Authentication method, communication device, communication system and storage medium
By using a two-way authentication method between IoT devices to generate and verify random numbers, responses, and information, the problem of authentication accuracy and security when IoT devices do not store keys is solved, thus achieving communication stability and security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2025-01-15
- Publication Date
- 2026-07-23
AI Technical Summary
In communication between IoT devices, how to ensure the accuracy and security of the authentication process and prevent communication fraud, especially how to trigger authentication when IoT devices do not store keys.
IoT devices perform two-way authentication by sending requests and receiving messages, including generating and verifying random numbers, responses, messages, and keys, to ensure the accuracy and security of the authentication process.
It enables secure authentication between IoT devices, prevents communication fraud, ensures communication stability and data security, and avoids resource waste.
Smart Images

Figure CN2025072609_23072026_PF_FP_ABST
Abstract
Description
Authentication methods, communication equipment, communication systems, storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to authentication methods, communication devices, communication systems, and storage media. Background Technology
[0002] Internet of Things (IoT) devices have been introduced into communication systems. Summary of the Invention
[0003] This disclosure proposes authentication methods, communication equipment, communication systems, and storage media.
[0004] According to a first aspect of the present disclosure, an authentication method is provided, performed by a first device, the method comprising: sending a first request to a second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; receiving a first message sent by the second device, the first message being used by the first device to authenticate the second device; and authenticating the second device based on the first message.
[0005] According to a second aspect of the present disclosure, an authentication method is provided, performed by a second device, the method comprising: receiving a first request sent by a first device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; and sending a first message to the first device, the first message being used by the first device to authenticate the second device.
[0006] According to a third aspect of the present disclosure, an authentication method is provided for a communication system, the communication system including a first device and a second device, the method comprising: the first device sending a first request to the second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the second device sending a first message to the first device, the first message being used by the first device to authenticate the second device; and the first device authenticating the second device based on the first message.
[0007] According to a fourth aspect of the present disclosure, a first device is provided, comprising: a transceiver module configured to send a first request to a second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the transceiver module further configured to receive a first message sent by the second device, the first message being used by the first device to authenticate the second device; and a processing module configured to authenticate the second device based on the first message.
[0008] According to a fifth aspect of the present disclosure, a second device is provided, comprising: a transceiver module configured to receive a first request sent by a first device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the transceiver module is further configured to send a first message to the first device, the first message being used by the first device to authenticate the second device.
[0009] According to a sixth aspect of the present disclosure, a communication device is provided, comprising:
[0010] One or more processors;
[0011] The processor is configured to invoke instructions to cause the communication device to execute any of the authentication methods described in the first or second aspect.
[0012] According to a seventh aspect of the present disclosure, a communication system is provided, including a second device and a first device, wherein the first device is configured to implement the authentication method described in the first aspect, and the second device is configured to implement the authentication method described in the second aspect.
[0013] According to an eighth aspect of the present disclosure, a storage medium is provided that stores instructions that, when executed on a communication device, cause the communication device to perform an authentication method as described in any of the first to second aspects.
[0014] In a ninth aspect, embodiments of this disclosure provide a program product, including a computer program that, when executed by a communication device, implements the authentication methods described in the first and second aspects.
[0015] In a tenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the authentication methods described in the first and second aspects.
[0016] It is understood that the aforementioned network devices, terminals, communication devices, communication systems, storage media, program products, and computer programs are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here. Attached Figure Description
[0017] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which:
[0018] Figure 1A is a schematic diagram of the architecture of some communication systems provided in the embodiments of this disclosure;
[0019] Figures 1B-1C are schematic diagrams illustrating the architecture of a first device communicating according to an embodiment of the present disclosure;
[0020] Figure 2 is an interactive schematic diagram of an authentication method provided in an embodiment of this disclosure;
[0021] Figures 3A-3D are schematic flowcharts of an authentication method provided in another embodiment of this disclosure;
[0022] Figure 4 is an interactive schematic diagram of the authentication method provided in another embodiment of this disclosure;
[0023] Figure 5A is a schematic diagram of the structure of a first device provided in an embodiment of this disclosure;
[0024] Figure 5B is a schematic diagram of the structure of a second device provided in an embodiment of this disclosure;
[0025] Figure 6A is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;
[0026] Figure 6B is a schematic diagram of the structure of a chip provided in an embodiment of this disclosure. Detailed Implementation
[0027] This disclosure provides an authentication method, communication device, communication system, and storage medium.
[0028] In a first aspect, embodiments of this disclosure propose an authentication method executed by a first device. The method includes: sending a first request to a second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; receiving a first message sent by the second device, the first message being used by the first device to authenticate the second device; and authenticating the second device based on the first message.
[0029] In the above embodiments, the first device can send a first request to the second device to request the activation of authentication between the second device and the first device. The second device will send a first message to the first device so that the first device can authenticate the second device based on the first message. Thus, communication authentication is performed between the first device and the second device, which can ensure the security of communication between the second device and the first device, avoid communication fraud, and ensure communication stability.
[0030] In conjunction with some embodiments of the first aspect, in some embodiments, sending the first request to the second device includes: the first device not storing at least one of a first key and a second key, and sending the first request to the second device; wherein the first key is used to protect the confidentiality of at least one of data, information, and signaling between the first device and the second device, and the second key is used to protect the integrity of at least one of data, information, and signaling between the first device and the second device.
[0031] In the above embodiments, the preconditions for the first device to send the first request were described. Optionally, when the first device does not store a key for confidentiality protection and / or integrity protection, the first device may send a first request to the second device to request the triggering of authentication between the second device and the first device. This clarifies the timing of the first device requesting authentication, ensuring that the first device can request to trigger authentication at an appropriate time, guaranteeing the accuracy of the authentication method execution, and preventing the first device from triggering authentication at unnecessary times, thus avoiding resource waste caused by unnecessary authentication.
[0032] In conjunction with some embodiments of the first aspect, in some embodiments, the first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, and one or more first identifiers; wherein the first indication is used to indicate the function of the first request, and the one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
[0033] In conjunction with some embodiments of the first aspect, in some embodiments, the first message includes at least one of the following: a second random number generated by the second device, a first response, first information, a first verification value, and a second identifier for indicating a second security algorithm; wherein, the second security algorithm is used to protect the confidentiality and / or integrity of at least one of data, information, and signaling between the first device and the second device, the second security algorithm is any first security algorithm, the first response is used by the first device to authenticate the second device, and the first response is generated based on at least one of the device identifier of the first device, the first random number, the second random number, and a third key; the first information includes information that the second device needs to send to the first device, the first information is protected by a first key, and the first verification value is used by the first device to authenticate the second device, and the first verification value is generated based on the second key.
[0034] In some embodiments, in conjunction with the first aspect, the method further includes: generating a second response based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key; and generating at least one of the first key and the second key.
[0035] In conjunction with some embodiments of the first aspect, in some embodiments, authenticating the second device based on the first message includes: verifying the first response based on the second response, and / or verifying the first verification value based on the second key; the authentication of the second device based on the first message further includes at least one of the following: the first response verification passes, and / or the first verification value verification passes, determining that the second device authentication is successful; the first response verification fails, and / or the first verification value verification fails, determining that the second device authentication fails.
[0036] In the above embodiments, it is explained how the first device specifically authenticates the second device so that the first device can accurately authenticate the second device, thereby ensuring the communication security between the second device and the first device, avoiding communication fraud, and ensuring communication stability.
[0037] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: the second device being authenticated, storing at least one of the device identifier, first key, and second key of the first device, and sending first data to the second device, the first data being data that the first device needs to send to the second device, the first data being protected by the first key and / or the second key.
[0038] In the above embodiments, when the second device is authenticated, the first device can communicate with the second device based on the key, thereby further ensuring the security of the communication data between the first device and the second device, preventing the leakage of the communication data between the first device and the second device, and ensuring communication stability.
