WO2016155112A1 - 一种物联网设备的认证方法及终端 - Google Patents

一种物联网设备的认证方法及终端 Download PDF

Info

Publication number
WO2016155112A1
WO2016155112A1 PCT/CN2015/080377 CN2015080377W WO2016155112A1 WO 2016155112 A1 WO2016155112 A1 WO 2016155112A1 CN 2015080377 W CN2015080377 W CN 2015080377W WO 2016155112 A1 WO2016155112 A1 WO 2016155112A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
secure channel
internet
network device
binding relationship
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/080377
Other languages
English (en)
French (fr)
Inventor
张云飞
郑倩
雷艺学
张晨璐
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Publication of WO2016155112A1 publication Critical patent/WO2016155112A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present invention relates to the field of Internet of Things technologies, and in particular, to an authentication method and terminal for an Internet of Things device.
  • IoT devices or Machine Type Communication (MTC) devices
  • MTC Machine Type Communication
  • Attack technologies that have appeared on the Internet, such as distributed denial of service (Distributed Denial of Service, DDoS), certificate theft, etc., may appear on the Internet of Things.
  • DDoS distributed Denial of Service
  • certificate theft etc.
  • An effective solution is to develop universal identity authentication for IoT devices.
  • the IoT device authenticates the device through the SMS registration process, and the security architecture of the MTC device based on the SMS registration is shown in FIG. 1 .
  • the Home Subscriber Server (HSS)/Home Location Register (HLR) needs to store the user information of each MTC device.
  • HSS Home Subscriber Server
  • HLR Home Location Register
  • the user identification of the MTC device is the mobile station international subscriber identity (Mobile Subscriber International) ISDN number, MSISDN) has a 16-bit length limit in the international standard, so the address space of the MSISDN may not be sufficient to support future massive MTC devices.
  • MSISDN Mobile Subscriber International ISDN number
  • the invention provides an authentication method and a terminal for an Internet of Things device to realize lightweight authentication of an Internet of Things device.
  • an authentication method for an Internet of Things device comprising:
  • the terminal When the terminal receives the authentication request of the IoT device, the terminal confirms the binding relationship between the terminal and the IoT device, and confirms the first secure channel of the IoT device and the terminal. Whether it has been established;
  • the terminal sends a request for establishing a second secure channel between the Internet of Things device and the network device to the network device, so that the network device queries the machine type communication.
  • the interworking function MTC-IWF stores the binding relationship to confirm whether the second secure channel is established;
  • the terminal receives a setup response of the second secure channel sent by the network device;
  • the terminal sends an authentication response to the IoT device.
  • a terminal including:
  • a confirmation unit configured to confirm whether the first secure channel of the IoT device and the terminal is established by querying whether a binding relationship between the storage terminal and the IoT device is received when receiving an authentication request of the IoT device ;
  • a first sending unit configured to send, to the network device, a request for establishing a second secure channel between the IoT device and the network device, if the first secure channel is established, to enable the network device Querying whether the machine type communication interworking function MTC-IWF stores the binding relationship to confirm whether the second secure channel is established;
  • a receiving unit configured to receive a setup response of the second secure channel sent by the network device, if it is confirmed that the second secure channel is established;
  • a second sending unit configured to send an authentication response to the IoT device.
  • the authentication method and the terminal of the Internet of Things device provided by the present invention can reduce the storage and synchronization cost of the network side background by binding the IoT device to the intelligent terminal for authentication of the access network, and also solve the problem.
  • the problem of insufficient identification of networked devices enables a lightweight security authentication process for accessing mobile networks of IoT devices.
  • FIG. 1 is a schematic diagram of a security architecture of an MTC device based on short message registration in the prior art
  • FIG. 2 is a schematic flowchart of an authentication method of an Internet of Things device according to an embodiment of the present invention
  • FIG. 3 is a schematic flowchart of another method for authenticating an Internet of Things device according to an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of a security architecture for an MTC device to be bound to an intelligent terminal for authentication according to an embodiment of the present invention
  • FIG. 5 is a schematic structural diagram of a terminal according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic structural diagram of another terminal according to an embodiment of the present invention.
  • the present invention is applicable to an authentication scenario when an IoT device accesses a mobile network.
  • the present invention can reduce the storage and synchronization cost of the network side background by binding the IoT device to the intelligent terminal for authentication of the access network, and also solves the problem.
  • the problem of insufficient identification of networked devices enables a lightweight security authentication process for accessing mobile networks of IoT devices.
  • the terminal involved in the present invention may be a terminal device that can access the network, such as a mobile phone or a tablet computer.
  • FIG. 2 is a schematic flowchart of a method for authenticating an Internet of Things device according to an embodiment of the present invention. The method includes the following steps:
  • Step S101 when the terminal receives the authentication request of the Internet of Things device, the terminal confirms the binding relationship between the terminal and the Internet of Things device, and confirms the first security of the Internet of Things device and the terminal. Whether the channel has been established.
  • IoT devices must first be authenticated before accessing the mobile network.
  • one or more Internet of Things devices are bound by the terminal, and the binding relationship between the terminal and the Internet of Things device is stored.
  • the terminal receives the authentication request of the IoT device, and confirms whether the storage device and the IoT device are bound to each other, and confirms whether the first secure channel of the IoT device and the terminal has been established; if the IoT device is not connected to the terminal If the relationship is determined, it is confirmed that the IoT device cannot perform security authentication through the terminal.
  • Step S102 if it is confirmed that the first secure channel is established, the terminal sends a request for establishing a second secure channel between the Internet of Things device and the network device to the network device, so that the network device queries Whether the machine type communication interworking function MTC-IWF stores the binding relationship to confirm whether the second secure channel has been established.
  • the terminal requests the network device to establish a second secure channel between the IoT device and the network device, so that the IoT device can actually authenticate through the access network.
  • the communication between the terminal and the network device belongs to the prior art, except that the content that the terminal communicates with the network device here is to confirm whether the network device allows the IoT device to access the network through the terminal.
  • the basis for confirmation is the binding relationship between the terminal and the Internet of Things device stored in the Machine Type Communication-Inter Working Function (MTC-IWF). If the network device receives the setup request of the second secure channel, the MTC-IWF queries whether the binding relationship is stored, and then responds to the terminal to confirm whether the second secure channel is established.
  • MTC-IWF Machine Type Communication-Inter Working Function
  • the network side background needs to store the user information and the subscription data of each IoT device one by one.
  • the identifier of the Internet of Things device such as the mobile device international
  • IMEI International Mobile Equipment Identity
  • USIM Universal Subscriber Identity Module
  • the IoT device binding terminal is no longer limited by the length of the user identifier of the IoT device, the IoT device under the terminal can adopt any identifier, and the identifiers of the IoT devices of each terminal can be the same or different.
  • Step S103 If it is confirmed that the second secure channel is established, the terminal receives a setup response of the second secure channel sent by the network device.
  • the terminal receives a response message sent by the network device requesting to establish a second secure channel, and confirms that the second secure channel is established.
  • Step S104 The terminal sends an authentication response to the Internet of Things device.
  • the terminal If the terminal confirms that the first secure channel and the second secure channel of the IoT device have been established, it is considered to be a licensed secure communication link, and the Internet of Things device is also determined to be a secure communication device and can ring. Should be an authentication request for IoT devices.
  • the authentication method of the Internet of Things device provided by the embodiment of the present invention, by binding the IoT device to the intelligent terminal for authentication of the access network, the storage and synchronization cost of the network side background can be reduced, and the Internet of Things device is also solved.
