WO2024199161A1 - 鉴权方法、鉴权装置、通信设备及可读存储介质 - Google Patents
鉴权方法、鉴权装置、通信设备及可读存储介质 Download PDFInfo
- Publication number
- WO2024199161A1 WO2024199161A1 PCT/CN2024/083454 CN2024083454W WO2024199161A1 WO 2024199161 A1 WO2024199161 A1 WO 2024199161A1 CN 2024083454 W CN2024083454 W CN 2024083454W WO 2024199161 A1 WO2024199161 A1 WO 2024199161A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- tag
- reader
- information
- writer
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/40—Security arrangements using identity modules
- H04W12/47—Security arrangements using identity modules using near field communication [NFC] or radio frequency identification [RFID] modules
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/80—Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
Definitions
- the present application belongs to the field of wireless communication technology, and specifically relates to an authentication method, an authentication device, a communication device and a readable storage medium.
- UE User Equipment
- RAN Radio Access Network
- Radio Frequency Identification In Radio Frequency Identification (RFID) technology, information transmission between the reader and the tag works in a secure mode.
- the authentication process must be performed first. Specifically, it usually includes the identity authentication process of the reader and/or tag, so that information transmission between the reader and the tag is carried out on the premise of confirming that their identity is legitimate.
- RFID protocol the following three types of authentication are supported:
- One-way authentication of the tag to the reader is used to verify whether the reader has passed the authentication, that is, whether the identity of the reader is legal;
- the reader performs one-way authentication on the tag, which is used for the reader to verify whether the tag has passed the authentication, that is, whether the tag's identity is legal;
- Bidirectional authentication is used for the tag to authenticate whether the reader is authenticated and the reader to authenticate whether the tag is authenticated, that is, whether the identity of the reader is legal and whether the identity of the tag is legal.
- the identification/authentication scheme in the above RFID technology cannot be fully applied to 3GPP-related communication systems.
- the main reason is that in the RFID technology solution, the legitimacy of the tag identity is directly authenticated by the reader/writer.
- the reader/writer may be implemented based on the UE or RAN.
- the UE or RAN itself is also an untrusted node.
- the embodiments of the present application provide an authentication method, an authentication device, a communication device and a readable storage medium, which can solve the problem of how to authenticate a tag in a 3GPP system and how the tag authenticates a UE or a RAN as a reader/writer.
- a tag device authentication method comprising:
- the first device sends a first authentication command, the first authentication command is used for authentication of the tag device, and the first authentication command includes configuration information of security parameters of the tag device; wherein the first device is an access network device, a terminal or a core network device;
- the first device receives a first response, wherein the first response includes: first authentication information of the tag device;
- the first device determines whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device.
- a tag device authentication method comprising:
- the tag device receives a first authentication command sent by a first device, where the first authentication command is used for authentication of the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- the first device is an access network device, a terminal or a core network device;
- the tag device sends a first response to the first device according to the first authentication command, where the first response includes first authentication information of the tag device.
- a reader-writer device authentication method comprising:
- the first device sends a second authentication command, the second authentication command is used for authentication of the reader device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader device; wherein the first device is the reader device or the core network device, and the reader device is the access network device or the terminal;
- the first device receives a second response, wherein the second response includes an authentication result of whether the reader/writer device passes authentication or fails authentication.
- a reader-writer device authentication method comprising:
- the tag device receives a second authentication command sent by the first device, the second authentication command is used for authentication of the reader device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader device; wherein the first device is the reader device or a core network device, and the reader device is an access network device or a terminal;
- the tag device determines whether the reader/writer device passes the authentication according to the second authentication command.
- a security authentication method comprising:
- the core network device receives a request sent by a reader/writer device, wherein the request includes identification information of a tag device and/or a second input parameter for calculating authentication information of the reader/writer device;
- the reader/writer device is an access network device or a terminal;
- the core network device sends the security parameters of the tag device and/or the third authentication information of the reader/writer device to the reader/writer device, wherein the third authentication information is determined by the core network device through calculation based on the security parameters of the tag device and the second input parameters.
- an authentication device for a tag device comprising:
- a first sending module used to send a first authentication command, the first authentication command is used for authenticating a tag device, and the first authentication command includes configuration information of security parameters of the tag device; wherein the authentication device of the tag device is an access network device, a terminal or a core network device;
- a first receiving module configured to receive a first response, wherein the first response includes: first authentication information of the tag device;
- the first determination module is used to determine whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device.
- an authentication device for a tag device comprising:
- a first receiving module configured to receive a first authentication command sent by a first device, wherein the first authentication command is used for authenticating the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- the first device is an access network device, a terminal or a core network device;
- the first sending module is used to send a first response to the first device according to the first authentication command, where the first response includes first authentication information of the tag device.
- an authentication device for a reader/writer device comprising:
- a first sending module is used to send a second authentication command, the second authentication command is used for authenticating the reader/writer device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader/writer device; wherein the authentication device of the reader/writer device is the reader/writer device or a core network device, and the reader/writer device is an access network device or a terminal;
- the first receiving module is used to receive a second response, wherein the second response includes: an authentication result of whether the reader/writer device passes the authentication or fails the authentication.
- an authentication device for a reader/writer device comprising:
- a first receiving module is used to receive a second authentication command sent by a first device, the second authentication command is used for authentication of a reader/writer device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader/writer device; wherein the first device is the reader/writer device or a core network device, and the reader/writer device is an access network device or a terminal;
- the first determination module is used to determine whether the reader/writer device passes the authentication according to the second authentication command.
- a security authentication device comprising:
- a first receiving module is used to receive a request sent by a reader/writer device, wherein the request includes identification information of a tag device and/or a second input parameter used to calculate authentication information of the reader/writer device;
- the reader/writer device is an access network device or a terminal;
- the first sending module is used to send the security parameters of the tag device and/or the third authentication information of the reader/writer device to the reader/writer device, wherein the third authentication information is determined by the core network device through calculation based on the security parameters of the tag device and the second input parameters.
- a communication device comprising a processor and a memory, the memory storing A program or instruction running on the processor, which, when executed by the processor, implements the steps of the method described in the first aspect, the second aspect, the third aspect, the fourth aspect or the fifth aspect.
- a first device comprising a processor and a communication interface, wherein the communication interface is used to send a first authentication command, the first authentication command is used for authenticating a tag device, and the first authentication command includes configuration information of security parameters of the tag device; wherein the first device is an access network device, a terminal or a core network device; a first response is received, the first response includes: first authentication information of the tag device; the processor is used to determine whether the tag device has passed the authentication based on the configuration information of the security parameters and the first authentication information of the tag device.
- a tag device comprising a processor and a communication interface, wherein the communication interface is used to receive a first authentication command sent by a first device, the first authentication command is used for authenticating the tag device, and the first authentication command includes configuration information of security parameters of the tag device; the first device is an access network device, a terminal or a core network device; according to the first authentication command, a first response is sent to the first device, and the first response includes first authentication information of the tag device.
- a first device comprising a processor and a communication interface, wherein the communication interface is used to send a second authentication command, the second authentication command is used for authenticating a reader/writer device, the second authentication command includes configuration information of security parameters of a tag device and third authentication information of the reader/writer device; wherein the first device is the reader/writer device or a core network device, and the reader/writer device is an access network device or a terminal; a second response is received, and the second response includes: an authentication result of whether the reader/writer device passes or fails authentication.
- a tag device comprising a processor and a communication interface, wherein the communication interface is used to receive a request sent by a reader/writer device, the request including identification information of the tag device and/or a second input parameter for calculating authentication information of the reader/writer device; the reader/writer device is an access network device or a terminal; the processor is used to send security parameters of the tag device and/or third authentication information of the reader/writer device to the reader/writer device, wherein the third authentication information is determined by the core network device through calculation based on the security parameters of the tag device and the second input parameter.
- a core network device comprising a processor and a communication interface, wherein the communication interface is used to receive a first request for obtaining security parameters sent by a first device, the first request including identification information of a tag device; the first device is a reader/writer device, and the reader/writer device is an access network device or a terminal; when it is determined that the first device is a trusted device, the security parameters of the tag device are sent to the first device.
- a readable storage medium on which a program or instruction is stored.
- the program or instruction is executed by a processor, the steps of the method described in the first aspect, the second aspect, the third aspect, the fourth aspect or the fifth aspect are implemented.
- a wireless communication system comprising: a first device and a tag device, wherein the first device can be used to execute the steps of the method described in the first aspect, and the tag device can be used to execute the steps of the method described in the second aspect, or the first device can be used to execute the steps of the method described in the third aspect, and the tag device can be used to execute the steps of the method described in the fourth aspect.
- a wireless communication system including: a first device, a tag device and a core network device, wherein the first device can be used to execute the steps of the method described in the first aspect, the tag device can be used to execute the steps of the method described in the second aspect, and the core network device can be used to execute the steps of the method described in the fifth aspect.
- a wireless communication system including: a first device, a tag device and a core network device, wherein the first device can be used to execute the steps of the method described in the third aspect, the tag device can be used to execute the steps of the method described in the fourth aspect, and the core network device can be used to execute the steps of the method described in the fifth aspect.
- a chip comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, the second aspect, the third aspect, the fourth aspect or the fifth aspect.
- a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the program/program product is executed by at least one processor to implement the steps of the method described in the first aspect, the second aspect, the third aspect, the fourth aspect or the fifth aspect.
- the process of how to authenticate a tag device in a wireless communication system and the process of how the tag device authenticates the UE or RAN as a reader/writer device are clarified, so that the information transmission between the reader/writer device and the tag device works in a secure mode.
- FIG1 is a block diagram of a wireless communication system applicable to an embodiment of the present application.
- FIG. 2 is a schematic diagram of UE acting as a reader to transmit data from Ambient IoT (Tag) to Ambient IoT App;
- FIG. 3 is a schematic diagram of RAN acting as a reader to transmit data from Ambient IoT (Tag) to Ambient IoT App;
- FIG4 is a schematic diagram of a flow chart of an authentication method for a tag device according to an embodiment of the present application.
- FIG5 is a second flow chart of the authentication method of the tag device according to the embodiment of the present application.
- FIG6 is a flowchart of an authentication method for a reader/writer device according to an embodiment of the present application.
- FIG7 is a second flow chart of the authentication method of the reader/writer device according to an embodiment of the present application.
- FIG8 is a schematic diagram of a flow chart of a security authentication method according to an embodiment of the present application.
- FIG9 is a schematic diagram of a flow chart of an authentication method for a tag device according to Embodiment 1 of the present application.
- FIG10 is a schematic diagram of a flow chart of an authentication method for a tag device according to Embodiment 2 of the present application.
- FIG11 is a flow chart of an authentication method for a reader/writer device according to Embodiment 3 of the present application.
- FIG. 12 is a schematic flow chart of an authentication method for a reader/writer device according to Embodiment 4 of the present application.
- FIG13 is a flow chart of a two-way authentication method according to Embodiment 5 of the present application.
- FIG14 is a flow chart of a two-way authentication method according to Embodiment 6 of the present application.
- FIG15 is a flow chart of an authentication method for a tag device according to Embodiment 7 of the present application.
- FIG16 is a flow chart of an authentication method for a reader/writer device according to Embodiment 8 of the present application.
- FIG17 is a flow chart of a method for two-way authentication according to Embodiment 9 of the present application.
- FIG18 is a schematic diagram of a structure of an authentication device of a tag device according to an embodiment of the present application.
- FIG19 is a second structural diagram of the authentication device of the tag device according to an embodiment of the present application.
- FIG20 is a schematic diagram of a structure of an authentication device of a reader/writer device according to an embodiment of the present application.
- FIG21 is a second structural diagram of the authentication device of the reader/writer device according to an embodiment of the present application.
- FIG22 is a schematic diagram of the structure of a security authentication device according to an embodiment of the present application.
- FIG23 is a schematic diagram of the structure of a communication device according to an embodiment of the present application.
- FIG24 is a schematic diagram of the hardware structure of a terminal according to an embodiment of the present application.
- FIG25 is a schematic diagram of a hardware structure of a network side device according to an embodiment of the present application.
- FIG. 26 is a second schematic diagram of the hardware structure of the network side device according to an embodiment of the present application.
- first, second, etc. of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by “first” and “second” are generally of one type, and the number of objects is not limited, for example, the first object can be one or more.
- “or” in the present application represents at least one of the connected objects.
- “A or B” covers three schemes, namely, Scheme 1: including A but not including B; Scheme 2: including B but not including A; Scheme 3: including both A and B.
- the character "/" generally indicates that the objects associated with each other are in an "or” relationship.
- indication in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication).
- a direct indication can be understood as the sender explicitly informing the receiver of specific information, operations to be performed, or request results in the sent indication;
- an indirect indication can be understood as the receiver determining the corresponding information according to the indication sent by the sender, or making a judgment and determining the operations to be performed or request results according to the judgment result.
- LTE Long Term Evolution
- LTE-A Long Term Evolution-Advanced
- CDMA Code Division Multiple Access
- TDMA Time Division Multiple Access
- FDMA Frequency Division Multiple Access
- OFDMA Orthogonal Frequency Division Multiple Access
- SC-FDMA Single-carrier Frequency-Division Multiple Access
- NR New Radio
- FIG1 shows a block diagram of a wireless communication system applicable to an embodiment of the present application.
- the wireless communication system includes a terminal 11 and a network side device 12 .
- the terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a handheld computer, a netbook, an ultra-mobile personal computer (Ultra-mobile Personal Computer, UMPC), a mobile Internet device (Mobile Internet Device, MID), an augmented reality (Augmented Reality, AR), a virtual reality (Virtual Reality, VR) device, a robot, a wearable device (Wearable Device), a flight vehicle (flight vehicle), a vehicle user equipment (VUE), a shipborne equipment, a pedestrian terminal (Pedestrian User Equipment, PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines or furniture, etc.), a game console, a personal computer (
- Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc.
- the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application.
- the network side device 12 may include an access network device or a core network device, wherein the access network device may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit.
- the access network device may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point (Access Point, AS) or a wireless fidelity (Wireless Fidelity, WiFi) node, etc.
- WLAN wireless Local Area Network
- AS Access Point
- WiFi wireless Fidelity
- the base station can be called Node B (Node B, NB), Evolved Node B (Evolved Node B, eNB), the next generation Node B (the next generation Node B, gNB), New Radio Node B (New Radio Node B, NR Node B), access point, Relay Base Station (Relay Base Station, RBS), Serving Base Station (Serving Base Station, SBS), Base Transceiver Station (Base Transceiver Station, BTS), radio base station, radio transceiver, base Basic Service Set (BSS), Extended Service Set (ESS), home Node B (HNB), home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that, in the embodiments of the present application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
- the core network device may include the core network device may include but is not limited to at least one of the following: a core network node, a core network function, a mobility management entity (Mobility Management Entity, MME), an access mobility management function (Access and Mobility Management Function, AMF), a session management function (Session Management Function, SMF), a user plane function (User Plane Function, UPF), a policy control function (Policy Control Function, PCF), a policy and charging rules function unit (Policy and Charging Rules Function, PCRF), an edge application service discovery function (Edge Application Server Discovery Function, EASDF), a unified data management (Unified Data Management, UDM), a unified data repository (Unified Data Repository, UDR), a home user server (Home Subscriber Server, HSS), a centralized network configuration (Centralized network configuration, CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (Local NEF, or L-NEF), Binding Support Function (BSF),
- core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited. But not limited to at least one of the following: core network node, core network function, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), edge application service discovery function (Edge Application Server Discovery Function, EASDF), unified data management (Unified Data Management, UDM), unified data storage (Unified Data Repository, UDR), home user server (Home Subscriber Server, HSS), centralized network configuration (CNC), network storage function (Network Repository Function, NRF), network exposure function (Network Exposure Function, NEF), local NEF (Local NEF, or L-NE
- MME mobility management entity
- AMF Access Mobility Management Function
- Ambient IoT (abbreviated as A-IOT) is a new 3GPP IoT technology to be studied. Ambient IoT devices have ultra-low complexity and ultra-low power consumption.
- Ambient IoT also known as ambient power-enabled Internet of Things (Ambient power-enabled IoT)
- Ambient IoT devices are powered by energy harvesting.
- Ambient IoT devices do not have batteries or have limited energy storage capabilities (for example, using a capacitor).
- Energy sources for energy harvesting include radio waves, light, motion, heat, or other suitable energy sources.
- Ambient IoT devices The energy of Ambient IoT devices comes from energy harvesting. Regarding energy storage, Ambient IoT devices can have the following characteristics:
- Ambient IoT devices can be classified based on energy source, energy storage capability, passive or active emission, etc.
- Ambient IoT passive or active transmission has the following communication modes:
- Ambient IoT devices have power to work continuously or for a period of time.
- the energy can come from continuous energy harvesting, or it may have a certain energy storage capacity, such as being equipped with capacitors.
- the device can only support short-term active states and intermittent communication.
- the device can decide when to communicate with the network.
- the device does not necessarily monitor the network, that is, it may not monitor the called service for a long time.
- the Ambient IoT device can communicate with the Ambient IoT APP through the UE or RAN as a reader, as shown in Figures 2 and 3.
- the UE can act as a reader to transmit the data of the Ambient IoT (Tag) to the Ambient IoT App.
- the RAN directly acts as a reader to transmit the data of the Ambient IoT (Tag) to the Ambient IoT App.
- the participation of the 5G core network (5GC) is optional.
- Backscatter communication refers to the backscatter communication equipment using the radio frequency signals in other devices or the environment to modulate the signal to transmit its own information.
- the backscatter communication terminal equipment (BSC Tag, also known as BSC UE) can be a tag in traditional video identification (Radio Frequency Identification, RFID), or an ambient energy storage IoT (Ambient IoT), or a passive IoT (Passive-IoT) device.
- RFID Radio Frequency Identification
- Ambient IoT Ambient IoT
- Passive-IoT passive IoT
- the technical feature of backscatter technology is that it can complete the transmission of its own signal by changing the characteristics of the received ambient radio frequency signal, such as phase or amplitude information, to achieve extremely low power or zero power information transmission.
- RFID is a traditional backscatter communication system. Its main design goal is to identify the backscatter communication (BSC) device (i.e., Tag) within the coverage range of the reader (Identity document, ID) and read data.
- BSC backscatter communication
- the information transmission between the reader and the tag works in a safe mode.
- an authentication process must be performed first. Specifically, it usually includes an identity authentication process of the reader and/or the tag, so that information transmission between the reader and the tag is carried out on the premise that the identity is legal.
- the following three types of authentication are supported:
- One-way authentication of the tag to the reader is used to verify whether the reader has passed the authentication, that is, whether the identity of the reader is legal;
- the reader performs one-way authentication on the tag, which is used for the reader to verify whether the tag has passed the authentication, that is, whether the tag's identity is legal;
- Bidirectional authentication is used for the tag to authenticate whether the reader is authenticated and the reader to authenticate whether the tag is authenticated, that is, whether the identity of the reader is legal and whether the identity of the tag is legal.
- the protocol only standardizes the tag's security authentication command (Authenticate command).
- Authenticate command The security authentication protocol process requires several specific steps, and the supported authentication algorithms and processes are not standardized.
- an embodiment of the present application provides an authentication method for a tag device, including:
- Step 41 The first device sends a first authentication command, where the first authentication command is used for authenticating the tag device, and the first authentication command includes configuration information of security parameters of the tag device; wherein the first device is an access network (RAN) device, a terminal (UE) or a core network device;
- RAN access network
- UE terminal
- core network device RAN
- the core network device may be a core network node in related technologies, such as AMF, etc., or may be a newly introduced core network node.
- Step 42 The first device receives a first response, where the first response includes: first authentication information of the tag device;
- the first authentication information may be an authentication code or a data signature.
- Step 43 The first device determines whether the tag device passes the authentication according to the configuration information of the security parameters and the first authentication information of the tag device.
- the process of how to authenticate a tag device in a wireless communication system is clarified so that the information transmission between the reader/writer device (terminal or access network device) and the tag device works in a secure mode.
- the security parameters (security credential) of the tag device include at least one of the following: root key (RK) index (the root key is uniquely determined by the index value), communication encryption algorithm (used to indicate the data transmission encryption and integrity protection algorithm supported by the tag device), key length, security mode (used to indicate whether the tag device needs to perform security authentication, security authentication includes one-way authentication or two-way authentication, one-way authentication is the tag device authenticating the reader device or the reader device authenticating the tag device, whether secure communication is required), security function (used to indicate the security authentication algorithm supported by the tag device, the security authentication algorithm includes one-way authentication algorithm or two-way authentication algorithm, the one-way authentication algorithm is the algorithm used by the tag device to authenticate the reader device or the reader device to authenticate the tag device), Tsec (the reference time for the reader device to wait for the tag device to respond after sending a security authentication command or a security communication command, in units of 10ms).
- RK root key
- communication encryption algorithm used to indicate the data transmission encryption and integrity protection algorithm supported by the tag device
- the prerequisite step of the security authentication process is that the reader needs to trigger the security parameter acquisition process to obtain the tag's security parameters from the tag.
- the reader may be implemented based on access network devices or terminals. Since access network devices or terminals may be untrusted nodes, the process of the reader obtaining the tag's security parameters from the tag can be omitted.
- the first device is an access network device or a terminal
- the operator pre-configures the security parameters of all or part of the tag devices controlled by the operator to all trusted first devices through operation administration and maintenance (Operation Administration Maintenance, OAM).