[0039] Secondly, this disclosure provides an authentication method executed by a second device, the method comprising: receiving a first request sent by a first device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; and sending a first message to the first device, the first message being used by the first device to authenticate the second device.
[0040] In conjunction with some embodiments of the second aspect, in some embodiments, the first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, and one or more first identifiers; wherein the first indication is used to indicate the function of the first request, and the one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
[0041] In some embodiments, in conjunction with the second aspect, the method further includes: generating a second random number; sending a second request to a third device, the second request including a device identifier of the first device, the second request being used to request at least one of a third key and a second security algorithm; wherein the second security algorithm is used to perform confidentiality protection and / or integrity protection on at least one of data, information, and signaling between the first device and the second device, and the second security algorithm is any first security algorithm; receiving at least one of the third key and a second identifier indicating the second security algorithm sent by the third device; generating a first response based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key, the first response being used by the first device to authenticate the second device; generating at least one of a first key and a second key; wherein the first key is used to perform confidentiality protection on at least one of data, information, and signaling between the first device and the second device, and the second key is used to perform integrity protection on at least one of data, information, and signaling between the first device and the second device; protecting first information based on the first key, the first information including information that the second device needs to send to the first device; generating a first verification value based on the second key, the first verification value being used by the first device to authenticate the second device.
[0042] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: generating a second random number; sending a third request to a third device, the third request including at least one of the following: a device identifier of the first device, a first random number, a second random number, and a second identifier for indicating a second security algorithm; the third request is used to request at least one of a first response, a first key, and a second key; receiving at least one of the first response, the first key, and the second key sent by the third device, the first response being generated based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key; protecting first information based on the first key, the first information including information that the second device needs to send to the first device; and generating a first verification value based on the second key.
[0043] In conjunction with some embodiments of the second aspect, in some embodiments, the first message includes at least one of the following: a second random number, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm.
[0044] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: receiving first data sent by the first device, the first data being data that the first device needs to send to the second device; performing security verification on the first data based on a second key, wherein the first data passes the security verification, determining that the first device has been authenticated by the second device, and storing at least one of the device identifier of the first device, the first key, and the second key.
[0045] Thirdly, this disclosure provides an authentication method for a communication system, the communication system including a first device and a second device, the method including: the first device sending a first request to the second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the second device sending a first message to the first device, the first message being used by the first device to authenticate the second device; the first device authenticating the second device based on the first message.
[0046] Fourthly, this disclosure provides a first device, comprising: a transceiver module, configured to send a first request to a second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the transceiver module is further configured to receive a first message sent by the second device, the first message being used by the first device to authenticate the second device; and a processing module, configured to authenticate the second device based on the first message.
[0047] Fifthly, this disclosure provides a second device, comprising: a transceiver module, configured to receive a first request sent by a first device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the transceiver module is further configured to send a first message to the first device, the first message being used by the first device to authenticate the second device.
[0048] In a sixth aspect, embodiments of this disclosure provide a communication device comprising: one or more processors; one or more memories for storing instructions; wherein the processors are configured to invoke the instructions to cause the communication device to perform the methods described in the first aspect, the optional implementation of the first aspect, the second aspect, and the optional implementation of the second aspect.
[0049] In a seventh aspect, embodiments of this disclosure provide a communication system comprising: a first device and a second device; wherein the first device is configured to perform the method described in the first aspect and optional implementations thereof, and the second device is configured to perform the method described in the second aspect and optional implementations thereof.
[0050] Eighthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect, an optional implementation of the first aspect, the second aspect, and an optional implementation of the second aspect.
[0051] In a ninth aspect, embodiments of this disclosure provide a program product including a computer program that, when executed by a processor, implements the methods described in the first aspect, the optional implementation of the first aspect, the second aspect, and the optional implementation of the second aspect.
[0052] In a tenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect, an optional implementation of the first aspect, the second aspect, and an optional implementation of the second aspect.
[0053] It is understood that the aforementioned network devices, terminals, communication devices, communication systems, storage media, program products, and computer programs are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0054] This disclosure provides embodiments of authentication methods, communication devices, communication systems, and storage media. In some embodiments, terms such as authentication method and information processing method may be used interchangeably.
[0055] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments. In all embodiments of this disclosure, unless otherwise specified or logically conflicting, the terminology and / or descriptions between the embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0056] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0057] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0058] In the embodiments disclosed herein, "multiple" refers to two or more.
[0059] In some embodiments, the terms "at least one of A or B, at least one of A and B", "one or more", "a plurality of", "multiple" and the like can be used interchangeably.
[0060] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.
[0061] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.
[0062] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0063] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0064] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.
[0065] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.
[0066] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0067] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.
[0068] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
[0069] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.
[0070] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.
[0071] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0072] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0073] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0074] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0075] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0076] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure. As shown in Figure 1A, the communication system 100 may include a core network device and a first device; wherein, the first device and the core network device can communicate through a reader, and optionally, the reader may include at least one of an access network device and a terminal.
[0077] In some embodiments, the first device does not require a battery; it can collect ambient energy and / or artificial energy to power normal uplink and downlink transmission. Optionally, the ambient energy may include natural energy sources such as solar, wind, and nuclear energy, and the artificial energy may include energy such as electromagnetic waves emitted by artificial devices. In some embodiments, the first device may also be referred to as: Ambient Internet of Things (A-IoT) device, Internet of Things (IoT) device, low-power device, low-power ambient IoT device, A-IoT Device, A-IoT UE, A-IoT terminal, A-IoT Tag, tag, IoT terminal, etc.
[0078] In some embodiments, the terminal includes, but is not limited to, at least one of the following: mobile phone, wearable device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.
[0079] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system, but is not limited thereto.
[0080] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0081] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0082] In some embodiments, the core network equipment may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, including all or part of the second device and the third device, respectively. Network elements may be virtual or physical. The core network may include, for example, at least one of the following: Evolved Packet Core (EPC), 5G Core Network (5GCN), 6G Core Network (6GCN), and Next Generation Core (NGC).
[0083] Optionally, in some embodiments, the second device described above can be used to provide access and mobility management functions, such as an Access and Mobility Management Function (AMF) network element. Alternatively, the second device can be used to provide Internet of Things (IoT) functions, such as an Internet of Things Function (IoTF) network element or an Ambient Internet of Things Function (AIoTF) network element.
[0084] Optionally, in some embodiments, the third device can be used to provide unified data management functions, such as a Unified Data Management (UDM) network element; or, the third device can be used to provide unified data warehousing functions, such as a Unified Data Repository (UDR) network element. Alternatively, in some embodiments, the third device can be an application server.
[0085] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0086] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1A, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1A are illustrative. The communication system may include all or some of the main bodies in FIG1A, or it may include other main bodies outside of FIG1A. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0087] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future Generation Radio Access (FX), Global System for Mobile Communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other authentication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0088] Optionally, the aforementioned first device does not require a battery; it can collect ambient energy and / or artificial energy to supply normal uplink and downlink transmission. Optionally, the ambient energy may include natural energy sources such as solar, wind, and nuclear energy, and the artificial energy may include energy such as electromagnetic waves emitted by artificial devices. In some embodiments, the first device may also be referred to as: Ambient Internet of Things (A-IoT) device, Internet of Things (IoT) device, low-power device, low-power ambient IoT device, A-IoT Device, A-IoT UE, A-IoT terminal, A-IoT Tag, tag, IoT terminal, etc.
[0089] In some embodiments, the first device can be applied to a variety of different communication architectures in the communication system. Optionally, Figures 1B-1C are schematic diagrams of the architecture of the first device communicating according to embodiments of the present disclosure.
[0090] Optionally, as shown in Figure 1B, the first device (i.e., the Ambient IoT device in Figure 1B) and the network device (i.e., the base station (BS) in Figure 1B) can directly receive and send data.
[0091] Optionally, as shown in Figure 1C, the first device (i.e., the Ambient IoT device in Figure 1C) and the network device (i.e., the base station (BS) in Figure 1C) can indirectly receive and send data through an intermediate node. Optionally, the intermediate node can also be called an auxiliary node. The intermediate node can be, for example, any of the following: relay, integrated access backhaul (IAB) device, terminal, or repeater.
