G), it is also within the protection scope of the present application.
[0060] Optionally, the core network device can be implemented by one or more function modules in one device, or can be implemented by multiple devices together, and the embodiments of the present application do not make specific limitations hereon. It can be understood that the above function modules can be network elements in a hardware device, can be software function modules running on a dedicated hardware, or can be virtualized function modules instantiated on a platform (for example, a cloud platform).
[0061] The information interaction method, apparatus and related device provided by the embodiments of the present application will be described in detail below in combination with the accompanying drawings and some embodiments and application scenarios thereof.
[0062] The information interaction method provided by the embodiments of the present application can be executed by an information interaction apparatus, or a first communication node, or a function module or entity in the first communication node. The information interaction method provided by the embodiments of the present application is described by taking the first communication node as an example.
[0063] FIG. 2 shows a flowchart of the information interaction method provided by the embodiments of the present application. As shown in FIG. 2, the information interaction method provided by the embodiments of the present application can include the following step 101.
[0064] Step 101: The first communication node executes a first operation.
[0065] In some embodiments of the present application, the above-mentioned first communication node can perform information interaction with an AIoT device (for example, the first device in the following embodiments) as a reader.
[0066] In some embodiments of the present application, the above-mentioned first communication node is a terminal or an access network device.
[0067] As can be seen, since it is specified in the embodiments of the present application that the first communication node can be a terminal or an access network device, it can be ensured that the terminal or the access network device can send the authentication parameter to the first device, and / or the terminal or the access network device can send the authentication parameter to the first network node. Therefore, the situation that the network node (for example, the AAA function) or the first device cannot perform the authentication operation can be avoided.
[0068] In the embodiments of the present application, the above-mentioned first operation includes at least one of the following:
[0069] broadcasting a first message; the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first message carries a first authentication parameter, and the first authentication parameter is used to perform an authentication operation;
[0070] receiving first information from the first device, sending second information to the first network node based on the first information; the first information comprises second authentication parameters or identification information, the second information is used to perform an authentication operation or comprises identification information; the second authentication parameters are used to perform an authentication operation; the identification information is used to indicate the first device;
[0071] receiving third information from the first network node, sending third authentication parameters to the first device based on the third information; the third information is used to perform an authentication operation; the third authentication parameters are used to perform an authentication operation.
[0072] In some embodiments of the present application, the paging message can be a paging message used to page a terminal or an AIoT device (for example, the first device in the following embodiments). The inventory message can be an inventory message used to instruct the first communication node to perform an inventory operation on the AIoT device (for example, the first device in the following embodiments). The wake up message can be a wake up signal used to wake up the first communication node or the AIoT device (for example, the first device in the following embodiments). The AIoT message can be a message used to instruct the AIoT device to perform an operation.
[0073] In some embodiments of the present application, the first message can be a message sent by the core network function to the first communication node, and the first message comprises at least part of the content in the message.
[0074] In some embodiments of the present application, the first authentication parameters can be referred to as an Auth Container. The Auth Container can carry parameters used to perform an authentication operation, which can include a random number, a message authentication code (MAC), a user response RES, an authentication algorithm, and the like. Of course, the parameters can also include other parameters, which are not limited in the embodiments of the present application.
[0075] In some embodiments of the present application, the first communication node can broadcast the first message in a broadcast manner.
[0076] It can be understood that, since the first communication node can carry the first authentication parameters in the first message, the terminal (or AIoT device) can perform an authentication operation at the same time as paging and / or inventory and / or waking up the terminal (or AIoT device), without the need to additionally carry the first authentication parameters through a message. Therefore, the terminal (or AIoT device) can perform an authentication operation in time while saving air interface resources.
[0077] In some embodiments of the present application, the first operation comprises broadcasting the first message. In some examples, in combination with FIG. 2, as shown in FIG. 3, before step 101, the information interaction method provided by the embodiments of the present application can further comprise step 201, and step 101 can be implemented by step 101a.
[0078] In step 201, the first communication node receives the fourth authentication parameter from the first network node.
[0079] In the embodiments of the present application, the fourth authentication parameter is used to perform the authentication operation.
[0080] In some embodiments of the present application, the fourth authentication parameter can be referred to as an Auth Container. The Auth Container can carry a parameter used to perform the authentication operation, which can include a random number, a message authentication code (MAC), a user response RES, an authentication algorithm, and the like. Of course, the parameter can also include other parameters, which are not limited in the embodiments of the present application.
[0081] In some embodiments of the present application, the fourth authentication parameter can be carried by any message between the first communication node and the first network node. For example, the fourth authentication parameter can be carried by any message between the first communication node and the first network node in the process of paging and / or inventory and / or wake-up.
[0082] It can be understood that since the fourth authentication parameter can be carried by any message, the first network node can send the fourth authentication parameter to the first communication node in a timely manner when needed, so that the first communication node can receive the fourth authentication parameter in a timely manner.
[0083] In step 101a, the first communication node broadcasts the first message based on the fourth authentication parameter.
[0084] In some embodiments of the present application, the first communication node can encapsulate each item of content in the fourth authentication parameter into a first authentication parameter in the form of a Container, and then broadcast the first message; or the first communication node can generate a first authentication parameter based on the result of derivation or calculation of the fourth authentication parameter and broadcast the first message; or the first authentication parameter is the fourth authentication parameter.
[0085] As can be seen, since the first communication node can obtain the fourth authentication parameter from the first network node, the first communication node can accurately determine the first authentication parameter based on the fourth authentication parameter, and broadcast the first message carrying the first authentication parameter, so that the first device can accurately perform the authentication operation based on the first message.
[0086] In some embodiments of the present application, the first information can be carried by any message between the first communication node and the first device. For example, the first information can be carried by any message in the process of performing paging operation and / or inventory operation and / or wake-up operation between the first communication node and the first device.
[0087] It can be understood that since the first information can be carried by any message, the first device can timely send the first information to the first communication node at the required time, so that the first communication node can timely receive the first information.
[0088] In some embodiments of the present application, the second authentication parameter can be referred to as Auth Container. The Auth Container can carry parameters for performing authentication operation, which can include random number, message authentication code (MAC), user response RES, authentication algorithm, etc. for performing authentication operation. Of course, the parameters can also include other parameters, which are not limited by the embodiments of the present application.
[0089] In some embodiments of the present application, the first network node can include at least one of the following: AAA function, authentication server function (AUSF) function, unified data management (UDM) function.
[0090] In some embodiments of the present application, the first device can be an AIoT device.
[0091] In some embodiments of the present application, the identification information can include at least one of the following: identification of the first device, medium access control (MAC) address of the first device.
[0092] In some embodiments of the present application, the sending of the second information to the first network node based on the first information can be understood as: the first communication node expresses the content in the first information as the content of the second information through different information element (IE) after decapsulating, and then sends; or the first communication node generates the second information based on the result of deduction or calculation of the first information and sends; or the second information is the first information, and the first communication node forwards the information received from the first device to the first network node.
[0093] In some embodiments of the present application, the first operation includes receiving first information from the first device, and sending second information to the first network node based on the first information. In some examples, before the step 101, the information interaction method provided by the embodiments of the present application can further include at least one of the following steps 202 and 203.
[0094] The step 202 includes that the first communication node broadcasts a second message.
[0095] In the embodiments of the present application, the second message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message.
[0096] It can be understood that the difference between the second message and the first message is that the second message does not carry the first authentication parameter.
[0097] In some embodiments of the present application, in the case where the first communication node broadcasts the second message, the first device can obtain (or generate) the second authentication parameter or the identification information by itself, and send the first information to the first communication node. The first device can send a response message corresponding to the second message to the first communication node, and the response message carries the first information.
[0098] The step 203 includes that the first communication node broadcasts a first message.
[0099] In some embodiments of the present application, in the case where the first communication node broadcasts the first message, the first device can determine the second authentication parameter according to the first authentication parameter, or obtain the identification information according to the first authentication parameter, and send the first information to the first communication node. The first device can send a response message corresponding to the first message to the first communication node, and the response message carries the first information.
[0100] As can be seen, since the embodiments of the present application specify the message that can be sent by the first communication device, in the process of performing the authentication operation, the first communication node can accurately send the message to avoid the situation that the authentication operation cannot be performed.
[0101] In some embodiments of the present application, the first operation includes receiving first information from the first device, and sending second information to the first network node based on the first information. In some examples, before the step 101, the information interaction method provided by the embodiments of the present application can further include the following step 204.
[0102] The step 204 includes that the first communication node establishes a first session, and the first session is used to transmit information exchanged between the first device and the first network node through the first communication node, or is used to transmit information exchanged between the first communication node and the first network node on behalf of the first device.
[0103] In some embodiments of the present application, the first session can be a Protocol Data Unit (PDU) session.
[0104] In some embodiments of the present application, the first communication node can send a first request message to the SMF, the first request message being used to request to establish the first session, so that the SMF can configure the UPF, so that the first communication node can interact data with other network nodes (for example, AAA function) through the first session.
[0105] Therefore, since the first communication node can also establish the first session, in the subsequent steps, the first communication node can directly transmit information interacted by the first device with the first network node through the first communication node and the first network node through the first session, or transmit information interacted by the first device with the first network node through the first communication node through the first communication node, without the need for other network nodes to forward the information, so that the waste of air interface resources can be reduced.
[0106] In some embodiments of the present application, the third information can be carried by any message between the first communication node and the first network node. For example, the third information can be carried by any message between the first communication node and the first network node in the process of performing the inventory operation.
[0107] It can be understood that since the third information can be carried by the above-mentioned any message, the first device can send the third information to the first communication node in a timely manner when needed, so that the first communication node can receive the third information in a timely manner.
[0108] In some embodiments of the present application, the third authentication parameter can be referred to as an Auth Container. The Auth Container can carry a parameter used to perform an authentication operation, which can include a random number, a message authentication code (MAC), a user response RES, an authentication algorithm, and the like used to perform the authentication operation. Of course, the parameter can also include other parameters, which are not limited by embodiments of the present application.
[0109] In some embodiments of the present application, the third authentication parameter based on the third information sent to the first device can be understood as follows: the first communication node encapsulates each item of content in the third information into a Container form of the third authentication parameter and sends it to the first device; or generates the third authentication parameter based on the result derived or calculated based on the third information and sends it to the first device; or the third authentication parameter is the third information, and the first communication node forwards the information received from the first network node to the first device.
[0110] The embodiment of the present application provides an information interaction method, a first communication node performs a first operation, the first operation comprises at least one of the following: broadcasting a first message; receiving first information from a first device, sending second information to a first network node based on the first information; receiving third information from the first network node, and sending third authentication parameters to the first device based on the third information; wherein the first message comprises at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first message carries first authentication parameters, and the first authentication parameters are used to perform an authentication operation; the first information comprises second authentication parameters or identification information, and the second information is used to perform an authentication operation or comprises identification information; the second authentication parameters are used to perform an authentication operation; the identification information is used to indicate the first device; the third information is used to perform an authentication operation; and the third authentication parameters are used to perform an authentication operation. Since the embodiment of the present application provides that the first communication node can broadcast the first message, and / or receive the first information from the first device, and send the second information to the first network node based on the first information, and / or receive the third information from the first network node, and send the third authentication parameters to the first device based on the third information, so as to transmit the first authentication parameters and / or the second authentication parameters and / or the third authentication parameters used to perform the authentication operation, the situation that the network node (for example, AAA function) or the device (for example, AIoT device) cannot perform the authentication operation can be reduced, and therefore the network security can be improved.
[0111] In some embodiments of the present application, the information interaction method provided by the embodiment of the present application can further include the following steps 205 and 206.
[0112] Step 205, the first communication node receives fourth information from a second network node.
[0113] It should be noted that the execution sequence of steps 205 and 101 is not limited in the embodiment of the present application. In one example, the first communication node can execute step 101 first, and then execute step 205; in another example, the first communication node can execute step 205 first, and then execute step 101; in yet another example, the first communication node can execute step 101 and step 205 at the same time.
[0114] In some embodiments of the present application, the above-mentioned second network node can include at least one of the following: AF, Ambient Internet of Things Management Function (AIoT MF), AMF.
[0115] In the embodiment of the present application, the above-mentioned fourth information includes at least one of the following:
[0116] a fourth authentication parameter, used for performing an authentication operation;
[0117] related information of the first network node;
[0118] a first token, used for verifying the authentication operation;
[0119] first indication information, used for indicating that the fourth authentication parameter is obtained, or indicating that the fourth authentication parameter can be obtained, the fourth authentication parameter being used for performing the authentication operation;
[0120] fifth information, used for indicating at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.
[0121] It should be noted that the description of the fourth authentication parameter can refer to the specific description in the above embodiments, which will not be repeated here.
[0122] In some embodiments of the present application, the related information of the first network node can include at least one of the following: an identifier of the first network node, an address of the first network node, and the like.
[0123] In some embodiments of the present application, the fifth information is used for indicating the AIoT function, which can be understood as: the fifth information is used for indicating an ongoing AIoT-related operation.
[0124] In step 206, the first communication node performs at least one of the following based on the fourth information:
[0125] The fourth information includes related information of the fourth authentication parameter, and the first communication node broadcasts the first message based on the fourth authentication parameter;
[0126] The fourth information includes related information of the first network node, and the first communication node sends the second information to the first network node based on the related information of the first network node;
[0127] The fourth information includes the related information of the first network node, and the first communication node determines whether the received information is from or not from the first network node, or determines the authenticity of the first network node based on the related information of the first network node;
[0128] The fourth information includes the first token, and the first communication node sends the first token to the first network node;
[0129] The fourth information includes the fifth information, and the first communication node broadcasts the first message or the second message based on the fifth information, the second message including at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message;
[0130] The fourth information includes at least one of the first indication information and the fifth information, and the first communication node obtains the fourth authentication parameter from the first network node based on at least one of the first indication information and the fifth information, and broadcasts the first message based on the fourth authentication parameter.
[0131] In some embodiments of the present application, in the case that the first operation includes at least one of: receiving the first information from the first device, sending the second information to the first network node based on the first information; receiving the third information from the first network node, and sending the third authentication parameter to the first device based on the third information, the first communication node performs the fourth information based on the fourth information including the fourth authentication parameter, and the first communication node broadcasts the first message based on the fourth authentication parameter.