- the core network device can authenticate the first device, and if the first device is authenticated as a trusted node, the security parameters of the tag device can be sent to the first device, thereby ensuring that the access network device or terminal participating in the authentication is a trusted device.
- the first device when the first device is an access network device or a terminal, if the first device supports storage Before authenticating the tag device, it is first determined whether the security parameters of the tag device are stored.
- the first device sends the first authentication command, including: when the first device has the security parameters of the tag device, the first device does not need to obtain the security parameters of the tag device from the core network device, and sends the first authentication command to the tag device. That is, when the first device has the security parameters of the tag device, the first device can directly send the first authentication command to the tag device.
- the first device before the first device sends the first authentication command, it also includes: the first device sends a first request to the core network device for obtaining the security parameters, wherein the first request includes the identification information of the tag device; the first device receives the security parameters from the core network device. That is to say, in the case where the first device does not have the security parameters of the tag device, the first device first sends a first request to request to obtain the security parameters, and after obtaining the first security parameters, sends the first authentication command to the tag device.
- the first device can optionally support the situation where the security parameters of the pre-configured tag device are supported.
- a first authentication command is sent to the tag device.
- the security parameters of the pre-configured tag device are determined, the security parameters are obtained from the core network device.
- the first device is an access network device or a terminal; if the first device does not support storing security parameters, it is not necessary to determine whether the security parameters of the tag device are stored before authenticating the tag device.
- the method further includes:
- the first device sends a first request for acquiring security parameters to a core network device, wherein the first request includes identification information of the tag device, wherein the first request includes identification information of the tag device;
- the first device receives the security parameter from the core network device.
- the first device may not support the security parameters of the pre-configured tag device and directly obtain the security parameters from the core network device.
- the identification information of the tag device includes at least one of the following: the electronic product code (EPC) of the tag device, the tag identity (TID) of the tag device, the tag allocation identifier (the tag allocation identifier is stored in the tag information area.
- the data in the tag information area is written when the tag chip is produced and cannot be modified after writing).
- the identification information of the tag device is consistent with the production configuration of the tag device and cannot be modified after writing.
- the first device is a core network device
- the first device sending the first authentication command includes: the first device sending the first authentication command to the tag device through the access network device;
- the first device receiving the first response includes: the first device receiving the first response forwarded by the access network device;
- the access network device may transparently forward the first authentication command and the first response.
- the first device is an access network device where a source serving cell of the tag device is located;
- the first device sending the first authentication command includes: the first device sending the first authentication command through the destination service small
- the access network device where the target serving cell of the tag device is located sends the first authentication command to the tag device, wherein the access network device where the target serving cell of the tag device is located forwards the first authentication command;
- the first device receiving the first response includes: the first device receiving the first response forwarded by an access network device where a destination serving cell of the tag device is located.
- the access network device where the destination serving cell of the tag device is located may transparently forward the first authentication command and the first response.
- the access network device where the source service cell of the tag device is located can notify the access network device where the target service cell of the tag device is located of the authentication result of whether the tag device has passed the authentication.
- the notification here can be a displayed indication or an implicit indication.
- the implicit method is, for example, to initiate the UE context acquisition process between the access network device where the target service cell is located and the access network device where the source service cell is located.
- the first device determines whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device, including:
- the first device determines the second authentication information of the tag device by calculation according to the configuration information of the security parameter of the tag device and the first input parameter used to calculate the first authentication information of the tag device;
- the first device compares the second authentication information with the received first authentication information of the tag device to see whether they are the same;
- the second authentication information is the same as the first authentication information, determining that the tag device has passed the authentication
- the tag device If the second authentication information is different from the first authentication information, it is determined that the tag device has not passed the authentication.
- the calculation method of the first authentication information and the second authentication information is not limited, but the calculation method of the first authentication information and the second authentication information needs to be the same.
- the first input parameter includes at least one of the following: identification information of the tag device, identification information of the service cell of the tag device, context identification of the tag device, time information corresponding to the transmission of the first authentication information, frequency domain resource information corresponding to the transmission of the first authentication information, and beam information corresponding to the transmission of the first authentication information.
- the first device when the first device is a core network device, before the first device determines the first authentication information of the tag device by calculation based on the first input parameter and the configuration information of the security parameters of the tag device, it also includes: the first device receives the first input parameter sent by the access network device where the service cell of the tag device is located.
- the first input parameter includes at least one of the following: identification information of the tag device, identification information of the service cell of the tag device, context identification of the tag device, time information corresponding to the transmission of the first authentication information, frequency domain resource information corresponding to the transmission of the first authentication information, and beam information corresponding to the transmission of the first authentication information.
- the first device is an access network device or a terminal
- the determining whether the tag device passes the authentication further includes:
- the first device performs at least one of the following:
- control command includes at least one of the following:
- Deactivate command used to deactivate the tag device
- Inventory command used to inventory tag devices
- Read command used to read data from the tag device
- Control command used to control the tag device.
- the object of forwarding data may be a core network device in the related technology, such as a user plane function (UPF), or a newly introduced core network device, or an A-IOT App server, etc., which is not limited here.
- a core network device in the related technology, such as a user plane function (UPF), or a newly introduced core network device, or an A-IOT App server, etc., which is not limited here.
- UPF user plane function
- A-IOT App server etc.
- the first device is a core network device
- the determining whether the tag device passes the authentication further includes at least one of the following:
- the first device sends an authentication result indicating whether the tag device has passed the authentication to the access network device or the terminal;
- the core network device explicitly sends the authentication result to the access network device or terminal.
- the first device sends the authorization information of the tag device to the access network device or the terminal, and the authorization information is sent when the tag device passes the authentication.
- the core network device sends the authorization information of the tag device to the access network device or the terminal on the premise that the tag device passes the authentication, and the authorization information implicitly indicates that the tag device passes the authentication.
- the present embodiment also provides an authentication method for a tag device, including:
- Step 51 The tag device receives a first authentication command sent by a first device, where the first authentication command is used for authentication of the tag device and includes configuration information of security parameters of the tag device; the first device is an access network device, a terminal or a core network device;
- Step 52 The tag device sends a first response to the first device according to the first authentication command, where the first response includes first authentication information of the tag device.
- the first authentication information may be an authentication code or a data signature.
- the process of how to authenticate the tag device in the 3GPP system is clarified, so that the information transmission between the reader/writer device (access network device or terminal) and the tag device works in a secure mode.
- the security parameters (security credential) of the tag device include at least one of the following: a root key (RK) index (the root key is uniquely determined by the index value), a communication encryption algorithm (used to indicate the tag device Supported data transmission encryption and integrity protection algorithms), key length, security mode (used to indicate whether the tag device needs to perform security authentication, security authentication includes one-way authentication or two-way authentication, one-way authentication is the tag device authenticating the reader device or the reader device authenticating the tag device, whether secure communication is required), security function (used to indicate the security authentication algorithm supported by the tag device, the security authentication algorithm includes one-way authentication algorithm or two-way authentication algorithm, the one-way authentication algorithm is the algorithm used by the tag device to authenticate the reader device or the algorithm used by the reader device to authenticate the tag device), Tsec (the reference time for the reader device to wait for the tag device to respond after sending a security authentication command or a security communication command, in units of 10ms).
- RK root key
- the security authentication includes one-way authentication or two-way authentication,
- the first device is an access network device or a terminal
- the operator pre-configures the security parameters of all or part of the tag devices controlled by the operator to all trusted first devices through operation administration and maintenance (Operation Administration Maintenance, OAM).
- the core network device can authenticate the first device, and if the first device is authenticated as a trusted node, the security parameters of the tag device can be sent to the first device, thereby ensuring that the access network device or terminal participating in the authentication is a trusted device.
- the tag device sends a first response to the first device according to the first authentication command, including:
- the tag device determines the first authentication information of the tag device by calculation according to the configuration information of the security parameter and the first input parameter used to calculate the first authentication information of the tag device;
- the tag device sends the first response to the first device, where the first response includes the first authentication information.
- the first input parameter includes at least one of the following: identification information of the tag device, identification information of the service cell of the tag device, context identification of the tag device, time information corresponding to the transmission of the first authentication information, frequency domain resource information corresponding to the transmission of the first authentication information, and beam information corresponding to the transmission of the first authentication information.
- the above embodiment is about the authentication of tag devices.
- the following will introduce the authentication of reader/writer devices.
- the present embodiment also provides an authentication method for a reader/writer device, including:
- Step 61 The first device sends a second authentication command, which is used for authenticating the reader device.
- the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader device.
- the first device is the reader device or a core network device, and the reader device is an access network device or a terminal.
- the third authentication information may be an authentication code or a data signature.
- Step 62 The first device receives a second response, wherein the second response includes an authentication result indicating whether the reader/writer device has passed authentication or failed authentication.
- the process of how a tag device authenticates a UE or RAN as a reader/writer device in a 3GPP system is clarified, so that information transmission between the reader/writer device and the tag device works in a secure mode.
- the first device is an access network device or a terminal
- the operator pre-configures the security parameters of all or part of the tag devices controlled by the operator to all trusted first devices through operation administration and maintenance (Operation Administration Maintenance, OAM).
- the core network device can authenticate the first device, and if the first device is authenticated as a trusted node, the security parameters of the tag device can be sent to the first device, thereby ensuring that the access network device or terminal participating in the authentication is a trusted device.
- the process further includes: the first device determines third authentication information of the reader/writer device.
- the first device is the reader/writer device, and before the first device sends the second authentication command, the following step is further included:
- the first device sends a first request for obtaining security parameters to the core network device (this situation is usually when the first device does not support the security parameters of the pre-configured tag device, and directly obtains the security parameters from the core network device);
- the first device sends a first request for obtaining the security parameters to the core network device (this case is usually when the first device supports pre-configured security parameters of the tag device. If it is not determined that the security parameters of the tag device are not pre-configured, the security parameters are obtained from the core network device);
- the first request includes identification information of the tag device.
- the first device is a reader/writer device, and before the first device sends the second authentication command, the following step is further included:
- the first device sends a first request for obtaining security parameters to the core network device, wherein the first request includes identification information of the tag device and a second input parameter for calculating the third authentication information of the reader/writer device (this situation is usually when the first device does not support the pre-configured security parameters of the tag device, and directly obtains the security parameters from the core network device, and also needs to request the core network device to calculate the third authentication information of the reader/writer device);
- the first device receives the security parameters of the tag device and the third authentication information of the reader/writer device sent by the core network device;
- the first device sends a second request to the core network device; the first device receives the third authentication information of the reader/writer device sent by the core network device (this case is usually the case where the first device supports the pre-configured security parameters of the tag device. If it is determined that the security parameters of the tag device are pre-configured, there is no need to obtain the security parameters from the core network device, and only needs to request the core network device to calculate the reader/writer. The third authentication information of the writer device is sufficient);
- the first device sends a first request for obtaining the security parameters to the core network device; the first device receives the security parameters of the tag device and the third authentication information of the reader device sent by the core network device (this situation is usually the case where the first device supports pre-configured security parameters of the tag device. If it is determined that the security parameters of the tag device are not pre-configured, the security parameters are obtained from the core network device, and the core network device needs to be requested to calculate the third authentication information of the reader device);
- the first request includes the identification information of the tag device and a second input parameter for calculating the third authentication information of the reader/writer device
- the second request includes a second input parameter for calculating the third authentication information of the reader/writer device.
- the second input parameter includes at least one of the following: identification information of the first device, time information corresponding to the transmission of the third authentication information, frequency domain resource information corresponding to the transmission of the third authentication information, and beam information corresponding to the transmission of the third authentication information.
- the first device is a core network device
- the first device sending the second authentication command includes: the first device sending the second authentication command to the tag device through the access network device;
- the first device receiving the second response includes: the first device receiving the second response forwarded by the access network device.
- the access network device may transparently forward the second authentication command and the second response.
- the step further includes:
- the first device sends a first authentication command, where the first authentication command is used to authenticate the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- the first device receives a first response, wherein the first response includes: first authentication information of the tag device;
- the first device determines whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device.
- the tag device first authenticates the reader device, and then the reader device authenticates the tag device.
- the reader device first authenticates the tag device, and then the tag device authenticates the reader device.
- the present application embodiment further provides an authentication method for a reader/writer device, including:
- Step 71 The tag device receives a second authentication command sent by the first device, the second authentication command is used for authenticating the reader device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader device; wherein the first device is the reader device or a core network device, and the reader device is an access network device or a terminal;
- the third authentication information may be an authentication code or a data signature.
- Step 72 The tag device determines whether the reader/writer device has passed the authentication according to the second authentication command.
- the process of how a tag device authenticates a UE or RAN as a reader/writer device in a 3GPP system is clarified, so that information transmission between the reader/writer device and the tag device works in a secure mode.
- the prerequisite step of the security authentication process is that the reader needs to trigger the security parameter acquisition process and obtain the security parameters of the tag from the tag.
- the reader may be implemented based on the access network device or terminal. Since the access network device or terminal may be an untrusted node, the process of the reader obtaining the security parameters of the tag from the tag can be omitted.
- the first device is an access network device or a terminal, it can be considered to store the security parameters of the tag device in the first device.
- the security parameters of the tag device are stored in the first device, which may be that the security parameters of the tag device are pre-configured to the first device in a pre-configured manner.
- the core network device can authenticate the first device. If the first device is authenticated as a trusted node, the security parameters of the tag device can be sent to the first device, thereby ensuring that the access network device or terminal participating in the authentication is a trusted device.
- the tag device determines whether the reader/writer device passes the authentication according to the second authentication command, including:
- the tag device determines the fourth authentication information of the reader/writer device by calculation according to the configuration information of the security parameters of the tag device and the second input parameter used to calculate the third authentication information of the reader/writer device;
- the tag device compares the fourth authentication information with the third authentication information received from the reader/writer device to see whether they are the same;
- the fourth authentication information is the same as the third authentication information, determining that the reader/writer device has passed the authentication
- the fourth authentication information is different from the third authentication information, it is determined that the reader/writer device has not passed the authentication.
- the calculation method of the third authentication information and the fourth authentication information is not limited, but the calculation method of the third authentication information and the fourth authentication information needs to be the same.
- the second input parameter includes at least one of the following: identification information of the first device, time information corresponding to the transmission of the third authentication information, frequency domain resource information corresponding to the transmission of the third authentication information, and beam information corresponding to the transmission of the third authentication information.
- the step further includes:
- the tag device performs at least one of the following:
- the second response includes: an authentication result of whether the reader/writer device passes the authentication or fails the authentication;
- control command includes at least one of the following:
- Deactivate command used to deactivate the tag device
- Inventory command used to inventory tag devices
- Read command used to read data from the tag device
- Control command used to control the tag device.
- the method further includes:
- the tag device receives a first authentication command sent by the first device, where the first authentication command is used to authenticate the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- the tag device determines first authentication information of the tag device according to the first authentication command
- the tag device sends a first response to the first device, where the first response includes: first authentication information of the tag device.
- the tag device first authenticates the reader device, and then the reader device authenticates the tag device.
- the reader device first authenticates the tag device, and then the tag device authenticates the reader device.
- the step further includes:
- the tag device discards the first authentication command sent by the first device, where the first authentication command is used to authenticate the tag device and includes configuration information of security parameters of the tag device.
- the tag device first authenticates the reader/writer device, and then the reader/writer device authenticates the tag device. If the reader/writer device fails the authentication, the tag device no longer authenticates the reader/writer device.
- the embodiment of the present application also provides a security authentication method, including:
- Step 81 The core network device receives a request sent by a reader/writer device, wherein the request includes identification information of a tag device and/or a second input parameter for calculating authentication information of the reader/writer device; the reader/writer device is an access network device or a terminal;
- Step 82 The core network device sends the security parameters of the tag device and/or the third authentication information of the reader/writer device to the reader/writer device, wherein the third authentication information is determined by the core network device through calculation based on the security parameters of the tag device and the second input parameters.
- an access network device or terminal serving as a reader/writer device may obtain security parameters of the tag device from a core network device and/or request the core network device to determine authentication information of the reader/writer device before authenticating the tag device or requesting the tag device to authenticate the reader/writer device.
- the core network device may send the security parameters of the tag device and/or the authentication information of the reader/writer device to the reader/writer device, thereby ensuring that the access network device or terminal participating in the authentication is a trustworthy device.
- the core network device receives a request sent by the reader/writer device, wherein the request includes The identification information of the tag device, at this time, the core network device sends the security parameters of the tag device to the reader-writer device. That is, the reader-writer device only requests the security parameters of the tag device.
- the core network device receives a request sent by the reader/writer device, wherein the request includes a second input parameter for calculating the authentication information of the reader/writer device, and at this time, the core network device sends the third authentication information of the reader/writer device to the reader/writer device. That is, the reader/writer device only requests the core network device to determine the authentication information of the reader/writer device.
- the core network device receives a request sent by the reader device, the request includes identification information of the tag device and a second input parameter for calculating authentication information of the reader device, and at this time, the core network device sends the security parameters of the tag device and the third authentication information of the reader device to the reader device. That is, the reader device requests both the security parameters of the tag device and the core network device to determine the authentication information of the reader device.
- the core network device sending the security parameter of the tag device and/or the third authentication information of the reader-writer device to the reader-writer device includes:
- the core network device determines that the reader/writer device is credible, the core network device sends the security parameters of the tag device and/or the third authentication information of the reader/writer device to the reader/writer device.
- the core network device can be used to calculate authentication information for the reader/writer device.
- Embodiment 1 of the present application is a diagrammatic representation of Embodiment 1 of the present application
- the RAN node acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a one-way authentication of the A-IOT device by the RAN node, that is, the RAN node authenticates whether the A-IOT device is legal, and the peer entities of the security function are the A-IOT device and the RAN node.
- the authentication method of the tag device in the embodiment of the present application includes:
- Step 0a and step 0b are optional steps, which can be implemented by any of the following 1) or 2):
- the operator pre-configures the security parameters (security credentials) of all or part of the A-IOT devices controlled by the operator to all trusted RAN nodes through Operation Administration Maintenance (OAM).
- OAM Operation Administration Maintenance
- steps 0a and 0b can be skipped, and the RAN node directly triggers the air interface security authentication process, that is, the RAN node first executes step 1 in Figure 9.
- the RAN node will first request the security parameters of the A-IOT device from the 5GC node before triggering the air interface security authentication process.
- the request carries the identification (Identifier, ID) information of the A-IOT device.
- the 5GC node responds to the RAN node with the security parameters of the A-IOT device on the premise that the RAN node is trustworthy. That is, the RAN node executes step 0a and step 0b as the first step.
- the 5GC node can be a 5GC node of related technology (such as Access and Mobility Management Function (AMF)), or a newly introduced 5GC functional node, which is not limited here.
- AMF Access and Mobility Management Function
- the 5GC node When the operator does not support pre-configuration of the security parameters (security credentials) of all or part of the A-IOT devices controlled by the operator for all trusted RAN nodes through OAM, for a specific RAN node, before triggering the air interface security authentication process, the 5GC node is always requested for the security parameters of the A-IOT device.
- the 5GC node responds to the RAN node with the security parameters of the A-IOT device on the premise that the RAN node is trusted. That is, the RAN node executes step 0a as the first step, and whether step 0b is executed depends on whether the 5GC node determines whether the RAN node is trusted.
- the ID information of the A-IOT device may include at least one of the following: the electronic product code (EPC) of the A-IOT device, the tag identity (TID) of the A-IOT device, and the tag identity (TID) of the A-IOT device, which is stored in the tag information area.
- the data in the tag information area is written when the tag chip is produced and cannot be modified after writing).
- the above ID information is consistent with the production configuration of the A-IOT device and cannot be modified after writing.
- the security parameters of the A-IOT device may include at least one of the following: root key (RK) index (the root key is uniquely determined by the index value), communication encryption algorithm (used to indicate the data transmission encryption and integrity protection algorithm supported by the A-IOT device), key length, security mode (used to indicate whether the A-IOT device needs to perform security authentication, security authentication includes one-way authentication or two-way authentication, one-way authentication is the A-IOT device authenticating the RAN node or the RAN node authenticating the A-IOT device, whether secure communication is required), security function (used to indicate the security authentication algorithm supported by the A-IOT device, the security authentication algorithm includes one-way authentication algorithm or two-way authentication algorithm, the one-way authentication algorithm is the algorithm used by the A-IOT device to authenticate the RAN node or the algorithm used by the RAN node to authenticate the A-IOT device), Tsec (the reference time for the RAN node to wait for the A-IOT device to respond after sending a security authentication command or a security communication command,
- Step 1 The RAN node sends a one-way authentication command (i.e., the first authentication command in the above embodiment) to the A-IOT device.
- the one-way authentication command is used for authentication of the A-IoT device.
- the one-way authentication command carries at least the configuration information of the security parameters of the A-IOT device.
- the configuration information follows the content of the pre-configured security parameters of the RAN node or follows the configuration content of the security parameters obtained from the 5GC node (i.e., step 0b).
- the A-IOT device determines the authentication code or data signature of the A-IOT device by calculation.
- the method by which the A-IOT device generates the authentication code or data signature of the A-IOT device is not limited in this application.
- Step 2 The A-IOT device sends a response (first response) of a one-way authentication command to the RAN node, wherein the response of the one-way authentication command carries: ID information of the A-IOT device, and an authentication code or data signature of the A-IOT device.
