WO2023202631A1 - 签约方法、装置、通信设备、物联网设备及网元 - Google Patents

签约方法、装置、通信设备、物联网设备及网元 Download PDF

Info

Publication number
WO2023202631A1
WO2023202631A1 PCT/CN2023/089269 CN2023089269W WO2023202631A1 WO 2023202631 A1 WO2023202631 A1 WO 2023202631A1 CN 2023089269 W CN2023089269 W CN 2023089269W WO 2023202631 A1 WO2023202631 A1 WO 2023202631A1
Authority
WO
WIPO (PCT)
Prior art keywords
internet
information
subscription
things
contract
Prior art date
Application number
PCT/CN2023/089269
Other languages
English (en)
French (fr)
Inventor
李欢
吴晓波
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2023202631A1 publication Critical patent/WO2023202631A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/009Security arrangements; Authentication; Protecting privacy or anonymity specially adapted for networks, e.g. wireless sensor networks, ad-hoc networks, RFID networks or cloud networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/08Mobility data transfer
    • H04W8/14Mobility data transfer between corresponding nodes

Definitions

  • This application belongs to the field of communication technology, and specifically relates to a contracting method, device, communication equipment, Internet of Things equipment and network elements.
  • IoT devices generally include devices used in certain specific scenarios or specific services, such as smart homes/cities, smart utilities, e-health, etc.
  • IoT devices need to send their credentials to the network side during the process of registering with the mobile network.
  • the network side can authenticate the IoT device based on the credentials before providing services to it.
  • some IoT devices are not pre-installed with enterprise or operator authentication credentials during the production process, which makes it difficult for IoT devices to register to mobile networks.
  • Embodiments of the present application provide a signing method, device, communication equipment, Internet of Things equipment and network elements, which can realize online signing of Internet of Things equipment without pre-installed enterprise or operator authentication credentials.
  • the first aspect provides a contracting method, which includes:
  • the first communication device receives contracting request information from the Internet of Things device, where the contracting request information is used to request contracting data for the Internet of Things device;
  • the first communication device sends first information to the Internet of Things device in response to the subscription request information, where the first information is used to obtain subscription data of the Internet of Things device.
  • a signing device which device includes:
  • a first receiving module configured to receive signing request information from an Internet of Things device, where the signing request information is used to request signing data for the Internet of Things device;
  • the first sending module is configured to send first information to the Internet of Things device, where the first information is used to obtain contract data of the Internet of Things device.
  • the third aspect provides a contracting method, which includes:
  • the Internet of Things device sends contracting request information to the first communication device, where the contracting request information is used to request contracting data for the Internet of Things device;
  • the Internet of Things device receives first information from the first communication device, where the first information is used to obtain subscription data of the Internet of Things device.
  • the fourth aspect provides a contracting device, which includes:
  • the sixth sending module is used to send signing request information to the first communication device, wherein the signing request information is used to request signing data for the Internet of Things device;
  • the fifth receiving module is configured to receive first information from the first communication device, where the first information is used to obtain subscription data of the Internet of Things device.
  • the fifth aspect provides a contracting method, which includes:
  • the first network element receives a contract registration request message from the first communication device, where the contract registration request message is used to request contract registration for the Internet of Things device;
  • the first network element authenticates the Internet of Things device
  • the first network element sends a subscription registration response message to the first communication device, where the subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the sixth aspect provides a contracting device, which includes:
  • the eighth receiving module is configured to receive a contract registration request message from the first communication device, where the contract registration request message is used to request contract registration for the Internet of Things device;
  • An authentication module used to authenticate the Internet of Things device
  • a seventh sending module configured to send a subscription registration response message to the first communication device, where the subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • a communication device in a seventh aspect, includes a processor and a memory.
  • the memory stores programs or instructions that can be run on the processor. When the program or instructions are executed by the processor, Implement the steps of the method described in the first aspect.
  • a communication device including a processor and a communication interface, wherein the communication interface is used to receive signing request information from an Internet of Things device, and wherein the signing request information is used to provide the service for the Internet of Things
  • the device requests contract data; sends first information to the Internet of Things device, where the first information is used to obtain contract data of the Internet of Things device.
  • an Internet of Things device in a ninth aspect, includes a processor and a memory.
  • the memory stores programs or instructions that can be run on the processor.
  • the program or instructions are executed by the processor.
  • an Internet of Things device including a processor and a communication interface, wherein the communication interface is used to send signing request information to the first communication device, wherein the signing request information is used to provide the service for the thing.
  • the networking device requests subscription data; and receives first information from the first communication device, where the first information is used to obtain subscription data of the Internet of Things device.
  • a network element in an eleventh aspect, includes a processor and a memory.
  • the memory stores programs or instructions that can be run on the processor. When the program or instructions are executed by the processor, Implementation is as described in aspect 5 steps of the method.
  • a network element including a processor and a communication interface, wherein the communication interface is used to receive a subscription registration request message from a first communication device, wherein the subscription registration request message is used to request Perform contract registration for the Internet of Things device; authenticate the Internet of Things device; and send a contract registration response message to the first communication device, wherein the contract registration response message is used to indicate that the Internet of Things device has been accepted. Signing registration request.
  • a contracting system including: a communication device, an Internet of Things device and a network element.
  • the communication device can be used to perform the steps of signing as described in the first aspect
  • the Internet of Things device can be used to perform
  • the network element may be used to perform the step of signing as described in the fifth aspect.
  • a readable storage medium is provided. Programs or instructions are stored on the readable storage medium. When the programs or instructions are executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method are implemented. The steps of the method as described in the third aspect, or the steps of implementing the method as described in the fifth aspect.
  • a chip in a fifteenth aspect, includes a processor and a communication interface.
  • the communication interface is coupled to the processor.
  • the processor is used to run programs or instructions to implement the method described in the first aspect. The steps of the method, or the steps of implementing the method as described in the third aspect, or the steps of implementing the method as described in the fifth aspect.
  • a computer program or program product is provided, the computer program or program product is stored in a storage medium, and the computer program or program product is executed by at least one processor to implement as described in the first aspect
  • the first communication device receives signing request information from the Internet of Things device, where the signing request information is used to request signing data for the Internet of Things device; the first communication device responds to the The contract request information sends first information to the Internet of Things device, where the first information is used to obtain contract data of the Internet of Things device, so that the Internet of Things device can obtain the contract data based on the first information to sign a contract,
  • This enables IoT devices to register with the mobile network to obtain mobile network services.
  • Figure 1 is a block diagram of a wireless communication system applicable to the embodiment of the present application.
  • Figure 2 is a flow chart of a contract signing method provided by an embodiment of the present application.
  • Figure 3 is a flow chart of another contract signing method provided by the embodiment of the present application.
  • Figure 4 is a flow chart of another contract signing method provided by the embodiment of the present application.
  • FIG. 5 is a block diagram of another wireless communication system to which the embodiment of the present application is applicable.
  • Figure 6 is a flow chart of another contract signing method provided by the embodiment of the present application.
  • Figure 7 is a flow chart of another contract signing method provided by an embodiment of the present application.
  • Figure 8 is a structural diagram of a contracting device provided by an embodiment of the present application.
  • Figure 9 is a structural diagram of another signing device provided by an embodiment of the present application.
  • Figure 10 is a structural diagram of another signing device provided by an embodiment of the present application.
  • Figure 11 is a structural diagram of an electronic device provided by an embodiment of the present application.
  • Figure 12 is a structural diagram of a communication device provided by an embodiment of the present application.
  • Figure 13 is a structural diagram of an Internet of Things device provided by an embodiment of the present application.
  • Figure 14 is a structural diagram of a network element provided by an embodiment of the present application.
  • first, second, etc. in the description and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and that "first" and “second” are distinguished objects It is usually one type, and the number of objects is not limited.
  • the first object can be one or multiple.
  • “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the related objects are in an "or” relationship.
  • LTE Long Term Evolution
  • LTE-Advanced, LTE-A Long Term Evolution
  • LTE-A Long Term Evolution
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency Division Multiple Access
  • NR New Radio
  • FIG. 1 shows a block diagram of a wireless communication system to which embodiments of the present application are applicable.
  • the wireless communication system includes an Internet of Things device 11, a first communication device 12, a first network element 13 and a contract server 14.
  • the Internet of Things devices 11 may include devices used for certain specific scenarios or specific services, such as devices used for smart homes, smart cities, smart utilities, and electronic health.
  • the above-mentioned first communication device 12 may include a terminal or a radio access network (Radio Access Network, RAN) device, etc.
  • the terminal can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a palmtop computer, a netbook, or a super mobile personal computer ( ultra-mobile personal computer (UMPC), mobile Internet device (MID), augmented reality (AR)/virtual reality (VR) equipment, robots, wearable devices (Wearable Device), Vehicle User Equipment, VUE), Pedestrian User Equipment (PUE), smart home (home equipment with wireless communication functions, such as refrigerators, TVs, washing machines or furniture, etc.), game consoles, personal computers (PC), teller machines or self-service Machines and other terminal side equipment.
  • UMPC ultra-mobile personal computer
  • MID mobile Internet device
  • AR augmented reality
  • VR virtual reality
  • robots wearable devices
  • Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing wait. It should be noted that the embodiments of this application do not limit the specific type of terminal.
  • the above-mentioned access network equipment may also be called wireless access network equipment, radio access network (Radio Access Network, RAN), radio access network function or radio access network unit.
  • Access network equipment can include base stations, Wireless Local Area Networks (WLAN) access points or WiFi nodes, etc.
  • the base station can be called Node B, Evolved Node B (eNB), access point, base transceiver station ( Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home B-node, home evolved B-node, sending and receiving point ( Transmitting Receiving Point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms.
  • BTS Basic Service Set
  • ESS Extended Service Set
  • TRP Transmitting Receiving Point
  • TRP Transmitting Receiving Point
  • the above-mentioned first network element 13 may include a mobility management function or a session management function, etc.
  • the above-mentioned signing server 14 can be any server that supports providing signing data of Internet of Things devices.
  • the embodiment of this application takes the 3rd Generation Partnership Project (3rd Generation Partnership Project, 3GPP) fifth generation (5th-Generation, 5G) system as an example for description.
  • 3rd Generation Partnership Project 3rd Generation Partnership Project
  • 5G fifth generation
  • 3GPP 5G system includes terminal equipment, access network and core network.
  • Terminal devices need to be registered to the core network before they can further receive network services.
  • the terminal device sends its own credentials to the network. After the mobile network authenticates the terminal device, it can provide services to it.
  • IoT devices are only used in specific scenarios or specific services and may be manufactured in batches by IoT device manufacturers. In actual use, IoT devices may be purchased and deployed by enterprises, and the IoT devices are not pre-installed with the authentication credentials of a certain enterprise or operator during the production process.
  • Figure 2 is a flow chart of a contract signing method provided by an embodiment of the present application. The method can be executed by the first communication device. As shown in Figure 2, it includes the following steps:
  • Step 201 The first communication device receives signing request information from the Internet of Things device, where the signing request information is used to request signing data for the Internet of Things device;
  • the above-mentioned first communication device may include but is not limited to user equipment (User Equipment, UE) (also called terminal equipment) or radio access network (Radio Access Network, RAN) equipment, etc.
  • UE User Equipment
  • RAN Radio Access Network
  • the above-mentioned IoT device may be an Ambient Internet of Things device (Ambient Internet of Things, Ambient IoT device), which can absorb energy from the environment and can communicate with the receiving end by sending a reflected signal of the excitation signal after receiving an excitation signal from the transmitting end.
  • the first communication device may be a receiving end, a transmitting end, or a receiving end and a transmitting end.
  • the first communication device may also be called a reader/writer.
  • the above signing request information is used to request signing data for the Internet of Things device.
  • the above-mentioned signing request information may include but is not limited to at least one of the following: identification information of the Internet of Things device, and a first Internet of Things signing indication; wherein the first Internet of Things signing indication is used to indicate that the IoT devices request contracting data.
  • the identification information of the above-mentioned IoT device may include the Media Access Control (MAC) address of the IoT device, the Electronic Product Code (EPC) code, and the configured credentials of the IoT device (such as a default credentials or (called default credentials), or other information that can be used to identify an IoT device.
  • MAC Media Access Control
  • EPC Electronic Product Code
  • Step 202 The first communication device sends first information to the Internet of Things device in response to the subscription request information, where the first information is used to obtain subscription data of the Internet of Things device.
  • the above-mentioned first information is used to obtain the contract data of the Internet of Things device, that is, the Internet of Things device can obtain the contract data of the Internet of Things device according to the first information.
  • the first information may include but is not limited to at least one of the following: identification information of a subscription server, subscription data of the Internet of Things device; wherein the subscription server supports providing subscription data for the Internet of Things device. .
  • the subscription server can provide IoT devices with the subscription data needed to access the mobile network.
  • the identification information of the above-mentioned signing server may include but is not limited to at least one of the address of the signing server (for example, IP address) and the domain name of the signing server (for example, fully qualified domain name (Fully Qualified Domain Name, FQDN)), etc. item.
  • the above-mentioned contract server may also be called an Internet of Things online contract server (i.e., IoT online contract server).
  • the above contract data of the Internet of Things device may include credential information for the Internet of Things device to access the mobile network.
  • the first communication device may be configured with the identification information of the subscription server, or the first communication device may receive the identification information of the subscription server from the core network element.
  • the above-mentioned first communication device sends the first information to the Internet of Things device in response to the above-mentioned contract request information. It can be understood that the above-mentioned first communication device sending the first information to the Internet of Things device is triggered by the above-mentioned contract request information.
  • the Internet of Things device can obtain the contract data of the Internet of Things device based on the first information.
  • the first information includes the identification information of the contract server, and the Internet of Things device can establish a connection with the contract server based on the identification information of the contract server, and obtain the contract data of the Internet of Things device from the contract server; or the first information includes the identification information of the Internet of Things device.
  • Contract data the IoT device can directly obtain the contract data from the received first information.
  • the contracting method provided by the embodiment of the present application receives contracting request information from the Internet of Things device through the first communication device, wherein the contracting request information is used to request contracting data for the Internet of Things device; the first communication device responds Send first information to the Internet of Things device based on the contract request information, where the first information is used to obtain contract data of the Internet of Things device, so that the Internet of Things device can obtain the contract data based on the first information.
  • Signing a contract allows IoT devices to register to the mobile network to obtain mobile network services.
  • the first communication device in the above step 202 may be a receiving end, a transmitting end, or Either can be the receiving end and the sending end.
  • the first communication device may also be called a reader/writer.
  • the first communication device in the above step 201 and the above step 202 may be the same device or different devices.
  • the first communication device in the above step 201 is the receiving end
  • the first communication device in the above step 202 is the sending end.
  • the method further includes:
  • the first communication device sends a contract registration request message to the first network element, where the contract registration request message is used to request contract registration for the Internet of Things device;
  • the first communication device receives a subscription registration response message from the first network element, where the subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the first network element may include but is not limited to a mobility management function or a session management function.
  • the above-mentioned contract registration request message is used to request contract registration for the Internet of Things device.
  • the subscription registration request message may include but is not limited to at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a first Internet of Things subscription registration instruction; wherein, The first IoT subscription registration instruction is used to instruct to request subscription registration for the IoT device.
  • the identification information of the above-mentioned Internet of Things device may include but is not limited to the UE's International Mobile Subscriber Identity (IMSI), Universal Public User Identifier (Generic Public Subscription Identifier, GPSI), the user's permanent Identifier (Subscription Permanent Identifier, SUPI), User Hidden Identifier (Subscription Concealed Identifier, SUCI), Globally Unique Temporary UE Identity (GUTI), Permanent Equipment Identifier (Permanent Equipment Identifier, PEI), International Mobile At least one of the station equipment identification code (International Mobile station Equipment Identity, IMEI), reader identification, IP address, and MAC address; for RAN equipment, it may include but is not limited to the identification and reading and writing of RAN equipment. At least one of the identifiers of the device.
  • IMSI International Mobile Subscriber Identity
  • GPSI Global Public User Identifier
  • SUPI Subscriber Identity Permanent Identifier
  • User Hidden Identifier Subscription Concealed Identifier
  • GUI Globally Unique Temporary UE Identity
  • the above-mentioned first IoT subscription instruction may include at least one of the following: identification information of the IoT device, an IoT device instruction, an IoT device online contract instruction, and an online contract instruction.
  • the above-mentioned subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the subscription registration response message may include, but is not limited to, at least one of identification information of the subscription server and first key information.
  • the first secret key information may be used for data transmission between the first communication device and the Internet of Things device.
  • the above-mentioned first secret key information may include one or more secret key information.
  • the above-mentioned first secret key information may include first sub-key information for the first communication device side and a second sub-key information for the Internet of Things device side. Subkey information.
  • the above-mentioned first secret key information may include at least one of a key for data encryption, an encryption algorithm, a key for data decryption, and a decryption algorithm.
  • the above-mentioned first secret key information may include the first communication device used to process data sent to the Internet of Things device.
  • Secret key information and/or may include secret key information used by the first communication device to decrypt data from the Internet of Things device.
  • the first network element can authenticate the Internet of Things device. For example, authentication can be performed based on the default credentials of the Internet of Things device, and if the authentication is successful, a subscription registration response message is sent to the first communication device. After receiving the subscription registration response message from the first network element, the first communication device may send the first information to the Internet of Things device.
  • the first communication device sends a contract registration request message to the first network element, and upon receiving the contract registration response message from the first network element, the first information is sent to the Internet of Things device, which can improve the efficiency of things. Security of networked device contract registration.
  • the method may further include:
  • the first communication device receives identification information of the subscription server from the first network element.
  • the first network element may be configured with the identification information of the subscription server, and may send the identification information of the subscription server to the first communication device through a dedicated message, or may send the identification information to the first communication device by multiplexing other messages.
  • the identification information of the subscription server may be sent to the first communication device through a subscription registration response message, or the identification information of the subscription server may be sent to the first communication device through a session establishment response message.
  • the identification information of the subscription server from the first network element is received through the first communication device.
  • the Internet of Things corresponding to the first communication device can be improved. Flexibility in configuration of the contracting server for device online contracting.
  • the method may further include:
  • the first communication device sends a first session establishment request message to the first network element, where the first session establishment request message is used to request the establishment of a session channel for the Internet of Things device;
  • the first communication device receives a session establishment response message from the first network element.
  • the above-mentioned first session establishment request message is used to request the establishment of a session channel for the Internet of Things device.
  • the first session establishment request message may include but is not limited to at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a second Internet of Things subscription indication; wherein, The second IoT subscription instruction is used to instruct to establish a session channel for the IoT device to obtain subscription data.
  • the above-mentioned second IoT signing instruction may include at least one of the following: Single Network Slice Selection Assistance Information (S-NSSAI), Data Network Name (DNN), Internet of Things Identification information of the device, IoT device instructions, IoT device online contract instructions, online contract instructions.
  • S-NSSAI Single Network Slice Selection Assistance Information
  • DNN Data Network Name
  • the second IoT subscription instruction may be the S-NSSAI and DNN corresponding to the PDU session for establishing a PDU session related to the IoT device obtaining subscription data.
  • the above session establishment response message may be used to indicate that the session channel for the Internet of Things device has been established.
  • all The session establishment response message may include but is not limited to at least one of the following: identification information of the subscription server and first secret key information; wherein the first secret key information is used for the first communication device and the thing Transfer of data between networked devices.
  • identification information and first secret key information of the above-mentioned contract server please refer to the foregoing description, and will not be described again here.
  • the first communication device sends a first session establishment request message to the first network element and receives a session establishment response message from the first network element to establish a session channel for Internet of Things device signing. Then the first communication device or the Internet of Things device can obtain the subscription data of the Internet of Things device based on the session channel.
  • first session establishment request message can also be understood as being used to request the establishment of a session channel for obtaining subscription data for the Internet of Things device.
  • the above session establishment response message can be used to indicate that the session channel for the Internet of Things device to obtain subscription data has been established.
  • the existing session channel can be directly used to obtain the subscription data of the IoT device.
  • the PDU session channel can be directly used to obtain the subscription data of the Internet of Things device, and the first communication device does not need to send the first session establishment request message to the first network element.
  • the first information includes contract data of the Internet of Things device
  • the method further includes:
  • the first communication device obtains the subscription data of the Internet of Things device from the subscription server through a first session channel, wherein the first session channel is a session channel corresponding to the second information, and the second information is the session channel corresponding to the second information.
  • the above-mentioned first session channel may be a session channel in which the slice selection information and/or the data network name corresponding to the subscription of the IoT device have been established before the IoT device initiates the subscription request.
  • slice A corresponds to the signing session channels of IoT device a1, IoT device a2 and IoT device a3.
  • the session channel corresponding to slice A can be established; this can be used later.
  • the session channel obtains the contract data of IoT device a2 and IoT device a3.
  • This embodiment obtains the contract data of the Internet of Things device from the contract server through the slice corresponding to the Internet of Things device contract and/or the existing session channel of the data network, which not only improves the efficiency of obtaining the contract data of the Internet of Things device, but also saves money. Signaling resources.
  • the first communication device sends the first information to the Internet of Things device in response to the contract request information, which may include: the first communication device sends the first information to the Internet of Things device in response to the contract request information.
  • the first communication device carries the first information in the signing response message, so that the above signing response message can not only notify the IoT device that the network side has accepted its signing request, but also notify the IoT device to obtain the signing request.
  • the first information of the data so that the IoT device can obtain its contract data based on the first information, not only Saving signaling resources can also improve the efficiency of IoT devices in obtaining their contract data.
  • the method may further include:
  • the first communication device sends a subscription response message to the Internet of Things device in response to the subscription request information.
  • the first communication device may first send a signing response message to the Internet of Things device to notify the Internet of Things device that the network side has accepted its signing request, and then send the first information to the Internet of Things device, so that the Internet of Things device can First Information obtains contracting data for online contracting, which can improve the success rate of online contracting for IoT devices.
  • the signing response message includes second secret key information, and the second secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the above-mentioned second secret key information may be used for data transmission between the first communication device and the Internet of Things device.
  • the above-mentioned second secret key information may include at least one of a key for data encryption, an encryption algorithm, a key for data decryption, and a decryption algorithm.
  • the above-mentioned second secret key information may include secret key information used by the Internet of Things device to encrypt data sent to the first communication device, and/or may include secret key information used to decrypt data from the first communication device. key information.
  • the above-mentioned second secret key information may be configured on the first communication device; or, the first communication device may obtain the second secret key information from the first network element.
  • the above-mentioned first secret key information may include the above-mentioned second secret key information.
  • the data between the Internet of Things device and the first communication device can be encrypted or decrypted based on the above-mentioned second secret key information, thereby improving the communication between the first communication device and the first communication device.
  • Security of data transmission between IoT devices by carrying the second secret key information in the signing response message, the data between the Internet of Things device and the first communication device can be encrypted or decrypted based on the above-mentioned second secret key information, thereby improving the communication between the first communication device and the first communication device.
  • the first information is the identification information of the subscription server encrypted via third secret key information or the subscription data of the Internet of Things device encrypted via third secret key information, wherein the third secret key
  • the key information is used for data transmission between the first communication device and the Internet of Things device.
  • the above third key information may be configured in the first communication device; or the first communication device may obtain the key information from the first network element.
  • the above-mentioned first secret key information may include the above-mentioned third secret key information.
  • second key information and third key information may be the same or different, and this embodiment does not limit this.
  • the first communication device encrypts the identification information of the contract server or the contract data of the Internet of Things device with the third key information and sends it to the Internet of Things device. This can improve the identification information of the contract server or the contract data of the Internet of Things device. Transmission security.
  • the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network, or the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network and Fourth secret key information; wherein the fourth secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the above-mentioned fourth secret key information may be used for data transmission between the first communication device and the Internet of Things device.
  • the above-mentioned fourth secret key information may include a key for data encryption, an encryption algorithm, a key for data decryption, and and at least one of the decryption algorithm, etc.
  • the above-mentioned fourth key information may include key information used by the Internet of Things device to encrypt data sent to the first communication device, and/or may include key information used to decrypt data from the first communication device. Key information.
  • the signing server may be configured with the above-mentioned fourth secret key information, so that in the process of the first communication device or the Internet of Things device obtaining the credential information for the Internet of Things device to access the mobile network from the signing server, the fourth secret key information is Together with the credential information for the Internet of Things device to access the mobile network, it is sent to the first communication device or the Internet of Things device.
