Communication method, internet of things device, network function, system, and storage medium

By using a unique key and value authentication method in environmental IoT devices, the reliability and security issues caused by limited device energy are solved, enabling secure isolation and authentication between devices and improving the availability and reliability of the system.

WO2026152408A1PCT designated stage Publication Date: 2026-07-23BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2025-01-17
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Environmental IoT devices, due to their limited energy, struggle to achieve reliable authentication and secure isolation, impacting their availability and reliability.

Method used

By receiving and sending inventory requests and responses, authentication is performed using the unique keys and values ​​of each IoT device, and secure isolation is achieved, ensuring secure communication between devices in the same group.

Benefits of technology

It improves the availability and reliability of environmental IoT devices and enables secure isolation and authentication between devices in the same group.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073143_23072026_PF_FP_ABST
    Figure CN2025073143_23072026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a communication method, an Internet of Things device, a network function, a system, and a storage medium. The method comprises: receiving an inventory request sent by a reader, wherein the inventory request is used for requesting to inventory a group of Internet of Things devices, and the group of Internet of Things devices at least comprises a first Internet of Things device; on the basis of the inventory request, determining at least one of a first value corresponding to the first Internet of Things device and a first key corresponding to the first Internet of Things device, wherein the first value corresponding to the first Internet of Things device is used for verifying the identity of the first Internet of Things device, and each Internet of Things device in the group of Internet of Things devices corresponds to a different key; and sending an inventory response to the reader, wherein the inventory response at least comprises the first value corresponding to the first Internet of Things device. The present disclosure can achieve security isolation between Internet of Things devices in a same group, thereby improving the availability and reliability of Internet of Things technology, especially ambient Internet of Things technology.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods, Internet of Things (IoT) devices, network functions, systems, and storage media Technical Field

[0001] This disclosure relates to the field of communications, and in particular to communication methods, Internet of Things devices, network functions, systems, and storage media. Background Technology

[0002] Ambient Internet of Things (A-IoT) devices, also known as environmentally powered IoT devices, are either battery-free or have limited energy storage capabilities. Their energy can be supplied by harvesting radio waves, light, motion, heat, or any other suitable power source. Summary of the Invention

[0003] To improve the reliability of Internet of Things (IoT) technologies, especially environmental IoT technologies, embodiments of this disclosure provide a communication method, IoT device, network function, system, and storage medium.

[0004] According to a first aspect of the present disclosure, a communication method is provided, the method being executed by a first Internet of Things (IoT) device, the method comprising:

[0005] Receive a readout request sent by the reader; wherein the readout request is used to request a readout of a group of IoT devices, the group of IoT devices including at least the first IoT device;

[0006] Based on the inventory request, at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device is determined; wherein, the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key;

[0007] Send an inventory response to the reader; wherein the inventory response includes at least a first value corresponding to the first IoT device.

[0008] According to a second aspect of the present disclosure, a communication method is provided, the method being executed by a first network function, the method comprising:

[0009] Send a first request to the reader; wherein the first request is used to request the reader to broadcast an inventory request, the inventory request is used to perform an inventory to a group of IoT devices; wherein the inventory request is used for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key;

[0010] The reader receives a first response based on the inventory response sent by each IoT device; wherein the first response includes at least a first value corresponding to each IoT device in the group of IoT devices, and the first value corresponding to each IoT device is used to verify the identity of each IoT device.

[0011] According to a third aspect of the present disclosure, a communication method is provided, the method being executed by a second network function, the method comprising:

[0012] The system receives a second request sent by a first network function based on a first response; wherein the first response is used to respond to a first request sent by the first network function to the reader, the first request being used to request triggering the reader to broadcast an inventory request, the inventory request being used to perform an inventory on a group of IoT devices; wherein the inventory request is used for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key; wherein the second request is used to request verification of the identity of each IoT device in the group of IoT devices;

[0013] Based on the second request, a second response is sent to the first network function.

[0014] According to a fourth aspect of the present disclosure, a communication method is provided, the method comprising:

[0015] The first network function sends a first request to the reader; wherein the first request is used to request triggering a broadcast inventory request, the inventory request is used to inventory a group of IoT devices, the group of IoT devices including at least the first IoT device;

[0016] The reader broadcasts the disk storage request;

[0017] Based on the received inventory request, the first IoT device determines at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device; wherein, the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key;

[0018] The first IoT device sends an inventory response to the reader; wherein the inventory response includes at least a first value corresponding to the first IoT device;

[0019] The reader sends a first response to the first network function; wherein the first response includes at least a first value corresponding to each of the group of IoT devices;

[0020] Based on the first response, the first network function sends a second request to the second network function; wherein the second request is used to request verification of the identity of each IoT device in a group of IoT devices;

[0021] The second network function sends a second response to the first network function based on the second request.

[0022] According to a fifth aspect of the present disclosure, a communication device is provided, the communication device being used to perform the communication method described in any one of the first, second, or third aspects.

[0023] According to a sixth aspect of the present disclosure, a communication system is provided, including a first Internet of Things (IoT) device, a first network function, and a second network function, wherein the first IoT device is configured to implement the communication method described in any one of the first aspects, the first network function is configured to implement the communication method described in any one of the second aspects, and the second network function is configured to implement the communication method described in any one of the third aspects.

[0024] According to a seventh aspect of the present disclosure, a storage medium is provided that stores instructions that, when executed on a communication device, cause the communication device to perform a communication method as described in any one of the first, second, or third aspects.

[0025] According to an eighth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, is used to implement the communication method described in any one of the first, second, or third aspects.

[0026] In this embodiment of the disclosure, each IoT device in a group of IoT devices corresponds to a different key. After authenticating the IoT devices in the same group, secure isolation can be achieved between IoT devices belonging to the same group. Thus, by using the key corresponding to the IoT device, the designated IoT device can be controlled to perform a first operation, thereby improving the availability and reliability of IoT technology, especially environmental IoT technology.

[0027] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0028] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0029] Figure 1A is an exemplary schematic diagram of the architecture of a communication system provided according to an embodiment of the present disclosure.

[0030] Figure 1B is one of the exemplary topology diagrams in an environmental Internet of Things scenario provided according to embodiments of the present disclosure.

[0031] Figure 1C is a second exemplary topology diagram in an environmental Internet of Things scenario provided according to embodiments of the present disclosure.

[0032] Figure 2 is one of the exemplary interaction diagrams of the communication method provided according to an embodiment of the present disclosure.

[0033] Figure 3A is one of the exemplary flowcharts of a communication method provided according to an embodiment of the present disclosure.

[0034] Figure 3B is a second exemplary flowchart of a communication method provided according to an embodiment of the present disclosure.

[0035] Figure 3C is a third exemplary flowchart of a communication method provided according to an embodiment of the present disclosure.

[0036] Figure 4A is a second exemplary interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure.

[0037] Figure 4B is a schematic diagram of an exemplary scenario of function selection according to an embodiment of the present disclosure.

[0038] Figure 5A is an exemplary block diagram of a first Internet of Things (IoT) device provided according to an embodiment of the present disclosure.

[0039] Figure 5B is an exemplary block diagram of a first network function provided according to an embodiment of the present disclosure.

[0040] Figure 5C is an exemplary block diagram of a second network function provided according to an embodiment of the present disclosure.

[0041] Figure 6A is an exemplary block diagram of a communication device provided according to an embodiment of the present disclosure.

[0042] Figure 6B is an exemplary block diagram of a chip provided according to an embodiment of the present disclosure. Detailed Implementation

[0043] This disclosure provides a communication method, an Internet of Things (IoT) device, a network function, a system, and a storage medium.

[0044] In a first aspect, embodiments of this disclosure propose a communication method executed by a first Internet of Things (IoT) device. The method includes: receiving a disk access request sent by a reader; wherein the disk access request is for requesting disk access for a group of IoT devices, the group of IoT devices including at least the first IoT device; determining, based on the disk access request, at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device; wherein the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key; and sending a disk access response to the reader; wherein the disk access response includes at least the first value corresponding to the first IoT device.

[0045] In the above embodiments, secure isolation can be achieved between IoT devices belonging to the same group, improving the availability and reliability of IoT technology, especially environmental IoT technology.

[0046] In conjunction with some embodiments of the first aspect, in some embodiments, the inventory request includes at least one of the following: a group identifier; wherein the group identifier is an identifier of the group of IoT devices; and a first random number; wherein the first random number is determined by a first network function.

[0047] In the above embodiments, the inventory request may include at least one of the above-mentioned items, thereby improving the reliability of the process of inventorying a group of IoT devices.

[0048] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: if the inventory request does not include a first identifier, determining that the inventory request is for requesting inventory of the group of IoT devices; wherein the first identifier is the identifier of the first IoT device; if the inventory request includes a group identifier, determining that the inventory request is for requesting inventory of the group of IoT devices; wherein the group identifier is the identifier of the group of IoT devices.

[0049] In the above embodiments, if the inventory request does not include the identifier of the first IoT device, that is, if it does not include the first identifier, the first IoT device can determine that the inventory request is used to request inventory of the group of IoT devices, and / or, if the inventory request includes the group identifier, the first IoT device can determine that the inventory request is used to request inventory of the group of IoT devices, thereby improving the reliability of the group inventory process.

[0050] In conjunction with some embodiments of the first aspect, in some embodiments, determining at least one of the first value corresponding to the first IoT device and the first key corresponding to the first IoT device includes: determining at least one of the first value and the first key based on at least one first parameter using a first function; wherein the at least one first parameter includes at least one of the following: a first random number; wherein the first random number is determined by a first network function; a second random number; wherein the second random number is determined by the first IoT device; a fourth key; wherein the fourth key is a key stored on the first IoT device; a first identifier; wherein the first identifier is the identifier of the first IoT device; and a group identifier; wherein the group identifier is the identifier of the group of IoT devices.

[0051] In the above embodiments, the first IoT device can use the above method to determine the first value and / or the first key, which supports network functions to authenticate the first IoT device while enabling secure isolation between it and other IoT devices belonging to the same group, thereby improving the availability and reliability of IoT technology, especially environmental IoT technology.

[0052] In conjunction with some embodiments of the first aspect, in some embodiments, the inventory response further includes at least one of the following: a first identifier; wherein the first identifier is the identifier of the first IoT device; a group identifier; wherein the group identifier is the identifier of the group of IoT devices; and a second random number; wherein the second random number is determined by the first IoT device.

[0053] In the above embodiments, the inventory response may include at least one of the above-mentioned features, which is simple to implement and highly available.

[0054] Secondly, embodiments of this disclosure propose a communication method executed by a first network function, the method comprising: sending a first request to a reader; wherein the first request is used to request triggering the reader to broadcast an inventory request, the inventory request being used to perform an inventory to a group of Internet of Things (IoT) devices; wherein the inventory request is used for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key;

[0055] The reader receives a first response based on the inventory response sent by each IoT device; wherein the first response includes at least a first value corresponding to each IoT device in the group of IoT devices, and the first value corresponding to each IoT device is used to verify the identity of each IoT device.

[0056] In the above embodiments, the first network function can send a first request to the reader, thereby triggering the reader to broadcast an inventory request. Each networked device in the group of IoT devices can determine at least one of a first value and a first key corresponding to each IoT device based on the received inventory request. Each IoT device in the group corresponds to a different key, achieving the purpose of secure isolation between IoT devices within the group. Furthermore, the first network function can receive a first response sent by the reader, thereby obtaining the first value corresponding to each IoT device in the group of IoT devices, so as to authenticate each IoT device, achieving the purpose of group authentication and high availability.