[0092] Optionally, in some embodiments, the network devices (i.e., BS) and intermediate nodes (or auxiliary nodes) in Figures 1B and 1C can be collectively referred to as readers.
[0093] Optionally, the data transmitted between the Reader and the first device may include the following three service types: Device-terminated (DT), Device-originated–device-terminated triggered (DO-DTT), and Device-originated-autonomous (DO-A).
[0094] Optionally, both the aforementioned DT data and DO-DTT data require network triggering to be sent, while the aforementioned DO-A data can be actively triggered by the first device. The DO-A service type can provide more flexibility on both the first device side and the network side.
[0095] Optionally, DO-A service types pose a greater risk than DT or DO-DTT service types. For example, attackers can easily launch a Denial of Service (DoS) attack on the CN by creating a network of multiple unauthorized first devices to actively send false data. Therefore, how to implement one-way or two-way authentication for DO-A service types to ensure the confidentiality and integrity of information sent by the first devices is a pressing issue that needs to be addressed.
[0096] Figure 2 is an interactive schematic diagram of an authentication method according to an embodiment of the present disclosure. As shown in Figure 2, this embodiment of the disclosure relates to an authentication method for a communication system 100; the method includes:
[0097] Step 2101: The first device sends a first request to the second device.
[0098] In some embodiments, the second device may receive a first request sent by the first device, but is not limited thereto. The second device may also receive a first request sent by a subject other than the first device, in which case step 2101 may be omitted.
[0099] Optionally, the first device may also be referred to as an A-IoT device, a low-power device, a low-power environment IoT device, an A-IoT UE, an A-IoT terminal, an A-IoT tag, a tag, an IoT device, an IoT terminal, etc. For a detailed description of the first device, please refer to the description preceding the embodiment shown in Figure 2.
[0100] Optionally, the second device can be used to provide access and mobility management functions, such as an Access and Mobility Management Function (AMF) network element. Alternatively, the second device can be used to provide Internet of Things (IoT) functions, such as an Internet of Things Function (IoTF) network element or an Ambient Internet of Things Function (AIoTF) network element.
[0101] Optionally, the first device can communicate with the second device through the Reader. For a detailed introduction to the Reader, please refer to the description preceding the embodiment in Figure 2.
[0102] Optionally, the first request can be used to request triggering authentication between the second device and the first device. In some embodiments, the first request may include at least one of the following: the device identifier (ID) of the first device, a first random number (Nonce 1) generated by the first device, a first indication, and one or more first identifiers. Optionally, the first indication can be used to indicate the function of the first request. For example, the first indication can indicate whether the first request is used to request triggering authentication between the second device and the first device. In some embodiments, the first indication may also be called an authentication indication or other names, which are not specifically limited in this disclosure. Optionally, the first identifier can be used to indicate a first security algorithm supported by the first device. In some embodiments, the first identifier may not be included in the first request. For example, when the first device supports a first security algorithm, the first identifier may not be included in the first request. Optionally, when the first identifier is not included in the first request, the first security algorithm supported by the first device may be stored in advance in the third device. For example, the third device may store the first security algorithm supported by the first device in the context information of the first device. Optionally, the third device here can be used to provide unified data management functions. For example, the third device can be a Unified Data Management (UDM) network element, or it can be used to provide unified data storage functions. For example, the third device can be a Unified Data Repository (UDR) network element. Alternatively, in some embodiments, the third device can be an application server.
[0103] Optionally, the first request described above may also be referred to as a command request or other names, which will not be specifically mentioned in this disclosure.
[0104] Optionally, the first device may send a first request to the second device when at least one of the first key and the second key is not stored in the first device. For example, when the memory of the first device (e.g., non-volatile memory (NVM)) does not store at least one of the first key and the second key. Alternatively, the first device may send a first request to the second device after at least one of the first key and the second key stored in a volatile register of the first device is lost. In some embodiments, the first key may be used to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device. For example, the first key may be used to encrypt at least one of the data, information, and signaling between the first device and the second device. Optionally, the first key may also be called a confidentiality key, confidentiality protection key, encryption key, or other names, which are not specifically limited in this disclosure. Optionally, the second key can be used to protect the integrity of at least one of the data, information, and signaling between the first device and the second device. The method of integrity protection using the second key is explained in subsequent steps 2107 and 2110. Optionally, the second key may also be called an integrity key, integrity protection key, or other names, and this disclosure does not specifically limit this. Optionally, the first key and the second key may be collectively referred to as a session key or other names, and this disclosure does not specifically limit this.
[0105] Optionally, when the first device does not store at least one of the first key and the second key, the first request sent by the first device will not be protected by the key; for example, the first request will not be protected by the first key and / or the second key.
[0106] Optionally, the method of this disclosure embodiment can be applied to DO-A services. For example, when the first device has a DO-A requirement, such as when the first device needs to actively send data to the second device (i.e., the first device actively triggers the sending of data), the first device sends a first request to the second device to trigger authentication between the first device and the second device.
[0107] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0108] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transmit,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.
[0109] Step 2102: The second device sends a second request and / or a third request to the third device.
[0110] Optionally, in some embodiments, the second request may include the device identifier of the first device, and the second request may be used to request at least one of a third key and a second security algorithm.
[0111] Optionally, the third key may include at least one of the root key and the intermediate key of the first device. Optionally, different first devices may correspond to different root keys and / or different intermediate keys, wherein the intermediate key of the first device may be generated based on the root key and the device identifier of the first device. In some embodiments, the root key and / or intermediate key of the first device may be stored in the non-volatile memory (NVM) of the first device. In other embodiments, the root key and / or intermediate key of the first device may also be associated with the device identifier of the first device and stored in the third device. For example, the third device may associate the root key and / or intermediate key of the first device with the device identifier of the first device and store it in the context information of the first device.
[0112] Optionally, the aforementioned second security algorithm can be used to protect the confidentiality and / or integrity of at least one of the data, information, and signaling between the first device and the second device. The second security algorithm can be any of the first security algorithms. In some embodiments, the second security algorithm can be selected by the second device from one or more first security algorithms supported by the terminal. Optionally, when the second device selects a second security algorithm from one or more first security algorithms supported by the terminal, the second request may not be used to request the second security algorithm. In other embodiments, when the first request in step 2101 does not include a first identifier, indicating that the first device supports a first security algorithm, the second security algorithm should be that first security algorithm supported by the first device. In this case, since the first request in step 2101 does not include a first identifier, the second device cannot know which first security algorithm is supported by the first device. Furthermore, since the third device stores the first security algorithm supported by the first device, the second request sent by the second device to the third device can be used to request the second security algorithm from the third device.
[0113] Optionally, in some embodiments, the aforementioned third request can be used to request at least one of the first response (RES), the first key, and the second key. Optionally, the first response, the first key, and the second key can be used, for example, for the first device to authenticate the second device, or for secure communication with the first device. For details on the specific authentication method described here, please refer to step 2107.
[0114] Optionally, the third request may include at least one of the following: a device identifier of the first device, a first random number, a second random number generated by the second device, and a second identifier for indicating the second security algorithm. In some embodiments, when the second device selects a second security algorithm from one or more first security algorithms supported by the terminal, the third request may include the second identifier corresponding to the second security algorithm selected by the second device. When the second device does not select a second security algorithm from one or more first security algorithms supported by the terminal, for example, when the first request in step 2101 does not include the first identifier, the second device cannot select the second security algorithm because it cannot know the first security algorithm supported by the first device. In this case, the third request does not include the second identifier.
[0115] Step 2103: The third device sends the second information to the second device.