- the RAN node determines whether the A-IOT device is authenticated. Specifically, it can be determined according to the following method:
- the RAN node determines the authentication code or data signature of the A-IOT device, compares the authentication code or data signature of the A-IOT device calculated and generated by itself with the authentication code or data signature of the A-IOT device received in step 2, and if the two values are equal, the A-IOT device is judged to have passed the authentication; otherwise, the A-IOT device is judged to have failed the authentication.
- the RAN node is the RAN node where the source service cell of the A-IOT device is located; the RAN node where the source service cell of the A-IOT device is located determines the authentication code or data signature of the A-IOT device by calculation, and compares the authentication code or data signature of the A-IOT device calculated and generated by itself with the authentication code or data signature received in step 2 The authentication code or data signature of the A-IOT device is obtained. If the two values are equal, the A-IOT device is judged to have passed the authentication; otherwise, the A-IOT device is judged to have failed the authentication.
- the RAN node where the source service cell of the A-IOT device is located can notify the RAN node where the target service cell of the A-IOT device is located of the authentication result of whether the A-IOT device has passed the authentication.
- the notification here can be a displayed indication or an implicit indication.
- the implicit method is, for example, to initiate the UE context acquisition process between the RAN node where the target service cell is located and the RAN node where the source service cell is located.
- the method by which the RAN node where the source service cell of the A-IOT device is located calculates and generates the authentication code or data signature of the A-IOT device is not limited in this application, but must be consistent with the method by which the A-IOT device generates the authentication code or data signature of the A-IOT device.
- the RAN node determines that the A-IOT device passes the authentication, the RAN node performs at least one of the following:
- the object of forwarding data can be a 5GC node of related technology, such as a user plane function (UPF), or a newly introduced 5GC function node, or an A-IOT App server, etc., without limitation here.
- a 5GC node of related technology such as a user plane function (UPF), or a newly introduced 5GC function node, or an A-IOT App server, etc., without limitation here.
- UPF user plane function
- A-IOT App server etc.
- the RAN node acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a one-way authentication of the A-IOT device by the 5GC node (core network device), that is, the 5GC node authenticates whether the A-IOT device is legal, and the peer entities of the security function are the A-IOT device and the 5GC node.
- the RAN node is responsible for the transparent forwarding function of security authentication related commands, and does not actually participate in the security authentication function of the A-IOT device. It is the 5GC node that generates the security authentication command and executes the authentication function.
- the authentication method of the tag device in the embodiment of the present application includes:
- Step 1 The 5GC node sends a one-way authentication command (i.e., the first authentication command in the above embodiment) to the A-IOT device, and the one-way authentication command is transparently forwarded to the A-IOT device through the RAN node.
- the one-way authentication command is used for the authentication of the A-IoT device, and the one-way authentication command carries at least the configuration information of the security parameters of the A-IOT device.
- the A-IOT device determines the authentication code or data signature of the A-IOT device by calculation.
- the method by which the A-IOT device generates the authentication code or data signature of the A-IOT device is not limited in this application.
- Step 2 The A-IOT device sends a response (first response) of a one-way authentication command to the 5GC node, and the response of the one-way authentication command is transparently forwarded to the 5GC node through the RAN node.
- the response of the one-way authentication command carries: the ID information of the A-IOT device, the authentication code or data signature of the A-IOT device.
- Step 3 The RAN node forwards the response to the one-way authentication command, which will also be used to calculate the authentication code or At least one first input parameter of the data signature is sent to the 5GC node.
- the 5GC node determines whether the A-IOT device is authenticated, which can be determined in the following ways:
- the 5GC node determines the authentication code or data signature of the A-IOT device by calculation, and compares the authentication code or data signature of the A-IOT device calculated and generated by itself with the authentication code or data signature of the A-IOT device received. If the two values are equal, the A-IOT device is judged to have passed the authentication; otherwise, the A-IOT device is judged to have failed the authentication;
- the method by which the 5GC node calculates and generates the authentication code or data signature of the A-IOT device is not limited in this application, but must be consistent with the method by which the A-IOT device generates the authentication code or data signature of the A-IOT device.
- Step 4 The 5GC node feeds back to the RAN node the authentication result of whether the A-IOT device has passed the authentication.
- step 4 further, on the premise that the RAN node determines that the A-IOT device passes the authentication, the RAN node performs at least one of the following:
- the object of forwarding data can be a 5GC node of related technology, such as a user plane function (UPF), or a newly introduced 5GC function node, or an A-IOT App server, etc., without limitation here.
- a 5GC node of related technology such as a user plane function (UPF), or a newly introduced 5GC function node, or an A-IOT App server, etc., without limitation here.
- UPF user plane function
- A-IOT App server etc.
- the RAN node acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a one-way authentication of the RAN node by the A-IOT device, that is, the A-IOT device authenticates whether the RAN node is legal, and the peer entities of the security function are the A-IOT device and the RAN node.
- the authentication method of the reader/writer device in the embodiment of the present application includes:
- step 0a and step 0b are the same as that of embodiment 1 and will not be repeated here.
- Step 1 The RAN node sends a request for one-way authentication command (a second authentication command) to the A-IOT device.
- the request for one-way authentication command is used for authentication of the RAN node.
- the request for one-way authentication command carries at least configuration information of security parameters of the A-IOT device and an authentication code or data signature of the RAN node.
- the RAN node determines the authentication code or data signature of the RAN node by calculation.
- the method by which the RAN node generates the authentication code or data signature of the RAN node is not limited in this application.
- Step 2 The A-IOT device sends a response (i.e., a second response) to the RAN node requesting a one-way authentication command, where the response to the one-way authentication command request carries an authentication result indicating whether the RAN node has passed the authentication.
- a response i.e., a second response
- the A-IOT device determines whether the RAN node is authenticated.
- the determination can be made by the following method: the A-IOT device calculates and generates the authentication code or data signature of the RAN node by itself, and compares the authentication code or data signature of the RAN node calculated and generated by itself with the authentication code or data signature of the RAN node received in step 1. If the two values are equal, it is determined that the RAN node is authenticated; otherwise, it is determined that the RAN node authentication fails.
- the method by which the A-IOT device generates the RAN node authentication code or data signature is not limited in this application, but must be consistent with the method by which the RAN node generates the RAN node authentication code or data signature.
- the A-IOT device performs at least one of the following:
- the RAN node acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a one-way authentication of the RAN node by the A-IOT device, that is, the A-IOT device authenticates whether the RAN node is legal, and the peer entities of the security function are the A-IOT device and the 5GC node (core network device).
- the authentication method of the reader/writer device in the embodiment of the present application includes:
- Step 0a and step 0b are optional steps, which can be implemented by any of the following 1) or 2):
- the operator pre-configures the security parameters (security credentials) of all or part of the A-IOT devices controlled by the operator to all trusted RAN nodes through Operation Administration Maintenance (OAM).
- OAM Operation Administration Maintenance
- step 0a part or all of the second input parameters for calculating the authentication code or digital signature of the RAN node (such as the A-IOT device ID, the service cell ID of the A-IOT device, the UE context ID of the A-IOT device, the time information corresponding to the transmission of the authentication code or data signature, the frequency domain resource information corresponding to the transmission of the authentication code or data signature, and at least one of the beam information corresponding to the transmission of the authentication code or data signature) are sent to the 5GC node, and step 0b: the 5GC node returns the authentication code or digital signature of the RAN node to the RAN node.
- the second input parameters for calculating the authentication code or digital signature of the RAN node such as the A-IOT device ID, the service cell ID of the A-IOT device, the UE context ID of the A-IOT device, the time information corresponding to the transmission of the authentication code or data signature, the frequency domain resource information corresponding to the transmission of the authentication code or data signature, and at least one of the
- step 0a a request for obtaining the security parameters of the A-IOT device is sent to the 5GC node, and the request carries the ID information of the A-IOT device and part or all of the second input parameters for calculating the authentication code or digital signature of the RAN node.
- step 0b The 5GC node returns the security parameters of the A-IOT device and the authentication code or digital signature of the RAN node to the RAN node.
- the 5GC node can be a 5GC node in the related technology (such as AMF), or a newly introduced 5GC functional node, which is not limited here.
- the authentication code or digital signature of the RAN node is calculated by the 5GC node.
- the RAN node If the operator does not support pre-configuring the security parameters (security credentials) of all or part of the A-IOT devices controlled by the operator to all trusted RAN nodes through OAM, for a specific RAN node, the RAN node always requests the security parameters of the A-IOT device from the 5GC node before triggering the air interface security authentication process, and sends the second input parameter for calculating the authentication code or digital signature of the RAN.
- the 5GC node responds to the RAN node with the security parameters of the A-IOT device and the authentication code or digital signature of the RAN node on the premise that the RAN node is trusted. That is, the RAN node executes step 0a as the first step, and whether step 0b is executed depends on the authentication result of the 5GC node judging whether the RAN node is trusted.
- Step 1 The RAN node sends a one-way authentication request command (i.e., the second authentication command in the above embodiment) to the A-IOT device.
- the request one-way authentication command is used for the authentication of the RAN node, and the request one-way authentication command carries at least the configuration information of the security parameters of the A-IOT device and the authentication code or data signature of the RAN node.
- the configuration content follows the pre-configuration content of the RAN node or follows the configuration content returned by the 5GC node (i.e., step 0b);
- the 5GC node may send a request for one-way authentication command to the A-IOT device, and the request for one-way authentication command may be transparently forwarded to the A-IOT device through the RAN node.
- the 5GC node calculates and generates an authentication code or data signature of the RAN node.
- the method by which the 5GC node generates an authentication code or data signature of the RAN node is not limited in this application.
- Step 2 The A-IOT device sends a response (i.e., a second response) to the RAN node requesting a one-way authentication command, wherein the response to the one-way authentication command requesting at least carries an authentication result indicating whether the RAN node has passed the authentication.
- a response i.e., a second response
- the A-IOT device sends a response to a request for a one-way authentication command to the 5GC node, and the response to the request for a one-way authentication command is transparently forwarded to the 5GC node through the RAN node.
- the A-IOT device determines whether the RAN node is authenticated.
- the determination can be made by the following method: the A-IOT device calculates and generates the authentication code or data signature of the RAN node by itself, and compares the authentication code or data signature of the RAN node calculated and generated by itself with the authentication code or data signature of the RAN node received in step 1. If the two values are equal, it is determined that the RAN node is authenticated; otherwise, it is determined that the RAN node authentication fails.
- the A-IOT device generates the RAN node authentication code or data signature, which is not limited in this application, but must be consistent with the method of generating the RAN node authentication code or data signature by the 5GC node.
- the A-IOT device performs at least one of the following:
- the RAN node acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a two-way authentication between the A-IOT device and the RAN node, that is, the A-IOT device authenticates whether the RAN node is legal, and the RAN node authenticates whether the A-IOT device is legal.
- the peer entities of the security function are the A-IOT device and the RAN node.
- the method of the embodiment of the present application can be regarded as a combination of Embodiment 3 and Embodiment 1.
- Embodiment 3 and Embodiment 1 please refer to Embodiment 3 and Embodiment 1, and no repeated description will be given.
- the two-way authentication command in FIG. 13 refers to the one-way authentication command and the one-way authentication request command in the above-mentioned third and first embodiments.
- the RAN node acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a two-way authentication of the A-IOT device and the RAN node, that is, the A-IOT device authenticates whether the RAN node is legal, and the 5GC node authenticates whether the A-IOT device is legal.
- the peer entities of the security function are the A-IOT device and the 5GC node.
- the method of the embodiment of the present application can be regarded as a combination of the fourth embodiment and the second embodiment.
- the fourth embodiment and the second embodiment please refer to the fourth embodiment and the second embodiment, and the description will not be repeated.
- the two-way authentication command in FIG. 14 refers to the one-way authentication command and the one-way authentication request command in the above-mentioned fourth and second embodiments.
- the UE acts as a reader/writer device and the A-IOT device acts as a tag device.
- This embodiment is a one-way authentication of the A-IOT device by the UE, that is, the UE verifies whether the A-IOT device is legal, and the peer entities of the security function are the A-IOT device and the UE.
- the authentication method of the tag device in the embodiment of the present application includes:
- Step 0a and step 0b are optional steps, which can be implemented by any of the following 1) or 2):
- the operator pre-configures the security parameters (security credentials) of all or part of the A-IOT devices controlled by the operator to all trusted UEs through Operation Administration Maintenance (OAM). For a specific UE, before triggering the air interface security authentication process with the A-IOT device, it first determines whether the security parameters of the A-IOT device are stored in its pre-configuration.
- OAM Operation Administration Maintenance
- steps 0a and 0b can be skipped, and the UE directly triggers the air interface security authentication process, that is, the UE first executes step 1 in Figure 15.
- the UE will request the security parameters of the A-IOT device from the 5GC node before triggering the air interface security authentication process.
- the request carries the identification (ID) information of the A-IOT device.
- the 5GC node responds to the UE with the security parameters of the A-IOT device on the premise that the UE is trustworthy. That is, the UE first executes step 0a, and whether step 0b is executed depends on whether the 5GC node determines whether the UE is trustworthy.
- the 5GC node can be a 5GC node in the related technology (such as Access and Mobility Management Function (AMF)), or a newly introduced 5GC function node, which is not limited here.
- AMF Access and Mobility Management Function
- the 5GC node When the operator does not support pre-configuration of the security parameters (security credential) of all or part of the A-IOT devices controlled by the operator for all trusted UEs through OAM, for a specific UE, before triggering the air interface security authentication process, the 5GC node is always requested for the security parameters of the A-IOT device.
- the 5GC node responds to the UE with the security parameters of the A-IOT device on the premise that the UE is trusted. That is, the UE executes step 0a as the first step, and whether step 0b is executed depends on whether the 5GC node determines whether the UE is trusted.
- the ID information of the A-IOT device may include at least one of the following: the electronic product code (EPC) of the A-IOT device, the tag identity (TID) of the A-IOT device, and the tag identity (TID) of the A-IOT device, which is stored in the tag information area.
- the data in the tag information area is written when the tag chip is produced and cannot be modified after writing).
- the above ID information is consistent with the production configuration of the A-IOT device and cannot be modified after writing.
- the security parameters of the A-IOT device may include at least one of the following: a root key (RK) index (the root key is uniquely determined by the index value), a communication encryption algorithm (used to indicate the data transmission encryption and integrity protection algorithm supported by the A-IOT device), a key length, a security mode (used to indicate whether the A-IOT device needs to perform security authentication, security authentication includes one-way authentication or two-way authentication, and one-way authentication is whether the A-IOT device authenticates the UE or the UE Authentication of A-IOT devices, whether secure communication is required), security functions (used to indicate the security authentication algorithms supported by the A-IOT device, whether the security authentication algorithms include one-way authentication algorithms or two-way authentication algorithms, whether the one-way authentication algorithm is used by the A-IOT device to authenticate the UE or the UE to authenticate the A-IOT device), Tsec (the reference time for the UE to wait for the A-IOT device to respond after sending a security authentication command or a secure communication command, in units of
- Step 1 The UE sends a one-way authentication command to the A-IOT device (i.e., the first authentication command in the above embodiment).
- the one-way authentication command is used for authentication of the A-IoT device.
- the one-way authentication command carries at least the configuration information of the security parameters of the A-IOT device.
- the configuration information follows the content of the pre-configured security parameters of the UE or follows the configuration content of the security parameters obtained from the 5GC node (i.e., step 0b).
- the A-IOT device determines the authentication code or data signature of the A-IOT device by calculation.
- the method by which the A-IOT device generates the authentication code or data signature of the A-IOT device is not limited in this application.
- Step 2 The A-IOT device sends a response (first response) of a one-way authentication command to the UE, wherein the response of the one-way authentication command carries: ID information of the A-IOT device, and an authentication code or data signature of the A-IOT device.
- the UE determines whether the A-IOT device is authenticated.
- the determination may be made according to the following method:
- the UE determines the authentication code or data signature of the A-IOT device, compares the authentication code or data signature of the A-IOT device calculated and generated by itself with the authentication code or data signature of the A-IOT device received in step 2. If the two values are equal, the A-IOT device is judged to have passed the authentication; otherwise, the A-IOT device authentication is judged to have failed.
- the method by which the UE calculates and generates the authentication code or data signature of the A-IOT device is not limited in this application, but must be consistent with the method by which the A-IOT device generates the authentication code or data signature of the A-IOT device.
- the UE performs at least one of the following: sending a control command to the A-IOT device;
- the object of forwarding data can be a 5GC node in the related technology, such as the user plane function (UPF), or a newly introduced 5GC function node, or A-IOT App server, etc., without limitation here.
- the user plane function UPF
- a newly introduced 5GC function node or A-IOT App server, etc., without limitation here.
- the UE acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a one-way authentication of the UE by the A-IOT device, that is, the A-IOT device authenticates whether the UE is legal, and the peer entities of the security function are the A-IOT device and the UE.
- the authentication method of the reader/writer device in the embodiment of the present application includes:
- Step 0a and step 0b are the same as those in Embodiment 7 and will not be described again.
- Step 1 The UE sends a request for one-way authentication command (second authentication command) to the A-IOT device.
- the request for one-way authentication command is used for authentication of the RAN node.
- the request for one-way authentication command carries at least configuration information of security parameters of the A-IOT device, the authentication code or digital signature of the UE, and the second input parameter (such as the authentication code or digital signature) of the UE for calculating the authentication code or digital signature of the UE.
- the UE calculates and generates the UE authentication code or data signature.
- the method by which the UE generates the UE device authentication code or data signature is not limited in this application.
- the A-IOT device determines whether the UE is authenticated.
- the following method can be used to determine whether the UE is authenticated: the A-IOT device calculates and generates the authentication code or data signature of the UE by itself, and compares the authentication code or data signature of the UE calculated and generated by itself with the authentication code or data signature of the UE received in step 1. If the two values are equal, the UE is judged to be authenticated; otherwise, the UE authentication is judged to have failed.
- Step 2 The A-IOT device sends a response to the UE requesting a one-way authentication command, where the response to the one-way authentication command at least carries an authentication result indicating whether the UE has passed the authentication.
- the method by which the A-IOT device calculates and generates the authentication code or data signature of the UE is not limited in this application, but must be consistent with the method by which the UE generates the authentication code or data signature of the UE.
- the A-IOT device performs at least one of the following: responding to other commands sent by the UE; and sending data of the A-IOT device to the UE.
- the UE acts as a reader/writer device
- the A-IOT device acts as a tag device.
- This embodiment is a two-way authentication between the A-IOT device and the UE, that is, the A-IOT device authenticates whether the UE is legal, and the UE authenticates whether the A-IOT device is legal.
- the peer entities of the security function are the A-IOT device and the UE.
- the two-way authentication command in FIG. 17 refers to the one-way authentication command and the one-way authentication request command in the above-mentioned eighth and seventh embodiments.
- the authentication method for a tag device provided in the embodiment of the present application can be executed by an authentication device of the tag device.
- the authentication device of the tag device executing the authentication method for the tag device is taken as an example to illustrate the authentication device of the tag device provided in the embodiment of the present application.
- the present embodiment further provides an authentication device 180 of a tag device, including:
- the first sending module 181 is used to send a first authentication command, which is used for authenticating a tag device, and includes configuration information of security parameters of the tag device; wherein the authentication device 180 of the tag device is an access network device, a terminal or a core network device;
- a first receiving module 182 is configured to receive a first response, wherein the first response includes: first authentication information of the tag device;
- the first determination module 183 is used to determine whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device.
- the process of how to authenticate the tag device in the 3GPP system is clarified so that the information transmission between the reader/writer device (terminal or access network device) and the tag device works in a secure mode.
- the authentication device 180 of the tag device is an access network device or a terminal
- the security parameter storage In the authentication device 180 of the tag device, or, the security parameter is obtained by the authentication device 180 of the tag device from the core network device.
- the authentication device 180 of the tag device is an access network device or a terminal
- the first sending module 181 is used to send a first authentication command when the authentication device 180 of the tag device has the security parameters of the tag device.
- the authentication device 180 of the tag device is an access network device or a terminal; the authentication device 180 of the tag device further includes:
- a sending module configured to send a first request for obtaining security parameters to a core network device, wherein the first request includes identification information of the tag device; or, in the absence of the security parameters of the tag device, send a first request for obtaining security parameters to a core network device, wherein the first request includes identification information of the tag device;
- a receiving module is used to receive the security parameters from the core network device.
- the authentication device 180 of the tag device is a core network device
- the first sending module 181 is used to send the first authentication command to the tag device through the access network device;
- the first receiving module 182 is used to receive the first response forwarded by the access network device
- the authentication device 180 of the tag device is an access network device where the source serving cell of the tag device is located;
- the first sending module 181 is used to send the first authentication command to the tag device through the access network device where the destination serving cell of the tag device is located, wherein the access network device where the destination serving cell of the tag device is located forwards the first authentication command;
- the first receiving module 182 is configured to receive the first response forwarded by the access network device where the destination serving cell of the tag device is located.
- the first determination module 183 is used to determine the second authentication information of the tag device by calculation based on the configuration information of the security parameters of the tag device and the first input parameter used to calculate the first authentication information of the tag device; compare whether the second authentication information is the same as the received first authentication information of the tag device; if the second authentication information is the same as the first authentication information, determine that the tag device has passed the authentication; if the second authentication information is different from the first authentication information, determine that the tag device has not passed the authentication.