  • the method may also include:
  • the first communication device sends a third IoT subscription indication, where the third IoT subscription indication is used to instruct the first communication device to support IoT subscription.
  • the first communication device may send the third IoT signing instruction by broadcasting, or the first communication device may also send the third IoT signing instruction to a specific IoT device. In this way, the IoT device that receives the third IoT contracting instruction can select the first communication device to sign online.
  • first communication device and the Internet of Things device can communicate through backscattering technology, or can also communicate through non-3GPP technology, which is not limited by the embodiments of this application.
  • the above-mentioned first communication device can send an excitation signal to the Internet of Things device, and the excitation signal includes the third Internet of Things signing instruction.
  • the Internet of Things device can use the reflected signal of the received excitation signal to send to the first communication device. Signing request information.
  • the first communication device may send a non-3GPP technology signal, such as a WiFi signal or a Bluetooth signal, to the IoT device, where the non-3GPP technology signal includes the third IoT contract indication.
  • the above-mentioned first communication device may also send the subscription request information to the above-mentioned first communication device through non-3GPP technology signals.
  • the Internet of Things device when the Internet of Things device receives instructions from at least two communication devices that support Internet of Things contracting, it can select one communication device from the above-mentioned at least two communication devices to sign the contract.
  • the first communication device is a terminal, and the first communication device sends a subscription registration request message to the first network element, including:
  • the terminal sends a subscription registration request message to the first network element through the access network device, wherein the access network message sent by the terminal to the access network device includes the subscription registration request message and the second Internet of Things subscription Registration instruction, the second IoT subscription registration instruction is used to select the first network element that supports IoT subscription registration.
  • the terminal may send a subscription registration request message to the first network element through the access network device.
  • the first communication device may send an access network message carrying a contract registration request message and a second Internet of Things contract registration instruction to the access network device, and the access network device selects to support the Internet of Things according to the second Internet of Things contract registration instruction.
  • the registered first network element for example, the access network device selects a mobility management function or a session management function that supports IoT registration according to the second IoT subscription registration instruction, and sends a subscription registration request message to the selected first network element.
  • Figure 3 is a flow chart of another contracting method provided by an embodiment of the present application. This method can be executed by an Internet of Things device. As shown in Figure 3, it includes the following steps:
  • Step 301 The Internet of Things device sends signing request information to the first communication device, where the signing request information Used to request contract data for the IoT device.
  • the above-mentioned IoT device may be an ambient IoT device (i.e., Ambient IoT device).
  • the ambient IoT device may absorb energy from the environment, and may transmit the excitation signal after receiving an excitation signal from the transmitter. Communicates with the receiving end by reflecting signals.
  • the above-mentioned first communication device may include but is not limited to UE or RAN device, etc.
  • the above signing request information is used to request signing data for the Internet of Things device.
  • the above-mentioned signing request information may include but is not limited to at least one of the following: identification information of the Internet of Things device, and a first Internet of Things signing indication; wherein the first Internet of Things signing indication is used to indicate that the IoT devices request contracting data.
  • the identification information of the above-mentioned IoT device may include the MAC address of the IoT device, the EPC code, the configured credentials of the IoT device (such as default credentials), or other information that can be used to identify an IoT device.
  • the above-mentioned first IoT subscription instruction may include at least one of the following: identification information of the IoT device, an IoT device instruction, an IoT device online contract instruction, and an online contract instruction.
  • the Internet of Things device may send contracting request information to the first communication device to request contract data for the Internet of Things device when online contracting is required.
  • Step 302 The Internet of Things device receives first information from the first communication device, where the first information is used to obtain contract data of the Internet of Things device.
  • the above-mentioned first information is used to obtain the contract data of the Internet of Things device.
  • the first information may include but is not limited to at least one of the following: identification information of a subscription server, subscription data of the Internet of Things device; wherein the subscription server supports providing subscription data for the Internet of Things device. .
  • the subscription server can provide IoT devices with the subscription data needed to access the mobile network.
  • the identification information of the above-mentioned signing server may include, but is not limited to, at least one of the address (for example, IP address) of the signing server and the domain name (for example, FQDN) of the signing server.
  • the above-mentioned contract server may also be called an Internet of Things online contract server (i.e., IoT online contract server).
  • the above contract data of the Internet of Things device may include credential information for the Internet of Things device to access the mobile network.
  • the above-mentioned first communication device may be configured with the identification information of the above-mentioned subscription server, or the above-mentioned first communication device may receive the identification information of the above-mentioned subscription server from the core network element.
  • the Internet of Things device after receiving the first information from the first communication device, can obtain the subscription data of the Internet of Things device based on the first information.
  • the first information includes the identification information of the contract server, and the Internet of Things device can establish a connection with the contract server based on the identification information of the contract server, and obtain the contract data of the Internet of Things device from the contract server; or the first information includes the identification information of the Internet of Things device.
  • Contract data the Internet of Things device can directly obtain the contract data of the Internet of Things device from the received first information. It can be understood that after obtaining the subscription data, the IoT device can perform a contract based on the obtained subscription data to access the mobile network.
  • the contracting method provided by the embodiment of the present application sends contracting request information to the first communication device through the Internet of Things device, and receives the first information from the first communication device, wherein the first information is used for the Internet of Things Obtain the contract data of the device, so that the IoT device can obtain the contract data based on the first information to sign the contract, which solves the problem of existing technology There is a problem that it is difficult to sign online for IoT devices that do not have pre-installed enterprise or operator authentication credentials.
  • the first information includes identification information of the subscription server
  • the method may further include:
  • the Internet of Things device obtains the subscription data of the Internet of Things device from the subscription server.
  • the Internet of Things device can establish a connection with the signing server based on at least one of the address and domain name of the signing server, and then can obtain a connection from the signing server. Obtain the contract data of the IoT device from the server.
  • the IoT device can register with the mobile network based on the credential information in the above subscription data.
  • the Internet of Things device may send second information to the first communication device, where the second information may include the voucher information in the above-mentioned contract data.
  • the above-mentioned second information may also include a third IoT registration indication, and the third IoT registration indication is used to indicate that the above-mentioned IoT device has been registered to the mobile network.
  • the Internet of Things device can encrypt the above-mentioned second information based on the obtained secret key information and then send it to the first communication device.
  • the first communication device may decrypt the received second information based on the obtained secret key information.
  • the Internet of Things device receives the first information from the first communication device, including:
  • the Internet of Things device receives a subscription response message from the first communication device, wherein the subscription response message includes the first information.
  • the first communication device carries the first information in the signing response message.
  • the Internet of Things device can not only learn that the network side has accepted its signing request through the above signing response message, but also learn the first method used to obtain the signing data. information, so that the IoT device can obtain its contract data based on the first information, which not only saves signaling resources, but also improves the efficiency of the IoT device in obtaining its contract data.
  • the method may further include:
  • the Internet of Things device receives a subscription response message from the first communication device.
  • the Internet of Things device first receives a signing response message from the first communication device to learn that the network side has accepted its signing request. In this way, it can obtain the signing based on the first information after confirming that the network side has accepted its signing request. Online signing of data can improve the success rate of online signing of IoT devices.
  • the signing response message includes second secret key information, and the second secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the method may also include:
  • the IoT device receives a third IoT subscription indication from the first communication device, where the third IoT subscription indication is used to instruct the first communication device to support IoT subscription.
  • the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network, or the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network and Fourth secret key information; wherein the fourth secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the method further includes:
  • the Internet of Things device decrypts the first information according to fifth secret key information, where the fifth secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the fifth key information may be the key information obtained by the Internet of Things device and used for data transmission between the first communication device and the Internet of Things device.
  • the fifth secret key information may include at least one of a key used for data decryption, a decryption algorithm, and the like.
  • the above-mentioned second secret key information may include the above-mentioned fifth secret key information.
  • Figure 4 is a flow chart of another signing method provided by an embodiment of the present application. This method can be executed by the first network element. As shown in Figure 4, it includes the following steps:
  • Step 401 The first network element receives a contract registration request message from the first communication device, where the contract registration request message is used to request contract registration for the Internet of Things device.
  • the first network element may include but is not limited to a mobility management function or a session management function.
  • the above-mentioned first communication device may include a UE or RAN device that supports Internet of Things subscription, etc.
  • the above-mentioned contract registration request message is used to request contract registration for the Internet of Things device.
  • the subscription registration request message may include but is not limited to at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a first Internet of Things subscription registration instruction; wherein, The first IoT subscription registration instruction is used to instruct to request subscription registration for the IoT device.
  • Step 402 The first network element authenticates the Internet of Things device.
  • the first network element may send an authentication request message to the authentication service function to request authentication for the IoT device.
  • the authentication service function may authenticate the IoT device based on the default credentials of the IoT device, and If the authentication passes, an authentication response message is sent to the first network element to indicate that the Internet of Things device has passed the authentication or the authentication is successful.
  • Step 403 The first network element sends a subscription registration response message to the first communication device, where the subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the above-mentioned subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the subscription registration response message may include, but is not limited to, at least one of identification information of the subscription server, first secret key information, and the like.
  • the first secret key information may be used for data transmission between the first communication device and the Internet of Things device.
  • the above-mentioned first secret key information may include one or more secret key information, for example, the above-mentioned first secret key information
  • the key information may include first sub-key information for the first communication device side and second sub-key information for the Internet of Things device side.
  • the first communication device may send a subscription registration request message to the first network element to request subscription registration for the Internet of Things device.
  • the first network element After receiving the contract registration request message, the first network element authenticates the Internet of Things device, and if the authentication passes, sends a contract registration response message to the first communication device to indicate that the contract for the Internet of Things device has been accepted. Registration request.
  • the contracting method provided by the embodiment of this application receives a contract registration request message from the first communication device through the first network element, authenticates the Internet of Things device, and sends a contract registration response message to the first communication device, Furthermore, the first communication device can send the first information to the Internet of Things device when the network side has accepted the contract registration request of the Internet of Things device, so that the Internet of Things device can obtain contract data based on the first information for contract registration, which can improve Security of IoT device signing and registration
  • the method may also include:
  • the first network element sends identification information of a subscription server to the first communication device, where the subscription server supports providing subscription data for the Internet of Things device.
  • the first network element may be configured with the identification information of the subscription server, and may send the identification information of the subscription server to the first communication device through a dedicated message, or may send the identification information to the first communication device by multiplexing other messages.
  • the identification information of the subscription server may be sent to the first communication device through a subscription registration response message, or the identification information of the subscription server may be sent to the first communication device through a session establishment response message.
  • the first network element sends the identification information of the contract server to the first communication device. Compared with configuring the identification information of the contract server on the first communication device, it can improve the efficiency of the Internet of Things device corresponding to the first communication device. Flexibility in contracting server configuration for online contracting.
  • the method may also include:
  • the first network element receives a first session establishment request message from the first communication device, wherein the first session establishment request message is used to request the establishment of a session channel for the Internet of Things device;
  • the first network element sends a session establishment response message to the first communication device.
  • the above-mentioned first session establishment request message is used to request the establishment of a session channel for the Internet of Things device.
  • the first session establishment request message may include but is not limited to at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a second Internet of Things subscription indication; wherein, The second IoT subscription instruction is used to instruct to establish a session channel for the IoT device to obtain subscription data.
  • the above session establishment response message may be used to indicate that the session channel for the Internet of Things device has been established.
  • the session establishment response message may include, but is not limited to, at least one of the following: identification information of the signing server and first secret key information.
  • identification information and first secret key information of the above-mentioned contract server please refer to the foregoing description, and will not be described again here.
  • the above-mentioned second IoT subscription indication may include at least one of the following: S-NSSAI, DNN, identification information of the IoT device, IoT device indication, IoT device online subscription indication, and online subscription indication.
  • first session establishment request message can also be understood as being used to request the establishment of a session channel for obtaining subscription data for the Internet of Things device.
  • the above session establishment response message can be used to indicate that the session channel for the Internet of Things device to obtain subscription data has been established.
  • the first network element receives the first session establishment request message from the first communication device, and sends a session establishment response message to the first communication device to indicate that the session channel for the Internet of Things device has been established. , and then the first communication device or the Internet of Things device can obtain the subscription data of the Internet of Things device based on the session channel.
  • the first network element is configured with at least one of the following: identification information of the subscription server; and the first secret key information.
  • the first network element when the first network element has a mobility management function, the first network element may be configured with the identification information of the subscription server, the first secret key information, the S-NSSAI and the S-NSSAI corresponding to the IoT device subscription. /or DNN, at least one of the session management functions that support the signing of the Internet of Things device, etc.; in the case where the first network element is a session management function, the first network element can be configured with the identification information of the signing server, the above-mentioned At least one of the first secret key information, S-NSSAI and/or DNN corresponding to the IoT device contract.
  • the first network element is a mobility management function
  • the method further includes at least one of the following:
  • the mobility management function sends a second session establishment request message to the session management function, wherein the session management function supports an Internet of Things device subscription function, and the second session establishment request message is used to request the establishment of a session for the Internet of Things device. session channel;
  • the mobility management function sends identification information of a subscription server to the session management function, where the subscription server supports providing subscription data for the Internet of Things device;
  • the mobility management function sends the slice selection information and/or data network name corresponding to the Internet of Things device subscription to the session management function.
  • the above-mentioned mobility management functions such as Access and Mobility Management Function (AMF).
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • SMF Session Management Function
  • the first network element authenticates the Internet of Things device, including:
  • the first network element sends an authentication request message to the authentication service function, where the authentication request message includes the identification information of the Internet of Things device;
  • the first network element receives an authentication response message from the authentication service function, where the authentication response message is used to indicate successful authentication of the Internet of Things device.
  • the above-mentioned Authentication Server Function can authenticate the IoT device.
  • the IoT device can be authenticated based on the default credentials of the IoT device, and after the authentication If the authorization is passed, an authentication response message is sent to the first network element to indicate that the authentication of the Internet of Things device is successful.
  • the first network element obtains identification information of a contract server during the process of authenticating the Internet of Things device, where the contract server supports providing contract data for the Internet of Things device.
  • the first network element can obtain the identification information of the subscription server during the authentication process, and can send it to the first communication device.
  • the method also includes at least one of the following:
  • the first network element records the contract status of the Internet of Things device
  • the first network element records the Internet of Things subscription status of the first communication device.
  • the subscription status of the Internet of Things device may include an online subscription status of the Internet of Things device, where the online subscription status is used to indicate that the Internet of Things device is in a state of obtaining subscription data.
  • the IoT subscription status of the first communication device may include the IoT online subscription status of the first communication device.
  • the IoT online subscription status is used to indicate that the IoT device is obtaining a subscription through the first communication device. Data, or indicating that the first communication device is in a state of obtaining subscription data for the Internet of Things device.
  • the IoT device takes the ambient IoT device 21 (ie, AmbientIoT device) as an example.
  • the AmbientIoT device needs to absorb energy from the environment to receive the excitation signal and send a reflected signal after receiving the excitation signal. Contact the reader.
  • the UE or RAN 22 serves as a reader/writer for the IoT device, and the IoT device can access the mobile network 23 through the reader/writer to access the ambient IoT server 24 (for example, the ambient IoT APP) through the mobile network 23 .
  • Example 1 UE acts as a reader and writer, and Internet of Things devices (i.e. IoT devices) obtain contract data.
  • IoT devices Internet of Things devices
  • the contract signing method provided by the embodiment of this application may include the following steps:
  • Step a0 The UE sends a first IoT online subscription instruction (ie, the above-mentioned third IoT subscription instruction) to the IoT device to instruct the UE to support IoT online subscription.
  • the IoT device receives the IoT online signing instruction.
  • the UE may send a stimulus signal to the IoT device, which includes the first IoT online subscription indication; or, the UE may send a non-3GPP technology signal, such as a WiFi signal or a Bluetooth signal, to the IoT device, which includes the first IoT online subscription indication. instruct.
  • a non-3GPP technology signal such as a WiFi signal or a Bluetooth signal
  • step a0 may be an optional step.
  • Step a1 The IoT device sends an IoT online signing request (for example, the above-mentioned signing request information) to the UE.
  • the IoT online signing request includes the identification information of the IoT device.
  • the identification information of the IoT device can be the Media Access Control (MAC) address of the IoT device, the electronic product code (Electronic Product Code, EPC) code, the credential of the IoT device (such as the default credential). or default credentials), or other information that can be used to identify an IoT device.
  • the default credentials of the IoT device may be pre-configured on the IoT device.
  • the above-mentioned IoT online subscription request may also include a second IoT online subscription instruction (ie, the above-mentioned first IoT subscription instruction) to indicate requesting subscription data for the IoT device.
  • a second IoT online subscription instruction ie, the above-mentioned first IoT subscription instruction
  • the IoT device may use the reflected signal of the received excitation signal to send an IoT online signing request.
  • the IoT device can select a UE that supports online subscription and provide the UE with Send an IoT online signing request.
  • Step a2 The UE receives the IoT online subscription request and sends an IoT online subscription registration request message (i.e., the above-mentioned subscription registration request message) to the AMF.
  • the IoT online subscription registration request message is used to indicate that the IoT device requests to obtain subscription data.
  • the above-mentioned IoT online subscription request message may include the identity of the IoT device and the identity of the UE.
  • the above-mentioned IoT online subscription request message may also include a third IoT online subscription indication (ie, the above-mentioned first IoT subscription registration indication), which is used to instruct to request subscription registration for the IoT device.
  • the UE may carry an IoT online subscription registration request message and a third IoT online subscription instruction in the access network message, and the access network may select an AMF that supports IoT online subscription based on the third IoT online subscription instruction, and provide the UE with the IoT online subscription registration request message.
  • the selected AMF sends the above-mentioned IoT online contract registration request message.
  • Step a3 AMF sends an authentication request to AUSF, which includes the identification information of the IoT device.
  • Step a4 AMF receives the authentication response message from AUSF, indicating that the IoT device has been successfully authenticated.
  • the IoT device authenticates using the identification information (eg, default credentials) of the IoT device.
  • AMF can obtain the address or domain name of the IoT online signing server (ie, Provisioning Server (PVS)) during the authentication process.
  • PVS Provisioning Server
  • Step a5 The AMF sends an IoT online subscription registration response message (ie, the above-mentioned subscription registration response message) to the UE.
  • the online subscription registration response message can be used to indicate that the online subscription registration request of the IoT device has been accepted.
  • AMF can record the online subscription status of the IoT device.
  • the AMF may record the IoT online subscription status of the UE.
  • the UE may send an IoT online subscription response message (ie, the above-mentioned subscription response message) to the IoT device.
  • an IoT online subscription response message ie, the above-mentioned subscription response message
  • the IoT online signing response message may also include the IP address or domain name of the IoT online signing server (for example, a fully qualified domain name (Fully Qualified Domain Name, FQDN)).
  • IP address or domain name of the IoT online signing server for example, a fully qualified domain name (Fully Qualified Domain Name, FQDN)
  • the IoT online subscription response message may also include a data encryption key for interaction between the UE and the IoT device.
  • Step a6 The UE sends an IoT session establishment request message (that is, the above-mentioned first session establishment request message) to the AMF.
  • the IoT session establishment request message is used to instruct the establishment of a session channel for the IoT device to obtain subscription data.
  • the above-mentioned IoT session establishment request message may carry identification information of the IoT device.
  • the above-mentioned IoT session establishment request message may also include the identification information of the UE.
  • the UE sends a PDU session establishment request message to the AMF.
  • an AMF that supports IoT online subscription can be configured with S-NSSAI and/or DNN used by IoT online subscription.
  • the above-mentioned AMF that supports IoT online signing can also be configured with an SMF that supports IoT online signing.
  • the above-mentioned AMF that supports IoT online subscription can also be configured with a data encryption key for the interaction between the UE and the IoT device.
  • the AMF can select an SMF that supports IoT online subscription and send an IoT session establishment request message to the SMF.
  • the AMF can send the address or domain name of the IoT online signing server to the SMF.
  • the AMF can send the S-NSSAI and/or DNN used for IoT online contracting to the SMF.
  • the SMF that supports IoT online subscription can be configured with the address or domain name of the IoT online subscription server.
  • the SMF that supports IoT online subscription can also be configured or obtain the data encryption key for the interaction between the UE and the IoT device from the AMF.
  • Step a7 The UE receives the IoT session establishment response message.
  • the above-mentioned IoT session establishment response message may include the address or domain name of the IoT online subscription server.
  • the IoT online subscription response message may also include a key for interaction between the UE and the IoT device.
  • step a6 and step a7 may be optional steps.
  • the above steps a6 and a7 are not performed.
  • Step a8 The UE sends the address or domain name of the IoT online signing server to the IoT device.
  • the UE can use the data encryption key received in step a7 to encrypt the address or domain name of the IoT online subscription server.
  • step a8 and step a51 can be executed together.
  • the UE sends an IoT online subscription response message to the IoT device, and the IoT online subscription response message may include the address or domain name of the IoT online subscription server.
  • Step a9 The IoT device obtains the IoT device contract data from the IoT online contract server (PVS).
  • PVS IoT online contract server
  • the IoT device can establish a connection with the IoT online signing server according to the address or domain name of the IoT online signing server, and obtain the IoT device signing data from the IoT online signing server.
  • the above-mentioned IoT device contract data includes the credentials for the IoT device to access the mobile network.
  • the above-mentioned IoT device contract data may also include the key of the IoT device data.
  • Step a10 The IoT device registers with the mobile network using the credentials in the obtained contract data. Exemplarily, the IoT device sends the voucher in the subscription data to the UE.
  • the message in which the IoT device sends the credential to the UE may also include an IoT registration indication to instruct the IoT device to register.
  • the IoT device can encrypt the credentials using the obtained key. Accordingly, the UE uses the acquired key to decrypt the received information to obtain the IoT device's credentials.
  • Step a11 The UE sends an IoT device registration request to the AMF.
  • the IoT device registration request is used to register the IoT device to the mobile network.
  • the above-mentioned IoT device registration request may include the credentials of the IoT device.
  • the above-mentioned IoT device registration request may also include an IoT registration indication, which is used to instruct the registration of the IoT device.
  • Example 2 The UE acts as a reader and writer, and the UE acts as an agent for the IoT device to obtain contract data.
  • the contract signing method provided by the embodiment of this application may include the following steps:
  • Step b0 The UE sends a first IoT online subscription instruction (ie, the above-mentioned third IoT subscription instruction) to the IoT device to instruct the UE to support IoT online subscription.
  • the IoT device receives the IoT online signing instruction.
  • Step b1 The IoT device sends an IoT online signing request (for example, the above-mentioned signing request information) to the UE.
  • the IoT online signing request includes the identification information of the IoT device.
  • Step b 2 The UE receives the IoT online subscription request and sends an IoT online subscription registration request message to the AMF (i.e. The above-mentioned contract registration request message), the IoT online contract registration request message is used to indicate that the IoT device requests to obtain contract data.
  • the AMF i.e. The above-mentioned contract registration request message
  • Step b3 AMF sends an authentication request to AUSF, which includes the identification information of the IoT device.
  • Step b4 AMF receives the authentication response message from AUSF, indicating that the IoT device has been successfully authenticated.
  • Step b 5 The AMF sends an IoT online subscription registration response message (i.e., the above-mentioned subscription registration response message) to the UE.
  • the online subscription registration response message can be used to indicate that the online subscription registration request of the IoT device has been accepted.
  • Step b6 The UE sends an IoT session establishment request message (that is, the above-mentioned first session establishment request message) to the AMF.
  • the IoT session establishment request message is used to instruct the establishment of a session channel for the IoT device to obtain subscription data.
  • Step b7 The UE receives the IoT session establishment response message.
  • Step b8 The UE obtains the IoT device subscription data from the IoT online subscription server (PVS).
  • PVS IoT online subscription server
  • the UE establishes a connection with the IoT online signing server according to the address or domain name of the IoT online signing server, and obtains the IoT device signing data from the IoT online signing server.
  • Step b9 The UE sends the IoT device contract data to the IoT device.
  • the UE may use the key received in step b7 to encrypt the address or domain name of the IoT online subscription server.
  • step b9 and step b51 can be executed together.
  • the UE sends an IoT online subscription response message to the IoT device, which includes the address or domain name of the IoT online subscription server.
