Passive IoT Terminal Access Control for Shared Core Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of ensuring data security for passive terminal devices in a Passive Internet of Things (P-IoT) network, where core network devices are shared among multiple enterprises, as they are not owned by any single enterprise, leading to potential data theft risks.

Innovation Solution

A communication method and apparatus that ensures data security by determining if a passive terminal belongs to a set of shared terminals, allowing operations only from authorized application function network elements, using identifiers and subscription information to verify permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If core network devices are shared among multiple enterprises, then resource utilization and cost efficiency are improved, but data security and access control are worsened

Engineering Contradiction:
Improveresource utilizationVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments access rights by dividing the core network into multiple access and mobility management network elements, each serving specific enterprises or groups. This segmentation allows different enterprises to have dedicated access paths while sharing the overall network infrastructure, thus maintaining data security while improving resource utilization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an access and mobility management network element as an intermediary between terminal devices and the core network. This intermediary verifies authorization information and manages access rights, acting as a mediator that enables secure shared access among multiple enterprises while maintaining individual data security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If passive terminal devices are used across different enterprises, then device cost and power consumption are reduced, but authorization verification and access control become more complex

Engineering Contradiction:
Improvedevice costVSAvoidauthorization verification
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring authorization information in the access and mobility management network element before terminal devices access the network. The network element stores and verifies authorization data in advance, which simplifies the access process for passive terminal devices while maintaining security, reducing both device complexity and verification overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing the access and mobility management network element to autonomously verify authorization information and make access decisions without requiring complex verification protocols from the passive terminal devices. This transfers the verification burden to the network side, simplifying terminal device design while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260107119A1Communication method and communication apparatus
Publication Date: 2026.04.16 HUAWEI TECH CO LTD
  • US20260107119A1 patent drawing
  • US20260107119A1 patent drawing
  • US20260107119A1 patent drawing

AI summary

This application provides a communication method and apparatus. In the method, a core network receives an operation request for a passive terminal from at least one application function network element, and the core network allows the at least one application function network element to perform an operation on the passive terminal only when determining that the passive terminal belongs to a set of shared terminals. The passive terminal in the set of shared terminals is allowed to be used by the at least one application function network element. According to embodiments of this application, data security can be ensured.