- the authentication device 180 of the tag device is a core network device, it further includes:
- the second receiving module is used to receive the first input parameter sent by the access network device where the serving cell of the tag device is located.
- the first input parameter includes at least one of the following: identification information of the tag device, identification information of the service cell of the tag device, context identification of the tag device, time information corresponding to the transmission of the first authentication information, frequency domain resource information corresponding to the transmission of the first authentication information, and beam information corresponding to the transmission of the first authentication information.
- the authentication device 180 of the tag device is an access network device or a terminal, and further includes:
- An execution module configured to execute at least one of the following if the tag device passes the authentication:
- the authentication device 180 of the tag device is a core network device, and further includes at least one of the following:
- a second sending module is used to send an authentication result of whether the tag device has passed the authentication to the access network device or the terminal;
- the third sending module is used to send the authorization information of the tag device to the access network device or the terminal, and the authorization information is sent when the tag device passes the authentication.
- the authentication device of the tag device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip.
- the electronic device can be a terminal, or it can be other devices other than a terminal.
- the terminal can include but is not limited to the types of terminals 11 listed above, and other devices can be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiment of the present application.
- the authentication device of the tag device provided in the embodiment of the present application can implement each process implemented in the method embodiment of Figure 4 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the present embodiment further provides an authentication device 190 of a tag device, including:
- the first receiving module 191 is used to receive a first authentication command sent by a first device, the first authentication command is used for authenticating the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- the first device is an access network device, a terminal or a core network device;
- the first sending module 192 is used to send a first response to the first device according to the first authentication command, where the first response includes first authentication information of the tag device.
- the process of how to authenticate the tag device in the 3GPP system is clarified, so that the information transmission between the reader device (access network device or terminal) and the tag device works in a secure mode.
- the security parameter is stored in the first device, or the security parameter is obtained by the first device from a core network device.
- the first sending module 192 is used to determine the first authentication information of the tag device by calculation based on the configuration information of the security parameters and the first input parameter used to calculate the first authentication information of the tag device; and send the first response to the first device, wherein the first response includes the first authentication information.
- the first input parameter includes at least one of the following: identification information of the tag device, identification information of the service cell of the tag device, context identification of the tag device, time information corresponding to the transmission of the first authentication information, frequency domain resource information corresponding to the transmission of the first authentication information, and beam information corresponding to the transmission of the first authentication information.
- the authentication device of the tag device provided in the embodiment of the present application can implement each process implemented in the method embodiment of Figure 5 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the authentication method for a reader/writer device provided in the embodiment of the present application can be executed by an authentication device of the reader/writer device.
- the authentication device of the reader/writer device executing the authentication method of the reader/writer device is taken as an example to illustrate the authentication device of the reader/writer device provided in the embodiment of the present application.
- the present embodiment further provides an authentication device 200 for a reader/writer device, including:
- the first sending module 201 is used to send a second authentication command, the second authentication command is used for authenticating the reader/writer device, and the second authentication command includes the configuration information of the security parameters of the tag device and the third authentication information of the reader/writer device; wherein the authentication device 200 of the reader/writer device is the reader/writer device or the core network device, and the reader/writer device is the access network device or the terminal;
- the first receiving module 202 is used to receive a second response, wherein the second response includes: an authentication result of whether the reader/writer device passes the authentication or fails the authentication.
- the process of how a tag device authenticates a UE or RAN as a reader/writer device in a 3GPP system is clarified, so that information transmission between the reader/writer device and the tag device works in a secure mode.
- the security parameter is stored in the first device, or the security parameter is obtained by the first device from a core network device.
- the authentication device 200 of the reader/writer device further includes:
- the first determination module is used to determine the third authentication information of the reader/writer device.
- the authentication device 200 of the reader/writer device is the reader/writer device, further comprising:
- a second sending module used to send a first request for obtaining security parameters to the core network device
- the third sending module is used to send a first request for obtaining security parameters to a core network device when the first device does not have the security parameters of the tag device; wherein the first request includes identification information of the tag device.
- the authentication device 200 of the reader/writer device is the reader/writer device, further comprising:
- a fourth sending module configured to send a first request for acquiring security parameters to a core network device, wherein the first request includes identification information of the tag device and a second input parameter for calculating third authentication information of the reader/writer device;
- a second receiving module used to receive the security parameters of the tag device and the third authentication information of the reader device sent by the core network device;
- a fifth sending module configured to send a second request to a core network device when there are security parameters of the tag device; the first device receives the third authentication information of the reader/writer device sent by the core network device;
- a sixth sending module configured to send a first request for obtaining security parameters to a core network device in the absence of the security parameters of the tag device; the first device receives the security parameters of the tag device and the third authentication information of the reader-writer device sent by the core network device;
- the first request includes the identification information of the tag device and the second input parameter for calculating the third authentication information of the reader-writer device
- the second request includes the third authentication information for calculating the reader-writer device.
- the second input parameter of the information includes the identification information of the tag device and the second input parameter for calculating the third authentication information of the reader-writer device
- the second input parameter includes at least one of the following: identification information of the first device, time information corresponding to the transmission of the third authentication information, frequency domain resource information corresponding to the transmission of the third authentication information, and beam information corresponding to the transmission of the third authentication information.
- the authentication device 200 of the reader/writer device is a core network device
- the first sending module 201 is used to send the second authentication command to the tag device through the access network device;
- the first receiving module 202 is used to receive the second response forwarded by the access network device.
- the authentication device 200 of the reader/writer device further includes:
- a seventh sending module configured to send a first authentication command, where the first authentication command is used to authenticate the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- a third receiving module is used to receive a first response, wherein the first response includes: first authentication information of the tag device;
- the second determination module is used to determine whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device.
- the authentication device of the reader/writer device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip.
- the electronic device can be a terminal, or it can be other devices other than a terminal.
- the terminal can include but is not limited to the types of terminals 11 listed above, and other devices can be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiment of the present application.
- the authentication device of the reader/writer device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the present embodiment further provides an authentication device 210 of a reader/writer device, including:
- the first receiving module 211 is used to receive a second authentication command sent by the first device, the second authentication command is used for authentication of the reader device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader device; wherein the first device is the reader device or the core network device, and the reader device is an access network device or a terminal;
- the first determination module 212 is used to determine whether the reader/writer device passes the authentication according to the second authentication command.
- the process of how a tag device authenticates a UE or RAN as a reader/writer device in a 3GPP system is clarified, so that information transmission between the reader/writer device and the tag device works in a secure mode.
- the security parameter is stored in the first device, or the security parameter is obtained by the first device from a core network device.
- the first determination module 212 is used to determine the fourth authentication information of the reader-writer device by calculation according to the configuration information of the security parameters of the tag device and the second input parameter used to calculate the third authentication information of the reader-writer device; compare the fourth authentication information with the received third authentication information of the reader-writer device to see whether if the fourth authentication information is the same as the third authentication information, it is determined that the reader-writer device has passed the authentication; if the fourth authentication information is different from the third authentication information, it is determined that the reader-writer device has not passed the authentication.
- the second input parameter includes at least one of the following: identification information of the first device, time information corresponding to the transmission of the third authentication information, frequency domain resource information corresponding to the transmission of the third authentication information, and beam information corresponding to the transmission of the third authentication information.
- the authentication device 210 of the reader/writer device further includes:
- An execution module configured to execute at least one of the following if the reader/writer device passes the authentication:
- the second response includes: an authentication result of whether the reader/writer device passes the authentication or fails the authentication;
- the authentication device 210 of the reader/writer device further includes:
- a second receiving module configured to receive a first authentication command sent by the first device, wherein the first authentication command is used to authenticate the tag device, and the first authentication command includes configuration information of security parameters of the tag device;
- a second determination module configured to determine first authentication information of the tag device according to the first authentication command
- the sending module is used to send a first response to the first device, where the first response includes: first authentication information of the tag device.
- the authentication device 210 of the reader/writer device further includes:
- a discarding module is used to discard the first authentication command sent by the first device if the reader device fails to pass the authentication, wherein the first authentication command is used to authenticate the tag device and includes configuration information of security parameters of the tag device.
- the authentication device of the reader/writer device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 7 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the security authentication method provided in the embodiment of the present application can be executed by a security authentication device.
- the security authentication device provided in the embodiment of the present application is described by taking the security authentication method executed by the security authentication device as an example.
- the present embodiment further provides a security authentication device 220, including:
- the first receiving module 221 is used to receive a request sent by a reader/writer device, wherein the request includes identification information of a tag device and/or a second input parameter for calculating authentication information of the reader/writer device; the reader/writer device is an access network device or a terminal;
- the first sending module 222 is used to send the security parameters of the tag device and/or the third authentication information of the reader device to the reader device, wherein the third authentication information is determined by the core network device through calculation based on the security parameters of the tag device and the second input parameter.
- the access network device or terminal as the reader-writer device before the access network device or terminal as the reader-writer device authenticates the tag device, or before requesting the tag device to authenticate the reader-writer device, it can obtain the security parameters of the tag device from the core network device and/or request the core network device to determine the authentication information of the reader-writer device.
- the core network device verifies the reader-writer device. If it is credible, the security parameters of the tag device and/or the authentication information of the reader device are sent to the reader device, thereby ensuring that the access network device or terminal participating in the authentication is a credible device.
- the first sending module is used to send the security parameters of the tag device and/or the third authentication information of the reader/writer device to the reader/writer device when it is determined that the reader/writer device is credible.
- the security authentication device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or a chip.
- the security authentication device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 8 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the embodiment of the present application further provides a communication device 230, including a processor 231 and a memory 232, the memory 232 storing programs or instructions that can be run on the processor 231, for example, when the communication device 230 is a first device, the program or instruction is executed by the processor 231 to implement the various steps of the method embodiment executed by the first device, and can achieve the same technical effect.
- the communication device 230 is a tag device
- the program or instruction is executed by the processor 231 to implement the various steps of the method embodiment executed by the tag device, and can achieve the same technical effect.
- the communication device 230 is a core network device
- the program or instruction is executed by the processor 231 to implement the various steps of the method embodiment executed by the core network device, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the embodiment of the present application also provides a terminal, including a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps in the method embodiment shown in Figure 4 or Figure 6.
- This terminal embodiment corresponds to the method embodiment executed on the first device side above, and each implementation process and implementation method of the above method embodiment can be applied to the terminal embodiment and can achieve the same technical effect.
- Figure 24 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.
- the terminal 240 includes but is not limited to: a radio frequency unit 241, a network module 242, an audio output unit 243, an input unit 244, a sensor 245, a display unit 246, a user input unit 247, an interface unit 248, a memory 249 and at least some of the components of the processor 2410.
- the terminal 240 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 2410 through a power management system, so as to implement functions such as managing charging, discharging, and power consumption management through the power management system.
- a power source such as a battery
- the terminal structure shown in FIG24 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently, which will not be described in detail here.
- the input unit 244 may include a graphics processor (GPU) 2441 and a microphone 2442, and the graphics processor 2441 processes the image data of the static picture or video obtained by the image capture device (such as a camera) in the video capture mode or the image capture mode.
- the display unit 246 may include a display panel 2461, and the display panel 2461 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc.
- the user input unit 247 includes a touch panel 2471 and at least one of other input devices 2472.
- the touch panel 2471 is also called a touch screen.
- the touch panel 2471 may include two parts: a touch detection device and a touch controller.
- Other input devices 2472 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), Trackballs, mice, and joysticks are not discussed here.
- the RF unit 241 can transmit the data to the processor 2410 for processing; in addition, the RF unit 241 can send uplink data to the network side device.
- the RF unit 241 includes but is not limited to an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
- the memory 249 can be used to store software programs or instructions and various data.
- the memory 249 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.), etc.
- the memory 249 may include a volatile memory or a non-volatile memory.
- the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
- the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
- RAM random access memory
- SRAM static random access memory
- DRAM dynamic random access memory
- SDRAM synchronous dynamic random access memory
- DDRSDRAM double data rate synchronous dynamic random access memory
- ESDRAM enhanced synchronous dynamic random access memory
- SLDRAM synchronous link dynamic random access memory
- DRRAM direct memory bus random access memory
- the processor 2410 may include one or more processing units; optionally, the processor 2410 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 2410.
- the radio frequency unit 241 is used to send a first authentication command, the first authentication command is used for authenticating the tag device, and the first authentication command includes configuration information of security parameters of the tag device; receive a first response, the first response includes: first authentication information of the tag device;
- the processor 2410 is used to determine whether the tag device passes the authentication according to the configuration information of the security parameter and the first authentication information of the tag device.
- the process of how to authenticate the tag device in the 3GPP system is clarified so that the information transmission between the reader/writer device (terminal or access network device) and the tag device works in a secure mode.
- the radio frequency unit 241 is used to send a second authentication command, where the second authentication command is used for authenticating the reader/writer device, and the second authentication command includes configuration information of security parameters of the tag device and third authentication information of the reader/writer device; and receive a second response, where the second response includes: an authentication result of whether the reader/writer device passes or fails authentication.
- the process of how a tag device authenticates a UE or RAN as a reader/writer device in a 3GPP system is clarified, so that information transmission between the reader/writer device and the tag device works in a secure mode.
- the embodiment of the present application also provides a network side device, including a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps of the method embodiment shown in Figure 4 or Figure 6.
- the network side device embodiment corresponds to the first device side method embodiment described above, and each implementation process and implementation method of the above method embodiment can be applied to the network side device embodiment, and can achieve the same technical effect.
- the embodiment of the present application also provides a network side device.
- the network side device 2500 includes: an antenna 251, a radio frequency device 252, a baseband device 253, a processor 254 and a memory 255.
- the antenna 251 is connected to the radio frequency device 252.
- the radio frequency device 252 receives information through the antenna 251 and sends the received information to the baseband device 253 for processing.
- the baseband device 253 processes the information to be sent and sends it to the radio frequency device 252.
- the radio frequency device 252 processes the received information and sends it out through the antenna 251.
- the method executed by the network-side device in the above embodiment may be implemented in the baseband device 253, which includes a baseband processor.
- the baseband device 253 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 25, one of which is, for example, a baseband processor, which is connected to the memory 255 through a bus interface to call the program in the memory 255 and execute the network device operations shown in the above method embodiment.
- the network side device may also include a network interface 256, which is, for example, a Common Public Radio Interface (CPRI).
- CPRI Common Public Radio Interface
- the network side device 2500 of the embodiment of the present application also includes: instructions or programs stored in the memory 255 and executable on the processor 254.
- the processor 254 calls the instructions or programs in the memory 255 to execute the methods executed by the modules shown in Figure 18 or Figure 20, and achieves the same technical effect. To avoid repetition, it will not be repeated here.
- the embodiment of the present application further provides a network side device.
- the network side device 260 includes: a processor 261, a network interface 262 and a memory 263.
- the network interface 262 is, for example, a common public radio interface (CPRI).
- CPRI common public radio interface
- the network side device 260 of the embodiment of the present application also includes: instructions or programs stored in the memory 263 and executable on the processor 261.
- the processor 261 calls the instructions or programs in the memory 263 to execute the methods executed by the modules shown in Figure 18, Figure 20, or Figure 22, and achieves the same technical effect. To avoid repetition, it will not be repeated here.
- An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
- a program or instruction is stored.
- the various processes of the above-mentioned method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
- the processor is the processor in the terminal described in the above embodiment.
- the readable storage medium includes a computer readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
- the readable storage medium may be a non-transient readable storage medium.
- An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
- the embodiments of the present application further provide a computer program/program product, which is stored in a storage medium and is executed by at least one processor to implement the various processes of the above-mentioned method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described here.
- An embodiment of the present application also provides a wireless communication system, including: a first device and a tag device, wherein the first device can be used to execute the steps of the method described in the first device side, and the tag device can be used to execute the steps of the method described in the tag device side.
