Management of environmental internet of things devices in mobile communication network

By introducing collaborative management of reader devices, mobile network entities and network nodes in the 5G NR network, the registration, handover and mobility management problems of A-IoT devices in the mobile communication network are solved, and the security authentication and mobility support of devices are realized, improving the management efficiency and flexibility of the network.

CN120530657APending Publication Date: 2025-08-22QUALCOMM INC
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202380092621.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-03
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The existing 5G NR technology has challenges in managing environmental Internet of Things (A-IoT) devices, especially in mobile communication networks, especially under the control of 5G core networks, where A-IoT devices have a lack of effective solutions.

Method used

A method and device are provided to realize registration, authentication, switching and mobility management of A-IoT devices through the collaborative work of reader devices, mobile network entities and network nodes, including response to query commands, assignment of tag identifiers, delivery of temporary identifiers and management of reader lists, and optimize the signaling process to support initial access and connection establishment of A-IoT devices.

Benefits of technology

It realizes effective management of A-IoT devices in mobile communication networks, ensures safe authentication and mobility of devices, supports smooth switching between different readers, and improves network flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120530657A_ABST
    Figure CN120530657A_ABST
Patent Text Reader

Abstract

An apparatus, such as an environmental Internet of Things (A-IoT) device, configured to support registration and management in a mobile communication network (e.g., a cellular communication network) is provided. The apparatus receives a query command, sends a first message including at least a mobile network assigned tag identifier or an unregistered tag indicator in response to the query command, and receives a second message including at least a temporary identifier, a reader identifier or an authorized reader list for communication with a network node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to communication systems, and more particularly, to management of Ambient Internet of Things (A-IoT) devices in mobile communication networks. Background Art

[0002] Wireless communication systems are widely deployed to provide a variety of telecommunication services, such as telephony, video, data, messaging, and broadcasts. Typical wireless communication systems employ multiple-access technologies capable of supporting communication with multiple users by sharing available system resources. Examples of such multiple-access technologies include code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal frequency division multiple access (OFDMA), single-carrier frequency division multiple access (SC-FDMA), and time division synchronous code division multiple access (TD-SCDMA).

[0003] These multiple-access technologies have been adopted in various telecommunication standards to provide a common protocol that enables different wireless devices to communicate at the city, national, regional, and even global levels. An example telecommunication standard is 5G New Radio (NR). 5G NR is part of the continued evolution of mobile broadband, promulgated by the 3rd Generation Partnership Project (3GPP) to meet new requirements associated with latency, reliability, security, scalability (e.g., for the Internet of Things (IoT)), and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine-type communications (mMTC), and ultra-reliable low-latency communications (URLLC). Certain aspects of 5G NR may be based on the 4G Long Term Evolution (LTE) standard. Further improvements to 5G NR technology are needed. In addition, these improvements may also be applicable to other multiple-access technologies and telecommunication standards that adopt these technologies. Summary of the Invention

[0004] The following presents a simplified summary of one or more aspects in order to provide a basic understanding of these aspects. This summary is not an extensive overview of all contemplated aspects and is neither intended to identify key or critical elements of all aspects nor to delineate the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that will be presented later.

[0005] Various aspects described herein enable deployment of Ambient Internet of Things (A-IoT) devices in a mobile communication network (e.g., a cellular communication network, such as a 5G NR network). For example, the A-IoT devices described herein may support registration and management in a mobile communication network through a reader device (also referred to herein as a reader) and a radio access network (RAN) under the control of a core network (CN) (e.g., a 5G CN) in one or more A-IoT device deployment scenarios. In some use cases, reader device handover and / or A-IoT device mobility are considered. Examples of A-IoT device deployment scenarios may include warehouse inventory management, sensor network (smart grid) applications, automotive manufacturing, personal item positioning, smart home applications, and / or other suitable deployment scenarios.

[0006] Various aspects described herein may enable management of A-IoT devices in a mobile communication network, including: establishing A-IoT device security for network authentication, registering an A-IoT device at the mobile communication network, initial association of an A-IoT device to a valid reader, management of an A-IoT device to switch associations between different readers (e.g., reader handoff), and A-IoT device mobility across different readers.

[0007] Various aspects described herein include initial access and connection establishment for A-IoT devices and corresponding signaling design. Aspects described herein also include different types of tag IDs for A-IoT devices, tag authentication processes, different A-IoT states, reader switching with and without network-involved signaling, and process optimizations such as group-based query commands and association requests, and tag context broadcasting.

[0008] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be an A-IoT device. The apparatus receives a query command, transmits a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command, and receives a second message including at least a temporary identifier for communicating with a network node, a reader identifier, or an authorized reader list.

[0009] In one aspect of the present disclosure, a method, computer-readable medium, and apparatus are provided. The apparatus may be a mobile network entity, such as a core network device (also referred to as a core network entity). The apparatus receives a request to initiate context establishment for a tag device in a mobile network, performs an authentication operation for the tag device, assigns a tag identifier to the tag device based on the authentication operation, and sends a context establishment message including at least the tag identifier.

[0010] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a reader device. The apparatus sends a query command, receives a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command, and sends a second message including at least a temporary identifier for communicating with a network node, a reader identifier, or an authorized reader list.

[0011] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a network node. The apparatus receives a radio resource control establishment request for a tag device, sends a request for initiating context establishment for the tag device, wherein the request includes at least a tag identifier assigned by a mobile network or an unregistered tag indicator, receives a context establishment message including at least the tag identifier assigned by the mobile network, sends a radio resource control establishment message including at least a temporary identifier for the tag device, and receives a radio resource control establishment completion message for the tag device.

[0012] To accomplish the foregoing and related ends, one or more aspects include the features fully described below and particularly pointed out in the claims. The following description and the accompanying drawings set forth in detail certain illustrative features of one or more aspects. However, these features are indicative of but a few of the various ways in which the principles of the various aspects may be employed, and this description is intended to include all such aspects and their equivalents. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a diagram illustrating an example of a wireless communication system and an access network.

[0014] 2A , 2B, 2C, and 2D are diagrams illustrating examples of a first 5G / NR frame, a DL channel within a 5G / NR subframe, a second 5G / NR frame, and a UL channel within a 5G / NR subframe, respectively.

[0015] Figure 3 is a diagram illustrating an example of a base station and a user equipment (UE) in an access network.

[0016] Figure 4 A diagram illustrating an example decomposed base station architecture is shown.

[0017] Figure 5 is a diagram illustrating an example implementation of an A-IoT device and a reader.

[0018] Figure 6 is a diagram illustrating a single-station deployment scenario of an A-IoT device in a mobile communication network.

[0019] Figure 7is a diagram illustrating a single-station deployment scenario of an A-IoT device in a mobile communication network.

[0020] Figure 8A 、 Figure 8B 、 Figure 8C and Figure 8D This paper illustrates a dual-station deployment scenario for A-IoT devices in a mobile communication network.

[0021] Figure 9 is a diagram illustrating a mobility scenario of an A-IoT device in a mobile communication network.

[0022] Figure 10 is a diagram illustrating a mobility scenario of an A-IoT device in a mobile communication network.

[0023] Figure 11 is a diagram illustrating a mobility scenario of an A-IoT device in a mobile communication network.

[0024] Figure 12 is a signal flow diagram 1200 according to various aspects of the present disclosure.

[0025] Figure 13 is a signal flow diagram including an example of an authentication process according to various aspects of the present disclosure.

[0026] Figure 14 is a signal flow diagram according to various aspects of the present disclosure.

