Wireless communication method and apparatus, and device and readable storage medium

WO2026200995A1PCT designated stage Publication Date: 2026-10-01VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/085975
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-03-25
Publication Date
2026-10-01

Smart Images

  • Figure CN2026085975_01102026_PF_FP_ABST
    Figure CN2026085975_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the field of communications. Disclosed are a wireless communication method and apparatus, and a device and a readable storage medium. The method in the embodiments of the present application comprises: a first device receiving target challenge information, or receiving the target challenge information and third identification information, wherein the target challenge information comprises first challenge information, or comprises the first challenge information and second challenge information; sending a first message to a first communication node, wherein the first message comprises first identification information and first authentication information, the first identification information being generated on the basis of a shared key and first information, or the first identification information being the third identification information, and the first authentication information being generated on the basis of the shared key and second information. The first information comprises at least one of the following: first key generation information, which is used for generating a first key; and an identifier generation parameter, which is used for generating the first identification information; and the second information comprises at least one of the following: second key generation information, which is used for generating a second key; and an authentication information generation parameter, which is used for generating the first authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

Wireless communication methods, apparatus, devices and readable storage media

[0001] Cross-references to related applications

[0002] This application claims priority to Chinese Patent Application No. 202510385174.2, filed on March 28, 2025, entitled "Wireless Communication Method, Apparatus, Device and Readable Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application belongs to the field of communication technology, specifically relating to a wireless communication method, apparatus, device, and readable storage medium. Background Technology

[0004] In related technologies, communication nodes in a network housing AIoT devices can generate temporary identifiers and authentication information for AIoT devices based on a shared key and random numbers. The temporary identifier is used to identify the AIoT device, and its authentication information is used to authenticate it. However, since the temporary identifier and authentication information are generated using the same key and random numbers, there is a potential correlation between them. This could lead to the possibility of inferring the other information from one, posing a security risk. Summary of the Invention

[0005] This application provides a wireless communication method, apparatus, device, and readable storage medium that can reduce security risks associated with device identification and security authentication.

[0006] In a first aspect, a wireless communication method is provided, the method comprising:

[0007] The first device receives target challenge information from the network, or the first device receives target challenge information and third identification information from the network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0008] The first device sends a first message to the first communication node. The first message includes first identification information and first authentication information. The first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device.

[0009] Wherein, the first identification information is generated by the first device based on the shared key and the first information between the first device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the first device based on the shared key and the second information;

[0010] Wherein, the network is the network where the first communication node is located;

[0011] The first information includes at least one of the following:

[0012] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0013] Identifier generation parameters are used to generate the first identifier information;

[0014] The second information includes at least one of the following:

[0015] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0016] The authentication information generation parameters are used to generate the first authentication information.

[0017] Secondly, a wireless communication method is provided, the method comprising:

[0018] The first device receives the first challenge information from the network;

[0019] The first device sends a second message to the first communication node, the second message including third information; the third information is used by the first communication node to identify and authenticate the first device.

[0020] The third information includes any one of the following:

[0021] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0022] The first identification information is generated based on the shared key between the first device and the first communication node and the second information.

[0023] Wherein, the network is the network where the first communication node is located;

[0024] The first information includes at least one of the following:

[0025] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0026] Identifier generation parameters are used to generate the first identifier information;

[0027] The second information includes at least one of the following:

[0028] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0029] The authentication information generation parameters are used to generate the first authentication information.

[0030] Thirdly, a wireless communication method is provided, the method comprising:

[0031] The first communication node sends target challenge information, or the first communication node sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0032] The first communication node receives a first message from the first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device;

[0033] The first communication node identifies the first device based on the first identification information, or identifies the first device based on the first identification information and verifies the first authentication information based on the second authentication information associated with the first device;

[0034] The third identification information is generated based on the shared key between the first device and the first communication node and the first information, and the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following:

[0035] First key generation information is used to generate a first key, and the first key is used to generate the third identification information;

[0036] Identifier generation parameters are used to generate the third identifier information;

[0037] The second information includes at least one of the following:

[0038] Second key generation information, used to generate a second key, the second key being used to generate the second authentication information;

[0039] The authentication information generation parameters are used to generate the second authentication information.

[0040] Fourthly, a wireless communication method is provided, the method comprising:

[0041] The first communication node sends the first challenge information;

[0042] The first communication node receives a second message from the first device, the second message including third information;

[0043] The first communication node identifies and authenticates the first device based on the third information;

[0044] The third information includes any one of the following:

[0045] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0046] The first identification information is generated based on the shared key between the first device and the first communication node and the second information.

[0047] The first information includes at least one of the following:

[0048] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0049] Identifier generation parameters are used to generate the first identifier information;

[0050] The second information includes at least one of the following:

[0051] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0052] The authentication information generation parameters are used to generate the first authentication information.

[0053] Fifthly, a communication device is provided, comprising:

[0054] A receiving module is configured to receive target challenge information from a network, or receive target challenge information and third identification information from a network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0055] The sending module is used to send a first message to a first communication node. The first message includes first identification information and first authentication information. The first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device.

[0056] Wherein, the first identification information is generated by the first device based on the shared key and the first information between the first device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the first device based on the shared key and the second information;

[0057] Wherein, the network is the network where the first communication node is located;

[0058] The first information includes at least one of the following:

[0059] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0060] Identifier generation parameters are used to generate the first identifier information;

[0061] The second information includes at least one of the following:

[0062] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0063] The authentication information generation parameters are used to generate the first authentication information.

[0064] Sixthly, a communication device is provided, comprising:

[0065] The receiving module is used to receive the first challenge information from the network;

[0066] A sending module is used to send a second message to a first communication node, the second message including third information; the third information is used by the first communication node to identify and authenticate the first device.

[0067] The third information includes any one of the following:

[0068] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0069] The first identification information is generated based on the shared key between the first device and the first communication node and the second information.

[0070] Wherein, the network is the network where the first communication node is located;

[0071] The first information includes at least one of the following:

[0072] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0073] Identifier generation parameters are used to generate the first identifier information;

[0074] The second information includes at least one of the following:

[0075] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0076] The authentication information generation parameters are used to generate the first authentication information.

[0077] In a seventh aspect, a communication device is provided, comprising:

[0078] A sending module is used to send target challenge information, or a first communication node sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0079] A receiving module is configured to receive a first message from a first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device.

[0080] The processing module is configured to identify the first device based on the first identification information, or to identify the first device based on the first identification information and verify the first authentication information based on the second authentication information associated with the first device;

[0081] The third identification information is generated based on the shared key between the first device and the first communication node and the first information, and the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following:

[0082] First key generation information is used to generate a first key, and the first key is used to generate the third identification information;

[0083] Identifier generation parameters are used to generate the third identifier information;

[0084] The second information includes at least one of the following:

[0085] Second key generation information, used to generate a second key, the second key being used to generate the second authentication information;

[0086] The authentication information generation parameters are used to generate the second authentication information.

[0087] Eighthly, a communication device is provided, comprising:

[0088] The sending module is used to send the first challenge information;

[0089] A receiving module is configured to receive a second message from a first device, the second message including third information;

[0090] The processing module is used to identify and authenticate the first device based on the third information;

[0091] The third information includes any one of the following:

[0092] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0093] The first identification information is generated based on the shared key between the first device and the first communication node and the second information.

[0094] The first information includes at least one of the following:

[0095] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0096] Identifier generation parameters are used to generate the first identifier information;

[0097] The second information includes at least one of the following:

[0098] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0099] The authentication information generation parameters are used to generate the first authentication information.

[0100] A ninth aspect provides a communication device configured to perform the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect, or implement the steps of the method described in the third aspect, or implement the steps of the method described in the fourth aspect.

[0101] In a tenth aspect, a communication device is provided, the communication device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first, second, third, or fourth aspect.

[0102] Eleventhly, a communication device is provided, including a processor and a communication interface. The communication interface is used to receive target challenge information from a network, or to receive target challenge information and third identification information from a network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; and to send a first message to a first communication node, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the communication device, and the first authentication information is used by the first communication node to authenticate the communication device.

[0103] Wherein, the first identification information is generated by the communication device based on the shared key and the first information between the communication device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the communication device based on the shared key and the second information;

[0104] Wherein, the network is the network where the first communication node is located;

[0105] The first information includes at least one of the following:

[0106] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0107] Identifier generation parameters are used to generate the first identifier information;

[0108] The second information includes at least one of the following:

[0109] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0110] The authentication information generation parameters are used to generate the first authentication information.

[0111] In a twelfth aspect, a communication device is provided, including a processor and a communication interface, the communication interface being used to receive first challenge information from a network; and to send a second message to a first communication node, the second message including third information; the third information being used by the first communication node to identify and authenticate the communication device.

[0112] The third information includes any one of the following:

[0113] The first authentication information is generated based on the shared key between the communication device and the first communication node and the first information.

[0114] The first identification information is generated based on the shared key between the communication device and the first communication node and the second information.

[0115] Wherein, the network is the network where the first communication node is located;

[0116] The first information includes at least one of the following:

[0117] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0118] Identifier generation parameters are used to generate the first identifier information;

[0119] The second information includes at least one of the following:

[0120] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0121] The authentication information generation parameters are used to generate the first authentication information.

[0122] In a thirteenth aspect, a communication device is provided, including a processor and a communication interface, wherein the communication interface is used to send target challenge information, or the communication device sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; and to receive a first message from a first device, the first message including first identification information and first authentication information; the first identification information is used by the communication device to identify the first device, and the first authentication information is used by the communication device to authenticate the first device;

[0123] The processor is configured to identify the first device based on the first identification information, or to identify the first device based on the first identification information and verify the first authentication information based on the second authentication information associated with the first device;

[0124] Wherein, the third identification information is generated based on the shared key between the first device and the communication device and the first information, and the second authentication information is generated based on the shared key and the second information; wherein, the first information includes at least one of the following:

[0125] First key generation information is used to generate a first key, and the first key is used to generate the third identification information;

[0126] Identifier generation parameters are used to generate the third identifier information;

[0127] The second information includes at least one of the following:

[0128] Second key generation information, used to generate a second key, the second key being used to generate the second authentication information;

[0129] The authentication information generation parameters are used to generate the second authentication information.

[0130] In a fourteenth aspect, a communication device is provided, including a processor and a communication interface, wherein the communication interface is used to send first challenge information; and to receive a second message from a first device, the second message including third information;

[0131] The processor identifies and authenticates the first device based on the third information;

[0132] The third information includes any one of the following:

[0133] The first authentication information is generated based on the shared key between the first device and the communication device and the first information.

[0134] The first identification information is generated based on the shared key between the first device and the communication device and the second information.

[0135] The first information includes at least one of the following:

[0136] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0137] Identifier generation parameters are used to generate the first identifier information;

[0138] The second information includes at least one of the following:

[0139] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0140] The authentication information generation parameters are used to generate the first authentication information.

[0141] In a fifteenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0142] In a sixteenth aspect, a wireless communication system is provided, comprising: a terminal and a network-side device, wherein the terminal is configured to perform steps of the method as described in the first or second aspect, and the network-side device is configured to perform steps of the method as described in the third or fourth aspect.

[0143] In a seventeenth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect, or the steps of the method as described in the fourth aspect.

[0144] In an eighteenth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the wireless communication method as described in any one of the first to fourth aspects.

[0145] In this embodiment, the temporary identifier of the first device used for ID identification and the authentication information used for device verification are generated based on different information. This avoids the problem of security degradation caused by potential correlation between the generated temporary identifier and authentication information, and enables secure isolation between ID identification and device authentication, thereby reducing exposed security risks. Attached Figure Description

[0146] Figure 1 is a schematic diagram of a communication system architecture provided in an embodiment of this application.

[0147] Figure 2 is a schematic diagram of the inventory process of AIoT devices in related technologies.

[0148] Figure 3 is a schematic diagram of a wireless communication method provided in an embodiment of this application.

[0149] Figure 4 is a schematic diagram of an inventory process provided in an embodiment of this application.

[0150] Figure 5 is a schematic diagram of another wireless communication method provided in an embodiment of this application.

[0151] Figure 6 is a schematic diagram of an inventory process provided in an embodiment of this application.

[0152] Figure 7 is a schematic block diagram of a wireless communication device according to an embodiment of this application.

[0153] Figure 8 is a schematic block diagram of a wireless communication device provided according to an embodiment of this application.