  • Step b10 The IoT device registers with the mobile network using the credentials in the obtained contract data. As an example, the IoT device sends the voucher in the subscription data to the UE.
  • Step b11 The UE sends an IoT device registration request to the AMF.
  • the IoT device registration request is used to register the IoT device to the mobile network.
  • the solutions in the above examples can also be applied to an architecture in which the reader/writer is an access network device.
  • the reader/writer is an access network device
  • the messages exchanged between the access network device and the AMF can be transmitted using the Next Generation Application Protocol (NGAP) protocol.
  • NGAP Next Generation Application Protocol
  • the UE or RAN can also be connected to the IoT device through other access methods.
  • the above other access methods can include but are not limited to WiFi, Bluetooth, wired connection, etc.
  • the above-mentioned IoT devices can also be other devices, such as non-3GPP devices.
  • the embodiment of the present application obtains the online signing request of the IoT device through the reader/writer, and establishes a session channel for the IoT device to obtain the signing data, thereby completing the online signing of the IoT device.
  • the execution subject may be a contracting device, or a control module in the contracting device for executing the contracting method.
  • the contracting device performing the contracting method is used as an example to describe the contracting device provided by the embodiments of this application.
  • Figure 8 is a structural diagram of a signing device provided by an embodiment of the present application.
  • the signing device 800 includes:
  • the first receiving module 801 is used to receive signing request information from the Internet of Things device, where the signing request information is used to request signing data for the Internet of Things device;
  • the first sending module 802 is configured to send first information to the Internet of Things device, where the first information is used to obtain subscription data of the Internet of Things device.
  • the first information includes at least one of the following: identification information of a subscription server, subscription data of the Internet of Things device; wherein the subscription server supports providing subscription data for the Internet of Things device.
  • the identification information of the signing server includes at least one of the following: the address of the signing server and the domain name of the signing server.
  • the signing request information includes at least one of the following: identification information of the Internet of Things device, and a first Internet of Things signing indication; wherein the first Internet of Things signing indication is used to indicate that the Internet of Things device is the Request contracting data.
  • the device also includes:
  • the second sending module is configured to send a signing registration request message to the first network element after receiving the signing request information from the Internet of Things device, where the signing registration request message is used to request signing for the Internet of Things device. register;
  • the second receiving module is configured to receive a subscription registration response message from the first network element, where the subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the subscription registration request message includes at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a first Internet of Things subscription registration instruction; wherein the first Internet of Things subscription The registration instruction is used to indicate requesting contract registration for the Internet of Things device.
  • the subscription registration response message includes identification information of the subscription server.
  • the device also includes:
  • the third receiving module is configured to receive the identification information of the contract server from the first network element before sending the first information to the Internet of Things device.
  • the device also includes:
  • a third sending module configured to send a first session establishment request message to the first network element before sending the first information to the Internet of Things device, wherein the first session establishment request message is used to request the IoT devices establish session channels;
  • the fourth receiving module is configured to receive a session establishment response message from the first network element.
  • the first session establishment request message includes at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a second Internet of Things signing instruction; wherein, the second Internet of Things Signing instructions are used to refer to It is shown that a session channel is established for the Internet of Things device to obtain contract data.
  • the session establishment response message includes at least one of the following: identification information of the subscription server and first secret key information; wherein the first secret key information is used for the first communication device and the Internet of Things Transfer of data between devices.
  • the first information includes contract data of the Internet of Things device
  • the device also includes:
  • a first acquisition module configured to obtain the subscription data of the Internet of Things device from the subscription server through a first session channel before sending the first information to the Internet of Things device, wherein the first session channel is The session channel corresponding to the second information, where the second information is the slice selection information and/or data network name corresponding to the IoT device subscription.
  • the first sending module is specifically used for:
  • the device also includes:
  • the fourth sending module is configured to send a signing response message to the Internet of Things device before sending the first information to the Internet of Things device.
  • the signing response message includes second secret key information, and the second secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the first information is the identification information of the subscription server encrypted via third secret key information or the subscription data of the Internet of Things device encrypted via third secret key information, wherein the third secret key
  • the key information is used for data transmission between the first communication device and the Internet of Things device.
  • the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network, or the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network and Fourth secret key information; wherein the fourth secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the device also includes:
  • the fifth sending module is used to send a third Internet of Things signing instruction, wherein the third Internet of Things signing instruction is used to instruct the device to support Internet of Things signing.
  • the second sending module is specifically used for:
  • the second IoT subscription registration instruction is used to select the first network element that supports IoT subscription registration.
  • the signing device 800 in the embodiment of the present application may be an electronic device, for example, an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be a terminal or a wireless access network device, or may be other devices other than the terminal or the access network device.
  • the above-mentioned terminal or wireless access network device may include but is not limited to the types of terminals or wireless access network devices listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., this document Application examples are not Make specific limitations.
  • the contract signing device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 2 and achieve the same technical effect. To avoid duplication, details will not be described here.
  • Figure 9 is a structural diagram of a signing device provided by an embodiment of the present application. As shown in Figure 9, the signing device 900 includes:
  • the sixth sending module 901 is used to send signing request information to the first communication device, where the signing request information is used to request signing data for the Internet of Things device;
  • the fifth receiving module 902 is configured to receive first information from the first communication device, where the first information is used to obtain contract data of the Internet of Things device.
  • the first information includes at least one of the following: identification information of a subscription server, subscription data of the Internet of Things device; wherein the subscription server supports providing subscription data for the Internet of Things device.
  • the identification information of the signing server includes at least one of the following: the address of the signing server and the domain name of the signing server.
  • the signing request information includes at least one of the following: identification information of the Internet of Things device, and a first Internet of Things signing indication; wherein the first Internet of Things signing indication is used to indicate that the Internet of Things device is the Request contracting data.
  • the first information includes identification information of the subscription server
  • the device also includes:
  • the second acquisition module is configured to acquire the subscription data of the Internet of Things device from the subscription server after receiving the first information from the first communication device.
  • the fifth receiving module is specifically used for:
  • a subscription response message is received from the first communication device, wherein the subscription response message includes the first information.
  • the device also includes:
  • a sixth receiving module is configured to receive a subscription response message from the first communication device before receiving the first information from the first communication device.
  • the signing response message includes second secret key information, and the second secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the device also includes:
  • a seventh receiving module configured to receive a third IoT subscription indication from the first communication device, where the third IoT subscription indication is used to instruct the first communication device to support IoT subscription.
  • the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network, or the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network and Fourth secret key information; wherein the fourth secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the device also includes:
  • a decryption module configured to decrypt the first information according to fifth secret key information after receiving the first information from the first communication device, wherein the fifth secret key information is used for the third Transmission of data between a communication device and the Internet of Things device.
  • the signing device 900 in the embodiment of the present application may be an electronic device, for example, an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be an Internet of Things device or other devices other than an Internet of Things device.
  • the above-mentioned Internet of Things devices may include but are not limited to the types of Internet of Things devices listed above.
  • Other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiments of this application.
  • the contract signing device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 3 and achieve the same technical effect. To avoid duplication, details will not be described here.
  • Figure 10 is a structural diagram of a signing device provided by an embodiment of the present application.
  • the signing device 1000 includes:
  • the eighth receiving module 1001 is configured to receive a contract registration request message from the first communication device, where the contract registration request message is used to request contract registration for the Internet of Things device;
  • Authentication module 1002 used to authenticate the Internet of Things device
  • the seventh sending module 1003 is configured to send a subscription registration response message to the first communication device, where the subscription registration response message is used to indicate that the subscription registration request of the Internet of Things device has been accepted.
  • the subscription registration request message includes at least one of the following: the subscription registration request message includes at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, first thing Internet subscription registration instruction; wherein the first Internet of Things contract registration instruction is used to instruct to request contract registration for the Internet of Things device.
  • the device also includes:
  • An eighth sending module is configured to send identification information of a subscription server to the first communication device, where the subscription server supports providing subscription data for the Internet of Things device.
  • the device also includes:
  • a ninth receiving module configured to receive a first session establishment request message from the first communication device, wherein the first session establishment request message is used to request the establishment of a session channel for the Internet of Things device;
  • a ninth sending module configured to send a session establishment response message to the first communication device.
  • the first session establishment request message includes at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a second Internet of Things subscription indication; wherein, the second The IoT signing instruction is used to instruct the establishment of a session channel for the IoT device.
  • the session establishment response message includes at least one of the following:
  • First secret key information wherein the first secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the device is configured with at least one of the following: identification information of the subscription server; the first secret key information.
  • the device is a mobility management function
  • the device further includes a tenth sending module, the tenth sending module is used for at least one of the following:
  • the session management function After receiving the first session establishment request message from the first communication device, sending a second session establishment request message to a session management function, wherein the session management function supports an Internet of Things device signing function, and the second session The establishment request message is used to request the establishment of a session channel for the Internet of Things device;
  • the authentication module is specifically used to:
  • the authentication request message includes the identification information of the Internet of Things device
  • An authentication response message is received from the authentication service function, where the authentication response message is used to indicate successful authentication of the Internet of Things device.
  • the device obtains identification information of a subscription server during the process of authenticating the Internet of Things device, where the subscription server supports providing subscription data for the Internet of Things device.
  • the device further includes a recording module, which is specifically used for at least one of the following:
  • the signing device 1000 in the embodiment of the present application may be an electronic device, for example, an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be the first network element, or may be other devices other than the first network element.
  • the first network element may include but is not limited to the types of first network elements listed above.
  • Other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiments of this application. .
  • the contract signing device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 4 and achieve the same technical effect. To avoid duplication, details will not be described here.
  • this embodiment of the present application also provides an electronic device 1100, including a processor 1101 and a memory 1102.
  • the memory 1102 stores programs or instructions that can be run on the processor 1101, such as , when the electronic device 1100 is a first communication device, when the program or instruction is executed by the processor 1101, each step of the first communication device side contract method embodiment is implemented, and the same technical effect can be achieved.
  • the electronic device 1100 is an Internet of Things device, when the program or instruction is executed by the processor 1101, the steps of the above-mentioned IoT device side contracting method embodiment are implemented, and the same technical effect can be achieved. To avoid duplication, they will not be described again here. .
  • the electronic device 1100 is the first network element
  • the program or instruction is executed by the processor 1101
  • each step of the above-mentioned first network element side contracting method embodiment is implemented, and the same technical effect can be achieved. To avoid duplication, the steps are not included here.
  • Embodiments of the present application also provide a communication device, including a processor and a communication interface, wherein the communication interface is used to receive signing request information from an Internet of Things device, wherein the signing request information is used to provide the service for the Internet of Things
  • the device requests contract data; sends first information to the Internet of Things device, where the first information is used to obtain contract data of the Internet of Things device.
  • This communication device embodiment corresponds to the above-mentioned first communication device-side method embodiment.
  • Each implementation process and implementation manner of the above-mentioned method embodiment can be applied to this communication device embodiment, and can achieve the same technical effect.
  • FIG. 12 is a schematic diagram of the hardware structure of a communication device that implements an embodiment of the present application.
  • the communication device 1200 includes but is not limited to: radio frequency unit 1201, network module 1202, audio output unit 1203, input unit 1204, sensor 1205, display unit 1206, user input unit 1207, interface unit 1208, memory 1209, processor 1210, etc. at least some of the components.
  • the communication device 1200 may also include a power supply (such as a battery) that supplies power to various components.
  • the power supply may be logically connected to the processor 1210 through a power management system, thereby managing charging, discharging, and function through the power management system. Consumption management and other functions.
  • the structure of the communication device shown in Figure 12 does not constitute a limitation on the communication device.
  • the communication device may include more or less components than shown in the figure, or combine certain components, or arrange different components, which will not be described again here. .
  • the input unit 1204 may include a graphics processing unit (Graphics Processing Unit, GPU) 12041 and a microphone 12042.
  • the graphics processor 12041 is responsible for the image capture device (GPU) in the video capture mode or the image capture mode. Process the image data of still pictures or videos obtained by cameras (such as cameras).
  • the display unit 1206 may include a display panel 12061, which may be configured in the form of a liquid crystal display, an organic light emitting diode, or the like.
  • the user input unit 1207 includes at least one of a touch panel 12071 and other input devices 12072 .
  • Touch panel 12071 also known as touch screen.
  • the touch panel 12071 may include two parts: a touch detection device and a touch controller.
  • Other input devices 12072 may include but are not limited to physical keyboards, function keys (such as volume control keys, switch keys, etc.), trackballs, mice, and joysticks, which will not be described again here.
  • the radio frequency unit 1201 after receiving data from the first network element or the Internet of Things device, the radio frequency unit 1201 can transmit the data to the processor 1210 for processing; in addition, the radio frequency unit 1201 can send data to the first network element or the Internet of Things device.
  • the radio frequency unit 121 includes, but is not limited to, an antenna, at least one amplifier, transceiver, coupler, low noise amplifier, duplexer, etc.
  • Memory 1209 may be used to store software programs or instructions as well as various data.
  • the memory 1209 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instructions required for at least one function (such as a sound playback function, Image playback function, etc.) etc.
  • memory 1209 may include volatile memory or nonvolatile memory, or memory 1209 may include both volatile and nonvolatile memory.
  • the non-volatile memory can be read-only memory (Read-Only Memory, ROM), programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically removable memory. Erase programmable read-only memory (Electrically EPROM, EEPROM) or flash memory.
  • Volatile memory can be random access memory (Random Access Memory, RAM), static random access memory (Static RAM, SRAM), dynamic random access memory (Dynamic RAM, DRAM), synchronous dynamic memory Synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDRSDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchronous connected dynamic random access memory Access memory (Synch link DRAM, SLDRAM) and direct memory bus random access memory (Direct Rambus RAM, DRRAM).
  • Memory 1209 in embodiments of the present application includes, but is not limited to, these and any other suitable types of memory.
  • the processor 1210 may include one or more processing units; optionally, the processor 1210 integrates an application processor and a modem processor, where the application processor mainly handles operations related to the operating system, user interface, application programs, etc., Modem processors mainly process wireless communication signals, such as baseband processors. It can be understood that the above modem processor may not be integrated into the processor 1210.
  • the radio frequency unit 1201 is used to receive contract request information from the Internet of Things device, where the contract request information is used to request contract data for the Internet of Things device; and to send the first information to the Internet of Things device, where, The first information is used to obtain contract data of the Internet of Things device.
  • the contract request information is received from the Internet of Things device, where the contract request information is used to request contract data for the Internet of Things device; the first communication device responds to the contract request information to the The Internet of Things device sends the first information, wherein the first information is used to obtain the contract data of the Internet of Things device, so that the Internet of Things device can obtain the contract data based on the first information to perform the contract, which solves the problem in the existing technology.
  • the problem is that it is difficult to sign online for IoT devices that are pre-installed with enterprise or operator authentication credentials.
  • the first information includes at least one of the following: identification information of a subscription server, subscription data of the Internet of Things device; wherein the subscription server supports providing subscription data for the Internet of Things device.
  • the identification information of the signing server includes at least one of the following: the address of the signing server and the domain name of the signing server.
  • the signing request information includes at least one of the following: identification information of the Internet of Things device, and a first Internet of Things signing indication; wherein the first Internet of Things signing indication is used to indicate that the Internet of Things device is the Request contracting data.
  • the radio frequency unit 1201 is also used to:
  • the contract registration request message includes at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a first Internet of Things contract registration instruction; wherein, the first Internet of Things device
  • the Internet subscription registration instruction is used to indicate requesting contract registration for the Internet of Things device.
  • the subscription registration response message includes identification information of the subscription server.
  • the radio frequency unit 1201 is also used to:
  • the radio frequency unit 1201 is also used to:
  • first session establishment request message Before sending the first information to the Internet of Things device, send a first session establishment request message to the first network element, wherein the first session establishment request message is used to request the establishment of a session channel for the Internet of Things device;
  • the first session establishment request message includes at least one of the following: identification information of the Internet of Things device, identification information of the first communication device, and a second Internet of Things subscription indication; wherein, the second The IoT subscription instruction is used to instruct the establishment of a session channel for the IoT device to obtain subscription data.
  • the session establishment response message includes at least one of the following: identification information of the subscription server and first secret key information; wherein the first secret key information is used for the first communication device and the Transmission of data between IoT devices.
  • the first information includes contract data of the Internet of Things device
  • the radio frequency unit 1201 is also used to:
  • the second information is slice selection information and/or data network name corresponding to the IoT device contract.
  • the radio frequency unit 1201 is specifically used for:
  • the radio frequency unit 1201 is also used to:
  • the signing response message includes second secret key information, and the second secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the first information is the identification information of the subscription server encrypted via third secret key information or the subscription data of the Internet of Things device encrypted via third secret key information, wherein the third secret key
  • the key information is used for data transmission between the first communication device and the Internet of Things device.
  • the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network, or the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network and Fourth secret key information; wherein the fourth secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the radio frequency unit 1201 is also used to:
  • the radio frequency unit 1201 is also used to:
  • the access network device sends a subscription registration request message to the first network element, where the access network message sent by the first communication device to the access network device includes the subscription registration request message and the second IoT subscription Registration instruction, the second IoT subscription registration instruction is used to select the first network element that supports IoT subscription registration.
  • An embodiment of the present application also provides an Internet of Things device, including a processor and a communication interface, wherein the communication interface is used to send signing request information to the first communication device, wherein the signing request information is used to provide the Internet of Things device with Requesting subscription data; receiving first information from the first communication device, where the first information is used to obtain subscription data of the Internet of Things device.
  • This Internet of Things device embodiment corresponds to the above-mentioned Internet of Things device-side method embodiment.
  • Each implementation process and implementation method of the above-mentioned method embodiment can be applied to this Internet of Things device embodiment, and can achieve the same technical effect.
  • this embodiment of the present application also provides an Internet of Things device 1300, including a processor 1301, a memory 1302, and a transceiver module 1303.
  • the above-mentioned transceiver module 1303 may include a radio frequency transceiver, a Bluetooth module, a WIFI module, etc.
  • the transceiver module 1303 is used to: send contract request information to the first communication device, where the contract request information is used to request contract data for the Internet of Things device; receive the first information from the first communication device, wherein, the first information is used to obtain contract data of the Internet of Things device.
  • the first information includes at least one of the following: identification information of a subscription server, subscription data of the Internet of Things device; wherein the subscription server supports providing subscription data for the Internet of Things device.
  • the identification information of the signing server includes at least one of the following: the address of the signing server and the domain name of the signing server.
  • the signing request information includes at least one of the following: identification information of the Internet of Things device, and a first Internet of Things signing indication; wherein the first Internet of Things signing indication is used to indicate that the Internet of Things device is the Request contracting data.
  • the first information includes identification information of the subscription server
  • the transceiver module 1303 is also used to:
  • the transceiver module 1303 is specifically used for:
  • a subscription response message is received from the first communication device, wherein the subscription response message includes the first information.
  • the transceiver module 1303 is also used to:
  • the signing response message includes second secret key information, and the second secret key information is used for data transmission between the first communication device and the Internet of Things device.
  • the transceiver module 1303 is also used to:
  • the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network, or the subscription data of the Internet of Things device includes credential information for the Internet of Things device to access the mobile network and Fourth Secret Key information; wherein the fourth key information is used for data transmission between the first communication device and the Internet of Things device.
  • the transceiver module 1303 is also used to:
  • An embodiment of the present application also provides a network element, including a processor and a communication interface, wherein the communication interface is used to receive a subscription registration request message from the first communication device, wherein the subscription registration request message is used to request
  • the Internet of Things device performs contract registration; authenticates the Internet of Things device; and sends a contract registration response message to the first communication device, wherein the contract registration response message is used to indicate that the contract of the Internet of Things device has been accepted. Registration request.
  • This network element embodiment corresponds to the above-mentioned first network element side method embodiment. Each implementation process and implementation manner of the above-mentioned method embodiment can be applied to this network element embodiment, and can achieve the same technical effect.
  • the embodiment of the present application also provides a network element.
  • the network element 1400 includes: an antenna 141, a radio frequency device 142, a baseband device 143, a processor 144 and a memory 145.
  • the antenna 141 is connected to the radio frequency device 142 .
  • the radio frequency device 142 receives information through the antenna 141 and sends the received information to the baseband device 143 for processing.
  • the baseband device 143 processes the information to be sent and sends it to the radio frequency device 142.
  • the radio frequency device 142 processes the received information and then sends it out through the antenna 141.
  • the method performed by the first network element in the above embodiment can be implemented in the baseband device 143, which includes a baseband processor.
  • the baseband device 143 may include, for example, at least one baseband board on which multiple chips are disposed, as shown in FIG. Program to perform the network device operations shown in the above method embodiments.
  • the network element may also include a network interface 146, which is, for example, a common public radio interface (CPRI).
  • a network interface 146 which is, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network element 1400 in the embodiment of the present application also includes: instructions or programs stored in the memory 145 and executable on the processor 144.
  • the processor 144 calls the instructions or programs in the memory 145 to execute the modules shown in Figure 10
  • the implementation method and achieve the same technical effect will not be repeated here to avoid repetition.
  • the network element in the embodiment of the present application also includes: instructions or programs stored in the memory 145 and executable on the processor 144.
  • the processor 144 calls the instructions or programs in the memory 145 to execute the modules shown in Figure 10 method and achieve the same technical effect. To avoid duplication, we will not repeat it here.
  • Embodiments of the present application also provide a readable storage medium, with a program or instructions stored on the readable storage medium.
  • a program or instructions stored on the readable storage medium.
  • each process of the above-mentioned first communication device side contracting method embodiment is implemented. Either implement each process of the IoT device side contracting method embodiment, or implement each process of the first network element side contracting method embodiment and achieve the same technical effect. To avoid duplication, they will not be described again here.
  • the processor is the processor in the terminal described in the above embodiment, or the processor in the above embodiment. Processor in the network side device.
  • the readable storage medium includes computer readable storage media, such as computer read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk, etc.
  • An embodiment of the present application further provides a chip.
  • the chip includes a processor and a communication interface.
  • the communication interface is coupled to the processor.
  • the processor is used to run programs or instructions to implement the above-mentioned signing on the first communication device side.
  • chips mentioned in the embodiments of this application may also be called system-on-chip, system-on-a-chip, system-on-chip or system-on-chip, etc.
  • Embodiments of the present application further provide a computer program/program product.
  • the computer program/program product is stored in a storage medium.
  • the computer program/program product is executed by at least one processor to implement the above contracting method embodiment.
  • Each process can achieve the same technical effect. To avoid duplication, it will not be described again here.
  • Embodiments of the present application also provide a contracting system, including: communication equipment, Internet of Things equipment and network elements.
  • the communication equipment is used to execute various processes in Figure 2 and the above method embodiments.
  • the Internet of Things equipment uses When executing each process in Figure 3 and each of the above method embodiments, the network element is used to execute each process in Figure 4 and each above method embodiment, and can achieve the same technical effect. To avoid duplication, it will not be repeated here. Repeat.
  • the methods of the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is better. implementation.
  • the technical solution of the present application can be embodied in the form of a computer software product that is essentially or contributes to the existing technology.
  • the computer software product is stored in a storage medium (such as ROM/RAM, disk , optical disk), including several instructions to cause a terminal (which can be a mobile phone, computer, server, air conditioner, or network-side device, etc.) to execute the method described in various embodiments of this application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请公开了一种签约方法、装置、通信设备、物联网设备及网元,属于通信技术领域,本申请实施例的签约方法包括:第一通信设备接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。