[0132] In some embodiments of the present application, in the case that the first operation includes at least one of: broadcasting the first message; receiving the third information from the first network node, and sending the third authentication parameter to the first device based on the third information, the first communication node performs the fourth information based on the fourth information including the related information of the first network node, and the first communication node sends the second information to the first network node based on the related information of the first network node.
[0133] In some embodiments of the present application, in order to prevent fraud, when interacting with the first network node, it is judged whether the received information is from the first network node or the remote is the real first network node through the certificate information returned by the first network node, and the subsequent establishment of a secure channel based on the certificate can ensure that the information interacting with the first network node is not attacked by a man-in-the-middle.
[0134] In some embodiments of the present application, in the case that the first operation includes at least one of: receiving the first information from the first device, sending the second information to the first network node based on the first information; receiving the third information from the first network node, and sending the third authentication parameter to the first device based on the third information, the first communication node performs the fourth information based on the fourth information including the fifth information, and the first communication node broadcasts the first message or the second message based on the fifth information.
[0135] In some embodiments of the present application, in the case that the first operation includes at least one of: receiving the first information from the first device, sending the second information to the first network node based on the first information; receiving the third information from the first network node, and sending the third authentication parameter to the first device based on the third information, the first communication node performs the fourth information based on the fourth information including at least one of the first indication information and the fifth information, and the first communication node obtains the fourth authentication parameter from the first network node based on at least one of the first indication information and the fifth information, and broadcasts the first message based on the fourth authentication parameter.
[0136] Therefore, the first communication node can accurately perform the corresponding specific steps according to the specific content, so as to avoid the situation that the authentication operation cannot be performed or the authenticity of the first network node cannot be judged.
[0137] The execution subject of the information interaction method provided in the embodiments of the present application can be the information interaction device, or the second network node, or a functional module or entity in the second network node. The information interaction method provided in the embodiments of the present application is described by taking the second network node as an example.
[0138] FIG. 4 shows a flowchart of the information interaction method provided in the embodiments of the present application. As shown in FIG. 4, the information interaction method provided in the embodiments of the present application can include the following step 301.
[0139] Step 301: The second network node performs at least one of a second operation and a third operation.
[0140] It should be noted that the description of the second network node can refer to the specific description in the above embodiments, which will not be repeated here.
[0141] In the embodiments of the present application, the second operation includes at least one of the following:
[0142] sending fourth information to the first communication node;
[0143] receiving fourth information from a third network node, and sending the fourth information to the first communication node;
[0144] receiving first information from the first device, and sending second information to the first network node based on the first information; the first information includes a second authentication parameter, the second authentication parameter is used to perform an authentication operation, and the second information is used to perform the authentication operation;
[0145] receiving third information sent by the first network node, and sending a third authentication parameter to the first device based on the third information; the third information is used to perform an authentication operation, and the third authentication parameter is used to perform the authentication operation;
[0146] In some embodiments of the present application, the third network node can include at least one of the following: the first network node, the AF, the NEF, etc.
[0147] In the embodiments of the present application, the fourth information includes at least one of the following:
[0148] a fourth authentication parameter;
[0149] The related information of the first network node;
[0150] The first token is used for verifying the authentication operation.
[0151] The first indication information is used for indicating that the fourth authentication parameter is acquired or that the fourth authentication parameter can be acquired.
[0152] The fifth information is used for indicating at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.
[0153] In the embodiments of the present application, the fourth authentication parameter is used for performing the authentication operation.
[0154] In some embodiments of the present application, the second operation includes receiving the fourth information from the third network node and sending the fourth information to the first communication node. In some embodiments, the information interaction method provided by the embodiments of the present application can further include the following step 401.
[0155] Step 401, the fourth information includes the first token, and the second network node receives the first token from the first network node.
[0156] As can be seen, since the embodiments of the present application provide that the second network node receives the first token from the first network node, the second network node can send the accurate first token to the first communication node, so that the first network node and the first communication node can use the same token for verification in the subsequent steps, so as to avoid the situation that the verification fails due to the use of different tokens for verification, thereby causing the authentication parameter cannot be transmitted. Therefore, the situation that the authentication operation cannot be performed can be avoided.
[0157] In some embodiments of the present application, the second operation includes receiving the fourth information from the third network node and sending the fourth information to the first communication node. In some embodiments, the information interaction method provided by the embodiments of the present application can further include the following step 402.
[0158] Step 402, the fourth information includes the first token, and the second network node sends the first token to the first network node.
[0159] As can be seen, since the embodiments of the present application provide that the second network node sends the first token to the first network node, the first network node and the first communication node can use the same token for verification in the subsequent steps, so as to avoid the situation that the verification fails due to the use of different tokens for verification, thereby causing the authentication parameter cannot be transmitted. Therefore, the situation that the authentication operation cannot be performed can be avoided.
[0160] In the embodiments of this application, the third operation includes: receiving sixth information from the fourth network node, and performing the second operation based on the sixth information. The sixth information includes at least one of the following:
[0161] Second indication information;
[0162] Related information of the first network node;
[0163] First indication information, used to indicate obtaining the fourth authentication parameter, or indicating that the fourth authentication parameter can be obtained;
[0164] The second indication information includes at least one of the following:
[0165] Related information of the third network node;
[0166] Related information of the first device;
[0167] Related information of the first communication node;
[0168] Group identification information;
[0169] Service core network node information;
[0170] Service network information;
[0171] AIoT capability indication;
[0172] Indication information of allowing or not allowing the second operation.
[0173] In some embodiments of the application, the fourth network node can include at least one of the following: UDM, UDR.
[0174] In some embodiments of the application, the related information of the third network node can include at least one of the following: the identification of the third network node, the address of the third network node, etc. The related information of the third network node can be used to determine whether to allow the AIoT related operation to be performed.
[0175] The AIoT related operation can include but is not limited to inventory operation, paging operation, wake-up operation, etc.
[0176] In some embodiments of the application, the device identification of the first device can include at least one of the following: the identification of the first device, the manufacturer of the first device, etc. The device identification of the first device can be used to inventory whether the third network node can perform the AIoT related operation with the first device or the same type of device as the first device.
[0177] In some embodiments of the present application, the related information of the first communication node can include at least one of the following: an identity of the first communication node, an address of the first communication node, a type of the first communication node, and the like. The related information of the first communication node can be used to determine whether the first communication node can perform AIoT-related operations.
[0178] In some embodiments of the present application, the group identification information can be used to determine whether AIoT-related operations can be performed on devices related to the group identification. The above determinations can be combined, such as determining whether the third network node can use the first communication node to perform AIoT-related operations on devices related to a certain group identification or devices related to a certain manufacturer.
[0179] In some embodiments of the present application, the service core network node information can include at least one of the following: an ID of the service core network node, an IP address of the service core network node, and the like. The service core network node can be an AMF, and at this time, the service core network node information can be used by the second network node to learn which AMF is used to interact with the first communication node, whether the target device or the target first communication node of the AIoT operation is out of range, and the like (not served by some AMF, then not executed).
[0180] In some embodiments of the present application, the service network information can include at least one of the following: a Public Land Mobile Network (PLMN) identification, a PLMN name, and the like. The service network information can be used by the second network node to learn the access network of the first communication node, whether the target first communication node of the AIoT operation is out of range, and the like (not in a specified network or roaming, then not performing AIoT-related operations).
[0181] In some embodiments of the present application, the AIoT capability indication is used to determine whether the first communication node can perform AIoT-related operations. If the first communication node cannot perform AIoT-related operations, the first communication node is not used to perform AIoT-related operations.
[0182] In some embodiments of the present application, the step 301 can be specifically implemented by at least one of the following steps 301a to 301e.
[0183] The step 301a includes that the sixth information includes related information of the first network node, and the second network node sends the second information to the first network node based on the related information of the first network node.
[0184] In some embodiments of the present application, the first network node sending the second information can be understood as: the first network node can set a target for sending the second information according to the related information of the first network node, that is, sending the second information to the first network node.
[0185] Step 301b, the sixth information includes the related information of the first network node, and the second network node judges whether the received information comes from or does not come from the first network node or judges the authenticity of the first network node based on the related information of the first network node.
[0186] In some embodiments of the present application, in order to prevent fraud, when interacting with the first network node, the certificate information returned by the first network node is used to judge whether the remote end is a real first network node, and the subsequent establishment of a secure channel based on the certificate can ensure that the information interacting with the first network node is not attacked by a man-in-the-middle.
[0187] Step 301c, the second operation includes sending fourth information to the first communication node, and the sixth information includes first indication information, the second network node obtains fourth authentication parameters from the first network node based on the first indication information, and sends the fourth information to the first communication node, and the fourth information includes the fourth authentication parameters.
[0188] Step 301d, the second operation includes sending fourth information to the first communication node, and the sixth information includes service core network node information, the second network node selects the first communication node based on the service core network node information, and sends the fourth information to the first communication node.
[0189] Step 301e, the second operation includes sending fourth information to the first communication node, and the sixth information includes AIoT capability indication, the second network node selects the first communication node based on the AIoT capability indication, and sends the fourth information to the first communication node.
[0190] Therefore, the second network node can accurately execute the corresponding specific steps based on the information included in the sixth information, to accurately send the second information, and / or judge the authenticity of the first network node, and / or send the fourth information, and / or select the first communication node, and / or execute the second operation. Therefore, it can be avoided that the authentication operation cannot be executed, and / or the authenticity of the first network node cannot be judged.
[0191] In some embodiments of the present application, the information interaction method provided by the embodiments of the present application can further include the following step 403.
[0192] Step 403, the second network node sends third indication information related to AIoT function to the first network node.
[0193] It should be noted that the execution sequence of step 403 and step 301 is not limited in the embodiment of the present application. In one example, the second network node can execute step 403 first and then execute step 301; in another example, the second network node can execute step 301 first and then execute step 403; in yet another example, the second network node can execute step 403 and step 301 at the same time.
[0194] In the embodiment of the present application, the third indication information is used to obtain at least one of the following:
[0195] Third information;
[0196] A first key used for securely processing information interacting with the first device;
[0197] A fourth authentication parameter.
[0198] As can be seen, since the embodiment of the present application specifies the specific information that the second network node needs to send to the first network node, the second network node can accurately send the information required by the first network node to the first network node according to the specific information.
[0199] Embodiments of the present application provide an information interaction method, a second network node performs a second operation, the second operation includes at least one of the following: sending fourth information to a first communication node; receiving fourth information from a third network node, sending fourth information to a first communication node; receiving first information from a first device, sending second information to a first network node based on the first information; receiving third information sent by the first network node, sending third authentication parameters to the first device based on the third information; wherein the fourth information includes at least one of the following: fourth authentication parameters for performing authentication operations; related information of the first network node; a first token for verifying authentication operations; first indication information for indicating to obtain fourth authentication parameters, or indicating that fourth authentication parameters can be obtained; fifth information for indicating at least one of the following: paging, inventory, wake-up, command, request, AIoT function; the first information includes second authentication parameters for performing authentication operations, and the second information is used for performing authentication operations; the third information is used for performing authentication operations, and the third authentication parameters are used for performing authentication operations. And / or, the second network node performs a third operation, the third operation includes: obtaining sixth information from a fourth network node, and performing the second operation based on the sixth information; wherein the sixth information includes at least one of the following: second indication information; related information of the first network node; first indication information for indicating to obtain fourth authentication parameters, or indicating that fourth authentication parameters can be obtained; wherein the second indication information includes at least one of the following: related information of the third network node; related information of the first device; related information of the first communication node; group identifier information; service core network node information; service network information; AIoT capability indication; and indication information of whether to allow or not to allow the second operation.Since the second network node can send the fourth information to the first communication node in the embodiment of the present application, the first communication node can learn the fourth authentication parameter and / or the related information of the first network node and / or the first token and / or the first indication information, so that the first communication node can accurately learn the fourth authentication parameter, and / or accurately interact with the first network node, and / or use the same first token as other network nodes for verification, thereby reducing the situation that the first communication device cannot perform authentication operation, and / or cannot send authentication parameter to the first network node, and / or cannot interact with other network nodes; and / or receiving the fourth information from the third network node, sending the fourth information to the first communication node, so that the second network node can avoid the situation that the fourth information cannot be learned, and the first communication node can accurately learn the fourth authentication parameter, and / or accurately interact with the first network node, and / or use the same first token as other network nodes for verification, thereby reducing the situation that the first communication device cannot perform authentication operation, and / or cannot send authentication parameter to the first network node, and / or cannot interact with other network nodes; and / or, receiving the third information sent by the first network node, sending the third authentication parameter to the first device based on the third information, so that the first device can obtain the third authentication parameter for performing authentication operation. And / or, since the second network node can obtain the sixth information from the fourth network node and perform the second operation based on the sixth information in the embodiment of the present application, the situation that the second network node cannot perform the second operation due to not learning some information in the sixth information can be avoided. Thus, the situation that the network node (such as AAA function) or device (such as AIoT device) cannot perform authentication operation can be reduced, so that the network security can be improved.
[0200] The information interaction method provided in the embodiment of the present application can be executed by the information interaction device, or the first network node, or a functional module or entity in the first network node. The information interaction method provided in the embodiment of the present application is described by taking the first network node as an example.
[0201] FIG. 5 shows a flowchart of the information interaction method provided in the embodiment of the present application. As shown in FIG. 5, the information interaction method provided in the embodiment of the present application can include the following step 501.
[0202] In step 501, the first network node performs at least one of the following based on the third indication information related to the AIoT function:
[0203] generating the third information;
[0204] generating the first key;
[0205] generating a fourth authentication parameter;
[0206] sending third information to the second network node;
[0207] sending the first key to the second network node;
[0208] sending the fourth authentication parameter to the second network node.
[0209] It should be noted that the description of the first network node and the second network node can refer to the specific description in the above embodiments, and the embodiments of the present application will not be repeated here.
[0210] In some embodiments of the present application, the third indication information described above can be used to obtain at least one of the following:
[0211] the third information is used to perform an authentication operation
[0212] the first key is used to securely process information interacting with the first device;
[0213] the fourth authentication parameter is used to perform an authentication operation.
[0214] In the embodiments of the present application, the third information described above is used to perform an authentication operation; the first key described above is used to securely process information interacting with the first device; and the fourth authentication parameter described above is used to perform an authentication operation.
