Communication method and device

By segmenting the uplink NAS messages from AIoT devices into multiple secure uplink NAS payloads and transmitting them, the problem of AIoT devices being unable to send large amounts of data at once is solved, achieving a balance between data transmission security and resource efficiency.

WO2026152400A1PCT designated stage Publication Date: 2026-07-23GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
Filing Date
2025-01-17
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

When AIoT devices need to upload large amounts of data, they cannot send all the data at once, making it difficult to guarantee message security.

Method used

AIoT devices segment uplink NAS messages into multiple secure uplink NAS payloads and transmit them through multiple uplink MAC PDUs. Read/write devices and AIoT functions perform secure uplink NAS message generation and verification.

Benefits of technology

This ensures the security of AIoT devices during segmented message transmission, reduces processing resource consumption, and improves the reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073131_23072026_PF_FP_ABST
    Figure CN2025073131_23072026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method and a device. The method comprises: generating an uplink NAS message; processing the uplink NAS message to obtain a plurality of security-protected uplink NAS payloads; and sending a plurality of uplink MAC PDUs to a read-write device, wherein the plurality of uplink MAC PDUs carry the plurality of security-protected uplink NAS payloads.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and devices Technical Field

[0001] This application relates to the field of communications, and more specifically, to a communication method and apparatus. Background Technology

[0002] In related technologies, Ambient Powered IoT (AIoT) devices transmit uplink data through their corresponding readers or readers. However, AIoT devices have limited capabilities, and when the amount of uplink data to be uploaded is large, they may not be able to send it all at once. This necessitates that AIoT devices segment the data before sending it. However, in such scenarios, ensuring the security of the messages transmitted by AIoT devices becomes a problem that needs to be solved. Summary of the Invention

[0003] This application provides a communication method and device.

[0004] This application provides a communication method executed by an AIoT device, including:

[0005] Generate an uplink NAS message;

[0006] The uplink NAS messages are processed to obtain multiple secure uplink NAS payloads;

[0007] Multiple uplink MAC PDUs are sent to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security-protected uplink NAS loads.

[0008] This application provides a communication method executed by a read / write device, including:

[0009] Receive multiple uplink MAC PDUs from AIoT devices, wherein the multiple uplink MAC PDUs carry multiple secure uplink NAS loads;

[0010] Send a security-protected uplink NAS message to the AIoT function, wherein the security-protected uplink NAS message is generated based on the plurality of security-protected uplink NAS loads.

[0011] This application provides a communication method executed by an AIoT function, including:

[0012] Receive uplink NAS messages from the read / write device for security protection.

[0013] This application provides an AIoT device, including:

[0014] The first processing unit is used to generate uplink NAS messages; process the uplink NAS messages to obtain multiple secure uplink NAS payloads;

[0015] The first communication unit is used to send multiple uplink Media Access Control (MAC) Protocol Data Units (PDUs) to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security protection uplink NAS loads.

[0016] This application provides a read / write device, including:

[0017] The second communication unit is configured to receive multiple uplink MAC PDUs from an AIoT device, wherein the multiple uplink MAC PDUs carry multiple security-protected uplink NAS loads; and to send a security-protected uplink NAS message to the AIoT function, wherein the security-protected uplink NAS message is generated based on the multiple security-protected uplink NAS loads.

[0018] This application provides an AIoT function, including:

[0019] The third communication unit is used to receive uplink NAS messages for security protection from the read / write device.

[0020] This application provides an AIoT device, including a transceiver, a processor, and a memory. The memory stores a computer program, the transceiver communicates with other devices, and the processor calls and runs the computer program stored in the memory to enable the AIoT device to perform the methods described above.

[0021] This application provides a read / write device, including a transceiver, a processor, and a memory. The memory stores a computer program, the transceiver communicates with other devices, and the processor calls and runs the computer program stored in the memory to enable the read / write device to perform the methods described above.

[0022] This application provides an AIoT function, including a transceiver, a processor, and a memory. The memory stores a computer program, the transceiver communicates with other devices, and the processor calls and runs the computer program stored in the memory to enable the AIoT function to perform the methods described above.

[0023] This application provides a chip for implementing the above method.

[0024] Specifically, the chip includes a processor for retrieving and running a computer program from memory, causing a device equipped with the chip to perform the methods described above.

[0025] This application provides a computer-readable storage medium for storing a computer program, which, when run by a device, causes the device to perform the above-described method.

[0026] This application provides a computer program product, including computer program instructions that cause a computer to perform the above-described method.

[0027] This application provides a computer program that, when run on a computer, causes the computer to perform the above-described method.

[0028] By adopting the above scheme, AIoT devices can securely protect the uplink NAS messages they need to send, obtaining multiple secure uplink NAS payloads. These secure uplink NAS payloads are then carried in multiple uplink MAC PDUs and sent to the read / write device. In this way, AIoT devices can segment their sent messages and transmit secure NAS payloads, thereby ensuring the security of the messages in scenarios where AIoT devices transmit segmented messages.

[0029] Furthermore, AIoT devices can first segment uplink NAS messages, and then protect each segmented uplink NAS load individually. This ensures the security of each uplink NAS load sent by the AIoT device.

[0030] Furthermore, after providing overall security protection for the uplink NAS messages, AIoT devices can further segment the messages into multiple secure uplink NAS payloads. This reduces the number of security protection-related processes performed by the AIoT device, ensuring the security of the issued uplink NAS payloads while also reducing the processing resources consumed. Attached Figure Description

[0031] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.

[0032] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application.

[0033] Figure 3 is a schematic diagram of a processing scenario where multiple uplink NAS loads are segmented and then individually protected according to an embodiment of this application.

[0034] Figure 4 is a schematic flowchart of a communication method for individually securing each uplink NAS load according to an embodiment of this application.

[0035] Figure 5 is a schematic diagram of a scenario in which multiple secure uplink NAS loads are obtained by segmenting the overall secure uplink NAS message according to an embodiment of this application.

[0036] Figure 6 is a schematic flowchart of a communication method for dividing and sending multiple secure uplink NAS payloads after overall protection of the uplink NAS message according to an embodiment of the present application.

[0037] Figure 7 is a schematic flowchart of a communication method for individually securing each downlink NAS load according to an embodiment of this application.

[0038] Figure 8 is a schematic flowchart of a communication method in which a read / write device divides and sends multiple security protection downlink NAS payloads after receiving a command for overall protection of the AIoTF according to an embodiment of this application.

[0039] Figure 9 is a schematic block diagram of an AIoT device according to an embodiment of this application.

[0040] Figure 10 is a schematic block diagram of a read / write device according to an embodiment of this application.

[0041] Figure 11 is a schematic block diagram of an AIoT function according to an embodiment of this application.

[0042] Figure 12 is a schematic block diagram of a communication device according to an embodiment of this application.

[0043] Figure 13 is a schematic block diagram of a chip according to an embodiment of this application. Detailed Implementation

[0044] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0045] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.

[0046] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.

[0047] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0048] Figure 1 exemplarily illustrates a communication system 100. The communication system includes network devices 110 and terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and the coverage area of ​​each network device 110 may include multiple terminals 120; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include other network entities such as mobility management entities and access and mobility management functions; this embodiment does not limit this. The network devices may further include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.

[0049] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application. In Figure 2, the communication method is described from the perspective of interaction between an AIoT device, a read / write device, and AIoT functions. The sending / receiving of the AIoT device corresponds to the receiving / sending of the read / write device, and the sending / receiving of the read / write device corresponds to the receiving / sending of the AIoT function. As shown in Figure 2, the communication method may include the following steps:

[0050] S210 to S220 are executed on the AIoT device side, specifically:

[0051] S210, Generate an uplink NAS (Non-Access Stratum) message;

[0052] S220. Process the uplink NAS message to obtain multiple secure uplink NAS loads;

[0053] S230. Send multiple uplink MAC (Media Access Control) PDUs (Protocol Data Units) to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security-protected uplink NAS loads.

[0054] S240 to S250 are executed on the read / write device side, specifically:

[0055] S240, Receive multiple uplink MAC PDUs from an AIoT device, wherein the multiple uplink MAC PDUs carry multiple security-protected uplink NAS loads;

[0056] S250. Send a security-protected uplink NAS message to the AIoT function, wherein the security-protected uplink NAS message is generated based on the plurality of security-protected uplink NAS loads.

[0057] On the AIoT function side, S260 is executed, and uplink NAS messages for security protection are received from the read / write device.

[0058] AIoT devices can be replaced by low-power devices, zero-power devices, or ordinary terminals, etc. This article does not limit or exhaustively list the various types of entities that AIoT devices may replace.

[0059] A read / write device can also be called a reader. Specifically, a read / write device can be one of the following: an access network device or a terminal; the access network device can include at least one of the following: a base station, a gNB, an eNB, network devices in a future PLMN network, network devices in an NTN network, a satellite, etc.

[0060] AIoT function can be represented as AIoTF (AIoT Function), which can also be replaced by AIoT NF (Network Function) or AIoT MF (Management Function), etc.

[0061] The uplink NAS message may carry at least one of the following: data reported by the AIoT device, or the identifier of the AIoT device.

[0062] The data reported by the AIoT device can be data obtained by the AIoT device executing the AIoTF command, or the data reported by the AIoT device can be data actively reported by the AIoT device. This embodiment does not limit it.

[0063] The identifier of an AIoT device can be represented as an AIoT ID or an AIoT device ID, etc. The type of the AIoT device identifier can include a permanent identifier and / or a temporary identifier. This embodiment does not limit or exhaustively list the types of AIoT device identifiers.

[0064] In one example, the AIoT device may receive a command for an AIoT function, execute the corresponding operation of the command, and then generate an uplink NAS message. In this case, the uplink NAS message can be referred to as a response message, or a response message to the command. The command for this AIoT function will be simply referred to as a command in this application.

[0065] When the command is a read command, the AIoT device can perform the corresponding read operation according to the read command, and use the read data as the data reported by the AIoT device to generate an uplink NAS message; the uplink NAS message can carry the data reported by the AIoT device, and further, the uplink NAS message can also carry the identifier of the AIoT device.

[0066] When the command is a write command, the AIoT device can perform the corresponding data writing operation according to the write command, and use the indication information of the completion of data writing as the data reported by the AIoT device to generate an uplink NAS message; the uplink NAS message can carry the data reported by the AIoT device, and further, the uplink NAS message can also carry the identifier of the AIoT device.

[0067] The command can also be replaced with an inventory message. The AIoT device can execute the corresponding operation of the inventory message to obtain the AIoT device's identifier and generate an uplink NAS message. In this case, the uplink NAS message can carry the AIoT device's identifier.

[0068] The above is only an illustrative description of the command. In actual processing, the command can also be a disable, enable (or enable), or deactivate command. Correspondingly, the uplink NAS message can carry confirmation information (the data reported by the AIoT device can be confirmation information) and / or the identifier of the AIoT device. Not all possible situations are limited or exhaustively listed here.

[0069] In one example, the AIoT device may proactively generate uplink NAS messages. These uplink NAS messages may carry data proactively reported by the AIoT device, and further, they may also carry the AIoT device's identifier. In this case, the data may be data collected by the AIoT device or data generated by the AIoT device itself, etc. The specific method by which the AIoT device obtains the data is not limited here; the reason why the AIoT device proactively reports data is also not limited in this embodiment.

[0070] The uplink NAS message can be an AIoT uplink NAS-specific message; it can also be encapsulated in a NASC (NAS Container), and can be alternatively referred to as an uplink NASC. In the following text, the terms uplink NAS message, AIoT uplink NAS-specific message, and uplink NASC have the same meaning and will not be explained again.

[0071] An uplink MAC PDU can be called an uplink MAC message, or an uplink MAC PDU can be called a D2R (Device to Reader) message MAC PDU.

[0072] Uplink NAS messages are messages (or data) returned or sent by AIoT devices to AIoTF. These uplink NAS messages are divided into multiple blocks, i.e., multiple uplink NAS payloads. The multiple uplink NAS payloads are carried on the MAC PDUs of multiple D2R messages. The data fed back by the AIoT device (i.e., uplink NAS messages) is securely protected between the AIoT device and AIoTF.

[0073] Security protection may include at least one of encryption, integrity protection (abbreviated as integrity protection), and replay protection.

[0074] In some possible implementations, after the AIoT device divides the uplink NAS message into multiple uplink NAS loads, it performs security protection on each uplink NAS load individually and then sends it out. The AIoT device's processing of the uplink NAS message to obtain multiple secure uplink NAS loads may include: dividing the uplink NAS message into multiple uplink NAS loads; and performing security protection on the multiple uplink NAS loads based on multiple uplink freshness values ​​to obtain the multiple secure uplink NAS loads.

[0075] Referring to Figure 3, the process of separately protecting multiple uplink NAS loads after the AIoT device is segmented in this embodiment is illustrated as follows: The AIoT device segments the uplink NAS message (i.e., NASC) into multiple uplink NAS loads, such as NAS load 1, NAS load 2 to NAS load n in Figure 3, where n is an integer greater than 2; then the AIoT device performs security protection on each of the multiple uplink NAS loads, resulting in multiple protected uplink NAS loads, such as protected NAS load 1, protected NAS load 2 to protected NAS load n in Figure 3; finally, multiple uplink MAC PDUs carry the multiple protected uplink NAS loads, such as the MAC PDU carrying protected NAS load 1, the MAC PDU carrying protected NAS load 2 to the MAC PDU carrying protected NAS load n in Figure 3. Each MAC PDU also encapsulates its own header, which is not limited in this embodiment.

[0076] The communication method for providing individual security protection for each uplink NAS load in this embodiment will be explained with reference to Figure 4:

[0077] After the AIoT device generates an uplink NAS message, it can execute S401 to S403:

[0078] S401 divides the uplink NAS message into multiple uplink NAS payloads;

[0079] S402, based on multiple uplink fresh values, provides security protection for multiple uplink NAS loads, resulting in multiple secure uplink NAS loads;

[0080] S403, send multiple uplink MAC PDUs to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security-protected uplink NAS loads.

[0081] The read / write device side executes S411~S412:

[0082] S411, based on the receiving order of the multiple security-protected uplink NAS loads, add a tag corresponding to each security-protected uplink NAS load; based on each security-protected uplink NAS load and the tag corresponding to each security-protected uplink NAS load, concatenate to obtain the security-protected uplink NAS message.

[0083] S412 sends a security protection uplink NAS message to the AIoT function.

[0084] AIoTF executes S421~S422:

[0085] S421, based on the tag corresponding to each secure uplink NAS load contained in the secure uplink NAS message, multiple secure uplink NAS loads are obtained;

[0086] S422, if the uplink NAS load verification of the multiple security protections is successful based on multiple uplink fresh values, the uplink NAS message is obtained.

[0087] In S401, the AIoT device can divide the uplink NAS message into multiple uplink NAS payloads according to a specified length. The specified length can be configured according to the actual situation, such as 1000 bits, longer, or shorter; this embodiment does not limit it.

[0088] The different security protections of the uplink NAS load correspond to different uplink freshness values ​​among the multiple uplink freshness values.

[0089] In this embodiment, the number of uplink fresh values ​​is equal to the number of uplink NAS loads. Different uplink fresh values ​​have different values, and different uplink fresh values ​​are used to provide security protection for different uplink NAS loads to obtain different secure uplink NAS loads. Any uplink fresh value can be called the uplink fresh value corresponding to the secure uplink NAS load, or the uplink fresh value corresponding to the uplink NAS load, or the uplink fresh value corresponding to the secure uplink NAS load.

[0090] In one embodiment, the first secure uplink NAS load among the plurality of secure uplink NAS loads carries a first uplink fresh value among the plurality of uplink fresh values, wherein the first uplink fresh value is generated by the AIoT device. The uplink fresh values ​​corresponding to the other uplink NAS loads of each of the plurality of secure uplink NAS loads, excluding the first secure uplink NAS load, are calculated based on the first uplink fresh value.

[0091] Before performing security protection on each uplink NAS load, the AIoT device generates the uplink fresh value corresponding to that uplink NAS load.

[0092] The first uplink fresh value is the first uplink fresh value generated when the AIoT device sends the current uplink NAS message. This embodiment does not limit the method by which the AIoT device generates the first uplink fresh value. This first uplink fresh value can also be alternatively referred to as the first uplink nonce, or the first uplink counter, etc. In the following text, the first uplink fresh value and the first uplink nonce (or counter) have the same meaning and will not be explained again.

[0093] In addition to the first uplink fresh value, the uplink fresh values ​​corresponding to each other security protection uplink NAS load can be calculated directly based on the first uplink fresh value, or indirectly based on the first uplink fresh value.

[0094] Optionally, the uplink NAS load for the i-th security protection corresponds to the i-th uplink fresh value, which can be directly calculated based on the first uplink fresh value plus i-1, where i can be an integer greater than or equal to 2. For example, the second uplink fresh value corresponding to the second security protection uplink NAS load can be equal to the first uplink fresh value plus 1; the third uplink fresh value corresponding to the third security protection uplink NAS load can be equal to the first uplink fresh value plus 2, and so on, without exhaustive enumeration.

[0095] Optionally, the i-th uplink freshness value corresponding to the i-th security protection uplink NAS load can be calculated based on the (i-1)-th uplink freshness value plus m, where m can be an integer configured according to actual conditions, such as m equal to 1 or other integers. For example, the second uplink freshness value corresponding to the second security protection uplink NAS load can be equal to the first uplink freshness value plus 1; the third uplink freshness value corresponding to the third security protection uplink NAS load can be equal to the second uplink freshness value plus 1. The second uplink freshness value is calculated based on the first uplink freshness value, that is, the third uplink freshness value can be indirectly calculated from the first uplink freshness value, and so on, without exhaustive enumeration.

[0096] The AIoT device executing S402 may include: the AIoT device generating a first uplink fresh value, performing security protection on the first uplink NAS load among multiple uplink NAS loads based on the first uplink fresh value, and obtaining the first securely protected uplink NAS load; the AIoT device calculating a second uplink fresh value based on the first uplink fresh value, performing security protection on the second uplink NAS load among multiple uplink NAS loads based on the second uplink fresh value, and obtaining the second securely protected uplink NAS load, and so on, until the security protection processing for all uplink NAS loads is completed.

[0097] It should be noted that the AIoT device carries the first uplink fresh value in the first secure uplink NAS load, but does not carry the corresponding uplink fresh value in other secure uplink NAS loads.

[0098] Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

[0099] Optionally, security protection may include only full protection.