  • the problem of insufficient identification can realize the lightweight security authentication process of the IoT device accessing the mobile network.
  • FIG. 3 is a schematic flowchart of another method for authenticating an Internet of Things device according to an embodiment of the present invention. The method includes the following steps:
  • Step S201 The terminal establishes a binding relationship between the terminal and at least one IoT device.
  • a one-to-one or one-to-many simple binding relationship is established by using preset software according to the identifier of the IoT device, such as IMEI, the identifier of the terminal, such as IMEI, and the Universal Subscriber Identity Module (USIM). Or mapping relationship.
  • IMEI the identifier of the IoT device
  • IMEI the identifier of the terminal
  • USIM Universal Subscriber Identity Module
  • FIG. 4 a schematic diagram of a security architecture in which an MTC device is bound to an intelligent terminal for authentication is provided, and the smart terminal is bound to the MTC device 1 to the MTC device N.
  • Step S202 the terminal stores the binding relationship.
  • the terminal may store the binding relationship locally or in the cloud, and is not limited herein.
  • Step S203 the terminal sends a binding relationship establishment or update message to the network device, so that the network device sends the binding relationship to the MTC-IWF, so that the MTC-IWF establishes or updates the Binding relationship between the terminal and the IoT device.
  • the network side also needs to store a simple binding relationship between the IoT device and the terminal, as a basis for authenticating the access network of the IoT device, and the binding relationship can be stored or managed by the MTC-IWF.
  • the MTC-IWF may be an independent functional entity or a functional module dispersed in each network device.
  • the security architecture includes two network devices, namely, a Mobility Management Entity (MME) and an MTC Application Server (MTC Server). Both the MME and the MTC application server are connected to the MTC-IWF.
  • MME Mobility Management Entity
  • MTC Server MTC Application Server
  • Both the MME and the MTC application server are connected to the MTC-IWF.
  • the binding relationship may be received and parsed by the MME through the path 1 and then forwarded to the MTC-IWF.
  • the binding relationship may be received and parsed by the MTC application server through the path 2, and then forwarded to the MTC-IWF.
  • mapping relationship table or the mapping table of the terminal already exists in the MTC-IWF, the mapping relationship or the binding relationship of the mapping table needs to be updated.
  • Step S204 when the terminal receives the authentication request of the Internet of Things device, the terminal confirms the binding relationship between the terminal and the IoT device, and confirms that the Internet of Things device and the terminal are Whether a secure channel has been established.
  • step S101 is the same as step S101 of the foregoing embodiment, and details are not described herein again.
  • Step S205 if it is confirmed that the first secure channel is established, the terminal sends a request for establishing the second secure channel to the core network device, so that the core network device queries the machine type communication interworking function MTC- Whether the IWF stores the binding relationship to confirm whether the second secure channel is established, and the establishment request is the RRC message or the non-RRC resource layer message.
  • step S205 may be: if it is confirmed that the first secure channel has been established, the terminal sends a setup request of the second secure channel to a machine type communication MTC application server, so that the MTC application The server queries whether the machine type communication interworking function MTC-IWF stores the binding relationship to confirm whether the second secure channel has been established, and the establishment request is an application layer message.
  • the establishment of the second secure channel can be performed by path 1 or path 2 of FIG.
  • a second secure channel is established through path 1, where the network device is a core network.
  • the device such as the MME, optionally, before the terminal communicates with the core network device, if the terminal is disconnected in the network, the existing network authentication mechanism is used to request access to the mobile network, and the network side agrees After the terminal's access request, it becomes the connected state.
  • the terminal After confirming the connection state between the terminal and the core network device, the terminal sends a second secure channel establishment request to the core network device.
  • the establishment request may be a non-access stratum (NAS) message or wireless. Resource Control (RRC) message.
  • NAS non-access stratum
  • RRC Resource Control
  • the MME identifies, by the MTC-IWF entity, whether the relationship between the intelligent terminal and its subordinate MTC device exists, and if so, gives a response to the smart terminal as the relay access network.
  • the binding relationship between the terminal and the Internet of Things device is visible to the network side, so that the network device can distinguish the Internet of Things device to implement classification management and accounting.
  • a second secure channel is established through path 2, where the network device is an MTC application server.
  • the terminal sends a setup request of the second secure channel to the MTC application server.
  • the setup request is an application layer message.
  • the MTC application server identifies whether the smart terminal and its dependent MTC device relationship exist through the MTC-IWF entity, and if yes, gives a response to the smart terminal as the relay access network.
  • the binding relationship between the terminal and the Internet of Things device is invisible to the network side, and the smart terminal is always visible to the network side, and the intelligent terminal is responsible for the traffic consumption of all the Internet of Things devices.
  • Step S206 if it is confirmed that the second secure channel is established, the terminal receives a setup response of the second secure channel sent by the network device.
  • step S103 is the same as step S103 of the foregoing embodiment, and details are not described herein again.
  • Step S207 The terminal sends an authentication response to the IoT device.
  • step S104 This step is the same as step S104 of the foregoing embodiment, and details are not described herein again.
  • the authentication method of the Internet of Things device provided by the embodiment of the present invention, by binding the IoT device to the intelligent terminal for authentication of the access network, the storage and synchronization cost of the network side background can be reduced, and the Internet of Things device is also solved.
  • the problem of insufficient identification can realize the lightweight security authentication process of the IoT device accessing the mobile network.
  • An authenticator of an Internet of Things device provided by an embodiment of the present invention is implemented below with reference to FIG. 5-6.
  • the terminal of the law is described in detail:
  • FIG. 5 is a schematic structural diagram of a terminal according to an embodiment of the present invention.
  • the terminal 1000 includes:
  • the confirmation unit 11 is configured to confirm, when the terminal receives the authentication request of the Internet of Things device, whether to store the binding relationship between the terminal and the Internet of Things device, and confirm the first security of the Internet of Things device and the terminal. Whether the channel has been established.
  • IoT devices must first be authenticated before accessing the mobile network.
  • one or more Internet of Things devices are bound by the terminal, and the binding relationship between the terminal and the Internet of Things device is stored.
  • the terminal receives the authentication request of the IoT device, and confirms whether the storage device and the IoT device are bound to each other, and confirms whether the first secure channel of the IoT device and the terminal has been established; if the IoT device is not connected to the terminal If the relationship is determined, it is confirmed that the IoT device cannot perform security authentication through the terminal.
  • a first sending unit 12 configured to send, to the network device, a request for establishing a second secure channel between the IoT device and the network device, if the first secure channel is established, to enable the network
  • the device queries whether the machine type communication interworking function MTC-IWF stores the binding relationship to confirm whether the second secure channel has been established.
  • the first sending unit 12 requests the network device to establish a second secure channel between the Internet of Things device and the network device, so that the IoT device is truly Authentication through access to the network.
  • the communication between the terminal and the network device belongs to the prior art, except that the content that the terminal communicates with the network device here is to confirm whether the network device allows the IoT device to access the network through the terminal.
  • the basis for confirmation is the binding relationship between the terminal and the Internet of Things device stored in the MTC-IWF. If the network device receives the setup request of the second secure channel, the MTC-IWF queries whether the binding relationship is stored, and then responds to the terminal to confirm whether the second secure channel is established.
  • the network side background needs to store the user information and the subscription data of each IoT device one by one.
  • the identifier of the IoT device such as the IMEI, the terminal, is required.