[0154] Figure 9 is a schematic block diagram of a wireless communication device according to an embodiment of this application.

[0155] Figure 10 is a schematic block diagram of a wireless communication device provided according to an embodiment of this application.

[0156] Figure 11 is a schematic block diagram of a communication device provided according to an embodiment of this application.

[0157] Figure 12 is a schematic diagram of the hardware structure of a terminal according to an embodiment of this application.

[0158] Figure 13 is a schematic block diagram of a network-side device provided according to an embodiment of this application.

[0159] Figure 14 is a schematic block diagram of another network-side device provided according to an embodiment of this application. Detailed Implementation

[0160] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0161] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0162] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as the sender explicitly informing the receiver of specific information, the required operation, or the requested result in the instruction sent. An indirect instruction can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the required operation or requested result based on the judgment result.

[0163] It is worth noting that the technologies described in this application are not limited to Ambient Internet of Things (AIoT) systems, but can also be used in other wireless communication systems, such as Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, and other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) radio systems. th Generation 6G communication system.

[0164] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a communication node 12. The terminal 11 can be an AIoT device, mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart earphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 21 is not limited in the embodiments of this application.

[0165] Optionally, the communication node 12 may include at least one of the following: access network equipment and core network equipment.

[0166] Access network equipment can also be called Radio Access Network (RAN) equipment, Radio Access Network functions, or Radio Access Network units. Access network equipment can include AIoT readers, base stations, Wireless Local Area Network (WLAN) access points (APs), or Wireless Fidelity (WiFi) nodes, etc. The term "base station" can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), Non-Terrestrial Network (NTN) equipment (e.g., satellite or high altitude platform station), or any other suitable term in the field, provided that the same technical effect is achieved. The term "base station" is not limited to any specific technical terminology. It should be noted that this application embodiment only uses a base station in an NR system as an example for introduction, and does not limit the specific type of base station.

[0167] Core network equipment, also known as core network nodes, core network functions, or core network elements, includes, but is not limited to, at least one of the following: AIoT Function (AIoT F), Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), and Local NEF. NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), Network Data Analytics Function (NWDAF), and Non-Terrestrial Network (NTN) devices (such as satellite or high altitude platform station).It should be noted that the embodiments of this application only use the core network equipment in the NR system as an example for introduction, and do not limit the specific type of core network equipment. If the name of the core network equipment mentioned in the embodiments of this application changes in subsequent protocol versions (e.g., 6G), it is also within the scope of protection of this application.

[0168] Optionally, the core network equipment can be implemented by one or more functional modules in a single device, or by multiple devices working together; this application does not specifically limit this. It is understood that the aforementioned functional modules can be network elements in hardware devices, software functional modules running on dedicated hardware, or virtualized functional modules instantiated on a platform (e.g., a cloud platform).

[0169] Figure 2 illustrates the inventory process for AIoT devices in related technologies. As shown in Figure 2, it may include the following steps:

[0170] Step 1: AF sends an inventory request to the functional entity of the AIoT device (i.e., AIoT F). The inventory request includes the device's permanent identifier (ID), group identifier (Group ID), or mask information. The mask information can be the mask information of the permanent identifier, or it can be other information.

[0171] Step 2: AIoT F generates authentication information (XRES) and temporary ID (Temp ID) based on the shared key (e.g., Long Term Key (LTK)) and random number (RAND) between itself and the AIoT device.

[0172] Step 3: AIoT F sends an inventory request to the access network device of the AIoT device, such as the AIoT reader. The inventory request includes the device's Temp ID / MASK information and RAND.

[0173] Step 4: The AIoT reader pages the AIoT device. The paging message includes Temp ID / MASK information and RAND.

[0174] Step 5: The AIoT device generates authentication information (RES) and Temp ID based on the shared key (e.g., LTK) and RAND.

[0175] When the paging message includes a Temp ID, the AIoT device determines whether the calculated Temp ID is the same as the Temp ID included in the paging message. If they are the same, the device responds to the paging request.

[0176] When the paging message includes a Group ID, the AIoT device determines whether it is in the group indicated by the Group ID. If it is, it responds to the paging.

[0177] When the paging message includes MASK information, the AIoT device determines whether the local information meets the conditions represented by the MASK. For example, if the MASK is an ID MASK, the AIoT device checks whether its own ID meets the conditions represented by the MASK. If the conditions are met, it responds to the paging.

[0178] Step 6: The AIoT device responds to the paging, for example, the AIoT device sends an inventory response to the AIoT F, where the inventory response includes the Temp ID and RES generated by the AIoT device.

[0179] Step 7: AIoT F identifies and authenticates AIoT devices based on Temp ID and RES.

[0180] Step 8: If the verification is successful, AIoT F replies to AF with an inventory response, which includes the permanent identifier (ID) of the AIoT device.

[0181] However, since the Temp ID and authentication information are generated based on the same key and random number, there is a potential correlation between the two, and there is a possibility that the other information can be derived from one of the pieces of information, which poses a security risk.

[0182] The wireless communication method provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.

[0183] Figure 3 is a schematic diagram of a wireless communication method 200 according to an embodiment of this application. As shown in Figure 3, the wireless communication method 200 may include at least some of the following:

[0184] S210, the first device receives target challenge information from the network, or the first device receives target challenge information and third identification information from the network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0185] S220, the first device sends a first message to the first communication node, the first message including first identification information and first authentication information;

[0186] Correspondingly, the first communication node receives the first message from the first device.

[0187] In some embodiments, the first device may be an AIoT device, or it may be other terminal types as illustrated in Figure 1, which are not limited in this application.

[0188] In some embodiments, the first communication node may be a communication node in the network where the first device resides, such as a core network-side node. Optionally, when the first device is an AIoT device, the first communication node may be a core network function of the AIoT device, such as AIoT F.

[0189] The first communication node described in the embodiments of this application may also be referred to as a first communication device, a first communication entity, a first communication function, etc., and this application does not limit it in this way.

[0190] In some embodiments, the first message may be a NAS message, or other signaling used for interaction between the first device and the first communication node.

[0191] Optionally, the first device is an AIoT device, and the first message can be an inventory response message.

[0192] In some embodiments, the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device.

[0193] In some embodiments of this application, the method 200 further includes:

[0194] The first communication node identifies the first device based on the first identification information; or...

[0195] The first communication node identifies the first device based on the first identification information and verifies the first authentication information based on the second authentication information associated with the first device.

[0196] For example, the first communication node can identify the first device by comparing the first identification information and the third identification information. For instance, if the first identification information and the third identification information are the same, the authentication information associated with the third identification information is used as the second authentication information, and the first authentication information is verified based on the second authentication information.

[0197] In some embodiments, the first identification information is generated by the first device based on a shared key (e.g., LTK) between the first device and the first communication node and the first information, or the first identification information is a third identification information.

[0198] Optionally, the first identification information may be a temporary identifier (Temp ID) of the first device generated by the first device based on the shared key and the first information, or the first device may directly use the third identification information as the first identification information.

[0199] In some embodiments, the first authentication information is generated by the first device based on the shared key and the second information.

[0200] In some embodiments, the third identification information may be generated by the first communication node based on a shared key (e.g., LTK) and the first information.

[0201] For example, the third identification information could be a temporary identifier (Temp ID) of the first device generated by the first communication node based on the shared key and the first information.

[0202] In some embodiments, the second authentication information is generated based on the shared key and the second information.

[0203] For example, the second authentication information may be generated by the first communication node based on the shared key (e.g., LTK) and the second information, or it may be obtained from other network elements (e.g., AIoT Data Management (ADM) network elements, AF, or Authentication, Authorization, and Accounting (AAA) network elements).

[0204] In this embodiment of the application, the first authentication information is referred to as RES, and the second authentication information is referred to as XRES.

[0205] In this embodiment of the application, the first information and the second information are different.

[0206] In other words, in this embodiment of the application, the temporary identifier and authentication information of the first device are generated based on different information, which can avoid the problem of security degradation caused by potential correlation between the generated temporary identifier and authentication information, and can achieve secure isolation between ID recognition and device authentication, thereby reducing exposed security risks.

[0207] In some embodiments of this application, the first information may include at least one of the following:

[0208] First key generation information, used to generate a first key, the first key is used to generate first identification information or third identification information;

[0209] The identifier generation parameters are used to generate the first identifier information or the third identifier information.

[0210] In some embodiments of this application, the second information may include at least one of the following:

[0211] Second key generation information, used to generate a second key, the second key is used to generate first authentication information or second authentication information;

[0212] The authentication information generation parameters are used to generate either the first authentication information or the second authentication information.

[0213] In the embodiments of this application, the first key is also called the ID key, and the second key is also called the RES / XRES key.

[0214] The first key can be considered as a dedicated key for generating the Temp ID, and the second key can be considered as a dedicated key for generating authentication information. By generating the Temp ID and RES / XRES using the dedicated keys for the Temp ID and RES / XRES respectively, the potential association between the generated Temp ID and RES / XRES that could lead to security degradation can be avoided. This can achieve secure isolation between ID recognition and device authentication, and reduce the exposure of security risks.

[0215] In some embodiments, when the first key generation information is used to generate the first identification information, the first key generation information includes at least one of the following:

[0216] At least one of the first challenge information and the second challenge information;

[0217] Primary purpose information;

[0218] Second identification information of the first device;

[0219] First authentication information.

[0220] In some embodiments, when the first key generation information is used to generate the third identification information, the first key generation information includes at least one of the following:

[0221] At least one of the first challenge information and the second challenge information;

[0222] Primary purpose information;

[0223] Second identification information of the first device;

[0224] Second authentication information.

[0225] In some embodiments, when the identifier generation parameter is used to generate first identifier information, the identifier generation parameter includes at least one of the following:

[0226] At least one of the first challenge information and the second challenge information;

[0227] Primary purpose information;

[0228] Second identification information of the first device;

[0229] First authentication information.

[0230] In some embodiments, when the identifier generation parameter is used to generate third identifier information, the identifier generation parameter includes at least one of the following:

[0231] At least one of the first challenge information and the second challenge information;

[0232] Primary purpose information;

[0233] Second identification information of the first device;

[0234] Second authentication information.

[0235] In some embodiments, when the second key generation information is used to generate the first authentication information, the second key generation information includes at least one of the following:

[0236] At least one of the first challenge information and the second challenge information;

[0237] Secondary use information;

[0238] Second identification information of the first device;

[0239] First identification information.

[0240] In some embodiments, when the second key generation information is used to generate the second authentication information, the second key generation information includes at least one of the following:

[0241] At least one of the first challenge information and the second challenge information;

[0242] Secondary use information;

[0243] Second identification information of the first device;

[0244] Third identification information.

[0245] In some embodiments, when the authentication information generation parameters are used to generate first authentication information, the authentication information generation parameters include at least one of the following:

[0246] At least one of the first challenge information and the second challenge information;

[0247] Secondary use information;

[0248] Second identification information of the first device;

[0249] First identification information.

[0250] In some embodiments, when the authentication information generation parameters are used to generate second authentication information, the authentication information generation parameters include at least one of the following:

[0251] At least one of the first challenge information and the second challenge information;

[0252] Secondary use information;

[0253] Second identification information of the first device;

[0254] Third identification information.

[0255] In some embodiments, the first challenge information may be a first random information or a first random number (RAND1), a dynamically changing parameter such as the quantity information that increases or decreases successively, and this application does not limit it.

[0256] In some embodiments, the second challenge information may be a second random information or a second random number (RAND2), a dynamically changing parameter such as the quantity information that increases or decreases successively, and this application does not limit it.

[0257] In some embodiments, the first challenge information may be randomly generated by the first communication node, or it may be obtained from other network elements (such as ADM network elements, AF network elements, or AAA network elements), and this application does not limit this.

[0258] In some embodiments, the second challenge information may be randomly generated by the first communication node, or it may be obtained from other network elements (such as ADM network elements, AF network elements, or AAA network elements), and this application does not limit this.

[0259] In some embodiments, the second identification information of the first device may be a permanent identifier of the first device, such as a Subscription Permanent Identifier (SUPI), a Device ID, an International Mobile Subscriber Identity (IMSI), etc. This application does not limit this.

[0260] In some embodiments, the first purpose information may be first string information, such as “ID_Reg”, “Identification”, “AIoT_Identification”, etc., or it may be other information used to indicate the ID identification function, which is not limited in this application.

[0261] In some embodiments, the second-purpose information may be second string information, such as “auth”, “authentication”, “AIoT_Auth”, etc., or it may be other information used to indicate the device authentication function, which is not limited in this application.