[0100] Taking any one of the multiple uplink NAS loads as the j-th uplink NAS load as an example, the AIoT device can calculate the integrity check code corresponding to the j-th uplink NAS load based on the j-th uplink freshness value. Here, j is an integer greater than or equal to 1.

[0101] The algorithm for calculating the integrity check code can be the NAS integrity algorithm, which can be shared by AIoT devices and AIoTF. The key used to calculate the integrity check code can be the NAS key shared by AIoT devices and AIoTF, such as the NAS integrity protection key (referred to as the integrity key).

[0102] In addition to using the uplink fresh value, other parameters may be used to calculate the checksum. These other parameters must be parameters that both the AIoT device and the AIoTF possess. No restrictions or exhaustive lists are made here.

[0103] The j-th secure uplink NAS load can carry the j-th uplink NAS load itself and its corresponding integrity check code. This integrity check code can be placed after the j-th uplink NAS load. Additionally, the first secure uplink NAS load will also carry the first uplink fresh value. This first uplink fresh value can be placed before the first uplink NAS load; or it can be placed after the first uplink NAS load and before its corresponding integrity check code—this is not limited here.

[0104] Alternatively, security protection may consist of encryption only.

[0105] The AIoT device calculates a keystream based on the j-th uplink fresh value, and encrypts the j-th uplink NAS payload based on the keystream to obtain the j-th encrypted uplink NAS payload. Specifically, encrypting the j-th uplink NAS payload based on the keystream can be achieved by performing an XOR operation between the keystream and the j-th uplink NAS payload.

[0106] The algorithm for calculating the keystream can be a NAS encryption algorithm, which can be shared by the AIoT device and the AIoTF. The key used to calculate the keystream can be a NAS key shared by the AIoT device and the AIoTF, such as a NAS encryption key or a NAS confidentiality key. Besides using the uplink fresh value, other parameters may also be used to calculate the keystream. These other parameters must be possessed by both the AIoT device and the AIoTF; no restrictions or exhaustive lists are provided here. It should be noted that the length of the keystream can be the same as the length of the uplink NAS payload; this is not limited here.

[0107] The j-th secure uplink NAS payload can carry the j-th encrypted uplink NAS payload. Additionally, the first secure uplink NAS payload will also carry the first uplink fresh value. This first uplink fresh value can be placed before or after the first encrypted uplink NAS payload; there is no restriction on this.

[0108] Optionally, security protection may include encryption and integrity protection.

[0109] If encryption is performed before integrity verification, the AIoT device calculates the key stream based on the j-th uplink fresh value, encrypts the j-th uplink NAS payload based on the key stream, and obtains the j-th encrypted uplink NAS payload; and calculates the integrity verification code corresponding to the j-th uplink NAS payload based on the j-th uplink fresh value and the j-th encrypted uplink NAS payload.

[0110] If the integrity check is performed before encryption, the AIoT device calculates the integrity check code corresponding to the j-th uplink NAS load based on the j-th uplink fresh value; calculates the key stream based on the j-th uplink fresh value; and encrypts the j-th uplink NAS load based on the key stream to obtain the j-th encrypted uplink NAS load.

[0111] The j-th secure uplink NAS payload can carry the j-th encrypted uplink NAS payload and the integrity verification code corresponding to the j-th uplink NAS payload. The integrity verification code corresponding to the j-th uplink NAS payload can be placed after the j-th encrypted uplink NAS payload.

[0112] Additionally, the first secure uplink NAS payload will carry the first uplink fresh value. This first uplink fresh value can be placed before the first encrypted uplink NAS payload; or it can be placed after the first encrypted uplink NAS payload and before the integrity check code corresponding to the first uplink NAS payload. There is no limitation here.

[0113] Optionally, the AIoT device performing the processing in S403 can be performed alternately with the AIoT device performing the processing in S402.

[0114] For example, after the AIoT device completes the security protection of the first uplink NAS load based on the first uplink fresh value and obtains the first secure uplink NAS load, it sends the first secure uplink NAS load on the first uplink MAC PDU to the read / write device; then, after completing the security protection of the second uplink NAS load based on the second uplink fresh value and obtaining the second secure uplink NAS load, it sends the second secure uplink NAS load on the second uplink MAC PDU to the read / write device, and so on, without exhaustive enumeration.

[0115] Optionally, the AIoT device can execute S402 to complete the security protection of all uplink NAS loads. After obtaining all the securely protected uplink NAS loads, it can then execute S403 to sequentially carry each securely protected uplink NAS load on an uplink MAC PDU and send it to the read / write device.

[0116] For example, when an AIoT device sends multiple uplink MAC PDUs, the last uplink MAC PDU among the multiple uplink MAC PDUs may also carry first indication information, wherein the first indication information is used to indicate that the last uplink MAC PDU carries the last security-protected uplink NAS payload. Additionally, the first indication information may also be used to indicate that the security-protected uplink NAS message is segmented.

[0117] The last uplink MAC PDU can be the last of multiple uplink MAC PDUs. In other words, the AIoT device can also add first indication information to the last MAC PDU to indicate that the uplink MAC PDU is the last one, or that the uplink NAS load carried by the uplink MAC PDU for security protection is the last one.

[0118] After receiving multiple uplink MAC PDUs on the read / write device side, the processing of S411 may include: determining the receiving order of the security protection uplink NAS load carried by each uplink MAC PDU based on the receiving order of each uplink MAC PDU; adding a tag to each security protection uplink NAS load based on the receiving order of each security protection uplink NAS load; and concatenating or combining each security protection uplink NAS load and the tag corresponding to each security protection uplink NAS load according to the receiving order of each security protection uplink NAS load to obtain a security protection uplink NAS message.

[0119] Here, the tag corresponding to each secure uplink NAS load can be used to count each secure uplink NAS load. For example, the content of the tag corresponding to any secure uplink NAS load can be a numerical value, which can be a decimal value or a binary value, etc. For instance, the read / write device can add a tag to the first secure uplink NAS load carried by the first uplink MAC PDU; the content of the tag corresponding to the first secure uplink NAS load can be the numerical value 1 or the binary value "001", etc.; the read / write device can set a tag for the second secure uplink NAS load carried by the second uplink MAC PDU; the content of the tag corresponding to the second secure uplink NAS load can be the numerical value 2 or the binary value "010", etc., and so on, without exhaustive listing.

[0120] It should be understood that this is only an illustrative description of the label corresponding to each security protection uplink NAS load. In actual processing, the label corresponding to each security protection uplink NAS load may also have other specific functions, such as being used to segment uplink NAS loads with different security protections, and / or to indicate the position, order, or sorting of each security protection uplink NAS load in all security protection uplink NAS loads, etc. This is not limited or exhaustive.

[0121] When the read / write device splices or combines to obtain the secure uplink NAS message, the tag corresponding to each secure uplink NAS load can be placed before the secure uplink NAS load; or, the tag corresponding to each secure uplink NAS load can be placed after the secure uplink NAS load. This embodiment does not limit this.

[0122] AIoT devices can employ a single-threaded stop-and-wait mechanism. The read / write device waits for and receives multiple uplink MAC PDUs sent by the AIoT device until it reads the last uplink MAC PDU carrying the first indication information. At this point, it determines that the uplink MAC PDU is the last one or that the uplink MAC PDU carries the last security protection uplink NAS payload.

[0123] Optionally, after receiving each uplink MAC PDU, the read / write device performs tagging and splicing processing for each security-protected uplink NAS payload. For example, taking any one of the multiple uplink MAC PDUs as the j-th uplink MAC PDU, the read / write device can perform the S411 processing as follows:

[0124] When j equals 1, the receiving order of the first uplink MAC PDU is determined based on the receiving order of the first uplink NAS load; based on the receiving order of the first uplink NAS load, a tag is added to the first uplink NAS load; according to the receiving order of the first uplink NAS load, the first uplink NAS load and the tag corresponding to the first uplink NAS load are saved as the first combined content.

[0125] If j is greater than 1, check whether the j-th uplink MAC PDU carries the first indication information. If it does not carry the first indication information, determine the reception order of the j-th secure uplink NAS load based on the reception order of the j-th uplink MAC PDU. Add a tag to the j-th secure uplink NAS load based on the reception order of the j-th secure uplink NAS load. Combine or splice the j-th secure uplink NAS load and the tag corresponding to the j-th secure uplink NAS load into the (j-1)-th combined content and save it according to the reception order of the j-th secure uplink NAS load.

[0126] If the j-th uplink MAC PDU is detected to carry the first indication information, the receiving order of the j-th secure uplink NAS load is determined based on the receiving order of the j-th uplink MAC PDU; a tag is added to the j-th secure uplink NAS load based on the receiving order of the j-th secure uplink NAS load; according to the receiving order of the j-th secure uplink NAS load, the j-th secure uplink NAS load and the tag corresponding to the j-th secure uplink NAS load are combined or spliced ​​to the (j-1)-th combined content to determine the secure uplink NAS message.

[0127] Optionally, the read / write device performs the processing described in S411 after receiving multiple uplink MAC PDUs. For example, after receiving the current uplink MAC PDU, the read / write device checks whether the current uplink MAC PDU carries or contains the first indication information. If not, it saves the current uplink MAC PDU and continues to wait to receive the next uplink MAC PDU. If the current uplink MAC PDU carries or contains the first indication information, it determines that the currently received uplink MAC PDU is the last one. Based on the receiving order of each uplink MAC PDU in all saved uplink MAC PDUs, it determines the receiving order of the secure uplink NAS load carried by each uplink MAC PDU. Based on the receiving order of each secure uplink NAS load, it adds a tag to each secure uplink NAS load. According to the receiving order of each secure uplink NAS load, it concatenates or combines each secure uplink NAS load and the tag corresponding to each secure uplink NAS load to obtain the secure uplink NAS message.

[0128] In one example, if the tag corresponding to each security protection uplink NAS load is set before the security protection uplink NAS load, then after receiving the security protection uplink NAS message on the AIoTF side, S421 is executed. Specifically, it may include: if the j-th tag is found in the security protection uplink NAS message and the (j+1)-th tag is found, then all bits after the j-th tag and before the (j+1)-th tag are taken as the j-th security protection uplink NAS load; or, if the j-th tag is found in the security protection uplink NAS message and the (j+1)-th tag is not found, then all bits after the j-th tag up to the last bit are taken as the j-th security protection uplink NAS load, and the total security protection uplink NAS load is determined.

[0129] In one example, if the tag corresponding to each security protection uplink NAS load is set after the security protection uplink NAS load, then after receiving the security protection uplink NAS message on the AIoTF side, S421 is executed. Specifically, this may include: extracting from the j-th start bit in the security protection uplink NAS message up to the j-th tag, taking all bits after the j-th start bit and before the j-th tag as the j-th security protection uplink NAS load; if there are remaining bits after the j-th tag, then the first bit after the j-th tag is taken as the (j+1)-th start bit; if there are no remaining bits after the j-th tag, then the entire security protection uplink NAS load is determined. Wherein, when j equals 1, the first start bit is the first bit in the security protection uplink NAS message.

[0130] The AIoTF side verifies the uplink NAS load of the multiple security protections, including at least one of the following: decrypting each encrypted uplink NAS load carried by each security protection uplink NAS load; and performing integrity verification based on the integrity check code corresponding to each uplink NAS load carried by each security protection uplink NAS load.

[0131] In this embodiment, the number of uplink fresh values ​​is the same as the number of uplink NAS loads under security protection. AIoTF performs integrity verification and / or decryption on each uplink NAS load under security protection based on an uplink fresh value corresponding to that uplink NAS load.

[0132] Specifically, before AIoTF executes S422, it may include: decrypting each encrypted uplink NAS load based on the uplink freshness value corresponding to each security-protected uplink NAS load; and / or performing integrity verification based on the uplink freshness value corresponding to each security-protected uplink NAS load and the integrity check code corresponding to each uplink NAS load. The AIoTF execution of S422 may include: obtaining the uplink NAS message if the decryption of each encrypted uplink NAS load based on the uplink freshness value corresponding to each security-protected uplink NAS load is successful, and / or the integrity verification based on the uplink freshness value corresponding to each security-protected uplink NAS load and the integrity check code corresponding to each uplink NAS load is successful.

[0133] In this embodiment, before verifying the first secure uplink NAS load, AIoTF needs to extract the first uplink fresh value from the first secure uplink NAS load.

[0134] Before verifying each other secure uplink NAS load except the first secure uplink NAS load, AIoTF can calculate the uplink freshness value corresponding to each other secure uplink NAS load based on the first uplink freshness value.

[0135] Furthermore, the tags corresponding to the uplink NAS load of each security protection can also have a counting function. AIoTF can calculate the uplink freshness value corresponding to the uplink NAS load of other security protections based on the content of the tags corresponding to the uplink NAS load of each other security protection and the first uplink freshness value. For example, if the content of the tag corresponding to the uplink NAS load of a certain security protection is 3 or 011, then AIoTF can determine that the uplink NAS load of this security protection is the uplink NAS load of the 3rd security protection. Based on the first uplink freshness value plus 2 (i.e., 3 minus one), the uplink freshness value corresponding to the uplink NAS load of this security protection can be obtained.

[0136] In one example, after extracting any secure uplink NAS load, AIoTF can begin to verify the secure uplink NAS load based on the uplink fresh value corresponding to that secure uplink NAS load, until the last secure uplink NAS load is extracted and the verification is completed.

[0137] In one example, after extracting any security protection's uplink NAS load, AIoTF can first save the uplink NAS load of that security protection until the extraction of the last security protection's uplink NAS load is completed. Then, based on the uplink fresh value corresponding to each security protection's uplink NAS load, it can verify each security protection's uplink NAS load until the verification is completed.

[0138] Since AIoTF performs the same verification process for the uplink NAS load of each security protection, the following example will be taken as the uplink NAS load of the j-th security protection, where j is an integer greater than or equal to 1.

[0139] Optionally, security protection may include only full protection.

[0140] AIoTF calculates the j-th verification code based on the j-th uplink freshness value and the j-th uplink NAS load. If the j-th verification code matches the integrity verification code corresponding to the j-th uplink NAS load, the integrity verification of the j-th security protection's uplink NAS load is determined to be successful or passed. Alternatively, it may include: if the j-th verification code differs from the integrity verification code corresponding to the j-th uplink NAS load, the integrity verification of the j-th security protection's uplink NAS load is determined to have failed. The processing of AIoTF's verification code calculation should be the same as that of AIoT devices calculating integrity verification codes, and will not be repeated here.

[0141] In this case, AIoTF can sequentially perform integrity verification on the uplink NAS load of each security protection. AIoTF execution of S422 may include: if it is determined that the integrity verification of the uplink NAS load of each security protection is successful, concatenating the uplink NAS load carried in the uplink NAS load of each security protection in sequence to obtain the uplink NAS message.

[0142] In addition, if the AIoTF fails to verify the integrity of the uplink NAS load for any one or more security protections, the AIoTF may discard the uplink NAS message of that security protection and / or the AIoTF may send a notification or indication of verification failure to the AIoT device through the read / write device. Here, we do not limit or exhaust all the processes that the AIoTF may perform when the integrity verification fails.

[0143] Alternatively, security protection may consist of encryption only.

[0144] AIoTF calculates a keystream based on the j-th uplink freshness value, and decrypts the j-th encrypted uplink NAS payload based on the keystream. If decryption is successful, the j-th uplink NAS payload is obtained. Specifically, decrypting the j-th encrypted uplink NAS payload based on the keystream, and obtaining the j-th uplink NAS payload if decryption is successful, can be achieved by: performing an XOR operation between the keystream and the j-th encrypted uplink NAS payload; if decryption is successful, the j-th uplink NAS payload is obtained. Alternatively, it can include: if decryption fails (e.g., garbled characters are obtained), it can be determined that the decryption of the j-th encrypted uplink NAS payload has failed.

[0145] The algorithm and key used for calculating the AIoT key stream should be the same as those used by the AIoT device for calculating the key stream, and will not be repeated here.

[0146] In this case, AIoTF can decrypt each security protection uplink NAS load in sequence. AIoTF execution of S422 may include: if it is determined that each security protection uplink NAS load has been successfully decrypted, concatenating each decrypted uplink NAS load in sequence to obtain the uplink NAS message.

[0147] In addition, if AIoTF fails to decrypt any one or more security-protected uplink NAS payloads, AIoTF may discard the security-protected uplink NAS message and / or AIoTF may send a decryption failure notification or indication to the AIoT device through the read / write device. Here, we do not limit or exhaust all the processes that AIoTF may perform when decryption fails.

[0148] Optionally, security protection may include encryption and integrity protection.

[0149] If the AIoT device encrypts before ensuring integrity, then AIoTF performs integrity verification before decryption. AIoTF calculates the j-th verification code based on the j-th uplink fresh value and the j-th encrypted uplink NAS payload. If the j-th verification code is the same as the integrity verification code corresponding to the j-th uplink NAS payload, a key stream is calculated based on the j-th uplink fresh value. The j-th encrypted uplink NAS payload is then decrypted based on the key stream. If decryption is successful, the j-th uplink NAS payload is obtained.

[0150] If the AIoT device performs integrity verification before encryption, then AIoTF decrypts first and then performs integrity verification. AIoTF calculates a keystream based on the j-th uplink fresh value, and decrypts the j-th uplink NAS payload based on the keystream. If decryption is successful, the j-th uplink NAS payload is obtained. Based on the j-th uplink fresh value and the j-th uplink NAS payload, the j-th verification code is calculated. If the j-th verification code is the same as the integrity verification code corresponding to the j-th uplink NAS payload, the integrity verification of the j-th secure uplink NAS payload is determined to be successful or passed.

[0151] Additionally, it may include: determining that the verification of the security protection of the j-th uplink NAS load has failed if the j-th verification code is different from the integrity verification code corresponding to the j-th uplink NAS load and / or if decryption fails.

[0152] In this scenario, AIoTF's execution of S422 may include: if it is determined that the uplink NAS payloads for each security protection have been successfully decrypted and their integrity verification has been successful, concatenating the decrypted uplink NAS payloads in sequence to obtain an uplink NAS message. Additionally, if AIoTF fails to decrypt and / or verify the integrity of any one or more uplink NAS payloads for security protection, AIoTF may discard the uplink NAS message for that security protection and / or AIoTF may send a notification or indication of verification failure to the AIoT device via the read / write device. This does not limit or exhaustively list all possible processes that AIoTF may perform when decryption and / or integrity verification fail.