  • the identifiers such as IMEI and USIM can establish a one-to-one or one-to-many simple binding relationship or mapping relationship.
  • the contract authentication of the terminal and the network device already exists. Therefore, the storage and synchronization costs of the network side background can be reduced.
  • the IoT device is a binding terminal of the IoT device, it is no longer limited by the length of the user identifier of the IoT device, and the IoT device under the terminal can adopt any identifier, and each end
  • the identifiers of the IoT devices on the side may be the same or different.
  • the receiving unit 13 is configured to receive a setup response of the second secure channel sent by the network device, if it is confirmed that the second secure channel is established.
  • the receiving unit 13 receives the response message sent by the network device requesting to establish the second secure channel, and confirms that the second secure channel has been established.
  • the second sending unit 14 is configured to send an authentication response to the IoT device.
  • the terminal If the terminal confirms that the first secure channel and the second secure channel of the IoT device have been established, it is considered to be a licensed secure communication link, and the Internet of Things device is also determined to be a secure communication device and can ring. Should be an authentication request for IoT devices.
  • the terminal by binding the IoT device to the intelligent terminal for authentication of the access network, the storage and synchronization cost of the network side background can be reduced, and the problem of insufficient identification of the Internet of Things device is also solved. Thereby, a lightweight security authentication process of the IoT device accessing the mobile network can be realized.
  • FIG. 6 is a schematic structural diagram of another terminal according to an embodiment of the present invention.
  • the terminal 2000 includes:
  • the establishing unit 21 is configured to establish a binding relationship between the terminal and the at least one IoT device.
  • a one-to-one or one-to-many simple binding relationship or mapping relationship is established by the preset software according to the identifier of the IoT device, such as the IMEI, the identifier of the terminal, such as the IMEI, the USIM, and the like.
  • the identifier of the IoT device such as the IMEI
  • the identifier of the terminal such as the IMEI, the USIM, and the like.
  • FIG. 4 a schematic diagram of a security architecture in which an MTC device is bound to an intelligent terminal for authentication is provided, and the smart terminal is bound to the MTC device 1 to the MTC device N.
  • the storage unit 22 is configured to store the binding relationship.
  • the storage unit 22 can store the binding relationship locally or in the cloud, and is not limited herein.
  • the third sending unit 23 is configured to send a binding relationship establishment or update message to the network device, so that the network device sends the binding relationship to the MTC-IWF, so that the MTC-IWF is established or updated. Binding relationship between the terminal and the Internet of Things device.
  • the network side also needs to store a simple binding relationship between the IoT device and the terminal, as a basis for authenticating the access network of the IoT device, and the binding relationship can be stored or managed by the MTC-IWF.
  • the MTC-IWF can be an independent functional entity or can be dispersed in various network settings.
  • the function module in the standby.
  • the security architecture includes two types of network devices, namely, an MME and an MTC application server, and the MME and the MTC application server are both connected to the MTC-IWF, and the terminal can receive and parse the binding relationship by the MME through the path 1. After being forwarded to the MTC-IWF, the binding relationship may be received and parsed by the MTC application server through the path 2, and then forwarded to the MTC-IWF.
  • mapping relationship table or the mapping table of the terminal already exists in the MTC-IWF, the mapping relationship or the binding relationship of the mapping table needs to be updated.
  • the confirmation unit 24 is configured to confirm, when the terminal receives the authentication request of the Internet of Things device, whether to store the binding relationship between the terminal and the Internet of Things device, and confirm the number of the Internet of Things device and the terminal Whether a secure channel has been established.
  • the function of the confirmation unit 24 is the same as that of the confirmation unit 11 of the previous embodiment, and details are not described herein again.
  • the first sending unit 25 is configured to: if it is confirmed that the first secure channel is established, send the second secure channel establishment request to the core network device, so that the core network device queries the machine type communication interworking function. Whether the MTC-IWF stores the binding relationship to confirm whether the second secure channel is established, and the establishment request is the RRC message or the non-RRC resource layer message.
  • the first sending unit 25 may be further configured to: if it is confirmed that the first secure channel is established, send a setup request of the second secure channel to a machine type communication MTC application server, so that the MTC is The application server queries whether the machine type communication interworking function MTC-IWF stores the binding relationship to confirm whether the second secure channel has been established, and the establishment request is an application layer message.
  • the establishment of the second secure channel can be performed by path 1 or path 2 of FIG.
  • the second secure channel is established through the path 1.
  • the network device is a core network device, such as an MME.
  • the terminal is disconnected in the network before the terminal communicates with the core network device.
  • the existing network authentication mechanism is used to request access to the mobile network, and the network side becomes a connected state after agreeing to the terminal's access request.
  • the terminal sends a second secure channel establishment request to the core network device.
  • the establishment request may be a non-access layer message or a radio resource control (Radio Resource Control, RRC). ) message.
  • RRC Radio Resource Control
  • the MME identifies, by the MTC-IWF entity, whether the relationship between the intelligent terminal and its subordinate MTC device exists. If it does, it gives a response to the smart terminal as a relay access network.
  • the binding relationship between the terminal and the Internet of Things device is visible to the network side, so that the network device can distinguish the Internet of Things device to implement classification management and accounting.
  • a second secure channel is established through path 2, where the network device is an MTC application server.
  • the terminal sends a setup request of the second secure channel to the MTC application server.
  • the setup request is an application layer message.
  • the MTC application server identifies whether the smart terminal and its dependent MTC device relationship exist through the MTC-IWF entity, and if yes, gives a response to the smart terminal as the relay access network.
  • the binding relationship between the terminal and the Internet of Things device is invisible to the network side, and the smart terminal is always visible to the network side, and the intelligent terminal is responsible for the traffic consumption of all the Internet of Things devices.
  • the receiving unit 26 is configured to: if it is confirmed that the second secure channel is established, receive a setup response of the second secure channel sent by the network device.
  • the function of the receiving unit 26 is the same as that of the receiving unit 13 of the foregoing embodiment, and details are not described herein again.
  • the second sending unit 27 is configured to send an authentication response to the IoT device.
  • the function of the second sending unit 27 is the same as that of the second sending unit 14 of the foregoing embodiment, and details are not described herein again.
  • the terminal by binding the IoT device to the intelligent terminal for authentication of the access network, the storage and synchronization cost of the network side background can be reduced, and the problem of insufficient identification of the Internet of Things device is also solved. Thereby, a lightweight security authentication process of the IoT device accessing the mobile network can be realized.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a computer.
  • the computer readable medium may include a random access memory (RAM), a read-only memory (ROM), and an electrically erasable programmable read-only memory (Electrically Erasable Programmable).
  • EEPROM Electrically Error Read-Only Memory
  • CD-ROM Compact Disc Read-Only Memory
  • Any connection may suitably be a computer readable medium.
  • the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL), or wireless technologies such as infrared, radio, and microwave, Then coaxial cable, fiber optic cable, twisted pair, DSL or wireless technologies such as infrared, wireless and microwave are included in the fixing of the associated medium.
  • DSL Digital Subscriber Line
  • a disk and a disc include a compact disc (CD), a laser disc, a compact disc, a digital versatile disc (DVD), a floppy disk, and a Blu-ray disc, wherein the disc is usually magnetically copied, and the disc is The laser is used to optically replicate the data. Combinations of the above should also be included within the scope of the computer readable media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种物联网设备的认证方法及终端。其中的方法包括:当终端接收到物联网设备的认证请求时,终端通过查询是否存储终端与物联网设备的绑定关系,确认物联网设备与终端的第一安全通道是否已建立;若确认第一安全通道已建立,则终端向网络设备发送物联网设备与网络设备之间的第二安全通道的建立请求;若确认第二安全通道已建立,终端接收网络设备发送的第二安全通道的建立响应;终端向物联网设备发送认证响应。还公开了相应的终端。本发明通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。