- An embodiment of the present application also provides a wireless communication system, including: a first device, a tag device and a core network device, wherein the first device can be used to execute the steps of the method described in the first device side, the tag device can be used to execute the steps of the method described in the tag device side, and the core network device can be used to execute the steps of the method described in the core network device side.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
本申请公开了一种鉴权方法、鉴权装置、通信设备及可读存储介质,属于无线通信技术领域,本申请实施例的标签设备的鉴权方法包括:第一设备发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述第一设备为接入网设备、终端或核心网设备;所述第一设备接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
Description
相关申请的交叉引用
本申请主张在2023年03月31日在中国提交的中国专利申请No.202310350033.8的优先权,其全部内容通过引用包含于此。
本申请属于无线通信技术领域,具体涉及一种鉴权方法、鉴权装置、通信设备及可读存储介质。
未来第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)相关的通信系统中将支持一种全新的物联网(Internet of Things,IoT)技术,用户设备(User Equipment,UE,也称为终端)或者无线接入网(Radio Access Network,RAN)可以作为读写器(Reader)来传输标签(tag)的数据。
射频识别(Radio Frequency Identification,RFID)技术中,读写器和标签(Tag)之间的信息传输工作在安全模式。对于工作在安全模式的标签,首先要执行鉴别(authentication,也可以译为鉴权)过程,具体而言,其通常包括读写器和/或标签的身份认证过程,从而在确定其身份合法的前提下,进行读写器和标签之间的信息传输。在RFID协议中,支持如下三种类型的鉴别/鉴权:
标签对读写器的单向鉴权,用于标签认证读写器是否通过鉴权,即读写器的身份是否合法;
读写器对标签的单向鉴权,用于读写器认证标签是否通过鉴权,即标签的身份是否合法;
双向鉴权,用于标签认证读写器是否通过鉴权和读写器认证标签是否通过鉴权,即读写器的身份是否合法,且标签的身份是否合法。
但是上述RFID技术中的鉴别/鉴权方案不能完全应用于3GPP相关的通信系统,其主要原因在于:RFID技术方案中是由读写器直接认证标签身份的合法性,但是迁移到3GPP相关的通信系统后,读写器可能是基于UE或者RAN实现,然而在3GPP系统中UE或者RAN自身也是一个不可信的节点。
因此,在3GPP相关的通信系统中,如何认证标签,以及,标签如何认证作为读写器的UE或者RAN,是亟待解决的问题。
发明内容
本申请实施例提供一种鉴权方法、鉴权装置、通信设备及可读存储介质,能够解决在3GPP系统中如何认证标签以及标签如何认证作为读写器的UE或者RAN的问题。
第一方面,提供了一种标签设备的鉴权方法,该方法包括:
第一设备发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述第一设备为接入网设备、终端或核心网设备;
所述第一设备接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
第二方面,提供了一种标签设备的鉴权方法,该方法包括:
标签设备接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;
所述标签设备根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
第三方面,提供了一种读写器设备的鉴权方法,包括:
第一设备发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
所述第一设备接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
第四方面,提供了一种读写器设备的鉴权方法,包括:
标签设备接收第一设备发送的第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括所述标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证。
第五方面,提供了一种安全鉴权方法,该方法包括:
核心网设备接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;
所述核心网设备在向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息,其中,所述第三认证信息由所述核心网设备根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
第六方面,提供了一种标签设备的鉴权装置,包括:
第一发送模块,用于发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述标签设备的鉴权装置为接入网设备、终端或核心网设备;
第一接收模块,用于接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
第一确定模块,用于根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
第七方面,提供了一种标签设备的鉴权装置,包括:
第一接收模块,用于接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;
第一发送模块,用于根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
第八方面,提供了一种读写器设备的鉴权装置,包括:
第一发送模块,用于发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述读写器设备的鉴权装置为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
第一接收模块,用于接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
第九方面,提供了一种读写器设备的鉴权装置,包括:
第一接收模块,用于接收第一设备发送的第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括所述标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
第一确定模块,用于根据所述第二鉴权命令,确定所述读写器设备是否通过认证。
第十方面,提供了一种安全鉴权装置,包括:
第一接收模块,用于接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;
第一发送模块,用于在向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息,其中,所述第三认证信息由所述核心网设备根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
第十一方面,提供了一种通信设备,该终端包括处理器和存储器,所述存储器存储可
在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法的步骤。
第十二方面,提供了一种第一设备,包括处理器及通信接口,其中,所述通信接口用于发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述第一设备为接入网设备、终端或核心网设备;接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;所述处理器用于根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
第十三方面,提供了一种标签设备,包括处理器及通信接口,其中,所述通信接口用于接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
第十四方面,提供了一种第一设备,包括处理器及通信接口,其中,所述通信接口用于发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
第十五方面,提供了一种标签设备,包括处理器及通信接口,其中,所述通信接口用于接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;所述处理器用于向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息,其中,所述第三认证信息由所述核心网设备根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
第十六方面,提供了一种核心网设备,包括处理器及通信接口,其中,所述通信接口用于接收第一设备发送的用于获取安全参数的第一请求,所述第一请求中包括标签设备的标识信息;所述第一设备为读写器设备,所述读写器设备为接入网设备或终端;在确定所述第一设备为可信设备的情况下,向所述第一设备发送所述标签设备的安全参数。
第十七方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法的步骤。
第十八方面,提供了一种无线通信系统,包括:第一设备和标签设备,所述第一设备可用于执行如第一方面所述的方法的步骤,所述标签设备可用于执行如第二方面所述的方法的步骤,或者,所述第一设备可用于执行如第三方面所述的方法的步骤,所述标签设备可用于执行如第四方面所述的方法的步骤。
第十九方面,提供了一种无线通信系统,包括:第一设备、标签设备和核心网设备,所述第一设备可用于执行如第一方面所述的方法的步骤,所述标签设备可用于执行如第二方面所述的方法的步骤,所述核心网设备可用于执行如第五方面所述的方法的步骤。
第二十方面,提供了一种无线通信系统,包括:第一设备、标签设备和核心网设备,所述第一设备可用于执行如第三方面所述的方法的步骤,所述标签设备可用于执行如第四方面所述的方法的步骤,所述核心网设备可用于执行如第五方面所述的方法的步骤。
第二十一方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法。
第二十二方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述程序/程序产品被至少一个处理器执行以实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法的步骤。
在本申请实施例中,明确了在无线通信系统中如何认证标签设备的流程,以及,标签设备如何认证作为读写器设备的UE或RAN的流程,以使得读写器设备和标签设备之间的信息传输工作在安全模式。
图1为本申请实施例可应用的一种无线通信系统的框图;
图2为UE作为读写器(Reader)来传输Ambient IoT(Tag)的数据到Ambient IoT App的示意图;
图3为RAN作为读写器(Reader)传输Ambient IoT(Tag)的数据到Ambient IoT App的示意图;
图4为本申请实施例的标签设备的鉴权方法的流程示意图之一;
图5为本申请实施例的标签设备的鉴权方法的流程示意图之二;
图6为本申请实施例的读写器设备的鉴权方法的流程示意图之一;
图7为本申请实施例的读写器设备的鉴权方法的流程示意图之二;
图8为本申请实施例的安全鉴权方法的流程示意图;
图9为本申请实施例一的标签设备的鉴权方法的流程示意图;
图10为本申请实施例二的标签设备的鉴权方法的流程示意图;
图11为本申请实施例三的读写器设备的鉴权方法的流程示意图;
图12为本申请实施例四的读写器设备的鉴权方法的流程示意图;
图13为本申请实施例五的双向鉴权的方法的流程示意图;
图14为本申请实施例六的双向鉴权的方法的流程示意图;
图15为本申请实施例七的标签设备的鉴权方法的流程示意图;
图16为本申请实施例八的读写器设备的鉴权方法的流程示意图;
图17为本申请实施例九的双向鉴权的方法的流程示意图;
图18为本申请实施例的标签设备的鉴权装置的结构示意图之一;
图19为本申请实施例的标签设备的鉴权装置的结构示意图之二;
图20为本申请实施例的读写器设备的鉴权装置的结构示意图之一;
图21为本申请实施例的读写器设备的鉴权装置的结构示意图之二;
图22为本申请实施例的安全鉴权装置的结构示意图;
图23为本申请实施例的通信设备的结构示意图;
图24为本申请实施例的终端的硬件结构示意图;
图25为本申请实施例的网络侧设备的硬件结构示意图之一;
图26为本申请实施例的网络侧设备的硬件结构示意图之二。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,本申请中的“或”表示所连接对象的至少其中之一。例如“A或B”涵盖三种方案,即,方案一:包括A且不包括B;方案二:包括B且不包括A;方案三:既包括A又包括B。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请的术语“指示”既可以是一个直接的指示(或者说显式的指示),也可以是一个间接的指示(或者说隐含的指示)。其中,直接的指示可以理解为,发送方在发送的指示中明确告知了接收方具体的信息、需要执行的操作或请求结果等内容;间接的指示可以理解为,接收方根据发送方发送的指示确定对应的信息,或者进行判断并根据判断结果确定需要执行的操作或请求结果等。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency-Division Multiple Access,SC-FDMA)或其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,
并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统以外的系统,如第6代(6th Generation,6G)通信系统。
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)、笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(Ultra-mobile Personal Computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(Augmented Reality,AR)、虚拟现实(Virtual Reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、飞行器(flight vehicle)、车载设备(Vehicle User Equipment,VUE)、船载设备、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(Personal Computer,PC)、柜员机或者自助机等终端侧设备。可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。其中,车载设备也可以称为车载终端、车载控制器、车载模块、车载部件、车载芯片或车载单元等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以包括接入网设备或核心网设备,其中,接入网设备也可以称为无线接入网(Radio Access Network,RAN)设备、无线接入网功能或无线接入网单元。接入网设备可以包括基站、无线局域网(Wireless Local Area Network,WLAN)接入点(Access Point,AS)或无线保真(Wireless Fidelity,WiFi)节点等。其中,基站可被称为节点B(Node B,NB)、演进节点B(Evolved Node B,eNB)、下一代节点B(the next generation Node B,gNB)、新空口节点B(New Radio Node B,NR Node B)、接入点、中继站(Relay Base Station,RBS)、服务基站(Serving Base Station,SBS)、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点(home Node B,HNB)、家用演进型B节点(home evolved Node B)、发送接收点(Transmission Reception Point,TRP)或所属领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。
核心网设备可以包含核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM)、统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,
CNC)、网络存储功能(Network Repository Function,NRF)、网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM)、统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF)、网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。
下面首先对本申请涉及的技术内容进行简单说明。
1、Ambient IoT
Ambient IoT(可以简称为A-IOT)是一种待研究的新的3GPP IoT技术。Ambient IoT设备具有超低复杂度以及超低的功耗。
Ambient IoT,又称为环境能量使能的物联网(Ambient power-enabled Internet of Things,Ambient power-enabled IoT),是一种IoT业务,其中Ambient IoT设备通过能量采集(energy harvesting)供能,Ambient IoT设备没有电池,或者有有限的能量存储能力(例如,使用一个电容)。能量采集的能量源包括无线电波,光,运动,热或者其他合适的能量源。
Ambient IoT设备的能量来自于能量采集。关于能量存储,Ambient IoT设备可以具备以下特征:
1)无电池,无能量存储,完全依赖外部的能量源。或者,
2)有限的能量存储能力,无需换电池或充电。
Ambient IoT设备可以基于能量源(energy source)、能量存储能力(energy storage capability)、被动(Passive)或主动(Active)发射等进行分类。
Ambient IoT的被动(Passive)或主动(Active)发射,有如下多种通信模式:
1)正常操作。其中,Ambient IoT设备有电能连续工作或持续工作一段时间。能量可以来自连续的能量采集,或可能具备有一定的能量储存能力,例如装配有电容。
2)主动发射,支持设备触发的操作。其中,设备仅能支持短时间的活动状态,支持间歇式通信。设备可以决定何时与网络通信。设备不一定监听网络,也就是可能长时间不监听被叫业务。
3)被动发射,仅支持网络发起的按需操作。其中,设备不能自己发起业务。
在3GPP系统中,Ambient IoT设备可以通过作为读写器(Reader)的UE或RAN,与Ambient IoT APP通信,参见图2和图3。其中,图2中,UE可以作为读写器(Reader)来传输Ambient IoT(Tag)的数据到Ambient IoT App。图3中,RAN直接作为读写器(Reader)传输Ambient IoT(Tag)的数据到Ambient IoT App。其中,5G核心网(5G core network,5GC)的参与是可选的。
2、反向散射通信(Backscatter Communication,BSC)
反向散射通信是指反向散射通信设备利用其它设备或者环境中的射频信号进行信号调制来传输自己信息。反向散射通信终端设备(BSC Tag,也可以称为BSC UE),可以是传统视频识别(Radio Frequency Identification,RFID)中的Tag,或环境储能的IoT(Ambient IoT),或者是无源IoT(Passive-IoT)设备。反向散射技术作为一种无源或者低耗能技术,其技术特点在于可以通过改变接收到的环境射频信号的特性例如相位或幅度信息来完成自身信号的传输,实现极低功耗或零功耗的信息传送。
3、RFID协议中读写器和标签之间的安全鉴别协议
RFID是一种传统的反向散射通信系统,其主要设计目标就是对读写器覆盖范围内的反向散射通信(BSC)设备(即Tag)进行标识(Identity document,ID)识别以及数据读取。
可选地,读写器和标签(Tag)之间的信息传输工作在安全模式。对于工作在安全模式的标签,首先要执行鉴别(authentication,也可以译为鉴权)过程,具体而言,其通常包括读写器和/或标签的身份认证过程,从而在确定其身份合法的前提下,进行读写器和标签之间的信息传输。在RFID协议中,支持如下三种类型的鉴别/鉴权:
标签对读写器的单向鉴权,用于标签认证读写器是否通过鉴权,即读写器的身份是否合法;
读写器对标签的单向鉴权,用于读写器认证标签是否通过鉴权,即标签的身份是否合法;
双向鉴权,用于标签认证读写器是否通过鉴权和读写器认证标签是否通过鉴权,即读写器的身份是否合法,且标签的身份是否合法。
目前协议仅标准化了标签的安全鉴权命令(Authenticate command)。对于安全鉴权协议流程具体需要几个步骤,支持的鉴权算法和流程等并未标准化。
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的鉴权方法、鉴权装置、通信设备及可读存储介质进行详细地说明。
请参考图4,本申请实施例提供一种标签设备的鉴权方法,包括:
步骤41:第一设备发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述第一设备为接入网(RAN)设备、终端(UE)或核心网设备;
可选的,所述核心网设备可以是相关技术中的核心网节点,如AMF等,也可以是新引入的核心网节点。
步骤42:所述第一设备接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
可选的,所述第一认证信息可以是认证码或数据签名。
步骤43:所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
在本申请实施例中,明确了在无线通信系统中如何认证标签设备的流程,以使得读写器设备(终端或接入网设备)和标签设备之间的信息传输工作在安全模式。
可选的,所述标签设备的安全参数(security credential)包括以下至少一项:根密钥(Root key,RK)索引(通过索引值唯一确定根密钥)、通信加密算法(用于指示标签设备支持的数据传输加密和完整性保护算法)、密钥长度、安全模式(用于指示标签设备是否需要进行安全鉴权,安全鉴权包括进行单向鉴权还是双向鉴权,单向鉴权是标签设备鉴权读写器设备还是读写器设备鉴权标签设备、是否需要进行安全通信)、安全功能(用于指示标签设备支持的安全鉴权算法,安全鉴权算法包括单向鉴权算法还是双向鉴权算法,单向鉴权算法是标签设备鉴权读写器设备使用的算法还是读写器设备鉴权标签设备使用的算法)、Tsec(读写器设备发送安全鉴权命令或安全通信命令后,等待标签设备响应的参考时间,以10ms为单位)。可选的,上述安全参数与标签设备的出产配置保持一致,写入标签设备后不可修改。
RFID技术方案中,安全鉴权流程的前提步骤是,读写器需要触发安全参数获取流程,从标签获取标签的安全参数。但是迁移到3GPP系统后,读写器可能是基于接入网设备或终端实现,由于接入网设备或终端可能是不可信的节点,因此可以省略读写器从标签处获取标签的安全参数的流程。
本申请实施例中,可选的,当所述第一设备为接入网设备或终端时,可以考虑将所述标签设备的安全参数存储于所述第一设备中,可选的,运营商预先通过操作管理维护(Operation Administration Maintenance,OAM)的方式给所有可信的第一设备预配置该运营商管控的全部或部分标签设备的安全参数。
或者,考虑核心网设备作为一个可信的安全参数存储节点,所述安全参数由所述第一设备从核心网设备获取。此时,核心网设备可以对第一设备进行认证,如果认证第一设备是一个可信的节点,可以将标签设备的安全参数发送给第一设备,从而保证参与鉴权的接入网设备或终端是可信的设备。
本申请实施例中,可选的,所述第一设备为接入网设备或终端时,若第一设备支持存
储安全参数,在对标签设备进行鉴权之前,首先判断是否存有该标签设备的安全参数。
所述第一设备发送第一鉴权命令,包括:在所述第一设备有所述标签设备的安全参数的情况下,所述第一设备无需从核心网设备获取所述标签设备的安全参数,向标签设备发送第一鉴权命令。也就是说,在所述第一设备有所述标签设备的安全参数的情况下,第一设备可以直接向标签设备发送第一鉴权命令。
在所述第一设备没有所述标签设备的安全参数的情况下,所述第一设备发送第一鉴权命令之前,还包括:所述第一设备向核心网设备发送用于获取安全参数的第一请求,其中,所述第一请求中包括所述标签设备的标识信息;所述第一设备接收来自所述核心网设备的所述安全参数。也就是说,在所述第一设备没有所述标签设备的安全参数的情况下,第一设备先通过发送第一请求,请求获取安全参数,在获取到第一安全参数后,再向标签设备发送第一鉴权命令。
本实施例中,可选是第一设备支持预配置标签设备的安全参数的情况,当判断出有预配置的标签设备的安全参数时,则向标签设备发送第一鉴权命令,当判断出预配置标签设备的安全参数,则向核心网设备获取安全参数。
本申请实施例中,可选的,所述第一设备为接入网设备或终端;若第一设备不支持存储安全参数,在对标签设备进行鉴权之前,不需要判断是否存有该标签设备的安全参数。
此时,所述第一设备发送第一鉴权命令之前,还包括:
所述第一设备向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息,其中,所述第一请求中包括所述标签设备的标识信息;
所述第一设备接收来自所述核心网设备的所述安全参数。
本实施例中,可以是第一设备不支持预配置标签设备的安全参数的情况,直接向核心网设备获取安全参数。
其中,可选的,所述标签设备的标识信息包括以下至少一项:所述标签设备的电子产品代码(Electronic Product code,EPC),所述标签设备的标签分配标识符(Tag identity,TID,该标签分配标识符存储在标签信息区中。标签信息区的数据在标签芯片出产时写入,写入后不能修改)。可选的,所述标签设备的标识信息与所述标签设备的出产配置保持一致,写入后不可修改。
本申请实施例中,可选的,所述第一设备为核心网设备;
所述第一设备发送第一鉴权命令包括:所述第一设备通过接入网设备向所述标签设备发送所述第一鉴权命令;
所述第一设备接收第一响应包括:所述第一设备接收接入网设备转发的所述第一响应;
本实施例中,接入网设备可以是透明转发所述第一鉴权命令和所述第一响应。
本申请实施例中,可选的,所述第一设备为所述标签设备的源服务小区所在的接入网设备;
所述第一设备发送第一鉴权命令包括:所述第一设备通过所述标签设备的目的服务小
区所在的接入网设备向所述标签设备发送所述第一鉴权命令,其中,所述标签设备的目的服务小区所在的接入网设备转发所述第一鉴权命令;