[0153] Taking a security protection model that only includes encryption as an example, this embodiment is illustrated as follows: The AIoT device generates a nonce (the first uplink fresh value) and increments the nonce during use. That is, the nonce value is used to encrypt the first uplink NAS payload, which is then carried in the first uplink MAC PDU and sent to the Reader. In addition to carrying the first encrypted uplink NAS payload, the first secure uplink NAS payload also carries the plaintext of the nonce. The AIoT device then increments the nonce by one for encrypting the next uplink NAS payload, carries the next encrypted uplink NAS payload in the next uplink MAC PDU, and sends it to the Reader. However, when sending the next secure uplink NAS payload, only the next encrypted uplink NAS payload is included. The Reader tags each received secure uplink NAS payload with a counter and sends the concatenated secure uplink NAS message to the AIoTF. After receiving the secure uplink NAS message, AIoTF can use the plaintext nonce to decrypt the first uplink NAS payload. It can then increment the nonce to decrypt the next uplink NAS payload, and so on, until the last uplink NAS payload is decrypted, thus obtaining the complete uplink NAS message.

[0154] In this embodiment, the AIoT device does not need to dynamically maintain the fresh value, which reduces the exposure to generate the fresh value and ensures both security and energy efficiency.

[0155] In one embodiment, each of the plurality of secure uplink NAS loads carries an uplink fresh value corresponding to each secure uplink NAS load, wherein the uplink fresh value corresponding to each secure uplink NAS load is generated by the AIoT device.

[0156] Before performing security protection on each uplink NAS load, the AIoT device generates an uplink fresh value corresponding to that uplink NAS load. This embodiment does not limit the method by which the AIoT device generates each uplink fresh value; as long as the specific values ​​of different uplink fresh values ​​are different, they are within the protection scope of this embodiment. The uplink fresh value can also be alternatively referred to as an uplink nonce, or an uplink counter, etc.

[0157] The AIoT device executing S402 may include: the AIoT device generating a first uplink fresh value, performing security protection on the first uplink NAS load among multiple uplink NAS loads based on the first uplink fresh value, to obtain the first securely protected uplink NAS load; the AIoT device generating a second uplink fresh value, wherein the second uplink fresh value is different from the first uplink fresh value, performing security protection on the second uplink NAS load among multiple uplink NAS loads based on the second uplink fresh value, to obtain the second securely protected uplink NAS load, and so on, until the security protection processing of all uplink NAS loads is completed.

[0158] It should be noted that each AIoT device generates its own uplink fresh value, and the way each AIoT device generates its own uplink fresh value is unique and not known to AIoTF. Therefore, the corresponding uplink fresh value needs to be carried in each secure uplink NAS load.

[0159] Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

[0160] For example, security protection may only include integrity verification. The processing of the integrity verification code calculated by the AIoT device for each uplink NAS load is the same as in the previous embodiment and will not be repeated. Taking any one of the multiple uplink NAS loads as the j-th uplink NAS load as an example, the j-th secure uplink NAS load may carry the j-th uplink NAS load, the integrity verification code corresponding to the j-th uplink NAS load, and the j-th uplink freshness value.

[0161] For example, security protection may consist of encryption alone. The processing of encryption for each uplink NAS load by the AIoT device is the same as in the previous embodiments and will not be repeated. In this example, the j-th secure uplink NAS load may carry the j-th encrypted uplink NAS load and the j-th uplink fresh value.

[0162] For example, security protection may include encryption and integrity verification. The processing of the AIoT device encrypting each uplink NAS load and calculating the corresponding integrity verification code is the same as in the previous embodiments and will not be repeated. In this example, the j-th secure uplink NAS load may carry the j-th encrypted uplink NAS load, the integrity verification code corresponding to the j-th uplink NAS load, and the j-th uplink freshness value.

[0163] In this embodiment, the description of the AIoT device performing the S403 process is the same as in the previous embodiment, and will not be repeated.

[0164] After receiving multiple uplink MAC PDUs on the read / write device side, the processing of S411 is performed. The specific description of the read / write device performing S411 is the same as in the previous embodiment and will not be repeated.

[0165] The description of the processing of S421 performed on the AIoTF side is the same as that in the previous embodiments, and will not be repeated here.

[0166] Before AIoTF executes S422, it may include: decrypting each encrypted uplink NAS load based on the uplink freshness value corresponding to each security-protected uplink NAS load; and / or performing integrity verification based on the uplink freshness value corresponding to each security-protected uplink NAS load and the integrity check code corresponding to each uplink NAS load.

[0167] The AIoTF's execution of S422 may include: obtaining the uplink NAS message if the decryption of each encrypted uplink NAS load based on the uplink fresh value corresponding to each security-protected uplink NAS load is successful, and / or if the integrity verification based on the uplink fresh value corresponding to each security-protected uplink NAS load and the integrity check code corresponding to each uplink NAS load is successful.

[0168] In this embodiment, each security protection uplink NAS load also carries an uplink fresh value; before verifying each security protection uplink NAS load, AIoTF needs to extract its corresponding uplink fresh value from each security protection uplink NAS load.

[0169] In this embodiment, the uplink freshness value corresponding to each secure uplink NAS load can also have anti-replay verification functionality. The following example illustrates this using any secure uplink NAS load as the j-th secure uplink NAS load.

[0170] Optionally, security protection may include only full protection.

[0171] AIoTF determines whether the j-th uplink fresh value is the same as other uplink fresh values. If they are different, it calculates the j-th verification code based on the j-th uplink fresh value and the j-th uplink NAS load. If the j-th verification code is the same as the integrity verification code corresponding to the j-th uplink NAS load, it determines that the integrity verification of the uplink NAS load for the j-th security protection is successful or passes.

[0172] AIoTF processing may also include: determining that the integrity verification of the uplink NAS load for the j-th security protection has failed if the j-th verification code is different from the integrity verification code corresponding to the j-th uplink NAS load; and / or, determining that the uplink NAS load for the j-th security protection is a replay if the j-th uplink freshness value is the same as other uplink freshness values.

[0173] Here, if j equals 1, then the first uplink fresh value can be assumed to be different from the other uplink fresh values; if j is greater than 1, then the other uplink fresh values ​​can refer to each uplink fresh value from the first uplink fresh value to the (j-1)th uplink fresh value.

[0174] The algorithm and key used for calculating the AIoTF verification code should be the same as those used by the AIoT device to calculate the integrity verification code, and will not be repeated here.

[0175] In this case, AIoTF execution of S422 may include: after determining that the integrity verification of the uplink NAS load for each security protection is successful and that each uplink fresh value is different from other uplink fresh values, concatenating the uplink NAS loads carried in the uplink NAS load of each security protection in sequence to obtain the uplink NAS message.

[0176] If AIoTF fails to verify the integrity of uplink NAS load for any one or more security protections and / or determines that any one uplink fresh value is the same as other uplink fresh values, AIoTF may discard the uplink NAS message for that security protection and / or AIoTF may send a notification or indication of verification failure to AIoTF through the read / write device. Here, we do not limit or exhaust all the processes that AIoTF may perform when integrity verification fails.

[0177] Alternatively, security protection may consist of encryption only.

[0178] AIoTF determines whether the j-th uplink freshness value is the same as other uplink freshness values. If they are different, it calculates a keystream based on the j-th uplink freshness value and decrypts the j-th encrypted uplink NAS payload based on the keystream. If decryption is successful, the j-th uplink NAS payload is obtained. The decryption process based on the keystream for the j-th encrypted uplink NAS payload is the same as in the previous embodiment and will not be described again.

[0179] Additionally, it may include: determining that the decryption of the j-th encrypted uplink NAS load failed in the case of decryption failure (e.g., obtaining garbled text); and / or, determining that the j-th secure uplink NAS load is a replay if the j-th uplink fresh value is the same as other uplink fresh values.

[0180] In this case, AIoTF execution of S422 may include: after determining that each security-protected uplink NAS load has been successfully decrypted and that each uplink fresh value is different from other uplink fresh values, concatenating each decrypted uplink NAS load in sequence to obtain an uplink NAS message.

[0181] Additionally, if AIoTF fails to decrypt the uplink NAS payload of any one or more security protections and / or determines that any one uplink fresh value is the same as other uplink fresh values, AIoTF may discard the uplink NAS message of that security protection and / or AIoTF may send a notification or indication of verification failure to AIoTF through the read / write device.

[0182] Optionally, security protection may include encryption and integrity protection.

[0183] If the AIoT device encrypts before ensuring integrity, then AIoTF performs integrity verification before decryption. AIoTF determines whether the j-th uplink fresh value is the same as other uplink fresh values. If they are different, it calculates the j-th verification code based on the j-th uplink fresh value and the j-th encrypted uplink NAS payload. If the j-th verification code is the same as the integrity verification code corresponding to the j-th uplink NAS payload, it calculates the key stream based on the j-th uplink fresh value and decrypts the j-th uplink NAS payload based on the key stream. If decryption is successful, the j-th uplink NAS payload is obtained.

[0184] If the AIoT device performs integrity verification before encryption, then AIoTF decrypts first and then performs integrity verification. AIoTF determines whether the j-th uplink fresh value is the same as other uplink fresh values. If they are different, it calculates a key stream based on the j-th uplink fresh value, and decrypts the j-th uplink NAS payload based on the key stream. If decryption is successful, the j-th uplink NAS payload is obtained. Based on the j-th uplink fresh value and the j-th uplink NAS payload, the j-th verification code is calculated. If the j-th verification code is the same as the integrity verification code corresponding to the j-th uplink NAS payload, the integrity verification of the j-th secure uplink NAS payload is determined to be successful or passed.

[0185] Additionally, it may include: determining that the verification of the uplink NAS load for the j-th security protection has failed if the j-th verification code is different from the integrity verification code corresponding to the j-th uplink NAS load, and / or if decryption fails, and / or if the j-th uplink fresh value is the same as other uplink fresh values.

[0186] In this case, AIoTF execution of S422 may include: after determining that each security-protected uplink NAS load has been successfully decrypted, has been successfully verified for integrity, and that each uplink fresh value is different from other uplink fresh values, concatenating each decrypted uplink NAS load in sequence to obtain an uplink NAS message.

[0187] In addition, if AIoTF fails to decrypt the uplink NAS load of any one or more security protections, and / or fails to verify integrity, and / or determines that any one uplink fresh value is the same as other uplink fresh values, AIoTF may discard the uplink NAS message of that security protection and / or AIoTF may send a notification or indication of verification failure to AIoTF through the read / write device. Here, we do not limit or exhaust all the processes that AIoTF may perform when decryption and / or integrity verification fail.

[0188] Taking a security protection model that only includes encryption as an example, this embodiment provides an exemplary description: For each D2R message to be sent, the AIoT device generates a random number (nonce) and uses this random number as one of the parameters for generating the keystream. To ensure that the AIoTF can successfully decrypt the message, the device needs to send the plaintext of this random number to the AIoTF.

[0189] The solution provided in this embodiment eliminates the need for dynamic maintenance of fresh values ​​on the AIoT device side, resulting in lower energy consumption for the AIoT device.

[0190] In one embodiment, the uplink freshness value corresponding to each of the multiple secure uplink NAS loads is determined based on an uplink counter, wherein the uplink counter is jointly maintained by the AIoT device and the AIoT function.

[0191] In this embodiment, the AIoT device and the AIoTF can jointly maintain an uplink counter, the initial value of which is the same for both. In this embodiment, the uplink fresh value can also be called the uplink count value (Counter).

[0192] Taking any uplink NAS load as the j-th uplink NAS load as an example, the processing of S402 by the AIoT device is illustrated as follows: The AIoT device uses the current count value of the uplink counter as the j-th uplink fresh value, and performs security protection on the j-th uplink NAS load among multiple uplink NAS loads based on the j-th uplink fresh value, thus obtaining the j-th secure uplink NAS load; the AIoT device increments the value of the uplink counter by one. Wherein, when j equals 1, the current count value of the uplink counter can be the initial value of the uplink counter, that is, when the AIoT device performs security protection on the first uplink NAS load, it can directly use the initial value of the uplink counter as the first uplink fresh value (or uplink count value).

[0193] Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

[0194] For example, security protection may only include integrity verification. In this example, the uplink NAS load of the j-th security protection may carry the integrity verification code corresponding to the j-th uplink NAS load.

[0195] For example, security protection may consist of encryption only. In this example, the j-th secure uplink NAS load may carry the i-th encrypted uplink NAS load.

[0196] For example, security protection may include encryption and integrity verification. In this example, the j-th secure uplink NAS payload may carry the j-th encrypted uplink NAS payload and the integrity verification code corresponding to the j-th uplink NAS payload.

[0197] In this embodiment, the description of the AIoT device performing the S403 process is the same as in the previous embodiment, and will not be repeated.

[0198] After receiving multiple uplink MAC PDUs on the read / write device side, the processing in S411 is executed. The specific description of the read / write device executing S411 is the same as in the previous embodiment and will not be repeated. The tag set by the read / write device for each secure uplink NAS load can also be used to segment uplink NAS loads with different security protections, and / or to indicate the position, order, or sorting of each secure uplink NAS load in all secure uplink NAS loads, and / or to count each secure uplink NAS load, etc., without limitation or exhaustive list.

[0199] The description of the processing of S421 performed on the AIoTF side is the same as that in the previous embodiments, and will not be repeated here.

[0200] In this embodiment, the uplink NAS load of each security protection does not carry the uplink fresh value; before verifying the uplink NAS load of each security protection, AIoTF needs to determine the uplink fresh value corresponding to the uplink NAS load of each security protection based on the count value of the uplink counter corresponding to the AIoT device it maintains.

[0201] For example, when AIoTF verifies the first secure uplink NAS load, it can directly use the initial value of the uplink counter as the first uplink fresh value (or uplink count value). After AIoTF completes the verification of the first secure uplink NAS load, it can increment the uplink counter value by one. Then, when verifying the second secure uplink NAS load, it can use the current count value of the uplink counter as the uplink fresh value corresponding to the second secure uplink NAS load, and so on, without exhaustive enumeration.

[0202] The following example illustrates the process of using any one of the security-protected uplink NAS loads as the j-th security-protected uplink NAS load.

[0203] Optionally, security protection may include only full protection.

[0204] The AIoTF's verification process for the integrity check code of the j-th uplink NAS load is the same as in the previous embodiments and will not be described again. In this case, AIoTF's execution of S422 may include: if it is determined that the integrity verification of each security-protected uplink NAS load is successful, concatenating the uplink NAS loads carried in each security-protected uplink NAS load in sequence to obtain the uplink NAS message. Furthermore, the related processing that AIoTF may perform when integrity verification fails is also the same as in the previous embodiments and will not be described again.

[0205] Alternatively, security protection may consist of encryption only.

[0206] The AIoTF's decryption process for the j-th encrypted uplink NAS payload is the same as in the previous embodiments and will not be described again. In this case, AIoTF's execution of S422 may include: if it is determined that each secure uplink NAS payload has been successfully decrypted, concatenating the decrypted uplink NAS payloads in sequence to obtain the uplink NAS message. Furthermore, the AIoTF's handling when decryption of any one or more secure uplink NAS payloads fails is also the same as in the previous embodiments and will not be described again.

[0207] Optionally, security protection may include encryption and integrity protection.

[0208] If the AIoT device is encrypted first and then protected, then AIoTF will first perform integrity verification and then decryption. The specific verification process is the same as the aforementioned embodiments and will not be repeated here.

[0209] If the AIoT device is fully protected before encryption, then AIoTF will decrypt first and then perform integrity verification. The specific verification process is the same as in the aforementioned embodiments, and will not be repeated here.

[0210] In this case, AIoTF execution of S422 may include: if it is determined that each uplink NAS load for each security protection has been successfully decrypted and its integrity has been successfully verified, concatenating each decrypted uplink NAS load in sequence to obtain an uplink NAS message.

[0211] In addition, the handling of AIoTF in the event of failure to decrypt uplink NAS load under any one or more security protections, and / or failure to verify integrity, is the same as in the aforementioned embodiments, and will not be repeated here.

[0212] Taking security protection consisting only of encryption as an example, this embodiment provides an exemplary description: The AIoT device and AIoTF jointly maintain COUNT, using COUNT as one of the parameters for generating the keystream. After the AIoT device performs security protection processing for the current uplink NAS load and sends it out, it increments COUNT by one before processing the next uplink NAS load. In this embodiment, it is not necessary for the AIoT device to transmit the value of COUNT over the air interface.

[0213] The solution provided in this embodiment requires the AIoT device to maintain the COUNT value first, and this maintenance is dynamic. For the AIoT device, it can dynamically maintain tens of bits of characters and store them in dynamic NVM (non-volatile memory). Since the AIoT device needs a lot of energy to write to the NVM, this method is highly secure.

[0214] In some embodiments, processing the uplink NAS message to obtain multiple secure uplink NAS loads includes: dividing the uplink NAS message into multiple uplink NAS loads; determining the current uplink freshness value based on the uplink timer and the initial uplink freshness value, wherein the uplink timer and the initial uplink freshness value are jointly maintained by the AIoT device and the AIoT function; and performing security protection on the multiple uplink NAS loads based on the current uplink freshness value to obtain the multiple secure uplink NAS loads. That is, S402 above can be replaced with: dividing the uplink NAS message into multiple uplink NAS loads; determining the current uplink freshness value based on the uplink timer and the initial uplink freshness value; and performing security protection on the multiple uplink NAS loads based on the current uplink freshness value to obtain the multiple secure uplink NAS loads.

[0215] Unlike the previous embodiments, the update of the uplink fresh value does not depend on the number of uplink NAS loads, but is related to the timing duration of the uplink timer. That is, the value (or count value) of the uplink fresh value will only be updated after a certain duration. During this duration (i.e., within the timing duration of the uplink timer), no matter how many uplink NAS loads the AIoT device protects, it will not update the value (or count value) of the uplink fresh value.

[0216] The determination of the current uplink fresh value based on the uplink timer and the uplink initial fresh value includes one of the following: before the uplink timer expires for the first time, the uplink initial fresh value is used as the current uplink fresh value; when the uplink timer expires, the current uplink fresh value is incremented by one to obtain the updated current uplink fresh value.

[0217] The process of determining the current uplink fresh value based on the uplink timer and the initial uplink fresh value, and then applying security protection to the multiple uplink NAS loads based on the current uplink fresh value, can be executed alternately. That is, before the uplink timer expires for the first time, the AIoT device uses the initial uplink fresh value as the current uplink fresh value and sequentially begins the relevant security protection processing for multiple uplink NAS loads. Simultaneously, the AIoT device continuously monitors whether the uplink timer has expired. Once the uplink timer expires (e.g., reaches its set duration), the current uplink fresh value is updated by incrementing it by one. Then, the current uplink fresh value is used to sequentially apply the relevant security protection processing to each uplink NAS load, and so on.