Description

一种物联网设备的认证方法及终端
本申请要求于2015年04月03日提交中国专利局,申请号为201510157337.8、发明名称为“一种物联网设备的认证方法及终端”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及物联网技术领域,尤其涉及一种物联网设备的认证方法及终端。
背景技术
伴随着物联网的快速发展,物联网设备即机器类型通信(Machine Type Communication,MTC)设备已经成为一类新的网络安全威胁,曾经出现在互联网上的攻击技术,如分布式拒绝服务(Distributed Denial of Service,DDoS)、证书盗窃等,都可能出现在物联网上,例如数以千计的烤箱对InfoWord网站发动大规模DDoS攻击,致使网站的后台服务瘫痪。一个有效的解决途径是对物联网设备展开普遍的身份认证。
在第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)MTC网络架构中,物联网设备通过短信注册流程认证设备,MTC设备基于短信注册的安全架构如图1所示。为了对MTC设备的身份进行识别,防止非法的设备接入移动通信网络,后台归属用户服务器(Home Subscriber Server,HSS)/归属位置寄存器(Home Location Register,HLR)需要存储每个MTC设备的用户信息和签约数据,随着物联网技术的日趋发展和成熟,应用领域的多元化,MTC设备数量将出现爆炸性增长发展到百亿数量级,甚至比现在智能终端数量还要多几个量级,数以百亿数量级的设备数量对于后台的存储和同步是很大的成本。且MTC设备的用户标识即移动台国际用户识别码(Mobile Subscriber International  ISDN number,MSISDN)在国际标准中有16位长度限制,因此MSISDN的地址空间可能不足以支持未来海量的MTC设备。
因此,如何实现物联网设备的轻量级认证过程,是目前需要解决的问题。
发明内容
本发明提供了一种物联网设备的认证方法及终端,以实现物联网设备的轻量级认证。
一方面,提供了一种物联网设备的认证方法,所述方法包括:
当所述终端接收到物联网设备的认证请求时,所述终端通过查询是否存储所述终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立;
若确认所述第一安全通道已建立,则所述终端向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,以使所述网络设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立;
若确认所述第二安全通道已建立,所述终端接收所述网络设备发送的第二安全通道的建立响应;
所述终端向所述物联网设备发送认证响应。
另一方面,提供了一种终端,包括:
确认单元,用于当接收到物联网设备的认证请求时,通过查询是否存储终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立;
第一发送单元,用于若确认所述第一安全通道已建立,则向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,以使所述网络设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立;
接收单元,用于若确认所述第二安全通道已建立,接收所述网络设备发送的第二安全通道的建立响应;
第二发送单元,用于向所述物联网设备发送认证响应。
可见,根据本发明提供的一种物联网设备的认证方法及终端,通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为现有技术中的MTC设备基于短信注册的安全架构示意图;
图2为本发明实施例提供的一种物联网设备的认证方法的流程示意图;
图3为本发明实施例提供的另一种物联网设备的认证方法的流程示意图;
图4为本发明实施例提供的MTC设备绑定智能终端进行认证的安全架构示意图;
图5为本发明实施例提供的一种终端的结构示意图;
图6为本发明实施例提供的另一种终端的结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
本发明适用于物联网设备接入移动网络时的认证场景,本发明通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。
本发明所涉及的终端可以是手机、平板电脑等可以接入网络的终端设备。
下面结合图2-图4,对本发明实施例提供的一种物联网设备的认证方法进行详细描述:
请参阅图2,为本发明实施例提供的一种物联网设备的认证方法的流程示意图,该方法包括以下步骤:
步骤S101,当终端接收到物联网设备的认证请求时,所述终端通过查询是否存储所述终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立。
物联网设备在接入移动网络之前,首先要进行认证。本实施例中由终端绑定一个或多个物联网设备,并存储终端与物联网设备的绑定关系。终端接收物联网设备的认证请求,并通过查询是否存储终端与物联网设备的绑定关系,确认物联网设备与终端的第一安全通道是否已建立;若没有存储该物联网设备与终端的绑定关系,则确认该物联网设备不能通过该终端进行安全认证。
步骤S102,若确认所述第一安全通道已建立,则所述终端向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,以使所述网络设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立。
若终端已确认物联网设备与终端的第一安全通道已建立,则终端向网络设备请求建立物联网设备与网络设备之间的第二安全通道,以使物联网设备真正通过接入网络的认证。终端与网络设备的通信属于现有技术,只不过在这里终端与网络设备通信的内容是确认网络设备是否允许物联网设备通过终端接入网络。进行确认的根据是在机器类型通信互通功能(Machine Type Communication-Inter Working Function,MTC-IWF)中存储的终端与物联网设备的绑定关系。若网络设备接收到第二安全通道的建立请求后,在MTC-IWF查询是否存储了该绑定关系,然后向终端进行响应,以确认该第二安全通道是否已建立。
在现有技术中,如图1所示,网络侧后台需要一一存储每个物联网设备的用户信息和签约数据,而在本实施例中,仅需根据物联网设备的标识如移动设备国际身份码(International Mobile Equipment Identity,IMEI)、终端的标识如 IMEI、全球用户识别卡(Universal Subscriber Identity Module,USIM)等建立一对一或一对多的简单的绑定关系或映射关系即可。终端与网络设备的签约认证是已经存在的。因此,可以减少网络侧后台的存储和同步成本。且由于是物联网设备绑定终端,不再受物联网设备的用户标识的长度限制,在该终端下的物联网设备可以采用任意的标识,各个终端的物联网设备的标识可以相同或不同。
步骤S103,若确认所述第二安全通道已建立,所述终端接收所述网络设备发送的第二安全通道的建立响应。