[0116] Optionally, in some embodiments, when the second device sends a second request to the third device in step 2102, the second information may include at least one of a third key and a second identifier. Optionally, in some embodiments, when the second request in step 2102 is not used to request a second security algorithm, the second information may not include the second identifier. In some embodiments, when the second request in step 2102 is used to request a second security algorithm, indicating that the first device currently supports a first security algorithm, the third device may store a second security algorithm determined by the first security algorithm currently supported by the first device, and include a second identifier indicating the second security algorithm in the second information.
[0117] Optionally, in some embodiments, when the second device sends a third request to the third device in step 2102 above, the second information may include at least one of a first response, a first key, and a second key.
[0118] Optionally, the first response may be generated by the third device based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key. For example, the third device may generate the first response based on the first random number, the second random number, and the root key of the first device; or, the third device may generate the first response based on the first random number, the second random number, and the intermediate key of the first device; or, the third device may generate the first response based on the device identifier of the first device, the first random number, the second random number, and the intermediate key of the first device. This disclosure does not specifically limit the specific generation method of the first response, and any possible generation method is within the protection scope of this disclosure.
[0119] Optionally, the first key and the second key may be generated by the third device based on at least one of the second security algorithm and the third key. For example, the third device may generate at least one of the first key and the second key based on the second security algorithm and the root key of the first device, or the third device may generate at least one of the first key and the second key based on the second security algorithm and the intermediate key of the first device. Optionally, in some other embodiments, the third device may also generate at least one of the first key and the second key based on at least one of the first random number, the second random number, and the third key. For example, the third device may generate at least one of the first key and the second key based on the first random number, the second random number, and the root key of the first device, or the third device may generate at least one of the first key and the second key based on the first random number, the second random number, and the intermediate key of the first device. This disclosure does not specifically limit the specific generation method of the first key and the second key, and any possible generation method is within the protection scope of this disclosure.
[0120] Optionally, the second security algorithm used by the third device when generating the first key and / or the second key may be the security algorithm indicated by the second identifier in the third request of step 2102 above. Alternatively, when the third request of step 2102 above does not include the second identifier, it indicates that the first device currently supports a first security algorithm. In this case, the third device may use the second security algorithm determined by the first security algorithm currently supported by the first device that it stores, and generate the second key and / or the third key based on the second security algorithm.
[0121] Step 2104: The second device determines at least one of the first key, the second key, the first verification value, and the first response based on the second information.
[0122] Optionally, when the second information includes at least one of a third key and a second identifier, the second device may generate a first response based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key, and generate at least one of a first key and a second key based on at least one of a second security algorithm and a third key. The second security algorithm may be the security algorithm indicated by the second identifier in the second information, or it may be a security algorithm selected by the second device from one or more first security algorithms. For a detailed description of this part, please refer to steps 2101-2103 above. In some embodiments, at least one of the first key and the second key may also be generated based on at least one of a first random number, a second random number, and a third key. For the generation method of the "first response, first key, and second key," please refer to step 2103 above.
[0123] Optionally, when the second information includes at least one of the first response, the first key, and the second key, the second device can directly determine at least one of the first response, the first key, and the second key based on the second information.
[0124] Optionally, after the second device determines the second key, the second device can generate a first verification value based on the second key. For example, the second device can include at least one of "the device identifier of the first device, a second random number, a first response, first information, and a second identifier for indicating the second security algorithm" in the first message. Optionally, the aforementioned first information may include information that the second device needs to send to the first device. The first information may include, for example, command information or instruction information that the second device needs to send to the first device. The first information may be protected by the first key, for example, the first information may be encrypted by the first key. Furthermore, after the second device determines the first message, the second device can calculate the first message based on the second key and the second security algorithm to generate a first verification value. Optionally, the first verification value may be included in the first message. This first verification value can be used by the first device to authenticate the second device. For example, the first verification value can be used by the first device to perform integrity verification on the first message sent by the second device. The first verification value may be, for example, a message authentication code (MAC).
[0125] Step 2105: The second device sends a first message to the first device.
[0126] Optionally, the first message may include at least one of the following: a second random number generated by the second device, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm. For a detailed description of the "first response, first verification value, and second security algorithm," please refer to steps 2102-2104 above.
[0127] Optionally, the first information mentioned above may include information that the second device needs to send to the first device. For example, the first information may include command information or instruction information that the second device needs to send to the first device. The first information may be protected by a first key, for example, the first information may be encrypted by the first key.
[0128] Optionally, in some embodiments, the first message may include a second identifier. For example, when the second device selects a second security algorithm from one or more first security algorithms supported by the terminal, the first message may include the second identifier. In other embodiments, the first message may not include the second identifier. For example, when the second device does not select a second security algorithm, the first message may not include the second identifier.
[0129] Alternatively, the first message may also be referred to as a command response or other names, which are not specifically limited in this disclosure.
[0130] Step 2106: The first device generates at least one of the following: a second response, a first key, and a second key.
[0131] Optionally, the second response may include, for example, an expected user response (XRES). Optionally, the first device may generate the second response based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key included in the first message. Optionally, the method by which the first device generates the second response is the same as the method by which the second device generates the first response, and will not be described in detail here.
[0132] Optionally, the first device may generate at least one of the first key and the second key based on at least one of the second security algorithm and the third key included in the first message; or, at least one of the first key and the second key may be generated by the first device based on at least one of the first random number, the second random number, and the third key. Optionally, the method by which the first device generates at least one of the first key and the second key is the same as the method by which the second device generates at least one of the first key and the second key, and will not be described again here.
[0133] Step 2107: First device authenticates second device.
[0134] Optionally, the first device can authenticate the second device by performing a first operation. Optionally, the first operation may include at least one of the following: verifying a first response based on a second response, or verifying a first verification value based on a second key. Optionally, the above-mentioned "verifying a first response based on a second response" may include, for example, determining whether the second response is consistent with the first response; when the second response is consistent with the first response, confirming that the first response verification is successful; when the second response is inconsistent with the first response, confirming that the first response verification is unsuccessful. Optionally, the above-mentioned "verifying a first verification value based on a second key" may include, for example, generating a second verification value based on a second key and a second security algorithm included in the first message; optionally, the method for generating the second verification value is the same as the method for generating the first verification value; the first device determines whether the second verification value is consistent with the first verification value; when the second verification value is consistent with the first verification value, confirming that the first verification value verification is successful; when the second verification value is inconsistent with the first verification value, confirming that the first verification value verification is unsuccessful.
[0135] Optionally, when the first response verification passes and / or the first verification value verification passes, the first device determines that the second device authentication has passed; when the first response verification fails and / or the first verification value verification fails, the first device determines that the second device authentication has failed.
[0136] Step 2108: The second device is authenticated and the first device stores at least one of the device identifier, the first key, and the second key.
[0137] Optionally, the first device may associate and store at least one of the device identifier, the first key, and the second key in the memory (e.g., NVM) of the first device.
[0138] Optionally, the first device may store at least one of the generated first key and second key in the temporary memory (e.g., a register) of the first device.
[0139] Step 2109: The first device sends the first data to the second device.
[0140] Optionally, the first data can be data that the first device needs to send to the second device. For example, the first data can be data that the first device actively sends (i.e., data that the first device actively triggers to send). The first data can be protected by a first key and / or a second key. Optionally, the first data can be encrypted using the first key. Optionally, a third verification value can be generated using the second key and a second security algorithm, and the third verification value can be included in the first data. The first data can then be encrypted using the first key. Alternatively, in some embodiments, a third verification value can be generated using the second key and a second security algorithm, and the first data can be encrypted using the first key. Then, both the third verification value and the encrypted first data can be sent to the first device.
[0141] Step 2110: The second device performs security verification on the first data based on the second key.
[0142] Optionally, the second device can perform integrity verification on the first data based on the second key. For example, the second device can first decrypt the first data based on the first key and determine the third verification value included in the first data. Then, the second device can generate a fourth verification value based on the second key and the second security algorithm, and determine whether the fourth verification value is consistent with the third verification value. When the fourth verification value is consistent with the third verification value, the integrity verification of the first data is determined to be successful, that is, the first data passes the security verification. When the fourth verification value is inconsistent with the third verification value, the integrity verification of the first data is determined to be unsuccessful, that is, the first data fails the security verification.