[0262] In some embodiments, the first purpose information and the second purpose information may be predefined.

[0263] That is, the first device and the first communication node can obtain the first purpose information and the second purpose information without signaling interaction.

[0264] In some embodiments of this application, the method 200 further includes at least one of the following:

[0265] The first device generates first identification information based on the shared key and identification generation parameters;

[0266] The first device generates a first key based on the shared key and the first key generation information, and generates first identifier information based on the first key and the identifier generation parameters;

[0267] The first device generates first authentication information based on the shared key and authentication information generation parameters;

[0268] The first device generates a second key based on the shared key and the second key generation information, and generates first authentication information based on the second key and authentication information generation parameters.

[0269] For example, when the first information includes identifier generation parameters, the first device can generate first identifier information based on the shared key and the identifier generation parameters.

[0270] For example, when the first information includes first key generation information and identifier generation parameters, the first device can first generate a first key based on the shared key and the first key generation information, and then generate first identifier information based on the first key and the identifier generation parameters.

[0271] For example, when the second information includes authentication information generation parameters, the first device can generate the first authentication information based on the shared key and the authentication information generation parameters.

[0272] For example, when the second information includes second key generation information and authentication information generation parameters, the first device can first generate a second key based on the shared key and the second key generation information, and then generate the first authentication information based on the second key and the authentication information generation parameters.

[0273] In some embodiments of this application, the method 200 further includes at least one of the following:

[0274] The first communication node generates the third identification information based on the shared key and the identification generation parameters;

[0275] The first communication node generates a first key based on the shared key and the first key generation information, and generates third identification information based on the first key and the identification generation parameters.

[0276] The first communication node generates the second authentication information based on the shared key and authentication information.

[0277] The first communication node generates a second key based on the shared key and the second key generation information, and generates second authentication information based on the second key and authentication information generation parameters.

[0278] For example, when the first information includes identifier generation parameters, the first communication node can generate third identifier information based on the shared key and the identifier generation parameters.

[0279] For example, when the first information includes first key generation information and identifier generation parameters, the first communication node can first generate a first key based on the shared key and the first key generation information, and then generate third identifier information based on the first key and the identifier generation parameters.

[0280] For example, when the second information includes authentication information generation parameters, the first communication node can generate the second authentication information based on the shared key and the authentication information generation parameters.

[0281] For example, when the second information includes second key generation information and authentication information generation parameters, the first communication node can first generate a second key based on the shared key and the second key generation information, and then generate second authentication information based on the second key and the authentication information generation parameters.

[0282] That is, in the embodiments of this application, the first device and the first communication node can generate the temporary identifier and authentication information of the first device in a certain manner.

[0283] In the embodiments of this application, in order to ensure the secure isolation of ID recognition and device authentication, the generation parameters of Temp ID and RES / XRES can be set to be different. Alternatively, the generation parameters of the corresponding exclusive keys can be set to be different. Or, if one piece of information is generated based on the exclusive key and the other piece of information is not generated based on the exclusive key, the generation parameters of the exclusive key and the generation parameters of the other piece of information can be set to be different, etc. This application does not limit this.

[0284] The following section explains the setting of the first and second information in specific contexts.

[0285] Case 1: Both Temp ID and RES / XRES key are generated based on the corresponding key.

[0286] In this case 1, the first information includes the first key generation information, and the second information includes the second key generation information.

[0287] In this case, the difference between the first information and the second information may include:

[0288] The first key generation information and the second key generation information are different. For example, the parameters included in the first key generation information and the second key generation information are at least partially different.

[0289] In other words, since the first device uses different parameters to generate the ID key and RES / XRES key, when generating Temp ID and RES / XRES based on the ID key and RES key respectively, the potential correlation between the generated Temp ID and RES / XRES can be reduced.

[0290] Case 2: Both Temp ID and RES are generated based on the corresponding generation parameters.

[0291] In this scenario 2, the first information includes the identifier generation parameters, and the second information includes the authentication information generation parameters.

[0292] In this case, the difference between the first information and the second information may include:

[0293] The parameters for generating the identifier and the parameters for generating the authentication information are different. For example, the parameters for generating the identifier and the parameters for generating the authentication information include at least some different parameters.

[0294] In other words, the different parameters used to generate Temp ID and RES can reduce the potential correlation between the generated Temp ID and RES / XRES.

[0295] Case 3: One of Temp ID and RES is generated based on the corresponding exclusive key, and the other is generated based on the generation parameters.

[0296] Case 3-1: Temp ID is generated based on ID key, and RES is generated based on authentication information and parameters.

[0297] In this case 3-1, the first information includes the first key generation information, and the second information includes the authentication information generation parameters.

[0298] In this case, the difference between the first information and the second information may include:

[0299] The parameters for generating the first key and the authentication information are different.

[0300] In other words, the parameters used by the first device to generate the ID key and RES / XRES are different, which can reduce the potential correlation between the Temp ID and RES / XRES generated based on the ID key.

[0301] Case 3-2: Temp ID is generated based on the identifier generation parameters, and RES is generated based on the RES key.

[0302] In this case 3-2, the first information includes the identifier generation parameters, and the second information includes the second key generation information.

[0303] In this case, the difference between the first information and the second information may include:

[0304] The identifier generation parameters and the second key generation information are different.

[0305] In other words, the parameters used by the first device to generate the ID and RES / XRES key are different, which can reduce the potential correlation between the RES / XRES and Temp ID generated based on the RES / XRES key.

[0306] Case 4: Temp ID is generated based on ID key and identifier generation parameters, and RES is generated based on RES key and authentication information generation parameters.

[0307] In this case 4, the first information includes the first key generation information and the identifier generation parameters, and the second information includes the second key generation information and the authentication information generation parameters.

[0308] In this case, the difference between the first information and the second information may include:

[0309] The first key generation information and the second key generation information are different; and / or

[0310] The parameters for generating the identifier are different from those for generating the authentication information.

[0311] In other words, using different parameters to generate the Temp ID key and the RES / XRES key, and / or using different parameters to generate the Temp ID and the RES / XRES key, can reduce the potential correlation between the generated Temp ID and the RES / XRES.

[0312] Case 5: One piece of information is generated based on the corresponding exclusive key and generation parameters, and the other piece of information is generated based on the corresponding generation parameters.

[0313] Case 5-1: Temp ID is generated based on ID key and identifier generation parameters, while RES / XRES is generated based on authentication information generation parameters.

[0314] In this case 5-1, the first information includes the first key generation information and the identifier generation parameters, and the second information includes the authentication information generation parameters.

[0315] In this case, the difference between the first information and the second information may include:

[0316] The parameters for generating the first key and authentication information are different; and / or

[0317] The parameters for generating the identifier are different from those for generating the authentication information.

[0318] In other words, different parameters are used to generate Temp ID key and RES / XRES, and / or different parameters are used to generate Temp ID and RES, which can reduce the potential correlation between the generated Temp ID and RES / XRES.

[0319] Case 5-2: Temp ID is generated based on identifier generation parameters, and RES / XRES is generated based on RES / XRES key and authentication information generation parameters.

[0320] In this case 5-2, the first information includes the identifier generation parameters, and the second information includes the second key generation information and the authentication information generation parameters.

[0321] In this case, the difference between the first information and the second information may include:

[0322] The second key generation information and the identifier generation parameters are different; and / or

[0323] The parameters for generating the identifier are different from those for generating the authentication information.

[0324] In other words, using different parameters to generate Temp ID and RES / XRES key, and / or using different parameters to generate Temp ID and RES / XRES, can reduce the potential correlation between the generated Temp ID and RES / XRES.

[0325] It should be noted that, in the embodiments of this application, different challenge information can be used as distinguishing information for generating Temp ID and RES to reduce the potential correlation between the generated Temp ID and RES / XRES. Alternatively, different usage information can be used as distinguishing information for generating Temp ID and RES / XRES to reduce the potential correlation between the generated Temp ID and RES / XRES. Alternatively, a combination of both can be used as distinguishing information for generating Temp ID and RES / XRES to reduce the potential correlation between the generated Temp ID and RES / XRES. Alternatively, the potential correlation between the generated Temp ID and RES / XRES can be reduced by having one information's generation parameter (or key generation information) include specific information (e.g., challenge information, usage information, second identification information, etc.) while another information's generation parameter (or key generation information) does not include specific information, and one of the information is used as the generation parameter (or key generation information) of the other information. This application does not limit this approach.

[0326] The following describes the specific design of each piece of information in the first and second information, with reference to specific embodiments.

[0327] In some embodiments, when the target challenge information includes first challenge information and second challenge information, the first challenge information and / or the second challenge information can be used as distinguishing information for generating Temp ID and authentication information.

[0328] In some implementations, the first key generation information and / or identifier generation parameters include first challenge information, and the second key generation information and / or authentication information generation parameters include second challenge information.

[0329] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is generated include the first challenge information, and the parameters on which the first authentication information or the second authentication information is generated include the second challenge information. By using the first challenge information and the second challenge information as distinguishing information for generating Temp ID and RES / XRES, the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation can be avoided, thereby achieving secure isolation between ID recognition and device authentication.

[0330] In some other implementations, the first key generation information and / or identifier generation parameters include first challenge information and second challenge information, and the second key generation information and / or authentication information generation parameters include either the first challenge information or the second challenge information.

[0331] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is based include the first challenge information and the second challenge information, and the parameters on which the first authentication information or the second authentication information is based only include one of the challenge information. Then the other challenge information can be considered as the distinguishing information between the generated Temp ID and RES / XRES, which can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0332] In some other implementations, the first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

[0333] In this case, it can be assumed that the parameters on which the first authentication information or the second authentication information is based include the first challenge information and the second challenge information, and the parameters on which the first identification information or the third identification information is based only include one of the challenge information. Then the other challenge information can be considered as the distinguishing information between the generated Temp ID and RES / XRES. This can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0334] In other embodiments, Temp ID and RES / XRES can be distinguished by target challenge information, purpose information, using one of the information as a generation parameter (or key generation information) for the other.

[0335] In some implementations, the first key generation information and / or identifier generation parameters include at least one of the first authentication information and the first purpose information, and the second key generation information and / or authentication information generation parameters include at least the target challenge information.

[0336] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is generated include the first authentication information and / or the first purpose information, and the parameters on which the first authentication information or the second authentication information is generated include the target challenge information. The target challenge information is different from the first authentication information and / or the first purpose information, and can be used as distinguishing information for generating Temp ID and RES / XRES. This can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0337] In some other implementations, the first key generation information and / or identifier generation parameters include at least target challenge information, and the second key generation information and / or authentication information generation parameters include at least one of the first identifier information and the second purpose information.

[0338] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is generated include the target challenge information, and the parameters on which the first authentication information or the second authentication information is generated include the first identification information and / or the second purpose information. The target challenge information is different from both the first identification information and / or the second purpose information, and can be used as distinguishing information for generating Temp ID and RES / XRES. This can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0339] In some other implementations, the first key generation information and / or identifier generation parameters include at least the target challenge information and the second identifier information of the first device, while the second key generation information and / or authentication information generation parameters do not include the second identifier information of the first device.

[0340] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is generated include the target challenge information and the second identification information of the first device, the parameters on which the first authentication information or the second authentication information is generated do not include the second identification information of the first device, and the distinguishing information between the Temp ID and RES / XRES includes the second identification information of the first device. This can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0341] In some other implementations, the first key generation information and / or identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or authentication information generation parameters include the target challenge information and the second identifier information of the first device.

[0342] In this case, it can be assumed that the parameters on which the first authentication information or the second authentication information is generated include the target challenge information and the second identification information of the first device, while the parameters on which the first identification information or the third identification information is generated do not include the second identification information of the first device. The distinguishing information between the Temp ID and RES / XRES includes the second identification information of the first device. This can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0343] In some other implementations, the first key generation information and / or identifier generation parameters do not include the target challenge information, while the second key generation information and / or authentication information generation parameters at least include the target challenge information.

[0344] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is based do not include the target challenge information, while the parameters on which the first authentication information or the second authentication information is based include the target challenge information. Therefore, the distinguishing information for generating Temp ID and RES / XRES includes the target challenge information, which can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0345] In some other implementations, the first key generation information and / or identifier generation parameters include at least the target challenge information, while the second key generation information and / or authentication information generation parameters do not include the target challenge information.