所述第一设备接收第一响应包括:所述第一设备接收所述标签设备的目的服务小区所在的接入网设备转发的所述第一响应。
本实施例中,所述标签设备的目的服务小区所在的接入网设备可以是透明转发所述第一鉴权命令和所述第一响应。
进一步地,标签设备的源服务小区所在的接入网设备可以给标签设备的目标服务小区所在的接入网设备通知标签设备是否通过认证的鉴权结果。这里的通知可以是显示的指示,也可以是隐式的指示,隐式方式例如通过目标服务小区所在的接入网设备发起与源服务小区所在的接入网设备之间的UE上下文获取流程实现,当标签设备的上下文获取成功,则认为标签设备通过认证;当标签设备上下文获取失败,则认为认证失败。
本申请实施例中,可选的,所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证,包括:
所述第一设备根据所述标签设备的安全参数的配置信息和用于计算所述标签设备的第一认证信息的第一输入参数,通过计算确定所述标签设备的第二认证信息;
所述第一设备比较所述第二认证信息和接收到的所述标签设备的第一认证信息是否相同;
若所述第二认证信息和所述第一认证信息相同,确定所述标签设备通过认证;
若所述第二认证信息和所述第一认证信息不同,确定所述标签设备未通过认证。
本申请实施例中,不对第一认证信息和第二认证信息的计算方法进行限定,但是第一认证信息和第二认证信息的计算方法需要相同。
可选的,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
本申请实施例中,可选的,当所述第一设备为核心网设备时,所述第一设备根据第一输入参数以及所述标签设备的安全参数的配置信息,通过计算确定所述标签设备的第一认证信息之前还包括:所述第一设备接收所述标签设备的服务小区所在的接入网设备发送的所述第一输入参数。
可选的,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
本申请实施例中,可选的,所述第一设备为接入网设备或者终端,所述确定所述标签设备是否通过认证之后还包括:
若所述标签设备通过认证,所述第一设备执行以下至少一项:
1)向所述标签设备发送控制命令;
可选的,所述控制命令包括以下至少一项:
激活(Activate)命令,用于激活标签设备;
去激活(Deactivate)命令,用于去激活标签设备;
盘点(Inventory)命令,用于盘点标签设备;
读(Read)命令,用于从标签设备读取数据;
写(Write)命令,用于向标签设备写入数据;
定位(Positioning)命令,用于定位标签设备;
控制(Control)命令,用于控制标签设备。
2)接收所述标签设备发送的数据;
3)处理所述标签设备发送的数据;
4)转发所述标签设备发送的数据。
本申请实施例中,可选的,转发数据的对象可以是一个相关技术中的核心网设备,例如用户面功能(User plane Function,UPF),或者,一个新引入的核心网设备,或者A-IOT App server等,在此不做限定。
本申请实施例中,可选的,所述第一设备为核心网设备,所述确定所述标签设备是否通过认证之后还包括以下至少一项:
1)所述第一设备向接入网设备或终端发送所述标签设备是否通过认证的鉴权结果;
该种情况是核心网设备显式的将鉴权结果发送给接入网设备或终端。
2)所述第一设备向接入网设备或终端发送所述标签设备的授权信息,所述授权信息在所述标签设备通过认证的情况下发送。
该种情况下,核心网设备在标签设备通过认证的前提下向接入网设备或终端发送所述标签设备的授权信息,授权信息隐式表示通过标签设备通过认证。
请参考图5,本申请实施例还提供一种标签设备的鉴权方法,包括:
步骤51:标签设备接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;
步骤52:所述标签设备根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
可选的,所述第一认证信息可以是认证码或数据签名。
在本申请实施例中,明确了在3GPP系统中如何认证标签设备的流程,,以使得读写器设备(接入网设备或终端)和标签设备之间的信息传输工作在安全模式。
可选的,所述标签设备的安全参数(security credential)包括以下至少一项:根密钥(Root key,RK)索引(通过索引值唯一确定根密钥)、通信加密算法(用于指示标签设备
支持的数据传输加密和完整性保护算法)、密钥长度、安全模式(用于指示标签设备是否需要进行安全鉴权,安全鉴权包括进行单向鉴权还是双向鉴权,单向鉴权是标签设备鉴权读写器设备还是读写器设备鉴权标签设备、是否需要进行安全通信)、安全功能(用于指示标签设备支持的安全鉴权算法,安全鉴权算法包括单向鉴权算法还是双向鉴权算法,单向鉴权算法是标签设备鉴权读写器设备使用的算法还是读写器设备鉴权标签设备使用的算法)、Tsec(读写器设备发送安全鉴权命令或安全通信命令后,等待标签设备响应的参考时间,以10ms为单位)。可选的,上述安全参数与标签设备的出产配置保持一致,写入标签设备后不可修改。
本申请实施例中,可选的,当所述第一设备为接入网设备或终端时,可以考虑将所述标签设备的安全参数存储于所述第一设备中,可选的,运营商预先通过操作管理维护(Operation Administration Maintenance,OAM)的方式给所有可信的第一设备预配置该运营商管控的全部或部分标签设备的安全参数。
或者,考虑核心网设备作为一个可信的安全参数存储节点,所述安全参数由所述第一设备从核心网设备获取。此时,核心网设备可以对第一设备进行认证,如果认证第一设备是一个可信的节点,可以将标签设备的安全参数发送给第一设备,从而保证参与鉴权的接入网设备或终端是可信的设备。
本申请实施例中,可选的,所述标签设备根据所述第一鉴权命令,向所述第一设备发送第一响应,包括:
所述标签设备根据所述安全参数的配置信息和用于计算所述标签设备的第一认证信息的第一输入参数,通过计算确定所述标签设备的第一认证信息;
所述标签设备向所述第一设备发送所述第一响应,所述第一响应中包括所述第一认证信息。
本申请实施例中,可选的,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
上述实施例是对标签设备的鉴权,下面介绍对读写器设备的鉴权。
请参考图6,本申请实施例还提供一种读写器设备的鉴权方法,包括:
步骤61:第一设备发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
可选的,所述第三认证信息可以是认证码或数据签名。
步骤62:所述第一设备接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
在本申请实施例中,明确了在3GPP系统中标签设备如何认证作为读写器设备的UE或RAN的流程,以使得读写器设备和标签设备之间的信息传输工作在安全模式。
本申请实施例中,可选的,当所述第一设备为接入网设备或终端时,可以考虑将所述标签设备的安全参数存储于所述第一设备中,可选的,运营商预先通过操作管理维护(Operation Administration Maintenance,OAM)的方式给所有可信的第一设备预配置该运营商管控的全部或部分标签设备的安全参数。
或者,考虑核心网设备作为一个可信的安全参数存储节点,所述安全参数由所述第一设备从核心网设备获取。此时,核心网设备可以对第一设备进行认证,如果认证第一设备是一个可信的节点,可以将标签设备的安全参数发送给第一设备,从而保证参与鉴权的接入网设备或终端是可信的设备。
本申请实施例中,可选的,所述第一设备发送第二鉴权命令之前还包括:所述第一设备确定所述读写器设备的第三认证信息。
本申请实施例中,可选的,所述第一设备为所述读写器设备,所述第一设备发送第二鉴权命令之前还包括:
所述第一设备向核心网设备发送用于获取安全参数的第一请求(该种情况通常是第一设备不支持预配置标签设备的安全参数的情况,则直接向核心网设备获取安全参数);
或者,
在所述第一设备没有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送用于获取安全参数的第一请求(该种情况通常时第一设备支持预配置标签设备的安全参数的情况,如果没有判断没有预配置标签设备的安全参数,则向核心网设备获取安全参数);
其中,所述第一请求中包括所述标签设备的标识信息。
本申请实施例中,可选的,所述第一设备为读写器设备,所述第一设备发送第二鉴权命令之前还包括:
所述第一设备向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息和用于计算所述读写器设备的第三认证信息的第二输入参数(该种情况通常是第一设备不支持预配置标签设备的安全参数的情况,则直接向核心网设备获取安全参数,同时还需要请求核心网设备来计算读写器设备的第三认证信息);
所述第一设备接收所述核心网设备发送的所述标签设备的安全参数和所述读写器设备的第三认证信息;
或者,
在所述第一设备有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送第二请求;所述第一设备接收所述核心网设备发送的所述读写器设备的第三认证信息(该种情况通常是第一设备支持预配置标签设备的安全参数的情况,如果判断有预配置标签设备的安全参数,则无需向核心网设备获取安全参数,只需要请求核心网设备来计算读
写器设备的第三认证信息即可);
在所述第一设备没有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送用于获取安全参数的第一请求;所述第一设备接收所述核心网设备发送的所述标签设备的安全参数和所述读写器设备的第三认证信息(该种情况通常是第一设备支持预配置标签设备的安全参数的情况,如果判断没有预配置标签设备的安全参数,则向核心网设备获取安全参数,同时还需要请求核心网设备来计算读写器设备的第三认证信息);
其中,所述第一请求中包括所述标签设备的标识信息和用于计算所述读写器设备的第三认证信息的第二输入参数,所述第二请求中包括用于计算所述读写器设备的第三认证信息的第二输入参数。
本申请实施例中,可选的,所述第二输入参数包括以下至少一项:所述第一设备的标识信息,所述第三认证信息传输对应的时间信息,所述第三认证信息传输对应的频域资源信息,所述第三认证信息传输对应的波束信息。
本申请实施例中,可选的,所述第一设备为核心网设备;
所述第一设备发送第二鉴权命令包括:所述第一设备向通过接入网设备向所述标签设备发送所述第二鉴权命令;
所述第一设备接收第二响应包括:所述第一设备接收由所述接入网设备转发的所述第二响应。
本实施例中,可选的,所述接入网设备可以透明转发所述第二鉴权命令和所述第二响应。
本申请实施例中,可选的,所述第一设备接收第二响应之后还包括:
所述第一设备发送第一鉴权命令,所述第一鉴权命令用于对标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;
所述第一设备接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
本申请实施例中,标签设备先对读写器设备进行鉴权,然后再由读写器设备对标签设备进行鉴权。当然,在本申请的其他一些实施例中,也不排除,读写器设备先对标签设备进行鉴权,然后再由标签设备先对读写器设备进行鉴权。
请参考图7,本申请实施例还提供一种读写器设备的鉴权方法,包括:
步骤71:标签设备接收第一设备发送的第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括所述标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
可选的,所述第三认证信息可以是认证码或数据签名。
步骤72:所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证。
在本申请实施例中,明确了在3GPP系统中标签设备如何认证作为读写器设备的UE或RAN的流程,以使得读写器设备和标签设备之间的信息传输工作在安全模式。
RFID技术方案中,安全鉴权流程的前提步骤是,读写器需要触发安全参数获取流程,从标签获取标签的安全参数。但是迁移到3GPP系统后,读写器可能是基于接入网设备或终端实现,由于接入网设备或终端可能是不可信的节点,因此可以省略读写器从标签处获取标签的安全参数的流程。本申请实施例中,可选的,当所述第一设备为接入网设备或终端时,可以考虑将所述标签设备的安全参数存储于所述第一设备中,标签设备的安全参数存储于所述第一设备中,可以是,标签设备的安全参数通过预配置的方式预配置到所述第一设备中。或者,考虑核心网设备作为一个可信的安全参数存储节点,所述安全参数由所述第一设备从核心网设备获取。此时,核心网设备可以对第一设备进行认证,如果认证第一设备是一个可信的节点,可以将标签设备的安全参数发送给第一设备,从而保证参与鉴权的接入网设备或终端是可信的设备。
本申请实施例中,可选的,所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证,包括:
所述标签设备根据所述标签设备的安全参数的配置信息和用于计算所述读写器设备的第三认证信息的第二输入参数,通过计算确定所述读写器设备的第四认证信息;
所述标签设备比较所述第四认证信息和接收到的所述读写器设备的第三认证信息是否相同;
若所述第四认证信息和所述第三认证信息相同,确定所述读写器设备通过认证;
若所述第四认证信息和所述第三认证信息不同,确定所述读写器设备未通过认证。
本申请实施例中,不对第三认证信息和第四认证信息的计算方法进行限定,但是第三认证信息和第四认证信息的计算方法需要相同。
本申请实施例中,可选的,所述第二输入参数包括以下至少一项:所述第一设备的标识信息,所述第三认证信息传输对应的时间信息,所述第三认证信息传输对应的频域资源信息,所述第三认证信息传输对应的波束信息。
本申请实施例中,可选的,所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证之后还包括:
若所述读写器设备通过认证,所述标签设备执行以下至少一项:
向所述第一设备发送第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果;
1)响应所述读写器设备发送的控制命令;
可选的,所述控制命令包括以下至少一项:
激活(Activate)命令,用于激活标签设备;
去激活(Deactivate)命令,用于去激活标签设备;
盘点(Inventory)命令,用于盘点标签设备;
读(Read)命令,用于从标签设备读取数据;
写(Write)命令,用于向标签设备写入数据;
定位(Positioning)命令,用于定位标签设备;
控制(Control)命令,用于控制标签设备。
2)向所述读写器设备发送数据。
本申请实施例中,可选的,所述标签设备接收第一设备发送的第二鉴权命令之后还包括:
所述标签设备接收所述第一设备发送的第一鉴权命令,所述第一鉴权命令用于对所述标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;
所述标签设备根据所述第一鉴权命令,确定所述标签设备的第一认证信息;
所述标签设备向所述第一设备发送第一响应,所述第一响应中包括:所述标签设备的第一认证信息。
本申请实施例中,标签设备先对读写器设备进行鉴权,然后再由读写器设备对标签设备进行鉴权。当然,在本申请的其他一些实施例中,也不排除,读写器设备先对标签设备进行鉴权,然后再由标签设备先对读写器设备进行鉴权。
本申请实施例中,可选的,所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证之后还包括:
若所述读写器设备未通过认证,所述标签设备丢弃所述第一设备发送的第一鉴权命令,所述第一鉴权命令用于对所述标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息。
本申请实施例中,标签设备先对读写器设备进行鉴权,然后再由读写器设备对标签设备进行鉴权,如果所述读写器设备未通过认证,则标签设备不再对读写器设备进行鉴权。
请参考图8,本申请实施例还提供一种安全鉴权方法,包括:
步骤81:核心网设备接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;
步骤82:所述核心网设备向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息,其中,所述第三认证信息由所述核心网设备根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
本申请实施例中,作为读写器设备的接入网设备或终端在对标签设备进行鉴权之前,或者,请求标签设备对所述读写器设备进行鉴权之前,可以向核心网设备获取标签设备的安全参数和/或请求核心网设备确定读写器设备的认证信息,核心网设备验证读写器设备可信的情况下,再向读写器设备发送所述标签设备的安全参数和/或读写器设备的认证信息,从而保证参与鉴权的接入网设备或终端是可信的设备。
在一些实施例中,可选的,核心网设备接收读写器设备发送的请求,所述请求中包括
标签设备的标识信息,此时,核心网设备向所述读写器设备发送所述标签设备的安全参数。即读写器设备仅请求标签设备的安全参数。
在一些实施例中,可选的,核心网设备接收读写器设备发送的请求,所述请求中包括用于计算所述读写器设备的认证信息的第二输入参数,此时,核心网设备向所述读写器设备发送所述读写器设备的第三认证信息。即读写器设备仅请求请求核心网设备确定读写器设备的认证信息。
在一些实施例中,可选的,核心网设备接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和用于计算所述读写器设备的认证信息的第二输入参数,此时,核心网设备向所述读写器设备发送所述标签设备的安全参数和所述读写器设备的第三认证信息。即读写器设备既请求标签设备的安全参数,又请求核心网设备确定读写器设备的认证信息。
本申请实施例中,可选的,所述核心网设备向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息包括:
所述核心网设备在判断所述读写器设备可信的情况下,向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息。
本申请实施例中,核心网设备可以用于为读写器设备计算认证信息。
下面结合具体应用场景,对本申请实施例的上述方法举例进行说明。
本申请实施例一
本实施例中,RAN节点(接入网设备)作为读写器设备,A-IOT设备作为标签设备,本实施例是RAN节点对A-IOT设备的单向鉴权,即RAN节点认证A-IOT设备是否合法,安全功能的对等实体为A-IOT设备和RAN节点。
请参考图9,本申请实施例的标签设备的鉴权方法包括:
步骤0a和步骤0b为可选步骤,具体方式通过以下1)或2)任一项实现:
1)运营商预先通过操作管理维护(Operation Administration Maintenance,OAM)方式给所有可信RAN节点预配置该运营商管控的全部或部分A-IOT设备的安全参数(security credential)。对于某个特定RAN节点,其在触发与A-IOT设备之间的空口安全鉴权流程之前,首先判断其预配置中是否存有该A-IOT设备的安全参数。
a.若该A-IOT设备的安全参数在其预配置中,则可跳过步骤0a和步骤0b,RAN节点直接触发空口的安全鉴权流程,即RAN节点第一步执行图9中的步骤1。
b.若接入该RAN节点的A-IOT设备的安全参数不在其预配置中,则RAN节点在触发空口的安全鉴权流程之前,先向5GC节点请求该A-IOT设备的安全参数,请求中携带该A-IOT设备的标识(Identifier,ID)信息,5GC节点在判断RAN节点可信的前提下,向RAN节点响应该A-IOT设备的安全参数。即RAN节点第一步执行步骤0a和步骤0b。该5GC节点可以是相关技术的5GC节点(例如接入和移动性管理功能(Access and Mobility Management Function,AMF)),或者新引入的5GC功能节点,在此不做限定。
2)运营商未支持通过OAM方式给所有可信RAN节点预配置该运营商管控的全部或部分A-IOT设备的安全参数(security credential)的情况下,对于某个特定RAN节点,在触发空口的安全鉴权流程之前,总是先向5GC节点请求该A-IOT设备的安全参数,5GC节点在判断RAN节点可信的前提下,向RAN节点响应该A-IOT设备的安全参数,即RAN节点第一步执行步骤0a,步骤0b是否执行取决于5GC节点判断RAN节点是否可信。
其中,A-IOT设备的ID信息,可以包括以下至少一项:A-IOT设备的电子产品代码(Electronic Product code,EPC),A-IOT设备的标签分配标识符(Tag identity,TID),该标签分配标识符存储在标签信息区中。标签信息区的数据在标签芯片出产时写入,写入后不能修改)。上述ID信息与A-IOT设备的出产配置保持一致,写入后不可修改。
所述A-IOT设备的安全参数可以包括以下至少一项:根密钥(Root key,RK)索引(通过索引值唯一确定根密钥)、通信加密算法(用于指示A-IOT设备支持的数据传输加密和完整性保护算法)、密钥长度、安全模式(用于指示A-IOT设备是否需要进行安全鉴权,安全鉴权包括进行单向鉴权还是双向鉴权,单向鉴权是A-IOT设备鉴权RAN节点还是RAN节点鉴权A-IOT设备、是否需要进行安全通信)、安全功能(用于指示A-IOT设备支持的安全鉴权算法,安全鉴权算法包括单向鉴权算法还是双向鉴权算法,单向鉴权算法是A-IOT设备鉴权RAN节点使用的算法还是RAN节点鉴权A-IOT设备使用的算法)、Tsec(RAN节点发送安全鉴权命令或安全通信命令后,等待A-IOT设备响应的参考时间,以10ms为单位)。上述安全参数与A-IOT设备的出产配置保持一致,写入A-IOT设备后不可修改。
步骤1:RAN节点向A-IOT设备发送单向鉴权命令(即上述实施例中的第一鉴权命令),所述单向鉴权命令用于A-IoT设备的鉴权,所述单向鉴权命令至少携带A-IOT设备的安全参数的配置信息,该配置信息遵循RAN节点的预配置的安全参数的内容或者遵循从5GC节点获取的安全参数的配置内容(即步骤0b)。
根据步骤1,A-IOT设备通过计算确定A-IOT设备的认证码或数据签名。其中A-IOT设备生成A-IOT设备认证码或数据签名的方法,本申请不作限定。
步骤2:A-IOT设备向RAN节点发送单向鉴权命令的响应(第一响应),所述单向鉴权命令的响应中携带:A-IOT设备的ID信息,A-IOT设备的认证码或数据签名。
根据步骤2,RAN节点确定A-IOT设备是否通过认证,具体的,可以根据以下方法确定:
该RAN节点通过确定A-IOT设备的认证码或数据签名,比对自己计算并生成的A-IOT设备的认证码或数据签名,与步骤2中收到的A-IOT设备的认证码或数据签名,如果两者取值相等,则判断A-IOT设备通过认证;否则,判断A-IOT设备认证失败。
本申请实施例中,可选的,若该RAN节点为所述A-IOT设备的源服务小区所在的RAN节点;A-IOT设备的源服务小区所在的RAN节点通过计算确定A-IOT设备的认证码或数据签名,比对自己计算并生成的A-IOT设备的认证码或数据签名,与步骤2中收到
的A-IOT设备的认证码或数据签名,如果两者取值相等,则判断A-IOT设备通过认证;否则,判断A-IOT设备认证失败。
进一步地,A-IOT设备的源服务小区所在的RAN节点可以给A-IOT设备的目标服务小区所在的RAN节点通知A-IOT设备是否通过认证的鉴权结果。这里的通知可以是显示的指示,也可以是隐式的指示,隐式方式例如通过目标服务小区所在的RAN节点发起与源服务小区所在的RAN节点之间的UE上下文获取流程实现,当A-IOT设备的上下文获取成功,则认为A-IOT设备通过认证;当A-IOT设备上下文获取失败,则认为认证失败。
其中A-IOT设备的源服务小区所在的RAN节点计算并生成A-IOT设备的认证码或数据签名的方法,本申请不作限定。但须与A-IOT设备生成A-IOT设备的认证码或数据签名的方法,保持一致。
进一步地,在该RAN节点确定A-IOT设备通过认证的前提下,RAN节点执行以下至少一项:
向A-IOT设备发送控制命令;
接收或处理A-IOT设备的数据;
转发A-IOT设备的数据。
这里,转发数据的对象可以是一个相关技术的5GC节点,例如用户面功能(User plane Function,UPF),或者,一个新引入的5GC功能节点,或者A-IOT App server等,在此不做限定。
本申请实施例二
本实施例中,RAN节点(接入网设备)作为读写器设备,A-IOT设备作为标签设备,本实施例是5GC节点(核心网设备)对A-IOT设备的单向鉴权,即5GC节点认证A-IOT设备是否合法,安全功能的对等实体为A-IOT设备和5GC节点。
实施例二与实施例一的区别自于:RAN节点承担的是安全鉴权相关命令的透明转发功能,实质不参与A-IOT设备的安全鉴权功能,生成安全鉴权命令以及执行鉴权功能的是5GC节点。
请参考图10,本申请实施例的标签设备的鉴权方法包括:
步骤1:5GC节点向A-IOT设备发送单向鉴权命令(即上述实施例中的第一鉴权命令),所述单向鉴权命令通过RAN节点透明转发至A-IOT设备。所述单向鉴权命令用于A-IoT设备的鉴权,所述单向鉴权命令至少携带A-IOT设备的安全参数的配置信息。
根据步骤1,A-IOT设备通过计算确定A-IOT设备的认证码或数据签名。其中A-IOT设备生成A-IOT设备的认证码或数据签名的方法,本申请不作限定。
步骤2:A-IOT设备向5GC节点发送单向鉴权命令的响应(第一响应),所述单向鉴权命令的响应通过RAN节点透明转发至5GC节点。所述单向鉴权命令的响应中携带:A-IOT设备的ID信息,A-IOT设备的认证码或数据签名。
步骤3:RAN节点转发单向鉴权命令的响应,还将用于计算A-IOT设备的认证码或
数据签名的至少一个第一输入参数发送给5GC节点。
根据步骤3,5GC节点确定A-IOT设备是否通过认证,可以通过以下方式确定:
该5GC节点通过计算确定A-IOT设备的认证码或数据签名,比对自己计算并生成A-IOT设备的认证码或数据签名,与收到的A-IOT设备的认证码或数据签名,如果两者取值相等,则判断A-IOT设备通过认证;否则,判断A-IOT设备认证失败;
其中5GC节点计算并生成A-IOT设备的认证码或数据签名的方法,本申请不作限定。但须与A-IOT设备生成A-IOT设备的认证码或数据签名的方法,保持一致。
步骤4:5GC节点向RAN节点反馈所述A-IOT设备是否通过认证的鉴权结果。
根据步骤4,进一步地,在该RAN节点确定A-IOT设备通过认证的前提下,RAN节点执行以下至少一项:
向A-IOT设备发送其他命令;
接收或处理A-IOT设备的数据;
转发A-IOT设备的数据。
这里,转发数据的对象可以是一个相关技术的5GC节点,例如用户面功能(User plane Function,UPF),或者,一个新引入的5GC功能节点,或者A-IOT App server等,在此不做限定。
本申请实施例三
本实施例中,RAN节点(接入网设备)作为读写器设备,A-IOT设备作为标签设备,本实施例是A-IOT设备对RAN节点的单向鉴权,即A-IOT设备认证RAN节点是否合法,安全功能的对等实体为A-IOT设备和RAN节点。
请参考图11,本申请实施例的读写器设备的鉴权方法包括:
步骤0a和步骤0b描述同实施例一,不再重复描述。
步骤1:RAN节点向A-IOT设备发送请求单向鉴权命令(第二鉴权命令),所述请求单向鉴权命令用于RAN节点的鉴权,所述请求单向鉴权命令至少携带A-IOT设备的安全参数的配置信息,RAN节点的认证码或数据签名。
在步骤1之前,RAN节点通过计算确定RAN节点的认证码或数据签名。其中RAN节点生成RAN节点认证码或数据签名的方法,本申请不作限定。
步骤2:A-IOT设备向RAN节点发送请求单向鉴权命令的响应(即第二响应),所述请求单向鉴权命令的响应携带RAN节点是否通过认证的鉴权结果。
在步骤2之前,A-IOT设备确定RAN节点是否通过认证。可选的,可以通过以下方法确定:该A-IOT设备自己计算并生成RAN节点的认证码或数据签名,比对自己计算并生成RAN节点的认证码或数据签名,与步骤1中收到的RAN节点的认证码或数据签名,如果两者取值相等,则判断RAN节点通过认证;否则,判断RAN节点认证失败。