[0143] Optionally, in some embodiments, the second device may first generate a fourth verification value based on the second key and the second security algorithm, and determine whether the fourth verification value is consistent with the third verification value sent by the first device. Then, the second device can use the first key to decrypt the first data. Optionally, when the fourth verification value is consistent with the third verification value and the first data is successfully decrypted, the second device can determine that both the integrity verification and confidentiality verification of the first data are successful, and thus determine that the first data has passed security verification; when the fourth verification value is inconsistent with the third verification value, and / or the first data decryption fails, the second device can determine that the integrity verification and / or confidentiality verification of the first data are unsuccessful, and thus determine that the first data has failed security verification.
[0144] Step 2111: The first data passes security verification, confirming that the first device has been authenticated by the second device. The second device stores at least one of the device identifier, the first key, and the second key of the first device.
[0145] Optionally, the second device may associate and store at least one of the device identifier, first key, and second key of the first device in the context information of the first device.
[0146] Step 2112: The second device communicates with the first device using at least one of the first key and the second key.
[0147] In some embodiments, a first key can be used to encrypt at least one of the data, information, and signaling between the first device and the second device to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device. In some embodiments, a second key and a second security algorithm can be used to generate an integrity verification value, and this integrity verification value can be included in at least one of the data, information, and signaling between the first device and the second device to protect the integrity of at least one of the data, information, and signaling between the first device and the second device.
[0148] The authentication method involved in the embodiments of this disclosure may include at least one of steps 2101 to 2112. For example, steps 2101+2105, 2101+2102+2103+2104+2105, 2101+2105+2107, 2101+2105+2107+2108, and 2101+2105+2107+2108+2109 may be implemented as independent embodiments, but are not limited thereto.
[0149] In some embodiments, steps 2108 and 2109 may be performed in an interchangeable order or simultaneously.
[0150] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0151] Figure 3A is a flowchart illustrating an authentication method according to an embodiment of the present disclosure. As shown in Figure 3A, this disclosure relates to an authentication method for a first device, the method comprising:
[0152] Step 3101: Send the first request to the second device.
[0153] Step 3102: Receive the first message sent by the second device.
[0154] Step 3103: Authenticate the second device based on the first message.
[0155] Optionally, the first request is used to request and trigger authentication between the second device and the first device, wherein the first device includes an Internet of Things (IoT) device;
[0156] Optionally, the first message is used by the first device to authenticate the second device;
[0157] Optionally, sending the first request to the second device includes:
[0158] The first device, having not stored at least one of the first key and the second key, sends the first request to the second device; wherein the first key is used to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device, and the second key is used to protect the integrity of at least one of the data, information, and signaling between the first device and the second device.
[0159] Optionally, the first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, or one or more first identifiers;
[0160] Wherein, the first indication is used to indicate the effect of the first request, and one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
[0161] Optionally, the first message includes at least one of the following: a second random number generated by the second device, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm;
[0162] Wherein, the second security algorithm is used to protect the confidentiality and / or integrity of at least one of the data, information, and signaling between the first device and the second device, the second security algorithm being any of the first security algorithms, the first response being used by the first device to authenticate the second device, the first response being generated based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key; the first information includes information that the second device needs to send to the first device, the first information being protected by the first key, the first verification value being used by the first device to authenticate the second device, the first verification value being generated based on the second key.
[0163] Optionally, the method further includes:
[0164] A second response is generated based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key;
[0165] Generate at least one of the first key and the second key.
[0166] Optionally, authenticating the second device based on the first message includes:
[0167] The first response is verified based on the second response, and / or the first verification value is verified based on the second key;
[0168] The authentication of the second device based on the first message further includes at least one of the following: the first response verification is passed, and / or the first verification value verification is passed, determining that the second device is successfully authenticated;
[0169] If the first response verification fails, and / or the first verification value verification fails, it is determined that the second device authentication has failed.
[0170] Optionally, the method further includes:
[0171] Once the second device is authenticated, it stores at least one of the device identifier, first key, and second key of the first device, and sends first data to the second device. The first data is the data that the first device needs to send to the second device, and the first data is protected by the first key and / or the second key.
[0172] For a detailed description of steps 3101-3103, please refer to the above embodiment description.
[0173] The authentication method involved in the embodiments of this disclosure may include at least one of steps 3101 to 3103. For example, step 3101 may be implemented as a standalone embodiment, and steps 3102 and 3103 may be implemented as standalone embodiments, but are not limited thereto.
[0174] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0175] Figure 3B is a flowchart illustrating an authentication method according to an embodiment of the present disclosure. As shown in Figure 3B, this embodiment of the present disclosure relates to an authentication method for a first device, the method comprising:
[0176] Step 3201: Send the first request to the second device.
[0177] Step 3202: Receive the first message sent by the second device.
[0178] Step 3203: Generate at least one of the following: a second response, a first key, and a second key.
[0179] Step 3204: Authenticate the second device based on the first message.
[0180] Step 3205: The second device is authenticated and at least one of the device identifier, first key, and second key of the first device is stored.
[0181] Step 3206: Send the first data to the second device.
[0182] Step 3207: Communicate with the second device using at least one of the first key and the second key.
[0183] For a detailed description of steps 3201-3207, please refer to the above embodiment description.
[0184] The authentication method involved in the embodiments of this disclosure may include at least one of steps 3201 to 3207. For example, steps 3201+3202, 3201+3202+3204, 3201+3202+3204+3205, and 3201+3202+3204+3205+3206 may be implemented as independent embodiments, but are not limited thereto.
[0185] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0186] Figure 3C is a flowchart illustrating an authentication method according to an embodiment of the present disclosure. As shown in Figure 3C, this disclosure relates to an authentication method for a second device, the method comprising:
[0187] Step 3301: Receive the first request sent by the first device.
[0188] Step 3302: Send the first message to the first device.
[0189] Optionally, the first request is used to request and trigger authentication between the second device and the first device, wherein the first device includes an Internet of Things (IoT) device;
[0190] Optionally, the first message is used by the first device to authenticate the second device.
[0191] Optionally, the first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, or one or more first identifiers;
[0192] Wherein, the first indication is used to indicate the effect of the first request, and one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
[0193] Optionally, the method further includes:
[0194] Generate a second random number;
[0195] Send a second request to a third device, the second request including the device identifier of the first device, the second request being used to request at least one of a third key and a second security algorithm; wherein, the second security algorithm is used to perform confidentiality protection and / or integrity protection on at least one of data, information, and signaling between the first device and the second device, and the second security algorithm is any of the first security algorithms;
[0196] Receive at least one of the third key sent by the third device and the second identifier used to indicate the second security algorithm;
[0197] A first response is generated based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key, and the first response is used by the first device to authenticate the second device;
[0198] Generate at least one of a first key and a second key; wherein the first key is used to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device, and the second key is used to protect the integrity of at least one of the data, information, and signaling between the first device and the second device;
[0199] Based on the first key, first information is protected, and the first information includes information that the second device needs to send to the first device;
[0200] A first verification value is generated based on the second key, and the first verification value is used by the first device to authenticate the second device.
[0201] Optionally, the method further includes:
[0202] Generate a second random number;
[0203] A third request is sent to a third device, the third request including at least one of the following: a device identifier of the first device, a first random number, a second random number, and a second identifier for indicating a second security algorithm; the third request is used to request at least one of a first response, a first key, and a second key;
[0204] The device receives at least one of a first response, a first key, and a second key sent by the third device, wherein the first response is generated based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key;
[0205] Based on the first key, first information is protected, and the first information includes information that the second device needs to send to the first device;
[0206] A first verification value is generated based on the second key.
[0207] Optionally, the first message includes at least one of the following: a second random number, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm.