[0346] In this case, it can be assumed that the parameters on which the first identification information or the third identification information is based include the target challenge information, while the parameters on which the first authentication information or the second authentication information is based do not include the target challenge information. Therefore, the distinguishing information for generating Temp ID and RES / XRES includes the target challenge information, which can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0347] The following describes, with reference to specific embodiments, how the first identification information (or third identification information) and the first authentication information (or second authentication information) are generated.

[0348] Example 1: The target challenge information includes first challenge information and second challenge information. The first information includes the first challenge information, the second information includes the second challenge information, the first identification information or the third identification information is generated based on the shared key and the first challenge information, and the first authentication information or the second authentication information is generated based on the shared key and the second challenge information.

[0349] In other words, in this example, using different challenge information as the distinguishing information for generating Temp ID and RES / XRES can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0350] Example 2: The target challenge information includes first challenge information and second challenge information. The first information includes first purpose information and first target challenge information. The second information includes second purpose information and second target challenge information. The first target challenge information includes at least one of the first challenge information and the second challenge information. The second target challenge information includes at least one of the first challenge information and the second challenge information.

[0351] The first identification information or the third identification information is generated based on the shared key, the first purpose information, and the first target challenge information; the first authentication information or the second authentication information is generated based on the shared key, the second purpose information, and the second target challenge information.

[0352] In other words, in this example, different usage information can be used as distinguishing information for generating Temp ID and RES / XRES, which can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0353] Example 3: The target challenge information includes first challenge information, the first information includes first challenge information and first purpose information, the second information includes first challenge information and second purpose information, the first identification information or third identification information is generated based on the first key and the first purpose information, the first authentication information or second authentication information is generated based on the second key and the second purpose information, wherein the first key and the second key are both generated based on the shared key and the first challenge information.

[0354] In other words, in this example, different usage information can be used as distinguishing information for generating Temp ID and RES / XRES, which can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0355] Example 4: The target challenge information includes first challenge information, the first information includes first challenge information and first purpose information, the second information includes first challenge information, the first identification information or third identification information is generated based on the first key, the first key is generated based on the shared key, the first challenge information and the first purpose information, and the first authentication information or second authentication information is generated based on the shared key and the first challenge information.

[0356] In other words, in this example, the first-purpose information can be used as the distinguishing information between the generated ID key and RES / XRES. In turn, the first-purpose information can be used as the distinguishing information between the generated Temp ID and RES / XRES, which can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0357] Example 5: The target challenge information includes first challenge information, the first information includes first challenge information, the second information includes first challenge information and second purpose information, the first identification information or third identification information is generated based on the shared key and the first challenge information, the first authentication information or second authentication information is generated based on the second key, and the second key is generated based on the shared key, the first challenge information and the second purpose information.

[0358] In other words, in this example, the second-purpose information can be used as the distinguishing information between the generated ID key and RES / XRES. In turn, the first-purpose information can be used as the distinguishing information between the generated Temp ID and RES / XRES. This can avoid the problem of potential association between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0359] Example 6: The target challenge information includes first challenge information, the first information includes first challenge information, the second information includes first challenge information and second purpose information, wherein the first identification information or the third identification information is generated based on the first key, the first key is generated based on the shared key and the first challenge information, and the first authentication information or the second authentication information is generated based on the shared key, the first challenge information and the second purpose information.

[0360] In other words, in this example, the secondary use information can be used as the distinguishing information between the generated ID key and RES / XRES. This secondary use information can be used as the distinguishing information between the generated Temp ID and RES / XRES, which can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0361] Example 7: The target challenge information includes first challenge information, the first information includes first challenge information and first purpose information, the second information includes first challenge information, wherein the first identification information or the third identification information is generated based on the shared key, the first challenge information and the first purpose information, the first authentication information or the second authentication information is generated based on the second key, and the second key is generated based on the shared key and the first challenge information.

[0362] In other words, in this example, the primary purpose information can be used as distinguishing information for generating Temp ID and RES / XRES keys. Furthermore, by using this primary purpose information to distinguish between the generated Temp ID and RES / XRES, the potential association between the generated Temp ID and RES / XRES, which could lead to security degradation, can be avoided. This achieves secure isolation between ID recognition and device authentication.

[0363] Example 8: The target challenge information includes first challenge information, the first information includes first challenge information, the second information includes first challenge information and second purpose information, wherein the first identification information or the third identification information is generated based on the shared key and the first challenge information, and the first authentication information or the second authentication information is generated based on the shared key, the first challenge information and the second purpose information.

[0364] In other words, in this example, the secondary use information can serve as distinguishing information for generating Temp ID and RES / XRES, which can avoid the problem of potential correlation between the generated Temp ID and RES / XRES leading to security degradation, thereby achieving secure isolation between ID recognition and device authentication.

[0365] Example 9: The target challenge information includes first challenge information, the first information includes first challenge information and first purpose information, the second information includes first challenge information, wherein the first identification information or the third identification information is generated based on the shared key, the first challenge information and the first purpose information, and the first authentication information or the second authentication information is generated based on the shared key and the first challenge information.

[0366] In other words, in this example, the primary purpose information can be used as distinguishing information for generating Temp ID and RES / XRES, which can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0367] Example 10: The target challenge information includes first challenge information, the first information includes first challenge information and second identification information, the second information includes first challenge information, wherein the first identification information or the third identification information is generated based on the shared key, the first challenge information and the second identification information, and the first authentication information or the second authentication information is generated based on the shared key and the first challenge information.

[0368] Alternatively, the first information includes the first challenge information, and the second information includes the first challenge information and the second identification information, wherein the first identification information or the third identification information is generated based on the shared key and the first challenge information, and the first authentication information or the second authentication information is generated based on the shared key, the first challenge information, and the second identification information.

[0369] In other words, in this example, the second identification information can be used as distinguishing information for generating Temp ID and RES / XRES, which can avoid the problem of security degradation caused by potential correlation between the generated Temp ID and RES / XRES, thereby achieving secure isolation between ID recognition and device authentication.

[0370] Example 11: The target challenge information includes first challenge information and second challenge information. The first information includes first target challenge information, and the second information includes second target challenge information and second identification information. The first target challenge information includes at least one of the first challenge information and the second challenge information, and the second target challenge information includes at least one of the first challenge information and the second challenge information. The first identification information or the third identification information is generated based on the shared key and the first target challenge information, and the first authentication information or the second authentication information is generated based on the shared key, the second target challenge information, and the second identification information.

[0371] In other words, in this example, the second identification information can serve as the distinguishing information between the generated Temp ID and RES / XRES, preventing potential association between the generated Temp ID and RES / XRES that could lead to security degradation, thereby achieving secure isolation between ID recognition and device authentication. In this example, different challenge information can also be used to distinguish between the generated ID and RES / XRES. For example, the first target challenge information includes the first challenge information, and the second target challenge information includes the second challenge information. Alternatively, the first target challenge information includes both the first and second challenge information, and the second target challenge information includes either the second or first challenge information. Another example is that the first target challenge information includes either the first or second challenge information, and the second target challenge information includes both the second and first challenge information.

[0372] In some embodiments, the first device receives target challenge information from the network, or the first device receives target challenge information and third identification information from the network, including:

[0373] The first device receives target challenge information from the first communication node, or the first device receives target challenge information and the third identification information from the first communication node; or

[0374] The first device receives the target challenge information from the second communication node, or the first device receives the target challenge information and the third identification information from the second communication node, wherein the target challenge information, or the target challenge information and the third identification information, is received by the second communication node from the first communication node, and the second communication node is a communication node in the network where the first device is located.

[0375] Optionally, the second communication node can be an access network node of the network where the first device is located. For example, when the first device is an AIoT device, the second communication node can be an AIoT reader / writer.

[0376] In some embodiments, the first device receives target challenge information from a first communication node, or the first device receives target challenge information and the third identification information from a first communication node, including:

[0377] The first device receives target challenge information from the first communication node via a broadcast message or a unicast message, or the target challenge information and the third identification information.

[0378] For example, the first device can receive target challenge information from the first communication node via a paging message, or the target challenge information and the third identification information.

[0379] In some embodiments, the first device receives the target challenge information from the second communication node, or the first device receives the target challenge information and third identification information from the second communication node, including:

[0380] The first device receives target challenge information from the second communication node via NAS messages, or the target challenge information and the third identification information.

[0381] The following, with reference to Figure 4, using the first device as an AIoT device, describes the method for generating Temp ID and authentication information provided in this application embodiment. As shown in Figure 4, it may include the following steps:

[0382] Step 1: AF sends an inventory request to the first communication node. The inventory request includes the device's second identification information, such as a permanent identifier (ID).

[0383] Step 2: The first communication node generates Temp ID (corresponding to the third identification information mentioned above) based on the shared key (e.g., LTK) with the AIoT device and the first information, and generates authentication information (XRES) (corresponding to the second authentication information mentioned above) based on LTK and the second information.

[0384] Step 3: The first communication node sends an inventory request to the second communication node (e.g., the AIoT reader). The inventory request includes the Temp ID (i.e., the third identification information) of the AIoT device and RAND1 (i.e., the first random number), or RAND1 and RAND2 (i.e., the second random number).

[0385] Step 4: The second communication node pages the AIoT device. The paging message includes Temp ID (i.e., the third identification information) and RAND1, or includes Temp ID, RAND1 and RAND2.

[0386] Step 5: The AIoT device generates a Temp ID (corresponding to the first identification information mentioned above) based on the shared key (e.g., LTK) and the first information, and generates authentication information (RES) (corresponding to the first authentication information mentioned above) based on the LTK and the second information. The AIoT device determines whether its generated Temp ID matches the Temp ID in the paging message. If they match, it responds to the paging.

[0387] Step 6: The AIoT device responds to the paging, for example, the AIoT device sends an inventory response to the first communication node, wherein the inventory response includes the Temp ID (i.e., the first identification information) and RES (i.e., the first authentication information) generated by the AIoT device.

[0388] Step 7: The first communication node identifies and authenticates the AIoT device based on Temp ID and RES.

[0389] For example, the associated XRES can be found based on the Temp ID in the inventory response, and the RES in the inventory response can be verified based on the XRES.

[0390] Step 8: If the verification is successful, the first communication node replies to the AF with an inventory response, which carries the second identification information of the AIoT device.

[0391] In summary, in this embodiment, the temporary identifier of the first device used for ID recognition and the authentication information used for device verification are generated based on different information. This avoids the problem of security degradation caused by potential correlation between the generated temporary identifier and authentication information, and enables secure isolation between ID recognition and device authentication, thereby reducing exposed security risks.

[0392] Figure 5 is a schematic diagram of a wireless communication method 300 according to an embodiment of this application. As shown in Figure 5, the wireless communication method 300 may include at least some of the following:

[0393] S310, the first device receives the first challenge information from the network;

[0394] S320, the first device sends a second message to the first communication node, the second message including third information.

[0395] Correspondingly, the first communication node receives the second message from the first device.

[0396] The third piece of information is used by the first communication node to identify and authenticate the first device.

[0397] The third information includes either first authentication information or first identification information. The first authentication information is generated based on a shared key between the first device and the first communication node and first information, while the first identification information is generated based on a shared key between the first device and the first communication node and second information.

[0398] In other words, in this embodiment of the application, both ID identification and device authentication can be achieved with a single piece of information, avoiding the need for security isolation between ID identification and device authentication and reducing security risks.

[0399] In some embodiments, the first device may be an AIoT device, or it may be other terminal types, which are not limited in this application.

[0400] In some embodiments, the first communication node may be a communication node in the network where the first device resides, such as a core network-side node. Optionally, when the first device is an AIoT device, the first communication node may be a core network function of the AIoT device, such as AIoT F.

[0401] The first communication node described in the embodiments of this application may also be referred to as a first communication device, a first communication entity, a first communication function, etc., and this application does not limit it in this way.

[0402] In some embodiments, the second message may be a NAS message, or other signaling used for interaction between the first device and the first communication node.

[0403] Optionally, the first device is an AIoT device, and the second message can be an inventory response message.

[0404] In some embodiments of this application, method 300 further includes:

[0405] The first communication node identifies and authenticates the first device based on the third information and the third identification information, for example, by comparing the third information and the third identification information.

[0406] The first communication node identifies and authenticates the first device based on the third information and the second authentication information, for example, by comparing the third information and the second authentication information.

[0407] In some embodiments, the third identification information is generated based on the shared key and the first information, and the second authentication information is generated based on the shared key and the second information.