Description

签约方法、装置、通信设备、物联网设备及网元
相关申请的交叉引用
本申请主张在2022年4月22日在中国提交的中国专利申请No.202210432195.1的优先权,其全部内容通过引用包含于此。
技术领域
本申请属于通信技术领域,具体涉及一种签约方法、装置、通信设备、物联网设备及网元。
背景技术
物联网设备一般包括用于某些特定场景或特定服务的设备,例如,智能家居/城市、智能公用设施、电子健康等。目前,物联网设备在注册移动网络的过程中需要向网络侧发送自己的凭证,网络侧依据该凭证对物联网设备进行鉴权后可以对其提供服务。但在实际情况中,一些物联网设备在生产过程中没有预装企业或运营商的鉴权凭证,这样导致物联网设备难以注册到移动网络。
发明内容
本申请实施例提供一种签约方法、装置、通信设备、物联网设备及网元,能够实现没有预装企业或运营商的鉴权凭证的物联网设备的在线签约。
第一方面,提供了一种签约方法,该方法包括:
第一通信设备接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
第二方面,提供了一种签约装置,该装置包括:
第一接收模块,用于接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
第一发送模块,用于向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
第三方面,提供了一种签约方法,该方法包括:
物联网设备向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
所述物联网设备接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
第四方面,提供了一种签约的装置,该装置包括:
第六发送模块,用于向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为物联网设备请求签约数据;
第五接收模块,用于接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
第五方面,提供了一种签约方法,该方法包括:
第一网元接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;
所述第一网元对所述物联网设备进行鉴权;
所述第一网元向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
第六方面,提供了一种签约的装置,该装置包括:
第八接收模块,用于接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;
鉴权模块,用于对所述物联网设备进行鉴权;
第七发送模块,用于向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
第七方面,提供了一种通信设备,该通信设备包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,,所述程序或指令被所述处理器执行时实现如第一方面所述的方法的步骤。
第八方面,提供了一种通信设备,包括处理器及通信接口,其中,所述通信接口用于接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
第九方面,提供了一种物联网设备,该物联网设备包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第三方面所述的方法的步骤。
第十方面,提供了一种物联网设备,包括处理器及通信接口,其中,所述通信接口用于向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
第十一方面,提供了一种网元,该网元包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第五方面所述 的方法的步骤。
第十二方面,提供了一种网元,包括处理器及通信接口,其中,所述通信接口用于接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;对所述物联网设备进行鉴权;向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
第十三方面,提供了一种签约系统,包括:通信设备、物联网设备及网元,所述通信设备可用于执行如第一方面所述的签约的步骤,所述物联网设备可用于执行如第三方面所述的签约的步骤,所述网元可用于执行如第五方面所述的签约的步骤。
第十四方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面所述的方法的步骤,或者实现如第三方面所述的方法的步骤,或者实现如第五方面所述的方法的步骤。
第十五方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面所述的方法的步骤,或实现如第三方面所述的方法的步骤,或者实现如第五方面所述的方法的步骤。
第十六方面,提供了一种计算机程序或程序产品,所述计算机程序或程序产品被存储在存储介质中,所述计算机程序或程序产品被至少一个处理器执行以实现如第一方面所述的方法的步骤,或实现如第三方面所述的方法的步骤,或者实现如第五方面所述的方法的步骤。
在本申请实施例中,通过第一通信设备接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取,这样物联网设备可以基于第一信息获取签约数据进行签约,从而可以实现物联网设备注册至移动网络以获取移动网络的服务。
附图说明
图1是本申请实施例可应用的一种无线通信系统的框图;
图2是本申请实施例提供的一种签约方法的流程图;
图3是本申请实施例提供的另一种签约方法的流程图;
图4是本申请实施例提供的另一种签约方法的流程图;
图5是本申请实施例可应用的另一种无线通信系统的框图;
图6是本申请实施例提供的另一种签约方法的流程图;
图7是本申请实施例提供的另一种签约方法的流程图;
图8是本申请实施例提供的一种签约装置的结构图;
图9是本申请实施例提供的另一种签约装置的结构图;
图10是本申请实施例提供的另一种签约装置的结构图;
图11是本申请实施例提供的电子设备的结构图;
图12是本申请实施例提供的通信设备的结构图;
图13是本申请实施例提供的物联网设备的结构图;
图14是本申请实施例提供的网元的结构图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统应用以外的应用,如第6代(6th Generation,6G)通信系统。
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括物联网设备11、第一通信设备12、第一网元13和签约服务器14。其中,物联网设备11可以包括用于某些特定的场景或特定的服务的设备,例如,用于智能家居、智能城市、智能公用设施和电子健康等的设备。
上述第一通信设备12可以包括终端或无线接入网(Radio Access Network,RAN)设备等。其中,终端可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(augmented reality,AR)/虚拟现实(virtual reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(Vehicle User Equipment, VUE)、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(personal computer,PC)、柜员机或者自助机等终端侧设备。可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。需要说明的是,在本申请实施例并不限定终端的具体类型。
上述接入网设备也可以称为无线接入网设备、无线接入网(Radio Access Network,RAN)、无线接入网功能或无线接入网单元。接入网设备可以包括基站、无线局域网(Wireless Local Area Networks,WLAN)接入点或WiFi节点等,基站可被称为节点B、演进节点B(eNB)、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点、家用演进型B节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。
上述第一网元13可以包括移动性管理功能或会话管理功能等。上述签约服务器14可以为任意支持提供物联网设备的签约数据的服务器。
为了便于理解,本申请实施例以第三代合作计划(3rd Generation Partnership Project,3GPP)第五代(5th-Generation,5G)系统为例进行说明。以下对本申请实施例涉及的相关内容进行说明:
3GPP 5G系统包括终端设备、接入网和核心网。终端设备需要先注册到核心网,才可以进一步接受网络的服务。目前终端设备在向移动网络注册的过程中,向网络发送自己的凭证。移动网络对终端设备进行鉴权后,可以对其进行服务。
很多物联网设备只用于特定的场景或特定的服务,可能由物联网设备厂商批量制造。在实际使用中,物联网设备可能是由企业购买和部署的,而物联网设备在生产过程中并没有预装某个企业或运营商的鉴权凭证。
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的签约方法进行详细地说明。
请参见图2,图2是本申请实施例提供的一种签约方法的流程图,该方法可以由第一通信设备执行,如图2所示,包括以下步骤:
步骤201、第一通信设备接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
本实施例中,上述第一通信设备可以包括但不限于用户设备(User Equipment,UE)(也可称为终端设备)或无线接入网(Radio Access Network,RAN)设备等。
示例性地,上述物联网设备可以是环境物联网设备(Ambient Internet of Things, Ambient IoT设备),该环境物联网设备可以从环境中吸收能量,并可以在收到来自发送端的激励信号后通过发送该激励信号的反射信号的方式与接收端通信。第一通信设备可以是接收端,也可以是发送端,或者可以是接收端和发送端。第一通信设备也可以称为读写器。
上述签约请求信息用于为物联网设备请求签约数据。可选地,上述签约请求信息可以包括但不限于如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。上述物联网设备的标识信息可以包括物联网设备的媒体存取控制(Media Access Control,MAC)地址,产品电子代码(Electronic Product Code,EPC)码,物联网设备被配置的凭证(例如默认凭证或称缺省凭证),或者其它可以用于标识一个物联网设备的信息。
步骤202、所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
上述第一信息用于所述物联网设备的签约数据的获取,也即,物联网设备可以根据第一信息获得物联网设备的签约数据。可选地,所述第一信息可以包括但不限于如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。换而言之,签约服务器可以为物联网设备提供接入移动网络所需的签约数据。
上述签约服务器的标识信息可以包括但不限于所述签约服务器的地址(例如,IP地址)和所述签约服务器的域名(例如,全限定域名(Fully Qualified Domain Name,FQDN))等中的至少一项。其中,上述签约服务器也可以称为物联网在线签约服务器(即IoT在线签约服务器)。上述物联网设备的签约数据可以包括物联网设备接入移动网络的凭证信息。需要说明的是,上述第一通信设备可以被配置有上述签约服务器的标识信息,或者,上述第一通信设备可以从核心网网元接收上述签约服务器的标识信息。
上述第一通信设备响应于上述签约请求信息向物联网设备发送第一信息,可以理解为上述第一通信设备向物联网设备发送第一信息是由上述签约请求信息触发的。
在该实施例中,第一通信设备向物联网设备发送第一信息之后,物联网设备可以基于第一信息获取物联网设备的签约数据。例如,第一信息包括签约服务器的标识信息,物联网设备可以根据签约服务器的标识信息与签约服务器建立连接,并从签约服务器获取物联网设备的签约数据;或者,第一信息包括物联网设备的签约数据,物联网设备可以直接从接收的第一信息中获取到该签约数据。
本申请实施例提供的签约方法,通过第一通信设备接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取,这样物联网设备可以基于第一信息获取签约数据进行签约,从而可以实现物联网设备注册至移动网络以获取移动网络的服务。
值得说明的是,上述步骤202中的第一通信设备可以是接收端,也可以是发送端,或 者可以是接收端和发送端。第一通信设备也可以称为读写器。上述步骤201和上述步骤202中的第一通信设备可以是同一个设备也可以是不同的设备。例如,上述步骤201中的第一通信设备为接收端,上述步骤202中的第一通信设备为发送端,这两个第一通信设备组成了完整的读写器功能。为了简化描述,本申请以下实施例不再区分第一通信设备是发送端或接收端。
可选地,所述第一通信设备接收来自物联网设备的签约请求信息之后,所述方法还包括:
所述第一通信设备向第一网元发送签约注册请求消息,其中,所述签约注册请求消息用于请求为所述物联网设备进行签约注册;
所述第一通信设备接收来自所述第一网元的签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
本实施例中,上述第一网元可以包括但不限于移动性管理功能或会话管理功能等。
上述签约注册请求消息用于请求为所述物联网设备进行签约注册。可选地,所述签约注册请求消息可以包括但不限于如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
其中,上述物联网设备的标识信息可以参考前述步骤201中的相关描述,在此不做赘述。上述第一通信设备的标识信息,对于UE,其可以包括但不限于UE的国际移动用户识别码(International Mobile Subscription Identity,IMSI),通用公共用户标识符(Generic Public Subscription Identifier,GPSI),用户永久标识符(Subscription Permanent Identifier,SUPI),用户隐藏标识符(Subscription Concealed Identifier,SUCI),全局唯一临时标识(Globally Unique Temporary UE Identity,GUTI),永久设备标识符(Permanent Equipment Identifier,PEI),国际移动站设备识别码(International Mobile station Equipment Identity,IMEI),读写器的标识,IP地址,以及MAC地址等中的至少一项;对于RAN设备,其可以包括但不限于RAN设备的标识和读写器的标识等中的至少一项。
示例性地,上述第一物联网签约指示可以包括以下至少一项:物联网设备的标识信息,物联网设备指示,物联网设备在线签约指示,在线签约指示。
上述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。可选地,所述签约注册响应消息可以包括但不限于所述签约服务器的标识信息和第一秘钥信息中的至少一项。其中,所述第一秘钥信息可以用于所述第一通信设备和所述物联网设备之间数据的传输。上述第一秘钥信息可以包括一个或多个秘钥信息,例如,上述第一秘钥信息可以包括用于第一通信设备侧的第一子秘钥信息和用于物联网设备侧的第二子秘钥信息。
示例性地,上述第一秘钥信息可以包括用于数据加密的密钥,加密的算法,数据解密的密钥,以及解密的算法等中的至少一项。
例如,上述第一秘钥信息可以包括第一通信设备用于对向物联网设备发送数据进行加 密的秘钥信息,和/或,可以包括第一通信设备用于对来自物联网设备的数据进行解密的秘钥信息。
可选地,在该实施例中,第一通信设备向第一网元发送签约注册请求消息之后,第一网元可以对物联网设备进行鉴权。例如,可以基于物联网设备的默认凭证进行鉴权,并在鉴权成功的情况下向第一通信设备发送签约注册响应消息。第一通信设备接收来自第一网元的签约注册响应消息之后,可以向所述物联网设备发送第一信息。
本实施例通过第一通信设备向第一网元发送签约注册请求消息,并在接收来自所述第一网元的签约注册响应消息的情况下向物联网设备发送第一信息,这样可以提高物联网设备签约注册的安全性。
可选地,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还可以包括:
所述第一通信设备接收来自第一网元的所述签约服务器的标识信息。
本实施例中,上述第一网元可以被配置签约服务器的标识信息,并可以通过专用的消息向第一通信设备发送签约服务器的标识信息,也可以通过复用其他消息向第一通信设备发送签约服务器的标识信息,例如,可以通过签约注册响应消息向第一通信设备发送签约服务器的标识信息,或者可以通过会话建立响应消息向第一通信设备发送签约服务器的标识信息等。
本实施例通过第一通信设备接收来自第一网元的所述签约服务器的标识信息,相比于在第一通信设备配置签约服务器的标识信息,可以提高用于第一通信设备对应的物联网设备在线签约的签约服务器配置的灵活性。
可选地,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还可以包括:
所述第一通信设备向第一网元发送第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
所述第一通信设备接收来自所述第一网元的会话建立响应消息。
上述第一会话建立请求消息用于请求为所述物联网设备建立会话通道。可选地,所述第一会话建立请求消息可以包括但不限于如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指示为所述物联网设备获取签约数据建立会话通道。
示例性地,上述第二物联网签约指示可以包括以下至少一项:单网络切片选择辅助信息(Single Network Slice Selection Assistance Information,S-NSSAI),数据网络名称(Data Network Name,DNN),物联网设备的标识信息,物联网设备指示,物联网设备在线签约指示,在线签约指示。例如,上述第二物联网签约指示可以是建立物联网设备获取签约数据相关的PDU会话所对应的S-NSSAI和DNN。
上述会话建立响应消息可以用于指示用于物联网设备的会话通道已建立。可选地,所 述会话建立响应消息可以包括但不限于如下至少一项:所述签约服务器的标识信息,第一秘钥信息;其中,所述第一秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。上述签约服务器的标识信息和第一秘钥信息可以参见前述说明,在此不做赘述。
本实施例通过所述第一通信设备向第一网元发送第一会话建立请求消息,并接收来自所述第一网元的会话建立响应消息,以建立用于物联网设备签约的会话通道,进而第一通信设备或物联网设备可以基于该会话通道获取物联网设备的签约数据。
值得说明的是,上述第一会话建立请求消息也可以理解为用于请求为所述物联网设备获取签约数据建立会话通道。相应的,上述会话建立响应消息可以用于指示用于物联网设备获取签约数据的会话通道已建立。
需要说明的是,在物联网设备获取签约数据所需使用的会话通道已存在的情况下,可以直接利用已存在的会话通道获取物联网设备的签约数据。例如,当物联网设备签约对应的单网络切片选择辅助信息(Single Network Slice Selection Assistance Information S-NSSAI)和/或数据网络名称(Data Network Name,DNN)对应的协议数据单元(Protocol Data Unit,PDU)会话通道已经存在的情况下,可以直接利用该PDU会话通道获取物联网设备的签约数据,而第一通信设备无需向第一网元发送第一会话建立请求消息。
可选地,所述第一信息包括所述物联网设备的签约数据;
所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还包括:
所述第一通信设备通过第一会话通道从所述签约服务器获取所述物联网设备的签约数据,其中,所述第一会话通道为第二信息对应的会话通道,所述第二信息为所述物联网设备签约对应的切片选择信息和/或数据网络名称。
本实施例中,上述第一会话通道可以是物联网设备发起签约请求之前物联网设备签约对应的切片选择信息和/或数据网络名称已建立的会话通道。
示例性地,切片A对应物联网设备a1、物联网设备a2和物联网设备a3的签约会话通道,这样可以在物联网设备a1签约的过程中,建立切片A对应的会话通道;之后可以利用该会话通道获取物联网设备a2和物联网设备a3的签约数据。
本实施例通过所述物联网设备签约对应的切片和/或数据网络已有的会话通道从签约服务器获取物联网设备的签约数据,不仅可以提高获取物联网设备的签约数据的效率,还可以节省信令资源。
可选地,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,可以包括:所述第一通信设备响应于所述签约请求信息向所述物联网设备发送签约响应消息;其中,所述签约响应消息包括所述第一信息。
本实施例中,第一通信设备通过在签约响应消息中携带第一信息,这样通过上述签约响应消息不仅可以通知物联网设备网络侧已接受其签约请求,还可以告知物联网设备用于获取签约数据的第一信息,从而物联网设备可以基于第一信息获取其签约数据,不仅可以 节省信令资源,还可以提高物联网设备获取其签约数据的效率。
可选地,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还可以包括:
所述第一通信设备响应于所述签约请求信息向所述物联网设备发送签约响应消息。
本实施例中,第一通信设备可以先向物联网设备发送签约响应消息,以通知物联网设备网络侧已接受其签约请求,进而再向物联网设备发送第一信息,从而物联网设备可以基于第一信息获取签约数据进行在线签约,这样可以提高物联网设备在线签约的成功率。
可选地,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
本实施例中,上述第二秘钥信息可以用于所述第一通信设备和所述物联网设备之间数据的传输。示例性地,上述第二秘钥信息可以包括用于数据加密的密钥,加密的算法,数据解密的密钥,以及解密的算法等中的至少一项。
例如,上述第二秘钥信息可以包括用于物联网设备对向第一通信设备发送数据进行加密的秘钥信息,和/或,可以包括用于对来自第一通信设备的数据进行解密的秘钥信息。
可选地,上述第二秘钥信息可以被配置于第一通信设备;或者,第一通信设备可以从第一网元获取第二秘钥信息。可选地,上述第一秘钥信息可以包括上述第二秘钥信息。
本实施例通过在签约响应消息中携带第二秘钥信息,这样物联网设备和第一通信设备之间的数据可以基于上述第二秘钥信息进行加密或解密,进而可以提高第一通信设备和物联网设备之间数据传输的安全性。
可选地,所述第一信息为经由第三秘钥信息加密的所述签约服务器的标识信息或经由第三秘钥信息加密的所述物联网设备的签约数据,其中,所述第三秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
本实施例中,上述第三秘钥信息可以被配置于第一通信设备;或者第一通信设备可以从第一网元获取秘钥信息。可选地,上述第一秘钥信息可以包括上述第三秘钥信息。
需要说明的是,上述第二秘钥信息和第三秘钥信息可以相同,也可以不同,本实施例对此不做限定。
本实施例通过第一通信设备将签约服务器的标识信息或物联网设备的签约数据经第三秘钥信息加密后发给物联网设备,这样可以提高签约服务器的标识信息或物联网设备的签约数据传输的安全性。
可选地,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
上述第四秘钥信息可以用于第一通信设备和所述物联网设备之间数据的传输。示例性地,上述第四秘钥信息可以包括用于数据加密的密钥,加密的算法,数据解密的密钥,以 及解密的算法等中的至少一项。
例如,上述第四秘钥信息可以包括用于物联网设备对向第一通信设备发送的数据进行加密的秘钥信息,和/或,可以包括用于对来自第一通信设备的数据进行解密的秘钥信息。
示例的,签约服务器可以被配置上述第四秘钥信息,这样在第一通信设备或者物联网设备从签约服务器获取物联网设备接入移动网络的凭证信息的过程中,将该第四秘钥信息和物联网设备接入移动网络的凭证信息一并发送给第一通信设备或者物联网设备。
可选地,所述方法还可以包括:
所述第一通信设备发送第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
本实施例中,第一通信设备可以通过广播的方式发送第三物联网签约指示,或者上述第一通信设备也可以向特定的物联网设备发送第三物联网签约指示。这样接收到上述第三物联网签约指示的物联网设备可以选择上述第一通信设备进行在线签约。