[0208] Optionally, the method further includes:
[0209] Receive first data sent by the first device, wherein the first data is data that the first device needs to send to the second device;
[0210] The first data is securely verified based on the second key. If the first data passes the security verification, it is determined that the first device has been authenticated by the second device. At least one of the device identifier, the first key, and the second key of the first device is stored.
[0211] For a detailed description of steps 3301-3302, please refer to the above embodiment description.
[0212] The authentication method involved in the embodiments of this disclosure may include at least one of steps 3301 to 3302. For example, step 3301 may be implemented as an independent embodiment, step 3302 may be implemented as an independent embodiment, and steps 3301+3302 may be implemented as an independent embodiment, but are not limited thereto.
[0213] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0214] Figure 3D is a flowchart illustrating an authentication method according to an embodiment of the present disclosure. As shown in Figure 3D, this disclosure relates to an authentication method for a second device, the method comprising:
[0215] Step 3401: Receive the first request sent by the first device.
[0216] Step 3402: Send a second request and / or a third request to the third device.
[0217] Step 3403: Receive the second information sent by the third device.
[0218] Step 3404: Determine at least one of the first key, the second key, the first verification value, and the first response based on the second information.
[0219] Step 3405: Send the first message to the second device.
[0220] Step 3406: Receive the first data sent by the second device.
[0221] Step 3407: Perform security verification on the first data.
[0222] Step 3408: The first data passes security verification, confirming that the first device has been authenticated by the second device, and storing at least one of the device identifier, the first key, and the second key of the first device.
[0223] Step 3409: Communicate with the first device using at least one of the first key and the second key.
[0224] For a detailed description of steps 3401-3409, please refer to the above embodiment description.
[0225] The authentication method involved in the embodiments of this disclosure may include at least one of steps 3401 to 3409. For example, steps 3401+3405, 3401+3402+3403+3404+3405, and 3401+3402+3403+3404+3405+3406 may be implemented as independent embodiments, but are not limited thereto.
[0226] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0227] The following is an exemplary description of the above method:
[0228] Environmental IoT devices can be: IoT devices that support environmental power, requiring no batteries and using capacitors to provide storage capacity, with limited energy storage capabilities. In some embodiments, environmental IoT devices can be powered by collecting radio waves, light, motion, heat, or any other suitable power source. Environmental IoT can make supply chains more efficient and sustainable, and can provide the data needed for advanced transportation and smart city initiatives.
[0229] Optionally, the connection topology between environmental IoT devices and other devices can be divided into two categories: Topology 1 and Topology 2.
[0230] Optionally, Topology 1 can refer to Figure 1B above, where the BS (i.e., the base station) communicates directly with the environmental IoT device. In Topology 1, the environmental IoT device directly communicates bidirectionally with the base station. The communication information between the BS and the environmental IoT device can include environmental IoT data and / or signaling. In this Topology 1, the process of the BS sending data to the environmental IoT device can differ from the process of the BS receiving data from the environmental IoT device.
[0231] Optionally, Topology 2 can refer to Figure 1C above. The BS can communicate with the environmental IoT devices through intermediate nodes. In Topology 2, the environmental IoT devices and intermediate nodes communicate bidirectionally. In this Topology 2, the intermediate nodes can be relays, IAB nodes, UEs, repeaters, etc., and the intermediate nodes can transmit information between the BS and the environmental IoT devices.
[0232] Based on Topology 1 and Topology 2 above, the following different business types can be considered for environmental IoT services.
[0233] -DT: Device terminated.
[0234] -DO-DTT: Device Initiated-Device Termination Trigger. Environmental IoT devices can only send data to the CN after being triggered by the CN.
[0235] -DO-A: Device Initiated-Autonomous, environmental IoT devices can send data to the CN at any time via a card reader.
[0236] In Rel-19, only DT and DO-DTT are supported, meaning that environmental IoT devices need to be triggered by the network before they can provide collected data or execute requested commands. However, the DO-A service type offers more flexibility on both the device and network sides and will be supported and explored in Rel-20.
[0237] From a security perspective, DO-A service types may pose greater risks than DT or DO-DTT service types. For example, attackers can easily launch a DoS attack against a CN by creating a network of multiple IoT devices in an unauthorized environment and actively sending false data.
[0238] Therefore, it is necessary to study how to perform one-way or two-way authentication for DO-A service types and ensure the confidentiality / integrity of information sent by environmental IoT devices.
[0239] Alternatively, the main objective of the method disclosed herein is as follows:
[0240] Provide an authentication method for DO-A service types (network authentication performed by environmental IoT devices).
[0241] Protect information during AIoT service communication.
[0242] Figure 4 is an interactive schematic diagram of an authentication method according to an embodiment of this disclosure. It is assumed that the environmental IoT device ID and root key are stored in the NVM of the IoT device. The UDM or application server can maintain the environmental IoT device ID and the corresponding root key. The session key generated from the root key can be temporarily stored in the memory of the environmental IoT device. Referring to Figure 4, the method of this disclosure may include the following steps:
[0243] 1. The environmental IoT device (i.e., the IoT device in Figure 4) sends a command request to the IoTF / AMF via a reader, including the device ID, random number 1, authentication indication (optional), and security algorithm (optional).
[0244] Alternatively, due to the lack of a session key, the IoT device may initiate an authentication process.
[0245] 2. Once the IoTF / AMF receives a command request message, it can interact with the application server / UDM to obtain the root key / intermediate key corresponding to the IoT device in the environment.
[0246] Alternatively, in other embodiments, the UDM may provide an intermediate key to the IoTF / AMF, which is generated using the root key and the environmental IoT device ID.
[0247] 3. IoTF / AMF generates a random number 2 and can select a security algorithm to protect subsequent communications based on the received security algorithm.
[0248] Optionally, IoTF / AMF generates a session key based on the root key / intermediate key and the identifier of the selected security algorithm.
[0249] Optionally, IoTF / AMF generates a response RES based on random number 1, random number 2, and the root key / intermediate key.
[0250] Optionally, the IoTF / AMF sends a command response, including a random number 2, RES (optional), a command protected by a secret key (optional), and a MAC for integrity protection.
[0251] Optionally, IoTF / AMF stores the session key along with the environmental IoT device ID in the device context.
[0252] Optionally, the session key may include an integrity protection key and a confidentiality protection key.
[0253] Optionally, the environmental IoT device may only support one security algorithm. In this case, the supported security algorithm is stored in the UDM or application server associated with the environmental IoT device ID, and the security algorithm may not be provided in step 1.
[0254] Optionally, in other embodiments, the IoTF / AMF may provide the application server / UDM with random number 1, random number 2, and a selected security algorithm (optional). The application server / UDM calculates the session key and / or RES, and returns the session key and / or RES to the IoTF / AMF.
[0255] 4. Once an environmental IoT device receives a response message, it can perform at least one of the following operations to authorize and authenticate the IoTF / AMF.
[0256] Optionally, IoT devices generate session keys and XRES in the same manner as IoTF / AMF.
[0257] Optionally, IoT devices can verify the integrity of authentication command responses by MAC verification.
[0258] Optionally, IoT devices can verify their authenticity by comparing RES and XRES.
[0259] Optionally, if the MAC is successfully verified and / or RES equals XRES, the IoT device can store the session key in memory and begin processing protected commands sent from the IoTF / AMF.
[0260] 5. If authentication is successful, the IoT device can use the session key to send protected data to the CN.
[0261] 6. IoTF / AMF can verify the authenticity of a device by verifying data report messages.
[0262] As can be seen from the above, in the embodiments of this disclosure, the environmental IoT device can achieve at least one of the following:
[0263] Environmental IoT devices can send messages to trigger authentication between IoT devices and networks.
[0264] Environmental IoT devices can verify the response to commands sent by IoTF / AMF.
[0265] Environmental IoT devices can generate session keys using parameters contained in command response messages.
[0266] After verifying the authenticity of the network, the environmental IoT device is able to store the session key in memory.