若网络设备确认该第二安全通道已建立,终端接收网络设备发送的请求建立第二安全通道的响应消息,则确认该第二安全通道已建立。
步骤S104,所述终端向所述物联网设备发送认证响应。
若终端确认该物联网设备的第一安全通道和第二安全通道都已经建立,则认为这是一个被许可的安全通信链路,该物联网设备也被判定为一个安全的通信设备,可以响应该物联网设备的认证请求。
根据本发明实施例提供的一种物联网设备的认证方法,通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。
请参阅图3,为本发明实施例提供的另一种物联网设备的认证方法的流程示意图,该方法包括以下步骤:
步骤S201,终端建立所述终端与至少一个物联网设备的绑定关系。
本实施例中通过预置软件根据物联网设备的标识如IMEI、终端的标识如IMEI、全球用户识别卡(Universal Subscriber Identity Module,USIM)等建立一对一或一对多的简单的绑定关系或映射关系。如图4所示的本发明实施例提供的MTC设备绑定智能终端进行认证的安全架构示意图,智能终端与MTC设备1至MTC设备N进行绑定。
步骤S202,所述终端存储所述绑定关系。
该终端可以在本地或者在云端等存储该绑定关系,这里不作限定。
步骤S203,所述终端向网络设备发送绑定关系建立或更新消息,以使所述网络设备将所述绑定关系发送给所述MTC-IWF,以使所述MTC-IWF建立或更新所述终端与所述物联网设备的绑定关系。
网络侧也需存储物联网设备与终端的简单的绑定关系,以作为对物联网设备接入网络进行认证的根据,绑定关系可以由MTC-IWF存储或管理。需要说明的是,MTC-IWF可以是一个独立的功能实体,也可以是分散在各个网络设备中的功能模块。
如图4所示,该安全架构中包括两种网络设备,即:移动管理实体(Mobility Management Entity,MME)和MTC应用服务器(MTC Server),MME和MTC应用服务器都与MTC-IWF连接,终端可以通过路径1将绑定关系由MME接收、解析后转发给MTC-IWF,也可以通过路径2将绑定关系由MTC应用服务器接收、解析后转发给MTC-IWF。
若MTC-IWF中已经存在属于该终端的绑定关系表或映射表,则无需新建,只需要更新该映射表的映射关系或绑定关系即可。
步骤S204,当所述终端接收到物联网设备的认证请求时,所述终端通过查询是否存储所述终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立。
该步骤与前述实施例的步骤S101相同,在此不再赘述。
步骤S205,若确认所述第一安全通道已建立,则所述终端向所述核心网设备发送所述第二安全通道的建立请求,以使所述核心网设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立,所述建立请求为所述无线资源控制层消息或非无线资源控制层消息。
可替换的是,步骤S205也可以是:若确认所述第一安全通道已建立,则所述终端向机器类型通信MTC应用服务器发送所述第二安全通道的建立请求,以使所述MTC应用服务器查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立,所述建立请求为应用层消息。
第二安全通道的建立可以通过如图4的路径1或路径2进行。
作为一种实施方式,通过路径1建立第二安全通道,该网络设备为核心网 设备,如MME等,可选地,在终端与核心网设备通信之前,若终端在网络中处于断开连接状态,则先利用现有的网络鉴权机制请求接入移动网络,在网络侧同意终端的接入请求后变成连接状态。在确认终端与核心网设备之间为连接状态后,终端向核心网设备发送第二安全通道的建立请求,具体的,该建立请求可以是非接入层(Non-Access Stratum,NAS)消息或无线资源控制(Radio Resource Control,RRC)消息。MME通过MTC-IWF实体识别智能终端和它的从属MTC设备关系是否存在,若存在,则给出同意智能终端作为中继接入网络的响应。
需要说明的是,在该实施方式中,终端与物联网设备的绑定关系对网络侧可见,从而使网络设备可以区分物联网设备从而实现分类管控和计费。
作为一种实施方式,通过路径2建立第二安全通道,该网络设备为MTC应用服务器。终端向MTC应用服务器发送第二安全通道的建立请求,具体的,该建立请求为应用层消息。MTC应用服务器通过MTC-IWF实体识别智能终端和它的从属MTC设备关系是否存在,若存在,则给出同意智能终端作为中继接入网络的响应。
需要说明的是,在该实施方式中,终端与物联网设备的绑定关系对网络侧不可见,对网络侧可见的始终是智能终端,由智能终端承担所有物联网设备数据消费的流量。
步骤S206,若确认所述第二安全通道已建立,所述终端接收所述网络设备发送的第二安全通道的建立响应。
该步骤与前述实施例的步骤S103相同,在此不再赘述。
步骤S207,所述终端向所述物联网设备发送认证响应。
该步骤与前述实施例的步骤S104相同,在此不再赘述。
根据本发明实施例提供的一种物联网设备的认证方法,通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。
下面结合图5-图6,对实现本发明实施例提供的一种物联网设备的认证方 法的终端进行详细描述:
请参阅图5,为本发明实施例提供的一种终端的结构示意图,该终端1000包括:
确认单元11,用于当终端接收到物联网设备的认证请求时,通过查询是否存储所述终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立。
物联网设备在接入移动网络之前,首先要进行认证。本实施例中由终端绑定一个或多个物联网设备,并存储终端与物联网设备的绑定关系。终端接收物联网设备的认证请求,并通过查询是否存储终端与物联网设备的绑定关系,确认物联网设备与终端的第一安全通道是否已建立;若没有存储该物联网设备与终端的绑定关系,则确认该物联网设备不能通过该终端进行安全认证。
第一发送单元12,用于若确认所述第一安全通道已建立,则向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,以使所述网络设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立。
若确认单元11已确认物联网设备与终端的第一安全通道已建立,则第一发送单元12向网络设备请求建立物联网设备与网络设备之间的第二安全通道,以使物联网设备真正通过接入网络的认证。终端与网络设备的通信属于现有技术,只不过在这里终端与网络设备通信的内容是确认网络设备是否允许物联网设备通过终端接入网络。进行确认的根据是在MTC-IWF中存储的终端与物联网设备的绑定关系。若网络设备接收到第二安全通道的建立请求后,在MTC-IWF查询是否存储了该绑定关系,然后向终端进行响应,以确认该第二安全通道是否已建立。
在现有技术中,如图1所示,网络侧后台需要一一存储每个物联网设备的用户信息和签约数据,而在本实施例中,仅需根据物联网设备的标识如IMEI、终端的标识如IMEI、USIM等建立一对一或一对多的简单的绑定关系或映射关系即可。终端与网络设备的签约认证是已经存在的。因此,可以减少网络侧后台的存储和同步成本。且由于是物联网设备绑定终端,不再受物联网设备的用户标识的长度限制,在该终端下的物联网设备可以采用任意的标识,各个终 端的物联网设备的标识可以相同或不同。