值得说明的是,上述第一通信设备与物联网设备之间可以通过反向散射技术进行通信,或者也可以通过非3GPP技术进行通信,本申请实施例不作限制。
示例地,上述第一通信设备可以向物联网设备发送激励信号,该激励信号包括第三物联网签约指示,相应的,物联网设备可以使用接收到的激励信号的反射信号向第一通信设备发送签约请求信息。或者,上述第一通信设备可以向物联网设备发送非3GPP技术信号,例如,WiFi信号或蓝牙信号等,其中,上述非3GPP技术信号包括上述第三物联网签约指示。相应的,上述第一通信设备也可以通过非3GPP技术信号向上述第一通信设备发送签约请求信息。
可以理解的是,物联网设备在接收到至少两个通信设备发送的支持物联网签约的指示的情况下,可以从上述至少两个通信设备中选择一个通信设备进行签约。
可选地,所述第一通信设备为终端,所述第一通信设备向第一网元发送签约注册请求消息,包括:
所述终端通过接入网设备向第一网元发送签约注册请求消息,其中,所述终端向所述接入网设备发送的接入网消息包括所述签约注册请求消息和第二物联网签约注册指示,所述第二物联网签约注册指示用于选择支持物联网签约注册的第一网元。
本实施例中,终端可以通过接入网设备向第一网元发送签约注册请求消息。具体的,第一通信设备可以向接入网设备发送携带有签约注册请求消息和第二物联网签约注册指示的接入网消息,接入网设备根据第二物联网签约注册指示选择支持物联网注册的第一网元,例如,接入网设备根据第二物联网签约注册指示选择支持物联网注册的移动性管理功能或会话管理功能等,并向选择的第一网元发送签约注册请求消息。
请参见图3,图3是本申请实施例提供的另一种签约方法的流程图,该方法可以由物联网设备执行,如图3所示,包括以下步骤:
步骤301、物联网设备向第一通信设备发送签约请求信息,其中,所述签约请求信息 用于为所述物联网设备请求签约数据。
示例性地,上述物联网设备可以是环境物联网设备(即Ambient IoT设备),该环境物联网设备可以从环境中吸收能量,并可以在收到来自发送端的激励信号后通过发送该激励信号的反射信号的方式与接收端通信。上述第一通信设备可以包括但不限于UE或RAN设备等。
上述签约请求信息用于为物联网设备请求签约数据。可选地,上述签约请求信息可以包括但不限于如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。上述物联网设备的标识信息可以包括物联网设备的MAC地址,EPC码,物联网设备被配置的凭证(例如默认凭证或称缺省凭证),或者其它可以用于标识一个物联网设备的信息。
示例性地,上述第一物联网签约指示可以包括以下至少一项:物联网设备的标识信息,物联网设备指示,物联网设备在线签约指示,在线签约指示。
该步骤中,物联网设备可以在需要在线签约的情况下向第一通信设备发送签约请求信息,以为所述物联网设备请求签约数据。
步骤302、所述物联网设备接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
上述第一信息用于所述物联网设备的签约数据的获取。可选地,所述第一信息可以包括但不限于如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。换而言之,签约服务器可以为物联网设备提供接入移动网络所需的签约数据。
上述签约服务器的标识信息可以包括但不限于所述签约服务器的地址(例如,IP地址)和所述签约服务器的域名(例如,FQDN)等中的至少一项。其中,上述签约服务器也可以称为物联网在线签约服务器(即IoT在线签约服务器)。上述物联网设备的签约数据可以包括物联网设备接入移动网络的凭证信息。需要说明的是,上述第一通信设备可以被配置有上述签约服务器的标识信息,或者上述第一通信设备可以从核心网网元接收上述签约服务器的标识信息。
在该实施例中,物联网设备接收来自第一通信设备的第一信息之后,可以基于第一信息获取物联网设备的签约数据。例如,第一信息包括签约服务器的标识信息,物联网设备可以根据签约服务器的标识信息与签约服务器建立连接,并从签约服务器获取物联网设备的签约数据;或者,第一信息包括物联网设备的签约数据,物联网设备可以直接从接收的第一信息获取物联网设备的签约数据。可以理解的是,物联网设备在获取到签约数据之后,可以根据获取的签约数据进行签约以接入移动网络。
本申请实施例提供的签约方法,通过物联网设备向第一通信设备发送签约请求信息,并接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取,这样物联网设备可以基于第一信息获取签约数据进行签约,解决了现有技 术中没有预装企业或运营商的鉴权凭证的物联网设备难以在线签约的问题。
可选地,所述第一信息包括所述签约服务器的标识信息;
所述物联网设备接收来自所述第一通信设备的第一信息之后,所述方法还可以包括:
所述物联网设备从所述签约服务器获取所述物联网设备的签约数据。
示例的,物联网设备在接收来自第一通信设备的签约服务器的地址和域名中的至少一项之后,可以根据签约服务器的地址和域名中的至少一项与签约服务器建立连接,进而可以从签约服务器中获取物联网设备的签约数据。
可选地,物联网设备在获取到物联网设备的签约数据之后,可以基于上述签约数据中的凭证信息注册到移动网络。
可选地,物联网设备可以向第一通信设备发送第二信息,其中,第二信息可以包括上述签约数据中的凭证信息。可选地,上述第二信息还可以包括第三物联网注册指示,该第三物联网注册指示用于指示上述物联网设备已注册到移动网络。
可选地,物联网设备可以基于获取的秘钥信息对上述第二信息加密后发送给第一通信设备。相应的,第一通信设备可以基于获取的秘钥信息对接收到的第二信息进行解密。
可选地,所述物联网设备接收来自所述第一通信设备的第一信息,包括:
所述物联网设备接收来自所述第一通信设备的签约响应消息,其中,所述签约响应消息包括所述第一信息。
本实施例中,第一通信设备在签约响应消息中携带第一信息,这样物联网设备通过上述签约响应消息不仅可以获知网络侧已接受其签约请求,还可以获知用于获取签约数据的第一信息,从而物联网设备可以基于第一信息获取其签约数据,不仅可以节省信令资源,还可以提高物联网设备获取其签约数据的效率。
可选地,所述物联网设备接收来自所述第一通信设备的第一信息之前,所述方法还可以包括:
所述物联网设备接收来自所述第一通信设备的签约响应消息。
本实施例中,物联网设备先接收来自第一通信设备的签约响应消息以获知网络侧已接受其签约请求,这样可以在已确认网络侧已接受其签约请求的情况下基于第一信息获取签约数据进行在线签约,可以提高物联网设备在线签约的成功率。
可选地,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
需要说明的是,该实施方式的实现方式可以参见图2所示的实施例的相关说明,此处不作赘述。
可选地,所述方法还可以包括:
所述物联网设备接收来自所述第一通信设备的第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
需要说明的是,该实施方式的实现方式可以参见图2所示的实施例的相关说明,此处 不作赘述。
可选地,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
需要说明的是,该实施方式的实现方式可以参见图2所示的实施例的相关说明,此处不作赘述。
可选地,所述物联网设备接收来自所述第一通信设备的第一信息之后,所述方法还包括:
所述物联网设备根据第五秘钥信息对所述第一信息进行解密,其中,所述第五秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
本实施例中,上述第五秘钥信息可以为物联网设备获取的用于所述第一通信设备和所述物联网设备之间数据的传输的秘钥信息。示例性地,上述第五秘钥信息可以包括用于数据解密的密钥以及解密的算法等中的至少一项。可选地,上述第二秘钥信息可以包括上述第五秘钥信息。
请参见图4,图4是本申请实施例提供的另一种签约方法的流程图,该方法可以由第一网元执行,如图4所示,包括以下步骤:
步骤401、第一网元接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册。
本实施例中,上述第一网元可以包括但不限于移动性管理功能或会话管理功能等。上述第一通信设备可以包括支持物联网签约的UE或RAN设备等。
上述签约注册请求消息用于请求为所述物联网设备进行签约注册。可选地,所述签约注册请求消息可以包括但不限于如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
步骤402、所述第一网元对所述物联网设备进行鉴权。
示例的,第一网元可以向鉴权服务功能发送鉴权请求消息,以请求为物联网设备进行鉴权,鉴权服务功能可以依据物联网设备的默认凭证对物联网设备进行鉴权,并在鉴权通过的情况下向第一网元发送鉴权响应消息以指示物联网设备鉴权通过或鉴权成功。
步骤403、所述第一网元向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
本实施例中,上述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。可选地,所述签约注册响应消息可以包括但不限于所述签约服务器的标识信息和第一秘钥信息等中的至少一项。其中,所述第一秘钥信息可以用于所述第一通信设备和所述物联网设备之间数据的传输。上述第一秘钥信息可以包括一个或多个秘钥信息,例如,上述第一 秘钥信息可以包括用于第一通信设备侧的第一子秘钥信息和用于物联网设备侧的第二子秘钥信息。
示例的,上述第一通信设备可以在接收到来自物理网设备的的签约请求信息之后,向第一网元发送签约注册请求消息,以请求为物联网设备进行签约注册。第一网元接收到签约注册请求消息之后,对物联网设备进行鉴权,并在鉴权通过的情况下向第一通信设备发送签约注册响应消息,以指示已接受所述物联网设备的签约注册请求。
本申请实施例提供的签约方法,通过第一网元接收来自第一通信设备的签约注册请求消息,对所述物联网设备进行鉴权,并向所述第一通信设备发送签约注册响应消息,进而第一通信设备可以在网络侧已接受所述物联网设备的签约注册请求的情况下向物联网设备发送第一信息,使得物联网设备可以基于第一信息获取签约数据进行签约注册,可以提高物联网设备签约注册的安全性
可选地,所述方法还可以包括:
所述第一网元向所述第一通信设备发送签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据。
本实施例中,上述第一网元可以被配置签约服务器的标识信息,并可以通过专用的消息向第一通信设备发送签约服务器的标识信息,也可以通过复用其他消息向第一通信设备发送签约服务器的标识信息,例如,可以通过签约注册响应消息向第一通信设备发送签约服务器的标识信息,或者可以通过会话建立响应消息向第一通信设备发送签约服务器的标识信息等。
本实施例通过第一网元向所述第一通信设备发送签约服务器的标识信息,相比于在第一通信设备配置签约服务器的标识信息,可以提高用于第一通信设备对应的物联网设备在线签约的签约服务器配置的灵活性。
可选地,所述方法还可以包括:
所述第一网元接收来自所述第一通信设备的第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
所述第一网元向所述第一通信设备发送会话建立响应消息。
上述第一会话建立请求消息用于请求为所述物联网设备建立会话通道。可选地,所述第一会话建立请求消息可以包括但不限于如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指示为所述物联网设备获取签约数据建立会话通道。
上述会话建立响应消息可以用于指示用于物联网设备的会话通道已建立。可选地,所述会话建立响应消息可以包括但不限于如下至少一项:签约服务器的标识信息,第一秘钥信息。上述签约服务器的标识信息和第一秘钥信息可以参见前述说明,在此不做赘述。
示例性地,上述第二物联网签约指示可以包括以下至少一项:S-NSSAI,DNN,物联网设备的标识信息,物联网设备指示,物联网设备在线签约指示,在线签约指示。
值得说明的是,上述第一会话建立请求消息也可以理解为用于请求为所述物联网设备获取签约数据建立会话通道。相应的,上述会话建立响应消息可以用于指示用于物联网设备获取签约数据的会话通道已建立。
本实施例通过第一网元接收来自所述第一通信设备的第一会话建立请求消息,并向所述第一通信设备发送会话建立响应消息,以指示用于物联网设备的会话通道已建立,进而第一通信设备或物联网设备可以基于该会话通道获取物联网设备的签约数据。
可选地,所述第一网元被配置有如下至少一项:所述签约服务器的标识信息;所述第一秘钥信息。
示例的,在第一网元为移动性管理功能的情况下,上述第一网元可以被配置签约服务器的标识信息、上述第一秘钥信息、所述物联网设备签约对应的S-NSSAI和/或DNN、支持所述物联网设备签约的会话管理功能等中的至少一项;在第一网元为会话管理功能的情况下,上述第一网元可以被配置签约服务器的标识信息、上述第一秘钥信息、所述物联网设备签约对应的S-NSSAI和/或DNN等中的至少一项。
可选地,所述第一网元为移动性管理功能;
所述第一网元接收来自所述第一通信设备的第一会话建立请求消息之后,所述方法还包括如下至少一项:
所述移动性管理功能向会话管理功能发送第二会话建立请求消息,其中,所述会话管理功能支持物联网设备签约功能,所述第二会话建立请求消息用于请求为所述物联网设备建立会话通道;
所述移动性管理功能向所述会话管理功能发送签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据;
所述移动性管理功能向所述会话管理功能发送所述物联网设备签约对应的切片选择信息和/或数据网络名称。
上述移动性管理功能,例如,接入和移动性管理功能(Access and Mobility Management Function,AMF)。上述会话管理功能(Session Management Function,SMF)可以基于上述第二会话建立请求消息为物联网设备建立会话通道。
可选地,所述第一网元对所述物联网设备进行鉴权,包括:
所述第一网元向鉴权服务功能发送鉴权请求消息,其中,所述鉴权请求消息包括所述物联网设备的标识信息;
所述第一网元从所述鉴权服务功能接收鉴权响应消息,其中,所述鉴权响应消息用于指示所述物联网设备鉴权成功。
上述鉴权服务功能(Authentication Server Function,AUSF)在接收鉴权请求消息之后,可以对物联网设备进行鉴权,例如,可以依据物联网设备的默认凭证对物联网设备进行鉴权,并在鉴权通过的情况下向第一网元发送鉴权响应消息,以指示所述物联网设备鉴权成功。
可选地,所述第一网元在对所述物联网设备进行鉴权的过程中获取到签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据。
本实施例中,第一网元可以在鉴权过程中获取到签约服务器的标识信息,并可以并发送给第一通信设备。
可选地,所述方法还包括如下至少一项:
所述第一网元记录所述物联网设备的签约状态;
所述第一网元记录所述第一通信设备的物联网签约状态。
示例性地,上述物联网设备的签约状态可以包括上述物联网设备的在线签约状态,其中,上述在线签约状态用于指示该物联网设备正处于获取签约数据的状态。
示例性地,上述第一通信设备的物联网签约状态可以包括上述第一通信设备的物联网在线签约状态,该物联网在线签约状态用于指示该物联网设备正通过该第一通信设备获取签约数据,或者,指示该第一通信设备处于为物联网设备获取签约数据的状态。
以下以图5所示的网络架构对本申请实施例进行举例说明:
如图5所示,物联网设备以环境IoT设备21(即AmbientIoT设备)为例,其中,AmbientIoT设备需要从环境中吸收能量,以接收激励信号,并在收到激励信号后发送反射信号的方式与读写器联系。UE或RAN22作为物联网设备的读写器,物联网设备可以通过读写器接入移动网络23,以通过移动网络23访问环境物联网服务器24(例如环境IoTAPP)。
示例一:UE作为读写器,物联网设备(即IoT设备)获取签约数据。
参见图6,本申请实施例提供的签约方法可以包括如下步骤:
步骤a0、UE向IoT设备发送第一IoT在线签约指示(即上述第三物联网签约指示),用以指示UE支持IoT在线签约。相应的,IoT设备接收该IoT在线签约指示。
示例性地,UE可以向IoT设备发送激励信号,其中包括第一IoT在线签约指示;或者,UE可以向IoT设备发送非3GPP技术信号,例如,WiFi信号或蓝牙信号,其中包括第一IoT在线签约指示。
需要说明的是,上述步骤a0可以为可选步骤。
步骤a1、IoT设备向UE发送IoT在线签约请求(例如,上述签约请求信息),该IoT在线签约请求包括IoT设备的标识信息。
示例性地,IoT设备的标识信息可以为物联网设备的媒体存取控制(Media Access Control,MAC)地址,产品电子代码(Electronic Product Code,EPC)码,物联网设备的凭证(例如缺省凭证或默认凭证),或者其它可以用于标识一个物联网设备的信息。其中IoT设备的默认凭证可以是预先配置在IoT设备上的。
可选地,上述IoT在线签约请求还可以包括第二IoT在线签约指示(即上述第一物联网签约指示),以指示为IoT设备请求签约数据。
示例性地,IoT设备可以使用接收到的激励信号的反射信号,发送IoT在线签约请求。
可以理解的是,如果步骤a0发生,IoT设备可以选择支持在线签约的UE,向该UE 发送IoT在线签约请求。
步骤a2、UE接收到IoT在线签约请求,向AMF发送IoT在线签约注册请求消息(即上述签约注册请求消息),该IoT在线签约注册请求消息用于表示IoT设备请求获取签约数据。
可选地,上述IoT在线签约请求消息可以包括物联网设备的标识和UE的标识。可选地,上述IoT在线签约请求消息还可以包括第三IoT在线签约指示(即上述第一物联网签约注册指示),用于用于指示为所述物联网设备请求签约注册。
可选地,UE可以在接入网消息中携带IoT在线签约注册请求消息和第三IoT在线签约指示,进而接入网可以根据该第三IoT在线签约指示选择支持IoT在线签约的AMF,并向选择的AMF发送上述IoT在线签约注册请求消息。
步骤a3、AMF向AUSF发送鉴权请求,其中包括IoT设备的标识信息。
步骤a4、AMF接收来自AUSF的鉴权响应消息,指示IoT设备鉴权成功。
示例性地,IoT设备使用IoT设备的标识信息(例如,默认凭证)进行鉴权。
可选地,AMF在鉴权流程中可以获取IoT在线签约服务器(即配置服务器(Provisioning Server,PVS))的地址或域名。
步骤a5、AMF向UE发送IoT在线签约注册响应消息(即上述签约注册响应消息),该在线签约注册响应消息可以用于指示已经接受IoT设备的在线签约注册请求。
可选地,AMF可以记录该IoT设备的在线签约状态。
可选地,AMF可以记录该UE的IoT在线签约状态。
可选地,UE可以向IoT设备发送IoT在线签约响应消息(即上述签约响应消息)。
可选地,IoT在线签约响应消息还可以包括IoT在线签约服务器的IP地址或者域名(例如,全限定域名(Fully Qualified Domain Name,FQDN))。
可选地,IoT在线签约响应消息还可以包括UE与IoT设备交互的数据加密密钥。
步骤a6、UE向AMF发送IoT会话建立请求消息(即上述第一会话建立请求消息),该IoT会话建立请求消息用于指示为IoT设备建立会话通道,以获取签约数据。
可选地,上述IoT会话建立请求消息可以携带IoT设备的标识信息。可选地,上述IoT会话建立请求消息还可以包括UE的标识信息。
示例性地,UE向AMF发送PDU会话建立请求消息。
可选地,支持IoT在线签约的AMF可以被配置IoT在线签约所使用的S-NSSAI和/或DNN。上述支持IoT在线签约的AMF还可以被配置支持IoT在线签约的SMF。可选地,上述支持IoT在线签约的AMF还可以被配置UE与IoT设备交互的数据加密密钥。
可选地,AMF可以选择支持IoT在线签约的SMF,并向SMF发送IoT会话建立请求消息。
可选地,AMF可以向SMF发送IoT在线签约服务器的地址或域名。
可选地,AMF可以向SMF发送IoT在线签约所使用的S-NSSAI和/或DNN。
可选地,支持IoT在线签约的SMF可以被配置IoT在线签约服务器的地址或域名。可选地,支持IoT在线签约的SMF还可以被配置或者从AMF获取UE与IoT设备交互的数据加密密钥。
步骤a7、UE接收IoT会话建立响应消息。
可选地,上述IoT会话建立响应消息可以包括IoT在线签约服务器的地址或域名。
可选地,IoT在线签约响应消息还可以包括UE与IoT设备交互的密钥。
需要说明的是,步骤a6和步骤a7可以为可选步骤。示例性地,当IoT在线签约所使用的S-NSSAI和/或DNN对应的PDU会话已经存在时,不执行上述步骤a6和步骤a7。
步骤a8、UE向IoT设备发送IoT在线签约服务器的地址或域名。
可选地,UE可以使用步骤a7中接收到的数据加密秘钥对IoT在线签约服务器的地址或域名进行加密。
需要说明的是,上述步骤a8和步骤a51可以合并执行。例如,UE向Iot设备发送IoT在线签约响应消息,该IoT在线签约响应消息可以包括IoT在线签约服务器的地址或域名。
步骤a9、IoT设备从IoT在线签约服务器(即PVS)获取IoT设备签约数据。
示例性地,IoT设备可以根据IoT在线签约服务器的地址或域名与IoT在线签约服务器建立连接,并从IoT在线签约服务器获取IoT设备签约数据。
其中,上述IoT设备签约数据包括IoT设备接入移动网络的凭证。可选地,上述IoT设备签约数据还可以包括IoT设备数据的密钥。
步骤a10、IoT设备使用获取的签约数据中的凭证注册到移动网络。示例性地,IoT设备向UE发送签约数据中的凭证。
可选地,IoT设备向UE发送凭证的消息中还可以包括IoT注册指示,用于指示为IoT设备进行注册。
可选地,IoT设备可以使用获取的密钥对凭证进行加密。相应地,UE使用获取的密钥对接收到的信息进行解密,以获取IoT设备的凭证。
步骤a11、UE向AMF发送IoT设备注册请求,该IoT设备注册请求用于将IoT设备注册到移动网络。
其中,上述IoT设备注册请求可以包括IoT设备的凭证。可选地,上述IoT设备注册请求还可以包括IoT注册指示,用于指示为IoT设备进行注册。
示例二:UE作为读写器,UE代理IoT设备获取签约数据。
如图7所示,本申请实施例提供的签约方法可以包括如下步骤:
步骤b0、UE向IoT设备发送第一IoT在线签约指示(即上述第三物联网签约指示),用以指示UE支持IoT在线签约。相应的,IoT设备接收该IoT在线签约指示。
步骤b1、IoT设备向UE发送IoT在线签约请求(例如,上述签约请求信息),该IoT在线签约请求包括IoT设备的标识信息。
步骤b 2、UE接收到IoT在线签约请求,向AMF发送IoT在线签约注册请求消息(即 上述签约注册请求消息),该IoT在线签约注册请求消息用于表示IoT设备请求获取签约数据。
步骤b3、AMF向AUSF发送鉴权请求,其中包括IoT设备的标识信息。
步骤b4、AMF接收来自AUSF的鉴权响应消息,指示IoT设备鉴权成功。
步骤b 5、AMF向UE发送IoT在线签约注册响应消息(即上述签约注册响应消息),该在线签约注册响应消息可以用于指示已经接受IoT设备的在线签约注册请求。
步骤b6、UE向AMF发送IoT会话建立请求消息(即上述第一会话建立请求消息),该IoT会话建立请求消息用于指示为IoT设备建立会话通道,以获取签约数据。
步骤b7、UE接收IoT会话建立响应消息。
需要说明的是,本实施例的上述步骤b0至步骤b7可以分别参见上述步骤a0至步骤a7的对应说明,在此不做赘述。
步骤b8、UE从IoT在线签约服务器(即PVS)获取IoT设备签约数据。
示例性地,UE根据IoT在线签约服务器的地址或域名与IoT在线签约服务器建立连接,从IoT在线签约服务器获取IoT设备签约数据。
其中,IoT设备签约数据可以参考示例一中的相关的描述,在此不做赘述。
步骤b9、UE向IoT设备发送IoT设备签约数据。
可选地,UE可以使用步骤b7中接收到的密钥对IoT在线签约服务器的地址或域名进行加密。
值得说明的是,步骤b9和步骤b51可以合并执行。例如,UE向IoT设备发送IoT在线签约响应消息,其中包括IoT在线签约服务器的地址或域名。
步骤b10、IoT设备使用获取的签约数据中的凭证注册到移动网络。示例的,IoT设备向UE发送签约数据中的凭证。
步骤b11、UE向AMF发送IoT设备注册请求,该IoT设备注册请求用于将IoT设备注册到移动网络。
需要说明的是,本实施例的上述步骤b10至步骤b11可以分别参见上述步骤a10至步骤a11的对应说明,在此不做赘述。
需要说明的是,上述示例虽均以读写器UE为例,但上述示例的方案也可以适用于读写器为接入网设备的架构中。具体的,当读写器为接入网设备时,示例的,接入网设备与AMF之间交互的消息可以使用新一代应用协议(Next Generation Application Protocol,NGAP)协议传输。
此外还需说明的是,上述示例中UE或RAN也可以以其他接入方式与物联网设备连接,其中,上述其他接入方式可以包括但不限于WiFi、蓝牙、有线连接等。上述物联网设备也可以为其他设备,如非3GPP设备等。
综上可知,本申请实施例通过读写器获取物联网设备的在线签约请求,为物联网设备建立会话通道用于获取签约数据,从而可以完成物联网设备的在线签约。