[0267] In the embodiments of this disclosure, the IoTF / AMF side can achieve at least one of the following:
[0268] IoTF / AMF can receive messages to trigger authentication between IoT devices and the network.
[0269] IoTF / AMF can send messages containing a random number, RES, and MAC.
[0270] IoTF / AMF can protect command response messages by using sessions.
[0271] In some embodiments, if the arrows in the interaction diagram representing the sending of information, signaling, etc., from one subject to another pass through other subjects, it can be interpreted as the message being forwarded from one subject to another via other subjects, or it can be interpreted as the message being sent from one subject to another without passing through other subjects. For example, step 1 in Figure 4 can be interpreted as: forwarding a command request from the IoT device to the IoTF / AMF via the reader / writer.
[0272] This disclosure also proposes an apparatus (also referred to as a communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is proposed that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.
[0273] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0274] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0275] Figure 5A is a schematic diagram of the structure of a first device according to an embodiment of this disclosure. The first device is used to perform any of the above methods. In some embodiments, as shown in Figure 5A, the first device may include at least one of a processing module, a transceiver module, etc. In some embodiments, the transceiver module is used to send a first request to a second device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the transceiver module is further used to receive a first message sent by the second device, the first message being used by the first device to authenticate the second device; the processing module is used to authenticate the second device based on the first message.
[0276] Optionally, the transceiver module is used to perform at least one of the communication steps (e.g., steps 2101, 2105, 2109, 2112, 3101, 3102, but not limited thereto) performed by the first device in any of the above methods, which will not be elaborated here. Optionally, the processing module is used to perform at least one of the other steps (e.g., steps 2106, 2107, 2108, 3103, but not limited thereto) performed by the first device in any of the above methods, which will not be elaborated here.
[0277] Optionally, the transceiver module is further configured to: send the first request to the second device when the first device does not store at least one of the first key and the second key; wherein the first key is used to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device, and the second key is used to protect the integrity of at least one of the data, information, and signaling between the first device and the second device.
[0278] Optionally, the first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, or one or more first identifiers;
[0279] Wherein, the first indication is used to indicate the effect of the first request, and one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
[0280] Optionally, the first message includes at least one of the following: a second random number generated by the second device, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm;
[0281] Wherein, the second security algorithm is used to protect the confidentiality and / or integrity of at least one of the data, information, and signaling between the first device and the second device, the second security algorithm being any of the first security algorithms, the first response being used by the first device to authenticate the second device, the first response being generated based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key; the first information includes information that the second device needs to send to the first device, the first information being protected by the first key, the first verification value being used by the first device to authenticate the second device, the first verification value being generated based on the second key.
[0282] Optionally, the processing module is further configured to:
[0283] A second response is generated based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key;
[0284] Generate at least one of the first key and the second key.
[0285] Optionally, the processing module is further configured to:
[0286] The first response is verified based on the second response, and / or the first verification value is verified based on the second key;
[0287] The processing module is also used to determine that the second device authentication is successful if the first response verification is passed, and / or the first verification value verification is passed.
[0288] If the first response verification fails, and / or the first verification value verification fails, it is determined that the second device authentication has failed.
[0289] Optionally, the processing module is further configured to:
[0290] Once the second device is authenticated, it stores at least one of the device identifier, first key, and second key of the first device, and sends first data to the second device. The first data is the data that the first device needs to send to the second device, and the first data is protected by the first key and / or the second key.
[0291] Figure 5B is a schematic diagram of the structure of the second device proposed in an embodiment of this disclosure. The second device is used to perform any of the above methods. In some embodiments, as shown in Figure 5B, the second device may include at least one of a processing module, a transceiver module, etc. In some embodiments, the transceiver module is used to receive a first request sent by a first device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; the transceiver module is further used to send a first message to the first device, the first message being used by the first device to authenticate the second device.
[0292] Optionally, the transceiver module is used to perform at least one of the communication steps (e.g., steps 2101, 2102, 2103, 2105, 2109, 2112, 3201, 3202, but not limited thereto) performed by the second device in any of the above methods, which will not be elaborated here. Optionally, the processing module is used to perform at least one of the other steps (e.g., steps 2104, 2110, 2111, but not limited thereto) performed by the second device in any of the above methods, which will not be elaborated here.
[0293] Optionally, the first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, or one or more first identifiers;
[0294] Wherein, the first indication is used to indicate the effect of the first request, and one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
[0295] Optionally, the processing module is further configured to generate a second random number;
[0296] The transceiver module is further configured to send a second request to a third device, the second request including the device identifier of the first device, the second request being used to request at least one of a third key and a second security algorithm; wherein, the second security algorithm is used to perform confidentiality protection and / or integrity protection on at least one of the data, information, and signaling between the first device and the second device, and the second security algorithm is any of the first security algorithms;
[0297] The transceiver module is also configured to send at least one of the third key and the second identifier indicating the second security algorithm to the receiving third device;
[0298] The processing module is further configured to generate a first response based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key, wherein the first response is used by the first device to authenticate the second device;
[0299] The processing module is further configured to generate at least one of a first key and a second key; wherein the first key is used to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device, and the second key is used to protect the integrity of at least one of the data, information, and signaling between the first device and the second device.
[0300] The processing module is also configured to protect first information based on the first key, the first information including information that the second device needs to send to the first device;
[0301] The processing module is further configured to generate a first verification value based on the second key, the first verification value being used by the first device to authenticate the second device.
[0302] Optionally, the processing module is further configured to generate a second random number;
[0303] The transceiver module is further configured to send a third request to a third device, the third request including at least one of the following: a device identifier of the first device, a first random number, a second random number, and a second identifier for indicating a second security algorithm; the third request is used to request at least one of a first response, a first key, and a second key;
[0304] The transceiver module is further configured to receive at least one of a first response, a first key, and a second key sent by the third device, wherein the first response is generated based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key;
[0305] The processing module is also configured to protect first information based on the first key, the first information including information that the second device needs to send to the first device;
[0306] The processing module is also used to generate a first verification value based on the second key.
[0307] Optionally, the first message includes at least one of the following: a second random number, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm.
[0308] Optionally, the transceiver module is further configured to receive first data sent by the first device, wherein the first data is data that the first device needs to send to the second device;
[0309] The processing module is further configured to perform security verification on the first data based on the second key, and if the first data passes the security verification, it is determined that the first device has been authenticated by the second device, and at least one of the device identifier of the first device, the first key, and the second key is stored.
[0310] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, which may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver.
[0311] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.
[0312] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.
[0313] Figure 6A is a schematic diagram of the structure of the communication device 6100 proposed in an embodiment of this disclosure. The communication device 6100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 6100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0314] As shown in Figure 6A, the communication device 6100 is used to execute any of the above methods. In some embodiments, the communication device 6100 includes one or more processors 6101. The processor 6101 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 6100 is used to execute any of the above methods. Optionally, one or more processors 6101 are used to invoke instructions to cause the communication device 6100 to execute any of the above methods.
[0315] In some embodiments, the communication device 6100 further includes one or more transceivers 6102. When the communication device 6100 includes one or more transceivers 6102, the transceiver 6102 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps 2101, 2102, 2103, 2105, 2109, 2112, 3201, 3202, 3101, 3102, but not limited thereto), and the processor 6101 performs at least one of other steps (e.g., steps 2104, 2106, 2107, 2108, 2110, 2111, 3103, but not limited thereto). In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated together. Optionally, terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be used interchangeably; terms such as transmitter, transmitter unit, transmitter, and transmitter circuit can be used interchangeably; and terms such as receiver, receiver unit, receiver, and receiver circuit can be used interchangeably.
[0316] In some embodiments, the communication device 6100 further includes one or more memories 6103 for storing data and / or instructions. Optionally, one or more processors 6101 are used to invoke instructions stored in the memory 6103 to cause the communication device 6100 to perform any of the above methods. Optionally, all or part of the memory 6103 may also be located outside the communication device 6100. In an optional embodiment, the communication device 6100 may include one or more interface circuits 6104. Optionally, the interface circuit 6104 is connected to the memory 6102 and can be used to receive data and / or instructions from the memory 6102 or other devices, and can be used to send data and / or instructions to the memory 6102 or other devices. For example, the interface circuit 6104 can read data and / or instructions stored in the memory 6102 and send the data and / or instructions to the processor 6101.