[0057] In conjunction with some embodiments of the second aspect, in some embodiments, the first request includes at least one of the following: a group identifier; wherein the group identifier is an identifier of the group of IoT devices; and a first random number; wherein the first random number is determined by the first network function.

[0058] In conjunction with some embodiments of the second aspect, in some embodiments, the first response further includes at least one of the following: an identifier for each IoT device; a group identifier; wherein the group identifier is an identifier for the group of IoT devices; and a second random number determined by each IoT device.

[0059] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: sending a second request to a second network function based on the first response; wherein the second request is used to request verification of the identity of each IoT device in the group of IoT devices; receiving a second response sent by the second network function; and sending at least one first command to a reader based on the second response; wherein each first command is used to control a second IoT device to perform a first operation, the second IoT device being an IoT device in the group of IoT devices that has successfully passed authentication, the second key corresponding to the second IoT device being a key for security protection of the first command, and each IoT device in the group of IoT devices corresponding to a different key.

[0060] In the above embodiments, the first network function can send a second request to the second network function to request verification of the identity of each IoT device in the group of IoT devices. Subsequently, the second key corresponding to the second IoT device that has successfully passed the authentication can be used to securely protect the first command, thereby achieving the purpose of secure isolation between IoT devices belonging to the same group and ensuring high availability.

[0061] In conjunction with some embodiments of the second aspect, in some embodiments, the second request includes at least one of the following: a first random number; wherein the first random number is determined by the first network function; a second random number determined by each IoT device; an identifier of each IoT device; a first value corresponding to each IoT device; and a group identifier; wherein the group identifier is an identifier of the group of IoT devices.

[0062] In conjunction with some embodiments of the second aspect, in some embodiments, the second response includes at least one of the following: a second value corresponding to each IoT device; wherein the second value corresponding to each IoT device is a verification value obtained by authenticating each IoT device; a third key corresponding to each IoT device; and an identifier of a second IoT device; wherein the second IoT device is an IoT device that has successfully passed authentication in the group of IoT devices.

[0063] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes at least one of the following: the second response includes a second value corresponding to each IoT device, and the IoT device in the group of IoT devices whose second value is the same as the first value is determined as the second IoT device; the second response includes a third key corresponding to each IoT device, and the first value in the group of IoT devices is verified based on the third key, and the IoT device corresponding to the verified first value is determined as the second IoT device.

[0064] In the above embodiments, the first network function can identify the second IoT device based on the second response, thereby improving the availability and reliability of IoT technology, especially environmental IoT technology.

[0065] Thirdly, embodiments of this disclosure propose a communication method executed by a second network function. The method includes: receiving a second request sent by a first network function based on a first response; wherein the first response is used to respond to a first request sent by the first network function to a reader, the first request being used to request triggering the reader to broadcast an inventory request, the inventory request being used for each IoT device in a group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key; wherein the second request is used to request verification of the identity of each IoT device in the group of IoT devices; and sending a second response to the first network function based on the second request.

[0066] In the above embodiments, the second network function can send a second response to the first network function based on the second request, thereby achieving the purpose of identity authentication for the same group of IoT devices, and has high availability.

[0067] In conjunction with some embodiments of the third aspect, in some embodiments, the second request includes at least one of the following: a first random number; wherein the first random number is determined by the first network function; a second random number determined by each IoT device; an identifier of each IoT device; a first value corresponding to each IoT device; wherein the first value corresponding to each IoT device is used to verify the identity of each IoT device; a group identifier; wherein the group identifier is the identifier of the group of IoT devices.

[0068] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes: determining at least one of a second value corresponding to each IoT device and a third key corresponding to each IoT device based on the second request; wherein the second value is a verification value obtained by authenticating each IoT device.

[0069] In conjunction with some embodiments of the third aspect, in some embodiments, determining at least one of the second value corresponding to each IoT device and the third key corresponding to each IoT device based on the second request includes: determining at least one of the second value corresponding to each IoT device and the third key corresponding to each IoT device using a first function based on at least one first parameter; wherein the at least one first parameter includes at least one of the following: a first random number; wherein the first random number is determined by a first network function; a second random number; wherein the second random number is determined by the first IoT device; a fourth key; wherein the fourth key is a key stored on the first IoT device; a first identifier; wherein the first identifier is the identifier of the first IoT device; and a group identifier; wherein the group identifier is the identifier of the group of IoT devices.

[0070] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes at least one of the following: identifying an IoT device whose second value is the same as the first value as a second IoT device; verifying the first value in the group of IoT devices based on the third key, and identifying the IoT device corresponding to the verified first value as the second IoT device; wherein the second IoT device is an IoT device in the group of IoT devices that has successfully passed authentication.

[0071] In conjunction with some embodiments of the third aspect, in some embodiments, the second response includes at least one of the following: a second value corresponding to each IoT device; wherein the second value corresponding to each IoT device is a verification value obtained by authenticating each IoT device; a third key corresponding to each IoT device; and an identifier of a second IoT device; wherein the second IoT device is an IoT device that has successfully passed authentication in the group of IoT devices.

[0072] Fourthly, embodiments of this disclosure propose a communication method, the method comprising: a first network function sending a first request to a reader; wherein the first request is used to request triggering a broadcast inventory request, the inventory request being used to perform inventory on a group of IoT devices, the group of IoT devices including at least the first IoT device; the reader broadcasting the inventory request; the first IoT device, based on the received inventory request, determining at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device; wherein the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key; the first IoT device sending an inventory response to the reader; wherein the inventory response includes at least the first value corresponding to the first IoT device; the reader sending a first response to the first network function; wherein the first response includes at least the first value corresponding to each IoT device in the group of IoT devices; the first network function, based on the first response, sending a second request to a second network function; wherein the second request is used to request verification of the identity of each IoT device in the group of IoT devices; the second network function, based on the second request, sending a second response to the first network function.

[0073] Fifthly, embodiments of this disclosure provide a communication device for performing the communication method described in any one of the first, second, or third aspects.

[0074] In a sixth aspect, embodiments of this disclosure provide a communication system including a first Internet of Things (IoT) device, a first network function, and a second network function, wherein the first IoT device is configured to implement the communication method described in any one of the first aspects, the first network function is configured to implement the communication method described in any one of the second aspects, and the second network function is configured to implement the communication method described in any one of the third aspects.

[0075] In a seventh aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform a communication method as described in any one of the first, second, or third aspects.

[0076] Eighthly, embodiments of this disclosure provide a computer program product including a computer program that, when executed by a processor, is used to implement the communication method described in any one of the first, second, or third aspects.

[0077] Understandably, the aforementioned first IoT device, first network function, second network function, communication system, storage medium, program product, computer program, chip, or chip system are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0078] This disclosure presents communication methods, Internet of Things (IoT) devices, network functions, systems, and storage media. In some embodiments, the terms communication method, information processing method, and information transmission method may be used interchangeably.

[0079] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments. In all embodiments of this disclosure, unless otherwise specified or logically conflicting, the terminology and / or descriptions between the embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0080] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0081] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0082] In the embodiments disclosed herein, "multiple" refers to two or more.

[0083] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0084] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.

[0085] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.

[0086] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0087] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0088] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.

[0089] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.

[0090] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0091] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.

[0092] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).

[0093] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.

[0094] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.

[0095] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0096] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0097] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0098] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0099] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0100] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0101] As shown in Figure 1A, the communication system 100 includes at least one of the following: an Internet of Things (IoT) device 101, a first network function 102, and a second network function 103.

[0102] In some embodiments, the Internet of Things (IoT) device 101 may include, for example, at least one of the following: environmental IoT devices, wearable devices, automobiles with communication capabilities, smart cars, tablets, computers with wireless transceiver capabilities, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminal devices in industrial control, wireless terminal devices in self-driving, wireless terminal devices in remote medical surgery, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, and wireless terminal devices in smart homes, but is not limited thereto.

[0103] In some embodiments, this disclosure relates to a group of Internet of Things (IoT) devices 101, which includes at least a first IoT device 101-1. The first IoT device 101-1 can be any one of the IoT devices in the group.

[0104] In one example, the group of IoT devices 101 may include a second IoT device 101-2, which is an IoT device in the group that has been successfully authenticated.

[0105] In some embodiments, the first network function 102 may be used to perform tasks such as registering IoT device 101 and managing IoT device 101, and the name is not limited thereto.

[0106] In some embodiments, the first network function 102 may be independent of the core network equipment.

[0107] In some embodiments, the first network function 102 may be part of a core network device.

[0108] In some embodiments, the first network function 102 may be a core network function or a third-party network function that does not belong to the core network.

[0109] In some embodiments, the first network function 102 is, for example, an Access and Mobility Management Function (AMF).

[0110] In some embodiments, the first network function 102 is, for example, an Ambient Internet of Things Function (AIoTF) for controlling and / or managing environmental Internet of Things devices. Of course, the first network function 102 may also be other network functions, and this disclosure does not limit it.

[0111] In some embodiments, the second network function 103 may be used to store device information of the Internet of Things device 101, and the name is not limited thereto.

[0112] In some embodiments, the second network function 103 may be independent of the core network equipment.

[0113] In some embodiments, the second network function 103 may be part of the core network equipment.

[0114] In some embodiments, the second network function 103 may be a core network function or a third-party network function that does not belong to the core network.

[0115] In some embodiments, the second network function 103 is, for example, at least one of Unified Data Management (UDM), Unified Data Repository (UDR), Ambient Internet of Things Data Management Function (AIoTDM), third-party authentication function, and third-party authentication server.

[0116] In some embodiments, the communication system 100 may further include at least one of a reader 104, a third network function 105, and an access network device 106.

[0117] In some embodiments, the reader 104 may be located between the first network function 102 and the IoT device 101, transmitting commands and / or data sent by the first network function 102 to the IoT device 101, and / or transmitting data and / or information sent by the IoT device 101 to the first network function 102.

[0118] In some embodiments, the third network function 105 may be used to trigger inventory and / or control of a group of Internet of Things (IoT) devices 101, and the name is not limited thereto.

[0119] In some embodiments, the third network function 105 may be independent of the core network equipment.

[0120] In some embodiments, the third network function 105 may be part of the core network equipment.

[0121] In some embodiments, the third network function 105 may be a core network function or a third-party network function that does not belong to the core network.

[0122] In some embodiments, the third network function 105 may be a network function or an application function (AF).

[0123] In some embodiments, the access network device 106 may be a node or device that connects the IoT device 101 to the wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next generation eNB (ng-eNB), next generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), wireless backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.

[0124] In some embodiments, the access network device 106 and the reader 104 may be the same device, in which case the IoT device 101 can communicate directly with the access network device 106.

[0125] In some embodiments, there is an intermediate node between the access network device 106 and the Internet of Things device 101. In this case, the intermediate node corresponds to the reader 104 in FIG1A, and the access network device 106 and the Internet of Things device 101 can communicate through the reader 104.

[0126] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0127] In some embodiments, the access network device 106 may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0128] In some embodiments, applications of the Internet of Things for the Environment include improving supply chain efficiency and sustainability, preventing counterfeiting, and providing the data needed for advanced transportation and smart city initiatives.

[0129] In some embodiments, the connection topology of environmental IoT networks and devices includes the following two categories:

[0130] Topology 1, Base Station (BS) Environmental IoT devices.

[0131] For example, as shown in Figure 1B, in Topology 1, the environmental IoT device communicates directly and bidirectionally with the base station. Communication between the base station and the environmental IoT device includes environmental IoT data and / or signaling. This topology allows for the possibility that the signals sent by the BS to the environmental IoT device differ from the signals received by the BS from the environmental IoT device.