[0218] For example, before the uplink timer expires for the first time, the AIoT device uses the initial uplink fresh value as the current uplink fresh value. Based on the current uplink fresh value, it performs security protection on at least a portion of the multiple uplink NAS loads to obtain multiple protected uplink NAS loads. At the same time, the AIoT device keeps monitoring whether the uplink timer has expired in real time. If the uplink timer is detected to have expired for the first time, the current uplink fresh value is incremented by one to obtain the updated current uplink fresh value. If there are still remaining uplink NAS loads among the multiple uplink NAS loads, the remaining uplink NAS loads are protected based on the updated current uplink fresh value, and so on.

[0219] Taking any uplink NAS load as the j-th uplink NAS load as an example, the processing performed by the AIoT device is illustrated as follows: The AIoT device checks whether the uplink timer's duration has expired. If the uplink timer's duration has not expired, the j-th uplink NAS load is protected based on the current uplink freshness value, resulting in the j-th protected uplink NAS load. If the uplink timer's duration has expired, the uplink timer's duration is reset to zero and restarted. The current uplink freshness value is incremented by one to obtain the updated current uplink freshness value. Based on the current uplink freshness value, the j-th uplink NAS load is protected, resulting in the j-th protected uplink NAS load. Before the first timeout of the uplink timer's duration, the current uplink freshness value is equal to the initial uplink freshness value.

[0220] Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

[0221] For example, security protection may only include integrity verification. In this example, the uplink NAS load of the j-th security protection may carry the integrity verification code corresponding to the j-th uplink NAS load.

[0222] For example, security protection may consist of encryption only. In this example, the j-th secure uplink NAS load may carry the i-th encrypted uplink NAS load.

[0223] For example, security protection may include encryption and integrity verification. In this example, the j-th secure uplink NAS payload may carry the j-th encrypted uplink NAS payload and the integrity verification code corresponding to the j-th uplink NAS payload.

[0224] In this embodiment, the description of the AIoT device performing the S403 process is the same as in the previous embodiment, and will not be repeated.

[0225] After receiving multiple uplink MAC PDUs on the read / write device side, the processing of S411 is performed. The specific description of the read / write device performing S411 is the same as in the previous embodiment and will not be repeated.

[0226] The processing on the AIoTF side also includes: obtaining multiple secure uplink NAS loads based on the tags corresponding to each secure uplink NAS load contained in the secure uplink NAS message; determining the current uplink freshness value based on the uplink timer and the uplink initial freshness value, wherein the uplink timer and the uplink initial freshness value are jointly maintained by the AIoT device and the AIoT function; and obtaining the uplink NAS message if the multiple secure uplink NAS loads are successfully verified based on the current uplink freshness value.

[0227] In other words, the description of the processing of S421 on the AIoTF side is the same as that in the previous embodiment, and will not be repeated. The aforementioned S422 is replaced by: determining the current uplink fresh value based on the uplink timer and the uplink initial fresh value; and obtaining the uplink NAS message if the uplink NAS load verification of the multiple security protections is successful based on the current uplink fresh value.

[0228] In this embodiment, each secure uplink NAS load does not carry uplink fresh value; AIoTF also needs to determine the current uplink fresh value based on the uplink timer and uplink initial fresh value corresponding to the AIoT device it maintains.

[0229] The AIoTF execution is based on the uplink timer and the uplink initial fresh value. The process of determining the current uplink fresh value is the same as that of the aforementioned AIoT devices, and will not be repeated here.

[0230] It's important to understand that the AIoTF's processes for determining the current uplink freshness value based on the uplink timer and the initial uplink freshness value, as well as the verification of the uplink NAS loads for multiple security protections based on this current uplink freshness value, can be executed alternately. That is, before the uplink timer expires for the first time, the AIoTF uses the initial uplink freshness value as the current uplink freshness value and sequentially begins the verification process for the uplink NAS loads of multiple security protections. Simultaneously, the AIoTF continuously monitors whether the uplink timer has expired. Once the uplink timer expires (e.g., reaches its set duration), it updates the current uplink freshness value by incrementing it by one. Then, it continues to use the current uplink freshness value to sequentially verify the uplink NAS loads of each security protection, and so on. For example, before verifying the uplink NAS load for each security protection, AIoTF checks whether the uplink timer's duration has expired. If the uplink timer's duration has not expired, the current uplink fresh value is used to verify the uplink NAS load for the security protection. If the uplink timer's duration has expired, the uplink timer's duration is reset to zero and restarted, and the current uplink fresh value is incremented by one to obtain the updated current uplink fresh value. The uplink NAS load for the security protection is then verified based on this updated uplink fresh value. Before the uplink timer's duration expires for the first time, the current uplink fresh value is equal to the initial uplink fresh value.

[0231] The verification of the multiple security protections for the uplink NAS load is the same as in the previous embodiment, which also includes decrypting each encrypted uplink NAS load carried by each security protection uplink NAS load, and / or performing integrity verification based on the integrity check code corresponding to each uplink NAS load carried by each security protection uplink NAS load in the multiple security protections.

[0232] Taking any one of the security-protected uplink NAS loads as the j-th security-protected uplink NAS load as an example, the processing of verifying the security-protected uplink NAS load is illustrated.

[0233] Optionally, security protection may include only full protection.

[0234] AIoTF calculates the j-th verification code based on the current uplink freshness value and the j-th uplink NAS load. If the j-th verification code is the same as the integrity verification code corresponding to the j-th uplink NAS load, it determines that the integrity verification of the uplink NAS load for the j-th security protection is successful or passes. It may also include: if the j-th verification code is different from the integrity verification code corresponding to the j-th uplink NAS load, it determines that the integrity verification of the uplink NAS load for the j-th security protection has failed. The related processing of AIoTF calculating the verification code is the same as in the aforementioned embodiments and will not be described in detail. In this case, AIoTF execution of S422 may include: if it is determined that the integrity verification of the uplink NAS load for each security protection is successful, concatenating the uplink NAS loads carried in the uplink NAS load of each security protection in sequence to obtain the uplink NAS message. Furthermore, the related processing of AIoTF when the integrity verification of the uplink NAS load for any one or more security protections fails will not be described in detail.

[0235] Alternatively, security protection may consist of encryption only.

[0236] AIoTF calculates a keystream based on the current uplink freshness value. The decryption process for the j-th encrypted uplink NAS payload based on this keystream is the same as in the previous embodiments and will not be repeated. In this case, AIoTF execution of S422 may include: if it is determined that each secure uplink NAS payload has been successfully decrypted, concatenating the decrypted uplink NAS payloads in sequence to obtain the uplink NAS message. Furthermore, the handling by AIoTF when decryption of any one or more secure uplink NAS payloads fails is the same as in the previous embodiments and will not be repeated.

[0237] Optionally, security protection may include encryption and integrity protection.

[0238] If the AIoT device is encrypted before integrity verification, then AIoTF performs integrity verification before decryption. The specific verification process is the same as in the aforementioned embodiments and will not be repeated. If the AIoT device is secure before encryption, then AIoTF decrypts before integrity verification. The specific verification process is the same as in the aforementioned embodiments and will not be repeated. In this case, AIoTF execution of S422 may include: if it is determined that the uplink NAS load for each security protection is successfully decrypted and the integrity verification is successful, concatenating the decrypted uplink NAS loads in sequence to obtain the uplink NAS message. In addition, the related processing of AIoTF when decryption of any one or more uplink NAS loads for security protection fails and / or integrity verification fails is the same as in the aforementioned embodiments and will not be repeated.

[0239] Taking security protection that only includes encryption as an example, this embodiment is illustrated as follows: The AIoT device and the AIoTF jointly maintain the same uplink initial fresh value, which can be the same COUNT, the same random number, or the same index number. Furthermore, the AIoT device and the AIoTF jointly maintain a timer with the same set timeout duration. When the timer expires, the current uplink fresh value is incremented by one. Therefore, the same uplink fresh value may be reused for a period of time.

[0240] The solution provided in this embodiment requires the AIoT device to dynamically maintain a fresh value. This value does not need to be transmitted over the air interface. By using this fresh value, the security of the uplink NAS messages transmitted by the AIoT device can be guaranteed, while reducing energy consumption to a certain extent.

[0241] In some possible implementations, after the AIoT device performs overall security protection on the uplink NAS messages, it divides the secure uplink NAS messages into multiple secure uplink NAS payloads and sends them out. Specifically, the AIoT device's security protection of the uplink NAS messages to obtain multiple secure uplink NAS payloads may include: performing security protection on the uplink NAS messages to obtain secure uplink NAS messages; and dividing the secure uplink NAS messages into the multiple secure uplink NAS payloads.

[0242] Referring to Figure 5, the processing of dividing the overall security protection uplink NAS message of the AIoT device into multiple security protection uplink NAS loads in this embodiment is illustrated by example: The AIoT device performs overall security protection on the uplink NAS message (i.e., NASC) to obtain the security protection uplink NAS message (Figure 5 shows the security protection NASC); then the security protection uplink NAS message is divided into multiple security protection uplink NAS loads, such as protected NAS load 1, protected NAS load 2 to protected NAS load n as simply illustrated in Figure 5; finally, multiple uplink MAC PDUs respectively carry the multiple security protection uplink NAS loads, such as the MAC PDU carrying protected NAS load 1, the MAC PDU carrying protected NAS load 2 to the MAC PDU carrying protected NAS load n as simply illustrated in Figure 5. Each MAC PDU also encapsulates its own packet header, which is not limited in this embodiment.

[0243] The communication method for segmenting and sending multiple security-protected uplink NAS payloads after the overall protection uplink NAS message provided in this embodiment will be explained with reference to Figure 6:

[0244] After the AIoT device generates an uplink NAS message, it executes steps S601 to S603:

[0245] S601 processes the uplink NAS messages to obtain secure uplink NAS messages;

[0246] S602 divides the secure uplink NAS message into multiple secure uplink NAS payloads;

[0247] S603, send multiple uplink MAC PDUs to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security-protected uplink NAS loads.

[0248] The read / write device side executes S611 to S612:

[0249] S611, based on the order of the multiple security-protected uplink NAS loads, the security-protected uplink NAS message is concatenated to obtain the security-protected uplink NAS message.

[0250] S612 sends a security-protected uplink NAS message to the AIoT function.

[0251] AIoTF executes S621, and if the uplink NAS message for security protection is successfully verified, it obtains the uplink NAS message.

[0252] In this embodiment, the secure uplink NAS message carries at least one of the following: an encrypted uplink NAS message and a first integrity check code.

[0253] Optionally, security protection may include only full protection.

[0254] An AIoT device executing S601 may include: calculating a first integrity check code based on an uplink NAS message.

[0255] The uplink NAS message can refer to the plaintext content of the uplink NAS message, which may include data reported by the AIoT device and / or the identifier of the AIoT device.

[0256] The algorithm for calculating the first integrity check code can be the NAS integrity algorithm, and the key used to calculate the first integrity check code can be the NAS key shared by the AIoT device and AIoTF, such as the NAS integrity protection key (referred to as the integrity key). Other parameters may also be used to calculate the first integrity check code. These other parameters need to be parameters that both the AIoT device and AIoTF possess. This is not limited or exhaustive.

[0257] The secure uplink NAS message carries the uplink NAS message (or the plaintext content of the uplink NAS message) and a first integrity check code. The first integrity check code can be placed after the plaintext content of the uplink NAS message.

[0258] Alternatively, security protection may consist of encryption only.

[0259] The execution of S601 by an AIoT device may include: calculating a keystream, and encrypting the uplink NAS message (or the plaintext content of the uplink NAS message) based on the keystream to obtain an encrypted uplink NAS message. The encryption of the uplink NAS message based on the keystream can be achieved by performing an XOR operation between the keystream and the uplink NAS message. The algorithm for calculating the keystream can be a NAS encryption algorithm, which can be shared by the AIoT device and the AIoTF. The key used to calculate the keystream can be a NAS key shared by the AIoT device and the AIoTF, such as a NAS encryption key or a NAS confidentiality key. Other parameters may also be used in calculating the keystream; these other parameters must be possessed by both the AIoT device and the AIoTF, and are not limited or exhaustively listed here. It should be noted that the length of the keystream can be the same as the length of the uplink NAS message; this is not limited here.

[0260] Securely protected uplink NAS messages carry encrypted uplink NAS messages.

[0261] Optionally, security protection may include encryption and integrity protection.

[0262] If encryption is performed before integrity verification, the AIoT device executing S601 may include: calculating a key stream, encrypting the uplink NAS message (or the plaintext content of the uplink NAS message) based on the key stream to obtain an encrypted uplink NAS message; and calculating a first integrity verification code based on the encrypted uplink NAS message.

[0263] If the integrity check is performed before encryption, the execution of S601 by the AIoT device may include: calculating the first integrity check code based on the uplink NAS message (or the plaintext content of the uplink NAS message); calculating the key stream; encrypting the uplink NAS message based on the key stream to obtain the encrypted uplink NAS message.

[0264] The secure uplink NAS message carries an encrypted uplink NAS message and a first integrity check code; the first integrity check code can be placed after the encrypted uplink NAS message.

[0265] In S602, AIoT devices can divide a secure uplink NAS message into multiple secure uplink NAS payloads based on the specified length.

[0266] In S603, when an AIoT device sends multiple uplink MAC PDUs, the last uplink MAC PDU carries first indication information. This first indication information indicates at least one of the following: the security-protected uplink NAS payload carried by the last uplink MAC PDU carries the first integrity check code; or the last uplink MAC PDU carries the last security-protected uplink NAS payload. Additionally, this first indication information can also be used to indicate that the security-protected uplink NAS message has been segmented.

[0267] In other words, the AIoT device can add the first indication information to the last MAC PDU to indicate that the uplink MAC PDU is the last one, and / or the uplink NAS load carrying the security protection carried by the uplink MAC PDU is the last one, and / or the uplink NAS load carrying the security protection carried by the uplink MAC PDU carries the first integrity check code.

[0268] In some alternative examples, the first indication information can be used to instruct the secure uplink NAS payload carried by the first uplink MAC PDU to carry the first integrity check code. That is, the AIoT device can place the first integrity check code at the beginning of the secure uplink NAS message. In this case, when the AIoT device divides the secure uplink NAS payload into multiple secure uplink MAC PDUs, it can carry the first indication information in the last uplink MAC PDU to instruct the first secure uplink MAC PDU to carry the first integrity check code.

[0269] Executing S611 on the read / write device side may include: determining the last secure uplink NAS load among the secure uplink NAS loads based on the first indication information; and concatenating the secure uplink NAS message based on the order of the multiple secure uplink NAS loads.

[0270] Optionally, the process of S611 performed by the read / write device can be as follows: after receiving the current uplink MAC PDU, the read / write device checks whether the current uplink MAC PDU carries the first indication information. If not, it saves the current uplink MAC PDU and continues to wait to receive the next uplink MAC PDU. If the current uplink MAC PDU carries the first indication information, it determines that the currently received uplink MAC PDU is the last one and determines that the current uplink MAC PDU carries the last security protection uplink NAS load. Based on the receiving order of each uplink MAC PDU in all the saved uplink MAC PDUs, it determines the order of the security protection uplink NAS load carried by each uplink MAC PDU. Based on the order of each security protection uplink NAS load, it splices or combines each security protection uplink NAS load to obtain the security protection uplink NAS message.

[0271] Optionally, during the process of receiving each uplink MAC PDU, the read / write device performs uplink NAS load splicing for each security protection. For example, taking any one of the multiple uplink MAC PDUs as the j-th uplink MAC PDU, the read / write device's execution of S611 may specifically include:

[0272] When j equals 1, based on the receiving order of the first uplink MAC PDU, the order of the uplink NAS load with security protection carried by it is determined to be the first; the first uplink NAS load with security protection is saved as the first combined content.

[0273] If j is greater than 1, check whether the j-th uplink MAC PDU carries the first indication information. If it does not carry the first indication information, determine the order of the j-th security protection uplink NAS load based on the receiving order of the j-th uplink MAC PDU. Based on the order of the j-th security protection uplink NAS load, combine or splice the j-th security protection uplink NAS load to the end of the (j-1)-th combined content and save it.

[0274] If the j-th uplink MAC PDU is detected to carry the first indication information, it is determined that the j-th uplink MAC PDU carries the last security-protected uplink NAS load; based on the order of the security-protected uplink NAS load, the security-protected uplink NAS load is combined or spliced ​​to the end of the (j-1)-th combined content to determine the security-protected uplink NAS message.

[0275] Before AIoTF executes S621, it may include at least one of the following: decrypting the encrypted uplink NAS message; performing integrity verification on the secure uplink NAS message based on the first integrity check code. The process of AIoTF executing S621 may include: obtaining the uplink NAS message if the decryption of the encrypted uplink NAS message is successful and / or the integrity verification of the secure uplink NAS message is successful.

[0276] Optionally, security protection may include only full protection.

[0277] AIoTF calculates the first integrity verification code based on the uplink NAS message (or the plaintext content of the uplink NAS message). If the first integrity verification code is the same as the first integrity check code, it is determined that the integrity verification of the uplink NAS message for the security protection has been successful or passed. The process of AIoTF calculating the first integrity verification code should be the same as that of AIoT devices, and will not be repeated here.

[0278] In this case, if the integrity verification of the uplink NAS message under the security protection is successful or passes, AIoTF extracts the uplink NAS message (i.e., the plaintext content of the uplink NAS message).

[0279] Additionally, it may include: if the first integrity verification code is different from the first integrity check code, it is determined that the integrity verification of the uplink NAS message of the security protection has failed. AIoTF may discard the uplink NAS message of the security protection and / or send a notification or indication of verification failure to the AIoT device through the read / write device. Here, we do not limit or exhaust all the processes that AIoTF may perform when the integrity verification fails.

[0280] Alternatively, security protection may consist of encryption only.

[0281] AIoTF computes a keystream and decrypts the encrypted uplink NAS message based on this keystream. If decryption is successful, the plaintext content of the uplink NAS message is obtained. The decryption of the encrypted uplink NAS message based on the keystream can be achieved by performing an XOR operation between the keystream and the encrypted uplink NAS message.

[0282] Additionally, it may include: in the event of decryption failure (e.g., obtaining garbled text), AIoTF may discard the uplink NAS message protected by the security and / or AIoTF may send a notification or indication of decryption failure to the AIoT device through the read / write device. Here, we do not limit or exhaust all the processes that AIoTF may perform when decryption fails.

[0283] Optionally, security protection may include encryption and integrity protection.