[0215] In some embodiments of the present application, before the step 501 described above, the information interaction method provided by the embodiments of the present application can further include the following step 500.
[0216] Step 500, the first network node receives third indication information from the second network node.
[0217] As can be seen, since the first network node can receive the third indication information from the second network node to know the steps required to be performed by the first network node required by the second network node through the third indication information, after receiving the third indication information, the first network node can accurately perform the steps required to be performed by the first network node required by the second network node.
[0218] The embodiment of the present application provides an information interaction method, and the first network node can perform the following at least one operation based on the third indication information related to the AIoT function: generating third information; generating a first key; generating a fourth authentication parameter; sending the third information to the second network node; sending the first key to the second network node; and sending the fourth authentication parameter to the second network node; wherein the third information is used for performing an authentication operation, the first key is used for securely processing information interacting with the first device, and the fourth authentication parameter is used for performing the authentication operation. Since the first network node can generate the third information based on the third indication information related to the AIoT function, the situation that the authentication operation cannot be performed due to the failure to generate the third information can be avoided; and / or, the first key is generated based on the third indication information related to the AIoT function, so that the situation that the authentication operation fails due to the failure to securely process the information interacting with the first device can be avoided; and / or, the fourth authentication parameter is generated based on the third indication information related to the AIoT function, so that the situation that the other network node cannot obtain the fourth authentication parameter can be avoided, to avoid the situation that the authentication operation cannot be performed; and / or, the third information is sent to the second network node based on the third indication information related to the AIoT function, so that the situation that the second network node cannot perform the authentication operation due to the failure to receive the third information can be avoided; and / or, the first key is sent to the second network node based on the third indication information related to the AIoT function, so that the situation that the authentication operation fails due to the failure of the second network node to securely process the information interacting with the first device can be avoided; and / or, the fourth authentication parameter is sent to the second network node based on the third indication information related to the AIoT function, so that the situation that the second network node cannot obtain the fourth authentication parameter can be avoided, to avoid the situation that the authentication operation cannot be performed; thereby, the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, and thus the network security can be improved.
[0219] The information interaction method provided in the embodiment of the present application can be executed by the information interaction device, or the fourth network node, or a functional module or entity in the fourth network node. In the embodiment of the present application, the information interaction method executed by the fourth network node is taken as an example to illustrate the information interaction method provided in the embodiment of the present application.
[0220] FIG. 6 shows a flowchart of the information interaction method provided in the embodiment of the present application. As shown in FIG. 6, the information interaction method provided in the embodiment of the present application can include the following step 601.
[0221] Step 601: The fourth network node sends sixth information to the second network node.
[0222] In the embodiment of the present application, the sixth information includes at least one of the following:
[0223] second indication information;
[0224] information related to the first network node;
[0225] first indication information, used to indicate to obtain a fourth authentication parameter, or to indicate that the fourth authentication parameter can be obtained; the fourth authentication parameter is used to perform an authentication operation.
[0226] In the embodiments of the present application, the second indication information includes at least one of the following:
[0227] information related to the third network node;
[0228] information related to the first device;
[0229] information related to the first communication node;
[0230] group identification information;
[0231] service core network node information;
[0232] service network information;
[0233] AIoT capability indication;
[0234] indication information of allowing or not allowing the second operation.
[0235] In the embodiments of the present application, the second operation includes at least one of the following: sending fourth information to the first communication node; receiving fourth information from the third network node, sending the fourth information to the first communication node; receiving first information from the first device, and sending second information to the first network node based on the first information; the first information includes a second authentication parameter, the second authentication parameter is used to perform an authentication operation, and the second information is used to perform an authentication operation; receiving third information sent by the first network node, and sending third authentication parameter to the first device based on the third information; the third information is used to perform an authentication operation, and the third authentication parameter is used to perform an authentication operation; wherein the fourth information includes at least one of the following: fourth authentication parameter; information related to the first network node; first token, used to verify the authentication operation; first indication information, used to indicate to obtain a fourth authentication parameter, or to indicate that the fourth authentication parameter can be obtained; fifth information, used to indicate at least one of the following: paging, inventory, wake-up, command, request, AIoT function.
[0236] In some embodiments of the present application, the second indication information is also used to trigger the second network node to perform the second operation.
[0237] An information interaction method is provided in the embodiments of the present application. A fourth network node can send sixth information to a second network node, the sixth information including second indication information, related information of a first network node, and first indication information indicating that a fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained, the fourth authentication parameter being used to perform an authentication operation. The second indication information includes at least one of the following: related information of a third network node, related information of a first device, related information of a first communication node, group identifier information, service core network node information, service network information, AIoT capability indication, and indication information indicating whether a second operation is allowed or not allowed. The second operation includes at least one of the following: sending fourth information to the first communication node, receiving fourth information from the third network node and sending the fourth information to the first communication node, receiving first information from the first device and sending second information to the first network node based on the first information, the first information including a second authentication parameter used to perform an authentication operation and the second information being used to perform the authentication operation, receiving third information sent by the first network node and sending a third authentication parameter to the first device based on the third information, the third information being used to perform an authentication operation and the third authentication parameter being used to perform the authentication operation. The fourth information includes at least one of the following: the fourth authentication parameter, related information of the first network node, a first token used to verify the authentication operation, the first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained, and fifth information indicating at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.Since the fourth network node can send the second indication information to the second network node to indicate the second network node at least one of the related information of the third network node, the related information of the first device, the related information of the first communication node, the group identifier information, the service core network node information, the service network information, the AIoT capability indication, and the indication information of whether to allow the second operation, the second network node can select a suitable network node or communication node to perform the authentication operation, so that the situation that the authentication operation cannot be performed can be avoided; and / or, since the fourth network node can send the related information of the first network node to the second network node, the second network node can accurately interact with the first network node based on the related information of the first network node to transmit the authentication parameter, so that the situation that the authentication operation cannot be performed due to the failure to transmit the authentication parameter can be avoided; and / or, since the fourth network node can send the first indication information to the second network node to indicate the second network node to obtain the fourth authentication parameter or indicate that the second network node can obtain the fourth authentication parameter, the second network node can timely and accurately obtain the fourth authentication parameter based on which the authentication operation is performed, so that the situation that the authentication operation cannot be performed can be avoided; thereby, the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, so that the network security can be improved.
[0238] The information interaction method provided in the embodiments of the present application can be executed by the information interaction device, or the first device, or a functional module or entity in the first device. In the embodiments of the present application, the information interaction method executed by the first device is taken as an example to illustrate the information interaction method provided in the embodiments of the present application.
[0239] FIG. 7 shows a flowchart of the information interaction method provided in the embodiments of the present application. As shown in FIG. 7, the information interaction method provided in the embodiments of the present application can include the following step 701.
[0240] Step 701: The first device executes a fourth operation.
[0241] In some embodiments of the present application, the first device described above can be specifically an AIoT device.
[0242] In the embodiments of the present application, the fourth operation described above includes at least one of the following:
[0243] receiving a first message carrying a first authentication parameter broadcast by the first communication node, and sending a second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter, the first authentication parameter being used to perform an authentication operation;
[0244] receive a second message broadcast by the first communication node, and send second information to the first communication node or the second network node or the first network node; the second information comprises a second authentication parameter.
[0245] In the embodiments of the present application, the first message comprises at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; the second message comprises at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; the second authentication parameter is used to perform an authentication operation.
[0246] In some embodiments of the present application, the step 701 can be implemented by the following step 701a.
[0247] The step 701a comprises: determining or generating, by the first device based on the first authentication parameter, a second authentication parameter, and sending the second authentication parameter to the first communication node or the second network node or the first network node.
[0248] In some embodiments of the present application, the first device can directly determine the first authentication parameter as the second authentication parameter, or the first device can calculate or deduce the second authentication parameter by using the first authentication parameter.
[0249] As can be seen, since the embodiments of the present application specify the specific steps required to be performed by the first device in the case of receiving the first authentication parameter, the first device can accurately generate the second authentication parameter used to perform the authentication operation according to the specific steps, and send the second authentication parameter to the first communication node or the second network node or the first network node, so that the situation that the authentication operation cannot be performed can be avoided.
[0250] The embodiment of the present application provides an information interaction method, a first device can perform a fourth operation, the fourth operation includes at least one of the following: receiving a first message carrying a first authentication parameter broadcast by a first communication node, sending a second authentication parameter to the first communication node or a second network node or a first network node based on the first authentication parameter; receiving a second message broadcast by the first communication node, and sending second information to the first communication node or the second network node or the first network node; wherein the first message includes at least one of the following: paging message, inventory message, wake-up message, AIoT message; the first authentication parameter is used to perform an authentication operation; the second message includes at least one of the following: paging message, inventory message, wake-up message, AIoT message; the second authentication parameter is used to perform an authentication operation. Since the first device can receive the first message carrying the first authentication parameter broadcast by the first communication node, and send the second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter, the situation that the first device cannot determine which device to send the second authentication parameter to can be avoided, so that the situation that the authentication operation cannot be performed can be avoided; and / or, since the first device can receive the second message broadcast by the first communication node, and send the second information to the first communication node or the second network node or the first network node, the situation that the first device cannot determine when to send the second information to the first communication node or the second network node or the first network node can be avoided, so that the situation that the authentication operation cannot be performed can be avoided; so that the situation that the network node (for example, AAA function) or the device (for example, AIoT device) cannot perform the authentication operation can be reduced, so that the network security can be improved.
[0251] In the following, a complete example will be used to illustrate a possible scheme of the information interaction method provided by the embodiment of the present application.
[0252] As shown in FIG. 8, the information interaction method provided by the embodiment of the present application can include the following steps:
[0253] Step 1, the third network node sends a fourth authentication parameter to the second network node. The third network node can include at least one of the following: AF, NEF, AIoT MF, and the second network node can include at least one of the following: AF, NEF, AIoT MF, AMF. Wherein, the third network node and the second network node are different.
[0254] For example, when the second network node is NEF / AIoT MF / AMF, the third network node is AF. When the second network node is AIoT MF / AMF, the third network node is AF / NEF, etc.
[0255] Step 2, the second network node can obtain authorization information from the fourth network node, for example, at least one of the second indication information, the related information of the first network node and the first indication information. And the second network node can determine whether the fourth network node allows or does not allow to perform the authentication operation according to at least one of the second indication information, the related information of the first network node and the first indication information.
[0256] Step 3, the second network node can send fourth information to the first communication node in the case that the fourth network node allows to perform the authentication operation, and the fourth information carries the fourth authentication parameter.
[0257] Step 4, the first communication node can send the fourth authentication parameter to the first network node.
[0258] Optionally, the above steps 1-4 can be replaced by step 5, which is that the first network node sends the fourth authentication parameter to the second network node. It can be understood that the second network node can send the fourth information to the first communication node, and the fourth information carries the fourth authentication parameter.
[0259] Step 6, the first communication node broadcasts the first message, and the first message carries the first authentication parameter.
[0260] Step 7, the first device sends the first information to the first communication node, and the first information can carry the second authentication parameter.
[0261] It should be noted that the first communication node can also broadcast the second message, so that the first device can obtain or generate the second authentication parameter by itself and send the first information to the first communication node.
[0262] Step 8, the first communication node can send the second information to the first network node through the second network node or directly. In FIG. 8, the first communication node sends the second information to the first network node through the second network node.
[0263] For example, the first communication node can send the second information to the first network node directly through the first session.
[0264] Step 9, the first network node can send the third information to the first communication node through the second network node or directly. In FIG. 8, the first network node sends the third information to the first communication node through the second network node.
[0265] For example, the first network node can send the third information to the first communication node directly through the first session.
[0266] Step 10, the first communication node can send the third authentication parameter to the first device.
[0267] The information interaction method provided by the embodiments of the present application will be illustrated below by taking specific scenarios as examples.
[0268] It should be noted that in the following scenarios, the first network node includes at least one of the following: AAA function, UDM, the second network node includes at least one of the following: AF, NEF, AIoT MF, AMF, the third network node includes at least one of the following: AF, NEF, AIoT MF, the fourth network node is UDM or UDR, and the first device is an AIoT device.
[0269] Scenario one, the first communication node is a terminal.
[0270] As shown in FIG. 9, the information interaction method provided by the embodiments of the present application can include the following steps:
[0271] Step 11: The terminal registers a 5th generation (5G) network, at this time, the terminal can only establish an AIoT related PDU session of the control plane (without user plane (UP) resources).
[0272] Step 12, optionally, the AF (for example, the second network node) requests an authentication parameter Auth Container1 (for example, the fourth authentication parameter) such as including RAND1 from the AAA (for example, the first network node), for example, sending third indication information to request the authentication parameter Auth Container1.
[0273] Step 13, the AF sends an inventory request to the AMF or AIoT MF (for example, the third network node) through the NEF, including an inventory identification Inventory ID and optionally Auth Container1. The Inventory ID can be device ID, vendor ID, group ID, AF ID, etc.
[0274] Step 14, the AMF / AIoT MF selects a Reader based on the content of the inventory request, in this embodiment, the AMF / AIoT MF selects the terminal as the Reader.
[0275] Step 15a, the AMF / AIoT MF requests a query from the UDM, sends a UE ID (such as SUPI or GPSI), and can also send the Inventory ID in step 13, and can also send related information (such as address or ID information) of the AF.
[0276] Step 15b, the information returned by the UDM can include authorization information, and the authorization information includes at least one of the following:
[0277] whether the terminal is allowed or not allowed to be a Reader;
[0278] whether the terminal is allowed or not allowed to perform access to the Inventory ID (e.g. whether the AIoT device identified by the Inventory ID can be inventoried);
[0279] whether the terminal is allowed or not allowed to perform inventory operation for the AF;
[0280] AAA Info (e.g. address information);
[0281] Correspondingly, the subscription data of the terminal in the UDM can include at least one of the following:
[0282] information indicating whether the terminal is allowed or not allowed to be a Reader, Inventory ID information (which can also be an All indication, indicating that all AIoT devices can be inventoried), AAA Info, AF Info;
[0283] The AMF / AIoT MF performs authorization judgment based on the information returned by the UDM (judgment based on authorization information, or judgment as authorization failure if no authorization information is returned).