[0132] Topology 2:BS intermediate nodes Environmental IoT devices.

[0133] For example, as shown in Figure 1C, in topology 2, environmental IoT devices communicate bidirectionally with intermediate nodes between the devices and the base station. In this topology, intermediate nodes can be repeaters, integrated access and backhaul (IAB) nodes, terminals, etc., that enable environmental IoT. The intermediate nodes transmit information between the BS and the environmental IoT devices.

[0134] Based on the above topology, the core network or application server can send inventory or commands (e.g., read commands, write commands) to environmental IoT devices, and the environmental IoT devices can report sensor data to the core network or application server. From a security perspective, all transmitted information should be protected. Otherwise, attackers could intercept or manipulate this information, thereby disrupting or misleading the decision-making process.

[0135] In some embodiments, group inventory and / or group commands may be supported.

[0136] In one example, information transmission supporting environmental IoT services and related network functions can be considered, including information transmission between individual environmental IoT devices and network functions, and / or information transmission between a group of environmental IoT devices and network functions.

[0137] Among these aspects, the considerations include device type and functionality, and whether session-based transmission between IoT devices and network functions needs to be supported.

[0138] In one example, one could consider exposing enabled environmental IoT services to the AF, and how to do so, for example, the AF could request environmental IoT services for a single environmental IoT device and / or a group of environmental IoT devices.

[0139] To protect information transmission during group inventory and / or group command processes, a key for protecting communication information should be determined after group authentication, and security isolation requirements should be met.

[0140] Therefore, it is necessary to study how to support secure isolation after group authentication.

[0141] In some embodiments, group authentication methods can be used to authenticate a group of IoT devices, regardless of the security isolation between group members. After authentication, all devices in the group determine the same key to protect communication information.

[0142] For example, after the core network completes the authentication of a group of IoT devices, if it needs to shut down some IoT devices, it will send a command to the designated IoT devices to shut them down. However, since the command is protected by a key, and all IoT devices in the same group correspond to the same key, all IoT devices in the group use the key to verify the command. If the verification is successful, it is confirmed that the command is for itself, causing all IoT devices in the group to perform the shutdown operation. Obviously, this process cannot control the designated IoT devices to execute the network-side command.

[0143] To achieve secure isolation of devices within a group and improve the availability and reliability of IoT technology, especially environmental IoT technology, this disclosure provides the following communication methods, IoT devices, network functions, systems, and storage media.

[0144] Figure 2 is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2, the present disclosure relates to a communication method, which includes:

[0145] In step S2101, the third network function 105 sends a third request to the first network function 102.

[0146] In some embodiments, the first network function 102 receives a third request.

[0147] In some embodiments, the third network function 105 may be used to trigger inventory and / or control of a group of Internet of Things (IoT) devices 101, and the name is not limited thereto.

[0148] In some embodiments, the third network function 105 may be a network function (NF) or an application function (AF).

[0149] In some embodiments, the first network function 102 may be used to perform tasks such as registering IoT device 101 and managing IoT device 101, and the name is not limited thereto.

[0150] In some embodiments, the first network function 102 is, for example, an Access and Mobility Management Function (AMF).

[0151] In some embodiments, the first network function 102 is, for example, an Ambient Internet of Things Function (AIoTF) for controlling and / or managing environmental Internet of Things devices. Of course, the first network function 102 may also be other network functions, and this disclosure does not limit it.

[0152] In some embodiments, the IoT device 101 disclosed herein may include, but is not limited to, environmental IoT devices.

[0153] In some embodiments, a third request may be used to request the triggering of group inventory and / or group commands.

[0154] In one example, group inventory can refer to an inventory performed on a group of IoT devices 101.

[0155] In one example, a group command can be used to control at least one of a group of IoT devices 101 to perform a first operation.

[0156] For example, the first operation may include, but is not limited to, read operation, write operation, turn-on operation, turn-off operation, charging and / or power-on operation, etc., and this disclosure does not limit it.

[0157] In some embodiments, the third network function 105 may send a third request to the first network function 102 based on a user request.

[0158] In some embodiments, the third network function 105 may send a third request to the first network function 102 at a preset period.

[0159] In some embodiments, the third network function 105 may send a third request to the first network function 102 when an inventory of a group of IoT devices is required.

[0160] In some embodiments, the third network function 105 may send a third request to the first network function 102 if certain conditions for sending a third request are met. These conditions may be agreed upon by a protocol, set by a user, and / or configured by the first network function 102, and this disclosure does not limit their application.

[0161] The above is merely an illustrative example, and this disclosure does not limit the timing or event at which the third network function 105 sends a third request to the first network function 102.

[0162] In some embodiments, the name of the third request is not limited and can be interchanged with "group inventory trigger request", "group command trigger request", etc.

[0163] In some embodiments, the third request may include, but is not limited to, at least one of the following: group identifier; region information.

[0164] In one example, the group identifier can be the identifier of a group of IoT devices 101. This group identifier can identify one or more IoT devices 101 belonging to that group. For example, if IoT device #1, IoT device #2, and IoT device #3 belong to group #2, then with group identifier 2, IoT device #1, IoT device #2, and IoT device #3 can be identified.

[0165] In one example, the group identifier can be associated with the device identifier of IoT device 101.

[0166] For example, the device identifier of IoT device 101 includes a group identifier and a device identifier within the group. In this case, the third request includes the group identifier in the device identifier. For example, the device identifier of IoT device 101 is 001 010, where "001" can be the group identifier and "010" can be the device identifier of IoT device 101 within group #1. In this case, the third request may include "001".

[0167] In one example, area information can be used to indicate the area where the group of IoT devices 101 is located.

[0168] The area may refer to the geographical area where the group of IoT devices 101 is located, or it may refer to one or more physical cells where the group of IoT devices 101 is located. This disclosure does not limit it in this respect.

[0169] Step S2102, the first network function 102 determines the reader 104.

[0170] In some embodiments, the first network function 102 may select the reader corresponding to the group of IoT devices 101 from at least one reader based on a third request.

[0171] In one example, the third request includes a group identifier, and the first network function 102 can select, in at least one reader, a reader that supports serving each IoT device 101 in that group of IoT devices.

[0172] In one example, the third request includes region information, and the first network function can select a reader within the region indicated by the region information in at least one reader.

[0173] In one example, the number of readers 104 determined by the first network function 102 can be one or more, and this disclosure does not limit this.

[0174] In one example, the third request includes a group identifier and area information. The first network function can select, among at least one reader, to support a reader that serves each IoT device 101 in the group of IoT devices and is located within the first area.

[0175] The above is merely an illustrative example, and this disclosure does not limit the method by which the first network function 102 selects a reader.

[0176] In step S2103, the first network function 102 sends a first request to the reader 104.

[0177] In some embodiments, reader 104 receives a first request.

[0178] In some embodiments, the first network function 102 sends a first request to at least one selected reader 104.

[0179] In some embodiments, the first request is used to request that the reader 104 perform an inventory of a group of Internet of Things devices 101.

[0180] In some embodiments, the first request may be used to trigger the reader 104 to broadcast an inventory request for inventorying a group of IoT devices.

[0181] In some embodiments, the first network function 102 may send a first request to the reader 104 upon receiving a third request.

[0182] In some embodiments, the first network function 102 may send a first request to the reader 104 when it is necessary to trigger the reader 104 to perform an inventory of a group of Internet of Things devices 101.

[0183] In some embodiments, the first network function 102 may send a first request to the reader 104 based on a user request.

[0184] In some embodiments, the name of the first request is not limited and can be interchanged with "group disk trigger request", "trigger request", etc.

[0185] In some embodiments, the first request may include, but is not limited to, at least one of the following: a group identifier; a first random number.

[0186] In one example, the group identifier is the identifier of the group of IoT devices 101.

[0187] In one example, the first random number may be a random number determined by the first network function 102.

[0188] The first random number can be used to determine the first key. The first key corresponds to the first IoT device 101-1 and is a unique key for the first IoT device 101-1 used to protect communication information.

[0189] The first random number can be used to determine the first value, which can be used to verify the identity of the IoT device. For example, the first value corresponding to the first IoT device 101-1 can be used to verify the identity of the first IoT device 101-1.

[0190] The first random number can be used to determine the first key and the first value.

[0191] The first random number can be used to improve the security of the calculation process on the IoT device side. The calculation process may include the process of calculating the first value and / or the first key, or the process of calculating other security information related to the IoT device.

[0192] The first random number can be used to determine the third key. The third key is a key determined by the second network function 103 for each IoT device based on at least one first parameter; it can also be called a verification key.

[0193] The first random number can be used to determine the second value, which is the verification value obtained by authenticating each IoT device.

[0194] The first random number can be used to determine the third key and the second value.

[0195] The first random number can be used to improve the security of the calculation process on the second network function side. The calculation process may include the process of calculating the second value and / or the third key, or the process of calculating other security information related to IoT devices.

[0196] The first random number can be used to determine at least one of the first key, the first value, the third key, and the second value. This disclosure does not limit this.

[0197] Considering that the IoT device needs to calculate a key for protecting communication information and / or a value (e.g., a first value) for verifying the identity of the IoT device 101, at least one random number is required to improve the security of the calculation process. In this embodiment of the disclosure, the first random number can be determined by the first network function 102.

[0198] In some embodiments, if the first network function 102 requests the reader 104 to perform an inventory of a group of IoT devices 101, the first request may include a group identifier.

[0199] In some embodiments, if the first network function 102 requests to trigger the reader 104 to perform an inventory of a specific IoT device 101, the first request may not include a group identifier.

[0200] In some embodiments, if the first network function 102 requests the reader 104 to perform an inventory of a specific IoT device 101, the first request may include the identifier of the IoT device, such as a first identifier, which is the identifier of the first IoT device 101.

[0201] In some embodiments, if the first network function 102 requests the reader 104 to perform inventory on a group of IoT devices 101, the first request may not include the identifier of a specific IoT device, for example, it may not include the first identifier, which is the identifier of the first IoT device 101.

[0202] In some embodiments, if the first network function 102 requests the reader 104 to perform inventory on a group of IoT devices 101, the first request may not include the identifier of a specific IoT device, for example, it may not include the first identifier, and the first request may include the group identifier.

[0203] In some embodiments, if the first network function 102 requests the reader 104 to perform an inventory of a specific IoT device 101, the first request may include the identifier of the IoT device, such as a first identifier, and the first request may not include a group identifier.

[0204] In step S2104, reader 104 broadcasts a disk storage request.

[0205] In some embodiments, each of the IoT devices in a group of IoT devices 101 may receive the inventory request.

[0206] The group of IoT devices 101 includes at least a first IoT device 101-1. The first IoT device 101-1 is any one of the IoT devices in the group.

[0207] In some embodiments, if the first request includes a group identifier, the reader 104 may determine that a group of IoT devices 101 needs to be inventoried. In this case, the reader 104 may broadcast an inventory request, which can be used to request an inventory of a group of IoT devices.

[0208] In some embodiments, the reader 104 may broadcast an inventory request after receiving a first request from the first network function 102.

[0209] In some embodiments, the reader 104 may broadcast a disk storage request if a group disk storage is required.

[0210] In some embodiments, if the first request does not include a group identifier and / or includes the identifier of a specific IoT device, the reader 104 may determine that an inventory of a specific IoT device 101 is required. In this case, the reader 104 may send an inventory request only to that IoT device.

[0211] In some embodiments, the inventory request may include, but is not limited to, at least one of the following: a group identifier; a first random number.

[0212] The group identifier is the identifier of the group of IoT devices. The first random number is a random number determined by the first network function 102.