接收单元13,用于若确认所述第二安全通道已建立,接收所述网络设备发送的第二安全通道的建立响应。
若网络设备确认该第二安全通道已建立,接收单元13接收网络设备发送的请求建立第二安全通道的响应消息,则确认该第二安全通道已建立。
第二发送单元14,用于向所述物联网设备发送认证响应。
若终端确认该物联网设备的第一安全通道和第二安全通道都已经建立,则认为这是一个被许可的安全通信链路,该物联网设备也被判定为一个安全的通信设备,可以响应该物联网设备的认证请求。
根据本发明实施例提供的一种终端,通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。
请参阅图6,为本发明实施例提供的另一种终端的结构示意图,该终端2000包括:
建立单元21,用于建立终端与至少一个物联网设备的绑定关系。
本实施例中通过预置软件根据物联网设备的标识如IMEI、终端的标识如IMEI、USIM等建立一对一或一对多的简单的绑定关系或映射关系。如图4所示的本发明实施例提供的MTC设备绑定智能终端进行认证的安全架构示意图,智能终端与MTC设备1至MTC设备N进行绑定。
存储单元22,用于存储所述绑定关系。
存储单元22可以在本地或者在云端等存储该绑定关系,这里不作限定。
第三发送单元23,用于向网络设备发送绑定关系建立或更新消息,以使所述网络设备将所述绑定关系发送给所述MTC-IWF,以使所述MTC-IWF建立或更新所述终端与所述物联网设备的绑定关系。
网络侧也需存储物联网设备与终端的简单的绑定关系,以作为对物联网设备接入网络进行认证的根据,绑定关系可以由MTC-IWF存储或管理。需要说明的是,MTC-IWF可以是一个独立的功能实体,也可以是分散在各个网络设 备中的功能模块。
如图4所示,该安全架构中包括两种网络设备,即:MME和MTC应用服务器,MME和MTC应用服务器都与MTC-IWF连接,终端可以通过路径1将绑定关系由MME接收、解析后转发给MTC-IWF,也可以通过路径2将绑定关系由MTC应用服务器接收、解析后转发给MTC-IWF。
若MTC-IWF中已经存在属于该终端的绑定关系表或映射表,则无需新建,只需要更新该映射表的映射关系或绑定关系即可。
确认单元24,用于当所述终端接收到物联网设备的认证请求时,通过查询是否存储所述终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立。
该确认单元24的功能与前述实施例的确认单元11相同,在此不再赘述。
第一发送单元25,用于若确认所述第一安全通道已建立,则向所述核心网设备发送所述第二安全通道的建立请求,以使所述核心网设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立,所述建立请求为所述无线资源控制层消息或非无线资源控制层消息。
可替换的是,第一发送单元25也可以用于:若确认所述第一安全通道已建立,则向机器类型通信MTC应用服务器发送所述第二安全通道的建立请求,以使所述MTC应用服务器查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立,所述建立请求为应用层消息。
第二安全通道的建立可以通过如图4的路径1或路径2进行。
作为一种实施方式,通过路径1建立第二安全通道,该网络设备为核心网设备,如MME等,可选地,在终端与核心网设备通信之前,若终端在网络中处于断开连接状态,则先利用现有的网络鉴权机制请求接入移动网络,在网络侧同意终端的接入请求后变成连接状态。在确认终端与核心网设备之间为连接状态后,终端向核心网设备发送第二安全通道的建立请求,具体的,该建立请求可以是非接入层消息或无线资源控制(Radio Resource Control,RRC)消息。MME通过MTC-IWF实体识别智能终端和它的从属MTC设备关系是否存在, 若存在,则给出同意智能终端作为中继接入网络的响应。
需要说明的是,在该实施方式中,终端与物联网设备的绑定关系对网络侧可见,从而使网络设备可以区分物联网设备从而实现分类管控和计费。
作为一种实施方式,通过路径2建立第二安全通道,该网络设备为MTC应用服务器。终端向MTC应用服务器发送第二安全通道的建立请求,具体的,该建立请求为应用层消息。MTC应用服务器通过MTC-IWF实体识别智能终端和它的从属MTC设备关系是否存在,若存在,则给出同意智能终端作为中继接入网络的响应。
需要说明的是,在该实施方式中,终端与物联网设备的绑定关系对网络侧不可见,对网络侧可见的始终是智能终端,由智能终端承担所有物联网设备数据消费的流量。
接收单元26,用于若确认所述第二安全通道已建立,接收所述网络设备发送的第二安全通道的建立响应。
该接收单元26的功能与前述实施例的接收单元13的功能相同,在此不再赘述。
第二发送单元27,用于向所述物联网设备发送认证响应。
该第二发送单元27的功能与前述实施例的第二发送单元14相同,在此不再赘述。
根据本发明实施例提供的一种终端,通过将物联网设备绑定智能终端进行接入网络的认证,可以减少网络侧后台的存储和同步成本,同时也解决了物联网设备标识不足的问题,从而可以实现物联网设备的接入移动网络的轻量级安全性鉴权过程。
需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明并不受所描述的动作顺序的限制,因为根据本发明,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本发明所必须的。
在上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到本发明可以用硬件实现,或固件实现,或它们的组合方式来实现。当使用软件实现时,可以将上述功能存储在计算机可读介质中或作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是计算机能够存取的任何可用介质。以此为例但不限于:计算机可读介质可以包括随机存取存储器(Random Access Memory,RAM)、只读存储器(Read-Only Memory,ROM)、电可擦可编程只读存储器(Electrically Erasable Programmable Read-Only Memory,EEPROM)、只读光盘(Compact Disc Read-Only Memory,CD-ROM)或其他光盘存储、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质。此外。任何连接可以适当的成为计算机可读介质。例如,如果软件是使用同轴电缆、光纤光缆、双绞线、数字用户线(Digital Subscriber Line,DSL)或者诸如红外线、无线电和微波之类的无线技术从网站、服务器或者其他远程源传输的,那么同轴电缆、光纤光缆、双绞线、DSL或者诸如红外线、无线和微波之类的无线技术包括在所属介质的定影中。如本发明所使用的,盘(Disk)和碟(disc)包括压缩光碟(CD)、激光碟、光碟、数字通用光碟(DVD)、软盘和蓝光光碟,其中盘通常磁性的复制数据,而碟则用激光来光学的复制数据。上面的组合也应当包括在计算机可读介质的保护范围之内。
总之,以上所述仅为本发明技术方案的较佳实施例而已,并非用于限定本发明的保护范围。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (10)

