Passive IoT Terminal Access Control for Shared Core Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of ensuring data security for passive terminal devices in a Passive Internet of Things (P-IoT) network, where core network devices are shared among multiple enterprises, as they are not owned by any single enterprise, leading to potential data theft risks.
Innovation Solution
A communication method and apparatus that ensures data security by determining if a passive terminal belongs to a set of shared terminals, allowing operations only from authorized application function network elements, using identifiers and subscription information to verify permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If core network devices are shared among multiple enterprises, then resource utilization and cost efficiency are improved, but data security and access control are worsened
Solution Approach 1:
The patent segments access rights by dividing the core network into multiple access and mobility management network elements, each serving specific enterprises or groups. This segmentation allows different enterprises to have dedicated access paths while sharing the overall network infrastructure, thus maintaining data security while improving resource utilization.
Solution Approach 2:
The patent introduces an access and mobility management network element as an intermediary between terminal devices and the core network. This intermediary verifies authorization information and manages access rights, acting as a mediator that enables secure shared access among multiple enterprises while maintaining individual data security boundaries.
2Ease of manufacture
If passive terminal devices are used across different enterprises, then device cost and power consumption are reduced, but authorization verification and access control become more complex
Solution Approach 1:
The patent implements preliminary action by pre-configuring authorization information in the access and mobility management network element before terminal devices access the network. The network element stores and verifies authorization data in advance, which simplifies the access process for passive terminal devices while maintaining security, reducing both device complexity and verification overhead.
Solution Approach 2:
The patent enables self-service by allowing the access and mobility management network element to autonomously verify authorization information and make access decisions without requiring complex verification protocols from the passive terminal devices. This transfers the verification burden to the network side, simplifying terminal device design while maintaining security.
Data Source
AI summary
This application provides a communication method and apparatus. In the method, a core network receives an operation request for a passive terminal from at least one application function network element, and the core network allows the at least one application function network element to perform an operation on the passive terminal only when determining that the passive terminal belongs to a set of shared terminals. The passive terminal in the set of shared terminals is allowed to be used by the at least one application function network element. According to embodiments of this application, data security can be ensured.