[0213] In some embodiments, the inventory request does not include a first identifier, i.e., the identifier of the first IoT device 101-1, and the first IoT device 101-1 can determine that the inventory request is for inventorying a group of IoT devices.

[0214] In some embodiments, the inventory request includes a group identifier, and the first IoT device 101-1 determines that the inventory request is for inventorying a group of IoT devices.

[0215] In some embodiments, the inventory request does not include a group identifier, and the first IoT device 101-1 determines that the inventory request is for inventorying a group of IoT devices.

[0216] In some embodiments, the inventory request includes a first identifier, and the first IoT device 101-1 determines that the inventory request is for inventorying itself.

[0217] Step S2105: The first IoT device 101-1 establishes a connection with the reader 104.

[0218] In some embodiments, each of the IoT devices in the group can establish a connection with the reader 104.

[0219] In some embodiments, each IoT device in the group of IoT devices may establish a connection with the reader 104 in a manner similar to random access.

[0220] In some embodiments, the group of IoT devices includes at least a first IoT device 101-1, which can establish a connection with the reader 104 in a manner similar to random access.

[0221] In one example, the first IoT device 101-1 receives the inventory request and sends a preamble (similar to message 1 in a random access procedure) to the reader 104 based on the inventory request. The reader 104 sends an access confirmation message (similar to message 2 in a random access procedure) to the first IoT device 101-1 based on the received preamble. The first IoT device 101-1 sends its device identifier (similar to message 3 in a random access procedure), such as an Electronic Product Code (EPC), to the reader 104 based on the access confirmation message, thereby completing the connection establishment process.

[0222] The above is merely an illustrative example, and this disclosure does not limit the method by which the first IoT device 101-1 establishes a connection with the reader 104.

[0223] Step S2106, the first IoT device 101-1 determines the first value and / or the first key.

[0224] In some embodiments, the first value can be used to verify the identity of the first IoT device 101-1.

[0225] In some embodiments, the first key corresponds to the first IoT device 101-1 and is a unique key for the first IoT device 101-1 used to protect communication information.

[0226] In some embodiments, each IoT device 101 in a group of IoT devices corresponds to a different key.

[0227] In one example, the first key may be a "first session key", which may be a unique key of the first Internet of Things device 101-1 used when interacting with network functions for data and / or information. Of course, the first key may also be other types of keys, which are not limited in this disclosure.

[0228] For example, if a group of IoT devices includes IoT device #1 and IoT device #2, then IoT device #1 corresponds to key #1 and IoT device #2 corresponds to key #2. Key #1 and key #2 are different.

[0229] In some embodiments, the first IoT device 101-1 may determine a first value and / or a first key based on a received inventory request.

[0230] In some embodiments, the first IoT device 101-1 may determine the first value and / or the first key based on at least one first parameter and using a first function.

[0231] In one example, the first parameter may include, but is not limited to, at least one of the following: a first random number; a second random number; a fourth key; a first identifier; and a group identifier.

[0232] The first random number is a random number determined by the first network function 102.

[0233] The second random number is a random number determined by the first IoT device 101-1.

[0234] The second random number can be used to determine the first key. The first key corresponds to the first IoT device 101-1 and is a unique key for the first IoT device 101-1 used to protect communication information.

[0235] The second random number can be used to determine the first value, which can then be used to verify the identity of the IoT device. For example, the first value corresponding to the first IoT device 101-1 can be used to verify the identity of the first IoT device 101-1.

[0236] The second random number can be used to determine the first key and the first value.

[0237] The second random number can be used to improve the security of the calculation process on the IoT device side. The calculation process may include the process of calculating the first value and / or the first key, or the process of calculating other security information related to the IoT device.

[0238] The second random number can be used to determine the third key. The third key is a key determined by the second network function 103 for each IoT device based on at least one first parameter; it can also be called a verification key.

[0239] The second random number can be used to determine the second value, which is the verification value obtained by authenticating each IoT device.

[0240] The second random number can be used to determine the third key and the second value.

[0241] The second random number can be used to improve the security of the calculation process on the second network function side. The calculation process may include the process of calculating the second value and / or the third key, or the process of calculating other security information related to IoT devices.

[0242] The second random number can be used to determine at least one of the first key, the first value, the third key, and the second value. This disclosure does not limit this. The fourth key is a key stored on the first IoT device 101-1, and the fourth key may include, but is not limited to, at least one of the following: a group root key; a device root key.

[0243] The root key can be the root key of a group of IoT devices 101.

[0244] The group root key can be used for group authentication or group inventory, and this disclosure does not limit its use.

[0245] The device root key can be the root key of the first IoT device 101-1.

[0246] The device root key can be used for single-device authentication or single-device inventory, such as verifying the identity of the first IoT device 101-1.

[0247] It is understood that the group root key and the device root key may be the same or different, and this disclosure does not limit this.

[0248] It is understood that the device root key can also be used for group disk storage, and this disclosure does not limit this.

[0249] It is understood that the first IoT device 101-1 may store both the group root key and the device root key, or it may store only the group root key or the device root key, and this disclosure does not limit this either.

[0250] The first identifier can be the identifier of the first IoT device 101-1, such as the EPC of the first IoT device 101-1, or other permanent identifiers of the IoT device.

[0251] The group identifier can be the identifier of a group of IoT devices 101, such as group #1.

[0252] In one example, the group identifier can be associated with the device identifier of IoT device 101.

[0253] For example, the device identifier of IoT device 101 includes a group identifier and a device identifier within the group. In this case, the third request includes the group identifier from the device identifier.

[0254] The above is merely an illustrative example, and this disclosure does not limit the type of the first parameter.

[0255] In one example, the fourth key can be stored in the non-volatile memory (NVM) of the first IoT device 101-1.

[0256] For example, the fourth key can be written into the NVM of the first IoT device 101-1 at the time of manufacture.

[0257] In one example, the first function may include, but is not limited to, at least one of the following: function f1; function f2; function f3; function f4; function f5; key derivation function (KDF).

[0258] Among them, functions f1 to f5 can be functions agreed upon in the protocol for calculating security parameters.

[0259] KDF can be a function that uses a pseudo-random function to derive one or more keys from the primary key (or master key), and KDF can be defined by a protocol.

[0260] In some embodiments, the first IoT device 101-1 may determine the first value and / or the first key in the following manner:

[0261] Method 1: Based on the first random number, the fourth key, and the first identifier, a first function is used to determine the first value and / or the first key.

[0262] The first random number is a random number determined by the first network function 102. For a group of IoT devices, the first random number can be the same.

[0263] The fourth key can be the group root key and / or the device root key.

[0264] The first identifier is the identifier of the first IoT device 101-1.

[0265] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0266] Method 2: Based on the second random number, the fourth key, and the first identifier, a first function is used to determine the first value and / or the first key.

[0267] The second random number is a random number determined by the first IoT device 101-1. For a group of IoT devices, the second random number determined by each IoT device can be different.

[0268] The fourth key can be the group root key and / or the device root key.

[0269] The first identifier is the identifier of the first IoT device 101-1.

[0270] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0271] Method 3: Based on the first random number, the second random number, the fourth key, and the first identifier, a first function is used to determine the first value and / or the first key.

[0272] The first random number is a random number determined by the first network function 102. For a group of IoT devices, the first random number can be the same.

[0273] The second random number is a random number determined by the first IoT device 101-1. For a group of IoT devices, the second random number determined by each IoT device can be different.

[0274] The fourth key can be the group root key and / or the device root key.

[0275] The first identifier is the identifier of the first IoT device 101-1.

[0276] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0277] Method 4: Based on the first random number, the second random number, and the fourth key, a first function is used to determine the first value and / or the first key.

[0278] The first random number is a random number determined by the first network function 102. For a group of IoT devices, the first random number can be the same.

[0279] The second random number is a random number determined by the first IoT device 101-1. For a group of IoT devices, the second random number determined by each IoT device can be different.

[0280] The fourth key can be the group root key and / or the device root key.

[0281] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0282] Method 5: Based on the first random number, the fourth key, and the group identifier, a first function is used to determine the first value and / or the first key.

[0283] The first random number is a random number determined by the first network function 102. For a group of IoT devices, the first random number can be the same.

[0284] The fourth key can be the group root key and / or the device root key.

[0285] The group identifier is an identifier for a group of Internet of Things (IoT) devices.

[0286] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0287] Method 6: Based on the second random number, the fourth key, and the group identifier, a first function is used to determine the first value and / or the first key.

[0288] The second random number is a random number determined by the first IoT device 101-1. For a group of IoT devices, the second random number determined by each IoT device can be different.

[0289] The fourth key can be the group root key and / or the device root key.

[0290] The group identifier is an identifier for a group of Internet of Things (IoT) devices.

[0291] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0292] Method 7: Based on the first random number, the second random number, the fourth key, and the group identifier, a first function is used to determine the first value and / or the first key.

[0293] The first random number is a random number determined by the first network function 102. For a group of IoT devices, the first random number can be the same.

[0294] The second random number is a random number determined by the first IoT device 101-1. For a group of IoT devices, the second random number determined by each IoT device can be different.

[0295] The fourth key can be the group root key and / or the device root key.

[0296] The group identifier is an identifier for a group of Internet of Things (IoT) devices.

[0297] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0298] Method 8: Based on the first random number and the fourth key, a first function is used to determine the first value and / or the first key.

[0299] The first random number is a random number determined by the first network function 102. For a group of IoT devices, the first random number can be the same.

[0300] The fourth key can be the group root key and / or the device root key.

[0301] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0302] Method 9: Based on the second random number and the fourth key, a first function is used to determine the first value and / or the first key.

[0303] The second random number is a random number determined by the first IoT device 101-1. For a group of IoT devices, the second random number determined by each IoT device can be different.

[0304] The fourth key can be the group root key and / or the device root key.

[0305] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0306] Method 10: Based on the first key and the determined disk response sent, a first function is used to determine the first value.

[0307] The first key is a key determined by the first IoT device based on other methods. These other methods can be any of the methods 1 to 9 mentioned above, or methods different from those mentioned above; this disclosure does not limit the specific methods.

[0308] Specifically, the inventory response to be sent can be the inventory response message itself or one or more values ​​included in the inventory response message. For example, if the inventory response message includes a first identifier, then the inventory response to be sent can be the value of the first identifier. As another example, if the inventory response message includes a second random number, then the inventory response to be sent can be the value of the second random number. The above are merely illustrative examples, and this disclosure does not limit the content of the inventory response to be sent.

[0309] The first function can be f1, f2, f3, f4, f5, or a KDF.

[0310] It is understandable that, in the above method, at least one of the first parameters used to determine the first key must be unique in order to ensure that the first key is unique to the first IoT device 101-1.

[0311] For example, in Method 1, the first identifier is the identifier of the first IoT device 101-1, which is necessarily different from the identifiers of other IoT devices in the group. That is, the first identifier is unique. Therefore, the calculated first key is different from the key determined by other IoT devices in the group.

[0312] For example, in method 9, the second random number is determined by the first IoT device 101-1, which is generally different from the random numbers determined by other IoT devices in the group. That is, the second random number is unique. Therefore, the first key determined based on the second random number and the fourth key (even if the fourth key is the group root key) is different from the key determined by other IoT devices in the group.

[0313] For example, in method 10, after determining the first key, the first IoT device 101-1 then determines the first value. The first IoT device 101-1 can use the first key and the determined disk response to determine the first value using the first function f1. At this time, the first value is MAC.