  1. 一种物联网设备的认证方法,其特征在于,包括:
    当所述终端接收到物联网设备的认证请求时,所述终端通过查询是否存储所述终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立;
    若确认所述第一安全通道已建立,则所述终端向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,以使所述网络设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立;
    若确认所述第二安全通道已建立,所述终端接收所述网络设备发送的第二安全通道的建立响应;
    所述终端向所述物联网设备发送认证响应。
  2. 如权利要求1所述的方法,其特征在于,所述终端接收所述物联网设备的认证请求之前,还包括:
    所述终端建立所述终端与至少一个所述物联网设备的绑定关系;
    所述终端存储所述绑定关系。
  3. 如权利要求2所述的方法,其特征在于,所述终端向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求之前,还包括:
    所述终端向网络设备发送绑定关系建立或更新消息,以使所述网络设备将所述绑定关系发送给所述MTC-IWF,以使所述MTC-IWF建立或更新所述终端与所述物联网设备的绑定关系。
  4. 如权利要求1-3任意一项所述的方法,其特征在于,所述终端向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,包括:
    所述终端向核心网设备发送所述第二安全通道的建立请求,所述建立请求 为无线资源控制层消息或非无线资源控制层消息。
  5. 如权利要求1-3任意一项所述的方法,其特征在于,所述终端向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,包括:
    所述终端向机器类型通信MTC应用服务器发送所述第二安全通道的建立请求,所述建立请求为应用层消息。
  6. 一种终端,其特征在于,包括:
    确认单元,用于当接收到物联网设备的认证请求时,通过查询是否存储终端与所述物联网设备的绑定关系,确认所述物联网设备与所述终端的第一安全通道是否已建立;
    第一发送单元,用于若确认所述第一安全通道已建立,则向网络设备发送所述物联网设备与所述网络设备之间的第二安全通道的建立请求,以使所述网络设备查询机器类型通信互通功能MTC-IWF是否存储所述绑定关系,以确认所述第二安全通道是否已建立;
    接收单元,用于若确认所述第二安全通道已建立,接收所述网络设备发送的第二安全通道的建立响应;
    第二发送单元,用于向所述物联网设备发送认证响应。
  7. 如权利要求6所述的终端,其特征在于,还包括:
    建立单元,用于建立所述终端与至少一个所述物联网设备的绑定关系;
    存储单元,用于存储所述绑定关系。
  8. 如权利要求7所述的终端,其特征在于,还包括:
    第三发送单元,用于向网络设备发送绑定关系建立或更新消息,以使所述网络设备将所述绑定关系发送给所述MTC-IWF,以使所述MTC-IWF建立或更新所述终端与所述物联网设备的绑定关系。
  9. 如权利要求6-8任意一项所述的终端,其特征在于,所述第一发送单元具体用于:
    向核心网设备发送所述第二安全通道的建立请求,所述建立请求为无线资源控制层消息或非无线资源控制层消息。
  10. 如权利要求6-8任意一项所述的终端,其特征在于,所述第一发送单元具体用于:
    向机器类型通信MTC应用服务器发送所述第二安全通道的建立请求,所述建立请求为应用层消息。
PCT/CN2015/080377 2015-04-03 2015-05-29 一种物联网设备的认证方法及终端 Ceased WO2016155112A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510157337.8 2015-04-03
CN201510157337.8A CN104780536B (zh) 2015-04-03 2015-04-03 一种物联网设备的认证方法及终端