[0284] If the AIoT device encrypts and then performs integrity verification, AIoTF calculates the first integrity verification code based on the encrypted uplink NAS message. If the first integrity verification code is the same as the first integrity check code, the key stream is calculated, and the encrypted uplink NAS message is decrypted based on the key stream. If the decryption is successful, the uplink NAS message is obtained.

[0285] If the AIoT device performs integrity verification before encryption, AIoTF calculates the key stream, decrypts the encrypted uplink NAS message based on the key stream, and obtains the uplink NAS message if decryption is successful. Based on the uplink NAS message, a first integrity verification code is calculated. If the first integrity verification code is the same as the first integrity check code, it is determined that the integrity verification of the secure uplink NAS message has been successful or passed, and the uplink NAS message is extracted and saved.

[0286] Additionally, it may include: in the event that the first integrity verification code is different from the first integrity check code, and / or in the event of decryption failure, determining that the verification of the uplink NAS message for the security protection has failed, the AIoTF may discard the uplink NAS message for the security protection and / or send a notification or indication of verification failure to the AIoT device through the read / write device. Here, we do not limit or exhaust all the processes that the AIoTF may perform when decryption fails and / or integrity verification fails.

[0287] The following is an illustrative example of the uplink NAS load segmented into multiple security protections after overall integrity protection provided in this embodiment: After receiving a command request message from AIoTF sent by the reader, the AIoT device performs the corresponding operation (read, write, inventory) and returns a command response message (i.e., an uplink NAS message) to AIoTF. This command response message may contain the reported data and the device's identifier, AIoT ID. These parameters may be contained in the NASC (NAS container), or in an AIoT-specific NAS message. The AIoT device first performs data protection, i.e., performs integrity protection only, encryption and integrity protection, or encryption only. If the AIoT device performs integrity protection, the MIC (Message Integrity Code) calculated by the AIoT device from the parameters contained in the entire NASC is the first integrity verification code in the aforementioned embodiment. When an AIoT device is segmented into multiple secure uplink NAS loads, the MIC needs to be carried within one of these secure uplink NAS loads. Therefore, when an uplink MAC PDU carries a secure uplink NAS load, it also needs to include first indication information. This first indication information indicates the block (or uplink NAS load) in which the MIC resides. This first indication information can be a new indication, or it can also indicate that the uplink MAC PDU carries the last secure uplink NAS load. When receiving multiple uplink MAC PDUs, the reader needs to assemble the encrypted and intact NASC. If the reader cannot determine which block the MIC is contained in, it cannot assemble the correct NASC, and the AIoTF cannot decrypt and verify the integrity of the received protected NASC. Alternatively, the MIC may be carried by default in the first secure uplink NAS load, or by default in the last secure uplink NAS load.

[0288] By adopting the solution provided in this embodiment, uplink NAS messages can be protected as a whole at once, which can not only ensure the security of uplink NAS messages, but also improve processing efficiency.

[0289] In some possible implementations, the uplink NAS message is obtained from a command executed by the AIoT device to perform an AIoT function. The AIoT function command can also be securely protected. After the AIoT function divides the command into multiple downlink NAS loads, it performs individual security protection on each downlink NAS load based on multiple downlink freshness values ​​before issuing it.

[0290] Accordingly, the processing of the AIoT device before receiving the uplink NAS message also includes: receiving multiple downlink MAC PDUs from the read / write device, wherein the multiple downlink MAC PDUs carry multiple security-protected downlink NAS loads; and obtaining the command based on the multiple security-protected downlink NAS loads. Specifically, obtaining the command based on the multiple security-protected downlink NAS loads includes obtaining the command if the verification of the multiple security-protected downlink NAS loads based on multiple downlink freshness values ​​is successful.

[0291] The communication method for providing individual security protection for each downlink NAS load in this embodiment will be explained with reference to Figure 7:

[0292] The AIoT function (AIoTF) side executes S701 to S703:

[0293] S701 divides the commands for AIoT functions into multiple downlink NAS payloads;

[0294] S702, based on multiple downlink fresh values, perform security protection on the multiple downlink NAS loads to obtain multiple secure downlink NAS loads;

[0295] S703 sends the downlink NAS load of the multiple security protections to the read / write device.

[0296] On the read / write device side, S711 is executed to receive multiple downlink NAS payloads for security protection from the AIoT function; and to send multiple downlink MAC PDUs to the AIoT device, wherein the multiple downlink MAC PDUs carry multiple downlink NAS payloads for security protection. Here, different downlink MAC PDUs carry downlink NAS payloads for different security protections.

[0297] After receiving multiple downlink MAC PDUs from the read / write device, the AIoT device executes S721, and obtains the command if the downlink NAS load of the multiple security protections is successfully verified based on multiple downlink fresh values.

[0298] In S701, AIoTF can divide a command into multiple downlink NAS payloads according to a specified length. The description of the specified length is the same as in the previous embodiment.

[0299] In some embodiments, the plurality of downlink fresh values ​​includes a plurality of downlink fresh values, and different security-protected downlink NAS loads among the plurality of security-protected downlink NAS loads correspond to different downlink fresh values ​​among the plurality of downlink fresh values.

[0300] In this embodiment, the number of downlink fresh values ​​is equal to the number of downlink NAS loads. Different downlink fresh values ​​have different values, and different downlink fresh values ​​are used to provide security protection for different downlink NAS loads to obtain different secure downlink NAS loads. Any downlink fresh value can be referred to as the downlink fresh value corresponding to the secure downlink NAS load, or the downlink fresh value corresponding to the downlink NAS load, or the downlink fresh value corresponding to the secure downlink NAS load, or the downlink fresh value corresponding to the downlink NAS load.

[0301] In one embodiment, the first downlink NAS load among the plurality of security-protected downlink NAS loads carries a first downlink fresh value among the plurality of downlink fresh values, wherein the first downlink fresh value is generated by the AIoT function. The downlink fresh values ​​corresponding to the other downlink NAS loads of each security protection among the plurality of security-protected downlink NAS loads, excluding the first security-protected downlink NAS load, are calculated based on the first downlink fresh value.

[0302] Before performing security protection on each downlink NAS load, the AIoTF side generates the downlink fresh value corresponding to that downlink NAS load.

[0303] The method for generating the first downlink fresh value is not limited in this embodiment. This first downlink fresh value can also be referred to as the first downlink nonce, or the first downlink counter, etc. In the following text, the first downlink fresh value and the first downlink nonce (or counter) have the same meaning and will not be explained again.

[0304] Besides the first downlink fresh value, the downlink fresh values ​​corresponding to the downlink NAS loads of each other security protection can be calculated directly or indirectly based on the first downlink fresh value. The processing by which AIoTF calculates the downlink fresh values ​​of the downlink NAS loads of each other security protection based on the first downlink fresh value is similar to the processing by which the AIoT device calculates the uplink fresh values ​​of the uplink NAS loads of each other security protection based on the first uplink fresh value in the aforementioned embodiments, and will not be repeated here.

[0305] The AIoTF execution of S702 may include: the AIoTF generating a first downlink fresh value, applying security protection to a first downlink NAS load based on the first downlink fresh value, resulting in a first secure downlink NAS load; the AIoTF calculating a second downlink fresh value based on the first downlink fresh value, applying security protection to a second downlink NAS load based on the second downlink fresh value, resulting in a second secure downlink NAS load; the AIoTF calculating a third downlink fresh value based on the first downlink fresh value (or based on the second downlink fresh value), applying security protection to a third downlink NAS load based on the third downlink fresh value, resulting in a third secure downlink NAS load, and so on, until the security protection processing for all downlink NAS loads is completed. This ensures that different downlink NAS loads are protected using different downlink fresh values, and the calculation method of the downlink fresh values ​​is only known to the AIoT device and the AIoTF side, thus making it more difficult for attackers to crack the fresh values, thereby enhancing the security of the protection for each downlink NAS load.

[0306] It should be noted that AIoTF needs to carry the first downlink fresh value in the first secure downlink NAS load, while the corresponding downlink fresh value does not need to be carried in other secure downlink NAS loads besides the first secure downlink NAS load.

[0307] Each of the multiple secure downlink NAS loads carries at least one of the following: each encrypted downlink NAS load, and a security check code corresponding to each downlink NAS load.

[0308] Optionally, security protection may include only full protection.

[0309] Taking any downlink NAS load as the j-th downlink NAS load as an example, AIoTF can calculate the integrity check code corresponding to the j-th downlink NAS load based on the j-th downlink freshness value.

[0310] The algorithm for calculating the integrity check code and the related key are the same as in the aforementioned embodiments, and will not be repeated here. Besides using the downlink fresh value, other parameters may also be used to calculate the integrity check code. These other parameters must be parameters that both the AIoT device and the AIoTF possess; no limitations or exhaustive list are provided here.

[0311] The j-th secure downlink NAS load can carry the j-th downlink NAS load and its corresponding integrity verification code. This integrity verification code can be placed after the j-th downlink NAS load.

[0312] In addition, the first secure downlink NAS load will also carry the first downlink fresh value. This first downlink fresh value can be placed before the first downlink NAS load; or it can be placed after the first downlink NAS load and before the integrity check code corresponding to the first downlink NAS load, without any limitation.

[0313] Alternatively, security protection may consist of encryption only.

[0314] AIoTF calculates a keystream based on the j-th downlink freshness value, and encrypts the j-th downlink NAS payload based on the keystream to obtain the j-th encrypted downlink NAS payload. The encryption process for the j-th downlink NAS payload based on the keystream is the same as the encryption process for the j-th uplink NAS payload in the previous embodiment, and will not be described again.

[0315] The algorithm for calculating the key stream and the related descriptions of the keys used are the same as in the previous embodiments, and will not be repeated here. In addition to using the uplink fresh value, other parameters may also be used to calculate the key stream. These other parameters need to be parameters that both the AIoT device and the AIoTF have. They are not limited or exhaustively listed here.

[0316] The j-th secure downlink NAS payload can carry the j-th encrypted downlink NAS payload. Additionally, the first secure downlink NAS payload will also carry the first downlink fresh value. This first downlink fresh value can be placed before or after the first encrypted downlink NAS payload; there is no restriction on this.

[0317] Optionally, security protection may include encryption and integrity protection.

[0318] If encryption is performed before integrity verification, then AIoTF calculates the key stream based on the j-th downlink freshness value, encrypts the j-th downlink NAS payload based on the key stream, and obtains the j-th encrypted downlink NAS payload; and calculates the integrity verification code corresponding to the j-th downlink NAS payload based on the j-th downlink freshness value and the j-th encrypted downlink NAS payload.

[0319] If the integrity check is performed before encryption, the AIoT device calculates the integrity check code corresponding to the j-th downlink NAS load based on the j-th downlink fresh value; calculates the key stream based on the j-th downlink fresh value; and encrypts the j-th downlink NAS load based on the key stream to obtain the j-th encrypted downlink NAS load.

[0320] The j-th secure downlink NAS payload can carry the j-th encrypted downlink NAS payload and the integrity verification code corresponding to the j-th downlink NAS payload. The integrity verification code corresponding to the j-th downlink NAS payload can be placed after the j-th encrypted downlink NAS payload.

[0321] Additionally, the first secure downlink NAS payload will also carry the first downlink fresh value. This first downlink fresh value can be placed before the first encrypted downlink NAS payload; or it can be placed after the first encrypted downlink NAS payload and before the integrity check code corresponding to the first downlink NAS payload. There is no limitation here.

[0322] Optionally, the AIoTF can perform the S703 process alternately with the AIoTF performing the S702 process.

[0323] For example, after AIoTF completes the security protection of the first downlink NAS load based on the first downlink fresh value and obtains the first secure downlink NAS load, it sends the first secure downlink NAS load to the read / write device; then, after completing the security protection of the second downlink NAS load based on the second downlink fresh value and obtaining the second secure downlink NAS load, it sends the second secure downlink NAS load to the read / write device, and so on, without exhaustive enumeration.

[0324] Optionally, AIoTF can execute S702 to complete the security protection of all downlink NAS loads. After obtaining all the secure downlink NAS loads, it can then execute S703 to send each secure downlink NAS load to the read / write device in sequence.

[0325] After receiving the downlink NAS payload for each security protection on the read / write device side, the downlink NAS payload for each security protection is carried on a downlink MAC PDU and sent to the AIoT device. The downlink MAC PDU sent by the read / write device can also be called a downlink MAC message, or an R2D (Reader to Device) message, or an R2D message MAC PDU, etc., and we will not exhaust all possible names here.

[0326] The AIoT device receives multiple downlink MAC PDUs from the read / write device, which may include: for each downlink MAC PDU received by the AIoT device, extracting the security-protected downlink NAS payload from that downlink MAC PDU.

[0327] The verification of the downlink NAS load for the multiple security protections on the AIoT device side includes at least one of the following: decrypting each encrypted downlink NAS load carried by each security protection downlink NAS load in the multiple security protections; and performing integrity verification based on the integrity check code corresponding to each downlink NAS load carried by each security protection downlink NAS load in the multiple security protections.

[0328] In this embodiment, the AIoT device performs integrity verification and / or decryption on the downlink NAS load of each security protection based on a downlink freshness value corresponding to the downlink NAS load of each security protection. The verification of the downlink NAS load of the multiple security protections by the AIoT device includes at least one of the following: decrypting each encrypted downlink NAS load; performing integrity verification based on the integrity check code corresponding to each downlink NAS load.

[0329] Specifically, before executing S721, the AIoT device may include: decrypting each encrypted downlink NAS load based on the downlink freshness value corresponding to each security protection downlink NAS load; and / or performing integrity verification based on the downlink freshness value corresponding to each security protection downlink NAS load and the integrity check code corresponding to each downlink NAS load.

[0330] The processing of S721 by the AIoT device may include: obtaining the command if the decryption of each encrypted downlink NAS load based on the downlink fresh value corresponding to each security protection downlink NAS load is successful, and / or the integrity verification based on the downlink fresh value corresponding to each security protection downlink NAS load and the integrity check code corresponding to each downlink NAS load is successful.

[0331] In this embodiment, before verifying the downlink NAS load of the first security protection, the AIoT device needs to extract a first downlink fresh value from the downlink NAS load of the first security protection. Before verifying each other downlink NAS load of security protection besides the first security protection, the AIoT device can calculate the downlink fresh value corresponding to the downlink NAS load of each other security protection based on the first downlink fresh value. The method by which the AIoT device calculates the downlink fresh value corresponding to each other downlink NAS load of security protection should be the same as that of AIoTF, and will not be described in detail.

[0332] In one example, after extracting any downlink NAS load for a security protection, the AIoT device can begin to verify the downlink NAS load for that security protection based on the downlink freshness value corresponding to that downlink NAS load, until the last downlink NAS load for a security protection is extracted and the verification is completed.

[0333] In one example, after extracting the downlink NAS load of any security protection, the AIoT device can first save the downlink NAS load of that security protection until the extraction of the downlink NAS load of the last security protection is completed. Then, based on the downlink freshness value corresponding to the downlink NAS load of each security protection, the downlink NAS load of each security protection is verified until the verification is completed.

[0334] Since the verification process for the downlink NAS load of each security protection is the same for AIoT devices, the following example will be taken as the downlink NAS load of the j-th security protection, where j is an integer greater than or equal to 1.

[0335] Optionally, security protection may include only full protection.

[0336] The AIoT device calculates the j-th downlink verification code based on the j-th downlink freshness value and the j-th downlink NAS load. If the j-th downlink verification code is the same as the integrity verification code corresponding to the j-th downlink NAS load, the integrity verification of the j-th security protection's downlink NAS load is determined to be successful or passed. It may also include: if the j-th downlink verification code is different from the integrity verification code corresponding to the j-th downlink NAS load, the integrity verification of the j-th security protection's downlink NAS load is determined to be unsuccessful. The processing of the AIoT device's downlink verification code calculation should be the same as the processing of the AIoTF's integrity verification code calculation, and will not be repeated here.

[0337] In this scenario, the AIoT device can sequentially perform integrity verification on the downlink NAS load of each security protection. Once the AIoT device confirms that the integrity verification of the downlink NAS load of each security protection is successful, it will concatenate the downlink NAS loads carried in the downlink NAS load of each security protection in sequence to obtain the command.

[0338] In addition, if the AIoT device fails to verify the integrity of the downlink NAS load for any one or more security protections, the AIoT device may discard the command of the security protection and / or send a notification or indication of verification failure to the AIoTF through the read / write device. Here, we do not limit or exhaust all the processes that the AIoT device may perform when the integrity verification fails.

[0339] Alternatively, security protection may consist of encryption only.

[0340] The AIoT device calculates a keystream based on the j-th downlink freshness value, and decrypts the j-th encrypted downlink NAS payload based on the keystream. If decryption is successful, the j-th downlink NAS payload is obtained. The decryption process for the j-th encrypted downlink NAS payload based on the keystream is the same as the decryption process for the j-th encrypted uplink NAS payload in the previous embodiment, and will not be repeated here. Additionally, it may include: if decryption fails (e.g., garbled characters are obtained), determining that the decryption of the j-th encrypted downlink NAS payload has failed.

[0341] The algorithm and key used for calculating the key stream of AIoT devices should be the same as those used for calculating the key stream of AIoTF, and will not be repeated here.

[0342] In this scenario, the AIoT device can decrypt the downlink NAS load of each security protection sequentially. Once the AIoT device confirms that the downlink NAS load of each security protection has been successfully decrypted, it will concatenate the decrypted downlink NAS loads in sequence to obtain the command.

[0343] In addition, if the AIoT device fails to decrypt the downlink NAS load of any one or more security protections, the AIoT device may discard the command of the security protection and / or the AIoT device may send a notification or indication of decryption failure to the AIoTF through the read / write device. Here, we do not limit or exhaust all the processes that the AIoT device may perform when decryption fails.

[0344] Optionally, security protection may include encryption and integrity protection.

[0345] If AIoTF encrypts first and then performs integrity verification, the AIoT device first performs integrity verification and then decryption. The AIoT device calculates the j-th downlink verification code based on the j-th downlink freshness value and the j-th encrypted downlink NAS payload. If the j-th downlink verification code is the same as the integrity verification code corresponding to the j-th downlink NAS payload, the device calculates the key stream based on the j-th downlink freshness value, and decrypts the j-th encrypted downlink NAS payload based on the key stream. If decryption is successful, the j-th downlink NAS payload is obtained.

[0346] If AIoTF performs integrity verification before encryption, the AIoT device first decrypts and then performs integrity verification. The AIoT device calculates a keystream based on the j-th downlink fresh value, and decrypts the j-th downlink NAS payload based on the keystream. If decryption is successful, the j-th downlink NAS payload is obtained. Based on the j-th downlink fresh value and the j-th downlink NAS payload, the j-th downlink verification code is calculated. If the j-th downlink verification code is the same as the integrity verification code corresponding to the j-th downlink NAS payload, the integrity verification of the j-th secure downlink NAS payload is determined to be successful or passed.