[0314] It should be noted that the first network function 102 can select a first function for the first IoT device 101-1. For example, as shown in Figure 4B, the first IoT device 101-1 can support at least one function among f1, f2, ..., f5, or KDF. The first network function 102 can select one of the functions supported by the first IoT device 101-1 as the first function.

[0315] For example, the process for determining the first key and / or the first value is as follows:

[0316] The following parameters can be used as input S to the KDF:

[0317] -FC = 0xaa,

[0318] -P0 = random number (first random number or second random number),

[0319] -L0 = the length of the random number (i.e., 0x00 0x10),

[0320] -P1 = Device identifier,

[0321] -L1 = Length of the device identifier (i.e., 0x00 0x10),

[0322] The input key (KEY) can be equal to the group root key.

[0323] First value = f2 K (RAND), where RAND is the first or second random number, and K is the group root key. f2 is the message authentication function.

[0324] For example, the first value may be a response value (RES) determined by the device.

[0325] For example, the first value could be a Message Authentication Code (MAC).

[0326] For example, the first value can be other values ​​used to authenticate the identity of IoT device 101, which are not limited in this disclosure.

[0327] For example, the process of determining the first key is as follows:

[0328] The following parameters can be used as input S to the KDF:

[0329] -FC = 0xaa,

[0330] -P0 = random number (first random number or second random number),

[0331] -L0 = the length of the random number (i.e., 0x00 0x10),

[0332] -P1 = Group identifier,

[0333] -L1 = the length of the group identifier (i.e., 0x00 0x10),

[0334] The input key (KEY) can be equal to the device root key.

[0335] For example, the process of determining the first key is as follows:

[0336] The following parameters can be used as input S to the KDF:

[0337] -FC = 0xbb,

[0338] -P0 = random number (first random number or second random number),

[0339] -L0 = the length of the random number (i.e., 0x00 0x10),

[0340] -P1 = Device identifier,

[0341] -L1 = Length of the device identifier (i.e., 0x00 0x10),

[0342] The input key (KEY) can be equal to the device root key.

[0343] The above is merely an illustrative example. This disclosure does not limit the method by which the first IoT device 101-1 determines the first value and / or the first key, as long as different IoT devices within the same group correspond to different keys.

[0344] In step S2107, the first IoT device 101-1 sends an inventory response to the reader 104.

[0345] In some embodiments, reader 104 receives a disk storage response.

[0346] In some embodiments, reader 104 receives inventory responses from each IoT device in the group.

[0347] In some embodiments, the inventory response sent by the first IoT device 101-1 may include at least a first value corresponding to the first IoT device. The first value may be RES, MAC, or other values ​​used to authenticate the identity of the IoT device 101.

[0348] In some embodiments, the inventory response may include, but is not limited to, at least one of the following: a first identifier; a group identifier; and a second random number.

[0349] The first identifier is the identifier of the first IoT device 101-1. The group identifier is the identifier of a group of IoT devices. The second random number is a random number determined by the first IoT device 101-1.

[0350] In step S2108, the reader 104 sends a first response to the first network function 102.

[0351] In some embodiments, the first network function 102 receives a first response.

[0352] In some embodiments, after aggregating the inventory responses of each IoT device in the group, the reader 104 sends a first response to the first network function 102. For example, the reader 104 aggregates all received inventory responses and sends the first response to the first network function 102. As another example, the reader 104 aggregates the parameters (e.g., a second random number, a first value, etc.) in all received inventory responses and sends the first response to the first network function 102.

[0353] In some embodiments, a first response is used to respond to a first request. The first response may include at least a first value corresponding to each of the set of IoT devices.

[0354] In some embodiments, the first response may include, but is not limited to, at least one of the following: the identifier of each IoT device; a group identifier; and a second random number determined for each IoT device, for example, the first response may include (group identifier #1 < device identifier #1, RES #1, random number #1>, < device identifier #2, RES #2, random number #2>).

[0355] In some embodiments, the name of the first response is not limited and can be interchanged with "group disk trigger response", "trigger response", etc.

[0356] In step S2109, the first network function 102 sends a second request to the second network function 103.

[0357] In some embodiments, the second network function 103 receives a second request.

[0358] In some embodiments, the second request is used to request verification of the identity of each of the IoT devices in the group of IoT devices.

[0359] In some embodiments, the name of the second request is not limited and can be interchanged with "verification request", "authentication request", etc.

[0360] In some embodiments, the second network function 103 is a network function that stores device information of the Internet of Things device 101.

[0361] In some embodiments, the second network function 103 is, for example, at least one of UDM, UDR, AIoTDM, third-party authentication function, and third-party authentication server.

[0362] In some embodiments, the second network function 103 may store a device identifier, a group identifier, and a fourth key, and the data structure it adopts may be as shown in Table 1, for example.

[0363] Table 1

[0364] Alternatively, the second network function 103 may store the device identifier and the fourth key, and its data structure may be as shown in Table 2, for example.

[0365] Table 2

[0366] Alternatively, the second network function 103 may store the device identifier and the fourth key, and its data structure may be as shown in Table 3, for example.

[0367] Table 3

[0368] The above is merely an illustrative example, and this disclosure does not limit the data structure used by the second network function 103 when storing at least one of the fourth key, device identifier, and group identifier.

[0369] In some embodiments, the first network function 102 sends a second request to the second network function 103 when it is necessary to verify the identity of each IoT device in the group.

[0370] In some embodiments, upon receiving a first response, the first network function 102 sends a second request to the second network function 103.

[0371] In some embodiments, the first network function 102 may send a second request to the second network function 103 without storing device information of the Internet of Things device.

[0372] In some embodiments, the second request may include, but is not limited to, at least one of the following: a first random number; a second random number determined for each IoT device in the group; an identifier for each IoT device; a first value corresponding to each IoT device; and a group identifier. Specific details have been described in the foregoing embodiments and will not be repeated here.

[0373] In step S2110, the second network function 103 determines the second value and / or the third key.

[0374] In some embodiments, the second value is the verification value obtained by authenticating each IoT device.

[0375] In one example, the second value could be the expected response (XRES) determined by the second network function 103.

[0376] In one example, the second value could be the MAC determined by the second network function 103, or the value representing the identity of other authenticated IoT devices 101.

[0377] In some embodiments, the third key is a key determined by the second network function 103 for each IoT device based on at least one first parameter, and may also be referred to as a verification key.

[0378] In one example, the third key may be a "third session key," which is not limited in this disclosure.

[0379] In some embodiments, the second network function 103 determines a second value and / or a third key corresponding to each IoT device based on at least one first parameter and using a first function.

[0380] The first parameter may include, but is not limited to, at least one of the following: a first random number; a second random number; a fourth key; a first identifier; and a group identifier. In one example, the second network function 103 may determine the third key corresponding to the IoT device in the same way that each IoT device 101 determines the first key. The specific determination method will not be elaborated here.

[0381] The second network function 103 can determine the second value and / or the third key in the following ways:

[0382] Method 1: Based on the first random number, the fourth key, and the first identifier, a first function is used to determine the second value and / or the third key.

[0383] Method 2: Based on the second random number, the fourth key, and the first identifier, a first function is used to determine the second value and / or the third key.

[0384] Method 3: Based on the first random number, the second random number, the fourth key, and the first identifier, a first function is used to determine the second value and / or the third key.

[0385] Method 4: Based on the first random number, the second random number, and the fourth key, a first function is used to determine the second value and / or the third key.

[0386] Method 5: Based on the first random number, the fourth key, and the group identifier, a first function is used to determine the second value and / or the third key.

[0387] Method 6: Based on the second random number, the fourth key, and the group identifier, a first function is used to determine the second value and / or the third key.

[0388] Method 7: Based on the first random number, the second random number, the fourth key, and the group identifier, a first function is used to determine the second value and / or the third key.

[0389] Method 8: Based on the first random number and the fourth key, a first function is used to determine the second value and / or the third key.

[0390] Method 9: Based on the second random number and the fourth key, the first function is used to determine the second value and / or the third key.

[0391] Method 10: Based on the third key and the inventory response sent by the received IoT device, a first function is used to determine the second value.

[0392] For example, if IoT device 101 uses method 2, based on a second random number, a fourth key (assuming it is the device root key), and a first identifier (the identifier of the IoT device), and uses a first function such as KDF to determine a first value and / or a first key, then the second network function also uses method 2, based on the second random number carried in the second request, the stored fourth key (device root key), and the first identifier (the identifier of the IoT device), and uses KDF to determine a third key corresponding to the IoT device.

[0393] For example, if IoT device 101 uses method 7, based on a first random number, a second random number, a fourth key (assuming it is the group root key), and a group identifier, and uses a first function such as the f2 function to determine a first value and / or a first key, then the second network function also uses method 7, based on the first and second random numbers carried in the second request, the stored fourth key (group root key), and the group identifier, and uses the f2 function to determine a second value and / or a third key corresponding to the IoT device.

[0394] For example, if IoT device 101 uses method 8, based on the first random number and the fourth key (device root key), and uses a first function such as the f1 function to determine the first value and / or the first key, then the second network function also uses method 8, based on the first random number carried in the second request and the stored fourth key (device root key), and uses the f1 function to determine the second value and / or the third key corresponding to the IoT device.

[0395] For example, if IoT device 101 uses method 10, based on the first key and the determined disk response sent, and uses a first function such as the f1 function to determine the first value, then the second network function also uses method 10, based on the disk response carried in the second request and the determined third key, and uses the f1 function to determine the second value corresponding to the IoT device.

[0396] The above is merely an illustrative example. The second network function 103 can determine the second value and / or the third key in the same way as the IoT device 101. This disclosure does not limit the specific determination methods adopted by the second network function 103 and the IoT device 101.

[0397] Step S2111, the second network function 103 determines the second IoT device 101-2.

[0398] In some embodiments, the second IoT device 101-2 is an IoT device that has successfully passed authentication from a group of IoT devices.

[0399] In some embodiments, the second network function 103 can identify an IoT device with the same second value as the first value as a second IoT device 101-2.

[0400] In some embodiments, the second network function 103 may verify the first value in the group of IoT devices based on the third key, and determine the IoT device corresponding to the verified first value as the second IoT device 101-2.

[0401] In one example, the third key is a key determined by the second network function 103 using the same determination method as the IoT device, and can therefore be used to verify the first value in the inventory response sent by the IoT device 101. The verification method can, for example but not limited to, use the same determination method as the IoT device (i.e., the method for determining the first value) to verify whether the received message originates from a genuine IoT device. If the first value can be determined, the verification is considered successful; otherwise, the verification is considered unsuccessful.

[0402] In some embodiments, the second network function 103 may first identify IoT devices in the group of IoT devices whose second value is the same as the first value as candidate IoT devices. Further, based on the first value of the candidate IoT device determined by the third key verification, if the verification is successful, the candidate IoT device is then identified as the second IoT device 101-2.

[0403] In some embodiments, the second network function 103 may first verify the first value of each IoT device based on the third key, and the verified IoT devices shall be used as candidate IoT devices. Then, the candidate IoT devices with the same second value as the first value shall be determined as the second IoT devices 101-2.

[0404] Of course, if a conflict occurs in the above process, for example, if a candidate IoT device in a group of IoT devices has the same second value as the first value but fails to verify the first value based on the third key, or if a candidate IoT device that passes the verification based on the third key has a second value that is different from the first value, then the second network function 103 can determine that the candidate IoT device cannot be the second IoT device 101-2, or the second network function 103 can re-determine the second value and / or the third key in order to determine the second IoT device 101-2 again.

[0405] The above is merely an illustrative example, and this disclosure does not limit the method by which the second network function 103 determines the second Internet of Things device 101-2.