[0408] In some embodiments, the first information includes at least one of the following:

[0409] First key generation information, used to generate a first key, the first key is used to generate first identification information;

[0410] The identifier generation parameters are used to generate the first identifier information.

[0411] In some embodiments, the first key generation information includes at least one of the following:

[0412] The first challenge information;

[0413] Primary purpose information;

[0414] The second identification information of the first device.

[0415] In some embodiments, the identifier generation parameters include at least one of the following:

[0416] The first challenge information;

[0417] Primary purpose information;

[0418] The second identification information of the first device.

[0419] In some embodiments, the second information includes at least one of the following:

[0420] Second key generation information is used to generate a second key, and the second key is used to generate first authentication information;

[0421] The authentication information generation parameters are used to generate the first authentication information.

[0422] In some embodiments, the second key generation information includes at least one of the following:

[0423] The first challenge information;

[0424] Secondary use information;

[0425] The second identification information of the first device.

[0426] In some embodiments, the authentication information generation parameters include at least one of the following:

[0427] The first challenge information;

[0428] Secondary use information;

[0429] The second identification information of the first device.

[0430] The specific implementation details of the above information can be found in the relevant descriptions in method 200. For the sake of brevity, they will not be repeated here.

[0431] Optionally, in method 300, the first purpose information and the second purpose information can be the same purpose information, such as purpose information used to indicate both ID identification and device authentication functions. For example, "auth+ID_Reg", "AIoT_Identification+

[0432] "authentication", etc.

[0433] In some embodiments, method 300 further includes any one of the following:

[0434] The first device generates first identification information based on the shared key and identification generation parameters;

[0435] The first device generates a first key based on the shared key and the first key generation information, and generates first identifier information based on the first key and the identifier generation parameters;

[0436] The first device generates first authentication information based on the shared key and authentication information generation parameters;

[0437] The first device generates a second key based on the shared key and the second key generation information, and generates first authentication information based on the second key and authentication information generation parameters.

[0438] For example, when the first information includes identifier generation parameters, the first device can generate first identifier information based on the shared key and the identifier generation parameters.

[0439] For example, when the first information includes first key generation information and identifier generation parameters, the first device can first generate a first key based on the shared key and the first key generation information, and then generate first identifier information based on the first key and the identifier generation parameters.

[0440] For example, when the second information includes authentication information generation parameters, the first device can generate the first authentication information based on the shared key and the authentication information generation parameters.

[0441] For example, when the second information includes second key generation information and authentication information generation parameters, the first device can first generate a second key based on the shared key and the second key generation information, and then generate the first authentication information based on the second key and the authentication information generation parameters.

[0442] In some embodiments, the method 300 further includes any one of the following:

[0443] The first communication node generates the third identification information based on the shared key and the identification generation parameters;

[0444] The first communication node generates a first key based on the shared key and the first key generation information, and generates third identification information based on the first key and the identification generation parameters.

[0445] The first communication node generates the second authentication information based on the shared key and authentication information.

[0446] The first communication node generates a second key based on the shared key and the second key generation information, and generates second authentication information based on the second key and authentication information generation parameters.

[0447] For example, when the first information includes identifier generation parameters, the first communication node can generate third identifier information based on the shared key and the identifier generation parameters.

[0448] For example, when the first information includes first key generation information and identifier generation parameters, the first communication node can first generate a first key based on the shared key and the first key generation information, and then generate third identifier information based on the first key and the identifier generation parameters.

[0449] For example, when the second information includes authentication information generation parameters, the first communication node can generate the second authentication information based on the shared key and the authentication information generation parameters.

[0450] For example, when the second information includes second key generation information and authentication information generation parameters, the first communication node can first generate a second key based on the shared key and the second key generation information, and then generate second authentication information based on the second key and the authentication information generation parameters.

[0451] That is, in the embodiments of this application, the first device and the first communication node can generate the temporary identifier or authentication information of the first device in a certain manner.

[0452] In some specific embodiments, the first identification information or the third identification information can be generated based on the shared key and the first challenge information, and the first authentication information or the second authentication information can be generated based on the shared key and the first challenge information.

[0453] In some specific embodiments, the first identification information or the third identification information can be generated based on the shared key, the first challenge information and the first purpose information, and the first authentication information or the second authentication information can be generated based on the shared key, the first challenge information and the second purpose information.

[0454] In other specific embodiments, the first identification information or the third identification information can be generated based on the shared key, the first challenge information, and the second identification information, and the first authentication information or the second authentication information can be generated based on the shared key, the first challenge information, and the second identification information.

[0455] In some other specific embodiments, the first identification information or the third identification information can be generated based on the shared key, the first challenge information, the first purpose information and the second identification information, and the first authentication information or the second authentication information can be generated based on the shared key, the first challenge information, the second purpose information and the second identification information.

[0456] In some embodiments, the first device receiving first challenge information from the network may include at least one of the following:

[0457] The first device receives the first challenge information from the first communication node;

[0458] The first device receives first challenge information from the second communication node, wherein the first challenge information is received by the second communication node from the first communication node, and the second communication node is a communication node in the network where the first device is located.

[0459] Optionally, the second communication node can be an access network node of the network where the first device is located. For example, when the first device is an AIoT device, the second communication node can be an AIoT reader / writer.

[0460] In some embodiments, the first device receives first challenge information from the first communication node, including:

[0461] The first device receives the first challenge information from the first communication node via a broadcast message or a unicast message.

[0462] For example, the first device can receive the first challenge information from the first communication node via a paging message.

[0463] In some embodiments, the first device receives first challenge information from the second communication node, including:

[0464] The first device receives the first challenge information from the second communication node via NAS messages.

[0465] The following, with reference to Figure 6, using the first device as an AIoT device, describes the method for generating third information provided in this application embodiment. As shown in Figure 6, it may include the following steps:

[0466] Step 1: AF sends an inventory request to the first communication node. The inventory request includes the device's second identification information, such as a permanent identifier (ID).

[0467] Step 2: The first communication node generates Temp ID (corresponding to the third identification information mentioned above) based on the shared key (e.g., LTK) with the AIoT device and the first information, or generates authentication information (XRES) (corresponding to the second authentication information mentioned above) based on LTK and the second information.

[0468] Step 3: The first communication node sends an inventory request to the second communication node (e.g., the AIoT reader). The inventory request includes the Temp ID / XRES of the AIoT device and RAND1 (i.e., the first random number).

[0469] Step 4: The second communication node pages the AIoT device, where the paging message includes Temp ID / XRES and RAND1.

[0470] Step 5: The AIoT device generates a Temp ID (corresponding to the first identification information mentioned above) based on the shared key (e.g., LTK) and the first information, or generates authentication information (RES) (corresponding to the first authentication information mentioned above) based on the LTK and the second information. The AIoT device determines whether its generated Temp ID or RES matches the Temp ID or XRES in the paging message. If they match, it responds to the paging.

[0471] Step 6: The AIoT device responds to the paging, for example, the AIoT device sends an inventory response to the first communication node, wherein the inventory response includes the Temp ID (i.e., the first identification information) or RES (i.e., the first authentication information) generated by the AIoT device.

[0472] Step 7: The first communication node identifies and authenticates the AIoT device based on Temp ID or RES.

[0473] For example, based on its own generated Temp ID and XRES, it can perform device identification and authentication on the Temp ID or RES in the inventory response.

[0474] Step 8: If the verification is successful, the first communication node replies to the AF with an inventory response, which carries the second identification information of the AIoT device.

[0475] In summary, in this embodiment, a single piece of information can achieve both ID identification and device authentication, avoiding the need for secure isolation between ID identification and device authentication and reducing security risks.

[0476] The wireless communication method provided in this application can be executed by a communication device. This application uses the example of a communication device executing the wireless communication method to illustrate the communication device provided in this application.

[0477] This application provides a communication device. As an example, the communication device may be a communication equipment or a component within a communication equipment, such as a chip. The communication equipment may be a terminal, a network-side device, or a server, etc. Exemplarily, the terminal may include, but is not limited to, the type of terminal 11 listed above, and the network-side device may include, but is not limited to, the type of network-side device 12 listed above. This application does not impose specific limitations.

[0478] The communication device includes a receiving module, a transmitting module, and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, etc., such as central processing units (CPUs), microprocessors, digital signal processors (DSPs), artificial intelligence (AI) processors, graphics processing units (GPUs), application-specific integrated circuits (ASICs), network processors (NPs), field-programmable gate arrays (FPGAs), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceivers, pins, circuits, buses, radio frequency units, etc.

[0479] Specifically, referring to Figure 7, when the communication device is the first device or a component of the first device, the communication device 400 includes:

[0480] The receiving module 401 is used to receive target challenge information from the network, or to receive target challenge information and third identification information from the network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0481] The sending module 402 is used to send a first message to a first communication node. The first message includes first identification information and first authentication information. The first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device.

[0482] Wherein, the first identification information is generated by the first device based on the shared key and the first information between the first device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the first device based on the shared key and the second information;

[0483] The network in question is the network where the first communication node is located.

[0484] The first piece of information includes at least one of the following:

[0485] First key generation information, used to generate a first key, which is used to generate the first identification information;

[0486] Identifier generation parameters are used to generate the first identifier information;

[0487] The second piece of information includes at least one of the following:

[0488] Second key generation information, used to generate a second key, which is used to generate the first authentication information;

[0489] The authentication information generation parameters are used to generate the first authentication information.

[0490] In some embodiments, the first key generation information includes at least one of the following:

[0491] At least one of the first challenge information and the second challenge information;

[0492] Primary purpose information;

[0493] The second identification information of the first device;

[0494] This is the first authentication information.

[0495] In some embodiments, the identifier generation parameters include at least one of the following:

[0496] At least one of the first challenge information and the second challenge information;

[0497] Primary purpose information;

[0498] The second identification information of the first device;

[0499] This is the first authentication information.

[0500] In some embodiments, the second key generation information includes at least one of the following:

[0501] At least one of the first challenge information and the second challenge information;

[0502] Secondary use information;

[0503] The second identification information of the first device;

[0504] This is the first identifier information.

[0505] In some embodiments, the authentication information generation parameters include at least one of the following:

[0506] At least one of the first challenge information and the second challenge information;

[0507] Secondary use information;

[0508] The second identification information of the first device;

[0509] This is the first identifier information.

[0510] In some embodiments, the first key generation information and the second key generation information are different; or

[0511] The parameters for generating this identifier are different from the parameters for generating this authentication information; or

[0512] The parameters for generating the first key and the authentication information are different; or

[0513] The second key generation information is different from the identifier generation parameters.

[0514] In some embodiments, the first use information and the second use information are predefined.

[0515] In some embodiments, the device 400 further includes:

[0516] The processing module is used to perform at least one of the following:

[0517] The first identification information is generated based on the shared key and the identification generation parameters;

[0518] The first key is generated based on the shared key and the first key generation information, and the first identifier information is generated based on the first key and the identifier generation parameters;

[0519] The first authentication information is generated based on the shared key and the authentication information generation parameters;

[0520] The second key is generated based on the shared key and the second key generation information, and the first authentication information is generated based on the second key and the authentication information generation parameters.

[0521] In some embodiments, the target challenge information includes the first challenge information and the second challenge information;

[0522] Wherein, the first key generation information and / or the identifier generation parameters include the first challenge information, and the second key generation information and / or the authentication information generation parameters include the second challenge information; or,

[0523] The first key generation information and / or the identifier generation parameters include the first challenge information and the second challenge information, and the second key generation information and / or the authentication information generation parameters contain either the first challenge information or the second challenge information; or...

[0524] The first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

[0525] In some embodiments, the first key generation information and / or the identifier generation parameters include at least one of the first authentication information and the first purpose information, and the second key generation information and / or the authentication information generation parameters include at least the target challenge information; or...

[0526] The first key generation information and / or the identifier generation parameters include at least the target challenge information, and the second key generation information and / or the authentication information generation parameters include at least one of the first identifier information and the second purpose information; or...

[0527] The first key generation information and / or the identifier generation parameters include at least the target challenge information and the second identifier information of the first device, while the second key generation information and / or the authentication information generation parameters do not include the second identifier information of the first device; or...

[0528] The first key generation information and / or the identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or the authentication information generation parameters at least include the target challenge information and the second identifier information of the first device; or...