Publications (1)

Publication Number Publication Date
WO2016155112A1 true WO2016155112A1 (zh) 2016-10-06

Family

ID=53621704

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/080377 Ceased WO2016155112A1 (zh) 2015-04-03 2015-05-29 一种物联网设备的认证方法及终端

Country Status (2)

Country Link
CN (1) CN104780536B (zh)
WO (1) WO2016155112A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018076798A1 (zh) * 2016-10-31 2018-05-03 华为技术有限公司 一种传输数据的方法和装置
US11153309B2 (en) 2018-03-13 2021-10-19 At&T Mobility Ii Llc Multifactor authentication for internet-of-things devices
CN113595992A (zh) * 2021-07-07 2021-11-02 青岛海尔科技有限公司 安全绑定方法及系统、存储介质、电子装置

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106656946B (zh) * 2015-11-03 2020-05-19 东莞酷派软件技术有限公司 一种动态鉴权方法及装置
CN107306394A (zh) * 2016-04-21 2017-10-31 上海中兴软件有限责任公司 一种蜂窝物联网终端信息的获取方法及装置、系统
CN107920079B (zh) * 2017-11-21 2018-10-16 山东勤成信息科技有限公司 基于物联网的移动医疗服务方法
CN109995701B (zh) * 2017-12-29 2020-12-01 华为技术有限公司 一种设备引导的方法、终端以及服务器
CN108683715B (zh) 2018-04-26 2022-05-10 京东方科技集团股份有限公司 中间设备、物联网终端及其接入物联网平台的方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102083212A (zh) * 2010-04-30 2011-06-01 大唐移动通信设备有限公司 一种标识终端的方法、系统和装置
US20120284787A1 (en) * 2011-04-08 2012-11-08 Olivier Clemot Personal Secured Access Devices
CN103107878A (zh) * 2011-11-15 2013-05-15 中兴通讯股份有限公司 移动用户身份识别卡与机器类通信设备绑定的方法及装置
CN103250389A (zh) * 2011-03-22 2013-08-14 Nec欧洲有限公司 操作网络的方法和网络

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102204306A (zh) * 2011-04-28 2011-09-28 华为技术有限公司 Mtc终端通过网关与网络通信的方法、设备及系统
CN103188738B (zh) * 2011-12-27 2015-11-25 华为技术有限公司 资源配置方法、装置和系统
CN103781114A (zh) * 2012-10-24 2014-05-07 中兴通讯股份有限公司 网络接入方法、装置及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102083212A (zh) * 2010-04-30 2011-06-01 大唐移动通信设备有限公司 一种标识终端的方法、系统和装置
CN103250389A (zh) * 2011-03-22 2013-08-14 Nec欧洲有限公司 操作网络的方法和网络
US20120284787A1 (en) * 2011-04-08 2012-11-08 Olivier Clemot Personal Secured Access Devices
CN103107878A (zh) * 2011-11-15 2013-05-15 中兴通讯股份有限公司 移动用户身份识别卡与机器类通信设备绑定的方法及装置

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018076798A1 (zh) * 2016-10-31 2018-05-03 华为技术有限公司 一种传输数据的方法和装置
US11153309B2 (en) 2018-03-13 2021-10-19 At&T Mobility Ii Llc Multifactor authentication for internet-of-things devices
CN113595992A (zh) * 2021-07-07 2021-11-02 青岛海尔科技有限公司 安全绑定方法及系统、存储介质、电子装置

Also Published As

Publication number Publication date
CN104780536A (zh) 2015-07-15
CN104780536B (zh) 2019-06-11

Similar Documents

Publication Publication Date Title
US11829774B2 (en) Machine-to-machine bootstrapping
WO2016155112A1 (zh) 一种物联网设备的认证方法及终端
CN113632513B (zh) 无线通信系统的装置变换方法和设备
JP7456444B2 (ja) ネットワーク装置の方法
EP2448298B1 (en) Method and system for changing selected home operator of machine to machine equipment
EP2421292B1 (en) Method and device for establishing security mechanism of air interface link
US20250106625A1 (en) Establishment of network connection for a communication device
EP1879325B1 (en) Method and system for updating a secret key
CN111052777A (zh) 支持无线通信系统中设备间简档转移的方法和装置
CN105307108A (zh) 一种物联网信息交互通信方法及系统
EP3000249A1 (en) Access network assisted bootstrapping
EP2466759B1 (en) Method and system for changing a selected home operator of a machine to machine equipment
CN106465096A (zh) 接入网络和获取客户识别模块信息的方法、终端及核心网
US10075447B2 (en) Secure distributed device-to-device network
CN115843447B (zh) 用户装备对边缘数据网络的接入的网络认证
JP6050513B2 (ja) 通信ネットワークで送信されるペイロードの保護
JP2019016070A (ja) 機器をリモートで管理するための装置、方法及びそのためのプログラム
CN102316450A (zh) M2m通信的基于组的认证方法及其设备
US20180219966A1 (en) Method for establishing ota sessions between terminals and an ota server, corresponding ota server and reverse proxy server
CN116868609A (zh) 用于边缘数据网络的用户装备认证和授权规程
CN121795007A (zh) 源设备跨平台eSIM配置文件传递
EP4591511A1 (en) Digital identity management
CN103731425A (zh) 网络无线终端接入控制方法及系统
EP4203392B1 (en) Authentication support for an electronic device to connect to a telecommunications network
CN121795006A (zh) 目标设备和授权服务器跨平台eSIM配置文件传递

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15887079

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15887079

Country of ref document: EP

Kind code of ref document: A1

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 11/04/2018)

122 Ep: pct application non-entry in european phase

Ref document number: 15887079

Country of ref document: EP

Kind code of ref document: A1