需要说明的是,本申请实施例提供的签约方法,执行主体可以为签约装置,或者,该签约装置中的用于执行签约方法的控制模块。本申请实施例中以签约装置执行签约方法为例,说明本申请实施例提供的签约装置。
请参见图8,图8是本申请实施例提供的一种签约装置的结构图,如图8所示,签约装置800包括:
第一接收模块801,用于接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
第一发送模块802,用于向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
可选地,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
可选地,所述签约服务器的标识信息包括如下至少一项:所述签约服务器的地址,所述签约服务器的域名。
可选地,所述签约请求信息包括如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。
可选地,所述装置还包括:
第二发送模块,用于所述接收来自物联网设备的签约请求信息之后,向第一网元发送签约注册请求消息,其中,所述签约注册请求消息用于请求为所述物联网设备进行签约注册;
第二接收模块,用于接收来自所述第一网元的签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
可选地,所述签约注册请求消息包括如下至少一项:所述物联网设备的标识信息,第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
可选地,所述签约注册响应消息包括所述签约服务器的标识信息。
可选地,所述装置还包括:
第三接收模块,用于所述向所述物联网设备发送第一信息之前,接收来自第一网元的所述签约服务器的标识信息。
可选地,所述装置还包括:
第三发送模块,用于所述向所述物联网设备发送第一信息之前,向第一网元发送第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
第四接收模块,用于接收来自所述第一网元的会话建立响应消息。
可选地,所述第一会话建立请求消息包括如下至少一项:所述物联网设备的标识信息,第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指 示为所述物联网设备获取签约数据建立会话通道。
可选地,所述会话建立响应消息包括如下至少一项:所述签约服务器的标识信息,第一秘钥信息;其中,所述第一秘钥信息用于第一通信设备和所述物联网设备之间数据的传输。
可选地,所述第一信息包括所述物联网设备的签约数据;
所述装置还包括:
第一获取模块,用于所述向所述物联网设备发送第一信息之前,通过第一会话通道从所述签约服务器获取所述物联网设备的签约数据,其中,所述第一会话通道为第二信息对应的会话通道,所述第二信息为所述物联网设备签约对应的切片选择信息和/或数据网络名称。
可选地,所述第一发送模块具体用于:
向所述物联网设备发送签约响应消息;其中,所述签约响应消息包括所述第一信息。
可选地,所述装置还包括:
第四发送模块,用于所述向所述物联网设备发送第一信息之前,向所述物联网设备发送签约响应消息。
可选地,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于第一通信设备和所述物联网设备之间数据的传输。
可选地,所述第一信息为经由第三秘钥信息加密的所述签约服务器的标识信息或经由第三秘钥信息加密的所述物联网设备的签约数据,其中,所述第三秘钥信息用于第一通信设备和所述物联网设备之间数据的传输。
可选地,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于第一通信设备和所述物联网设备之间数据的传输。
可选地,所述装置还包括:
第五发送模块,用于发送第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述装置支持物联网签约。
可选地,所述第二发送模块具体用于:
通过接入网设备向第一网元发送签约注册请求消息,其中,所述第二发送模块向所述接入网设备发送的接入网消息包括所述签约注册请求消息和第二物联网签约注册指示,所述第二物联网签约注册指示用于选择支持物联网签约注册的第一网元。
本申请实施例中的签约装置800可以是电子设备,例如,具有操作系统电子设备,也可以是电子设备中的部件,例如,集成电路或芯片。示例性地,该电子设备可以是终端或无线接入网设备,也可以为除终端或接入网设备之外的其他设备。示例性地,上述终端或无线接入网设备可以包括但不限于上述所列举的终端或无线接入网设备的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不 作具体限定。
本申请实施例提供的签约装置能够实现图2的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
请参见图9,图9是本申请实施例提供的一种签约装置的结构图,如图9所示,签约装置900包括:
第六发送模块901,用于向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为物联网设备请求签约数据;
第五接收模块902,用于接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
可选地,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
可选地,所述签约服务器的标识信息包括如下至少一项:所述签约服务器的地址,所述签约服务器的域名。
可选地,所述签约请求信息包括如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。
可选地,所述第一信息包括所述签约服务器的标识信息;
所述装置还包括:
第二获取模块,用于所述接收来自所述第一通信设备的第一信息之后,从所述签约服务器获取所述物联网设备的签约数据。
可选地,所述第五接收模块具体用于:
接收来自所述第一通信设备的签约响应消息,其中,所述签约响应消息包括所述第一信息。
可选地,所述装置还包括:
第六接收模块,用于所述接收来自所述第一通信设备的第一信息之前,接收来自所述第一通信设备的签约响应消息。
可选地,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述装置还包括:
第七接收模块,用于所述接收来自所述第一通信设备的第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
可选地,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述装置还包括:
解密模块,用于所述接收来自所述第一通信设备的第一信息之后,根据第五秘钥信息对所述第一信息进行解密,其中,所述第五秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
本申请实施例中的签约装置900可以是电子设备,例如,具有操作系统电子设备,也可以是电子设备中的部件,例如,集成电路或芯片。示例性地,该电子设备可以是物联网设备,也可以为除物联网设备之外的其他设备。示例性地,上述物联网设备可以包括但不限于上述所列举的物联网设备的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的签约装置能够实现图3的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
请参见图10,图10是本申请实施例提供的一种签约装置的结构图,如图10所示,签约装置1000包括:
第八接收模块1001,用于接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;
鉴权模块1002,用于对所述物联网设备进行鉴权;
第七发送模块1003,用于向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
可选地,所述签约注册请求消息包括如下至少一项:所述签约注册请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
可选地,所述装置还包括:
第八发送模块,用于向所述第一通信设备发送签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据。
可选地,所述装置还包括:
第九接收模块,用于接收来自所述第一通信设备的第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
第九发送模块,用于向所述第一通信设备发送会话建立响应消息。
可选地,所述第一会话建立请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指示为物联网设备建立会话通道。
可选地,所述会话建立响应消息包括如下至少一项:
签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据;
第一秘钥信息,其中,所述第一秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述装置被配置有如下至少一项:所述签约服务器的标识信息;所述第一秘 钥信息。
可选地,所述装置为移动性管理功能;
所述装置还包括第十发送模块,所述第十发送模块用于如下至少一项:
所述接收来自所述第一通信设备的第一会话建立请求消息之后,向会话管理功能发送第二会话建立请求消息,其中,所述会话管理功能支持物联网设备签约功能,所述第二会话建立请求消息用于请求为所述物联网设备建立会话通道;
所述接收来自所述第一通信设备的第一会话建立请求消息之后,向所述会话管理功能发送签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据;
所述接收来自所述第一通信设备的第一会话建立请求消息之后,向所述会话管理功能发送所述物联网设备签约对应的切片选择信息和/或数据网络名称。
可选地,所述鉴权模块具体用于:
向鉴权服务功能发送鉴权请求消息,其中,所述鉴权请求消息包括所述物联网设备的标识信息;
从所述鉴权服务功能接收鉴权响应消息,其中,所述鉴权响应消息用于指示所述物联网设备鉴权成功。
可选地,所述装置在对所述物联网设备进行鉴权的过程中获取到签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据。
可选地,所述装置还包括记录模块,所述记录模块具体用于如下至少一项:
记录所述物联网设备的签约状态;
记录所述第一通信设备的物联网签约状态。
本申请实施例中的签约装置1000可以是电子设备,例如,具有操作系统电子设备,也可以是电子设备中的部件,例如,集成电路或芯片。示例性地,该电子设备可以是第一网元,也可以为除第一网元之外的其他设备。示例性地,上述第一网元可以包括但不限于上述所列举的第一网元的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的签约装置能够实现图4的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
可选地,如图11所示,本申请实施例还提供一种电子设备1100,包括处理器1101和存储器1102,存储器1102上存储有可在所述处理器1101上运行的程序或指令,例如,该电子设备1100为第一通信设备时,该程序或指令被处理器1101执行时实现上述第一通信设备侧签约方法实施例的各个步骤,且能达到相同的技术效果。该电子设备1100为物联网设备时,该程序或指令被处理器1101执行时实现上述物联网设备侧签约方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。该电子设备1100为第一网元时,该程序或指令被处理器1101执行时实现上述第一网元侧签约方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述
本申请实施例还提供一种通信设备,包括处理器和通信接口,其中,所述通信接口用于接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。该通信设备实施例是与上述第一通信设备侧方法实施例对应的,上述方法实施例的各个实施过程和实现方式均可适用于该通信设备实施例中,且能达到相同的技术效果。具体地,图12为实现本申请实施例的一种通信设备的硬件结构示意图。
该通信设备1200包括但不限于:射频单元1201、网络模块1202、音频输出单元1203、输入单元1204、传感器1205、显示单元1206、用户输入单元1207、接口单元1208、存储器1209、以及处理器1210等中的至少部分部件。
本领域技术人员可以理解,通信设备1200还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器1210逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图12中示出的通信设备结构并不构成对通信设备的限定,通信设备可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。
应理解的是,本申请实施例中,输入单元1204可以包括图形处理单元(Graphics Processing Unit,GPU)12041和麦克风12042,图形处理器12041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元1206可包括显示面板12061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板12061。用户输入单元1207包括触控面板12071以及其他输入设备12072中的至少一种。触控面板12071,也称为触摸屏。触控面板12071可包括触摸检测装置和触摸控制器两个部分。其他输入设备12072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。
本申请实施例中,射频单元1201接收来自第一网元或物联网设备的数据后,可以传输给处理器1210进行处理;另外,射频单元1201可以向第一网元或物联网设备发送数据。通常,射频单元121包括但不限于天线、至少一个放大器、收发信机、耦合器、低噪声放大器、双工器等。
存储器1209可用于存储软件程序或指令以及各种数据。存储器1209可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器1209可以包括易失性存储器或非易失性存储器,或者,存储器1209可以包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动 态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器1209包括但不限于这些和任意其它适合类型的存储器。
处理器1210可包括一个或多个处理单元;可选地,处理器1210集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器1210中。
其中,射频单元1201,用于接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
本申请实施例通过接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取,这样物联网设备可以基于第一信息获取签约数据进行签约,解决了现有技术中没有预装企业或运营商的鉴权凭证的物联网设备难以在线签约的问题。
可选地,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
可选地,所述签约服务器的标识信息包括如下至少一项:所述签约服务器的地址,所述签约服务器的域名。
可选地,所述签约请求信息包括如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。
可选地,所述射频单元1201,还用于:
所述接收来自物联网设备的签约请求信息之后,向第一网元发送签约注册请求消息,其中,所述签约注册请求消息用于请求为所述物联网设备进行签约注册;
接收来自所述第一网元的签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
可选地,所述签约注册请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
可选地,所述签约注册响应消息包括所述签约服务器的标识信息。
可选地,所述射频单元1201,还用于:
所述向所述物联网设备发送第一信息之前,接收来自第一网元的所述签约服务器的标识信息。
可选地,所述射频单元1201,还用于:
所述向所述物联网设备发送第一信息之前,向第一网元发送第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
接收来自所述第一网元的会话建立响应消息。
可选地,所述第一会话建立请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指示为所述物联网设备获取签约数据建立会话通道。
可选地,所述会话建立响应消息包括如下至少一项:所述签约服务器的标识信息,第一秘钥信息;其中,所述第一秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述第一信息包括所述物联网设备的签约数据;
可选地,所述射频单元1201,还用于:
所述向所述物联网设备发送第一信息之前,通过第一会话通道从所述签约服务器获取所述物联网设备的签约数据,其中,所述第一会话通道为第二信息对应的会话通道,所述第二信息为所述物联网设备签约对应的切片选择信息和/或数据网络名称。
可选地,所述射频单元1201,具体用于:
向所述物联网设备发送签约响应消息;其中,所述签约响应消息包括所述第一信息。
可选地,所述射频单元1201,还用于:
所述向所述物联网设备发送第一信息之前,向所述物联网设备发送签约响应消息。
可选地,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述第一信息为经由第三秘钥信息加密的所述签约服务器的标识信息或经由第三秘钥信息加密的所述物联网设备的签约数据,其中,所述第三秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述射频单元1201,还用于:
发送第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
可选地,所述射频单元1201,还用于:
通过接入网设备向第一网元发送签约注册请求消息,其中,所述第一通信设备向所述接入网设备发送的接入网消息包括所述签约注册请求消息和第二物联网签约注册指示,所述第二物联网签约注册指示用于选择支持物联网签约注册的第一网元。
本申请实施例还提供一种物联网设备,包括处理器和通信接口,其中,所述通信接口用于向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为物联网设备请求签约数据;接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。该物联网设备实施例是与上述物联网设备侧方法实施例对应的,上述方法实施例的各个实施过程和实现方式均可适用于该物联网设备实施例中,且能达到相同的技术效果。
可选地,如图13所示,本申请实施例还提供一种物联网设备1300,包括处理器1301,存储器1302和收发模块1303。其中,上述收发模块1303可以包括射频收发机或蓝牙模块或WIFI模块等。
其中,所述收发模块1303用于:向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为物联网设备请求签约数据;接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
可选地,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
可选地,所述签约服务器的标识信息包括如下至少一项:所述签约服务器的地址,所述签约服务器的域名。
可选地,所述签约请求信息包括如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。
可选地,所述第一信息包括所述签约服务器的标识信息;
所述收发模块1303,还用于:
所述接收来自所述第一通信设备的第一信息之后,从所述签约服务器获取所述物联网设备的签约数据。
可选地,所述收发模块1303,具体用于:
接收来自所述第一通信设备的签约响应消息,其中,所述签约响应消息包括所述第一信息。
所述收发模块1303,还用于:
所述接收来自所述第一通信设备的第一信息之前,接收来自所述第一通信设备的签约响应消息。
可选地,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述收发模块1303,还用于:
接收来自所述第一通信设备的第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
可选地,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘 钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
可选地,所述收发模块1303,还用于:
所述接收来自所述第一通信设备的第一信息之后,根据第五秘钥信息对所述第一信息进行解密,其中,所述第五秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
本申请实施例还提供一种网元,包括处理器和通信接口,其中,所述通信接口用于接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;对所述物联网设备进行鉴权;向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。该网元实施例是与上述第一网元侧方法实施例对应的,上述方法实施例的各个实施过程和实现方式均可适用于该网元实施例中,且能达到相同的技术效果。
具体地,本申请实施例还提供了一种网元。如图14所示,该网元1400包括:天线141、射频装置142、基带装置143、处理器144和存储器145。天线141与射频装置142连接。在上行方向上,射频装置142通过天线141接收信息,将接收的信息发送给基带装置143进行处理。在下行方向上,基带装置143对要发送的信息进行处理,并发送给射频装置142,射频装置142对收到的信息进行处理后经过天线141发送出去。
以上实施例中第一网元执行的方法可以在基带装置143中实现,该基带装置143包括基带处理器。
基带装置143例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图14所示,其中一个芯片例如为基带处理器,通过总线接口与存储器145连接,以调用存储器145中的程序,执行以上方法实施例中所示的网络设备操作。
该网元还可以包括网络接口146,该接口例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本申请实施例的网元1400还包括:存储在存储器145上并可在处理器144上运行的指令或程序,处理器144调用存储器145中的指令或程序执行图10所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
具体地,本申请实施例的网元还包括:存储在存储器145上并可在处理器144上运行的指令或程序,处理器144调用存储器145中的指令或程序执行图10所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述第一通信设备侧签约方法实施例的各个过程,或者实现物联网设备侧签约方法实施例的各个过程,或者实现第一网元侧签约方法实施例的各个过程且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的终端中的处理器,或者上述实施例中所述的 网络侧设备中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述第一通信设备侧签约方法实施例的各个过程,或者实现物联网设备侧签约方法实施例的各个过程,或者实现第一网元侧签约方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述签约方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种签约系统,包括:通信设备、物联网设备及网元,所述通信设备用于执行如图2及上述各个方法实施例的各个过程,所述物联网设备用于执行如图3及上述各个方法实施例的各个过程,所述网元用于执行如图4及上述各个方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络侧设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (51)