[0284] It should be noted that step 15 can also be performed after step 20, and is performed once or twice. The AMF / AIoT MF sends the terminal ID and device ID to the UDM for query. Correspondingly, the subscription data of the terminal can include the device ID to implement authorization for the device ID. The authorization information returned by the UDM can also include whether the terminal is allowed or not allowed to perform access (e.g. inventory operation) to the device ID for the AF.
[0285] Step 16a, (e.g. in the case of authorization allowed) optionally, the AMF / AIoT MF sends the terminal ID, Inventory ID, related information of the AF (e.g. AF ID and / or AF address), and at least one of the first token token to the AAA function, such as through an authorization request.
[0286] Step 16b, the AAA function returns an authorization indication (such as success or failure, allow or not allow) to the AMF / AIoT MF and optionally Auth Container1 and optionally token (at least one of Auth Container1 and token can also be used to indicate authorization success), such as returned by an authorization response. Token is an arbitrary string or key used by the AAA function to determine whether to perform an authentication operation, thereby avoiding other terminals from impersonating terminals to insert AIoT devices and AAA functions to complete the authentication process between the agents, causing information leakage.
[0287] Step 16 can also be performed by the AMF / AIoT MF after step 20, or by the SMF.
[0288] Step 17, (such as in the case of authorization allowed) the AMF / AIoT MF sends an inventory request to the UE Reader carrying the Inventory ID and optionally Auth Container1, optionally authorization information (including at least one of the relevant information of the AAA function, token), such as sent by the DL NAS Transport message (for example, the third information). If the terminal Reader is in IDLE state, the AMF / AIoT MF will first trigger the paging operation of the terminal to make the terminal Reader enter the connected state first, and then send the inventory request.
[0289] Step 18, the terminal broadcasts the Inventory ID and optionally Auth Container2 (for example, the first authentication parameter), such as broadcasted by the AIoT paging message, SIB, etc. Among them, the terminal broadcasts the first message in the case of including Auth Container2, and broadcasts the second message in the case of not including Auth Container2. Auth Container2 is generated based on Auth Container1, such as Auth Container1 or information in Auth Container1 or derived from Auth Container1.
[0290] Step 19, the AIoT device (e.g. first device) receives the broadcasted message, judges it is relevant to itself, such as Inventory ID is its device ID or can be derived from its device ID or its information (such as vendor ID, etc.) can derive Inventory ID in the broadcast message, etc., sends a service request (such as Service Request message in AIoT message) to the UE Reader, including device ID or device ID and Auth Container3, such as Auth Container3 includes RES1 and RAND2, RES1 is generated based on RAND1. When step 8 includes Auth Container2, the AIoT device performs an authentication process based on Auth Container2, i.e. part or all of the content in Auth Container3 is generated based on Auth Container2, such as the content obtained by calculating Auth Container2 as a parameter.
[0291] Step 20a, (optionally, based on authorization information) the terminal sends a NAS message (e.g. second information) to the AMF / AIoT MF through the base station, including optionally device ID, optionally Auth Container5 and optionally related information of AAA function, such as carried by Service Request message of NAS.
[0292] Optionally, step 20b, the AMF / AIoT MF sends the above information to the SMF (wherein the related information of AAA function can not come from the terminal); or sends the above information to the SMF through the base station and AMF / AIoT MF, such as carried by PDU Session Modification Request message of NAS. Wherein Auth Container5 includes Auth Container4 and optionally token, or includes Auth Container4 secured based on token, wherein Auth Container4 is generated based on Auth Container3 or device and Auth Container3. The security protection includes at least one of encryption or integrity protection. The terminal can receive multiple device IDs of AIoT devices, and include multiple device IDs and their related Auth Containers in step 20, i.e. aggregation mode.
[0293] In general, the token can be generated and sent by the AMF / AIoT MF to the AAA function and the terminal, or generated and sent by the AAA function to the terminal (via the AMF / AIoT MF).
[0294] Step 21, optionally, the AMF / AIoT MF sends the optional device ID and the optional Auth Container 5 to the AAA function, or the SMF sends the above information to the AAA function through the UPF. For example, sending an AAA Request message carrying the above information, or sending an EAP Request (ID Response) message carrying the above information, wherein the ID field in the EAP Request includes the device ID and the optional Auth Container 5. Optionally, the AAA function judges whether the token is the same as the token received in step 16, and if not, it is not processed, otherwise the subsequent steps 22-26 are executed; or the AAA function processes the Auth Container 5 based on the token of step 16, and if the processing is correct, the subsequent steps 22-26 are executed. The security processing includes at least one of decryption or integrity verification. The security protection operation based on the token can be performed by the AMF / AIoT MF or the SMF. The AMF / AIoT MF / SMF and the AAA function can be based on the EAP protocol, the AMF / AIoT MF / SMF and the terminal can also be based on the EAP protocol, and the terminal and the AIoT device can not be based on the EAP protocol.
[0295] Steps 22a, 22b and 22c, optionally, the AAA function sends the Auth Container 7 to the AIoT device through the UPF, the SMF, the AMF / AIoT MF, the terminal. Or the Auth Container 7 is sent to the AIoT device through the AMF / AIoT MF and the terminal, wherein the terminal sends the Auth Container 7 to the AIoT device, which can be sent through the DL Transport message in the AIoT message, for example. The Auth Container 7 includes, for example, the MAC or RES2, which is generated based on the RAND2. The AAA function can include multiple device IDs and their corresponding Auth Containers in the Auth Container 7, that is, an aggregation manner, and the terminal sends an authentication request to multiple AIoT devices based on the aggregated Auth Container 7.
[0296] Step 23a, Step 23b and Step 23c, optionally, the AIoT device sends an Auth Container 9 to the terminal, wherein the Auth Container 9 can be generated based on the Auth Container 8. The terminal sends an Auth Container 11 to the AAA function through the AMF / AIoT MF, or sends the Auth Container 11 to the AAA function through the AMF / AIoT, SMF, UPF. Wherein the Auth Container 11 includes the Auth Container 10 and optionally token, or includes the Auth Container 10 which is securely protected based on token, the Auth Container 10 is generated based on the Auth Container 9. The token-based security protection operation can be performed by the terminal or the AMF / AIoT MF or the SMF. Optionally, the AAA function judges whether the token is the same as the token received in step 16, if not, it is not processed, otherwise, the subsequent steps 24-26 are executed; or the AAA function securely processes the Auth Container 11 based on the token of step 16, if the processing is correct, the subsequent steps 24-26 are executed. The terminal can include multiple device IDs and their corresponding Auth Container 10 in the Auth Container 11.
[0297] Step 24, optionally, repeat steps 22-23 (Auth Container with different content can be used).
[0298] Step 25, the AAA function authenticates the AIoT device successfully, and can send the obtained device ID to the AF.
[0299] Step 26, the AAA function sends an authentication result indication to the AMF / AIoT MF, optionally, also sends the device ID or multiple device IDs in the case of successful authentication; or the AAA function sends the above information to the SMF through the UPF, and the SMF sends the above information to the AMF / AIoT MF.
[0300] Step 27, after successful authentication, the AMF / AIoT MF sends a NAS message such as a Service Accept message to the terminal, or the SMF sends a NAS message such as a PDU Session Modification Command message to the terminal. The NAS message includes optionally the device ID or multiple device IDs.
[0301] So far, after steps 21-27, the AMF / AIoT MF as Authenticator or the SMF as Authenticator completes the authentication procedure between the AIoT device and the AAA function, which can be one-way authentication or two-way authentication.
[0302] Step 28, optionally, the terminal sends an AIoT message, such as a Service Accept message, to the AIoT device, which can be sent to multiple AIoT devices.
[0303] Step 29, optionally, the AMF / AIoT MF sends an inventory response to the AF through the NEF, including the device ID and optionally the Inventory ID, which can include multiple device IDs.
[0304] Scenario two, the first communication node is a terminal.
[0305] As shown in FIG. 10, the information interaction method provided by the embodiments of the present application can include the following steps:
[0306] Step 31, the difference from scenario one is that the terminal establishes a PDU session with UP resource, which is used to transfer authentication-related information. The network can set the NAT to perform short-term address mapping (one-time mapping - that is, the terminal sends data and releases the mapping address, or releases the mapping address after maintaining for a short period of time) on the AIoT-related PDU session, thereby avoiding the AAA function bypassing the control plane and directly sending data to the terminal through the user plane to perform some operations.
[0307] Steps 32-39 are the same as scenario one.
[0308] Step 40a, the terminal sends optional device ID and optional related information of the AAA function to the AMF / AIoT MF, such as through the Service Request message or UL NAS Transport message of the NAS.
[0309] Step 40b, optionally, the AMF / AIoT MF sends the related information of the AAA function and the optional device ID to the SMF.
[0310] Step 40c, optionally, the SMF configures the UPF based on the related information of the AAA function, so that the terminal can interact data (such as indicating to open the Gate, configuring the PDR and FAR, etc.) with the AAA function through the PDU session (for example, the first session).
[0311] Step 40d, the SMF returns a response to the AMF / AIoT MF, including an optional token (e.g. the first token).
[0312] Step 40e, the AMF / AIoT MF sends an optional token to the terminal, such as through a Service Accept message of NAS.
[0313] Generally, the token can be generated and sent to the AAA function and the terminal by the AMF / AIoT MF, or generated and sent to the AAA function and the terminal by the SMF, or generated and sent to the terminal by the AAA function (through the AMF / AIoT MF or the SMF).
[0314] Step 41, based on the obtained authorization information (such as the relevant information of the AAA), the terminal sends an optional device ID, an optional Auth Container4 and an optional token to the AAA function through the PDU session, the Auth Container4 can be securely protected based on the token, such as sending an AAA Request message carrying the above information, or sending an EAP Request (ID Response) message carrying the above information, wherein the ID field in the EAP Request includes the device ID and / or the Auth Container4, and can also include the token. Optionally, the AAA terminal judges whether the token is the same as the token received in step 36, and if not, it is not processed, otherwise the subsequent steps 42-46 are executed; or the AAA function securely processes the Auth Container4 based on the token of step 36, and if the processing is correct, the subsequent steps 42-46 are executed. Wherein, the Auth Container4 is generated based on the Auth Container3, or the device ID and the Auth Container3. The terminal and the AAA function can be based on the EAP protocol, and the terminal and the AIoT device can not be based on the EAP protocol.
[0315] Steps 42a and 42b, optionally, the AAA function sends an Auth Container7 to the AIoT device through the terminal (through the PDU session), wherein the terminal sends the Auth Container7 to the AIoT device can be sent through the DL Transport message in the AIoT message. The Auth Container7 includes, for example, the MAC or RES2, which is generated based on the RAND2.
[0316] Step 43a and Step 43b, optionally, the AIoT device sends Auth Container9 to the terminal, where Auth Container9 can be generated based on Auth Container8. The terminal sends Auth Container11 to the AAA function through the PDU session. Wherein, Auth Container11 includes Auth Container10 and optionally token, Auth Container10 can be securely protected based on token, and Auth Container10 is generated based on Auth Container9. Optionally, the AAA function judges whether the token is the same as the token received in step 36, and if not, it is not processed, otherwise the subsequent steps 44-46 are executed; or the AAA function securely processes Auth Container10 based on the token of step 36, and if the processing is correct, the subsequent steps 44-46 are executed.
[0317] Step 44, optionally, repeat steps 42-43 (Auth Container with different content can be used).
[0318] Step 45, the AAA function authenticates the AIoT device successfully, and can send the obtained device ID to the AF.
[0319] Step 46, the AAA sends an authentication result indication to the terminal (through the PDU session), and optionally, the device ID is also sent in the case of successful authentication.
[0320] So far, through steps 41-46, the UE Reader as the Authenticator has completed the authentication process between the AIoT device and the AAA function, which can be one-way authentication or two-way authentication.
[0321] Step 48, optionally, the terminal sends an AIoT message, such as a Service Accept message, to the AIoT device.
[0322] Step 49a and Step 49b, optionally, after successful authentication, the terminal sends the device ID and optionally the Inventory ID to the AMF / AIoT MF, such as through the UL NAS Transport message of the NAS. Optionally, the AMF / AIoT MF sends an inventory response to the AF through the NEF, including the device ID and optionally the Inventory ID.
[0323] Optionally, after the UE Reader enters IDLE state or the PDU session is deactivated, the SMF configures the UPF so that the UE Reader cannot interact with the outside through this PDU session.
[0324] Scenario three, the first communication node is an access network device.
[0325] As shown in FIG. 11, the information interaction method and scenario one provided by the embodiments of the present application have the following different steps:
[0326] Step 51, not executed. (The terminal does not need to register in 5G again)
[0327] Step 55a, optionally, the AMF / AIoT MF obtains the related information of the AAA from the UDR / UDM based on the Inventory ID and / or the AF information. Correspondingly, the UDR or UDM saves at least one of the following:
[0328] The relationship between the Inventory ID and the related information of the AAA, and the relationship between the AF ID and the related information of the AAA.
[0329] Step 55b, the AMF / AIoT MF performs authorization judgment based on the returned information, and performs inventory if the authorization information (the related information of the AAA) is included, otherwise not.
[0330] Steps 56a and 56b, the information sent to the AAA function does not include the terminal ID and the token (for example, the first token).
[0331] Step 57, send the Inventory ID and the optional Auth Container1 to the access network device through the N2 message.
[0332] Step 58, broadcast the Inventory ID and the optional Auth Container1 by the access network device.
[0333] Step 59, the message sent by the AIoT device is transparently forwarded to the AMF / AIoT MF by the access network device.
[0334] Step 61, only by AMF / AIoT MF, and the information sent to AAA only includes the device ID received from the AIoT device, or the device ID and the Auth Container3. The AMF / AIoT MF can know the relevant information of the AAA based on the information sent by the AIoT device, such as through the realm part of the device ID. The interaction between the AMF / AIoT MF and the AAA function can be based on the EAP protocol, and the interaction between the AMF / AIoT MF and the AIoT device can not be based on the EAP protocol.
[0335] Steps 62-66, the authentication of the AIoT device and the AAA function is implemented by taking the AIoT MF as the Authenticator. The messages exchanged between the AIoT MF / AMF and the AIoT device are transparently forwarded by the access network device.