[0406] In some embodiments, step S2111 is an optional execution step. For example, if the second IoT device 101-2 is determined by the first network function 102, step S2111 may not be executed.

[0407] In step S2112, the second IoT device 101-2 sends a second response to the first network function 102.

[0408] In some embodiments, the first IoT device 102-1 receives a second response.

[0409] In some embodiments, the second response is used to respond to the second request.

[0410] In some embodiments, the second response may include, but is not limited to, at least one of the following: a second value corresponding to each IoT device; a third key corresponding to each IoT device; and an identifier of the second IoT device.

[0411] The second value corresponding to each IoT device is the verification value obtained by authenticating each IoT device.

[0412] The second IoT device 101-2 is the IoT device that has successfully passed authentication among the group of IoT devices.

[0413] In some embodiments, the name of the second response is not limited and can be interchanged with "verification response", "authentication response", etc.

[0414] In step S2113, the first network function 102 determines the second IoT device 101-2.

[0415] In some embodiments, the second IoT device 101-2 is an IoT device that has successfully passed authentication from a group of IoT devices.

[0416] In some embodiments, the first network function 102 determines the second Internet of Things device 101-2 based on the second response.

[0417] In some embodiments, the second response includes a second value corresponding to each IoT device, and the first network function 102 identifies the IoT device in the group of IoT devices whose second value is the same as the first value as the second IoT device 101-2.

[0418] In some embodiments, the second response includes a third key corresponding to each IoT device, and the first network function 102 verifies the first value in the group of IoT devices based on the third key, and determines the IoT device corresponding to the verified first value as the second IoT device 101-2.

[0419] In one example, the third key is a key determined by the second network function 103 using the same determination method as the IoT device, and can therefore be used to verify the first value in the inventory response sent by the IoT device 101. The verification method can, for example but not limited to, use the same determination method as the IoT device (i.e., the method for determining the first value) to verify whether the received message originates from a genuine IoT device. If the first value can be determined, the verification is considered successful; otherwise, the verification is considered unsuccessful.

[0420] In some embodiments, the second response includes a second value corresponding to each IoT device and a third key corresponding to each IoT device. The first network function 102 may first determine a candidate IoT device in the group of IoT devices whose second value is the same as the first value. Further, it verifies the first value of the determined candidate IoT device based on the third key. If the verification is successful, the candidate IoT device is then determined as the second IoT device 101-2.

[0421] In some embodiments, the second response includes a second value corresponding to each IoT device and a third key corresponding to each IoT device. The first network function 102 may first verify the first value of each IoT device based on the third key, and the verified IoT devices shall be used as candidate IoT devices. Then, the candidate IoT devices with the same second value as the first value shall be determined as the second IoT devices 101-2.

[0422] Of course, if a conflict occurs in the above process, for example, if a candidate IoT device in a group of IoT devices has the same second value as the first value but fails to verify the first value based on the third key, the first network function 102 may not designate the candidate IoT device as the second IoT device. Alternatively, the first network function 102 may send a second request to the second network function 103 again to obtain a new second response, and based on the new second response, redetermine the second IoT device 101-2.

[0423] In some embodiments, the second response includes an identifier of the second IoT device, and the first network function 102 identifies the second IoT device 101-2 based on the identifier.

[0424] The above is merely an illustrative example, and this disclosure does not limit the scheme by which the first network function 102 determines the second Internet of Things device 101-2.

[0425] In step S2114, the first network function 102 sends at least one first command to the reader 104.

[0426] In some embodiments, the reader 104 receives at least one first command.

[0427] In some embodiments, each first command is used to control a second IoT device 101-2 to perform a first operation, the first operation including but not limited to write operation, read operation, turn-on operation, turn-off operation, and charging operation.

[0428] In one example, the second IoT device is one of the IoT devices in the group that has successfully been authenticated.

[0429] If the number of the second IoT devices is n, then the number of first commands can be less than or equal to n, where n is a non-negative integer. The number of first commands depends on whether control of the second IoT device 101-2 is required.

[0430] When n is 0, it means that there is no authenticated second IoT device in the group of IoT devices, or that no authenticated second IoT device should be controlled. In this case, the first network function 102 may not send any first command.

[0431] In one example, the second key corresponding to the second IoT device can be a key that securely protects the first command, thereby achieving secure isolation between IoT devices within the same group.

[0432] For example, the second key may be a second session key, which is not limited in this disclosure.

[0433] For example, using a second key to secure the first command can refer to encrypting the first command with the second key, or using the second key to calculate the key security verification information of the first command. Only IoT devices that can decrypt and / or successfully calculate the same security verification information can verify the first command.

[0434] The first network function 102 can send less than or equal to n first commands to the reader 104 at one time, or it can send less than or equal to n first commands in batches. This disclosure does not limit this.

[0435] In step S2115, the reader 104 sends at least one first command to at least one second IoT device 101-2.

[0436] In some embodiments, the second IoT device 101-2 receives the first command.

[0437] In some embodiments, the reader 104 can map the first command to a one-to-one correspondence with the previously stored IoT devices 101. That is, after the previous group inventory, the reader 104 can map each first command to an IoT device within that group.

[0438] In some embodiments, the second key corresponding to the second IoT device is a key used to securely protect the first command, so an unauthenticated IoT device will not receive the first command. Alternatively, even if an unauthenticated IoT device receives the first command, it will be unable to parse the content of the first command because the keys do not match.

[0439] In some embodiments, the second IoT device 101-2 performs a first operation based on a first command. For example, if the first command is used to control the IoT device to perform a shutdown operation, only the second IoT device 101-2 can perform the shutdown operation based on the first command, effectively preventing other IoT devices in the group from performing erroneous operations.

[0440] In step S2116, the first network function 102 sends a third response to the third network function 105.

[0441] In some embodiments, the third network function 105 receives a third response.

[0442] In some embodiments, a third response is used to respond to a third request.

[0443] In some embodiments, the third response may be used to indicate the result of the second IoT device executing the first command.

[0444] In some embodiments, after determining that the second IoT device has executed the first command, the first network function 102 sends a third response to the third network function 105.

[0445] In some embodiments, upon receiving a third request, the first network function 102 sends a third response to the third network function 105.

[0446] In some embodiments, the name of the third response is not limited and can be interchanged with "group inventory trigger response", "group command trigger response", etc.

[0447] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0448] In some embodiments, the terms “radio”, “wireless”, “radio access network (RAN)”, “access network (AN)”, and “RAN-based” can be used interchangeably.

[0449] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “bidirectional transmission,” and “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomous implementation, among other meanings.

[0450] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transfer,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.

[0451] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.

[0452] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2116. For example, step S2101 can be implemented as an independent embodiment, step S2102 can be implemented as an independent embodiment, step S2103 can be implemented as an independent embodiment, step S2102+S2103 can be implemented as an independent embodiment, step S2101+S2102+S2103 can be implemented as an independent embodiment, step S2104 can be implemented as an independent embodiment, step S2105 can be implemented as an independent embodiment, step S2104+S2105 can be implemented as an independent embodiment, step S2106 can be implemented as an independent embodiment, step S2107 can be implemented as an independent embodiment, step S2106+S2107 can be implemented as an independent embodiment, and step S2108 can be implemented as an independent embodiment. For example, steps S2106+S2107+S2108 can be implemented as independent embodiments, steps S2109 can be implemented as independent embodiments, steps S2110 can be implemented as independent embodiments, steps S2111 can be implemented as independent embodiments, steps S2112 can be implemented as independent embodiments, steps S2109+S2112 can be implemented as independent embodiments, steps S2109+S2111+S2112 can be implemented as independent embodiments, steps S2113 can be implemented as independent embodiments, steps S2114+S2115 can be implemented as independent embodiments, steps S2116 can be implemented as independent embodiments, and steps S2101+S2116 can be implemented as independent embodiments, but are not limited thereto.

[0453] In some embodiments, steps S2112 and S2113 may be performed in an alternate order or simultaneously.

[0454] In some embodiments, step S2111 is optional, and one or more of these steps may be omitted or substituted in different embodiments. For example, step S2111 may not be performed when the second IoT device 101-2 is determined by another device.

[0455] In some embodiments, step S2112 is optional, and one or more of these steps may be omitted or substituted in different embodiments. For example, if the second IoT device 101-2 is not present, step S2112 may not be performed.

[0456] In some embodiments, step S2114 is optional, and one or more of these steps may be omitted or substituted in different embodiments. For example, if it is not necessary to control any IoT device to perform the first operation, step S2114 may not be performed.

[0457] In some embodiments, steps S2101 to S2116 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0458] In some embodiments, the execution order of steps S2101 to S2116 is not limited.

[0459] In the above embodiments, secure isolation can be achieved between IoT devices belonging to the same group, thereby controlling a designated IoT device to perform a first operation through the key corresponding to the IoT device, which improves the availability and reliability of IoT technology, especially environmental IoT technology.

[0460] Figure 3A is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3A, this embodiment of the disclosure relates to a communication method, which is executed by a first Internet of Things device 101-1, and the method includes:

[0461] Step S3101: Obtain inventory request.

[0462] In some embodiments, the inventory request is used to request an inventory of a group of IoT devices, the group of IoT devices including at least the first IoT device.

[0463] In some embodiments, optional implementations of step S3101 can be found in optional implementations of step S2104 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0464] In some embodiments, the first IoT device 101-1 receives an inventory request sent by the reader 104, but is not limited thereto, and may also receive an inventory request sent by other entities.

[0465] In some embodiments, the first IoT device 101-1 obtains an inventory request as defined by the protocol.

[0466] In some embodiments, the first IoT device 101-1 obtains an inventory request from the upper layer(s).

[0467] In some embodiments, the first IoT device 101-1 processes the data to obtain an inventory request.

[0468] In some embodiments, step S3101 is omitted, and the first IoT device 101-1 autonomously implements the function indicated by the inventory request, or the above function is default or default.

[0469] Step S3102: Determine the first value and / or the first key.

[0470] In some embodiments, optional implementations of step S3102 can be found in optional implementations of step S2106 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0471] Step S3103: Send inventory response.

[0472] In some embodiments, the first IoT device 101-1 sends an inventory response to the reader 104.

[0473] In some embodiments, reader 104 receives a disk storage response.

[0474] In some embodiments, optional implementations of step S3103 can be found in optional implementations of step S2107 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0475] In some embodiments, steps S3101 to S3103 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0476] In some embodiments, the execution order of steps S3101 to S3103 is not limited.

[0477] In the above embodiments, secure isolation can be achieved between IoT devices belonging to the same group, thereby controlling a designated IoT device to perform a first operation through the key corresponding to the IoT device, which improves the availability and reliability of IoT technology, especially environmental IoT technology.

[0478] Figure 3B is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3B, the present disclosure relates to a communication method, which is executed by a first network function 102-1, and includes:

[0479] Step S3201: Send the first request.

[0480] In some embodiments, the first network function 102 sends a first request to the reader 104.

[0481] In some embodiments, reader 104 receives a first request.

[0482] In some embodiments, optional implementations of step S3201 can be found in optional implementations of step S2106 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0483] Step S3202: Obtain the first response.

[0484] In some embodiments, optional implementations of step S3202 can be found in optional implementations of step S2107 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0485] In some embodiments, the first network function 102 receives a first response sent by the reader 104, but is not limited thereto, and may also receive a first response sent by other entities.

[0486] In some embodiments, the first network function 102 obtains a first response as defined by the protocol.

[0487] In some embodiments, the first network function 102 obtains a first response from the upper layer(s).