  1. 一种签约方法,包括:
    第一通信设备接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
    所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
  2. 根据权利要求1所述的方法,其中,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
  3. 根据权利要求2所述的方法,其中,所述签约服务器的标识信息包括如下至少一项:所述签约服务器的地址,所述签约服务器的域名。
  4. 根据权利要求1所述的方法,其中,所述签约请求信息包括如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。
  5. 根据权利要求1或2所述的方法,其中,所述第一通信设备接收来自物联网设备的签约请求信息之后,所述方法还包括:
    所述第一通信设备向第一网元发送签约注册请求消息,其中,所述签约注册请求消息用于请求为所述物联网设备进行签约注册;
    所述第一通信设备接收来自所述第一网元的签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
  6. 根据权利要求5所述的方法,其中,所述签约注册请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
  7. 根据权利要求5所述的方法,其中,所述签约注册响应消息包括签约服务器的标识信息。
  8. 根据权利要求2所述的方法,其中,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还包括:
    所述第一通信设备接收来自第一网元的所述签约服务器的标识信息。
  9. 根据权利要求1或2所述的方法,其中,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还包括:
    所述第一通信设备向第一网元发送第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
    所述第一通信设备接收来自所述第一网元的会话建立响应消息。
  10. 根据权利要求9所述的方法,其中,所述第一会话建立请求消息包括如下至少一 项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指示为所述物联网设备获取签约数据建立会话通道。
  11. 根据权利要求9所述的方法,其中,所述会话建立响应消息包括如下至少一项:签约服务器的标识信息,第一秘钥信息;其中,所述第一秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  12. 根据权利要求2所述的方法,其中,所述第一信息包括所述物联网设备的签约数据;
    所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还包括:
    所述第一通信设备通过第一会话通道从所述签约服务器获取所述物联网设备的签约数据,其中,所述第一会话通道为第二信息对应的会话通道,所述第二信息为所述物联网设备签约对应的切片选择信息和/或数据网络名称。
  13. 根据权利要求1所述的方法,其中,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息,包括:
    所述第一通信设备响应于所述签约请求信息向所述物联网设备发送签约响应消息;其中,所述签约响应消息包括所述第一信息。
  14. 根据权利要求1所述的方法,其中,所述第一通信设备响应于所述签约请求信息向所述物联网设备发送第一信息之前,所述方法还包括:
    所述第一通信设备响应于所述签约请求信息向所述物联网设备发送签约响应消息。
  15. 根据权利要求13或14所述的方法,其中,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  16. 根据权利要求2所述的方法,其中,所述第一信息为经由第三秘钥信息加密的所述签约服务器的标识信息或经由第三秘钥信息加密的所述物联网设备的签约数据,其中,所述第三秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  17. 根据权利要求1所述的方法,其中,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  18. 根据权利要求1所述的方法,其中,所述方法还包括:
    所述第一通信设备发送第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
  19. 根据权利要求5所述的方法,其中,所述第一通信设备为终端,所述第一通信设备向第一网元发送签约注册请求消息,包括:
    所述终端通过接入网设备向第一网元发送签约注册请求消息,其中,所述终端向所述接入网设备发送的接入网消息包括所述签约注册请求消息和第二物联网签约注册指示,所 述第二物联网签约注册指示用于选择支持物联网签约注册的第一网元。
  20. 一种签约方法,包括:
    物联网设备向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
    所述物联网设备接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
  21. 根据权利要求20所述的方法,其中,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
  22. 根据权利要求21所述的方法,其中,所述签约服务器的标识信息包括如下至少一项:所述签约服务器的地址,所述签约服务器的域名。
  23. 根据权利要求20所述的方法,其中,所述签约请求信息包括如下至少一项:所述物联网设备的标识信息,第一物联网签约指示;其中,所述第一物联网签约指示用于指示为所述物联网设备请求签约数据。
  24. 根据权利要求21所述的方法,其中,所述第一信息包括所述签约服务器的标识信息;
    所述物联网设备接收来自所述第一通信设备的第一信息之后,所述方法还包括:
    所述物联网设备从所述签约服务器获取所述物联网设备的签约数据。
  25. 根据权利要求20所述的方法,其中,所述物联网设备接收来自所述第一通信设备的第一信息,包括:
    所述物联网设备接收来自所述第一通信设备的签约响应消息,其中,所述签约响应消息包括所述第一信息。
  26. 根据权利要求20所述的方法,其中,所述物联网设备接收来自所述第一通信设备的第一信息之前,所述方法还包括:
    所述物联网设备接收来自所述第一通信设备的签约响应消息。
  27. 根据权利要求25或26所述的方法,其中,所述签约响应消息包括第二秘钥信息,所述第二秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  28. 根据权利要求20所述的方法,其中,所述方法还包括:
    所述物联网设备接收来自所述第一通信设备的第三物联网签约指示,其中,所述第三物联网签约指示用于指示所述第一通信设备支持物联网签约。
  29. 根据权利要求20所述的方法,其中,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息,或者,所述物联网设备的签约数据包括所述物联网设备接入移动网络的凭证信息和第四秘钥信息;其中,所述第四秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  30. 根据权利要求20所述的方法,其中,所述物联网设备接收来自所述第一通信设 备的第一信息之后,所述方法还包括:
    所述物联网设备根据第五秘钥信息对所述第一信息进行解密,其中,所述第五秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  31. 一种签约方法,包括:
    第一网元接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;
    所述第一网元对所述物联网设备进行鉴权;
    所述第一网元向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
  32. 根据权利要求31所述的方法,其中,所述签约注册请求消息包括如下至少一项:所述签约注册请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
  33. 根据权利要求31所述的方法,其中,所述方法还包括:
    所述第一网元向所述第一通信设备发送签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据。
  34. 根据权利要求31所述的方法,其中,所述方法还包括:
    所述第一网元接收来自所述第一通信设备的第一会话建立请求消息,其中,所述第一会话建立请求消息用于请求为所述物联网设备建立会话通道;
    所述第一网元向所述第一通信设备发送会话建立响应消息。
  35. 根据权利要求34所述的方法,其中,所述第一会话建立请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第二物联网签约指示;其中,所述第二物联网签约指示用于指示为物联网设备获取签约数据建立会话通道。
  36. 根据权利要求34所述的方法,其中,所述会话建立响应消息包括如下至少一项:
    签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据;
    第一秘钥信息,其中,所述第一秘钥信息用于所述第一通信设备和所述物联网设备之间数据的传输。
  37. 根据权利要求36所述的方法,其中,所述第一网元被配置有如下至少一项:所述签约服务器的标识信息;所述第一秘钥信息。
  38. 根据权利要求34所述的方法,其中,所述第一网元为移动性管理功能;
    所述第一网元接收来自所述第一通信设备的第一会话建立请求消息之后,所述方法还包括如下至少一项:
    所述移动性管理功能向会话管理功能发送第二会话建立请求消息,其中,所述会话管理功能支持物联网设备签约功能,所述第二会话建立请求消息用于请求为所述物联网设备建立会话通道;
    所述移动性管理功能向所述会话管理功能发送签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据;
    所述移动性管理功能向所述会话管理功能发送所述物联网设备签约对应的切片选择信息和/或数据网络名称。
  39. 根据权利要求31所述的方法,其中,所述第一网元对所述物联网设备进行鉴权,包括:
    所述第一网元向鉴权服务功能发送鉴权请求消息,其中,所述鉴权请求消息包括所述物联网设备的标识信息;
    所述第一网元从所述鉴权服务功能接收鉴权响应消息,其中,所述鉴权响应消息用于指示所述物联网设备鉴权成功。
  40. 根据权利要求39所述的方法,其中,所述第一网元在对所述物联网设备进行鉴权的过程中获取到签约服务器的标识信息,其中,所述签约服务器支持为所述物联网设备提供签约数据。
  41. 根据权利要求31所述的方法,其中,所述方法还包括如下至少一项:
    所述第一网元记录所述物联网设备的签约状态;
    所述第一网元记录所述第一通信设备的物联网签约状态。
  42. 一种签约装置,包括:
    第一接收模块,用于接收来自物联网设备的签约请求信息,其中,所述签约请求信息用于为所述物联网设备请求签约数据;
    第一发送模块,用于向所述物联网设备发送第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
  43. 根据权利要求42所述的装置,其中,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
  44. 一种签约装置,包括:
    第六发送模块,用于向第一通信设备发送签约请求信息,其中,所述签约请求信息用于为物联网设备请求签约数据;
    第五接收模块,用于接收来自所述第一通信设备的第一信息,其中,所述第一信息用于所述物联网设备的签约数据的获取。
  45. 根据权利要求44所述的装置,其中,所述第一信息包括如下至少一项:签约服务器的标识信息,所述物联网设备的签约数据;其中,所述签约服务器支持为所述物联网设备提供签约数据。
  46. 一种签约装置,包括:
    第八接收模块,用于接收来自第一通信设备的签约注册请求消息,其中,所述签约注册请求消息用于请求为物联网设备进行签约注册;
    鉴权模块,用于对所述物联网设备进行鉴权;
    第七发送模块,用于向所述第一通信设备发送签约注册响应消息,其中,所述签约注册响应消息用于指示已接受所述物联网设备的签约注册请求。
  47. 根据权利要求46所述的装置,其中,所述签约注册请求消息包括如下至少一项:所述物联网设备的标识信息,所述第一通信设备的标识信息,第一物联网签约注册指示;其中,所述第一物联网签约注册指示用于指示为所述物联网设备请求签约注册。
  48. 一种通信设备,包括处理器,存储器及存储在所述存储器上并可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至19任一项所述的签约方法的步骤。
  49. 一种物联网设备,包括处理器,存储器及存储在所述存储器上并可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求20至30任一项所述的签约方法的步骤。
  50. 一种网元,包括处理器,存储器及存储在所述存储器上并可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求31至41任一项所述的签约方法的步骤。
  51. 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至19任一项所述的签约方法,或者实现如权利要求20至30任一项所述的签约方法的步骤,或者实现如权利要求31至41任一项所述的签约方法的步骤。
PCT/CN2023/089269 2022-04-22 2023-04-19 签约方法、装置、通信设备、物联网设备及网元 WO2023202631A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202210432195.1 2022-04-22
CN202210432195.1A CN116980876A (zh) 2022-04-22 2022-04-22 签约方法、装置、通信设备、物联网设备及网元