[0347] Additionally, it may include: determining that the verification of the downlink NAS load for the j-th security protection has failed if the j-th downlink verification code is different from the integrity verification code corresponding to the j-th downlink NAS load and / or if decryption fails.

[0348] In this scenario, once the AIoT device confirms that all downlink NAS loads for each security protection have been successfully decrypted and their integrity has been successfully verified, it concatenates the decrypted downlink NAS loads in sequence to obtain the command.

[0349] In addition, if the AIoT device fails to decrypt and / or verify the integrity of any one or more security protections' downlink NAS load, the AIoT device may discard the security protection command and / or send a notification or indication of verification failure to the AIoTF through the read / write device. Here, we do not limit or exhaust all the processes that the AIoT device may perform when decryption and / or integrity verification fail.

[0350] In one embodiment, each of the multiple secure downlink NAS loads carries a downlink fresh value corresponding to each secure downlink NAS load, wherein the downlink fresh value corresponding to each secure downlink NAS load is generated by the AIoTF.

[0351] Before performing security protection on each downlink NAS load, the AIoTF generates a downlink fresh value corresponding to that downlink NAS load. The method by which the AIoTF generates each downlink fresh value is not limited in this embodiment; as long as the specific values ​​of different downlink fresh values ​​are different, it is within the protection scope of this embodiment. The downlink fresh value can also be alternatively referred to as a downlink random number (Nonce) or a downlink counter (Counter), etc.

[0352] The AIoTF execution of S702 may include: the AIoTF generating a first downlink fresh value, performing security protection on the first downlink NAS load among multiple downlink NAS loads based on the first downlink fresh value, and obtaining the first securely protected downlink NAS load; the AIoTF generating a second downlink fresh value, wherein the second downlink fresh value is different from the first downlink fresh value, performing security protection on the second downlink NAS load among multiple downlink NAS loads based on the second downlink fresh value, and obtaining the second securely protected downlink NAS load, and so on, until the security protection processing of all downlink NAS loads is completed.

[0353] It should be noted that AIoTF needs to carry its corresponding downlink fresh value in each security protection downlink NAS load.

[0354] For example, security protection may only include integrity verification. The processing of the integrity verification code calculated by AIoTF for each downlink NAS load is the same as in the previous embodiment, and will not be repeated. Taking any one of the multiple downlink NAS loads as the j-th downlink NAS load as an example, the j-th secure downlink NAS load may carry the j-th downlink NAS load, the integrity verification code corresponding to the j-th downlink NAS load, and the j-th downlink freshness value.

[0355] For example, security protection may consist solely of encryption. The AIoTF's handling of encryption for each downlink NAS payload is the same as in the aforementioned embodiments and will not be repeated. In this example, the j-th secure downlink NAS payload may carry the j-th encrypted downlink NAS payload and the j-th downlink fresh value.

[0356] For example, security protection may include encryption and integrity verification. The AIoTF's processing of encrypting each downlink NAS load and calculating the corresponding integrity verification code is the same as in the previous embodiments and will not be repeated. In this example, the j-th secure downlink NAS load may carry the j-th encrypted downlink NAS load, the integrity verification code corresponding to the j-th downlink NAS load, and the j-th downlink freshness value.

[0357] The processing of S711 performed on the read / write device side is the same as in the aforementioned embodiments, and will not be described in detail here.

[0358] The processing from receiving multiple downlink MAC PDUs to the AIoT device before executing S721 differs from the previous embodiment only in that each security protection's downlink NAS load also carries a downlink fresh value. Before verifying each security protection's downlink NAS load, the AIoT device needs to extract its corresponding downlink fresh value from each security protection's downlink NAS load. The specific processing instructions related to the AIoT device executing S721, such as verifying each security protection's downlink NAS load and obtaining commands, are the same as in the previous embodiment and will not be repeated here.

[0359] In one embodiment, the downlink freshness value corresponding to each of the multiple security-protected downlink NAS loads is determined based on a downlink counter, wherein the downlink counter is jointly maintained by the AIoT device and the AIoT function.

[0360] In this embodiment, the AIoTF and the AIoT device can jointly maintain a downlink counter, and the initial value of the downlink counter or the initial count value is the same for both. In this embodiment, the downlink fresh value can also be referred to as the downlink count value (Counter).

[0361] Taking any downlink NAS load as the j-th downlink NAS load as an example, the processing of S702 by AIoTF is illustrated as follows: AIoTF uses the current count value of the downlink counter as the j-th downlink fresh value, and performs security protection on the j-th downlink NAS load among multiple downlink NAS loads based on the j-th downlink fresh value, thus obtaining the j-th secure downlink NAS load; AIoTF increments the value of the downlink counter by one. Where j equals 1, the current count value of the downlink counter can be the initial value of the downlink counter, that is, when AIoTF performs security protection on the first downlink NAS load, it can directly use the initial value of the downlink counter as the first downlink fresh value (or downlink count value).

[0362] For example, security protection may only include integrity verification. In this example, the downlink NAS load of the j-th security protection may carry the j-th downlink NAS load and the integrity verification code corresponding to the j-th downlink NAS load.

[0363] For example, security protections may consist of encryption only. In this example, the j-th security protection's downlink NAS payload may carry the i-th encrypted downlink NAS payload.

[0364] For example, security protection may include encryption and integrity verification. In this example, the j-th secure downlink NAS payload may carry the j-th encrypted downlink NAS payload and the integrity verification code corresponding to the j-th downlink NAS payload.

[0365] In this embodiment, the description of the processing of S703 by AIoTF is the same as that in the previous embodiment, and will not be repeated.

[0366] The specific description of the processing of S711 performed on the read / write device side is the same as that in the previous embodiments, and will not be repeated here.

[0367] The processing after receiving multiple downlink MAC PDUs on the AIoT device side differs from the aforementioned embodiments in that, since each security protection's downlink NAS load does not carry a downlink fresh value, the AIoT device needs to determine the downlink fresh value corresponding to each security protection's downlink NAS load based on the count value of its maintained downlink counter before verifying each security protection's downlink NAS load.

[0368] For example, when an AIoT device verifies the downlink NAS load of the first security protection, it can directly use the initial value of the downlink counter as the first downlink fresh value (or downlink count value). After the AIoT device completes the verification of the downlink NAS load of the first security protection, it can increment the downlink counter value by one. Then, when verifying the downlink NAS load of the second security protection, it can use the current count value of the downlink counter as the downlink fresh value corresponding to the downlink NAS load of the second security protection, and so on, without exhaustive enumeration.

[0369] The specific processing instructions for the AIoT device to perform S721, including verifying the downlink NAS load for each security protection and obtaining commands, are the same as those in the aforementioned embodiments, and therefore will not be repeated.

[0370] In some embodiments, the processing performed by the AIoTF further includes: dividing the command into multiple downlink NAS loads; determining the current downlink freshness value based on a downlink timer and a downlink initial freshness value, wherein the downlink timer and the downlink initial freshness value are jointly maintained by the AIoT device and the AIoT function; performing security protection on the multiple downlink NAS loads based on the current downlink freshness value to obtain multiple secure downlink NAS loads; and sending the multiple secure downlink NAS loads to the read / write device. That is, the aforementioned S702 is replaced by: determining the current downlink freshness value based on a downlink timer and a downlink initial freshness value; performing security protection on the multiple downlink NAS loads based on the current downlink freshness value to obtain multiple secure downlink NAS loads.

[0371] In this embodiment, the number of downlink fresh values ​​can be less than the number of downlink NAS loads, and different downlink fresh values ​​have different values.

[0372] Unlike the previous embodiments, the update of the downlink fresh value does not depend on the number of downlink NAS loads, but is related to the timing duration of the downlink timer. That is, the value (or count value) of the downlink fresh value will only be updated after a certain duration has elapsed. During this duration (i.e., within the timing duration of the downlink timer), AIoTF will not update the value (or count value) of the downlink fresh value, no matter how many downlink NAS loads it protects.

[0373] Specifically, determining the current downlink fresh value based on the downlink timer and the initial downlink fresh value includes one of the following: before the downlink timer expires for the first time, using the initial downlink fresh value as the current downlink fresh value; or when the downlink timer expires, incrementing the current downlink fresh value by one to obtain the updated current downlink fresh value.

[0374] Based on the downlink timer and the initial downlink fresh value, the processing to determine the current downlink fresh value, and the security protection of the multiple downlink NAS loads based on the current downlink fresh value, can be executed alternately. That is, before the downlink timer expires for the first time, the AIoT function will use the initial downlink fresh value as the current downlink fresh value and sequentially begin the security protection processing for multiple downlink NAS loads. Simultaneously, the AIoTF will continuously monitor whether the downlink timer has expired. Once the downlink timer expires (e.g., reaches its set duration), it will update the current downlink fresh value by incrementing it by one, and then continue using the current downlink fresh value to sequentially perform the security protection processing for each downlink NAS load, and so on.

[0375] Taking any downlink NAS load as the j-th downlink NAS load as an example, the processing of S702 by AIoTF is illustrated as follows: AIoTF detects whether the downlink timer's timing duration has expired. If the downlink timer's timing duration has not expired, the j-th downlink NAS load is protected based on the current downlink freshness value, resulting in the j-th protected downlink NAS load. If the downlink timer's timing duration has expired, the downlink timer's timing duration is reset to zero and restarted. The current downlink freshness value is incremented by one to obtain the updated current downlink freshness value. Based on the current downlink freshness value, the j-th downlink NAS load is protected, resulting in the j-th protected downlink NAS load. Before the downlink timer's timing duration expires for the first time, the current downlink freshness value is equal to the initial downlink freshness value.

[0376] For example, security protection may only include integrity verification. In this example, the downlink NAS load of the j-th security protection may carry the j-th downlink NAS load and the integrity verification code corresponding to the j-th downlink NAS load.

[0377] For example, security protections may consist of encryption only. In this example, the j-th security protection's downlink NAS payload may carry the i-th encrypted downlink NAS payload.

[0378] For example, security protection may include encryption and integrity verification. In this example, the j-th secure downlink NAS payload may carry the j-th encrypted downlink NAS payload and the integrity verification code corresponding to the j-th downlink NAS payload.

[0379] After receiving multiple downlink MAC PDUs on the AIoT device side, the following processing is performed instead: Based on the downlink timer and the downlink initial fresh value, the current downlink fresh value is determined, wherein the downlink timer and the downlink initial fresh value are jointly maintained by the AIoT device and the AIoT function; if the downlink NAS load verification of the multiple security protections is successful based on the current downlink fresh value, the command is obtained.

[0380] The AIoT device's process for determining the current downlink freshness value based on the downlink timer and the initial downlink freshness value is the same as the aforementioned AIoTF process. In this embodiment, the downlink NAS load of each security protection does not carry a downlink freshness value; the AIoT device still needs to determine the current downlink freshness value based on the timing duration of its maintained AIoTF downlink timer and the initial downlink freshness value. For example, before verifying the downlink NAS load of each security protection, the AIoT device checks whether the timing duration of the downlink timer has expired. If the timing duration of the downlink timer has not expired, the current downlink freshness value is used to verify the downlink NAS load of the security protection; if the timing duration of the downlink timer has expired, the timing duration of the downlink timer is reset to zero and restarted, and the current downlink freshness value is incremented by one to obtain the updated current downlink freshness value. The downlink NAS load of the security protection is then verified based on the current downlink freshness value. Specifically, before the first timing duration of the downlink timer expires, the current downlink freshness value is equal to the initial downlink freshness value.

[0381] The specific processing instructions for AIoT devices to verify the downlink NAS load for each security protection and to obtain commands are the same as those in the aforementioned embodiments, and therefore will not be repeated.

[0382] The solution provided in this embodiment requires the AIoT device to dynamically maintain a fresh value. This value does not need to be transmitted over the air interface. By using this fresh value, the security of the commands transmitted by AIoTF can be guaranteed, while reducing energy consumption to a certain extent.

[0383] In some possible implementations, after the AIoT function provides overall security protection for the commands, the read / write device divides the security-protected commands into multiple security-protected downlink NAS payloads and issues them.

[0384] The processing on the AIoT device side may include: receiving multiple downlink MAC PDUs from the read / write device, wherein the multiple downlink MAC PDUs carry multiple security-protected downlink NAS loads; and obtaining the command based on the multiple security-protected downlink NAS loads. Specifically, obtaining the command based on the multiple security-protected downlink NAS loads includes: concatenating the multiple security-protected downlink NAS loads into a security-protected command; and obtaining the command if the security-protected command is successfully verified.

[0385] The communication method for sending multiple security protection downlink NAS payloads by the read / write device in segmentation after receiving the overall protection AIoTF command, as described in Figure 8, is as follows:

[0386] The AIoT function (shown as AIoTF in Figure 8) executes S801 to S802:

[0387] S801, the command is protected to obtain a protected command. The protected command carries at least one of the following: an encrypted command, or a second integrity check code.

[0388] S802, send a security protection command to the read / write device.

[0389] The read / write device side executes S811 to S813:

[0390] S811, Receive a security protection command from the AIoT function;

[0391] S812, the security protection command is divided into multiple security protection downlink NAS loads.

[0392] S813, send multiple downlink MAC PDUs to the AIoT device, wherein the multiple downlink MAC PDUs carry multiple downlink NAS loads for security protection.

[0393] After receiving multiple downlink MAC PDUs from the read / write device, the AIoT device executes S821 to S822:

[0394] S821, concatenate the multiple downlink NAS loads for security protection into a security protection command;

[0395] S822, if the security protection command is successfully verified, the command is obtained.

[0396] Optionally, security protection may include only full protection.

[0397] AIoTF execution of S801 may include: calculating a second integrity check code based on a command.

[0398] Here, "command" can refer to the plaintext content of a command, such as any one of the following: read command, write command, inventory command, etc.

[0399] The algorithm for calculating the second integrity check code can be a NAS integrity algorithm, which can be shared by the AIoTF and AIoT devices. The key used to calculate the second integrity check code can be a NAS key shared by the AIoTF and AIoT devices, such as a NAS integrity protection key (referred to as the integrity key). Other parameters may also be used to calculate the second integrity check code; these other parameters must be possessed by both the AIoTF and AIoT devices, and are not limited or exhaustively listed here.

[0400] The security protection command carries: the command (or the plaintext content of the command) and a second integrity check code. The second integrity check code can be placed after the plaintext content of the command.

[0401] Alternatively, security protection may consist of encryption only.

[0402] The AIoTF execution of S801 may include: calculating a keystream, encrypting a command (or the plaintext content of the command) based on the keystream, and obtaining an encrypted command. The encryption of the command based on the keystream can be achieved by performing an XOR operation between the keystream and the command to obtain the encrypted command. The algorithm for calculating the keystream can be a NAS encryption algorithm, which can be shared by the AIoTF and the AIoT devices. The key used to calculate the keystream can be a NAS key shared by the AIoTF and the AIoT devices, such as a NAS encryption key or a NAS confidentiality key. Other parameters may also be used in calculating the keystream; these other parameters must be possessed by both the AIoTF and the AIoT devices, and are not limited or exhaustively listed here.

[0403] It should be noted that although this embodiment also uses key stream encryption for commands, the length of the key stream in this embodiment may be different from the length of the key stream used to encrypt each downlink NAS load in the previous embodiment. In this embodiment, the length of the key stream can be the same as the length of the command, while the length of the key stream used to encrypt the downlink NAS load in the previous embodiment can be the same as the length of the downlink NAS load. This is not limited here.

[0404] The security-protected commands carry encrypted commands.

[0405] Optionally, security protection may include encryption and integrity protection.

[0406] If encryption is performed before integrity verification, then AIoTF execution of S801 may include: calculating a key stream, encrypting the command (or plaintext content of the command) based on the key stream to obtain an encrypted command; and calculating a second integrity verification code based on the encrypted command.

[0407] If the integrity check is performed before encryption, then AIoTF execution of S801 may include: calculating a second integrity check code based on the command (or the plaintext content of the command); calculating a key stream; encrypting the command based on the key stream to obtain an encrypted command.

[0408] The security protection command carries an encrypted command and a second integrity verification code; the second integrity verification code can be placed after the encrypted command.

[0409] On the read / write device side, the processing of S812 may include: the read / write device dividing the security protection command into multiple security protection downlink NAS loads according to a specified length. The description of the specified length is the same as in the previous embodiments and will not be repeated.

[0410] In S813, when the read / write device sends multiple downlink MAC PDUs, the last downlink MAC PDU among the multiple downlink MAC PDUs carries second indication information, wherein the second indication information is used to indicate at least one of the following: the security-protected downlink NAS load carried by the last downlink MAC PDU carries a second integrity check code, or the last downlink MAC PDU carries the last security-protected downlink NAS load.

[0411] The read / write device can add a second indication information to the last MAC PDU to indicate that the downlink MAC PDU is the last one, and / or the downlink NAS load carrying the security protection carried by the downlink MAC PDU is the last one, and / or the downlink NAS load carrying the security protection carried by the downlink MAC PDU carries a second integrity check code.

[0412] After receiving the downlink MAC PDU on the AIoT device side, S821 is executed, which may specifically include: determining the last security protection downlink NAS load among the multiple security protection downlink NAS loads based on the second indication information; and concatenating the security protection command based on the order of the multiple security protection downlink NAS loads.

[0413] Optionally, the AIoT device may perform the following process in S821: After receiving the current downlink MAC PDU, the AIoT device checks whether the current downlink MAC PDU carries or contains the second indication information. If not, it saves the current downlink MAC PDU and continues to wait to receive the next downlink MAC PDU. If the current downlink MAC PDU carries or contains the second indication information, it determines that the currently received downlink MAC PDU is the last one and that the current downlink MAC PDU carries the downlink NAS load of the last security protection. Based on the receiving order of each downlink MAC PDU in all saved downlink MAC PDUs, it determines the order of the downlink NAS loads of security protection carried by each downlink MAC PDU. Based on the order of the downlink NAS loads of each security protection, it splices or combines the downlink NAS loads of each security protection to obtain the security protection command.

[0414] Optionally, during the process of receiving each downlink MAC PDU, the AIoT device performs downlink NAS load splicing for each security protection. For example, taking any one of the multiple downlink MAC PDUs as the j-th downlink MAC PDU, the specific processing of S821 by the AIoT device may include:

[0415] When j equals 1, the order of the downlink NAS load carrying the security protection is determined to be first based on the reception order of the first downlink MAC PDU; based on the order of the downlink NAS load of the first security protection, the downlink NAS load of the first security protection is saved as the first downlink combined content.