[0336] Step 68, sent by the AMF / AIoT MF to the AIoT device.
[0337] Scenario four, the first communication node is a terminal.
[0338] As shown in FIG. 12, the information interaction method provided by the embodiment of the application can include the following steps:
[0339] Step 71, the AIoT AF sends a check command to the AIoT MF through the NEF.
[0340] Step 72, the AIoT MF selects a terminal for checking.
[0341] Step 73, the AIoT MF interacts with the UDM to obtain authorization related information, such as whether the terminal is allowed to serve the AF for checking operation.
[0342] Step 74, if the authorization is passed, the AIoT MF sends a response to the AIoT AF through the NEF.
[0343] Step 75, the AIoT MF sends an AIoT paging command to the terminal (which can be sent through the AMF).
[0344] Step 76, the terminal can interact with the AAA-S through the PDU session before paging (which can be triggered by the AIoT MF sending indication information, and the indication information can be obtained by the AIoT MF through the UDM). The AAA-S can return authentication information, such as a random NONCENW.
[0345] Step 77, the terminal broadcasts the AIoT paging message, which can include an Auth Container containing the authentication information obtained from the AAA-S in step 6.
[0346] Step 78, the AIoT device decides to respond to the AIoT paging and sends an AIoT message to the UE reader carrying the device identity, possibly including another Auth Container containing authentication information, such as the third-party identity and optionally the NONCENW and RES pair.
[0347] Step 79, the terminal as a proxy for the AIoT device interacts with the AAA-S through a PDU session to enable interaction between the AIoT device and the AAA-S, such as using the EAP framework.
[0348] Step 80, the terminal can further interact with the AIoT device to complete authentication if the AAA-S has instructions.
[0349] Step 81, steps 79 and 80 can be repeated (using different authentication parameters).
[0350] Step 82, if the authentication is successful, the terminal will receive an authentication success indication from the AAA-S and optionally device identity information. The terminal sends an AIoT message to the AIoT MF (possibly through the AMF).
[0351] Step 83, the AIoT MF notifies the AIoT AF through the NEF.
[0352] Scenario five, the first communication node is an access network device.
[0353] As shown in FIG. 13, the information interaction method provided by the embodiments of the present application can include the following steps:
[0354] Step 91, the AIoT AF sends an inventory command to the AIoT MF through the NEF.
[0355] Step 92, the AIoT MF selects an access network device for inventory.
[0356] Step 93, the AIoT MF interacts with the UDR to obtain authorization-related information, such as whether the AF is allowed to perform the inventory.
[0357] Steps 94a and 94b, if the authorization is successful, the AIoT MF can interact with the AAA-S (which can be triggered by the AIoT MF obtaining indication information through the UDR) before sending a paging command to the access network device. The AAA-S can return authentication information, such as a random NONCENW.
[0358] Step 95, authorization pass, then the AIoT MF sends a response to the AIoT AF through the NEF.
[0359] Step 96, authorization success, then the AIoT MF sends an AIoT paging command to the access network device (may pass through the AMF), which may include an Auth Container containing the authentication information obtained from the AAA-S in step 4.
[0360] Step 97, the access network device broadcasts an AIoT paging message, which may include an Auth Container containing the authentication information in step 6.
[0361] Step 98, the AIoT device decides to respond to the AIoT paging and sends an AIoT message carrying the device identity to the AIoT MF (through the RAN reader), which may include another Auth Container containing authentication information such as the third-party identity and optionally the NONCE DV and RES pair.
[0362] Step 99, the AIoT MF interacts with the AAA-S as a proxy for the AIoT device to implement the interaction between the AIoT device and the AAA-S, such as using the EAP framework. The AIoT MF may further interact with the AIoT device (through the RAN reader) to complete the authentication if the AAA-S has instructions.
[0363] Step 100, authentication success, then the AIoT MF receives an authentication success indication from the AAA-S and optionally device identity information. The AIoT MF notifies the AIoT AF through the NEF.
[0364] Scenario six, the first communication node is a terminal.
[0365] As shown in FIG. 14, the information interaction method provided by the embodiments of the present application can include the following steps:
[0366] Step 110, the terminal completes 5G network registration.
[0367] Steps 111-115 are the same as steps 71-75 of scenario four.
[0368] Step 116, the terminal broadcasts an AIoT paging message.
[0369] Steps 117a and 117b, the AIoT device decides to respond to the AIoT paging and sends an AIoT message carrying the device identity to the terminal. The terminal sends the AIoT message to the AIoT MF (may pass through the AMF).
[0370] Step 118, the AIoT MF sends a device identity and AIoT indication information request authentication to the UDM through the AUSF.
[0371] Step 119, the UDM generates an authentication vector based on the AIoT indication, including RAND, AUTN, RES*, and possibly generates a key KAIoT for AIoT, and the UDM sends the authentication vector to the AUSF, and the AUSF sends RAND and AUTN to the AIoT MF.
[0372] Steps 120a and 102b, the AIoT MF encapsulates the RAND and AUTN into an Auth Container and sends the AIoT carrying the Auth Container to the terminal (possibly through the AMF).
[0373] Steps 121a and 121b, the AIoT device sends an AIoT message carrying another Auth Container to the terminal, and the Auth Container includes RES*. The terminal sends the AIoT message to the AIoT MF (possibly through the AMF).
[0374] Step 122, the AIoT MF decapsulates the RES* from the Auth Container and sends the RES* to the AUSF for authentication.
[0375] Step 123, if the authentication is successful, the AUSF sends a success indication and optionally KAIoT and device identity (such as SUPI) to the AIoT MF.
[0376] Step 124, the AIoT MF may send KAIoT and device identity (such as GPSI) to the terminal through the AMF.
[0377] Step 125, the AIoT MF notifies the AIoT AF through the NEF.
[0378] Scenario seven, the first communication node is an access network device.
[0379] As shown in FIG. 15, the information interaction method provided by the embodiments of the present application can include the following steps:
[0380] Steps 131-133 are the same as steps 91-93 in scenario five;
[0381] Step 134 is the same as step 95 in scenario five.
[0382] Step 135, if the authorization is successful, the AIoT MF sends an AIoT paging command to the access network device (may pass through the AMF).
[0383] Step 136, the access network device broadcasts the AIoT paging message.
[0384] Step 137, the AIoT device decides to respond to the AIoT paging, and sends an AIoT message carrying the device identifier to the AIoT MF (through the access network device).
[0385] Step 138, the AIoT MF sends the device identifier and AIoT indication information to the UDM through the AUSF for requesting authentication.
[0386] Step 139, the UDM generates an authentication vector based on the AIoT indication, including RAND, AUTN, RES*, and possibly generates a key KAIoT for AIoT, and the UDM sends the authentication vector to the AUSF, and the AUSF sends the RAND and AUTN to the AIoT MF.
[0387] Step 140, the AIoT MF encapsulates the RAND and AUTN into an Auth Container, and sends an AIoT message carrying the Auth Container to the AIoT device (through the RAN reader, and possibly through the AMF).
[0388] Step 141, the AIoT device sends an AIoT message carrying another Auth Container to the AIoT MF (through the RAN reader, and possibly through the AMF), and the Auth Container includes RES*.
[0389] Step 142, the AIoT MF decapsulates the RES* from the Auth Container, and sends the RES* to the AUSF for authentication.
[0390] Step 143, if the authentication is successful, the AUSF sends a success indication, and optionally the KAIoT and the device identifier (such as SUPI) to the AIoT MF.
[0391] Step 144, the AIoT MF notifies the AIoT AF through the NEF.
[0392] The information interaction method provided in the embodiments of the present application, and the execution subject can be an information interaction device. In the embodiments of the present application, the information interaction device executing the information interaction method is taken as an example to illustrate the information interaction device provided in the embodiments of the present application.
[0393] Embodiments of the present application provide an information interaction apparatus. As an example, the information interaction apparatus can be a communication device or a component in the communication device, such as a chip. The communication device can be a terminal, a network-side device, a server, or the like. Exemplarily, the terminal can include, but is not limited to, the types of the terminal 11 listed above, the network-side device can include, but is not limited to, the types of the network-side device 12 listed above, and embodiments of the present application do not make specific limitations.
[0394] The information interaction apparatus includes a receiving module, a sending module, and a processing module. The receiving module, the sending module, and the processing module can be implemented by software or by hardware. When implemented by hardware, the processing module can be implemented by a processor. Exemplarily, the processor can include a general-purpose processor, a special-purpose processor, or the like, such as a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), an artificial intelligent (AI) processor, a graphics processing unit (GPU), an application specific integrated circuit (ASIC), a network processor (NP), a field programmable gate array (FPGA), or other programmable logic devices, a gate circuit, a transistor, a discrete hardware component, or the like. The receiving module and the sending module can be implemented by a communication interface. The communication interface can include one or more of a transceiver, a pin, a circuit, a bus, a radio frequency unit, or the like.
[0395] Specifically, referring to FIG. 16, when the information interaction apparatus is a first communication node or a component in the first communication node, the information interaction apparatus 40 includes at least one of a receiving module 41 and a sending module 42. FIG. 16 schematically shows that the information interaction apparatus 40 includes the receiving module 41 and the sending module 42.
[0396] The information interaction apparatus 40 performs a first operation, and the first operation comprises at least one of the following: the sending module 42 broadcasts a first message; the first message comprises at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first message carries a first authentication parameter, and the first authentication parameter is used to perform an authentication operation; the receiving module 41 receives first information from a first device, and the sending module 42 sends second information to a first network node based on the first information received by the receiving module 41; the first information comprises a second authentication parameter or identification information, and the second information is used to perform an authentication operation or comprises identification information; the second authentication parameter is used to perform an authentication operation; the identification information is used to indicate the first device; the receiving module 41 receives third information from the first network node, and the sending module 42 sends a third authentication parameter to the first device based on the third information received by the receiving module 41; the third information is used to perform an authentication operation; and the third authentication parameter is used to perform an authentication operation.
[0397] The information interaction apparatus provided in the embodiments of the present application can broadcast a first message, receive first information from a first device, send second information to a first network node based on the first information, receive third information from the first network node, and send a third authentication parameter to the first device based on the third information, so that the first authentication parameter and / or the second authentication parameter and / or the third authentication parameter used to perform an authentication operation can be transmitted, and thus, the situation that a network node (for example, an AAA function) or a device (for example, an AIoT device) cannot perform an authentication operation can be reduced, and thus, network security can be improved.
[0398] In some embodiments of the present application, the first operation comprises that the receiving module 41 receives first information from a first device, and the sending module 42 sends second information to a first network node based on the first information received by the receiving module 41; and the sending module 42 is further configured to perform at least one of the following before the information interaction apparatus 40 performs the first operation: broadcast a second message; the second message comprises at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; and broadcast the first message.
[0399] In some embodiments of the present application, the first operation comprises that the sending module 42 broadcasts a first message. The receiving module 41 is further configured to receive a fourth authentication parameter from a first network node before the information interaction apparatus 40 performs the first operation; and the fourth authentication parameter is used to perform an authentication operation. The information interaction apparatus 40 provided in the embodiments of the present application can further comprise a processing module. The processing module broadcasts the first message based on the fourth authentication parameter received by the receiving module 41.
[0400] In some embodiments of the present application, the receiving module 41 further receives fourth information from the second network node; the fourth information comprises at least one of the following: fourth authentication parameters; related information of the first network node; a first token for verifying an authentication operation; first indication information for indicating obtaining the fourth authentication parameters or indicating that the fourth authentication parameters can be obtained, the fourth authentication parameters being used for performing the authentication operation; fifth information for indicating at least one of the following: paging, inventory, wake-up, command, request, AIoT function; the information interaction apparatus 40 provided by the embodiments of the present application can further comprise a processing module. Wherein, the processing module performs at least one of the following based on the fourth information received by the receiving module 41: the fourth information comprises the fourth authentication parameters, and the first message is broadcast based on the fourth authentication parameters; the fourth information comprises the related information of the first network node, and the second information is sent to the first network node based on the related information of the first network node; the fourth information comprises the related information of the first network node, and it is judged whether the received information comes from or does not come from the first network node or the authenticity of the first network node based on the related information of the first network node; the fourth information comprises the first token, and the first token is sent to the first network node; the fourth information comprises the fifth information, and the first message or the second message is broadcast based on the fifth information, the second message comprising at least one of the following: paging message, inventory message, wake-up message, AIoT message; the fourth information comprises at least one of the first indication information and the fifth information, and the fourth authentication parameters are obtained from the first network node based on at least one of the first indication information and the fifth information, and the first message is broadcast based on the fourth authentication parameters; wherein, the fourth authentication parameters are used for performing the authentication operation.
[0401] In some embodiments of the present application, the first operation comprises that the receiving module 41 receives first information from the first device, and the sending module 42 sends second information to the first network node based on the first information. The information interaction apparatus 40 provided by the embodiments of the present application can further comprise a processing module. Wherein, the processing module establishes a first session before the information interaction apparatus 40 performs the first operation, the first session being used for transmitting information interacted by the first device through the information interaction apparatus 40 and the first network node, or being used for transmitting information interacted by the information interaction apparatus 40 on behalf of the first device and the first network node.
[0402] In some embodiments of the present application, the information interaction apparatus 40 is a terminal or an access network device.
[0403] Referring to FIG. 17, when the information interaction apparatus is the second network node or a component in the second network node, the information interaction apparatus 50 comprises at least one of the following: a sending module 51 and a receiving module 52. In FIG. 17, the information interaction apparatus 50 is schematically shown as comprising the sending module 51 and the receiving module 52.