[0529] The first key generation information and / or the identifier generation parameters do not include the target challenge information, while the second key generation information and / or the authentication information generation parameters at least include the target challenge information; or...

[0530] The first key generation information and / or the identifier generation parameters include at least the target challenge information, while the second key generation information and / or the authentication information generation parameters do not include the target challenge information.

[0531] In some embodiments, the receiving module 401 is further configured to perform at least one of the following:

[0532] Receive the target challenge information from the first communication node, or receive the target challenge information and the third identification information from the first communication node;

[0533] The target challenge information is received from the second communication node, or the target challenge information and the third identification information are received from the second communication node, wherein the target challenge information, or the target challenge information and the third identification information are received by the second communication node from the first communication node, and the second communication node is a communication node of the network.

[0534] In some embodiments, the first device is an environmental Internet of Things (AIoT) device.

[0535] The communication device 400 provided in this application embodiment can implement the various processes implemented in the method embodiments of Figures 3 to 4 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0536] Referring to Figure 8, when the communication device is a first device or a component of the first device, the communication device 500 includes:

[0537] Receiver module 501 is used to receive the first challenge information from the network;

[0538] The sending module 502 is used to send a second message to the first communication node, the second message including third information; the third information is used by the first communication node to identify and authenticate the first device.

[0539] The third piece of information includes any one of the following:

[0540] The first authentication information is generated based on the shared key and first information between the first device and the first communication node;

[0541] The first identification information is generated based on the shared key between the first device and the first communication node and the second information;

[0542] The network in question is the network where the first communication node is located.

[0543] The first piece of information includes at least one of the following:

[0544] First key generation information, used to generate a first key, which is used to generate the first identification information;

[0545] Identifier generation parameters are used to generate the first identifier information;

[0546] The second piece of information includes at least one of the following:

[0547] Second key generation information, used to generate a second key, which is used to generate the first authentication information;

[0548] The authentication information generation parameters are used to generate the first authentication information.

[0549] In some embodiments, the first key generation information includes at least one of the following:

[0550] This is the first challenge information;

[0551] Primary purpose information;

[0552] The second identification information of the first device.

[0553] In some embodiments, the identifier generation parameters include at least one of the following:

[0554] This is the first challenge information;

[0555] Primary purpose information;

[0556] The second identification information of the first device.

[0557] In some embodiments, the second key generation information includes at least one of the following:

[0558] This is the first challenge information;

[0559] Secondary use information;

[0560] The second identification information of the first device.

[0561] In some embodiments, the authentication information generation parameters include at least one of the following:

[0562] This is the first challenge information;

[0563] Secondary use information;

[0564] The second identification information of the first device.

[0565] In some embodiments, the first purpose information and the second purpose information are predefined.

[0566] In some embodiments, the communication device 500 further includes a processing module for performing any one of the following:

[0567] The first identification information is generated based on the shared key and the identification generation parameters;

[0568] The first key is generated based on the shared key and the first key generation information, and the first identifier information is generated based on the first key and the identifier generation parameters;

[0569] The first authentication information is generated based on the shared key and the authentication information generation parameters;

[0570] The second key is generated based on the shared key and the second key generation information, and the first authentication information is generated based on the second key and the authentication information generation parameters.

[0571] In some embodiments, the first device is an environmental Internet of Things (AIoT) device.

[0572] The communication device 500 provided in this application embodiment can implement the various processes implemented in the method embodiments of Figures 5 to 6 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0573] Referring to Figure 9, when the communication device is a first communication node or a component within the first communication node, the communication device 600 includes:

[0574] The sending module 601 is used to send target challenge information, or the first communication node sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information;

[0575] The receiving module 602 is configured to receive a first message from the first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device;

[0576] The processing module 603 is configured to identify the first device based on the first identification information, or to identify the first device based on the first identification information and verify the first authentication information based on the second authentication information associated with the first device;

[0577] The third identification information is generated based on the shared key and first information between the first device and the first communication node, and the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following:

[0578] First key generation information, used to generate a first key, which is used to generate the third identification information;

[0579] The identifier generation parameters are used to generate this third identifier information;

[0580] The second piece of information includes at least one of the following:

[0581] Second key generation information, used to generate a second key, which is used to generate the second authentication information;

[0582] The authentication information generation parameters are used to generate this second authentication information.

[0583] In some embodiments, the first key generation information includes at least one of the following:

[0584] At least one of the first challenge information and the second challenge information;

[0585] Primary purpose information;

[0586] The second identification information of the first device;

[0587] This is the second authentication information.

[0588] In some embodiments, the identifier generation parameters include at least one of the following:

[0589] At least one of the first challenge information and the second challenge information;

[0590] Primary purpose information;

[0591] The second identification information of the first device;

[0592] This is the second authentication information.

[0593] In some embodiments, the second key generation information includes at least one of the following:

[0594] At least one of the first challenge information and the second challenge information;

[0595] Secondary use information;

[0596] The second identification information of the first device;

[0597] This third identification information.

[0598] In some embodiments, the authentication information generation parameters include at least one of the following:

[0599] At least one of the first challenge information and the second challenge information;

[0600] Secondary use information;

[0601] The second identification information of the first device;

[0602] This third identification information.

[0603] In some embodiments, the processing module 603 is further configured to perform at least one of the following:

[0604] The third identification information is generated based on the shared key and the identification generation parameters;

[0605] The first key is generated based on the shared key and the first key generation information, and the third identification information is generated based on the first key and the identification generation parameters;

[0606] The second authentication information is generated based on the shared key and the authentication information generation parameters;

[0607] The second key is generated based on the shared key and the second key generation information, and the second authentication information is generated based on the second key and the authentication information generation parameters;

[0608] The third identification information is used by the first communication node to identify the first device by comparing the first identification information and the third identification information.

[0609] In some embodiments, the target challenge information includes the first challenge information and the second challenge information;

[0610] Wherein, the first key generation information and / or the identifier generation parameters include the first challenge information, and the second key generation information and / or the authentication information generation parameters include the second challenge information; or,

[0611] The first key generation information and / or the identifier generation parameters include the first challenge information and the second challenge information, and the second key generation information and / or the authentication information generation parameters contain either the first challenge information or the second challenge information; or...

[0612] The first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

[0613] In some embodiments, the first key generation information and / or the identifier generation parameters include at least one of the first authentication information and the first purpose information, and the second key generation information and / or the authentication information generation parameters include at least the target challenge information; or...

[0614] The first key generation information and / or the identifier generation parameters include at least the target challenge information, and the second key generation information and / or the authentication information generation parameters include at least one of the first identifier information and the second purpose information; or...

[0615] The first key generation information and / or the identifier generation parameters include at least the target challenge information and the second identifier information of the first device, while the second key generation information and / or the authentication information generation parameters do not include the second identifier information of the first device; or...

[0616] The first key generation information and / or the identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or the authentication information generation parameters at least include the target challenge information and the second identifier information of the first device; or...

[0617] The first key generation information and / or the identifier generation parameters do not include the target challenge information, while the second key generation information and / or the authentication information generation parameters at least include the target challenge information; or...

[0618] The first key generation information and / or the identifier generation parameters include at least the target challenge information, while the second key generation information and / or the authentication information generation parameters do not include the target challenge information.

[0619] In some embodiments, the first device is an environmental Internet of Things (AIoT) device.

[0620] The communication device 600 provided in this application embodiment can implement the various processes implemented in the method embodiments of FIG3 to FIG4 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0621] Referring to Figure 10, when the communication device is a first communication node or a component of the first communication node, the communication device 700 includes:

[0622] Sending module 701 is used to send the first challenge information;

[0623] The receiving module 702 is configured to receive a second message from the first device, the second message including third information;

[0624] Processing module 703 is used to identify and authenticate the first device based on the third information;

[0625] The third piece of information includes any one of the following:

[0626] The first authentication information is generated based on the shared key and first information between the first device and the first communication node;

[0627] The first identification information is generated based on the shared key between the first device and the first communication node and the second information;

[0628] The first piece of information includes at least one of the following:

[0629] First key generation information, used to generate a first key, which is used to generate the first identification information;

[0630] Identifier generation parameters are used to generate the first identifier information;

[0631] The second piece of information includes at least one of the following:

[0632] Second key generation information, used to generate a second key, which is used to generate the first authentication information;

[0633] Authentication information generation parameters are used to generate the first authentication information;

[0634] In some embodiments, the first key generation information includes at least one of the following:

[0635] This is the first challenge information;

[0636] Primary purpose information;

[0637] The second identification information of the first device.

[0638] In some embodiments, the identifier generation parameters include at least one of the following:

[0639] This is the first challenge information;

[0640] Primary purpose information;

[0641] The second identification information of the first device.

[0642] In some embodiments, the second key generation information includes at least one of the following:

[0643] This is the first challenge information;

[0644] Secondary use information;

[0645] The second identification information of the first device.

[0646] In some embodiments, the authentication information generation parameters include at least one of the following:

[0647] This is the first challenge information;

[0648] Secondary use information;

[0649] The second identification information of the first device.

[0650] In some embodiments, the first purpose information and the second purpose information are predefined.

[0651] In some embodiments, the processing module 703 is further configured to perform any of the following:

[0652] Generate third identification information based on the shared key and the identification generation parameters;

[0653] The first key is generated based on the shared key and the first key generation information, and the third identification information is generated based on the first key and the identification generation parameters;

[0654] Generate second authentication information based on the shared key and the authentication information generation parameters;

[0655] The second key is generated based on the shared key and the second key generation information, and the second authentication information is generated based on the second key and the authentication information generation parameters;

[0656] The third identification information is used by the first communication node to identify and authenticate the first device by comparing the third information and the third identification information; or the second authentication information is used by the first communication node to identify and authenticate the first device by comparing the third information and the second authentication information.

[0657] In some embodiments, the first device is an environmental Internet of Things (AIoT) device.

[0658] The communication device 700 provided in this application embodiment can implement the various processes implemented in the method embodiments of FIG5 to FIG6 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0659] As shown in Figure 11, this application embodiment also provides a communication device 800, including a processor 801 and a memory 802. The memory 802 stores a program or instructions that can run on the processor 801. For example, when the communication device 800 is a terminal, the program or instructions executed by the processor 801 implement the steps executed by the first device in the method embodiments of Figures 3 to 6, and achieve the same technical effect. When the communication device 800 is a network-side device, the program or instructions executed by the processor 801 implement the steps executed by the first communication node or the second communication node in the method embodiments of Figures 3 to 6, and achieve the same technical effect. To avoid repetition, this will not be described again here.

[0660] This application also provides a terminal, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps in the method embodiments shown in Figures 3 to 6. This terminal embodiment corresponds to the above-described terminal-side method embodiments, and all implementation processes and methods of the above-described method embodiments can be applied to this terminal embodiment and achieve the same technical effect. The terminal can be the communication device 400 shown in Figure 7 or the communication device 500 shown in Figure 8. Specifically, Figure 12 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of this application.

[0661] The terminal 900 includes, but is not limited to, at least some of the following components: radio frequency unit 901, network module 902, audio output unit 903, input unit 904, sensor 905, display unit 906, user input unit 907, interface unit 908, memory 909, and processor 910.

[0662] Those skilled in the art will understand that the terminal 900 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to the processor 910 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in Figure 12 does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0663] It should be understood that, in this embodiment, the input unit 904 may include a graphics processor 9041 and a microphone 9042. The graphics processor 9041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 906 may include a display panel 9061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 907 includes at least one of a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 may include a touch detection device and a touch controller. Other input devices 9072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.

[0664] In this embodiment, after receiving downlink data from a network-side device (e.g., a first communication node or a second communication node), the radio frequency unit 901 can transmit it to the processor 910 for processing; additionally, the radio frequency unit 901 can send uplink data to the network-side device. Typically, the radio frequency unit 901 includes, but is not limited to, an antenna, amplifier, transceiver, coupler, low-noise amplifier, duplexer, etc.

[0665] The memory 909 can be used to store software programs or instructions, as well as various data. The memory 909 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 909 may include volatile memory or non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 909 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.

[0666] Processor 910 may include one or more processing units; optionally, processor 910 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 910.