[0416] If j is greater than 1, check whether the j-th downlink MAC PDU carries the second indication information. If it does not carry the second indication information, determine the order of the j-th security protection downlink NAS load based on the receiving order of the j-th downlink MAC PDU. Based on the order of the j-th security protection downlink NAS load, combine or splice the j-th security protection downlink NAS load after the (j-1)-th combined content and save it.

[0417] If the j-th downlink MAC PDU is detected to carry the second indication information, then the j-th downlink MAC PDU is determined to be the last downlink MAC PDU, and it is determined to carry the last security protection downlink NAS load; based on the order of the security protection downlink NAS load, the security protection downlink NAS load is combined or spliced ​​to the (j-1)-th combined content to determine the security protection command.

[0418] Before executing S822, the AIoT device may include at least one of the following: decrypting the encrypted command; performing an integrity check on the security-protected command based on the second integrity verification code. The AIoT device's execution of S822 may include: obtaining the command if the encrypted command is successfully decrypted and / or the integrity check of the security-protected command is successful.

[0419] Optionally, security protection may include only full protection.

[0420] The AIoT device calculates a second integrity verification code based on the command (or the plaintext content of the command). If the second integrity verification code is the same as the second integrity check code, the integrity verification of the command for the security protection is determined to be successful or passed. The processing of the AIoT device calculating the second integrity verification code should be the same as the processing of the AIoTF calculating the second integrity check code, and will not be repeated here.

[0421] In this case, if the AIoT device successfully verifies or passes the integrity check of the security protection command, it extracts the command (i.e., the plaintext content of the command).

[0422] Additionally, it may include: if the second integrity verification code is different from the second integrity check code, it is determined that the integrity verification of the security protection command has failed. The AIoT device may discard the security protection command and / or the AIoT device may send a verification failure notification or indication to the AIoT function through the read / write device. Here, we do not limit or exhaust all the processes that the AIoT device may perform when the integrity verification fails.

[0423] Alternatively, security protection may consist of encryption only.

[0424] AIoT devices compute a keystream and decrypt encrypted commands based on this keystream. If decryption is successful, the plaintext command is obtained. The decryption of the encrypted command based on the keystream can be achieved by performing an XOR operation between the keystream and the encrypted command.

[0425] Additionally, it may include: in the event of decryption failure (e.g., obtaining garbled text), the AIoT device may discard the security protection command and / or the AIoT device may send a decryption failure notification or instruction to the AIoT function through the read / write device. Here, we do not limit or exhaust all the processes that the AIoT device may perform when decryption fails.

[0426] Optionally, security protection may include encryption and integrity protection.

[0427] If AIoTF encrypts first and then verifies integrity, the AIoT device first performs integrity verification and then decryption. The AIoT device calculates a second integrity verification code based on the encrypted command. If the second integrity verification code is the same as the second integrity check code, it calculates the key stream and decrypts the encrypted command based on the key stream. If decryption is successful, the command is obtained.

[0428] If AIoT performs integrity verification before encryption, the AIoT device first decrypts and then performs integrity verification. The AIoT device calculates a key stream, decrypts the encrypted command based on the key stream, and obtains the command if decryption is successful. Based on the command, it calculates a second integrity verification code. If the second integrity verification code is the same as the second integrity check code, it is determined that the integrity verification of the command under security protection has been successful or passed, and the command is extracted and saved.

[0429] Additionally, it may include: in the event that the second integrity verification code is different from the second integrity check code and / or in the event of decryption failure, determining that the verification of the security protection command has failed, the AIoT device may discard the security protection command and / or send a verification failure notification or indication to the AIoT function through the read / write device. Here, we do not limit or exhaust all the processes that the AIoT device may perform when decryption fails and / or integrity verification fails.

[0430] In terms of related technologies, an AIoT device's D2R message is an AIoT NAS-specific message carried at the MAC and PHY layers. RAN2 is researching D2R message segmentation. This means that after an AIoT device receives an R2D message containing the required feedback command, the data returned to the AIoTF is divided into multiple blocks, each carried on a separate MAC PDU of a D2R message. This is to account for the limitations of AIoT device form factors; these devices have low communication capabilities and may not be able to send all data using a single D2R message. Furthermore, due to the segmentation design of AIoT device D2R and R2D messages, communication between the AIoT device and the UE reader / BS reader requires using the MAC layer to carry AIoT-specific NAS messages from the upper layers. The protection of AIoT device communication messages resides at the NAS layer; the segmented message must not compromise its security, and the receiving end of the NAS message must be able to decrypt and verify the message correctly.

[0431] In the above-described solution provided in this application embodiment, the AIoT device can securely protect the uplink NAS messages it needs to send, obtain multiple securely protected uplink NAS payloads, and then carry these multiple securely protected uplink NAS payloads in multiple uplink MAC PDUs and send them to the read / write device. In this way, the AIoT device can segment its sent messages and transmit the securely protected NAS payloads, thereby ensuring the security of the messages in scenarios where the AIoT device transmits segmented messages.

[0432] Figure 9 is a schematic diagram of the composition structure of an AIoT device according to an embodiment of this application, including:

[0433] The first processing unit 901 is used to generate uplink NAS messages; process the uplink NAS messages to obtain multiple secure uplink NAS loads;

[0434] The first communication unit 902 is used to send multiple uplink MAC PDUs to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security protection uplink NAS loads.

[0435] The first processing unit is configured to divide the uplink NAS message into multiple uplink NAS loads; and to perform security protection on the multiple uplink NAS loads based on multiple uplink fresh values ​​to obtain the multiple security-protected uplink NAS loads.

[0436] The first of the multiple secure uplink NAS loads carries the first uplink fresh value among the multiple uplink fresh values, wherein the first uplink fresh value is generated by the AIoT device.

[0437] The uplink freshness value corresponding to the other uplink NAS loads of each of the multiple security protections, excluding the uplink NAS load of the first security protection, is calculated based on the first uplink freshness value.

[0438] Each of the multiple secure uplink NAS loads carries an uplink fresh value corresponding to each secure uplink NAS load, wherein the uplink fresh value corresponding to each secure uplink NAS load is generated by the AIoT device.

[0439] The uplink freshness value corresponding to each of the multiple secure uplink NAS loads is determined based on an uplink counter, wherein the uplink counter is jointly maintained by the AIoT device and the AIoT function.

[0440] The first processing unit is configured to divide the uplink NAS message into multiple uplink NAS loads; determine the current uplink freshness value based on the uplink timer and the uplink initial freshness value, wherein the uplink timer and the uplink initial freshness value are jointly maintained by the AIoT device and the AIoT function; and perform security protection on the multiple uplink NAS loads based on the current uplink freshness value to obtain the multiple security-protected uplink NAS loads.

[0441] The first processing unit is configured to perform one of the following: before the uplink timer expires for the first time, use the initial uplink fresh value as the current uplink fresh value; if the uplink timer expires, increment the current uplink fresh value by one to obtain the updated current uplink fresh value.

[0442] Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

[0443] The first processing unit is used to process the uplink NAS message to obtain a secure uplink NAS message; and to divide the secure uplink NAS message into the plurality of secure uplink NAS loads.

[0444] The secure uplink NAS message carries at least one of the following: an encrypted uplink NAS message, or a first integrity check code.

[0445] The last uplink MAC PDU among the plurality of uplink MAC PDUs carries first indication information, wherein the first indication information is used to indicate at least one of the following: the security-protected uplink NAS load carried by the last uplink MAC PDU carries the first integrity check code; or the last uplink MAC PDU carries the last security-protected uplink NAS load.

[0446] The uplink NAS message is obtained by the AIoT device executing the AIoT function command.

[0447] The first communication unit is configured to receive multiple downlink MAC PDUs from the read / write device, wherein the multiple downlink MAC PDUs carry multiple security-protected downlink NAS loads;

[0448] The first processing unit is used to obtain the command based on the downlink NAS load of the multiple security protections.

[0449] The first processing unit is configured to obtain the command if the downlink NAS load of the multiple security protections is successfully verified based on multiple downlink fresh values.

[0450] The first of the multiple secure downlink NAS loads carries the first downlink fresh value among the multiple downlink fresh values.

[0451] The downlink freshness value corresponding to the other downlink NAS loads of each of the multiple security protections, excluding the downlink NAS load of the first security protection, is calculated based on the first downlink freshness value.

[0452] Each of the multiple security-protected downlink NAS loads carries the downlink fresh value corresponding to each security-protected downlink NAS load.

[0453] The downlink freshness value corresponding to each downlink NAS load in the multiple security protections is determined based on a downlink counter, wherein the downlink counter is jointly maintained by the AIoT device and the AIoT function.

[0454] The first processing unit is configured to determine the current downlink freshness value based on the downlink timer and the downlink initial freshness value, wherein the downlink timer and the downlink initial freshness value are jointly maintained by the AIoT device and the AIoT function; and to obtain the command if the downlink NAS load of the multiple security protections is successfully verified based on the current downlink freshness value.

[0455] The first processing unit is configured to perform one of the following: before the downlink timer expires for the first time, use the initial downlink fresh value as the current downlink fresh value; when the downlink timer expires, increment the current downlink fresh value by one to obtain the updated current downlink fresh value.

[0456] Each of the multiple secure downlink NAS loads carries at least one of the following: each encrypted downlink NAS load, and a security check code corresponding to each downlink NAS load.

[0457] The first processing unit is configured to perform at least one of the following: decrypt each encrypted downlink NAS load carried by each of the plurality of secure downlink NAS loads; and perform integrity verification based on the integrity check code corresponding to each downlink NAS load carried by each of the plurality of secure downlink NAS loads.

[0458] The first processing unit is used to concatenate the multiple security-protected downlink NAS loads into a security protection command; and to obtain the command if the security protection command is successfully verified.

[0459] The security protection command carries at least one of the following: the encrypted command, or a second integrity check code.

[0460] The last downlink MAC PDU among the plurality of downlink MAC PDUs carries second indication information, wherein the second indication information is used to indicate at least one of the following: the security-protected downlink NAS load carried by the last downlink MAC PDU carries a second integrity check code, or the last downlink MAC PDU carries the last security-protected downlink NAS load.

[0461] The first processing unit is configured to determine the last security protection downlink NAS load among the plurality of security protection downlink NAS loads based on the second indication information; and to concatenate the security protection command based on the order of the plurality of security protection downlink NAS loads.

[0462] The first processing unit is configured to perform at least one of the following: decrypting the encrypted command; performing integrity verification on the security-protected command based on the second integrity verification code.

[0463] Figure 10 is a schematic diagram of the composition structure of a read / write device according to an embodiment of this application, including:

[0464] The second communication unit 1001 is configured to receive multiple uplink MAC PDUs from an AIoT device, wherein the multiple uplink MAC PDUs carry multiple security-protected uplink NAS loads; and to send a security-protected uplink NAS message to the AIoT function, wherein the security-protected uplink NAS message is generated based on the multiple security-protected uplink NAS loads.

[0465] As shown in Figure 10, the read / write device also includes:

[0466] The second processing unit 1002 is used to add a tag corresponding to each of the multiple secure uplink NAS loads based on the receiving order of the multiple secure uplink NAS loads; and to concatenate the secure uplink NAS message based on each secure uplink NAS load and the tag corresponding to each secure uplink NAS load.

[0467] The last uplink MAC PDU among the plurality of uplink MAC PDUs carries first indication information, wherein the first indication information is used to indicate at least one of the following: the security-protected uplink NAS load carried by the last uplink MAC PDU carries the first integrity check code; or the last uplink MAC PDU carries the last security-protected uplink NAS load.

[0468] The second processing unit is configured to determine the last secure uplink NAS load among the secure uplink NAS loads based on the first indication information; and to concatenate the secure uplink NAS message based on the order of the plurality of secure uplink NAS loads.

[0469] The second communication unit is configured to receive multiple downlink NAS loads for security protection from the AIoT function; and to send multiple downlink MAC PDUs to the AIoT device, wherein the multiple downlink MAC PDUs carry multiple downlink NAS loads for security protection.

[0470] The second communication unit is used to receive a security protection command from the AIoT function and send multiple downlink MAC PDUs to the AIoT device, wherein the multiple downlink MAC PDUs carry multiple downlink NAS loads for security protection;

[0471] The second processing unit is used to divide the security protection command into multiple security protection downlink NAS loads.

[0472] The last downlink MAC PDU among the plurality of downlink MAC PDUs carries second indication information, wherein the second indication information is used to indicate at least one of the following: the security-protected downlink NAS load carried by the last downlink MAC PDU carries a second integrity check code, or the last downlink MAC PDU carries the last security-protected downlink NAS load.

[0473] Figure 11 is a schematic diagram of the composition structure of an AIoT function according to an embodiment of this application, including:

[0474] The third communication unit 1101 is used to receive uplink NAS messages for security protection from the read / write device.

[0475] As shown in Figure 11, AIoT functionality also includes:

[0476] The third processing unit 1102 is used to obtain multiple secure uplink NAS loads based on the tags corresponding to each secure uplink NAS load contained in the secure uplink NAS message; and to obtain the uplink NAS message if the multiple secure uplink NAS loads are successfully verified based on multiple uplink fresh values.

[0477] The first of the multiple secure uplink NAS loads carries the first uplink fresh value among the multiple uplink fresh values.

[0478] The uplink freshness value corresponding to the other uplink NAS loads of each of the multiple security protections, excluding the uplink NAS load of the first security protection, is calculated based on the first uplink freshness value.

[0479] Each of the multiple secure uplink NAS loads carries the uplink fresh value corresponding to each secure uplink NAS load.

[0480] The uplink freshness value corresponding to each of the multiple secure uplink NAS loads is determined based on an uplink counter, wherein the uplink counter is jointly maintained by the AIoT device and the AIoT function.

[0481] The third processing unit 1102 is used to obtain multiple secure uplink NAS loads based on the tags corresponding to each secure uplink NAS load contained in the secure uplink NAS message; determine the current uplink freshness value based on the uplink timer and the uplink initial freshness value, wherein the uplink timer and the uplink initial freshness value are jointly maintained by the AIoT device and the AIoT function; and obtain the uplink NAS message if the multiple secure uplink NAS loads are successfully verified based on the current uplink freshness value.

[0482] The third processing unit 1102 is configured to perform one of the following: before the first expiration of the uplink timer, use the initial uplink fresh value as the current uplink fresh value; if the uplink timer expires, increment the current uplink fresh value by one to obtain the updated current uplink fresh value.

[0483] Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

[0484] The third processing unit is configured to perform at least one of the following: decrypt each encrypted uplink NAS load carried by each of the plurality of secure uplink NAS loads; and perform integrity verification based on the integrity check code corresponding to each uplink NAS load carried by each of the plurality of secure uplink NAS loads.

[0485] The third processing unit is used to obtain the uplink NAS message if the verification of the uplink NAS message for the security protection is successful.

[0486] The secure uplink NAS message carries at least one of the following: an encrypted uplink NAS message, or a first integrity check code.

[0487] The third processing unit is configured to perform at least one of the following: decrypt the encrypted uplink NAS message; and perform integrity verification on the secure uplink NAS message based on the first integrity check code.

[0488] The uplink NAS message is obtained by the AIoT device executing the command of the AIoT function.

[0489] The third processing unit is used to divide the command into multiple downlink NAS loads; and to perform security protection on the multiple downlink NAS loads based on multiple downlink fresh values ​​to obtain multiple security-protected downlink NAS loads.

[0490] The third communication unit is used to send the downlink NAS load of the multiple security protections to the read / write device.

[0491] The first of the multiple secure downlink NAS loads carries the first downlink fresh value among the multiple downlink fresh values, wherein the first downlink fresh value is generated by the AIoT function.

[0492] The downlink freshness value corresponding to the other downlink NAS loads of each of the multiple security protections, excluding the downlink NAS load of the first security protection, is calculated based on the first downlink freshness value.

[0493] Each of the multiple security-protected downlink NAS loads carries a downlink fresh value corresponding to each security-protected downlink NAS load, wherein the downlink fresh value corresponding to each security-protected downlink NAS load is generated by the AIoT function.

[0494] The downlink freshness value corresponding to each downlink NAS load in the multiple security protections is determined based on a downlink counter, wherein the downlink counter is jointly maintained by the AIoT device and the AIoT function.

[0495] The third processing unit is used to divide the command into multiple downlink NAS loads; determine the current downlink freshness value based on the downlink timer and the downlink initial freshness value, wherein the downlink timer and the downlink initial freshness value are jointly maintained by the AIoT device and the AIoT function; and perform security protection on the multiple downlink NAS loads based on the current downlink freshness value to obtain multiple secure downlink NAS loads.

[0496] The third communication unit is used to send the downlink NAS load of the multiple security protections to the read / write device.

[0497] The third processing unit is configured to perform one of the following: before the downlink timer expires for the first time, use the initial downlink fresh value as the current downlink fresh value; or when the downlink timer expires, increment the current downlink fresh value by one to obtain the updated current downlink fresh value.

[0498] Each of the multiple secure downlink NAS loads carries at least one of the following: each encrypted downlink NAS load, and a security check code corresponding to each downlink NAS load.

[0499] The third processing unit is used to perform security protection on the command and obtain a security-protected command;

[0500] The third communication unit is used to send the security protection command to the read / write device.

[0501] The security protection command carries at least one of the following: the encrypted command, or a second integrity check code.

[0502] The device in this application embodiment can realize the corresponding functions of the various devices in the foregoing communication method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0503] Figure 12 is a schematic structural diagram of a communication device 1200 according to an embodiment of this application. The communication device 1200 includes a processor 1210, which can call and run computer programs from a memory to enable the communication device 1200 to implement the methods in the embodiments of this application. In one possible implementation, the communication device 1200 may further include a memory 1220. The processor 1210 can call and run computer programs from the memory 1220 to enable the communication device 1200 to implement the methods in the embodiments of this application. The memory 1220 may be a separate device independent of the processor 1210, or it may be integrated into the processor 1210. In one possible implementation, the communication device 1200 may further include a transceiver 1230, which the processor 1210 can control to communicate with other devices. Specifically, it can send information or data to other devices, or receive information or data sent by other devices. The transceiver 1230 may include a transmitter and a receiver. The transceiver 1230 may further include antennas, and the number of antennas may be one or more.