[0404] The information interaction apparatus 50 performs at least one of a second operation and a third operation, the second operation comprising at least one of: the sending module 51 sending fourth information to the first communication node; the receiving module 52 receiving fourth information from the third network node, the sending module 51 sending the fourth information received by the receiving module 52 to the first communication node; the receiving module 52 receiving first information from the first device, the sending module 51 sending second information to the first network node based on the first information received by the receiving module 52; the first information comprising a second authentication parameter used for performing an authentication operation, the second information used for performing an authentication operation; the receiving module 52 receiving third information sent by the first network node, the sending module 51 sending a third authentication parameter to the first device based on the third information received by the receiving module 52; the third information used for performing an authentication operation, the third authentication parameter used for performing an authentication operation; wherein the fourth information comprises at least one of: a fourth authentication parameter; related information of the first network node; a first token used for verifying an authentication operation; first indication information used for indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; fifth information used for indicating at least one of: paging, inventory, wake-up, command, request, AIoT function; the third operation comprising: receiving sixth information from the fourth network node, and performing the second operation based on the sixth information; wherein the sixth information comprises at least one of: second indication information; related information of the first network node; first indication information used for indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; wherein the second indication information comprises at least one of: related information of the third network node; related information of the first device; related information of the first communication node; group identification information; service core network node information; service network information; AIoT capability indication; indication information indicating whether the second operation is allowed or not allowed; wherein the fourth authentication parameter is used for performing an authentication operation.
[0405] The embodiment of the present application provides an information interaction device, and the embodiment of the present application stipulates that the information interaction device can send fourth information to the first communication node, so that the first communication node can obtain the fourth authentication parameter and / or the related information of the first network node and / or the first token and / or the first indication information, thereby enabling the first communication node to accurately obtain the fourth authentication parameter, and / or accurately interact with the first network node, and / or use the same first token as the other network nodes to perform verification, so that the situation that the first communication device cannot perform authentication operation, and / or cannot send the authentication parameter to the first network node, and / or cannot interact with the other network nodes can be reduced; and / or the fourth information is received from the third network node, the fourth information is sent to the first communication node, so that the situation that the information interaction device cannot obtain the fourth information can be avoided, and the first communication node can accurately obtain the fourth authentication parameter, and / or accurately interact with the first network node, and / or use the same first token as the other network nodes to perform verification, so that the situation that the first communication device cannot perform authentication operation, and / or cannot send the authentication parameter to the first network node, and / or cannot interact with the other network nodes can be reduced; and / or the third information is received from the first network node, and the third authentication parameter is sent to the first device based on the third information, so that the first device can obtain the third authentication parameter used for performing the authentication operation. And / or, the information interaction device can obtain the sixth information from the fourth network node and perform the second operation based on the sixth information, so that the situation that the information interaction device cannot perform the second operation due to not obtaining some information in the sixth information can be avoided. Therefore, the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, so that the network security can be improved.
[0406] In some embodiments of the present application, the second operation includes that the sending module 51 sends the fourth information to the first communication node; the fourth information includes the first token, and the receiving module 52 further receives the first token from the first network node.
[0407] In some embodiments of the present application, the second operation includes that the receiving module 52 receives the fourth information from the third network node, and the sending module 51 sends the fourth information to the first communication node; the fourth information includes the first token, and the sending module 51 further sends the first token to the first network node.
[0408] In some embodiments of the present application, the information interaction device 50 provided by the embodiments of the present application can further include: a processing module; performing a second operation based on the sixth information, including at least one of the following: the sixth information includes related information of the first network node, the sending module 51 sends the second information to the first network node based on the related information of the first network node; the sixth information includes related information of the first network node, the processing module judges whether the received information comes from or does not come from the first network node or judges the authenticity of the first network node based on the related information of the first network node; the second operation includes sending fourth information to the first communication node, the sixth information includes first indication information, the receiving module 52 obtains fourth authentication parameters from the first network node based on the first indication information, and the sending module 51 sends the fourth information to the first communication node, and the fourth information includes the fourth authentication parameters; the second operation includes sending fourth information to the first communication node, the sixth information includes service core network node information, the processing module selects the first communication node based on the service core network node information, and sends the fourth information to the first communication node; the second operation includes sending fourth information to the first communication node, and the sixth information includes AIoT capability indication, and the processing module selects the first communication node based on the AIoT capability indication, and sends the fourth information to the first communication node.
[0409] In some embodiments of the present application, the sending module 51 further sends third indication information related to AIoT function to the first network node, and the third indication information is used to obtain at least one of the following: the third information; the first key used for securely processing information interacting with the first device; and the fourth authentication parameter.
[0410] Referring to FIG. 18, when the information interaction device is the first network node or a component in the first network node, the information interaction device 60 includes: a processing module 61.
[0411] The processing module 61 is configured to perform at least one of the following based on the third indication information related to AIoT: generating the third information; generating the first key; generating the fourth authentication parameter; sending the third information to the second network node; sending the first key to the second network node; and sending the fourth authentication parameter to the second network node; wherein the third information is used to perform an authentication operation; wherein the first key is used to securely process information interacting with the first device; and wherein the fourth authentication parameter is used to perform an authentication operation.
[0412] The embodiment of the present application provides an information interaction device, since the information interaction device can generate third information based on third indication information related to an AIoT function, the authentication operation cannot be performed due to the failure in generating the third information can be avoided; and / or, the first key is generated based on the third indication information related to the AIoT function, so that the authentication operation failure due to the failure in safely processing the information interacted with the first device can be avoided; and / or, the fourth authentication parameter is generated based on the third indication information related to the AIoT function, so that the fourth authentication parameter cannot be acquired by other network nodes, thereby avoiding the authentication operation failure; and / or, the third information is sent to the second network node based on the third indication information related to the AIoT function, so that the authentication operation cannot be performed due to the failure in that the third information is not received by the second network node; and / or, the first key is sent to the second network node based on the third indication information related to the AIoT function, so that the authentication operation failure due to the failure in safely processing the information interacted with the first device by the second network node can be avoided; and / or, the fourth authentication parameter is sent to the second network node based on the third indication information related to the AIoT function, so that the fourth authentication parameter cannot be acquired by the second network node, thereby avoiding the authentication operation failure; thereby, the authentication operation failure of the network node (for example, the AAA function) or the device (for example, the AIoT device) can be reduced, and thus the network security can be improved.
[0413] In some embodiments of the present application, the information interaction device 60 provided by the embodiment of the present application can include a receiving module.
[0414] Referring to FIG. 19, when the information interaction device is a fourth network node or a component in the fourth network node, the information interaction device 70 includes a sending module 71.
[0415] The sending module 71 is configured to send sixth information to the second network node, the sixth information comprising at least one of the following: second indication information; related information of the first network node; first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; the fourth authentication parameter is used to perform the authentication operation; wherein the second indication information comprises at least one of the following: related information of the third network node; related information of the first device; related information of the first communication node; group identifier information; service core network node information; service network information; AIoT capability indication; indication information indicating whether the second operation is allowed or not allowed; wherein the second operation comprises at least one of the following: sending fourth information to the first communication node; receiving fourth information from the third network node, sending the fourth information to the first communication node; receiving first information from the first device, and sending second information to the first network node based on the first information; the first information comprises a second authentication parameter used to perform the authentication operation, and the second information is used to perform the authentication operation; receiving third information sent by the first network node, and sending a third authentication parameter to the first device based on the third information; the third information is used to perform the authentication operation, and the third authentication parameter is used to perform the authentication operation; wherein the fourth information comprises at least one of the following: the fourth authentication parameter; related information of the first network node; a first token used to verify the authentication operation; first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; and fifth information indicating at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.
[0416] The embodiment of the present application provides an information interaction device, since the information interaction device can send second indication information to the second network node, at least one of the following information is indicated to the second network node: related information of the third network node, related information of the first device, related information of the first communication node, group identifier information, service core network node information, service network information, AIoT capability indication and indication information of allowing or not allowing the second operation, so that the second network node can select a suitable network node or communication node to perform the authentication operation, so that the situation that the authentication operation cannot be performed can be avoided; and / or, since the information interaction device can send the related information of the first network node to the second network node, so that the second network node can accurately interact with the first network node based on the related information of the first network node to transmit the authentication parameter, so that the situation that the authentication operation cannot be performed due to the failure to transmit the authentication parameter can be avoided; and / or, since the information interaction device can send the first indication information to the second network node to indicate that the second network node acquires the fourth authentication parameter or that the second network node can acquire the fourth authentication parameter, so that the second network node can acquire the fourth authentication parameter in time and accurately, and perform the authentication operation based on the fourth authentication parameter, so that the situation that the authentication operation cannot be performed can be avoided; so that the situation that the network node (for example, AAA function) or the device (for example, AIoT device) cannot perform the authentication operation can be reduced, so that the network security can be improved.
[0417] Referring to FIG. 20, when the information interaction device is the first device or a component in the first device, the information interaction device 80 includes at least one of the following: a receiving module 81, a sending module 82 and a processing module 83. In FIG. 20, the information interaction device 80 is schematically shown as including the receiving module 81 and the sending module 82.
[0418] The information interaction device 80 performs a fourth operation, and the fourth operation includes at least one of the following: the receiving module 81 receives a first message carrying a first authentication parameter broadcast by the first communication node, and the processing module 83 sends a second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter received by the receiving module 81; the first authentication parameter is used to perform an authentication operation; the receiving module 81 receives a second message broadcast by the first communication node, and the sending module 82 sends second information to the first communication node or the second network node or the first network node; the second information includes the second authentication parameter; wherein the first message includes at least one of the following: a paging message, an inventory message, a wake-up message and an AIoT message; wherein the second message includes at least one of the following: a paging message, an inventory message, a wake-up message and an AIoT message; and the second authentication parameter is used to perform an authentication operation.
[0419] The information interaction apparatus provided in the embodiments of the present application can receive the first message carrying the first authentication parameter broadcast by the first communication node, and send the second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter, so that the situation that the information interaction apparatus cannot determine to which device the second authentication parameter is sent can be avoided, and the situation that the authentication operation cannot be performed can be avoided, and thus the situation that the network node (for example, the AAA function) or the device (for example, the AIoT device) cannot perform the authentication operation can be reduced, and thus the network security can be improved.
[0420] In some embodiments of the present application, the processing module 83 is specifically configured to determine or generate the second authentication parameter based on the first authentication parameter, and send the second authentication parameter to the first communication node or the second network node or the first network node.
[0421] The information interaction apparatus provided in the embodiments of the present application can implement each process implemented by the method embodiments of FIGS. 2 to 15, and achieve the same technical effects. To avoid repetition, details are not described herein.
[0422] As shown in FIG. 21, the embodiments of the present application further provide a communication device 90, which includes a processor 91 and a memory 92, and the memory 92 stores programs or instructions executable on the processor 91. For example, when the communication device 90 is a terminal or an AIoT device, the programs or instructions are executed by the processor 91 to implement each step of the information interaction method embodiments on the first communication device side or the first device side, and achieve the same technical effects. When the communication device 90 is a network side device (for example, the first communication device, the second network node, the first network node, or the fourth network node), the programs or instructions are executed by the processor 91 to implement each step of the information interaction method embodiments on the first communication device side, the second network node side, the first network node side, or the fourth network node, and achieve the same technical effects. To avoid repetition, details are not described herein.
[0423] The embodiment of the present application further provides a terminal comprising a processor and a communication interface, wherein the communication interface is coupled with the processor, and the processor is configured to run programs or instructions to implement the steps in the method embodiments shown in FIG. 2 and FIG. 3. The terminal embodiment corresponds to the method embodiment of the first communication node side, and each implementation process and implementation manner of the method embodiment can be applied to the terminal embodiment, and the same technical effects can be achieved. The terminal can be the information interaction device shown in FIG. 16. Specifically, FIG. 22 is a schematic diagram of the hardware structure of a terminal for implementing the embodiment of the present application.
[0424] The terminal 1000 includes, but is not limited to, at least part of components such as a radio frequency unit 1001, a network module 1002, an audio output unit 1003, an input unit 1004, a sensor 1005, a display unit 1006, a user input unit 1007, an interface unit 1008, a memory 1009, and a processor 1010.
[0425] Those skilled in the art can understand that the terminal 1000 can further include a power supply (such as a battery) for supplying power to each component, and the power supply can be logically connected with the processor 1010 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The terminal structure shown in FIG. 22 does not constitute a limitation on the terminal, and the terminal can include more or fewer components than those shown, or combine certain components, or different component arrangements, which will not be described here.
[0426] It should be understood that in the embodiment of the present application, the input unit 1004 can include a graphics processor 10041 and a microphone 10042, and the graphics processor 10041 processes image data of a still picture or a video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1006 can include a display panel 10061, which can be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 1007 includes at least one of a touch panel 10071 and other input devices 10072. The touch panel 10071 is also called a touch screen. The touch panel 10071 can include two parts of a touch detection device and a touch controller. The other input devices 10072 can include, but are not limited to, a physical keyboard, function keys (such as volume control keys, on-off keys, etc.), a trackball, a mouse, a joystick, etc., which will not be described here.
[0427] In the embodiment of the present application, the radio frequency unit 1001 can transmit downlink data from a network side device to the processor 1010 for processing, and can send uplink data to the network side device. Generally, the radio frequency unit 1001 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
[0428] The memory 1009 can be used to store software programs or instructions and various data. The memory 1009 can mainly include a first storage area storing programs or instructions and a second storage area storing data, wherein the first storage area can store an operating system, at least one application program or instruction required by a function (such as a sound playing function, an image playing function, etc.), and the like. In addition, the memory 1009 can include a volatile memory or a non-volatile memory. The non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synch link DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM). The memory 1009 in the embodiments of the present application includes but is not limited to these and any other suitable type of memory.
[0429] The processor 1010 can include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 1010.
[0430] In an example, the terminal can be the first communication node in the above-mentioned embodiments:
[0431] The terminal performs a first operation, and the first operation includes at least one of the following:
[0432] The radio frequency unit 1001 broadcasts a first message; the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first message carries a first authentication parameter, and the first authentication parameter is used to perform an authentication operation.
[0433] The radio frequency unit 1001 receives first information from the first device, and sends second information to the first network node based on the first information; the first information includes a second authentication parameter or identification information, and the second information is used to perform an authentication operation or includes identification information; the second authentication parameter is used to perform an authentication operation; and the identification information is used to indicate the first device.
[0434] The radio frequency unit 1001 receives third information from the first network node, and sends a third authentication parameter to the first device based on the third information; the third information is used to perform an authentication operation; and the third authentication parameter is used to perform an authentication operation.
[0435] The embodiments of the present application provide a terminal, because the embodiments of the present application stipulate that the terminal can broadcast a first message, and / or receive first information from a first device, and send second information to a first network node based on the first information, and / or receive third information from the first network node, and send a third authentication parameter to the first device based on the third information, so as to transmit a first authentication parameter and / or a second authentication parameter and / or a third authentication parameter used to perform an authentication operation, therefore, the situation that a network node (for example, an AAA function) or a device (for example, an AIoT device) cannot perform an authentication operation can be reduced, and thus the network security can be improved.