[0488] In some embodiments, the first network function 102 processes the data to obtain a first response.

[0489] In some embodiments, step S3202 is omitted, and the first network function 102 autonomously implements the function indicated by the first response, or the above function is defaulted or set to default.

[0490] In some embodiments, steps S3201 to S3202 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0491] In some embodiments, the execution order of steps S3201 to S3202 is not limited.

[0492] In the above embodiments, the first network function can at least obtain the first value corresponding to each IoT device in the group in order to authenticate each IoT device, thereby improving the feasibility of group authentication.

[0493] Figure 3C is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3C, the present disclosure relates to a communication method, which is executed by a second network function 102-2, and includes:

[0494] Step S3301: Obtain the second request.

[0495] In some embodiments, optional implementations of step S3301 can be found in optional implementations of step S2107 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0496] In some embodiments, the second network function 103 receives a second request sent by the first network function 102, but is not limited thereto, and may also receive a second request sent by other entities.

[0497] In some embodiments, the second network function 103 obtains a second request as defined by the protocol.

[0498] In some embodiments, the second network function 103 obtains a second request from the upper layer(s).

[0499] In some embodiments, the second network function 103 processes the request to obtain the second request.

[0500] In some embodiments, step S3301 is omitted, and the second network function 103 autonomously implements the function indicated by the second request, or the above function is defaulted or set to default.

[0501] Step S3302: Send the second response.

[0502] In some embodiments, the second IoT device 101-2 sends a second response to the first network function 102.

[0503] In some embodiments, the first IoT device 102-1 receives a second response.

[0504] In some embodiments, optional implementations of step S3302 can be found in optional implementations of step S2112 in FIG2 and other related parts in the embodiments involved in FIG2, which will not be repeated here.

[0505] In some embodiments, steps S3301 to S3302 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0506] In some embodiments, the execution order of steps S3301 to S3302 is not limited.

[0507] In the above embodiments, the second network function can send a second response to the first network function based on the second request, thereby achieving the purpose of identity authentication for the same group of IoT devices, and has high availability.

[0508] The above process is further illustrated with examples below.

[0509] Assumption:

[0510] This device (i.e., the IoT device) stores a device root key and a group root key in the NVM. The device root key is used for single-device authentication. The group root key is used for group authentication.

[0511] - The UDM / UDR / third-party authentication server stores the device ID, device root key, group root key, and group ID. The data structure is shown in Table 1 or Table 2, for example.

[0512] For example, as shown in Figure 4A, the communication method includes the following steps:

[0513] In step S4101, the NF or AF sends a service request to the AIoT or AMF via the NEF. The service request includes a group identifier (ID) and / or area information used to trigger group inventory / group commands.

[0514] In step S4102, AIoTF or AMF selects a reader based on the group ID and / or area information.

[0515] In step S4103, the AIoTF or AMF determines a random number and sends a service request to the selected reader. If the inventory is for a group of devices, the AIoTF or AMF provides the reader with a group ID. If the inventory is for all devices in the area, no group ID is provided to the reader. The service request may include the group ID and the random number.

[0516] In step S4104, the reader sends a disk storage request, which may include a group ID and a random number.

[0517] In step S4105, devices #1 and #2 perform a process similar to random access to establish a connection with the reader.

[0518] In step S4106, devices #1 and #2 derive their keys and MAC addresses based on the random number, the group root key, and the device ID. Devices #1 and #2 then send the group ID, device ID, and the calculated RES to the reader.

[0519] In this regard, considering that each device has a unique device ID, the exported key is unique for each device.

[0520] If the device ID is not included in the disk storage request, the device considers this disk storage to be for group disk storage and uses the stored group root key to determine the key and RES.

[0521] In step S4107, the reader can aggregate all inventory responses and provide them to AIoTF or AMF.

[0522] In step S4108, assuming the device ID and group ID contain domain information for routing, the AIoTF or AMF can select a UDM, UDR, or third-party authentication server that stores the corresponding security information based on the device ID or group ID. The AIoTF or AMF sends an authentication request to the selected UDM, UDR, or third-party authentication server. The authentication request includes a random number determined by the AIoTF or AMF in step S4103, one or more device IDs, and the associated RES and group ID (optional).

[0523] In step S4109, the UDM, UDR, or third-party authentication server retrieves the relevant security material and calculates the XRES for each device. The method for determining the XRES is the same as the method for determining the RES on the device side. The UDM, UDR, or third-party authentication server returns one or more device IDs and the associated XRES.

[0524] Alternatively, UDM, UDR, or a third-party authentication server will compare the RES and XRES for each device. The authentication request only includes the authentication result, such as the device ID being successfully authenticated.

[0525] In step S4110, if a device ID and associated XRES are returned from the UDM, UDR, or a third-party authentication server, the AIoTF or AMF compares the RES and XRES for each device. For devices that have successfully authenticated, the AIoTF or AMF can initiate a command procedure.

[0526] In step S4111, AIoTF or AMF returns a service response to AF or NF.

[0527] Among them, the key derivation function:

[0528] The following parameters are used to form the input S of the KDF.

[0529] -FC = 0xaa,

[0530] -P0 = random number,

[0531] -L0 = the length of the random number (i.e., 0x00 0x10),

[0532] -P1 = Device ID,

[0533] -L1 = the length of the device ID (i.e., 0x00 0x10),

[0534] The input key should be equal to the group root key.

[0535] RES / XRES = f2 K (RAND), where RAND is a random number sent by AIoT or AMF, and K is the group root key. F2 is the message authentication function.

[0536] Alternatively, RES or XRES can be determined by KDF or other functions, as shown in Figure 4B, where the function can be selected by AIoT or AMF.

[0537] For example, suppose:

[0538] This device stores only one device root key in NVM. The device root key is used for single device authentication and group authentication.

[0539] - The UDM, UDR, or third-party authentication server stores the device ID, device root key, and group ID. The data structure is shown in Table 2.

[0540] Devices and authentication functions in the network determine keys using the device root key, group ID, and random number.

[0541] Key derivation function 1:

[0542] The following parameters are used to form the input S of the KDF.

[0543] -FC = 0xaa,

[0544] -P0 = random number,

[0545] -L0 = the length of the random number (i.e., 0x00 0x10),

[0546] -P1 = Group ID,

[0547] -L1 = the length of the group ID (i.e., 0x00 0x10),

[0548] The input key should be equal to the device root key.

[0549] Key derivation function 2:

[0550] The following parameters are used to form the input S of the KDF.

[0551] -FC = 0xbb,

[0552] -P0 = random number,

[0553] -L0 = the length of the random number (i.e., 0x00 0x10),

[0554] -P1 = Device ID,

[0555] -L1 = the length of the device ID (i.e., 0x00 0x10),

[0556] The input key should be equal to the device root key.

[0557] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.

[0558] This disclosure also proposes an apparatus (also referred to as a communication device) for implementing any of the above methods. For example, an apparatus is proposed that includes units or modules for implementing the steps performed by the first Internet of Things (IoT) device (e.g., an environmental IoT device) in any of the above methods. Furthermore, another apparatus is proposed that includes units or modules for implementing the steps performed by network functions (e.g., a first network function, a second network function, etc.) in any of the above methods.

[0559] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0560] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0561] Figure 5A is a schematic diagram of the structure of a first Internet of Things (IoT) device according to an embodiment of this disclosure. As shown in Figure 5A, the first IoT device 5100 may include at least one of a transceiver module 5101 and a processing module 5102.

[0562] In some embodiments, the transceiver module 5101 is configured to receive a storage request sent by the reader; wherein the storage request is configured to request storage of a group of IoT devices, the group of IoT devices including at least the first IoT device; and to send a storage response to the reader; wherein the storage response includes at least a first value corresponding to the first IoT device.

[0563] In some embodiments, the processing module 5102 is used to determine at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device based on the inventory request; wherein the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key.

[0564] Optionally, the transceiver module 5101 is used to perform at least one of the communication steps such as sending and / or receiving performed by the first IoT device 5100 in any of the above methods (e.g., steps S2104, S2107, S2105, S2106, S2201, S2203, S2204, S2206, but not limited thereto), which will not be elaborated here.

[0565] Optionally, the processing module 5102 is used to execute at least one of the other steps (such as step S2105, step S2106, step S2115, but not limited thereto) executed by the first IoT device 5100 in any of the above methods, which will not be described in detail here.

[0566] Figure 5B is a schematic diagram of the structure of the first network function proposed in an embodiment of this disclosure. As shown in Figure 5B, the first network function 5200 may include: a transceiver module 5201.

[0567] In some embodiments, the transceiver module 5201 is configured to send a first request to the reader; wherein the first request is configured to request the reader to broadcast an inventory request, the inventory request being configured to perform an inventory check on a group of IoT devices; wherein the inventory request is configured for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key; and to receive a first response sent by the reader based on the inventory check response sent by each IoT device; wherein the first response includes at least the first value corresponding to each IoT device in the group of IoT devices, the first value corresponding to each IoT device being used to verify the identity of each IoT device.

[0568] Optionally, the transceiver module 5201 is used to perform at least one of the communication steps such as sending and / or receiving performed by the first network function 5200 in any of the above methods (e.g., steps S2101, S2108, S2109, S2112, S2114, S2116, but not limited thereto), which will not be elaborated here.

[0569] Figure 5C is a schematic diagram of the structure of the second network function proposed in an embodiment of this disclosure. As shown in Figure 5C, the second network function 5300 may include: a transceiver module 5301.

[0570] In some embodiments, the transceiver module 5301 is configured to receive a second request sent by a first network function based on a first response; wherein the first response is configured to respond to a first request sent by the first network function to the reader, the first request being configured to request triggering the reader to broadcast an inventory request, the inventory request being configured to perform an inventory on a group of IoT devices; wherein the inventory request is configured for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key; wherein the second request is configured to request verification of the identity of each IoT device in the group of IoT devices; and based on the second request, a second response is sent to the first network function.

[0571] Optionally, the transceiver module 5301 is used to perform at least one of the communication steps (such as step S2109, step S2112, but not limited thereto) performed by the second network function 5300 in any of the above methods, which will not be described in detail here.

[0572] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, which may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver.

[0573] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.

[0574] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.

[0575] Figure 6A is a schematic diagram of the structure of the communication device 6100 proposed in an embodiment of this disclosure. The communication device 6100 may be an Internet of Things (IoT) device or network function (e.g., a first network function, a second network function, etc.), or it may be a chip, chip system, or processor that supports IoT devices or network functions in implementing any of the above methods. The communication device 6100 can be used to implement the methods described in the above method embodiments, and for details, please refer to the description in the above method embodiments.

[0576] As shown in Figure 6A, the communication device 6100 includes one or more processors 6101. The processor 6101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control the communication device (e.g., base station, baseband chip, DU or CU, etc.), execute programs, and process program data. Optionally, the communication device 6100 can be used to execute any of the above methods. Optionally, one or more processors 6101 can be used to invoke instructions to cause the communication device 6100 to execute any of the above methods.

[0577] In some embodiments, the communication device 6100 further includes one or more transceivers 6102. When the communication device 6100 includes one or more transceivers 6102, the transceivers 6102 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2103, S2104, S2107, S2108, S2109, S2112, S2114, S2115, S2116, but not limited thereto), and the processor 6101 performs at least one of other steps (e.g., steps S2102, S2105, S2106, S2110, S2111, S2113, but not limited thereto). In optional embodiments, the transceivers may include a receiver and / or a transmitter, which may be separate or integrated together. Optionally, terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be used interchangeably; terms such as transmitter, transmitting unit, transmitter, and transmitting circuit can be used interchangeably; and terms such as receiver, receiving unit, receiver, and receiving circuit can be used interchangeably.