Publications (1)

Publication Number Publication Date
WO2023202631A1 true WO2023202631A1 (zh) 2023-10-26

Family

ID=88419255

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/089269 WO2023202631A1 (zh) 2022-04-22 2023-04-19 签约方法、装置、通信设备、物联网设备及网元

Country Status (2)

Country Link
CN (1) CN116980876A (zh)
WO (1) WO2023202631A1 (zh)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109150807A (zh) * 2017-06-19 2019-01-04 上海中兴软件有限责任公司 凭证分发方法、用户终端、用户签约认证管理单元及介质
CN109150507A (zh) * 2017-06-19 2019-01-04 上海中兴软件有限责任公司 一种设备凭证分发方法和系统、用户设备及管理实体
CN109981543A (zh) * 2017-12-28 2019-07-05 中兴通讯股份有限公司 一种安全保护方法、装置及系统
WO2021225355A1 (en) * 2020-05-05 2021-11-11 Samsung Electronics Co., Ltd. Method and system for n3iwf selection in user equipment for network connectivity
CN113950045A (zh) * 2020-07-17 2022-01-18 荣耀终端有限公司 签约数据的下载方法和电子设备
CN114071452A (zh) * 2020-08-07 2022-02-18 华为技术有限公司 用户签约数据的获取方法及装置

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109150807A (zh) * 2017-06-19 2019-01-04 上海中兴软件有限责任公司 凭证分发方法、用户终端、用户签约认证管理单元及介质
CN109150507A (zh) * 2017-06-19 2019-01-04 上海中兴软件有限责任公司 一种设备凭证分发方法和系统、用户设备及管理实体
CN109981543A (zh) * 2017-12-28 2019-07-05 中兴通讯股份有限公司 一种安全保护方法、装置及系统
WO2021225355A1 (en) * 2020-05-05 2021-11-11 Samsung Electronics Co., Ltd. Method and system for n3iwf selection in user equipment for network connectivity
CN113950045A (zh) * 2020-07-17 2022-01-18 荣耀终端有限公司 签约数据的下载方法和电子设备
CN114071452A (zh) * 2020-08-07 2022-02-18 华为技术有限公司 用户签约数据的获取方法及装置

Also Published As

Publication number Publication date
CN116980876A (zh) 2023-10-31

Similar Documents

Publication Publication Date Title
US9137012B2 (en) Wireless authentication methods and apparatus
US10798082B2 (en) Network authentication triggering method and related device
US20160050565A1 (en) Secure provisioning of an authentication credential
US10470102B2 (en) MAC address-bound WLAN password
KR20160083128A (ko) 암호화된 통신을 위한 방법 및 시스템
JP2018532325A (ja) ユーザ機器ueのアクセス方法、アクセスデバイス、およびアクセスシステム
WO2023280194A1 (zh) 网络连接管理方法、装置、可读介质、程序产品及电子设备
US11121871B2 (en) Secured key exchange for wireless local area network (WLAN) zero configuration
CN108012264A (zh) 用于802.1x载体热点和Wi-Fi呼叫认证的基于经加密的IMSI的方案
CN113518348B (zh) 业务处理方法、装置、系统及存储介质
US20180095500A1 (en) Tap-to-dock
JP2016519873A (ja) 汎用ブートストラッピングアーキテクチャを用いてセキュアな音声通信を確立する方法
WO2020029754A1 (zh) 一种签约信息配置方法及通信设备
WO2022028259A1 (zh) 用户签约数据的获取方法及装置
US20220272511A1 (en) Subscription data management method and apparatus
US9930048B2 (en) Customer identification for seamless wireless-network access
WO2007034299A1 (en) Re-keying in a generic bootstrapping architecture following handover of a mobile terminal
TW202112101A (zh) 密鑰產生以及終端配網方法、裝置、設備
CN106599698A (zh) 一种加密图片、解密图片的方法和装置
CN113301563A (zh) 网络配置方法、装置、设备和存储介质
WO2020029735A1 (zh) 扩展的通用引导架构认证方法、装置及存储介质
US20240089728A1 (en) Communication method and apparatus
EP4013091A1 (en) Communication method and apparatus
WO2023071836A1 (zh) 一种通信方法及装置
WO2023202631A1 (zh) 签约方法、装置、通信设备、物联网设备及网元

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23791286

Country of ref document: EP

Kind code of ref document: A1