[0436] In some embodiments of the present application, the first operation includes that the radio frequency unit 1001 receives first information from the first device, and sends second information to the first network node based on the first information;
[0437] The radio frequency unit 1001 further performs at least one of the following before the terminal performs the first operation:
[0438] Broadcast a second message; the second message includes at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message;
[0439] Broadcast a first message.
[0440] In some embodiments of the present application, the first operation includes broadcasting a first message.
[0441] The radio frequency unit 1001 is further configured to receive a fourth authentication parameter from the first network node before the terminal performs the first operation; and the fourth authentication parameter is used to perform an authentication operation.
[0442] The radio frequency unit 1001 is specifically configured to broadcast a first message based on the fourth authentication parameter.
[0443] In some embodiments of the present application, the radio frequency unit 1001 is further configured to receive fourth information from the second network node, wherein the fourth information comprises at least one of the following: fourth authentication parameters; related information of the first network node; a first token used to verify an authentication operation; first indication information used to indicate that the fourth authentication parameters are obtained or that the fourth authentication parameters can be obtained, wherein the fourth authentication parameters are used to perform the authentication operation; and fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.
[0444] The processor 1010 is configured to perform at least one of the following based on the fourth information: when the fourth information comprises the fourth authentication parameters, broadcast the first message based on the fourth authentication parameters; when the fourth information comprises the related information of the first network node, send the second information to the first network node based on the related information of the first network node; when the fourth information comprises the related information of the first network node, determine whether the received information is from or not from the first network node or determine the authenticity of the first network node based on the related information of the first network node; when the fourth information comprises the first token, send the first token to the first network node; and when the fourth information comprises the fifth information, broadcast the first message or the second message based on the fifth information, wherein the second message comprises at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; and when the fourth information comprises at least one of the first indication information and the fifth information, obtain the fourth authentication parameters from the first network node based on at least one of the first indication information and the fifth information, and broadcast the first message based on the fourth authentication parameters.
[0445] In the embodiments of the present application, the fourth authentication parameters are used to perform the authentication operation.
[0446] In some embodiments of the present application, the first operation comprises that the radio frequency unit 1001 receives first information from the first device and sends the second information to the first network node based on the first information.
[0447] The processor 1010 is further configured to establish a first session before the terminal performs the first operation, wherein the first session is used to transmit information exchanged between the first device and the first network node through the terminal, or is used to transmit information exchanged between the terminal and the first network node on behalf of the first device.
[0448] In another example, the terminal can be the first device in the above-mentioned embodiments.
[0449] The terminal performs a fourth operation, wherein the fourth operation comprises at least one of the following:
[0450] The radio frequency unit 1001 receives a first message carrying a first authentication parameter broadcast by the first communication node, and sends a second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter; the first authentication parameter is used to perform an authentication operation.
[0451] The radio frequency unit 1001 receives a second message broadcast by the first communication node, and sends second information to the first communication node or the second network node or the first network node; the second information includes the second authentication parameter.
[0452] The first message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; the second message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; and the second authentication parameter is used to perform an authentication operation.
[0453] The embodiments of the present application provide a terminal. Since the terminal can receive a first message carrying a first authentication parameter broadcast by a first communication node, and send a second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter, the terminal can avoid the situation that it cannot determine to which device to send the second authentication parameter, so that the situation that the authentication operation cannot be performed can be avoided; and / or since the terminal can receive a second message broadcast by the first communication node, and send second information to the first communication node or the second network node or the first network node, the terminal can avoid the situation that it cannot determine when to send the second information to the first communication node or the second network node or the first network node, so that the situation that the authentication operation cannot be performed can be avoided; thereby the situation that the network node (for example, AAA function) or the device (for example, AIoT device) cannot perform the authentication operation can be reduced, so that the network security can be improved.
[0454] In some embodiments of the present application, the processor 1010 is configured to determine or generate the second authentication parameter based on the first authentication parameter.
[0455] The radio frequency unit 1001 is configured to send the second authentication parameter to the first communication node or the second network node or the first network node.
[0456] It can be understood that the implementation process of each implementation manner mentioned in the embodiments can refer to the related description of the method embodiment information interaction method, and achieve the same or corresponding technical effects. To avoid repetition, it will not be described here.
[0457] It should be noted that the device can also implement the steps in the method shown in FIG. 7, or can implement the method executed by each module shown in FIG. 20.
[0458] The embodiment of the present application further provides a network side device, comprising a processor and a communication interface, the communication interface is coupled with the processor, the processor is used for running programs or instructions to realize the steps of the method embodiments shown in FIG. 2 to FIG. 6. The network side device embodiment corresponds to the first communication node, the second network node, the first network node and the fourth network node side method embodiments, and each implementation process and implementation manner of the above method embodiments can be applied to the network side device embodiment, and the same technical effects can be achieved.
[0459] Specifically, the embodiment of the present application further provides a network side device, which can be the information interaction device shown in FIG. 16 to FIG. 19. As shown in FIG. 23, the network side device 2000 comprises an antenna 2001, a radio frequency device 2002, a baseband device 2003, a processor 2004 and a memory 2005. The antenna 2001 is connected with the radio frequency device 2002. In the uplink direction, the radio frequency device 2002 receives information through the antenna 2001, and sends the received information to the baseband device 2003 for processing. In the downlink direction, the baseband device 2003 processes the information to be sent and sends it to the radio frequency device 2002, and the radio frequency device 2002 processes the received information and sends it out through the antenna 2001.
[0460] The method performed by the network side device in the above embodiment can be implemented in the baseband device 2003, which comprises a baseband processor.
[0461] The baseband device 2003 may, for example, comprise at least one baseband board, and a plurality of chips are arranged on the baseband board, as shown in FIG. 23, one of the chips is a baseband processor, which is connected with the memory 2005 through a bus interface to call the programs in the memory 2005 and execute the network device operations shown in the above method embodiments.
[0462] The network side device may, for example, further comprise a network interface 2006, which is a common public radio interface (Common Public Radio Interface, CPRI).
[0463] Specifically, the network side device 2000 of the embodiment of the present application further comprises instructions or programs stored in the memory 2005 and executable on the processor 2004, the processor 2004 calls the instructions or programs in the memory 2005 to execute the methods performed by the modules shown in FIG. 16 to FIG. 19, and achieves the same technical effects. To avoid repetition, it will not be described here.
[0464] Specifically, the embodiment of the present application further provides a network side device. As shown in FIG. 24, the network side device 3000 includes a processor 3001, a network interface 3002 and a memory 3003. The network side device can be the information interaction apparatus shown in FIGS. 17-19. The network interface 3002 is, for example, a common public radio interface (CPRI).
[0465] Specifically, the network side device 3000 of the embodiment of the present application further includes instructions or programs stored in the memory 3003 and executable on the processor 3001. The processor 3001 invokes the instructions or programs in the memory 3003 to perform the method performed by each module shown in FIGS. 17-19 and achieve the same technical effects. To avoid repetition, details are not described herein.
[0466] The embodiment of the present application further provides a readable storage medium having programs or instructions stored thereon. The programs or instructions are executed by a processor to implement each process of the above information interaction method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein.
[0467] The processor is the processor in the terminal described in the above embodiments. The readable storage medium includes a computer readable storage medium, such as a computer readable only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc. In some examples, the readable storage medium can be a non-transitory readable storage medium.
[0468] The embodiment of the present application further provides a chip including a processor and a communication interface. The communication interface is coupled to the processor. The processor is configured to run programs or instructions to implement each process of the above information interaction method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein.
[0469] It should be understood that the chip mentioned in the embodiment of the present application can also be referred to as a system chip, a system on chip, a chip system or a system on chip, etc.
[0470] The embodiment of the present application further provides a computer program / program product stored in a storage medium. The computer program / program product is executed by at least one processor to implement each process of the above information interaction method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein.
[0471] The embodiments of the present application further provide a wireless communication system, comprising: a first communication node, a second network node, a first network node, a fourth network node and a first device, the first communication node is configured to perform the steps of the information interaction method, the second network node is configured to perform the steps of the information interaction method, the first network node is configured to perform the steps of the information interaction method, the fourth network node is configured to perform the steps of the information interaction method, and the first device is configured to perform the steps of the information interaction method,
[0472] It should be noted that, in this document, the terms "comprising", "including", or any other variant thereof are intended to cover a non-exclusive inclusion, such that processes, methods, articles, or apparatuses that comprise a list of elements not only include those elements, but also include other elements not expressly listed or inherent to such processes, methods, articles, or apparatuses. Without further limitation, an element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element. In addition, it should be pointed out that the scope of the methods and apparatuses in the embodiments of the present application is not limited to performing functions in the order shown or discussed, but can also include performing functions in a substantially simultaneous manner or in reverse order, for example, the described methods can be performed in an order different from that described, and various steps can also be added, omitted or combined. In addition, features described with reference to certain examples can be combined in other examples.
[0473] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be realized by means of computer software products and general hardware platforms, of course, they can also be realized by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disc, optical disc, etc.), and includes a plurality of instructions for making the terminal or network side device execute the method described in each embodiment of the present application.
[0474] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above-mentioned specific embodiments, the above-mentioned specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms of embodiments under the inspiration of the present application without departing from the scope of the present application and the scope protected by the claims.
Claims
1. An information interaction method, comprising: a first communication node performing a first operation, the first operation comprising at least one of the following: broadcasting a first message; the first message comprising at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message of low-power physical network; the first message carrying a first authentication parameter, the first authentication parameter being used to perform an authentication operation; receiving first information from a first device, and sending second information to a first network node based on the first information; the first information comprising a second authentication parameter or identification information, the second information being used to perform an authentication operation or comprising the identification information; the second authentication parameter being used to perform an authentication operation; the identification information being used to indicate the first device; receiving third information from the first network node, and sending a third authentication parameter to the first device based on the third information; the third information being used to perform an authentication operation; the third authentication parameter being used to perform an authentication operation.
2. The method of claim 1, wherein, the first operation comprises the receiving first information from the first device, and sending the second information to the first network node based on the first information; before the first communication node performs the first operation, the method further comprises at least one of the following: the first communication node broadcasts a second message; the second message comprising at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; the first communication node broadcasts the first message.
3. The method of claim 1 or 2, wherein, the first operation comprises the broadcasting the first message; before the first communication node performs the first operation, the method further comprises: the first communication node receives a fourth authentication parameter from the first network node; the fourth authentication parameter being used to perform an authentication operation; the first communication node performs the first operation, comprising: the first communication node broadcasts the first message based on the fourth authentication parameter.
4. The method of claim 1 or 2, wherein, the method further comprises: the first communication node receives fourth information from a second network node; the fourth information comprising at least one of the following: a fourth authentication parameter; related information of a first network node; a first token used to verify an authentication operation; first indication information used to indicate obtaining the fourth authentication parameter, or indicating that the fourth authentication parameter can be obtained; fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, AIoT function; the first communication node performs at least one of the following based on the fourth information: the fourth information comprises the fourth authentication parameter, and the first communication node broadcasts the first message based on the fourth authentication parameter; the fourth information comprises the related information of the first network node, and the first communication node sends the second information to the first network node based on the related information of the first network node; the fourth information comprises the related information of the first network node, and the first communication node judges whether the received information is from or not from the first network node, or judges the authenticity of the first network node based on the related information of the first network node; the fourth information comprises the first token, and the first communication node sends the first token to the first network node; The fourth information includes the fifth information, and the first communication node broadcasts the first message or a second message based on the fifth information, the second message including at least one of the following: a paging message, an inventory message, a wake-up message, an AIoT message; The fourth information includes at least one of the first indication information and the fifth information, and the first communication node acquires the fourth authentication parameter from the first network node based on at least one of the first indication information and the fifth information, and broadcasts the first message based on the fourth authentication parameter; The fourth authentication parameter is used to perform an authentication operation.
5. The method of any one of claims 1 to 4, wherein, The first operation includes receiving the first information from the first device, and sending the second information to the first network node based on the first information; Before the first communication node performs the first operation, the method further includes: The first communication node establishes a first session, and the first session is used to transmit information that the first device interacts with the first network node through the first communication node, or is used to transmit information that the first communication node proxies the first device to interact with the first network node.
6. The method of any one of claims 1 to 5, wherein, The first communication node is a terminal or an access network device.
7. An information interaction method, comprising: The second network node performs at least one of a second operation and a third operation, the second operation including at least one of the following: Sending fourth information to a first communication node; Receiving fourth information from a third network node, and sending the fourth information to a first communication node; Receiving first information from a first device, and sending second information to a first network node based on the first information; the first information includes a second authentication parameter used to perform an authentication operation, and the second information is used to perform an authentication operation; Receiving third information sent by a first network node, and sending a third authentication parameter to a first device based on the third information; the third information is used to perform an authentication operation, and the third authentication parameter is used to perform an authentication operation; The fourth information includes at least one of the following: Fourth authentication parameter; Related information of the first network node; First token used to verify an authentication operation; First indication information used to indicate that the fourth authentication parameter is acquired or that the fourth authentication parameter can be acquired; Fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, AIoT function; The third operation includes: receiving sixth information from a fourth network node, and performing the second operation based on the sixth information; The sixth information includes at least one of the following: Second indication information; Related information of the first network node; First indication information used to indicate that the fourth authentication parameter is acquired or that the fourth authentication parameter can be acquired; The second indication information includes at least one of the following: Related information of the third network node; Related information of the first device; Related information of the first communication node; Group identification information; Service core network node information; Service network information; AIoT capability indication; Indication information indicating whether the second operation is allowed or not allowed; The fourth authentication parameter is used for performing an authentication operation.
8. The method of claim 7, wherein, The second operation includes sending fourth information to the first communication node; and the method further includes: The fourth information includes the first token, and the second network node sends the first token to the first network node.
9. The method of claim 7, wherein, The second operation includes receiving fourth information from a third network node and sending the fourth information to the first communication node; and the method further includes: The fourth information includes the first token, and the second network node sends the first token to the first network node.