[0578] In some embodiments, the communication device 6100 further includes one or more memories 6103 for storing data. Optionally, all or part of the memories 6103 may be located outside the communication device 6100. In optional embodiments, the communication device 6100 may include one or more interface circuits 6104. Optionally, the interface circuits 6104 are connected to the memories 6102 and can be used to receive data from the memories 6102 or other devices, and to send data to the memories 6102 or other devices. For example, the interface circuits 6104 can read data stored in the memories 6102 and send the data to the processor 6101.

[0579] The communication device 6100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 6100 described in this disclosure is not limited thereto, and the structure of the communication device 6100 may not be limited by FIG. 6A. The communication device may be a standalone device or a part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0580] Figure 6B is a schematic diagram of the structure of chip 6200 according to an embodiment of this disclosure. For cases where the communication device 6100 can be a chip or a chip system, please refer to the schematic diagram of chip 6200 shown in Figure 6B, but it is not limited thereto.

[0581] Chip 6200 includes one or more processors 6201. Chip 6200 is used to perform any of the methods described above.

[0582] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data. Optionally, all or part of the memories 6203 may be located outside chip 6200. Optionally, interface circuit 6202 is connected to memory 6203, and interface circuit 6202 can be used to receive data from memory 6203 or other devices, and interface circuit 6202 can be used to send data to memory 6203 or other devices. For example, interface circuit 6202 can read data stored in memory 6203 and send the data to processor 6201.

[0583] In some embodiments, the interface circuit 6202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2103, S2104, S2107, S2108, S2109, S2112, S2114, S2115, S2116, but not limited thereto). The interface circuit 7202 performing the communication steps such as sending and / or receiving in the above method refers, for example, to the interface circuit 7202 performing data interaction between the processor 7201, the chip 7200, the memory 7203, or the transceiver device. In some embodiments, the processor 7201 performs at least one of other steps (e.g., steps S2102, S2105, S2106, S2110, S2111, S2113, but not limited thereto).

[0584] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0585] This disclosure also proposes a communication device, which can be an Internet of Things (IoT) device. When the communication device is an IoT device, it can be used to execute any of the methods described above performed on the IoT device side. The communication device may include, but is not limited to, at least one of the following:

[0586] This disclosure also proposes a communication device that can function as a network function. When the communication device functions as a network function, it can be used to execute any of the methods described above by the first network function side or the second network function side. The communication device can be a single device including at least one of the core network elements, or it can be multiple core network devices or a group of devices, each corresponding to a different core network element. For example, the core network element can be at least one of AMF, AIoTF, UDM, and UDR. The communication device can execute any of the methods described above for the network function side provided in this disclosure, based on implementing the functions of at least one of the core network elements.

[0587] This disclosure also proposes a communication device, which can be a network device. When the communication device is a network device, it can perform any of the methods described above performed by the network function side. The communication device may include, but is not limited to, at least one of access network devices and core network devices.

[0588] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 6100, cause the communication device 6100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0589] This disclosure also provides a program product that, when executed by the communication device 6100, causes the communication device 6100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0590] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

[0591] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A communication method, characterized in that, The method is performed by a first Internet of Things (IoT) device, and the method includes: Receive a readout request sent by the reader; wherein the readout request is used to request a readout of a group of IoT devices, the group of IoT devices including at least the first IoT device; Based on the inventory request, at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device is determined; wherein, the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key; Send an inventory response to the reader; wherein the inventory response includes at least a first value corresponding to the first IoT device.

2. The method according to claim 1, characterized in that, The inventory request includes at least one of the following: Group identifier; wherein, the group identifier is the identifier of the group of IoT devices; A first random number; wherein the first random number is determined by a first network function.

3. The method according to claim 1 or 2, characterized in that, The method further includes at least one of the following: The inventory request does not include a first identifier, indicating that the inventory request is used to request an inventory of the group of IoT devices; wherein, the first identifier is the identifier of the first IoT device; The inventory request includes a group identifier, which indicates that the inventory request is used to request an inventory of the group of IoT devices; wherein, the group identifier is the identifier of the group of IoT devices.

4. The method according to any one of claims 1-3, characterized in that, Determining at least one of the first value corresponding to the first IoT device and the first key corresponding to the first IoT device includes: Based on at least one first parameter, at least one of the first value and the first key is determined; wherein, the at least one first parameter includes at least one of the following: A first random number; wherein the first random number is determined by a first network function; A second random number; wherein the second random number is determined by the first IoT device; A fourth key; wherein the fourth key is a key stored on the first IoT device; First identifier; wherein, the first identifier is the identifier of the first IoT device; Group identifier; wherein the group identifier is the identifier of the group of IoT devices.

5. The method according to any one of claims 1-4, characterized in that, The inventory response also includes at least one of the following: First identifier; wherein, the first identifier is the identifier of the first IoT device; Group identifier; wherein, the group identifier is the identifier of the group of IoT devices; The second random number is determined by the first IoT device.

6. A communication method, characterized in that, The method is performed by a first network function, and the method includes: Send a first request to the reader; wherein the first request is used to request the reader to broadcast an inventory request, the inventory request is used to perform an inventory to a group of IoT devices; wherein the inventory request is used for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key; The reader receives a first response based on the inventory response sent by each IoT device; wherein the first response includes at least a first value corresponding to each IoT device in the group of IoT devices, and the first value corresponding to each IoT device is used to verify the identity of each IoT device.

7. The method according to claim 6, characterized in that, The first request includes at least one of the following: Group identifier; wherein, the group identifier is the identifier of the group of IoT devices; A first random number; wherein the first random number is determined by the first network function.

8. The method according to claim 6 or 7, characterized in that, The first response also includes at least one of the following: The identifier of each IoT device; Group identifier; wherein, the group identifier is the identifier of the group of IoT devices; The second random number determined for each IoT device.

9. The method according to any one of claims 6-8, characterized in that, The method further includes: Based on the first response, a second request is sent to the second network function; wherein the second request is used to request verification of the identity of each IoT device in the group of IoT devices; Receive the second response sent by the second network function; Based on the second response, at least one first command is sent to the reader; wherein each first command is used to control a second IoT device to perform a first operation, the second IoT device is an IoT device that has successfully passed authentication in the group of IoT devices, the second key corresponding to the second IoT device is a key for security protection of the first command, and each IoT device in the group of IoT devices corresponds to a different key.

10. The method according to claim 9, characterized in that, The second request includes at least one of the following: A first random number; wherein the first random number is determined by the first network function; The second random number determined for each IoT device; The identifier of each IoT device; The first value corresponding to each IoT device; Group identifier; wherein the group identifier is the identifier of the group of IoT devices.

11. The method according to claim 9 or 10, characterized in that, The second response includes at least one of the following: The second value corresponding to each IoT device; wherein, the second value corresponding to each IoT device is a verification value obtained by authenticating each IoT device; The third key corresponding to each IoT device; The identifier of the second IoT device; wherein the second IoT device is the IoT device that has successfully passed authentication in the group of IoT devices.

12. The method according to claim 11, characterized in that, The method further includes at least one of the following: The second response includes a second value corresponding to each IoT device, and the IoT device in the group of IoT devices whose second value is the same as the first value is identified as the second IoT device; The second response includes a third key corresponding to each IoT device. Based on the third key, the first value in the group of IoT devices is verified, and the IoT device corresponding to the verified first value is determined as the second IoT device.

13. A communication method, characterized in that, The method is executed by a second network function, and the method includes: The system receives a second request sent by a first network function based on a first response; wherein the first response is used to respond to a first request sent by the first network function to the reader, the first request being used to request triggering the reader to broadcast an inventory request, the inventory request being used to perform an inventory on a group of IoT devices; wherein the inventory request is used for each IoT device in the group of IoT devices to determine at least one of a first value corresponding to each IoT device and a first key corresponding to each IoT device, wherein each IoT device in the group of IoT devices corresponds to a different key; wherein the second request is used to request verification of the identity of each IoT device in the group of IoT devices; Based on the second request, a second response is sent to the first network function.

14. The method according to claim 13, characterized in that, The second request includes at least one of the following: A first random number; wherein the first random number is determined by the first network function; The second random number determined for each IoT device; The identifier of each IoT device; The first value corresponding to each IoT device; wherein, the first value corresponding to each IoT device is used to verify the identity of each IoT device; Group identifier; wherein the group identifier is the identifier of the group of IoT devices.

15. The method according to claim 14, characterized in that, The method further includes: Based on the second request, at least one of a second value corresponding to each IoT device and a third key corresponding to each IoT device is determined; wherein, the second value is a verification value obtained by authenticating each IoT device.

16. The method according to claim 15, characterized in that, The step of determining at least one of the second value corresponding to each IoT device and the third key corresponding to each IoT device based on the second request includes: Based on at least one first parameter, at least one of a second value corresponding to each IoT device and a third key corresponding to each IoT device is determined; wherein, the at least one first parameter includes at least one of the following: A first random number; wherein the first random number is determined by a first network function; A second random number; wherein the second random number is determined by the first IoT device; The fourth key; wherein the fourth key is a key stored on the first IoT device; First identifier; wherein, the first identifier is the identifier of the first Internet of Things device; Group identifier; wherein the group identifier is the identifier of the group of IoT devices.

17. The method according to claim 15 or 16, characterized in that, The method further includes at least one of the following: IoT devices whose second value is the same as the first value are identified as the second IoT devices; Based on the third key, the first value in the group of IoT devices is verified, and the IoT device corresponding to the verified first value is determined as the second IoT device. The second IoT device is the IoT device that has successfully passed authentication among the group of IoT devices.

18. The method according to any one of claims 13-16, characterized in that, The second response includes at least one of the following: The second value corresponding to each IoT device; wherein, the second value corresponding to each IoT device is a verification value obtained by authenticating each IoT device; The third key corresponding to each IoT device; The identifier of the second IoT device; wherein the second IoT device is the IoT device that has successfully passed authentication in the group of IoT devices.

19. A communication method, characterized in that, The method includes: The first network function sends a first request to the reader; wherein the first request is used to request triggering a broadcast inventory request, the inventory request is used to inventory a group of IoT devices, the group of IoT devices including at least the first IoT device; The reader broadcasts the disk storage request; Based on the received inventory request, the first IoT device determines at least one of a first value corresponding to the first IoT device and a first key corresponding to the first IoT device; wherein, the first value corresponding to the first IoT device is used to verify the identity of the first IoT device, and each IoT device in the group of IoT devices corresponds to a different key; The first IoT device sends an inventory response to the reader; wherein the inventory response includes at least a first value corresponding to the first IoT device; The reader sends a first response to the first network function; wherein the first response includes at least a first value corresponding to each of the group of IoT devices; Based on the first response, the first network function sends a second request to the second network function; wherein the second request is used to request verification of the identity of each IoT device in a group of IoT devices; The second network function sends a second response to the first network function based on the second request.

20. A communication device, characterized in that, The communication device is used to perform the communication method according to any one of claims 1-5, 6-12 or 13-18.

21. A communication system, characterized in that, The device includes a first Internet of Things (IoT) device, a first network function, and a second network function, wherein the first IoT device is configured to implement the communication method of any one of claims 1-5, the first network function is configured to implement the communication method of any one of claims 6-12, and the second network function is configured to implement the communication method of any one of claims 13-18.

22. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, it causes the communication device to perform the communication method as described in any one of claims 1-5, 6-12, or 13-18.

23. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program is used to implement the communication method according to any one of claims 1-5, 6-12, or 13-18.