[0504] In one possible implementation, the communication device 1200 may be an AIoT device, a read / write device, or an AIoT function in the embodiments of this application, and the communication device 1200 may implement the corresponding processes implemented by the AIoT device, the read / write device, or the AIoT function in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0505] Figure 13 is a schematic structural diagram of a chip 1300 according to an embodiment of this application. The chip 1300 includes a processor 1310, which can call and run computer programs from memory to implement the methods in the embodiments of this application. In one possible implementation, the chip 1300 may further include a memory 1320. The processor 1310 can call and run computer programs from the memory 1320 to implement the methods executed by the AIoT device in the embodiments of this application. The memory 1320 may be a separate device independent of the processor 1310, or it may be integrated into the processor 1310. In one possible implementation, the chip 1300 may further include an input interface 1330. The processor 1310 can control the input interface 1330 to communicate with other devices or chips; specifically, it can acquire information or data sent by other devices or chips. In one possible implementation, the chip 1300 may further include an output interface 1340. The processor 1310 can control the output interface 1340 to communicate with other devices or chips, specifically, it can output information or data to other devices or chips.

[0506] In one possible implementation, the chip can be applied to the AIoT device, read / write device, or AIoT function in the embodiments of this application, and the chip can implement the corresponding processes implemented by the AIoT device, read / write device, or AIoT function in the various methods of the embodiments of this application. For simplicity, these will not be elaborated further here. It should be understood that the chip mentioned in the embodiments of this application can also be called a system-on-a-chip, system-on-a-chip, chip system, or system-on-chip, etc. The processor mentioned above can be a general-purpose processor, digital signal processor (DSP), field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), or other programmable logic device, transistor logic device, discrete hardware component, etc. Among them, the general-purpose processor mentioned above can be a microprocessor or any conventional processor, etc. The memory mentioned above can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM). It should be understood that the above-described memory is exemplary but not limiting. For example, the memory in the embodiments of this application can also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM), etc. In other words, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.

[0507] This application also provides a communication system. The communication system includes an AIoT device, a read / write device, and an AIoT function. The AIoT device is used to implement the corresponding functions implemented by the AIoT device in the above-described method; the read / write device is used to implement the corresponding functions implemented by the read / write device in the above-described method; and the AIoT function is used to implement the corresponding functions implemented by the AIoT function in the above-described method.

[0508] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).

[0509] It should be understood that the sequence number of each process in the various embodiments of this application does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The above descriptions are merely specific embodiments of this application, and the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method performed by an environmental Internet of Things (AIoT) device, comprising: Generate uplink non-access stratum (NAS) messages; The uplink NAS messages are processed to obtain multiple secure uplink NAS payloads; Multiple uplink Media Access Control (MAC) Protocol Data Units (PDUs) are sent to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security-protected uplink NAS loads.

2. The method according to claim 1, wherein, The process of processing the uplink NAS message yields multiple secure uplink NAS payloads, including: The uplink NAS message is divided into multiple uplink NAS loads; Security protection is applied to the multiple uplink NAS loads based on multiple uplink fresh values, resulting in the multiple secure uplink NAS loads.

3. The method according to claim 2, wherein, The first of the multiple secure uplink NAS loads carries the first uplink fresh value among the multiple uplink fresh values, wherein the first uplink fresh value is generated by the AIoT device.

4. The method according to claim 3, wherein, The uplink freshness value corresponding to the other uplink NAS loads of each of the multiple security protections, excluding the uplink NAS load of the first security protection, is calculated based on the first uplink freshness value.

5. The method according to claim 2, wherein, Each of the multiple secure uplink NAS loads carries an uplink fresh value corresponding to each secure uplink NAS load, wherein the uplink fresh value corresponding to each secure uplink NAS load is generated by the AIoT device.

6. The method according to claim 2, wherein, The uplink freshness value corresponding to each of the multiple secure uplink NAS loads is determined based on an uplink counter, wherein the uplink counter is jointly maintained by the AIoT device and the AIoT function.

7. The method according to claim 1, wherein, The process of processing the uplink NAS message yields multiple secure uplink NAS payloads, including: The uplink NAS message is divided into multiple uplink NAS loads; The current uplink freshness value is determined based on the uplink timer and the uplink initial freshness value, wherein the uplink timer and the uplink initial freshness value are jointly maintained by the AIoT device and the AIoT function; Based on the current uplink freshness value, the multiple uplink NAS loads are protected to obtain the multiple protected uplink NAS loads.

8. The method according to claim 7, wherein, The determination of the current uplink freshness value based on the uplink timer and the uplink initial freshness value includes one of the following: Before the first expiration of the uplink timer, the initial uplink fresh value is used as the current uplink fresh value; If the uplink timer expires, the current uplink freshness value is incremented by one to obtain the updated current uplink freshness value.

9. The method according to any one of claims 2-8, wherein, Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

10. The method according to claim 1, wherein, The process of processing the uplink NAS message yields multiple secure uplink NAS payloads, including: The uplink NAS message is processed to obtain a secure uplink NAS message; The secure uplink NAS message is segmented into multiple secure uplink NAS payloads.

11. The method according to claim 10, wherein, The secure uplink NAS message carries at least one of the following: an encrypted uplink NAS message, or a first integrity check code.

12. The method according to claim 11, wherein, The last uplink MAC PDU among the plurality of uplink MAC PDUs carries first indication information, wherein the first indication information is used to indicate at least one of the following: the security-protected uplink NAS load carried by the last uplink MAC PDU carries the first integrity check code; or the last uplink MAC PDU carries the last security-protected uplink NAS load.

13. The method according to any one of claims 1-12, wherein, The uplink NAS message is obtained by the AIoT device executing the AIoT function command.

14. The method of claim 13, further comprising: Receive multiple downlink MAC PDUs from the read / write device, wherein the multiple downlink MAC PDUs carry multiple security-protected downlink NAS loads; The command is obtained based on the downlink NAS load with the multiple security protections.

15. The method according to claim 14, wherein, The downlink NAS load based on the multiple security protections obtains the command, including: The command is obtained when the downlink NAS load of the multiple security protections is successfully verified based on multiple downlink fresh values.

16. The method according to claim 15, wherein, The first of the multiple secure downlink NAS loads carries the first downlink fresh value among the multiple downlink fresh values.

17. The method according to claim 16, wherein, The downlink freshness value corresponding to the other downlink NAS loads of each of the multiple security protections, excluding the downlink NAS load of the first security protection, is calculated based on the first downlink freshness value.

18. The method according to claim 15, wherein, Each of the multiple security-protected downlink NAS loads carries the downlink fresh value corresponding to each security-protected downlink NAS load.

19. The method according to claim 15, wherein, The downlink freshness value corresponding to each downlink NAS load in the multiple security protections is determined based on a downlink counter, wherein the downlink counter is jointly maintained by the AIoT device and the AIoT function.

20. The method of claim 14, wherein, The downlink NAS load based on the multiple security protections obtains the command, including: The current downlink freshness value is determined based on the downlink timer and the downlink initial freshness value, wherein the downlink timer and the downlink initial freshness value are jointly maintained by the AIoT device and the AIoT function; The command is obtained if the downlink NAS load of the multiple security protections is successfully verified based on the current downlink freshness value.

21. The method according to claim 20, wherein, The determination of the current downlink freshness value based on the downlink timer and the initial downlink freshness value includes one of the following: Before the downlink timer expires for the first time, the initial downlink fresh value is used as the current downlink fresh value; When the downlink timer expires, the current downlink fresh value is incremented by one to obtain the updated current downlink fresh value.

22. The method according to any one of claims 15-21, wherein, Each of the multiple secure downlink NAS loads carries at least one of the following: each encrypted downlink NAS load, and a security check code corresponding to each downlink NAS load.

23. The method according to claim 22, wherein, The downlink NAS load verification of the multiple security protections includes at least one of the following: Decrypt each encrypted downlink NAS load carried by each of the multiple security-protected downlink NAS loads; Integrity verification is performed based on the integrity check code corresponding to each downlink NAS load carried by each of the multiple security protections in the downlink NAS load.

24. The method according to claim 14, wherein, The downlink NAS load based on the multiple security protections obtains the command, including: The multiple downlink NAS loads for security protection are concatenated into a security protection command; If the security protection command is successfully verified, the command is obtained.

25. The method according to claim 24, wherein, The security protection command carries at least one of the following: the encrypted command, or a second integrity check code.

26. The method of claim 25, wherein, The last downlink MAC PDU among the plurality of downlink MAC PDUs carries second indication information, wherein the second indication information is used to indicate at least one of the following: the security-protected downlink NAS load carried by the last downlink MAC PDU carries a second integrity check code, or the last downlink MAC PDU carries the last security-protected downlink NAS load.

27. The method according to claim 26, wherein, The command to concatenate the multiple security-protected downlink NAS loads into a security protection command includes: Based on the second indication information, determine the last security protection downlink NAS load among the multiple security protection downlink NAS loads; The command for the security protection is obtained by concatenating the downlink NAS load based on the order of the multiple security protections.

28. The method according to any one of claims 25-27, further comprising at least one of the following: Decrypt the encrypted command; The integrity of the security protection command is verified based on the second integrity verification code.

29. A communication method performed by a read / write device, comprising: Receive multiple uplink MAC PDUs from AIoT devices, wherein the multiple uplink MAC PDUs carry multiple secure uplink NAS loads; Send a security-protected uplink NAS message to the AIoT function, wherein the security-protected uplink NAS message is generated based on the plurality of security-protected uplink NAS loads.

30. The method of claim 29, further comprising: Based on the receiving order of the multiple security protection uplink NAS loads, add a tag corresponding to each security protection uplink NAS load in the multiple security protection uplink NAS loads; Based on the uplink NAS load of each security protection and the tag corresponding to the uplink NAS load of each security protection, the uplink NAS message of the security protection is obtained by concatenation.

31. The method according to claim 29, wherein, The last uplink MAC PDU among the plurality of uplink MAC PDUs carries first indication information, wherein the first indication information is used to indicate at least one of the following: the security-protected uplink NAS load carried by the last uplink MAC PDU carries a first integrity check code; or the last uplink MAC PDU carries the last security-protected uplink NAS load.

32. The method of claim 31, further comprising: Based on the first indication information, determine the last secure uplink NAS load among the secure uplink NAS loads; Based on the order of the uplink NAS loads under the multiple security protections, the uplink NAS messages under the security protections are concatenated to obtain the uplink NAS messages under the security protections.

33. The method according to any one of claims 29-32, further comprising: Receive downlink NAS loads from multiple security protections of the AIoT function; Multiple downlink MAC PDUs are sent to the AIoT device, wherein the multiple downlink MAC PDUs carry multiple downlink NAS loads for security protection.

34. The method according to any one of claims 29-32, further comprising: Receive a security protection command from the AIoT function; The security protection command is divided into multiple security protection downlink NAS loads; Multiple downlink MAC PDUs are sent to the AIoT device, wherein the multiple downlink MAC PDUs carry multiple downlink NAS loads for security protection.

35. The method according to claim 34, wherein, The last downlink MAC PDU among the plurality of downlink MAC PDUs carries second indication information, wherein the second indication information is used to indicate at least one of the following: the security-protected downlink NAS load carried by the last downlink MAC PDU carries a second integrity check code, or the last downlink MAC PDU carries the last security-protected downlink NAS load.

36. A communication method performed by an AIoT function, comprising: Receive uplink NAS messages from the read / write device for security protection.

37. The method of claim 36, further comprising: Based on the tags corresponding to each secure uplink NAS load contained in the secure uplink NAS message, multiple secure uplink NAS loads are obtained. If the uplink NAS load verification of the multiple security protections is successful based on multiple uplink fresh values, the uplink NAS message is obtained.

38. The method according to claim 37, wherein, The first of the multiple secure uplink NAS loads carries the first uplink fresh value among the multiple uplink fresh values.

39. The method according to claim 38, wherein, The uplink freshness value corresponding to the other uplink NAS loads of each of the multiple security protections, excluding the uplink NAS load of the first security protection, is calculated based on the first uplink freshness value.

40. The method of claim 37, wherein, Each of the multiple secure uplink NAS loads carries the uplink fresh value corresponding to each secure uplink NAS load.

41. The method according to claim 37, wherein, The uplink freshness value corresponding to each of the multiple secure uplink NAS loads is determined based on an uplink counter, wherein the uplink counter is jointly maintained by the AIoT device and the AIoT function.

42. The method of claim 36, further comprising: Based on the tags corresponding to each secure uplink NAS load contained in the secure uplink NAS message, multiple secure uplink NAS loads are obtained. The current uplink freshness value is determined based on the uplink timer and the uplink initial freshness value, wherein the uplink timer and the uplink initial freshness value are jointly maintained by the AIoT device and the AIoT function; If the uplink NAS load verification of the multiple security protections is successful based on the current uplink freshness value, the uplink NAS message is obtained.

43. The method according to claim 42, wherein, The determination of the current uplink freshness value based on the uplink timer and the uplink initial freshness value includes one of the following: Before the first expiration of the uplink timer, the initial uplink fresh value is used as the current uplink fresh value; If the uplink timer expires, the current uplink freshness value is incremented by one to obtain the updated current uplink freshness value.

44. The method according to any one of claims 37-43, wherein, Each of the multiple secure uplink NAS loads carries at least one of the following: each encrypted uplink NAS load, and a security check code corresponding to each uplink NAS load.

45. The method according to claim 44, wherein, The uplink NAS load verification of the multiple security protections includes at least one of the following: Decrypt each encrypted uplink NAS load carried by each of the multiple secure uplink NAS loads; Integrity verification is performed based on the integrity check code corresponding to each uplink NAS load carried by each of the multiple security-protected uplink NAS loads.

46. ​​The method of claim 36, further comprising: If the uplink NAS message for the security protection is successfully verified, the uplink NAS message is obtained.

47. The method according to claim 46, wherein, The secure uplink NAS message carries at least one of the following: an encrypted uplink NAS message, or a first integrity check code.

48. The method of claim 47, further comprising at least one of the following: Decrypt the encrypted uplink NAS message; Integrity verification is performed on the uplink NAS message protected by the first integrity check code.

49. The method according to any one of claims 36-48, wherein, The uplink NAS message is obtained by the AIoT device executing the command of the AIoT function.

50. The method of claim 49, further comprising: The command is divided into multiple downlink NAS loads; Security protection is applied to the multiple downlink NAS loads based on multiple downlink fresh values, resulting in multiple secure downlink NAS loads. Send the multiple security protections of the downlink NAS load to the read / write device.

51. The method according to claim 50, wherein, The first of the multiple secure downlink NAS loads carries the first downlink fresh value among the multiple downlink fresh values, wherein the first downlink fresh value is generated by the AIoT function.

52. The method according to claim 51, wherein, The downlink freshness value corresponding to the other downlink NAS loads of each of the multiple security protections, excluding the downlink NAS load of the first security protection, is calculated based on the first downlink freshness value.

53. The method according to claim 50, wherein, Each of the multiple security-protected downlink NAS loads carries a downlink fresh value corresponding to each security-protected downlink NAS load, wherein the downlink fresh value corresponding to each security-protected downlink NAS load is generated by the AIoT function.

54. The method according to claim 50, wherein, The downlink freshness value corresponding to each downlink NAS load in the multiple security protections is determined based on a downlink counter, wherein the downlink counter is jointly maintained by the AIoT device and the AIoT function.

55. The method of claim 49, further comprising: The command is divided into multiple downlink NAS loads; The current downlink freshness value is determined based on the downlink timer and the downlink initial freshness value, wherein the downlink timer and the downlink initial freshness value are jointly maintained by the AIoT device and the AIoT function; Based on the current downlink freshness value, the multiple downlink NAS loads are protected to obtain multiple protected downlink NAS loads; Send the multiple security protections of the downlink NAS load to the read / write device.

56. The method according to claim 55, wherein, The determination of the current downlink freshness value based on the downlink timer and the initial downlink freshness value includes one of the following: Before the downlink timer expires for the first time, the initial downlink fresh value is used as the current downlink fresh value; When the downlink timer expires, the current downlink fresh value is incremented by one to obtain the updated current downlink fresh value.

57. The method according to any one of claims 50-56, wherein, Each of the multiple secure downlink NAS loads carries at least one of the following: each encrypted downlink NAS load, and a security check code corresponding to each downlink NAS load.

58. The method of claim 49, further comprising: The command is then protected to obtain a protected command. Send the security protection command to the read / write device.

59. The method according to claim 58, wherein, The security protection command carries at least one of the following: the encrypted command, or a second integrity check code.

60. An AIoT device, comprising: The first processing unit is used to generate uplink NAS messages; The uplink NAS messages are processed to obtain multiple secure uplink NAS payloads; The first communication unit is used to send multiple uplink Media Access Control (MAC) Protocol Data Units (PDUs) to the read / write device, wherein the multiple uplink MAC PDUs carry the multiple security protection uplink NAS loads.

61. A read / write device, comprising: The second communication unit is configured to receive multiple uplink MAC PDUs from an AIoT device, wherein the multiple uplink MAC PDUs carry multiple security-protected uplink NAS loads; and to send a security-protected uplink NAS message to the AIoT function, wherein the security-protected uplink NAS message is generated based on the multiple security-protected uplink NAS loads.

62. An AIoT function, comprising: The third communication unit is used to receive uplink NAS messages for security protection from the read / write device.

63. An AIoT device, comprising: A transceiver, a processor, and a memory for storing a computer program, the transceiver for communicating with other devices, and the processor for calling and running the computer program stored in the memory to cause the AIoT device to perform the method as described in any one of claims 1 to 28.

64. A read / write device, comprising: A transceiver, a processor, and a memory for storing a computer program, the transceiver for communicating with other devices, and the processor for calling and running the computer program stored in the memory to cause the read / write device to perform the method as described in any one of claims 29 to 35.

65. An AIoT function, comprising: A transceiver, a processor, and a memory for storing a computer program, the transceiver for communicating with other devices, and the processor for calling and running the computer program stored in the memory to cause the AIoT function to perform the method as described in any one of claims 36 to 59.

66. A chip, comprising: A processor for retrieving and running a computer program from memory, causing a device having the chip mounted to perform the method as described in any one of claims 1 to 28, or claims 29 to 35, or claims 36 to 59.

67. A computer-readable storage medium for storing a computer program that, when run by a device, causes the device to perform the method as described in any one of claims 1 to 28, or claims 29 to 35, or claims 36 to 59.

68. A computer program product comprising computer program instructions that cause a computer to perform the method as claimed in any one of claims 1 to 28, or claims 29 to 35, or claims 36 to 59.

69. A computer program that causes a computer to perform the method as described in any one of claims 1 to 28, or claims 29 to 35, or claims 36 to 59.