10. The method of any one of claims 7 to 9, wherein, The second operation based on the sixth information includes at least one of the following: The sixth information includes related information of the first network node, and the second network node sends the second information to the first network node based on the related information of the first network node; The sixth information includes related information of the first network node, and the second network node determines whether the received information is from or not from the first network node or determines the authenticity of the first network node based on the related information of the first network node; The second operation includes sending fourth information to the first communication node, the sixth information includes the first indication information, the second network node acquires the fourth authentication parameter from the first network node based on the first indication information, and sends the fourth information to the first communication node, wherein the fourth information includes the fourth authentication parameter; The second operation includes sending fourth information to the first communication node, the sixth information includes the service core network node information, and the second network node selects the first communication node based on the service core network node information and sends the fourth information to the first communication node; The second operation includes sending fourth information to the first communication node, the sixth information includes the AIoT capability indication, and the second network node selects the first communication node based on the AIoT capability indication and sends the fourth information to the first communication node.
11. The method of any one of claims 7 to 10, wherein, The method further includes: The second network node sends third indication information related to AIoT function to the first network node, and the third indication information is used to acquire at least one of the following: The third information; A first key used for securely processing information interacting with the first device; The fourth authentication parameter.
12. An information interaction method, comprising: A first network node performs at least one of the following based on third indication information related to AIoT function: Generating third information; Generating a first key; Generating a fourth authentication parameter; Sending the third information to a second network node; Sending the first key to the second network node; Sending the fourth authentication parameter to the second network node; The third information is used for performing an authentication operation; The first key is used for securely processing information interacting with the first device; The fourth authentication parameter is used for performing an authentication operation.
13. The method of claim 12, wherein, The method further includes: The first network node receives the third indication information from the second network node.
14. An information interaction method, comprising: The fourth network node sends sixth information to the second network node, the sixth information comprising at least one of: second indication information; related information of the first network node; first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained, the fourth authentication parameter being used to perform the authentication operation; The second indication information comprises at least one of: related information of the third network node; related information of the first device; related information of the first communication node; group identity information; service core network node information; service network information; AIoT capability indication; indication information indicating whether the second operation is allowed or not allowed; The second operation comprises at least one of: sending fourth information to the first communication node; receiving fourth information from the third network node and sending the fourth information to the first communication node; receiving first information from the first device and sending second information to the first network node based on the first information, the first information comprising a second authentication parameter used to perform the authentication operation, and the second information being used to perform the authentication operation; receiving third information sent by the first network node and sending a third authentication parameter to the first device based on the third information, the third information being used to perform the authentication operation, and the third authentication parameter being used to perform the authentication operation; The fourth information comprises at least one of: the fourth authentication parameter; related information of the first network node; a first token used to verify the authentication operation; first indication information indicating that the fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; fifth information indicating at least one of: paging, inventory, wake-up, command, request, and AIoT function.
15. An information interaction method, comprising: The first device performs a fourth operation, the fourth operation comprising at least one of: receiving a first message carrying a first authentication parameter broadcast by a first communication node, and sending a second authentication parameter to the first communication node or a second network node or a first network node based on the first authentication parameter, the first authentication parameter being used to perform an authentication operation; receiving a second message broadcast by the first communication node, and sending second information to the first communication node or the second network node or the first network node, the second information comprising a second authentication parameter; The first message comprises at least one of: a paging message, an inventory message, a wake-up message, and an AIoT message; The second message comprises at least one of: a paging message, an inventory message, a wake-up message, and an AIoT message; The second authentication parameter is used to perform the authentication operation.
16. The method of claim 15, wherein, The sending of the second authentication parameter to the first communication node or the second network node or the first network node based on the first authentication parameter comprises: The first device determines or generates the second authentication parameter based on the first authentication parameter, and sends the second authentication parameter to the first communication node or the second network node or the first network node.
17. An information interaction apparatus, comprising at least one of: a receiving module and a sending module; The information interaction device performs a first operation, and the first operation includes at least one of the following: The sending module broadcasts a first message; the first message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; the first message carries a first authentication parameter, and the first authentication parameter is used to perform an authentication operation; The receiving module receives first information from a first device, and the sending module sends second information to a first network node based on the first information received by the receiving module; the first information includes a second authentication parameter or identification information, and the second information is used to perform an authentication operation or includes the identification information; the second authentication parameter is used to perform an authentication operation; and the identification information is used to indicate the first device; The receiving module receives third information from a first network node, and the sending module sends a third authentication parameter to a first device based on the third information received by the receiving module; the third information is used to perform an authentication operation; and the third authentication parameter is used to perform an authentication operation.
18. The apparatus of claim 17, wherein, The first operation includes that the receiving module receives first information from a first device, and the sending module sends second information to a first network node based on the first information received by the receiving module; Before the information interaction device performs the first operation, the sending module further performs at least one of the following: Broadcast a second message; the second message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; Broadcast the first message.
19. The apparatus of claim 17 or 18, wherein, The first operation includes that the sending module broadcasts a first message; Before the information interaction device performs the first operation, the receiving module further receives a fourth authentication parameter from a first network node; The fourth authentication parameter is used to perform an authentication operation; The information interaction device further includes a processing module; The processing module broadcasts the first message based on the fourth authentication parameter received by the receiving module.
20. The apparatus of claim 17 or 18, wherein, The receiving module further receives fourth information from a second network node; the fourth information includes at least one of the following: A fourth authentication parameter; Related information of a first network node; A first token used to verify an authentication operation; First indication information used to indicate that the fourth authentication parameter is obtained or that the fourth authentication parameter used to perform an authentication operation can be obtained; Fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, and AIoT function; The information interaction device further includes a processing module; The processing module performs at least one of the following based on the fourth information received by the receiving module: The fourth information includes the fourth authentication parameter, and the first message is broadcast based on the fourth authentication parameter; The fourth information includes related information of the first network node, and the second information is sent to the first network node based on the related information of the first network node; The fourth information includes related information of the first network node, and based on the related information of the first network node, it is determined whether the received information comes from or does not come from the first network node, or the authenticity of the first network node is determined; The fourth information includes the first token, and the first token is sent to the first network node; The fourth information includes the fifth information, and based on the fifth information, the first message or a second message is broadcasted, the second message including at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message; The fourth information includes at least one of the first indication information and the fifth information, and based on at least one of the first indication information and the fifth information, the fourth authentication parameter is obtained from the first network node, and based on the fourth authentication parameter, the first message is broadcasted. The fourth authentication parameter is used to perform an authentication operation.
21. The apparatus of any one of claims 17-20, wherein, The first operation includes that the receiving module receives the first information from the first device, and the sending module sends the second information to the first network node based on the first information. The information interaction apparatus further includes a processing module. The processing module establishes a first session before the information interaction apparatus performs a first operation, the first session being used to transmit information exchanged between the first device and the first network node through the information interaction apparatus, or being used to transmit information exchanged between the first device and the first network node by the information interaction apparatus as a proxy.
22. The apparatus of any one of claims 17-21, wherein, The information interaction apparatus is a terminal or an access network device.
23. An information interaction apparatus, the information interaction apparatus including at least one of the following: a sending module and a receiving module; The information interaction apparatus performs at least one of a second operation and a third operation, the second operation including at least one of the following: The sending module sends fourth information to a first communication node; The receiving module receives fourth information from a third network node, and the sending module sends the fourth information received by the receiving module to the first communication node; The receiving module receives first information from a first device, and the sending module sends second information to a first network node based on the first information received by the receiving module; the first information includes a second authentication parameter, the second authentication parameter being used to perform an authentication operation, and the second information being used to perform an authentication operation; The receiving module receives third information sent by a first network node, and the sending module sends a third authentication parameter to a first device based on the third information received by the receiving module; the third information is used to perform an authentication operation, and the third authentication parameter is used to perform an authentication operation; wherein The fourth information includes at least one of the following: A fourth authentication parameter; Related information of a first network node; A first token used to verify an authentication operation; First indication information used to indicate that a fourth authentication parameter is obtained or that a fourth authentication parameter can be obtained; Fifth information used to indicate at least one of the following: paging, inventory, wake-up, command, request, and AIoT function; The third operation comprises: receiving sixth information from the fourth network node, and performing the second operation based on the sixth information; The sixth information comprises at least one of the following: Second indication information; Related information of the first network node; First indication information, used for indicating that the fourth authentication parameter is acquired, or indicating that the fourth authentication parameter can be acquired; The second indication information comprises at least one of the following: Related information of the third network node; Related information of the first device; Related information of the first communication node; Group identification information; Service core network node information; Service network information; AIoT capability indication; Indication information indicating whether the second operation is allowed or not allowed; The fourth authentication parameter is used for performing an authentication operation.
24. The apparatus of claim 23, wherein, The second operation comprises that the sending module sends fourth information to the first communication node; The fourth information comprises the first token, and the receiving module further receives the first token from the first network node.
25. The apparatus of claim 23, wherein, The second operation comprises that the receiving module receives fourth information from the third network node, and the sending module sends the fourth information to the first communication node; The fourth information comprises the first token, and the sending module further sends the first token to the first network node.
26. The apparatus of any one of claims 23-25, wherein, The information interaction apparatus further comprises a processing module; the performing the second operation based on the sixth information comprises at least one of the following: The sixth information comprises related information of the first network node, and the second network node sends the second information to the first network node based on the related information of the first network node; The sixth information comprises related information of the first network node, and the second network node judges whether the received information is from or not from the first network node, or judges the authenticity of the first network node based on the related information of the first network node; The second operation comprises that the fourth information is sent to the first communication node, the sixth information comprises the first indication information, the second network node acquires the fourth authentication parameter from the first network node based on the first indication information, sends the fourth information to the first communication node, and the fourth information comprises the fourth authentication parameter; The second operation comprises that the fourth information is sent to the first communication node, the sixth information comprises the service core network node information, the second network node selects the first communication node based on the service core network node information, and sends the fourth information to the first communication node; The second operation comprises that the fourth information is sent to the first communication node, the sixth information comprises the AIoT capability indication, the second network node selects the first communication node based on the AIoT capability indication, and sends the fourth information to the first communication node.
27. The apparatus of any one of claims 23-26, wherein, The sending module further sends third indication information related to an AIoT function to the first network node, and the third indication information is used for acquiring at least one of the following: The third information; A first key used for securely processing information interacted with the first device; The fourth authentication parameter.
28. An information interaction device, the information interaction device comprising: A processing module; The processing module is configured to perform at least one of the following based on third indication information related to the AIoT function: generating third information; generating a first key; generating a fourth authentication parameter; sending the third information to a second network node; sending the first key to the second network node; sending the fourth authentication parameter to the second network node; wherein the third information is used to perform an authentication operation; wherein the first key is used to securely process information interacting with the first device; wherein the fourth authentication parameter is used to perform an authentication operation.
29. The apparatus of claim 28, wherein, The information interaction apparatus further includes a receiving module. The receiving module is configured to receive the third indication information from the second network node.
30. An information interaction device, the information interaction device comprising: a sending module; The sending module is configured to send sixth information to a second network node, the sixth information including at least one of the following: second indication information; related information of the first network node; first indication information indicating that a fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; the fourth authentication parameter is used to perform an authentication operation; wherein the second indication information includes at least one of the following: related information of a third network node; related information of the first device; related information of the first communication node; group identification information; service core network node information; service network information; AIoT capability indication; indication information indicating whether a second operation is allowed or not allowed; wherein the second operation includes at least one of the following: sending fourth information to the first communication node; receiving fourth information from the third network node and sending the fourth information to the first communication node; receiving first information from the first device and sending second information to the first network node based on the first information; the first information includes a second authentication parameter used to perform an authentication operation, and the second information is used to perform an authentication operation; receiving third information sent by the first network node and sending a third authentication parameter to the first device based on the third information; the third information is used to perform an authentication operation, and the third authentication parameter is used to perform an authentication operation; wherein the fourth information includes at least one of the following: a fourth authentication parameter; related information of the first network node; a first token used to verify an authentication operation; first indication information indicating that a fourth authentication parameter is obtained or that the fourth authentication parameter can be obtained; fifth information indicating at least one of the following: paging, inventory, wake-up, command, request, and AIoT function.
31. An information interaction apparatus, including at least one of the following: a receiving module, a sending module, and a processing module; The information interaction apparatus performs a fourth operation, which includes at least one of the following: The receiving module receives a first message carrying a first authentication parameter broadcast by a first communication node, and the processing module sends a second authentication parameter to the first communication node, a second network node, or a first network node based on the first authentication parameter received by the receiving module; the first authentication parameter is used to perform an authentication operation; The receiving module receives a second message broadcast by a first communication node, and the sending module sends second information to the first communication node or the second network node or the first network node; the second information includes a second authentication parameter; wherein, The first message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message. The second message includes at least one of the following: a paging message, an inventory message, a wake-up message, and an AIoT message. The second authentication parameter is used to perform an authentication operation.
32. The apparatus of claim 31, wherein, The processing module is specifically configured to determine or generate the second authentication parameter based on the first authentication parameter, and send the second authentication parameter to the first communication node or the second network node or the first network node. 33.A terminal comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions being executed by the processor to implement the steps of the information interaction method according to any one of claims 1 to 6, or the steps of the information interaction method according to claim 16 or 17. 34.A network-side device comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions being executed by the processor to implement the steps of the information interaction method according to any one of claims 1 to 15.
35. A wireless communication system, comprising: The first communication node is configured to implement the steps of the information interaction method according to any one of claims 1 to 6, the second network node is configured to implement the steps of the information interaction method according to any one of claims 7 to 11, the first network node is configured to implement the steps of the information interaction method according to claim 12 or 13, the fourth network node is configured to implement the steps of the information interaction method according to claim 14, and the first device is configured to implement the steps of the information interaction method according to claim 15 or 16. 36.A readable storage medium, the readable storage medium storing programs or instructions, the programs or instructions being executed by a processor to implement the steps of the information interaction method according to any one of claims 1 to 16.
Citation Information
Patent Citations
Terminal management method and core network equipment
CN116567780A
Information sending method and device, information obtaining method and device, electronic equipment and storage medium
CN117729541A
Communication method and communication device
CN118265032A
Reader-writer management method, terminal and network side equipment
CN118283611A
Authorizing wireless communication devices to communicate with ambient devices
WO2024088605A1