[0667] In some implementations, the radio frequency unit 901 is used to receive target challenge information from the network, or to receive target challenge information and third identification information from the network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; and to send a first message to a first communication node, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device;

[0668] Wherein, the first identification information is generated by the first device based on the shared key and the first information between the first device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the first device based on the shared key and the second information;

[0669] Among them, the network is the network where the first communication node is located;

[0670] The first piece of information includes at least one of the following:

[0671] First key generation information, used to generate a first key, the first key is used to generate first identification information;

[0672] Identifier generation parameters are used to generate the first identifier information;

[0673] The second piece of information includes at least one of the following:

[0674] Second key generation information is used to generate a second key, and the second key is used to generate first authentication information;

[0675] The authentication information generation parameters are used to generate the first authentication information.

[0676] In other implementations, the radio frequency unit 901 is used to receive first challenge information from the network; and to send a second message to the first communication node, the second message including third information; the third information is used by the first communication node to identify and authenticate the first device;

[0677] The third piece of information includes any one of the following:

[0678] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0679] The first identification information is generated based on the shared key between the first device and the first communication node and the second information;

[0680] Among them, the network is the network where the first communication node is located;

[0681] The first piece of information includes at least one of the following:

[0682] First key generation information, used to generate a first key, the first key is used to generate first identification information;

[0683] Identifier generation parameters are used to generate the first identifier information;

[0684] The second piece of information includes at least one of the following:

[0685] Second key generation information is used to generate a second key, and the second key is used to generate first authentication information;

[0686] The authentication information generation parameters are used to generate the first authentication information.

[0687] It is understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant descriptions of the method embodiments in Figures 3 to 6, and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.

[0688] This application also provides a network-side device, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method embodiments shown in Figures 3 to 6. This network-side device embodiment corresponds to the above-described first communication node or second communication node method embodiments. All implementation processes and methods of the above-described method embodiments can be applied to this network-side device embodiment and can achieve the same technical effects.

[0689] Specifically, this application embodiment also provides a network-side device, which may be the communication device 600 shown in FIG9 or the communication device 700 shown in FIG10. As shown in FIG13, the network-side device 1000 includes: an antenna 1001, a radio frequency device 1002, a baseband device 1003, a processor 1004, and a memory 1005. The antenna 1001 is connected to the radio frequency device 1002. In the uplink direction, the radio frequency device 1002 receives information through the antenna 1001 and sends the received information to the baseband device 1003 for processing. In the downlink direction, the baseband device 1003 processes the information to be transmitted and sends it to the radio frequency device 1002, which processes the received information and then transmits it through the antenna 1001.

[0690] The method executed by the network-side device in the above embodiments can be implemented in the baseband device 1003, which includes a baseband processor.

[0691] The baseband device 1003 may include at least one baseband board, on which multiple chips are disposed, as shown in FIG13. One of the chips is, for example, a baseband processor, which is connected to the memory 1005 via a bus interface to call the program or instructions in the memory 1005 to execute the network-side device operation shown in the above method embodiment.

[0692] The network-side device may also include a network interface 1006, such as a Common Public Radio Interface (CPRI).

[0693] In some implementations, the radio frequency device 1002 is used to transmit target challenge information, or the first communication node transmits target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; and to receive a first message from a first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device;

[0694] The processor 1004 is configured to identify the first device based on the first identification information, or to identify the first device based on the first identification information and to verify the first authentication information based on the second authentication information associated with the first device;

[0695] The third identification information is generated based on the shared key between the first device and the first communication node and the first information, while the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following:

[0696] First key generation information, used to generate the first key, and the first key is used to generate the third identification information;

[0697] Identifier generation parameters are used to generate third-party identifier information;

[0698] The second piece of information includes at least one of the following:

[0699] Second key generation information, used to generate a second key, and the second key is used to generate second authentication information;

[0700] The authentication information generation parameters are used to generate the second authentication information.

[0701] In some other implementations, the radio frequency device 1002 is used to transmit first challenge information; and to receive a second message from the first device, the second message including third information;

[0702] The processor 1004 is used to identify and authenticate the first device based on the third information;

[0703] The third piece of information includes any one of the following:

[0704] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0705] The first identification information is generated based on the shared key between the first device and the first communication node and the second information;

[0706] The first piece of information includes at least one of the following:

[0707] First key generation information, used to generate a first key, the first key is used to generate first identification information;

[0708] Identifier generation parameters are used to generate the first identifier information;

[0709] The second piece of information includes at least one of the following:

[0710] Second key generation information is used to generate a second key, and the second key is used to generate first authentication information;

[0711] The authentication information generation parameters are used to generate the first authentication information.

[0712] In addition, the network-side device 1000 of this application embodiment also includes: a program or instructions stored in the memory 1005 and executable on the processor 1004. The processor 1004 calls the program or instructions in the memory 1005 to execute the methods executed by each module in the communication device shown in FIG9 or FIG10 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.

[0713] Specifically, this application also provides a network-side device. As shown in FIG14, the network-side device 1100 includes a processor 1101, a network interface 1102, and a memory 1103. The network-side device may be the communication device shown in FIG9 or FIG10. The network interface 1102 is, for example, a common public radio interface (CPRI).

[0714] In some implementations, network interface 1102 is used to send target challenge information, or the first communication node sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; and to receive a first message from the first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device;

[0715] The processor 1101 is configured to identify the first device based on the first identification information, or to identify the first device based on the first identification information and verify the first authentication information based on the second authentication information associated with the first device;

[0716] The third identification information is generated based on the shared key between the first device and the first communication node and the first information, and the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following:

[0717] First key generation information is used to generate a first key, and the first key is used to generate the third identification information;

[0718] Identifier generation parameters are used to generate the third identifier information;

[0719] The second information includes at least one of the following:

[0720] Second key generation information, used to generate a second key, the second key being used to generate the second authentication information;

[0721] The authentication information generation parameters are used to generate the second authentication information.

[0722] In some other implementations, network interface 1102 is used to send first challenge information; and to receive a second message from a first device, the second message including third information;

[0723] Processor 1101 is used to identify and authenticate the first device based on the third information;

[0724] The third information includes any one of the following:

[0725] The first authentication information is generated based on the shared key between the first device and the first communication node and the first information.

[0726] The first identification information is generated based on the shared key between the first device and the first communication node and the second information.

[0727] The first information includes at least one of the following:

[0728] First key generation information, used to generate a first key, the first key being used to generate the first identification information;

[0729] Identifier generation parameters are used to generate the first identifier information;

[0730] The second information includes at least one of the following:

[0731] Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information;

[0732] The authentication information generation parameters are used to generate the first authentication information.

[0733] In addition, the network-side device 1100 of this application embodiment also includes: a program or instructions stored in the memory 1103 and executable on the processor 1101. The processor 1101 calls the program or instructions in the memory 1103 to execute the steps performed by each module in the communication device shown in FIG9 or FIG10 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.

[0734] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the method embodiments shown in Figures 3 to 6 above and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0735] The processor mentioned above is either the processor in the terminal described in the above embodiments or the processor in the network-side device. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium may be a non-transient readable storage medium.

[0736] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the method embodiments of Figures 3 to 6 above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0737] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0738] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the method embodiments of Figures 3 to 6 above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0739] This application also provides a communication system, including: a first device and a first communication node, wherein the first device can be used to perform the steps of the wireless communication method described above, and the first communication node can be used to perform the steps of the wireless communication method described above.

[0740] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0741] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of computer software products plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.), and the computer software product includes several instructions to cause the terminal or network-side device to execute the methods described in the various embodiments of this application.

[0742] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.

Claims

1. A wireless communication method, wherein, include: The first device receives target challenge information from the network, or the first device receives target challenge information and third identification information from the network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; The first device sends a first message to the first communication node. The first message includes first identification information and first authentication information. The first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device. Wherein, the first identification information is generated by the first device based on the shared key and the first information between the first device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the first device based on the shared key and the second information; Wherein, the network is the network where the first communication node is located; The first information includes at least one of the following: First key generation information, used to generate a first key, the first key being used to generate the first identification information; Identifier generation parameters are used to generate the first identifier information; The second information includes at least one of the following: Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information; The authentication information generation parameters are used to generate the first authentication information.

2. The method according to claim 1, wherein, The first key generation information and the second key generation information are different; or The identifier generation parameters and the authentication information generation parameters are different; or The parameters for generating the first key and the authentication information are different; or The second key generation information is different from the identifier generation parameters.

3. The method according to claim 1 or 2, wherein, The first key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The first authentication information; And / or, the identifier generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The first authentication information; And / or, the second key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The first identification information; And / or, the authentication information generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The first identification information.

4. The method according to any one of claims 1-3, wherein, The method further includes at least one of the following: The first device generates the first identifier information based on the shared key and the identifier generation parameters; The first device generates the first key based on the shared key and the first key generation information, and generates the first identification information based on the first key and the identification generation parameters; The first device generates the first authentication information based on the shared key and the authentication information generation parameters; The first device generates the second key based on the shared key and the second key generation information, and generates the first authentication information based on the second key and the authentication information generation parameters.

5. The method according to any one of claims 1-4, wherein, The target challenge information includes the first challenge information and the second challenge information; Wherein, the first key generation information and / or the identifier generation parameters include the first challenge information, and the second key generation information and / or the authentication information generation parameters include the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information and the second challenge information, and the second key generation information and / or the authentication information generation parameters include either the first challenge information or the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

6. The method according to claim 3, wherein, The first key generation information and / or the identifier generation parameters include at least one of the first authentication information and the first purpose information, and the second key generation information and / or the authentication information generation parameters include at least the target challenge information; or, The first key generation information and / or the identifier generation parameters include at least the target challenge information, and the second key generation information and / or the authentication information generation parameters include at least one of the first identifier information and the second purpose information; or, The first key generation information and / or the identifier generation parameters include at least the target challenge information and the second identifier information of the first device, while the second key generation information and / or the authentication information generation parameters do not include the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or the authentication information generation parameters at least include the target challenge information and the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the target challenge information, while the second key generation information and / or the authentication information generation parameters at least include the target challenge information; or, The first key generation information and / or the identifier generation parameters include at least the target challenge information, while the second key generation information and / or the authentication information generation parameters do not include the target challenge information.

7. The method according to any one of claims 1-6, wherein, The first device receives target challenge information from the network, or the first device receives target challenge information and third identification information from the network, including: The first device receives the target challenge information from the first communication node, or the first device receives the target challenge information and the third identification information from the first communication node; or The first device receives the target challenge information from the second communication node, or the first device receives the target challenge information and the third identification information from the second communication node, wherein the target challenge information, or the target challenge information and the third identification information, is received by the second communication node from the first communication node, and the second communication node is a communication node of the network.

8. The method according to any one of claims 1-7, wherein, The first device is an environmental Internet of Things (A-IoT) device.

9. A wireless communication method, wherein, include: The first device receives the first challenge information from the network; The first device sends a second message to the first communication node, the second message including third information; The third information is used by the first communication node to identify and authenticate the first device; The third information includes any one of the following: The first authentication information is generated based on the shared key between the first device and the first communication node and the first information. The first identification information is generated based on the shared key between the first device and the first communication node and the second information. Wherein, the network is the network where the first communication node is located; The first information includes at least one of the following: First key generation information, used to generate a first key, the first key being used to generate the first identification information; Identifier generation parameters are used to generate the first identifier information; The second information includes at least one of the following: Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information; The authentication information generation parameters are used to generate the first authentication information.

10. The method according to claim 9, wherein, The first key generation information includes at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the identifier generation parameters include at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the second key generation information includes at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device; And / or, the authentication information generation parameters include at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device.

11. The method according to claim 9 or 10, wherein, The method further includes any one of the following: The first device generates the first identifier information based on the shared key and the identifier generation parameters; The first device generates the first key based on the shared key and the first key generation information, and generates the first identification information based on the first key and the identification generation parameters; The first device generates the first authentication information based on the shared key and the authentication information generation parameters; The first device generates the second key based on the shared key and the second key generation information, and generates the first authentication information based on the second key and the authentication information generation parameters.

12. The method according to any one of claims 9-11, wherein, The first device is an environmental Internet of Things (AIoT) device.

13. A wireless communication method, wherein, include: The first communication node sends target challenge information, or the first communication node sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; The first communication node receives a first message from the first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device; The first communication node identifies the first device based on the first identification information, or identifies the first device based on the first identification information and verifies the first authentication information based on the second authentication information associated with the first device; The third identification information is generated based on the shared key between the first device and the first communication node and the first information, and the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following: First key generation information is used to generate a first key, and the first key is used to generate the third identification information; Identifier generation parameters are used to generate the third identifier information; The second information includes at least one of the following: Second key generation information, used to generate a second key, the second key being used to generate the second authentication information; The authentication information generation parameters are used to generate the second authentication information.