其中A-IOT设备生成RAN节点认证码或数据签名的方法,本申请不作限定。但须与RAN节点生成RAN节点认证码或数据签名的方法,保持一致。
进一步地,在该A-IOT设备确定RAN节点通过认证的前提下,A-IOT设备执行以下至少一项:
响应RAN节点发送的控制命令;
向RAN节点发送A-IOT设备的数据。
本申请实施例四
本实施例中,RAN节点(接入网设备)作为读写器设备,A-IOT设备作为标签设备,本实施例是A-IOT设备对RAN节点的单向鉴权,即A-IOT设备认证RAN节点是否合法,安全功能的对等实体为A-IOT设备和5GC节点(核心网设备)。
请参考图12,本申请实施例的读写器设备的鉴权方法包括:
步骤0a和步骤0b为可选步骤,具体方式通过以下1)或2)任一项实现:
1)运营商预先通过操作管理维护(Operation Administration Maintenance,OAM)方式给所有可信RAN节点预配置该运营商管控的全部或部分A-IOT设备的安全参数(security credential)。对于某个特定RAN节点,其在触发与A-IOT设备之间的空口安全鉴权流程之前,首先判断其预配置中是否存有该A-IOT设备的安全参数。
a.若该A-IOT设备的安全参数在其预配置中,则在步骤0a中向5GC节点发送用于计算RAN节点的认证码或数字签名的部分或全部第二输入参数(如A-IOT设备ID,A-IOT设备的服务小区ID、A-IOT设备的UE context ID,认证码或数据签名传输对应的时间信息、认证码或数据签名传输对应的频域资源信息、认证码或数据签名传输对应的波束信息中的至少一项),步骤0b:5GC节点向所述RAN节点返回所述RAN节点的认证码或数字签名。
b.若该A-IOT设备的安全参数不在其预配置中,则在步骤0a中,向5GC节点发送获取该A-IOT设备的安全参数的请求,并携带A-IOT设备的ID信息和用于计算RAN节点的认证码或数字签名的部分或全部第二输入参数,步骤0b:5GC节点向所述RAN节点返回该A-IOT设备的安全参数和所述RAN节点的认证码或数字签名。
这里,5GC节点可以是相关技术中的5GC节点(例如AMF),或者新引入的5GC功能节点,在此不做限定。
也就是说,本实施例中,由5GC节点计算RAN节点的认证码或数字签名。
2)运营商未支持通过OAM方式给所有可信RAN节点预配置该运营商管控的全部或部分A-IOT设备的安全参数(security credential)的情况下,对于某个特定RAN节点,则RAN节点在触发空口的安全鉴权流程之前,总是先向5GC节点请求该A-IOT设备的安全参数,并发送用于计算RAN的认证码或数字签名的第二输入参数,5GC节点在判断RAN节点可信的前提下,向RAN节点响应该A-IOT设备的安全参数和所述RAN的节点的认证码或数字签名。即RAN节点第一步执行步骤0a,步骤0b是否执行取决于5GC节点判断RAN节点是否可信的认证结果。
步骤1:RAN节点向A-IOT设备发送请求单向鉴权命令(即上述实施例中的第二鉴
权命令),所述请求单向鉴权命令用于RAN节点的鉴权,所述请求单向鉴权命令至少携带A-IOT设备的安全参数的配置信息,RAN节点的认证码或数据签名。该配置内容遵循RAN节点的预配置内容或者遵循5GC节点返回的配置内容(即步骤0b);
或者,也可以由5GC节点向A-IOT设备发送请求单向鉴权命令,所述请求单向鉴权命令通过RAN节点透明转发至A-IOT设备。
在步骤1之前,5GC节点计算并生成RAN节点的认证码或数据签名。其中5GC节点生成RAN节点的认证码或数据签名的方法,本申请不作限定。
步骤2:A-IOT设备向RAN节点发送请求单向鉴权命令的响应(即第二响应),所述请求单向鉴权命令的响应至少携带RAN节点是否通过认证的鉴权结果。
或者,A-IOT设备向5GC节点发送请求单向鉴权命令的响应,所述请求单向鉴权命令的响应通过RAN节点透明转发至5GC节点。
在步骤2之前,A-IOT设备确定RAN节点是否通过认证。可选的,可以通过以下方法确定:该A-IOT设备自己计算并生成RAN节点的认证码或数据签名,比对自己计算并生成RAN节点的认证码或数据签名,与步骤1中收到的RAN节点的认证码或数据签名,如果两者取值相等,则判断RAN节点通过认证;否则,判断RAN节点认证失败。
其中A-IOT设备生成RAN节点认证码或数据签名,本申请不作限定。但须与5GC节点生成RAN节点认证码或数据签名的方法,保持一致。
进一步地,在该A-IOT设备确定RAN节点通过认证的前提下,A-IOT设备执行以下至少一项:
响应RAN节点发送的其他命令;
向RAN节点发送A-IOT设备的数据。
本申请实施例五
本实施例中,RAN节点(接入网设备)作为读写器设备,A-IOT设备作为标签设备,本实施例是A-IOT设备和RAN节点的双向鉴权,即A-IOT设备认证RAN节点是否合法,且RAN节点认证A-IOT设备是否合法,安全功能的对等实体为A-IOT设备和RAN节点。
参见图13,本申请实施例的方法可视为实施例三和实施例一的组合,具体可参见实施例三和实施例一,不再重复描述。
其中,图13中的双向鉴权命令相参见上述实施例三和实施例一中的单向鉴权命令和请求单向鉴权命令。
本申请实施例六
本实施例中,RAN节点(接入网设备)作为读写器设备,A-IOT设备作为标签设备,本实施例是A-IOT设备和RAN节点的双向鉴权,即A-IOT设备认证RAN节点是否合法,且5GC节点认证A-IOT设备是否合法,安全功能的对等实体为A-IOT设备和5GC节点。
参见图14,本申请实施例的方法可视为实施例四和实施例二的组合,具体可参见实施例四和实施例二,不再重复描述。
其中,图14中的双向鉴权命令相参见上述实施例四和实施例二中的单向鉴权命令和请求单向鉴权命令。
本申请实施例七
本实施例中,UE(终端)作为读写器设备,A-IOT设备作为标签设备,本实施例是UE对A-IOT设备的单向鉴权,即UE认证A-IOT设备是否合法,安全功能的对等实体为A-IOT设备和UE。
请参考图15,本申请实施例的标签设备的鉴权方法包括:
步骤0a和步骤0b为可选步骤,具体方式通过以下1)或2)任一项实现:
1)运营商预先通过操作管理维护(Operation Administration Maintenance,OAM)方式给所有可信UE预配置该运营商管控的全部或部分A-IOT设备的安全参数(security credential)。对于某个特定UE,其在触发与A-IOT设备之间的空口安全鉴权流程之前,首先判断其预配置中是否存有该A-IOT设备的安全参数。
a.若该A-IOT设备的安全参数在其预配置中,则可跳过步骤0a和步骤0b,UE直接触发空口的安全鉴权流程,即UE第一步执行图15中的步骤1。
b.若接入该UE的A-IOT设备的安全参数不在其预配置中,则UE在触发空口的安全鉴权流程之前,先向5GC节点请求该A-IOT设备的安全参数,请求中携带该A-IOT设备的标识(ID)信息,5GC节点在判断UE可信的前提下,向UE响应该A-IOT设备的安全参数。即UE第一步执行步骤0a,步骤0b是否执行取决于5GC节点判断UE是否可信。该5GC节点可以是相关技术中的5GC节点(例如接入和移动性管理功能(Access and Mobility Management Function,AMF)),或者新引入的5GC功能节点,在此不做限定。
2)运营商未支持通过OAM方式给所有可信UE预配置该运营商管控的全部或部分A-IOT设备的安全参数(security credential)的情况下,对于某个特定UE,在触发空口的安全鉴权流程之前,总是先向5GC节点请求该A-IOT设备的安全参数,5GC节点在判断UE可信的前提下,向UE响应该A-IOT设备的安全参数,即UE第一步执行步骤0a,步骤0b是否执行取决于5GC节点判断UE是否可信。
其中,A-IOT设备的ID信息,可以包括以下至少一项:A-IOT设备的电子产品代码(Electronic Product code,EPC),A-IOT设备的标签分配标识符(Tag identity,TID),该标签分配标识符存储在标签信息区中。标签信息区的数据在标签芯片出产时写入,写入后不能修改)。上述ID信息与A-IOT设备的出产配置保持一致,写入后不可修改。
所述A-IOT设备的安全参数可以包括以下至少一项:根密钥(Root key,RK)索引(通过索引值唯一确定根密钥)、通信加密算法(用于指示A-IOT设备支持的数据传输加密和完整性保护算法)、密钥长度、安全模式(用于指示A-IOT设备是否需要进行安全鉴权,安全鉴权包括进行单向鉴权还是双向鉴权,单向鉴权是A-IOT设备鉴权UE还是UE
鉴权A-IOT设备、是否需要进行安全通信)、安全功能(用于指示A-IOT设备支持的安全鉴权算法,安全鉴权算法包括单向鉴权算法还是双向鉴权算法,单向鉴权算法是A-IOT设备鉴权UE使用的算法还是UE鉴权A-IOT设备使用的算法)、Tsec(UE发送安全鉴权命令或安全通信命令后,等待A-IOT设备响应的参考时间,以10ms为单位)。上述安全参数与A-IOT设备的出产配置保持一致,写入A-IOT设备后不可修改。
步骤1:UE向A-IOT设备发送单向鉴权命令(即上述实施例中的第一鉴权命令),所述单向鉴权命令用于A-IoT设备的鉴权,所述单向鉴权命令至少携带A-IOT设备的安全参数的配置信息,该配置信息遵循UE的预配置的安全参数的内容或者遵循从5GC节点获取的安全参数的配置内容(即步骤0b)。
根据步骤1,A-IOT设备通过计算确定A-IOT设备的认证码或数据签名。其中A-IOT设备生成A-IOT设备认证码或数据签名的方法,本申请不作限定。
步骤2:A-IOT设备向UE发送单向鉴权命令的响应(第一响应),所述单向鉴权命令的响应中携带:A-IOT设备的ID信息,A-IOT设备的认证码或数据签名。
根据步骤2,UE确定A-IOT设备是否通过认证,可选的,可以根据以下方法确定:
该UE通过确定A-IOT设备的认证码或数据签名,比对自己计算并生成的A-IOT设备的认证码或数据签名,与步骤2中收到的A-IOT设备的认证码或数据签名,如果两者取值相等,则判断A-IOT设备通过认证;否则,判断A-IOT设备认证失败。
其中UE计算并生成A-IOT设备的认证码或数据签名的方法,本申请不作限定。但须与A-IOT设备生成A-IOT设备认证码或数据签名的方法,保持一致。
进一步地,在该UE确定A-IOT设备通过认证的前提下,UE执行以下至少一项:向A-IOT设备发送控制命令;
接收或处理A-IOT设备的数据;
转发A-IOT设备的数据。
这里,转发数据的对象可以是一个相关技术中的5GC节点,例如用户面功能(User plane Function,UPF),或者,一个新引入的5GC功能节点,或者A-IOT App server等,在此不做限定。
本申请实施例八
本实施例中,UE(终端)作为读写器设备,A-IOT设备作为标签设备,本实施例是A-IOT设备对UE的单向鉴权,即A-IOT设备认证UE是否合法,安全功能的对等实体为A-IOT设备和UE。
请参考图16,本申请实施例的读写器设备的鉴权方法包括:
步骤0a和步骤0b同实施例七,不再重复描述。
步骤1:UE向A-IOT设备发送请求单向鉴权命令(第二鉴权命令),所述请求单向鉴权命令用于RAN节点的鉴权,所述请求单向鉴权命令至少携带A-IOT设备的安全参数的配置信息,UE的认证码或数字签名,计算UE的认证码或数字签名的第二输入参数(如
UE ID,认证码或数据签名传输对应的时间信息、频域信息或波束信息中的至少一项)
在步骤1之前,UE计算并生成UE的认证码或数据签名。其中UE生成UE设备认证码或数据签名的方法,本申请不作限定。
根据步骤1,A-IOT设备确定UE是否通过认证。可选的,可以通过以下方法确定:该A-IOT设备自己计算并生成UE的认证码或数据签名,比对自己计算并生成UE的认证码或数据签名,与步骤1中收到的UE的认证码或数据签名,如果两者取值相等,则判断UE通过认证;否则,判断UE认证失败。
步骤2:A-IOT设备向UE发送请求单向鉴权命令的响应,所述请求单向鉴权命令的响应至少携带UE是否通过认证的鉴权结果。
其中A-IOT设备计算并生成UE的认证码或数据签名的方法,本申请不作限定。但须与UE生成UE认证码或数据签名的方法,保持一致。
进一步地,在A-IOT设备确定该UE通过认证的前提下,A-IOT设备执行以下至少一项:响应UE发送的其他命令;向UE发送A-IOT设备的数据。
本申请实施例九
本实施例中,UE(终端)作为读写器设备,A-IOT设备作为标签设备,本实施例是A-IOT设备和UE的双向鉴权,即A-IOT设备认证UE是否合法,且UE认证A-IOT设备是否合法,安全功能的对等实体为A-IOT设备和UE。
请参考图17,本申请实施例的方法可视为实施例八和实施例七的组合,具体可参见实施例八和实施例七,不再重复描述。
其中,图17中的双向鉴权命令相参见上述实施例八和实施例七中的单向鉴权命令和请求单向鉴权命令。
本申请实施例提供的标签设备的鉴权方法,执行主体可以为标签设备的鉴权装置。本申请实施例中以标签设备的鉴权装置执行标签设备的鉴权方法为例,说明本申请实施例提供的标签设备的鉴权装置。
请参考图18,本申请实施例还提供一种标签设备的鉴权装置180,包括:
第一发送模块181,用于发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述标签设备的鉴权装置180为接入网设备、终端或核心网设备;
第一接收模块182,用于接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
第一确定模块183,用于根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
在本申请实施例中,明确了在3GPP系统中如何认证标签设备的流程,以使得读写器设备(终端或接入网设备)和标签设备之间的信息传输工作在安全模式。
可选的,当所述标签设备的鉴权装置180为接入网设备或终端时,所述安全参数存储
于所述标签设备的鉴权装置180中,或者,所述安全参数由所述标签设备的鉴权装置180从核心网设备获取。
可选的,所述标签设备的鉴权装置180为接入网设备或终端;
所述第一发送模块181,用于在所述标签设备的鉴权装置180有所述标签设备的安全参数的情况下,发送第一鉴权命令。
可选的,所述标签设备的鉴权装置180为接入网设备或终端;所述标签设备的鉴权装置180还包括:
发送模块,用于向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息;或者,在没有所述标签设备的安全参数的情况下,向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息;
接收模块,用于接收来自所述核心网设备的所述安全参数。
可选的,所述标签设备的鉴权装置180为核心网设备;
所述第一发送模块181,用于通过接入网设备向所述标签设备发送所述第一鉴权命令;
所述第一接收模块182,用于接收接入网设备转发的所述第一响应;
或者
所述标签设备的鉴权装置180为所述标签设备的源服务小区所在的接入网设备;
所述第一发送模块181,用于通过所述标签设备的目的服务小区所在的接入网设备向所述标签设备发送所述第一鉴权命令,其中,所述标签设备的目的服务小区所在的接入网设备转发所述第一鉴权命令;
所述第一接收模块182,用于接收所述标签设备的目的服务小区所在的接入网设备转发的所述第一响应。
可选的,所述第一确定模块183,用于根据所述标签设备的安全参数的配置信息和用于计算所述标签设备的第一认证信息的第一输入参数,通过计算确定所述标签设备的第二认证信息;比较所述第二认证信息和接收到的所述标签设备的第一认证信息是否相同;若所述第二认证信息和所述第一认证信息相同,确定所述标签设备通过认证;若所述第二认证信息和所述第一认证信息不同,确定所述标签设备未通过认证。
可选的,所述标签设备的鉴权装置180为核心网设备时,还包括:
第二接收模块,用于接收所述标签设备的服务小区所在的接入网设备发送的所述第一输入参数。
可选的,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
可选的,所述标签设备的鉴权装置180为接入网设备或者终端,还包括:
执行模块,用于若所述标签设备通过认证,执行以下至少一项:
向所述标签设备发送控制命令;
接收所述标签设备发送的数据;
处理所述标签设备发送的数据;
转发所述标签设备发送的数据。
可选的,所述标签设备的鉴权装置180为核心网设备,还包括以下至少一项:
第二发送模块,用于向接入网设备或终端发送所述标签设备是否通过认证的鉴权结果;
第三发送模块,用于向接入网设备或终端发送所述标签设备的授权信息,所述授权信息在所述标签设备通过认证的情况下发送。
本申请实施例中的标签设备的鉴权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的标签设备的鉴权装置能够实现图4的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
请参考图19,本申请实施例还提供一种标签设备的鉴权装置190,包括:
第一接收模块191,用于接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;
第一发送模块192,用于根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
在本申请实施例中,明确了在3GPP系统中如何认证标签设备的流程,,以使得读写器设备(接入网设备或终端)和标签设备之间的信息传输工作在安全模式。
可选的,当所述第一设备为接入网设备或终端时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获取。
可选的,所述第一发送模块192,用于根据所述安全参数的配置信息和用于计算所述标签设备的第一认证信息的第一输入参数,通过计算确定所述标签设备的第一认证信息;向所述第一设备发送所述第一响应,所述第一响应中包括所述第一认证信息。
可选的,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
本申请实施例提供的标签设备的鉴权装置能够实现图5的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例提供的读写器设备的鉴权方法,执行主体可以为读写器设备的鉴权装置。
本申请实施例中以读写器设备的鉴权装置执行读写器设备的鉴权方法为例,说明本申请实施例提供的读写器设备的鉴权装置。
请参考图20,本申请实施例还提供一种读写器设备的鉴权装置200,包括:
第一发送模块201,用于发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述读写器设备的鉴权装置200为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
第一接收模块202,用于接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
在本申请实施例中,明确了在3GPP系统中标签设备如何认证作为读写器设备的UE或RAN的流程,以使得读写器设备和标签设备之间的信息传输工作在安全模式。
可选的,当所述第一设备为所述读写器设备时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获取
可选的,所述读写器设备的鉴权装置200还包括:
第一确定模块,用于确定所述读写器设备的第三认证信息。
可选的,所述读写器设备的鉴权装置200为所述读写器设备,还包括:
第二发送模块,用于向核心网设备发送用于获取安全参数的第一请求;
或者,
第三发送模块,用于在所述第一设备没有所述标签设备的安全参数的情况下,向核心网设备发送用于获取安全参数的第一请求;其中,所述第一请求中包括所述标签设备的标识信息。
可选的,所述读写器设备的鉴权装置200为所述读写器设备,还包括:
第四发送模块,用于向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息和用于计算所述读写器设备的第三认证信息的第二输入参数;
第二接收模块,用于接收所述核心网设备发送的所述标签设备的安全参数和所述读写器设备的第三认证信息;
或者,
第五发送模块,用于在有所述标签设备的安全参数的情况下,向核心网设备发送第二请求;所述第一设备接收所述核心网设备发送的所述读写器设备的第三认证信息;
第六发送模块,用于在没有所述标签设备的安全参数的情况下,向核心网设备发送用于获取安全参数的第一请求;所述第一设备接收所述核心网设备发送的所述标签设备的安全参数和所述读写器设备的第三认证信息;
其中,所述第一请求中包括所述标签设备的标识信息和用于计算所述读写器设备的第三认证信息的第二输入参数,所述第二请求中包括用于计算所述读写器设备的第三认证信
息的第二输入参数。
可选的,所述第二输入参数包括以下至少一项:所述第一设备的标识信息,所述第三认证信息传输对应的时间信息,所述第三认证信息传输对应的频域资源信息,所述第三认证信息传输对应的波束信息。
可选的,所述读写器设备的鉴权装置200为核心网设备;
所述第一发送模块201,用于向通过接入网设备向所述标签设备发送所述第二鉴权命令;
所述第一接收模块202,用于接收由所述接入网设备转发的所述第二响应。
可选的,所述读写器设备的鉴权装置200还包括:
第七发送模块,用于发送第一鉴权命令,所述第一鉴权命令用于对标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;
第三接收模块,用于接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
第二确定模块,用于根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
本申请实施例中的读写器设备的鉴权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的读写器设备的鉴权装置能够实现图6的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
请参考图21,本申请实施例还提供一种读写器设备的鉴权装置210,包括:
第一接收模块211,用于接收第一设备发送的第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括所述标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;
第一确定模块212,用于根据所述第二鉴权命令,确定所述读写器设备是否通过认证。
在本申请实施例中,明确了在3GPP系统中标签设备如何认证作为读写器设备的UE或RAN的流程,以使得读写器设备和标签设备之间的信息传输工作在安全模式。
可选的,当所述第一设备为所述读写器设备时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获取。
可选的,所述第一确定模块212,用于根据所述标签设备的安全参数的配置信息和用于计算所述读写器设备的第三认证信息的第二输入参数,通过计算确定所述读写器设备的第四认证信息;比较所述第四认证信息和接收到的所述读写器设备的第三认证信息是否
相同;若所述第四认证信息和所述第三认证信息相同,确定所述读写器设备通过认证;若所述第四认证信息和所述第三认证信息不同,确定所述读写器设备未通过认证。
可选的,所述第二输入参数包括以下至少一项:所述第一设备的标识信息,所述第三认证信息传输对应的时间信息,所述第三认证信息传输对应的频域资源信息,所述第三认证信息传输对应的波束信息。
可选的,所述读写器设备的鉴权装置210还包括:
执行模块,用于若所述读写器设备通过认证,执行以下至少一项:
向所述第一设备发送第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果;
响应所述读写器设备发送的控制命令;
向所述读写器设备发送数据。
可选的,所述读写器设备的鉴权装置210还包括:
第二接收模块,用于接收所述第一设备发送的第一鉴权命令,所述第一鉴权命令用于对所述标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;
第二确定模块,用于根据所述第一鉴权命令,确定所述标签设备的第一认证信息;
发送模块,用于向所述第一设备发送第一响应,所述第一响应中包括:所述标签设备的第一认证信息。
可选的,所述读写器设备的鉴权装置210还包括:
丢弃模块,用于若所述读写器设备未通过认证,丢弃所述第一设备发送的第一鉴权命令,所述第一鉴权命令用于对所述标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息。
本申请实施例提供的读写器设备的鉴权装置能够实现图7的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例提供的安全鉴权方法,执行主体可以为安全鉴权装置。本申请实施例中以安全鉴权装置执行安全鉴权方法为例,说明本申请实施例提供的安全鉴权装置。
请参考图22,本申请实施例还提供一种安全鉴权装置220,包括:
第一接收模块221,用于接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;
第一发送模块222,用于向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息,其中,所述第三认证信息由所述核心网设备根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
本申请实施例中,作为读写器设备的接入网设备或终端在对标签设备进行鉴权之前,或者,请求标签设备对所述读写器设备进行鉴权之前,可以向核心网设备获取标签设备的安全参数和/或请求核心网设备确定读写器设备的认证信息,核心网设备验证读写器设备
可信的情况下,再向读写器设备发送所述标签设备的安全参数和/或读写器设备的认证信息,从而保证参与鉴权的接入网设备或终端是可信的设备。
可选的,所述第一发送模块,用于在判断所述读写器设备可信的情况下,向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息。
本申请实施例中的安全鉴权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。
本申请实施例提供的安全鉴权装置能够实现图8的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
如图23所示,本申请实施例还提供一种通信设备230,包括处理器231和存储器232,存储器232上存储有可在所述处理器231上运行的程序或指令,例如,该通信设备230为第一设备时,该程序或指令被处理器231执行时实现上述第一设备执行的方法实施例的各个步骤,且能达到相同的技术效果。该通信设备230为标签设备时,该程序或指令被处理器231执行时实现上述标签设备执行的方法实施例的各个步骤,且能达到相同的技术效果。该通信设备230为核心网设备时,该程序或指令被处理器231执行时实现上述核心网设备执行的方法实施例的各个步骤,且能达到相同的技术效果。为避免重复,这里不再赘述。
本申请实施例还提供一种终端,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如图4或图6所示方法实施例中的步骤。该终端实施例与上述第一设备侧执行的方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该终端实施例中,且能达到相同的技术效果。具体地,图24为实现本申请实施例的一种终端的硬件结构示意图。
该终端240包括但不限于:射频单元241、网络模块242、音频输出单元243、输入单元244、传感器245、显示单元246、用户输入单元247、接口单元248、存储器249以及处理器2410等中的至少部分部件。
本领域技术人员可以理解,终端240还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器2410逻辑相连,从而通过电源管理系统实现管理充电、放电以及功耗管理等功能。图24中示出的终端结构并不构成对终端的限定,终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。