[0317] The communication device 6100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 6100 described in this disclosure is not limited thereto, and the structure of the communication device 6100 may not be limited by FIG. 6A. The communication device may be a standalone device or a part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0318] Figure 6B is a schematic diagram of the structure of chip 6200 according to an embodiment of this disclosure. For cases where the communication device 6100 can be a chip or a chip system, please refer to the schematic diagram of chip 6200 shown in Figure 6B, but it is not limited thereto.
[0319] Chip 6200 includes one or more processors 6201. Chip 6200 is used to perform any of the methods described above.
[0320] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data and / or instructions. Optionally, all or part of the memories 6203 may be located outside of chip 6200. Optionally, interface circuit 6202 is connected to memory 6203, and interface circuit 6202 can be used to receive data and / or instructions from memory 6203 or other devices, and interface circuit 6202 can be used to send data and / or instructions to memory 6203 or other devices. For example, interface circuit 6202 can read data and / or instructions stored in memory 6203 and send the data and / or instructions to processor 6201.
[0321] In some embodiments, the interface circuit 6202 performs at least one of the communication steps such as sending and / or receiving in the above-described method (e.g., steps 2101, 2103, 2105, 3102, and 4102, but not limited thereto). The interface circuit 6202 performing the communication steps such as sending and / or receiving in the above-described method refers, for example, to the interface circuit 6202 performing data and / or instruction interaction between the processor 6201, the chip 6200, the memory 6203, or the transceiver device. In some embodiments, the processor 6201 performs at least one of other steps (e.g., steps 2102, 2104, 2106, 3101, and 4101, but not limited thereto).
[0322] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0323] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0324] This disclosure also proposes a program product, including a program and / or instructions, which, when executed by a communication device, cause the communication device to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.
[0325] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
[0326] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).
[0327] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0328] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0329] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. An authentication method characterized by, The method is performed by a first device, and the method comprises: sending, to a second device, a first request, the first request being used to request triggering authentication between the second device and the first device, the first device comprising an Internet of Things (IoT) device; receiving a first message sent by the second device, the first message being used for the first device to authenticate the second device; authenticating the second device based on the first message.
2. The method of claim 1, wherein, The sending, to the second device, of the first request comprises: The first device does not store at least one of a first key and a second key, and the first request is sent to the second device; wherein the first key is used to protect confidentiality of at least one of data, information, and signaling between the first device and the second device, and the second key is used to protect integrity of at least one of data, information, and signaling between the first device and the second device.
3. The method of claim 1 or 2, wherein, The first request comprises at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, and one or more first identifiers; The first indication is used to indicate an effect of the first request, and the one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
4. The method according to any one of claims 1 to 3, characterized in that, The first message comprises at least one of the following: a second random number generated by the second device, a first response, first information, a first verification value, and a second identifier used to indicate a second security algorithm; The second security algorithm is used to protect confidentiality and / or integrity of at least one of data, information, and signaling between the first device and the second device, the second security algorithm is any first security algorithm, the first response is used for the first device to authenticate the second device, the first response is generated based on at least one of the following: a device identifier of the first device, the first random number, the second random number, and a third key; the first information comprises information that needs to be sent by the second device to the first device, the first information is protected by the first key, and the first verification value is used for the first device to authenticate the second device, the first verification value is generated based on the second key.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: generating a second response based on at least one of the following: a device identifier of the first device, the first random number, the second random number, and the third key; generating at least one of the first key and the second key.
6. The method of any one of claims 1-5, wherein, The authenticating the second device based on the first message comprises: verifying the first response based on the second response, and / or verifying the first verification value based on the second key; The authenticating the second device based on the first message further comprises at least one of the following: if the first response verification is passed and / or the first verification value verification is passed, it is determined that the second device authentication is passed; if the first response verification is not passed and / or the first verification value verification is not passed, it is determined that the second device authentication is not passed.
7. The method of any one of claims 1-6, wherein, The method further comprises: Once the second device is authenticated, it stores at least one of the device identifier, first key, and second key of the first device, and sends first data to the second device. The first data is the data that the first device needs to send to the second device, and the first data is protected by the first key and / or the second key.
8. An authentication method characterized by, Performed by a second device, the method includes: Receive a first request sent by a first device, the first request being used to request triggering authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; A first message is sent to the first device, and the first message is used by the first device to authenticate the second device.
9. The method of claim 8, wherein, The first request includes at least one of the following: a device identifier of the first device, a first random number generated by the first device, a first indication, or one or more first identifiers; Wherein, the first indication is used to indicate the effect of the first request, and one or more first identifiers are used to indicate one or more first security algorithms supported by the first device.
10. The method of claim 8 or 9, wherein, The method further includes: Generate a second random number; Send a second request to a third device, the second request including the device identifier of the first device, the second request being used to request at least one of a third key and a second security algorithm; wherein, the second security algorithm is used to perform confidentiality protection and / or integrity protection on at least one of data, information, and signaling between the first device and the second device, and the second security algorithm is any of the first security algorithms; Receive at least one of the third key sent by the third device and the second identifier used to indicate the second security algorithm; A first response is generated based on at least one of the device identifier of the first device, the first random number, the second random number, and the third key, and the first response is used by the first device to authenticate the second device; Generate at least one of a first key and a second key; wherein the first key is used to protect the confidentiality of at least one of the data, information, and signaling between the first device and the second device, and the second key is used to protect the integrity of at least one of the data, information, and signaling between the first device and the second device; Based on the first key, first information is protected, and the first information includes information that the second device needs to send to the first device; A first verification value is generated based on the second key, and the first verification value is used by the first device to authenticate the second device.
11. The method of any one of claims 8-10, wherein, The method further includes: Generate a second random number; A third request is sent to a third device, the third request including at least one of the following: a device identifier of the first device, a first random number, a second random number, and a second identifier for indicating a second security algorithm; the third request is used to request at least one of a first response, a first key, and a second key; The device receives at least one of a first response, a first key, and a second key sent by the third device, wherein the first response is generated based on at least one of the device identifier of the first device, a first random number, a second random number, and a third key; Based on the first key, first information is protected, and the first information includes information that the second device needs to send to the first device; A first verification value is generated based on the second key.
12. The method of any one of claims 8-11, wherein, The first message includes at least one of the following: a second random number, a first response, a first message, a first verification value, and a second identifier for indicating a second security algorithm.
13. The method of any one of claims 8-12, wherein, The method further includes: Receive first data sent by the first device, wherein the first data is data that the first device needs to send to the second device; The first data is securely verified based on the second key. If the first data passes the security verification, it is determined that the first device has been authenticated by the second device. At least one of the device identifier, the first key, and the second key of the first device is stored.
14. An authentication method for a communication system, the communication system comprising a first device and a second device, the method comprising: The first device sends a first request to the second device, the first request being used to request the triggering of authentication between the second device and the first device, the first device including an Internet of Things (IoT) device; The second device sends a first message to the first device, the first message being used by the first device to authenticate the second device; The first device authenticates the second device based on the first message.
15. A communication device, characterized by The communication device is used to perform the method according to any one of claims 1 to 7, 8 to 13.
16. A communication system, characterized by The device includes a first device and a second device, wherein the first device is configured to implement the method of any one of claims 1 to 7, and the second device is configured to implement the method of any one of claims 8 to 13.
17. A storage medium, the storage medium storing instructions, wherein, When the instructions are executed on the communication device, the communication device performs the method as described in any one of claims 1 to 7, 8 to 13.
18. A program product comprising at least one of a program, instructions, characterized in that, When at least one of the programs or instructions is executed by the communication device, it implements the method of any one of claims 1 to 7, 8 to 13.