14. The method according to claim 13, wherein, The first key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The second authentication information; And / or, the identifier generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The second authentication information; And / or, the second key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The third identification information; And / or, the authentication information generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The third identification information.

15. The method according to claim 13 or 14, wherein, The method further includes at least one of the following: The first communication node generates the third identification information based on the shared key and the identification generation parameters; The first communication node generates the first key based on the shared key and the first key generation information, and generates the third identification information based on the first key and the identification generation parameters; The first communication node generates the second authentication information based on the shared key and the authentication information generation parameters; The first communication node generates the second key based on the shared key and the second key generation information, and generates the second authentication information based on the second key and the authentication information generation parameters; The third identification information is used by the first communication node to identify the first device by comparing the first identification information and the third identification information.

16. The method according to any one of claims 13-15, wherein, The target challenge information includes the first challenge information and the second challenge information; Wherein, the first key generation information and / or the identifier generation parameters include the first challenge information, and the second key generation information and / or the authentication information generation parameters include the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information and the second challenge information, and the second key generation information and / or the authentication information generation parameters include either the first challenge information or the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

17. The method of claim 14, wherein, The first key generation information and / or the identifier generation parameters include at least one of the first authentication information and the first purpose information, and the second key generation information and / or the authentication information generation parameters include at least the target challenge information; or, The first key generation information and / or the identifier generation parameters include at least the target challenge information, and the second key generation information and / or the authentication information generation parameters include at least one of the first identifier information and the second purpose information; or, The first key generation information and / or the identifier generation parameters include at least the target challenge information and the second identifier information of the first device, while the second key generation information and / or the authentication information generation parameters do not include the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or the authentication information generation parameters at least include the target challenge information and the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the target challenge information, while the second key generation information and / or the authentication information generation parameters at least include the target challenge information; or, The first key generation information and / or the identifier generation parameters include at least the target challenge information, while the second key generation information and / or the authentication information generation parameters do not include the target challenge information.

18. The method according to any one of claims 13-17, wherein, The first device is an environmental Internet of Things (AIoT) device.

19. A wireless communication method, wherein, include: The first communication node sends the first challenge information; The first communication node receives a second message from the first device, the second message including third information; The first communication node identifies and authenticates the first device based on the third information; The third information includes any one of the following: The first authentication information is generated based on the shared key between the first device and the first communication node and the first information. The first identification information is generated based on the shared key between the first device and the first communication node and the second information. The first information includes at least one of the following: First key generation information, used to generate a first key, the first key being used to generate the first identification information; Identifier generation parameters are used to generate the first identifier information; The second information includes at least one of the following: Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information; The authentication information generation parameters are used to generate the first authentication information.

20. The method according to claim 19, wherein, The first key generation information includes at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the identifier generation parameters include at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the second key generation information includes at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device; And / or, the authentication information generation parameters include at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device.

21. The method according to claim 19 or 20, wherein, The method further includes any one of the following: The first communication node generates third identification information based on the shared key and the identification generation parameters; The first communication node generates the first key based on the shared key and the first key generation information, and generates the third identification information based on the first key and the identification generation parameters; The first communication node generates second authentication information based on the shared key and the authentication information generation parameters; The first communication node generates the second key based on the shared key and the second key generation information, and generates the second authentication information based on the second key and the authentication information generation parameters; Wherein, the third identification information is used by the first communication node to identify and authenticate the first device by comparing the third information and the third identification information, or the second authentication information is used by the first communication node to identify and authenticate the first device by comparing the third information and the second authentication information.

22. The method according to any one of claims 19-21, wherein, The first device is an environmental Internet of Things (AIoT) device.

23. A communication device, wherein, The communication device includes: A receiving module is configured to receive target challenge information from a network, or receive target challenge information and third identification information from a network, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; The sending module is used to send a first message to a first communication node. The first message includes first identification information and first authentication information. The first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device. Wherein, the first identification information is generated by the first device based on the shared key and the first information between the first device and the first communication node, or the first identification information is the third identification information, and the first authentication information is generated by the first device based on the shared key and the second information; Wherein, the network is the network where the first communication node is located; The first information includes at least one of the following: First key generation information, used to generate a first key, the first key being used to generate the first identification information; Identifier generation parameters are used to generate the first identifier information; The second information includes at least one of the following: Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information; The authentication information generation parameters are used to generate the first authentication information.

24. The apparatus according to claim 23, wherein, The first key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The first authentication information; And / or, the identifier generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The first authentication information; And / or, the second key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The first identification information; And / or, the authentication information generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The first identification information.

25. The apparatus according to claim 23 or 24, wherein, The apparatus further includes: a processing module for performing at least one of the following: The first identification information is generated based on the shared key and the identification generation parameters; The first key is generated based on the shared key and the first key generation information, and the first identifier information is generated based on the first key and the identifier generation parameters; The first authentication information is generated based on the shared key and the authentication information generation parameters; The second key is generated based on the shared key and the second key generation information, and the first authentication information is generated based on the second key and the authentication information generation parameters.

26. The apparatus according to claim 23, wherein, The target challenge information includes the first challenge information and the second challenge information; Wherein, the first key generation information and / or the identifier generation parameters include the first challenge information, and the second key generation information and / or the authentication information generation parameters include the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information and the second challenge information, and the second key generation information and / or the authentication information generation parameters include either the first challenge information or the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

27. The apparatus according to claim 24, wherein, The first key generation information and / or the identifier generation parameters include at least one of the first authentication information and the first purpose information, and the second key generation information and / or the authentication information generation parameters include the target challenge information; or... The first key generation information and / or the identifier generation parameters include the target challenge information, and the second key generation information and / or the authentication information generation parameters include at least one of the first identifier information and the second purpose information; or, The first key generation information and / or the identifier generation parameters include the target challenge information and the second identifier information of the first device, while the second key generation information and / or the authentication information generation parameters do not include the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or the authentication information generation parameters include the target challenge information and the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the target challenge information, while the second key generation information and / or the authentication information generation parameters include the target challenge information; or... The first key generation information and / or the identifier generation parameters include the target challenge information, while the second key generation information and / or the authentication information generation parameters do not include the target challenge information.

28. A communication device, wherein, The communication device includes: The receiving module is used to receive the first challenge information from the network; A sending module is used to send a second message to a first communication node, the second message including third information; the third information is used by the first communication node to identify and authenticate the first device. The third information includes any one of the following: The first authentication information is generated based on the shared key between the first device and the first communication node and the first information. The first identification information is generated based on the shared key between the first device and the first communication node and the second information. Wherein, the network is the network where the first communication node is located; The first information includes at least one of the following: First key generation information, used to generate a first key, the first key being used to generate the first identification information; Identifier generation parameters are used to generate the first identifier information; The second information includes at least one of the following: Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information; The authentication information generation parameters are used to generate the first authentication information.

29. The apparatus according to claim 28, wherein, The first key generation information includes at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the identifier generation parameters include at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the second key generation information includes at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device; And / or, the authentication information generation parameters include at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device.

30. The apparatus according to claim 28 or 29, wherein, The device further includes a processing module for performing any of the following: The first identification information is generated based on the shared key and the identification generation parameters; The first key is generated based on the shared key and the first key generation information, and the first identifier information is generated based on the first key and the identifier generation parameters; The first authentication information is generated based on the shared key and the authentication information generation parameters; The second key is generated based on the shared key and the second key generation information, and the first authentication information is generated based on the second key and the authentication information generation parameters.

31. A communication device, comprising, in a first communication node, the communication device comprising: A sending module is used to send target challenge information, or a first communication node sends target challenge information and third identification information, wherein the target challenge information includes first challenge information, or the target challenge information includes first challenge information and second challenge information; A receiving module is configured to receive a first message from a first device, the first message including first identification information and first authentication information; the first identification information is used by the first communication node to identify the first device, and the first authentication information is used by the first communication node to authenticate the first device. The processing module is configured to identify the first device based on the first identification information, or to identify the first device based on the first identification information and verify the first authentication information based on the second authentication information associated with the first device; The third identification information is generated based on the shared key between the first device and the first communication node and the first information, and the second authentication information is generated based on the shared key and the second information; wherein the first information includes at least one of the following: First key generation information is used to generate a first key, and the first key is used to generate the third identification information; Identifier generation parameters are used to generate the third identifier information; The second information includes at least one of the following: Second key generation information, used to generate a second key, the second key being used to generate the second authentication information; The authentication information generation parameters are used to generate the second authentication information.

32. The apparatus according to claim 31, wherein, The first key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The second authentication information; And / or, the identifier generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Primary purpose information; The second identification information of the first device; The second authentication information; And / or, the second key generation information includes at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The third identification information; And / or, the authentication information generation parameters include at least one of the following: At least one of the first challenge information and the second challenge information; Secondary use information; The second identification information of the first device; The third identification information.

33. The apparatus according to claim 31 or 32, wherein, The target challenge information includes the first challenge information and the second challenge information; Wherein, the first key generation information and / or the identifier generation parameters include the first challenge information, and the second key generation information and / or the authentication information generation parameters include the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information and the second challenge information, and the second key generation information and / or the authentication information generation parameters include either the first challenge information or the second challenge information; or... The first key generation information and / or the identifier generation parameters include the first challenge information or the second challenge information, and the second key generation information and / or the authentication information generation parameters include the first challenge information and the second challenge information.

34. The apparatus according to claim 32, wherein, The first key generation information and / or the identifier generation parameters include at least one of the second authentication information and the first purpose information, wherein the second key generation information and / or the authentication information generation parameters include the target challenge information; or... The first key generation information and / or the identifier generation parameters include the target challenge information, and the second key generation information and / or the authentication information generation parameters include at least one of the first identifier information and the second purpose information; or, The first key generation information and / or the identifier generation parameters include the target challenge information and the second identifier information of the first device, while the second key generation information and / or the authentication information generation parameters do not include the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the second identifier information of the first device, and the second key generation information and / or the authentication information generation parameters include the target challenge information and the second identifier information of the first device; or... The first key generation information and / or the identifier generation parameters do not include the target challenge information, while the second key generation information and / or the authentication information generation parameters include the target challenge information; or... The first key generation information and / or the identifier generation parameters include the target challenge information, while the second key generation information and / or the authentication information generation parameters do not include the target challenge information.

35. A communication device, wherein, The communication device includes: The sending module is used to send the first challenge information; A receiving module is configured to receive a second message from a first device, the second message including third information; The processing module is used to identify and authenticate the first device based on the third information; The third information includes any one of the following: The first authentication information is generated based on the shared key between the first device and the first communication node and the first information. The first identification information is generated based on the shared key between the first device and the first communication node and the second information. The first information includes at least one of the following: First key generation information, used to generate a first key, the first key being used to generate the first identification information; Identifier generation parameters are used to generate the first identifier information; The second information includes at least one of the following: Second key generation information is used to generate a second key, and the second key is used to generate the first authentication information; The authentication information generation parameters are used to generate the first authentication information.

36. The apparatus according to claim 35, wherein, The first key generation information includes at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the identifier generation parameters include at least one of the following: The first challenge information; Primary purpose information; The second identification information of the first device; And / or, the second key generation information includes at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device; And / or, the authentication information generation parameters include at least one of the following: The first challenge information; Secondary use information; The second identification information of the first device.

37. The apparatus according to claim 35 or 36, wherein, The processing module is also configured to perform any one of the following: Generate third identification information based on the shared key and the identification generation parameters; The first key is generated based on the shared key and the first key generation information, and the third identification information is generated based on the first key and the identification generation parameters; Generate second authentication information based on the shared key and the authentication information generation parameters; The second key is generated based on the shared key and the second key generation information, and the second authentication information is generated based on the second key and the authentication information generation parameters.

38. A communication device, wherein, The device includes a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions being executed by the processor to implement the steps of the wireless communication method as claimed in any one of claims 1 to 8, or the steps of the wireless communication method as claimed in any one of claims 9 to 12, or the steps of the wireless communication method as claimed in any one of claims 13 to 18, or the steps of the wireless communication method as claimed in any one of claims 19 to 22.

39. A readable storage medium, wherein, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the wireless communication method as claimed in any one of claims 1 to 8, or the steps of the wireless communication method as claimed in any one of claims 9 to 12, or the steps of the wireless communication method as claimed in any one of claims 13 to 18, or the steps of the wireless communication method as claimed in any one of claims 19 to 22.