应理解的是,本申请实施例中,输入单元244可以包括图形处理器(Graphics Processing Unit,GPU)2441和麦克风2442,图形处理器2441对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元246可包括显示面板2461,可以采用液晶显示器、有机发光二极管等形式来配置显示面板2461。用户输入单元247包括触控面板2471以及其他输入设备2472中的至少一种。触控面板2471,也称为触摸屏。触控面板2471可包括触摸检测装置和触摸控制器两个部分。其他输入设备2472可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、
轨迹球、鼠标、操作杆,在此不再赘述。
本申请实施例中,射频单元241接收来自网络侧设备的下行数据后,可以传输给处理器2410进行处理;另外,射频单元241可以向网络侧设备发送上行数据。通常,射频单元241包括但不限于天线、放大器、收发信机、耦合器、低噪声放大器、双工器等。
存储器249可用于存储软件程序或指令以及各种数据。存储器249可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器249可以包括易失性存储器或非易失性存储器。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器249包括但不限于这些和任意其它适合类型的存储器。
处理器2410可包括一个或多个处理单元;可选的,处理器2410集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器2410中。
其中,在一个实施例中,射频单元241,用于发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;
处理器2410,用于根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
在本申请实施例中,明确了在3GPP系统中如何认证标签设备的流程,以使得读写器设备(终端或接入网设备)和标签设备之间的信息传输工作在安全模式。
可以理解,本实施例中提及的各实现方式的实现过程可以参照方法实施例4的相关描述,并达到相同或相应的技术效果,为避免重复,在此不再赘述。
或者,在另一个实施例中,射频单元241,用于发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
在本申请实施例中,明确了在3GPP系统中标签设备如何认证作为读写器设备的UE或RAN的流程,以使得读写器设备和标签设备之间的信息传输工作在安全模式。
可以理解,本实施例中提及的各实现方式的实现过程可以参照方法实施例6的相关描述,并达到相同或相应的技术效果,为避免重复,在此不再赘述。
本申请实施例还提供一种网络侧设备,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如图4或图6所示的方法实施例的步骤。该网络侧设备实施例与上述第一设备侧方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该网络侧设备实施例中,且能达到相同的技术效果。
具体地,本申请实施例还提供了一种网络侧设备。如图25所示,该网络侧设备2500包括:天线251、射频装置252、基带装置253、处理器254和存储器255。天线251与射频装置252连接。在上行方向上,射频装置252通过天线251接收信息,将接收的信息发送给基带装置253进行处理。在下行方向上,基带装置253对要发送的信息进行处理,并发送给射频装置252,射频装置252对收到的信息进行处理后经过天线251发送出去。
以上实施例中网络侧设备执行的方法可以在基带装置253中实现,该基带装置253包括基带处理器。
基带装置253例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图25所示,其中一个芯片例如为基带处理器,通过总线接口与存储器255连接,以调用存储器255中的程序,执行以上方法实施例中所示的网络设备操作。
该网络侧设备还可以包括网络接口256,该接口例如为通用公共无线接口(Common Public Radio Interface,CPRI)。
具体地,本申请实施例的网络侧设备2500还包括:存储在存储器255上并可在处理器254上运行的指令或程序,处理器254调用存储器255中的指令或程序执行图18或图20所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
具体地,本申请实施例还提供了一种网络侧设备。如图26所示,该网络侧设备260包括:处理器261、网络接口262和存储器263。其中,网络接口262例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本申请实施例的网络侧设备260还包括:存储在存储器263上并可在处理器261上运行的指令或程序,处理器261调用存储器263中的指令或程序执行图18或图20或图22所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。在一些示例中,可读存储介质可以是非瞬态的可读存储介质。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种无线通信系统,包括:第一设备和标签设备,所述第一设备可用于执行如上述第一设备侧执行的所述的方法的步骤,所述标签设备可用于执行如上述标签设备侧执行的所述的方法的步骤。
本申请实施例还提供了一种无线通信系统,包括:第一设备、标签设备和核心网设备,所述第一设备可用于执行如上述第一设备侧所述的方法的步骤,所述标签设备可用于执行如上述标签设备侧所述的方法的步骤,所述核心网设备可用于执行如上述核心网设备侧所述的方法的步骤。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助计算机软件产品加必需的通用硬件平台的方式来实现,当然也可以通过硬件。该计算机软件产品存储在存储介质(如ROM、RAM、磁碟、光盘等)中,包括若干指令,用以使得终端或者网络侧设备执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式的实施方式,这些实施方式均属于本申请的保护之内。
Claims (38)
- 一种标签设备的鉴权方法,包括:第一设备发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述第一设备为接入网设备、终端或核心网设备;所述第一设备接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
- 根据权利要求1所述的方法,其中,当所述第一设备为接入网设备或终端时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获取。
- 根据权利要求1所述的方法,其中,所述第一设备为接入网设备或终端;所述第一设备发送第一鉴权命令,包括:在所述第一设备有所述标签设备的安全参数的情况下,所述第一设备发送第一鉴权命令。
- 根据权利要求1所述的方法,其中,所述第一设备为接入网设备或终端;在所述第一设备发送第一鉴权命令之前,还包括:所述第一设备向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息;或者,在所述第一设备没有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送用于获取安全参数的第一请求,其中,所述第一请求中包括所述标签设备的标识信息;所述第一设备接收来自所述核心网设备的所述安全参数。
- 根据权利要求1所述的方法,其中,所述第一设备为核心网设备;所述第一设备发送第一鉴权命令包括:所述第一设备通过接入网设备向所述标签设备发送所述第一鉴权命令;所述第一设备接收第一响应包括:所述第一设备接收接入网设备转发的所述第一响应;或者所述第一设备为所述标签设备的源服务小区所在的接入网设备;所述第一设备发送第一鉴权命令包括:所述第一设备通过所述标签设备的目的服务小区所在的接入网设备向所述标签设备发送所述第一鉴权命令,其中,所述标签设备的目的服务小区所在的接入网设备转发所述第一鉴权命令;所述第一设备接收第一响应包括:所述第一设备接收所述标签设备的目的服务小区所在的接入网设备转发的所述第一响应。
- 根据权利要求1所述的方法,其中,所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证,包括:所述第一设备根据所述标签设备的安全参数的配置信息和用于计算所述标签设备的第一认证信息的第一输入参数,通过计算确定所述标签设备的第二认证信息;所述第一设备比较所述第二认证信息和接收到的所述标签设备的第一认证信息是否相同;若所述第二认证信息和所述第一认证信息相同,确定所述标签设备通过认证;若所述第二认证信息和所述第一认证信息不同,确定所述标签设备未通过认证。
- 根据权利要求6所述的方法,其中,当所述第一设备为核心网设备时,所述第一设备根据第一输入参数以及所述标签设备的安全参数的配置信息,通过计算确定所述标签设备的第一认证信息之前还包括:所述第一设备接收所述标签设备的服务小区所在的接入网设备发送的所述第一输入参数。
- 根据权利要求6或7所述的方法,其中,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
- 根据权利要求1或6所述的方法,其中,所述第一设备为接入网设备或者终端,所述确定所述标签设备是否通过认证之后还包括:若所述标签设备通过认证,所述第一设备执行以下至少一项:向所述标签设备发送控制命令;接收所述标签设备发送的数据;处理所述标签设备发送的数据;转发所述标签设备发送的数据。
- 根据权利要求1或6所述的方法,其中,所述第一设备为核心网设备,所述确定所述标签设备是否通过认证之后还包括以下至少一项:所述第一设备向接入网设备或终端发送所述标签设备是否通过认证的鉴权结果;所述第一设备向接入网设备或终端发送所述标签设备的授权信息,所述授权信息在所述标签设备通过认证的情况下发送。
- 一种标签设备的鉴权方法,包括:标签设备接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;所述标签设备根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
- 根据权利要求11所述的方法,其中,当所述第一设备为接入网设备或终端时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获 取。
- 根据权利要求11所述的方法,其中,所述标签设备根据所述第一鉴权命令,向所述第一设备发送第一响应,包括:所述标签设备根据所述安全参数的配置信息和用于计算所述标签设备的第一认证信息的第一输入参数,通过计算确定所述标签设备的第一认证信息;所述标签设备向所述第一设备发送所述第一响应,所述第一响应中包括所述第一认证信息。
- 根据权利要求13所述的方法,其中,所述第一输入参数包括以下至少一项:所述标签设备的标识信息,所述标签设备的服务小区的标识信息,所述标签设备的上下文标识,所述第一认证信息传输对应的时间信息,所述第一认证信息传输对应的频域资源信息,所述第一认证信息传输对应的波束信息。
- 一种读写器设备的鉴权方法,包括:第一设备发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;所述第一设备接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
- 根据权利要求15所述的方法,其中,当所述第一设备为所述读写器设备时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获取。
- 根据权利要求15或16所述的方法,其中,所述第一设备发送第二鉴权命令之前还包括:所述第一设备确定所述读写器设备的第三认证信息。
- 根据权利要求15或16所述的方法,其中,所述第一设备为所述读写器设备,所述第一设备发送第二鉴权命令之前还包括:所述第一设备向核心网设备发送用于获取安全参数的第一请求;或者,在所述第一设备没有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送用于获取安全参数的第一请求;其中,所述第一请求中包括所述标签设备的标识信息。
- 根据权利要求15或16所述的方法,其中,所述第一设备为读写器设备,所述第一设备发送第二鉴权命令之前还包括:所述第一设备向核心网设备发送用于获取安全参数的第一请求,所述第一请求中包括所述标签设备的标识信息和用于计算所述读写器设备的第三认证信息的第二输入参数;所述第一设备接收所述核心网设备发送的所述标签设备的安全参数和所述读写器设备的第三认证信息;或者,在所述第一设备有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送第二请求;所述第一设备接收所述核心网设备发送的所述读写器设备的第三认证信息;在所述第一设备没有所述标签设备的安全参数的情况下,所述第一设备向核心网设备发送用于获取安全参数的第一请求;所述第一设备接收所述核心网设备发送的所述标签设备的安全参数和所述读写器设备的第三认证信息;其中,所述第一请求中包括所述标签设备的标识信息和用于计算所述读写器设备的第三认证信息的第二输入参数,所述第二请求中包括用于计算所述读写器设备的第三认证信息的第二输入参数。
- 根据权利要求19所述的方法,其中,所述第二输入参数包括以下至少一项:所述第一设备的标识信息,所述第三认证信息传输对应的时间信息,所述第三认证信息传输对应的频域资源信息,所述第三认证信息传输对应的波束信息。
- 根据权利要求15所述的方法,其中,所述第一设备为核心网设备;所述第一设备发送第二鉴权命令包括:所述第一设备向通过接入网设备向所述标签设备发送所述第二鉴权命令;所述第一设备接收第二响应包括:所述第一设备接收由所述接入网设备转发的所述第二响应。
- 根据权利要求15所述的方法,其中,所述第一设备接收第二响应之后还包括:所述第一设备发送第一鉴权命令,所述第一鉴权命令用于对标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;所述第一设备根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
- 一种读写器设备的鉴权方法,包括:标签设备接收第一设备发送的第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括所述标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证。
- 根据权利要求23所述的方法,其中,当所述第一设备为所述读写器设备时,所述安全参数存储于所述第一设备中,或者,所述安全参数由所述第一设备从核心网设备获取。
- 根据权利要求23所述的方法,其中,所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证,包括:所述标签设备根据所述标签设备的安全参数的配置信息和用于计算所述读写器设备 的第三认证信息的第二输入参数,通过计算确定所述读写器设备的第四认证信息;所述标签设备比较所述第四认证信息和接收到的所述读写器设备的第三认证信息是否相同;若所述第四认证信息和所述第三认证信息相同,确定所述读写器设备通过认证;若所述第四认证信息和所述第三认证信息不同,确定所述读写器设备未通过认证。
- 根据权利要求25所述的方法,其中,所述第二输入参数包括以下至少一项:所述第一设备的标识信息,所述第三认证信息传输对应的时间信息,所述第三认证信息传输对应的频域资源信息,所述第三认证信息传输对应的波束信息。
- 根据权利要求23所述的方法,其中,所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证之后还包括:若所述读写器设备通过认证,所述标签设备执行以下至少一项:向所述第一设备发送第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果;响应所述读写器设备发送的控制命令;向所述读写器设备发送数据。
- 根据权利要求23所述的方法,其中,所述标签设备接收第一设备发送的第二鉴权命令之后还包括:所述标签设备接收所述第一设备发送的第一鉴权命令,所述第一鉴权命令用于对所述标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述标签设备根据所述第一鉴权命令,确定所述标签设备的第一认证信息;所述标签设备向所述第一设备发送第一响应,所述第一响应中包括:所述标签设备的第一认证信息。
- 根据权利要求23所述的方法,其中,所述标签设备根据所述第二鉴权命令,确定所述读写器设备是否通过认证之后还包括:若所述读写器设备未通过认证,所述标签设备丢弃所述第一设备发送的第一鉴权命令,所述第一鉴权命令用于对所述标签设备进行认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息。
- 一种安全鉴权方法,包括:核心网设备接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;所述核心网设备向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息,其中,所述第三认证信息由所述核心网设备根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
- 根据权利要求30所述的方法,其中,所述核心网设备向所述读写器设备发送所述 标签设备的安全参数和/或所述读写器设备的第三认证信息包括:所述核心网设备在判断所述读写器设备可信的情况,向所述读写器设备发送所述标签设备的安全参数和/或所述读写器设备的第三认证信息。
- 一种标签设备的鉴权装置,包括:第一发送模块,用于发送第一鉴权命令,所述第一鉴权命令用于标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;其中,所述标签设备的鉴权装置为接入网设备、终端或核心网设备;第一接收模块,用于接收第一响应,所述第一响应中包括:所述标签设备的第一认证信息;第一确定模块,用于根据所述安全参数的配置信息和所述标签设备的第一认证信息,确定所述标签设备是否通过认证。
- 一种标签设备的鉴权装置,包括:第一接收模块,用于接收第一设备发送的第一鉴权命令,所述第一鉴权命令用于所述标签设备的认证,所述第一鉴权命令中包括所述标签设备的安全参数的配置信息;所述第一设备为接入网设备、终端或核心网设备;第一发送模块,用于根据所述第一鉴权命令,向所述第一设备发送第一响应,所述第一响应中包括所述标签设备的第一认证信息。
- 一种读写器设备的鉴权装置,包括:第一发送模块,用于发送第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述读写器设备的鉴权装置为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;第一接收模块,用于接收第二响应,所述第二响应中包括:所述读写器设备通过认证或者未通过认证的鉴权结果。
- 一种读写器设备的鉴权装置,包括:第一接收模块,用于接收第一设备发送的第二鉴权命令,所述第二鉴权命令用于读写器设备的认证,所述第二鉴权命令中包括标签设备的安全参数的配置信息和所述读写器设备的第三认证信息;其中,所述第一设备为所述读写器设备或核心网设备,所述读写器设备为接入网设备或终端;第一确定模块,用于根据所述第二鉴权命令,确定所述读写器设备是否通过认证。
- 一种安全鉴权装置,包括:第一接收模块,用于接收读写器设备发送的请求,所述请求中包括标签设备的标识信息和/或用于计算所述读写器设备的认证信息的第二输入参数;所述读写器设备为接入网设备或终端;第一发送模块,用于在向所述读写器设备发送所述标签设备的安全参数和/或所述读 写器设备的第三认证信息,其中,所述第三认证信息根据所述标签设备的安全参数和所述第二输入参数通过计算确定。
- 一种通信设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至10任一项所述的标签设备的鉴权方法的步骤,或者,所述程序或指令被所述处理器执行时实现如权利要求11至14任一项所述的标签设备的鉴权方法的步骤,或者,所述程序或指令被所述处理器执行时实现如权利要求15至22任一项所述的读写器设备的鉴权方法的步骤,或者,所述程序或指令被所述处理器执行时实现如权利要求23至29任一项所述的读写器设备的鉴权方法的步骤,或者,所述程序或指令被所述处理器执行时实现如权利要求30至31任一项所述的安全鉴权方法的步骤。
- 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至10任一项所述的标签设备的鉴权方法的步骤,或者,实现如权利要求11至14任一项所述的标签设备的鉴权方法的步骤,或者,实现如权利要求15至22任一项所述的读写器设备的鉴权方法的步骤,或者,实现如权利要求23至29任一项所述的读写器设备的鉴权方法的步骤,或者,实现如权利要求30至31任一项所述的安全鉴权方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202310350033.8A CN118741509A (zh) | 2023-03-31 | 2023-03-31 | 鉴权方法、鉴权装置、通信设备及可读存储介质 |
| CN202310350033.8 | 2023-03-31 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024199161A1 true WO2024199161A1 (zh) | 2024-10-03 |
Family
ID=92862913
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/083454 Ceased WO2024199161A1 (zh) | 2023-03-31 | 2024-03-25 | 鉴权方法、鉴权装置、通信设备及可读存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN118741509A (zh) |
| WO (1) | WO2024199161A1 (zh) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114025352A (zh) * | 2020-07-17 | 2022-02-08 | 华为技术有限公司 | 终端设备的鉴权方法及其装置 |
| WO2022142446A1 (zh) * | 2020-12-31 | 2022-07-07 | 华为技术有限公司 | 一种鉴权方法及通信装置 |
-
2023
- 2023-03-31 CN CN202310350033.8A patent/CN118741509A/zh active Pending
-
2024
- 2024-03-25 WO PCT/CN2024/083454 patent/WO2024199161A1/zh not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114025352A (zh) * | 2020-07-17 | 2022-02-08 | 华为技术有限公司 | 终端设备的鉴权方法及其装置 |
| WO2022142446A1 (zh) * | 2020-12-31 | 2022-07-07 | 华为技术有限公司 | 一种鉴权方法及通信装置 |
Non-Patent Citations (1)
| Title |
|---|
| NOKIA: "Ambient IoT Security Considerations", 3GPP TSG-RAN #99, RP-230056, no. RP-230056, 10 March 2023 (2023-03-10), pages 1 - 3, XP009557804 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN118741509A (zh) | 2024-10-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20250317733A1 (en) | Method for managing reader/writer, terminal, and network side device | |
| US12254118B2 (en) | Electronic device for performing edge computing service, and operating method of electronic device | |
| CN113037741A (zh) | 一种鉴权方法和相关装置 | |
| WO2023143418A1 (zh) | 设备鉴权方法、装置、终端及网络功能 | |
| WO2024093783A1 (zh) | 操作执行方法、装置、终端及网络功能 | |
| WO2024149103A1 (zh) | 一种盘点处理方法、装置及设备 | |
| CN116567778B (zh) | Pin的组建方法及设备 | |
| CN116567626B (zh) | 设备鉴权方法、装置及通信设备 | |
| WO2024199161A1 (zh) | 鉴权方法、鉴权装置、通信设备及可读存储介质 | |
| WO2024169807A1 (zh) | 信号发送、信号接收方法、装置、终端及网络侧设备 | |
| WO2024067436A1 (zh) | 信息传输方法、装置及设备 | |
| CN114173336B (zh) | 鉴权失败的处理方法、装置、终端及网络侧设备 | |
| CN116567777B (zh) | 接入参数使用方法、终端及网络侧 | |
| WO2025209362A1 (zh) | 通信方法、装置、设备及存储介质 | |
| US20240106643A1 (en) | Processing method and obtaining method for key material, information transmission method, and device | |
| WO2025055786A1 (zh) | 认证处理方法、装置、终端及网络侧设备 | |
| WO2025026363A1 (zh) | 物联网设备控制方法、装置、通信设备及可读存储介质 | |
| US20240114016A1 (en) | Key material sending method, key material obtaining method, information transmission method, and device | |
| WO2025209292A1 (zh) | 信息上报方法、信息处理方法、装置及设备 | |
| WO2024222602A1 (zh) | 物联网设备凭证信息的处理方法、装置及相关设备 | |
| WO2025209295A1 (zh) | 通信处理方法、装置、设备及可读存储介质 | |
| CN120456027A (zh) | 无线通信方法、装置、设备及存储介质 | |
| WO2025185705A1 (zh) | 标识指示方法、装置、终端设备及第一网络节点 | |
| WO2025167831A1 (zh) | 频域位置确定方法、装置、终端及可读存储介质 | |
| EP4732566A1 (en) | Pure authentication and key management for applications (akma) based two-factor authentication |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24777950 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |