Core Network Access Control for Shared Passive IoT Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of ensuring data security for passive terminal devices in a Passive Internet of Things (P-IoT) network, where core network devices are shared among multiple enterprises, as they are not owned by any single enterprise, leading to potential data theft risks.
Innovation Solution
A communication method and apparatus that allows core networks to determine if a passive terminal belongs to a set of shared terminals, ensuring that only authorized enterprises can perform operations on these devices by verifying operation requests against subscription and policy information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If core network devices are shared among multiple enterprises, then resource utilization and cost efficiency are improved, but data security and access control are worsened due to potential unauthorized access
Solution Approach 1:
The patent segments access rights by creating a many-to-many mapping relationship between enterprises and passive terminals. Each enterprise is granted access only to specific terminals it is authorized to use, rather than providing universal access to all shared terminals. This segmentation of access permissions resolves the contradiction by maintaining high resource utilization while ensuring data security through granular access control.
Solution Approach 2:
The patent introduces a core network device as an intermediary that mediates between multiple enterprises and shared passive terminals. The core network device maintains subscription information and operation policy information, and performs determination operations to verify whether an enterprise is authorized to perform operations on specific terminals. This intermediary mechanism enables secure shared access without requiring direct trust between enterprises.
2Reliability
If access control verification is performed for each operation request, then data security is improved, but processing time and operational complexity are worsened
Solution Approach 1:
The patent performs preliminary determination of enterprise-terminal authorization relationships when subscription information or operation policy information is updated. The core network device determines in advance which enterprises are authorized to access which terminals and stores this determination result. When operation requests are received, the system only needs to verify against pre-computed authorization relationships rather than performing full verification for each request, reducing processing time while maintaining security.
3Measurement precision
If operation policy information is stored in the core network, then access control precision is improved, but network complexity and information management burden are worsened
Solution Approach 1:
The patent designs the core network device to perform multiple functions: maintaining subscription information, storing operation policy information, determining authorization relationships, and verifying operation requests. By consolidating these functions in a single multi-functional component, the system achieves precise access control without proportionally increasing overall network complexity, as the core network device handles diverse tasks through integrated mechanisms.
Data Source
Figure 1~2(b)
Figure 3
Figure 4
AI summary
This application provides a communication method and apparatus. In the method, a core network receives an operation request for a passive terminal from at least one application function network element, and the core network allows the at least one application function network element to perform an operation on the passive terminal only when determining that the passive terminal belongs to a set of shared terminals. The passive terminal in the set of shared terminals is allowed to be used by the at least one application function network element. According to embodiments of this application, data security can be ensured.