[0027] Figure 15 is a diagram illustrating an example set of available states for an A-IoT device as described herein.

[0028] Figure 16 Signal flow diagrams according to various aspects of the present disclosure are illustrated.

[0029] Figure 17 Signal flow diagrams according to various aspects of the present disclosure are illustrated.

[0030] Figure 18 Signal flow diagrams according to various aspects of the present disclosure are illustrated.

[0031] Figure 19 Signal flow diagrams according to various aspects of the present disclosure are illustrated.

[0032] Figure 20 is a signal flow diagram according to various aspects of the present disclosure.

[0033] Figure 21A and Figure 21B is a flow chart of a method of wireless communication.

[0034] Figure 22 is a flow chart of a method of wireless communication.

[0035] Figure 23 is a conceptual data flow diagram illustrating the flow of data between different parts / components in an example apparatus.

[0036] Figure 24 is a diagram illustrating an example of a hardware implementation for an apparatus employing a processing system.

[0037] Figure 25 is a flow chart of a method of wireless communication.

[0038] Figure 26 is a conceptual data flow diagram illustrating the flow of data between different parts / components in an example apparatus.

[0039] Figure 27 is a diagram illustrating an example of a hardware implementation for an apparatus employing a processing system.

[0040] Figure 28A and Figure 28B is a flow chart of a method of wireless communication.

[0041] Figure 29 is a flow chart of a method of wireless communication.

[0042] Figure 30 is a conceptual data flow diagram illustrating the flow of data between different parts / components in an example apparatus.

[0043] Figure 31 is a diagram illustrating an example of a hardware implementation for an apparatus employing a processing system.

[0044] Figure 32 is a flow chart of a method of wireless communication.

[0045] Figure 33 is a conceptual data flow diagram illustrating the flow of data between different parts / components in an example apparatus.

[0046] Figure 34 is a diagram illustrating an example of a hardware implementation for an apparatus employing a processing system. DETAILED DESCRIPTION

[0047] The detailed description set forth below in conjunction with the accompanying drawings is intended as a description of various configurations and is not intended to represent the only configurations with which the concepts described herein may be practiced. The detailed description includes specific details to provide a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some cases, well-known structures and components are shown in block diagram form to avoid obscuring such concepts.

[0048] Several aspects of telecommunications systems will now be presented with reference to various apparatus and methods. These apparatus and methods are described in the following detailed description and illustrated in the accompanying drawings by various blocks, components, circuits, processes, algorithms, etc. (collectively, "elements"). These elements can be implemented using electronic hardware, computer software, or any combination thereof. Whether these elements are implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system.

[0049] As an example, an element, or any portion of an element, or any combination of elements, may be implemented as a "processing system" that includes one or more processors. Examples of processors include a microprocessor, a microcontroller, a graphics processing unit (GPU), a central processing unit (CPU), an application processor, a digital signal processor (DSP), a reduced instruction set computing (RISC) processor, a system on a chip (SoC), a baseband processor, a field programmable gate array (FPGA), a programmable logic device (PLD), a state machine, gating logic, discrete hardware circuits, and other suitable hardware configured to perform the various functions described throughout this disclosure. One or more processors in a processing system can execute software. Whether referred to as software, firmware, middleware, microcode, hardware description language, or other names, software should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subroutines, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc.

[0050] Thus, in one or more example embodiments, the described functionality may be implemented in hardware, software, or any combination thereof. If implemented in software, the functionality may be stored or encoded as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media. A storage medium may be any available medium that can be accessed by a computer. By way of example and not limitation, such computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage, other magnetic storage devices, combinations of the foregoing types of computer-readable media, or any other medium that can be used to store computer-executable code in the form of instructions or data structures that can be accessed by a computer.

[0051] Figure 11 is a diagram illustrating an example of a wireless communication system and access network 100. The wireless communication system, also referred to as a wireless wide area network (WWAN), includes a base station 102, a UE 104, an evolved packet core (EPC) 160, and another core network 190 (e.g., a 5G core (5GC)). Base station 102 may include a macro cell (a high-power cellular base station) and / or a small cell (a low-power cellular base station). A macro cell includes a base station. Small cells include femto cells, pico cells, and micro cells.

[0052] Base stations 102 configured for 4G LTE (collectively referred to as the Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN)) can interface with EPC 160 via a backhaul link 132 (e.g., an S1 interface). Base stations 102 configured for 5G NR (collectively referred to as the Next Generation RAN (NG-RAN)) can interface with core network 190 via a backhaul link 184. Among other functions, base stations 102 can perform one or more of the following: delivery of user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, distribution of non-access stratum (NAS) messages, NAS node selection, synchronization, radio access network (RAN) sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracking, RAN information management (RIM), paging, positioning, and delivery of warning messages. Base stations 102 may communicate with each other directly or indirectly (eg, through EPC 160 or core network 190) via backhaul links 134 (eg, X2 interfaces). Backhaul links 134 may be wired or wireless.

[0053] Base stations 102 can communicate wirelessly with UEs 104. Each of base stations 102 can provide communication coverage for a corresponding geographic coverage area 110. Overlapping geographic coverage areas 110 may exist. For example, a small cell 102′ can have a coverage area 110′ that overlaps with the coverage area 110 of one or more macro base stations 102. A network that includes both small cells and macro cells may be referred to as a heterogeneous network. A heterogeneous network may also include Home evolved Node Bs (eNBs) (HeNBs), which can provide service to a restricted group known as a Closed Subscriber Group (CSG). The communication link 120 between base station 102 and UE 104 may include uplink (UL) (also known as a reverse link) transmissions from UE 104 to base station 102 and / or downlink (DL) (also known as a forward link) transmissions from base station 102 to UE 104. Communication link 120 may utilize multiple-input, multiple-output (MIMO) antenna technology, including spatial multiplexing, beamforming, and / or transmit diversity. This communication link may be over one or more carriers. Base station 102 / UE 104 may use spectrum with a bandwidth of up to Y MHz (e.g., 5 MHz, 10 MHz, 15 MHz, 20 MHz, 100 MHz, 400 MHz, etc.) for each carrier allocated in the carrier aggregation for a total of up to Yx MHz (x component carriers) for transmission in each direction. These carriers may or may not be adjacent to each other. The allocation of carriers may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be allocated for DL ​​compared to UL). Component carriers may include a primary component carrier and one or more secondary component carriers. The primary component carrier may be referred to as a primary cell (PCell) and the secondary component carriers may be referred to as secondary cells (SCells).

[0054] Certain UEs 104 may communicate with each other using device-to-device (D2D) communication links 158. D2D communication links 158 may utilize DL / UL WWAN spectrum. D2D communication links 158 may utilize one or more sidelink channels, such as a physical sidelink broadcast channel (PSBCH), a physical sidelink discovery channel (PSDCH), a physical sidelink shared channel (PSSCH), and a physical sidelink control channel (PSCCH). D2D communication may be accomplished via various wireless D2D communication systems, such as, for example, FlashLinQ, WiMedia, Bluetooth, ZigBee, Wi-Fi based on the IEEE 802.11 standard, LTE, or NR.

[0055] The wireless communication system may also include a Wi-Fi access point (AP) 150 that communicates with a Wi-Fi station (STA) 152 via a communication link 154 in the 5 GHz unlicensed spectrum. When communicating in the unlicensed spectrum, the STA 152 / AP 150 may perform a clear channel assessment (CCA) to determine whether the channel is available before communicating.

[0056] Small cell 102' can operate in licensed and / or unlicensed spectrum. When operating in unlicensed spectrum, small cell 102' can employ NR and utilize the same 5 GHz unlicensed spectrum as used by Wi-Fi AP 150. Small cell 102' employing NR in unlicensed spectrum can improve access network coverage and / or increase access network capacity.

[0057] Base station 102, whether a small cell 102' or a large cell (e.g., a macro base station), may include an eNB, gNodeB (gNB), or another type of base station. Some base stations, such as gNB 180, may operate in traditional sub-6 GHz spectrum, millimeter wave (mmW) frequencies, and / or near-mmW frequencies to communicate with UE 104. When gNB 180 operates in mmW or near-mmW frequencies, gNB 180 may be referred to as a mmW base station. Extremely high frequency (EHF) is a portion of the RF spectrum in the electromagnetic spectrum. EHF has a range of 30 GHz to 300 GHz, with wavelengths between 1 and 10 mm. Radio waves in this band may be referred to as millimeter waves. Near-mmW extends down to frequencies of 3 GHz, with wavelengths of 100 mm. Super high frequency (SHF) bands extend between 3 GHz and 30 GHz and are also referred to as centimeter waves. Communications using mmW / near-mmW radio frequency bands (e.g., 3 GHz-300 GHz) suffer from extremely high path loss and short range. The mmW base station 180 may use beamforming 182 with the UE 104 to compensate for the extremely high path loss and short range.

[0058] Base station 180 may transmit beamformed signals in one or more transmit directions 182′ to UE 104. UE 104 may receive beamformed signals from base station 180 in one or more receive directions 182″. UE 104 may also transmit beamformed signals in one or more transmit directions to base station 180. Base station 180 may receive beamformed signals in one or more receive directions from UE 104. Base station 180 / UE 104 may perform beam training to determine the optimal receive direction and transmit direction for each of base station 180 / UE 104. The transmit direction and receive direction of base station 180 may or may not be the same. The transmit direction and receive direction of UE 104 may or may not be the same.

[0059] EPC 160 may include a Mobility Management Entity (MME) 162, other MMEs 164, a Serving Gateway 166, a Multimedia Broadcast Multicast Service (MBMS) Gateway 168, a Broadcast Multicast Service Center (BM-SC) 170, and a Packet Data Network (PDN) Gateway 172. MME 162 may communicate with a Home Subscriber Server (HSS) 174. MME 162 is a control node that handles signaling between UE 104 and EPC 160. Generally speaking, MME 162 provides bearer and connection management. All user Internet Protocol (IP) packets pass through Serving Gateway 166, which itself is connected to PDN Gateway 172. PDN Gateway 172 provides UE IP address allocation and other functions. PDN Gateway 172 and BM-SC 170 are connected to IP Services 176. IP Services 176 may include the Internet, an intranet, an IP Multimedia Subsystem (IMS), PS streaming services, and / or other IP services. The BM-SC 170 provides functionality for the provisioning and delivery of MBMS user services. It serves as the entry point for content providers' MBMS delivery, authorizes and initiates MBMS bearer services within the public land mobile network (PLMN), and schedules MBMS delivery. The MBMS gateway 168 distributes MBMS services to base stations 102 within a Multicast Broadcast Single Frequency Network (MBSFN) area that broadcasts specific services. It is also responsible for session management (start / stop) and for collecting eMBMS-related billing information.

[0060] Core network 190 may include access and mobility management function (AMF) 192, other AMFs 193, session management function (SMF) 194, and user plane function (UPF) 195. AMF 192 may communicate with unified data management (UDM) 196. AMF 192 is a control node that handles signaling between UE 104 and core network 190. Generally speaking, AMF 192 provides QoS flow and session management. All user Internet Protocol (IP) packets pass through UPF 195. UPF 195 provides UE IP address allocation and other functions. UPF 195 connects to IP services 197. IP services 197 may include the Internet, intranet, IP Multimedia Subsystem (IMS), PS streaming services, and / or other IP services.

[0061] A base station may also be referred to as a gNB, Node B, evolved Node B (eNB), access point, base transceiver station, radio base station, radio transceiver, transceiver functionality, basic service set (BSS), extended service set (ESS), transmit reception point (TRP), or some other suitable terminology. Base station 102 provides an access point to EPC 160 or core network 190 for UEs 104. Examples of UEs 104 include cellular phones, smartphones, Session Initiation Protocol (SIP) phones, laptops, personal digital assistants (PDAs), satellite radios, global positioning systems, multimedia devices, video devices, digital audio players (e.g., MP3 players), cameras, game consoles, tablets, smart devices, wearable devices, vehicles, electric meters, gas pumps, large or small kitchen appliances, healthcare devices, implants, sensors / actuators, displays, or any other similarly functional device. Some of UEs 104 may be referred to as IoT devices (e.g., parking meters, gas pumps, toasters, vehicles, heart rate monitors, etc.). UE 104 may also be referred to as a station, a mobile station, a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, or some other suitable terminology.

[0062] exist Figure 1 In the present invention, UE 104 can act as a reader for a tag device, such as ambient IoT (A-IoT) device 105. For example, UE 104 can communicate with A-IoT device 105 via communication link 107. In some examples, communication link 107 can include at least a forward link (FL) or a backscatter link (BL). In some examples, UE 104 can assist A-IoT device 105 in initiating a radio resource control (RRC) connection establishment with base station 102.

[0063] Reference again Figure 1 In some aspects, the A-IoT device 105 may be configured to send a first message including at least a tag identifier (ID) assigned by the mobile network (e.g., a unique tag ID) or an unregistered tag indicator in response to the query command, and receive a second message (198) including at least a temporary ID, a reader ID, or a list of authorized readers for communicating with the network node. While the following description may focus on 5G NR, the concepts described herein may be applicable to other similar areas, such as LTE, LTE-A, CDMA, GSM, and other wireless technologies.

[0064] Figure 2A is a diagram 200 illustrating an example of a first subframe within a 5G / NR frame structure. Figure 2B is a diagram 230 illustrating an example of a DL channel within a 5G / NR subframe. Figure 2C is a diagram 250 illustrating an example of a second subframe within a 5G / NR frame structure. Figure 2D is a diagram 280 illustrating an example of a UL channel within a 5G / NR subframe. The 5G / NR frame structure can be FDD, where for a particular set of subcarriers (carrier system bandwidth), subframes within that subcarrier set are dedicated to either DL or UL, or TDD, where for a particular set of subcarriers (carrier system bandwidth), subframes within that subcarrier set are dedicated to both DL and UL. In the examples provided in Figures 2A and 2C, it is assumed that the 5G / NR frame structure is TDD, where subframe 4 is configured with slot format 28 (primarily DL), where D stands for DL, U stands for UL, and X is used flexibly between DL / UL, and subframe 3 is configured with slot format 34 (primarily UL). While subframes 3 and 4 are shown as having slot formats 34 and 28, respectively, any particular subframe can be configured with any of the various available slot formats 0-61. Slot formats 0 and 1 are all DL and all UL, respectively. The other slot formats 2-61 include a mix of DL, UL, and flexible symbols. The UE is configured with the slot format via a received slot format indicator (SFI), either dynamically via DL control information (DCI) or semi-statically / statically via radio resource control (RRC) signaling. Note that the following description also applies to the 5G / NR frame structure for TDD.

[0065] Other wireless communication technologies may have different frame structures and / or different channels. A frame (10 ms) can be divided into 10 equally sized subframes (1 ms). Each subframe may include one or more slots. A subframe may also include mini-slots, which may include 7, 4, or 2 symbols. Each slot may include 7 or 14 symbols, depending on the slot configuration. For slot configuration 0, each slot may include 14 symbols, and for slot configuration 1, each slot may include 7 symbols. Symbols on the DL may be cyclic prefix (CP) OFDM (CP-OFDM) symbols. Symbols on the UL may be CP-OFDM symbols (for high-throughput scenarios) or discrete Fourier transform (DFT) spread OFDM (DFT-s-OFDM) symbols (also known as single-carrier frequency division multiple access (SC-FDMA) symbols) (for power-limited scenarios; limited to single-stream transmission). The number of slots within a subframe depends on the slot configuration and numerology. For slot configuration 0, different parameter sets µ 0 to 5 allow 1, 2, 4, 8, 16, and 32 slots per subframe, respectively. For slot configuration 1, different parameter sets 0 to 2 allow 2, 4, and 8 slots per subframe, respectively. Accordingly, for slot configuration 0 and parameter set µ, there are 14 symbols per slot and 2 per subframe. µ time slots. The subcarrier spacing and symbol length / duration are functions of the parameter set. The subcarrier spacing can be equal to ,in For parameter sets 0 to 5. Therefore, the subcarrier spacing for parameter set µ=0 is 15 kHz, and the subcarrier spacing for parameter set µ=5 is 480 kHz. The symbol length / duration is inversely related to the subcarrier spacing. Figures 2A to 2D provide examples of slot configuration 0 with 14 symbols per slot and parameter set µ=0 with 1 slot per subframe. The subcarrier spacing is 15 kHz and the symbol duration is approximately 66.7 s.

[0066] A resource grid can be used to represent the frame structure. Each slot consists of a resource block (RB) (also known as a physical RB (PRB)) that extends over 12 consecutive subcarriers. The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.

[0067] As illustrated in FIG2A , some of the REs carry reference (pilot) signals (RSs) for the UE. The RSs may include demodulation RSs (DM-RSs) used for channel estimation at the UE (indicated as R for a specific configuration). x, where 100x is the port number, but other DM-RS configurations are possible) and channel state information reference signal (CSI-RS). RSs may also include beam measurement RS (BRS), beam refinement RS (BRRS), and phase tracking RS (PT-RS).

[0068] Figure 2B illustrates examples of various downlink channels within a subframe of a frame. The physical downlink control channel (PDCCH) carries DCI within one or more control channel elements (CCEs). Each CCE consists of nine resource element groups (REGs), with each REG consisting of four consecutive REs within an OFDM symbol. The primary synchronization signal (PSS) may be within symbol 2 of specific subframes of a frame. The PSS is used by the UE 104 to determine subframe / symbol timing and physical layer identification. The secondary synchronization signal (SSS) may be within symbol 4 of specific subframes of a frame. The SSS is used by the UE to determine the physical layer cell identity group number and radio frame timing. Based on the physical layer identity and physical layer cell identity group number, the UE can determine the physical cell identifier (PCI). Based on the PCI, the UE can determine the location of the aforementioned DM-RS. The physical broadcast channel (PBCH), which carries the master information block (MIB), can be logically grouped with the PSS and SSS to form a synchronization signal (SS) / PBCH block. The MIB provides the system frame number (SFN) and the number of RBs in the system bandwidth. The Physical Downlink Shared Channel (PDSCH) carries user data, broadcast system information not sent through the PBCH (such as System Information Blocks (SIBs)), and paging messages.

[0069] As illustrated in Figure 2C , some of the REs carry DM-RSs (indicated as R for a specific configuration, but other DM-RS configurations are possible) for channel estimation at the base station. The UE can transmit DM-RSs for the physical uplink control channel (PUCCH) and DM-RSs for the physical uplink shared channel (PUSCH). The PUSCH DM-RS can be transmitted in the first or first two symbols of the PUSCH. The PUCCH DM-RS can be transmitted in different configurations depending on whether a short or long PUCCH is transmitted and the specific PUCCH format used. Although not shown, the UE can also transmit a sounding reference signal (SRS). The SRS can be used by the base station for channel quality estimation to enable frequency-dependent scheduling of the UL.

[0070] Figure 2D illustrates an example of various UL channels within a subframe of a frame. The PUCCH may be located as indicated in one configuration. The PUCCH carries uplink control information (UCI), such as scheduling requests, channel quality indicators (CQIs), precoding matrix indicators (PMIs), rank indicators (RIs), and HARQ ACK / NACK feedback. The PUSCH carries data and may additionally be used to carry buffer status reports (BSRs), power headroom reports (PHRs), and / or UCI.

[0071] Figure 3 Figure 3 is a block diagram of a base station 310 communicating with a UE 350 in an access network. In the DL, IP packets from the EPC 160 may be provided to the controller / processor 375. The controller / processor 375 implements Layer 3 and Layer 2 functions. Layer 3 includes the Radio Resource Control (RRC) layer, and Layer 2 includes the Service Data Adaptation Protocol (SDAP) layer, the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Medium Access Control (MAC) layer. The controller / processor 375 provides RRC layer functions associated with broadcasting of system information (e.g., MIB, SIB), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-radio access technology (RAT) mobility, and measurement configuration for UE measurement reporting; PDCP layer functions associated with header compression / decompression, security (ciphering, deciphering, integrity protection, integrity verification), and handover support functions; RLC layer functions associated with delivery of upper layer packet data units (PDUs), error correction through ARQ, concatenation, segmentation and reassembly of RLC service data units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction through HARQ, priority handling, and logical channel prioritization.

[0072] The transmit (TX) processor 316 and receive (RX) processor 370 implement Layer 1 functions associated with various signal processing functions. Layer 1, which includes the physical (PHY) layer, may include error detection on the transport channel, forward error correction (FEC) coding / decoding of the transport channel, interleaving, rate matching, mapping onto the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. The TX processor 316 handles the mapping to the signal constellation based on various modulation schemes (e.g., binary phase-shift keying (BPSK), quadrature phase-shift keying (QPSK), M-order phase-shift keying (M-PSK), and M-order quadrature amplitude modulation (M-QAM)). The coded and modulated symbols are then separated into parallel streams. Each stream is then mapped to an OFDM subcarrier, multiplexed with a reference signal (e.g., a pilot) in the time and / or frequency domain, and then combined using an inverse fast Fourier transform (IFFT) to produce a physical channel carrying the time-domain OFDM symbol stream. The OFDM stream is spatially pre-coded to generate multiple spatial streams. Channel estimates from a channel estimator 374 may be used to determine the coding and modulation schemes, as well as for spatial processing. The channel estimates may be derived from a reference signal and / or channel condition feedback transmitted by the UE 350. Each spatial stream may then be provided to a different antenna 320 via a separate transmitter 318TX. Each transmitter 318TX may modulate an RF carrier with a corresponding spatial stream for transmission.

[0073] At the UE 350, each receiver 354RX receives a signal via its corresponding antenna 352. Each receiver 354RX recovers the information modulated onto the RF carrier and provides the information to a receive (RX) processor 356. The TX processor 368 and the RX processor 356 implement Layer 1 functions associated with various signal processing functions. The RX processor 356 performs spatial processing on the information to recover any spatial streams destined for the UE 350. If multiple spatial streams are destined for the UE 350, they may be combined by the RX processor 356 into a single OFDM symbol stream. The RX processor 356 then converts the OFDM symbol stream from the time domain to the frequency domain using a fast Fourier transform (FFT). The frequency-domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, along with the reference signal, are recovered and demodulated by determining the most likely signal constellation point transmitted by the base station 310. These soft decisions may be based on channel estimates calculated by the channel estimator 358. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally sent on the physical channel by base station 310. The data and control signals are then provided to a controller / processor 359, which implements layer 3 and layer 2 functionality.

[0074] The controller / processor 359 may be associated with a memory 360 that stores program codes and data. The memory 360 may be referred to as a computer-readable medium. In the UL, the controller / processor 359 provides demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets from the EPC 160. The controller / processor 359 is also responsible for error detection using an ACK and / or NACK protocol to support HARQ operations.

[0075] Similar to the functions described in conjunction with DL transmissions by the base station 310, the controller / processor 359 provides RRC layer functions associated with system information (e.g., MIB, SIB) acquisition, RRC connection, and measurement reporting; PDCP layer functions associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functions associated with delivery of upper layer PDUs, error correction through ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto TBs, demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction through HARQ, priority handling, and logical channel prioritization.

[0076] Channel estimates derived by the channel estimator 358 based on a reference signal or feedback transmitted by the base station 310 may be used by the TX processor 368 to select the appropriate coding and modulation schemes and to facilitate spatial processing. The spatial streams generated by the TX processor 368 may be provided to different antennas 352 via separate transmitters 354TX. Each transmitter 354TX may modulate an RF carrier with a corresponding spatial stream for transmission.

[0077] UL transmissions are processed at the base station 310 in a manner similar to that described in conjunction with the receiver functionality at the UE 350. Each receiver 318RX receives a signal through its respective antenna 320. Each receiver 318RX recovers information modulated onto an RF carrier and provides the information to an RX processor 370.

[0078] The controller / processor 375 may be associated with a memory 376 that stores program codes and data. The memory 376 may be referred to as a computer-readable medium. In the UL, the controller / processor 375 provides demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets from the UE 350. The IP packets from the controller / processor 375 may be provided to the EPC 160. The controller / processor 375 is also responsible for error detection using an ACK and / or NACK protocol to support HARQ operations.

[0079] At least one of the TX processor 368, the RX processor 356, and the controller / processor 359 may be configured to combine Figure 1 The 198 came to perform all aspects.

[0080] The deployment of a communication system, such as a 5G New Radio (NR) system, can be arranged in a variety of ways using various components or constituent parts. In a 5G NR system or network, a network node, a network entity, a mobility element of the network, a radio access network (RAN) node, a core network node, a network element, or network equipment (such as a base station (BS)), or one or more units (or one or more components) performing base station functions can be implemented in a converged or disaggregated architecture. For example, a base station (such as a node B (NB), an evolved NB (eNB), an NR base station, a 5G NB, an access point (AP), a transmit / receive point (TRP), or a cell) can be implemented as a converged base station (also known as a standalone base station or a monolithic base station) or a disaggregated base station.

[0081] A converged base station can be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. A disaggregated base station can be configured to utilize a protocol stack that is physically or logically distributed across two or more units, such as one or more central or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs). In some aspects, a CU can be implemented within a RAN node, and one or more DUs can be co-located with the CU, or alternatively, can be geographically or virtually distributed across one or more other RAN nodes. A DU can be implemented to communicate with one or more RUs. Each of the CU, DU, and RU can also be implemented as a virtual unit, namely a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).

[0082] Base station-type operation or network design may take into account the aggregated nature of base station functionality. For example, a disaggregated base station may be utilized in an integrated access backhaul (IAB) network, an open radio access network (O-RAN (a network configuration such as that promoted by the O-RAN Alliance)), or a virtualized radio access network (vRAN, also known as a cloud radio access network (C-RAN)). Disaggregation can include distributing functionality across two or more units at various physical locations, as well as virtually distributing the functionality of at least one unit, which enables flexibility in network design. The various units of a disaggregated base station or disaggregated RAN architecture can be configured for wired or wireless communication with at least one other unit.

[0083] The deployment of a communication system, such as a 5G New Radio (NR) system, can be arranged in a variety of ways using various components or elements. In a 5G NR system or network, a network node, a network entity, a mobility element of a network, a radio access network (RAN) node, a core network node, a network element, or network equipment (such as a base station (BS)), or one or more units (or one or more components) performing base station functions can be implemented in a converged or disaggregated architecture. For example, a base station (such as a Node B (NB), an evolved NB (eNB), an NR base station, a 5G NB (gNB), an access point (AP), a transmit / receive point (TRP), or a cell) can be implemented as a converged base station (also known as a standalone BS or a monolithic BS) or a disaggregated base station.

[0084] A converged base station can be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. A disaggregated base station can be configured to utilize a protocol stack that is physically or logically distributed across two or more units, such as one or more central or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs). In some aspects, a CU can be implemented within a RAN node, and one or more DUs can be co-located with the CU, or alternatively, can be geographically or virtually distributed across one or more other RAN nodes. A DU can be implemented to communicate with one or more RUs. Each of the CU, DU, and RU can also be implemented as a virtual unit, namely a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).

[0085] Base station-type operation or network design may take into account the aggregated nature of base station functionality. For example, a disaggregated base station may be utilized in an integrated access backhaul (IAB) network, an open radio access network (O-RAN (a network configuration such as that promoted by the O-RAN Alliance)), or a virtualized radio access network (vRAN, also known as a cloud radio access network (C-RAN)). Disaggregation can include distributing functionality across two or more units at various physical locations, as well as virtually distributing the functionality of at least one unit, which enables flexibility in network design. The various units of a disaggregated base station or disaggregated RAN architecture can be configured for wired or wireless communication with at least one other unit.

[0086] Figure 4A diagram illustrating an example disaggregated base station 400 architecture is shown. The disaggregated base station 400 architecture may include one or more central units (CUs) 410, which may communicate directly with a core network 420 via a backhaul link, or indirectly through one or more disaggregated base station units, such as a near real-time (near-RT) RAN intelligent controller (RIC) 425 via an E2 link, or a non-real-time (non-RT) RIC 415 associated with a service management and orchestration (SMO) framework 405, or both. The CUs 410 may communicate with one or more distributed units (DUs) 430 via corresponding midhaul links, such as the F1 interface. The DUs 430 may communicate with one or more radio units (RUs) 440 via corresponding fronthaul links. The RUs 440 may communicate with corresponding UEs 450 via one or more radio frequency (RF) access links. In some implementations, a UE 450 may be served simultaneously by multiple RUs 440.

[0087] Each of the units (i.e., CU 410, DU 430, RU 440, as well as near-RT RIC 425, non-RT RIC 415, and SMO framework 405) may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) via a wired or wireless transmission medium. Each of the units, or an associated processor or controller that provides instructions to the communication interface of these units, may be configured to communicate with one or more of the other units via the transmission medium. For example, these units may include a wired interface configured to receive signals or transmit signals to one or more of the other units via the wired transmission medium. Additionally, these units may include a wireless interface that may include a receiver, transmitter, or transceiver (such as a radio frequency (RF) transceiver) configured to receive signals or transmit signals to one or more of the other units via the wireless transmission medium, or both.

[0088] In some aspects, the CU 410 may host one or more higher-layer control functions. Such control functions may include radio resource control (RRC), packet data convergence protocol (PDCP), service data adaptation protocol (SDAP), etc. Each control function may be implemented using an interface configured to communicate signals with other control functions hosted by the CU 410. The CU 410 may be configured to handle user plane functions (i.e., central unit-user plane (CU-UP)), control plane functions (i.e., central unit-control plane (CU-CP)), or a combination thereof. In some implementations, the CU 410 may be logically split into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units may communicate bidirectionally with the CU-CP units via an interface (such as an E1 interface). As needed, the CU 410 may be implemented to communicate with the DU 430 for network control and signaling.

[0089] The DU 430 may correspond to a logical unit that includes one or more base station functions for controlling the operation of one or more RUs 440. In some aspects, the DU 430 may host one or more of a radio link control (RLC) layer, a medium access control (MAC) layer, and one or more higher physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation and demodulation, etc.), depending at least in part on a functional split, such as that defined by the Third Generation Partnership Project (3GPP). In some aspects, the DU 430 may also host one or more lower PHY layers. Each layer (or module) may be implemented using an interface configured to communicate signals with other layers (and modules) hosted by the DU 430 or with control functions hosted by the CU 410.

[0090] Lower layer functions may be implemented by one or more RUs 440. In some deployments, a RU 440 controlled by a DU 430 may correspond to a logical node that hosts RF processing functions or low PHY layer functions (such as performing fast Fourier transforms (FFTs), inverse FFTs (iFFTs), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.), or both, based at least in part on a functional split (such as a lower layer functional split). In such an architecture, the RU 440 may be implemented to handle over-the-air (OTA) communications with one or more UEs 450. In some implementations, both real-time and non-real-time aspects of control and user plane communications with the RU 440 may be controlled by the corresponding DU 430. In some scenarios, this configuration may enable the DU 430 and CU 410 to be implemented in a cloud-based RAN architecture, such as a vRAN architecture.

[0091] The SMO framework 405 can be configured to support RAN deployment and provisioning of both non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 405 can be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via an operations and maintenance interface (such as the O1 interface). For virtualized network elements, the SMO framework 405 can be configured to interact with a cloud computing platform (such as Open Cloud (O-Cloud) 490) to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface (such as the O2 interface). Such virtualized network elements may include, but are not limited to, the CU 410, DU 430, RU 440, and near-RT RIC 425. In some implementations, the SMO framework 405 can communicate with 4G RAN hardware (such as the Open eNB (O-eNB) 411) via the O1 interface. Additionally, in some implementations, the SMO framework 405 can communicate directly with one or more RUs 440 via the O1 interface. The SMO framework 405 may also include a non-RT RIC 415 configured to support the functionality of the SMO framework 405 .

[0092] The non-RT RIC 415 can be configured to include logic that enables non-real-time control and optimization of RAN elements and resources, artificial intelligence / machine learning (AI / ML) workflows including model training and updating, or policy-based guidance of applications / features in the near-RT RIC 425. The non-RT RIC 415 can be coupled to or in communication with the near-RT RIC 425 (e.g., via an A1 interface). The near-RT RIC 425 can be configured to include logic that enables near-real-time control and optimization of RAN elements and resources through data collection and actions via an interface (e.g., via an E2 interface) that connects one or more CUs 410, one or more DUs 430, or both, and the O-eNB with the near-RT RIC 425.

[0093] In some implementations, to generate AI / ML models to be deployed in the near-RT RIC 425, the non-RT RIC 415 may receive parameters or external enrichment information from an external server. Such information may be utilized by the near-RT RIC 425 and may be received at the SMO framework 405 or the non-RT RIC 415 from non-network data sources or from network functions. In some examples, the non-RT RIC 415 or the near-RT RIC 425 may be configured to tune RAN behavior or performance. For example, the non-RT RIC 415 may monitor long-term trends and patterns in performance and employ AI / ML models to execute corrective actions through the SMO framework 405 (such as via reconfiguration of O1) or by creating RAN management policies (such as A1 policies).

[0094] Ambient IoT (A-IoT) devices (e.g., passive IoT devices) can be ultra-low-complexity and ultra-low-power devices, and may have complexity and power consumption orders of magnitude lower than existing low-complexity and low-power devices, such as reduced-capability (RedCap) UEs, enhanced machine-type communication (eMTC) devices, and narrowband IoT (NB-IoT) devices. There are different types of A-IoT devices. For example, a first type of A-IoT device (also referred to as a Type A device) may not have a battery or any energy storage capability. Therefore, a first type of A-IoT device is completely dependent on the availability of an external energy source. A second type of A-IoT device (also referred to as a Type B device) may have a limited energy storage device (e.g., super capacity or regular capacity) that does not require manual replacement or recharging.

[0095] In some examples, A-IoT devices (also referred to herein as tags or tag devices) are typically implemented as passive devices and lack active RF components. A-IoT devices can transmit data by modulating incident RF signals transmitted by ambient transmitters (e.g., cellular devices such as smartphones, base stations, etc.). Ambient RF signals can be used not only as a signal source for backscattering but also as an energy source for energy harvesting.

[0096] It should be noted that the A-IoT devices described herein can have a longer read range than conventional RF identification (RFID) devices. The limited read range of such conventional RFID devices (e.g., one or two meters) makes it difficult to support large-scale deployments with seamless mobile network coverage.

[0097] Figure 5 is a diagram illustrating an example implementation of an A-IoT device 502 and a reader 504. In some examples, the reader 504 may be a UE, a network node (eg, a base station), or other suitable device capable of receiving and processing a modulated backscatter signal. Figure 5 In an example implementation, the A-IoT device 502 includes an energy harvester 506, a control circuit 508, a memory 510, a switch 512, a plurality of load impedances (such as a first load impedance (Z1) 514, a second load impedance (Z2) 516, and an Nth load impedance (Z N ) 518 (eg, where N is a positive integer)) and antenna 520.

[0098] The reader 504 includes a transmitter 522 coupled to a first antenna 524 and a receiver 526 coupled to a second antenna 528. The reader 504 may have full-duplex capabilities such that the reader 504 may concurrently transmit and receive signals (eg, RF signals).

[0099] A-IoT device 502 can communicate with a reader using backscatter communication. In backscatter communication, information is transmitted via antenna modulation and may not involve active generation of RF signals. For example, a backscatter device (e.g., A-IoT device 502) can adjust the reflection coefficient of its antenna by switching a given set of impedances (e.g., using switch 512 and load impedances 514, 516, 518), thereby causing a varying amount of the incident signal to be backscattered.

[0100] When using BPSK modulation, the A-IoT device 502 can switch the value of the load impedance between a very high impedance and a relatively matched load (e.g., via switch 512). In the high impedance case, the mismatch between the antenna impedance 520 and the load impedance will allow the A-IoT device 502 to reflect all of the incoming signal's power back to the reader 504. In the matched case, most of the power from the incoming RF signal can be absorbed, and very little power can be reflected to the reader 504. The impedance switching frequency can be based on the data rate.

[0101] exist Figure 5 In the example, reader 504 may transmit a carrier wave 530, which may be a continuous wave (CW). In some examples, carrier wave 530 may be an ambient RF signal from a mobile communication network (e.g., 5G NR). A-IoT device 502 may receive carrier wave 530 and may backscatter modulated signal 532. In some examples, energy harvester 506 may harvest energy from carrier wave 530 and may power control circuitry 508 and memory 510. In some implementations, control circuitry 508 may be a microcontroller and may include data processing capabilities (e.g., public / private key generation, encryption, decryption, and / or other suitable data processing capabilities). Memory 510 may store identification information associated with A-IoT device 502, such as a tag identifier (ID) and / or an electronic product code (EPC).

[0102] Figure 6 is a diagram illustrating a single-station deployment scenario of an A-IoT device 502 in a mobile communication network 600. For example, Figure 6 5 shows full duplex communication between the A-IoT device 502 and the network node 604. In some examples, the network node 604 can be a base station as described herein. Figure 6 In FIG. 6 , transmissions 610 from network node 604 may include a continuous wave and a forward link. The continuous wave may serve as both an energy source and a carrier signal for backscatter communication. The forward link carries control signaling to A-IoT 502. Transmissions 612 from A-IoT device 502 may include a backscatter link that carries data from A-IoT device 502 to network node 604.

[0103] Figure 7 is a diagram illustrating a single-station deployment scenario of an A-IoT device 502 in a mobile communication network 700. For example, Figure 7 7 shows full-duplex communication between the A-IoT device 502 and the UE 702. Figure 7 In FIG. 7 , transmission 710 from UE 702 may include a continuous wave and a forward link. The continuous wave may serve as both an energy source and a carrier signal for backscatter communication. The forward link carries control signaling to A-IoT 502. Transmission 712 from A-IoT device 502 may include a backscatter link that carries data from A-IoT device 502 to UE 702.

[0104] Figure 8A 、 Figure 8B 、 Figure 8C and Figure 8D The dual-station deployment scenario of the A-IoT device 806 in the mobile communication network 800 is illustrated. Figure 8A 、 Figure 8B 、 Figure 8C and Figure 8D In the embodiment of the present invention, the network node 804 can be a base station configured for half-duplex communication. The UE 802 can receive messages from the network node 804 via the DL 810 and can send messages to the network node 804 via the UL 812. The DL 810 and the UL 812 can be implemented using the Uu interface. The UE 802 can operate as a reader of the A-IoT device 806.

[0105] exist Figure 8A In the embodiment of the present invention, the transmission 814 from the network node 804 to the A-IoT device 806 may include a continuous wave and a forward link. The transmission 816 from the A-IoT device 806 to the UE 802 may include a backscatter link that carries data from the A-IoT device 806 to the UE 802.

[0106] exist Figure 8B In the example embodiment, the transmission 826 from the UE 802 to the A-IoT device 806 may include a continuous wave and a forward link. The transmission 824 from the A-IoT device 806 to the network node 804 may include a backscatter link that carries data from the A-IoT device 806 to the network node 804.

[0107] exist Figure 8C 806, and the transmission 836 from the UE 802 to the A-IoT device 806 may include a forward link. The transmission 838 from the A-IoT device 806 to the UE 802 may include a backscatter link that carries data from the A-IoT device 806 to the UE 802.

[0108] exist Figure 8D 806 may include a continuous wave, and the transmission 844 from the network node 804 to the A-IoT device 806 may include a forward link. The transmission 846 from the A-IoT device 806 to the network node 804 may include a backscatter link that carries data from the A-IoT device 806 to the network node 804.

[0109] In various aspects described herein, a reader device (also referred to herein as a reader) capable of receiving RF signals from an A-IoT device can be implemented as a UE or a network node. In various aspects described herein, an RF source from which an A-IoT device can harvest energy and receive messages (e.g., continuous wave and forward link) can be implemented as a UE or a network node. In some examples, the reader device and the RF source can be paired with respect to the forward link and backscatter link of the A-IoT device. For example, and as Figure 9 As shown, the A-IoT device 908 may receive a continuous wave signal from an RF source (eg, UE 904 ) and may reflect and modulate the incoming signal (eg, the continuous wave signal) to a reader.

[0110] Figure 9 900 is a diagram illustrating a first mobility scenario of an A-IoT device 908. Figure 9 In FIG, the network node 902 may communicate with a first UE 904 in a first DL coverage area 914 via a first Uu link 910, and communicate with a second UE 906 in a second DL coverage area 922 via a second Uu link 912. Figure 9In the embodiment of the present invention, each of the first UE 904 and the second UE 906 can operate as an RF source for the A-IoT device 908 (e.g., for RF transmission), but not as a reader for the A-IoT device 908 (e.g., not for RF reception). The network node 902 can operate as a reader for the A-IoT device 908 (e.g., for RF reception), but not as an RF source for the A-IoT device 908 (e.g., for RF transmission).

[0111] exist Figure 9 , the A-IoT device 908 receives a continuous wave signal 916 from an RF source (e.g., UE 904) and reflects and modulates the continuous wave signal 916 to a reader (e.g., network node 902) via a backscatter link 918. After the A-IoT device 908 moves 920 to a second DL coverage area 922, the A-IoT device 908 may switch its RF source from UE 904 to UE 906 (e.g., the A-IoT device 908 in the second DL coverage area 922 receives a continuous wave signal 924 from UE 906 and no longer receives a continuous wave signal 916 from UE 904). It should be noted that after the A-IoT device 908 moves to the second DL coverage area 922, the A-IoT device 908 remains at the reader (e.g., network node 902).

[0112] Figure 10 1000 is a diagram illustrating a second mobility scenario of an A-IoT device 1008. Figure 10 In FIG, the network node 1002 may communicate with a first UE 1004 in a first UL coverage area 1014 via a first Uu link 1010 and with a second UE 1006 in a second UL coverage area 1022 via a second Uu link 1012. Figure 10 In the embodiment of the present invention, each of the first UE 1004 and the second UE 1006 can operate as a reader for the A-IoT device 1008 (e.g., for RF reception), but not as an RF source for the A-IoT device 1008 (e.g., for RF transmission). The network node 1002 can operate as an RF source for the A-IoT device 1008 (e.g., for RF transmission), but not as a reader for the A-IoT device 1008 (e.g., not for RF reception).

[0113] exist Figure 10, the A-IoT device 908 receives a continuous wave signal 1016 from an RF source (e.g., network node 1002) and reflects and modulates the continuous wave signal 1016 to a reader (e.g., UE 1004) via a backscatter link 1018. After the A-IoT device 1008 moves 1020 to a second UL coverage area 1022, the A-IoT device 1008 may switch its reader from UE 1004 to UE 1006 (e.g., UE 1006 receives backscatter link 1026, and UE 1004 no longer receives backscatter link 1018). It should be noted that after the A-IoT device 1008 moves to the second UL coverage area 1022, the A-IoT device 1008 remains the reader (e.g., network node 1002).

[0114] Figure 11 1100 is a diagram illustrating a third mobility scenario of an A-IoT device 1110. Figure 11 In , the first network node 1102 can communicate with the first UE 1106 in the first coverage area 1116 via the first Uu link 1112, and the second network node 1104 can communicate with the second UE 1108 in the second coverage area 1124 via the second Uu link 1114. Figure 11 In the embodiment, each of the first network node 1102 and the second network node 1104 can operate as a reader for the A-IoT device 1110 (e.g., for RF reception), but not as an RF source for the A-IoT device 1110 (e.g., for RF transmission). Each of the first UE 1106 and the second UE 1108 can operate as an RF source for the A-IoT device 1110 (e.g., for RF transmission), but not as a reader for the A-IoT device 1110 (e.g., not for RF reception).

[0115] exist Figure 11 , the A-IoT device 1110 receives a continuous wave signal 1118 from an RF source (e.g., a first UE 1106) and reflects and modulates the continuous wave signal 1118 to a reader (e.g., network node 1102) via a backscatter link 1120. After the A-IoT device 1110 moves 1122 to a second coverage area 1124, the A-IoT device 1110 may switch both its RF source and reader from the UE 1106 and network node 1102 to the UE 1108 and network node 1104. For example, the second network node 1104 receives the backscatter link 1128, and the first network node 1102 no longer receives the backscatter link 1120, and the A-IoT device 1110 receives the continuous wave signal 1126 from the second UE 1108 and no longer receives the continuous wave signal 1118 from the first UE 1106.

[0116] The A-IoT devices described herein can support registration and management in a mobile communication network through a reader device (also referred to herein as a reader) and a radio access network (RAN) under the control of a core network (CN) (e.g., a 5G CN) in one or more A-IoT device deployment scenarios. In some use cases, reader device handover and / or A-IoT device mobility are considered. Examples of A-IoT device deployment scenarios may include warehouse inventory management, sensor network (smart grid) applications, automotive manufacturing, personal item location, smart home applications, and / or other suitable deployment scenarios.

[0117] Various aspects described herein may enable management of A-IoT devices in a mobile communication network, including: establishing A-IoT device security for network authentication, registering an A-IoT device at the mobile communication network, initial association of an A-IoT device to a valid reader, management of an A-IoT device to switch associations between different readers (e.g., reader handoff), and A-IoT device mobility across different readers.

[0118] Various aspects described herein include initial access and connection establishment for A-IoT devices and corresponding signaling design. Aspects described herein also include different types of tag IDs for A-IoT devices, tag authentication processes, different A-IoT states, reader switching with and without network-involved signaling, and process optimizations such as group-based query commands and association requests, and tag context broadcasting.

[0119] Figure 12 is a signal flow diagram 1200 according to various aspects of the present disclosure. Figure 12 The system includes an A-IoT device 1202, a reader 1204, a network node 1206, and a core network (CN) 1208. In some examples, the network node 1206 may be a base station. In some examples, the reader 1204 may be a UE. Figure 12 In the example, the reader 1204 and the network node 1206 may perform relay operations (e.g., operations similar to layer 2 and / or layer 3 relays) between the A-IoT device 1202 and the CN 1208. In the signal flow diagram 1200, the portion 1210 indicated by the dashed line includes a connection establishment process (e.g., an RRC connection establishment process).

[0120] Reader 1204 may send a query command 1212. In various aspects described herein, a query command may be a message requesting basic information (such as a tag ID) from an A-IoT device. A-IoT device 1202 may receive query command 1212 and may send a response message 1214 in response to query command 1212. In some examples, response message 1214 may include a unique tag ID previously assigned by a mobile network entity, such as CN 1208. In some examples, if A-IoT device 1202 has not yet been assigned a unique tag ID, response message 1214 may include an unregistered tag indicator (also known as a new tag indicator). For example, if A-IoT device 1202 has not previously registered with a mobile network entity, such as CN 1208, response message 1214 may include an unregistered tag indicator. In some aspects, the unregistered tag indicator may be the tag product ID or a portion of the tag product ID.

[0121] In some examples, the A-IoT device 1202 can include a reader ID in the response message 1214 with the unique tag ID. In some examples, the reader ID can identify the reader from which the A-IoT device 1202 received the unique tag ID. In some cases, the reader ID can be associated with the reader 1204.

[0122] In some examples, if the A-IoT device 1202 has not previously registered with a mobile network entity (such as CN 1208), the A-IoT device 1202 may include a tag product ID (or a portion of the tag product ID) associated with the A-IoT device 1202 in the response message 1214, which may serve as an unregistered tag indicator. In some examples, the tag product ID may include an identifier assigned by the manufacturer or supplier of the tag itself and may be stored in a tag ID (TID) memory of the tag at the A-IoT device 1202. In some examples, the tag product ID may also include an electronic product code (EPC) associated with the A-IoT device 1202. The EPC may be an identifier that gives a unique identification to a specific product (e.g., the A-IoT device 1202) that includes the tag. In some examples, the EPC may be associated with a provider such as EPCglobal. ™ In other examples, the EPC code may be non-EPCglobal ™ application.

[0123] In some examples, the response message 1214 may include security information. In various aspects described herein, security information may refer to information associated with signaling integrity protection and / or encryption. In one example, the security information may be an authentication token to facilitate authentication of messages from the A-IoT device at the receiver device. In a non-limiting example, the security information may be a 16-bit string.

[0124] If the A-IoT device 1202 is not registered with a mobile network entity (e.g., CN 1208), the reader 1204 may assist the A-IoT device 1202 in initiating an RRC connection establishment with the network node 1206. For example, the reader 1204 may send an RRC setup request 1216 to the network node 1206.

[0125] In some examples, an RRC setup request (e.g., RRC setup request 1216) may be a message requesting establishment of an RRC connection at a network node (e.g., network node 1206). In some examples, the RRC setup request may include an identifier of the A-IoT device (e.g., a unique tag ID). In some examples, the RRC setup request may also include connection establishment terms (e.g., information regarding a reason for establishing the connection) and / or other suitable information.

[0126] The network node 1206 may receive the RRC setup request 1216 and may attempt to identify the A-IoT device 1202. If the network node 1206 cannot identify the A-IoT device 1202, the network node 1206 may send an initiate tag context setup message 1218. In some examples, the initiate tag context setup message 1218 may be configured to initiate a tag context setup procedure at the CN 1208.

[0127] In some examples, an initiate tag context setup message (also referred to as an initial context setup request), such as initiate tag context setup message 1218, may trigger an initial context setup procedure at a mobile network entity (e.g., at an AMF of a core network). For example, the tag context (e.g., for an A-IoT device) may include a bearer context, a security context, and / or other parameters for communicating with the A-IoT device.

[0128] The CN 1208 may perform an authentication process 1220 in response to the initiate tag context setup message 1218. The authentication process 1220 may allow the CN 1208 to register the A-IoT device 1202. For example, the CN 1208 may perform the authentication process 1220 with the A-IoT device 1202 to generate and assign a unique tag ID for the A-IoT device 1202. In various aspects described herein, when a unique tag ID has been assigned to the A-IoT device 1202, the A-IoT device 1202 may be considered registered at the CN 1208. Figure 13 An example of an authentication process 1220 is described.

[0129] CN 1208 may send a tag context setup message 1222 after completing authentication process 1220. In some examples, tag context setup message 1222 may include a unique tag ID. Network node 1206 may receive tag context setup message 1222.

[0130] The network node 1206 may send an RRC setup message 1224 to the A-IoT device 1202 in response to the tag context setup message 1222. In some examples, the RRC setup message 1224 may include the unique tag ID. In some examples, the RRC setup message 1224 may include a temporary identifier. For example, the temporary identifier may be a radio network temporary identifier (RNTI) (also referred to as a tag-RNTI) for the A-IoT device 1202. The A-IoT device 1202 may use the temporary identifier (e.g., the tag-RNTI) to monitor the physical (PHY) channel. In some examples, the network node 1206 may forward the unique tag ID to the A-IoT device 1202.

[0131] In some examples, the RRC setup message (e.g., RRC setup message 1224) may include an identifier of the A-IoT device (e.g., a unique tag ID). In some examples, the RRC setup message may also include radio bearer information (e.g., a signaling radio bearer configuration for RRC messages, such as an SRB1 configuration), cell configuration information (e.g., a PDCCH channel configuration and a PDSCH channel configuration for enabling reception of SRB1), and / or other suitable information.

[0132] In some examples, the network node can use the tag-RNTI of the A-IoT device to scramble the cyclic redundancy check (CRC) bits of a radio channel message (e.g., PDCCH) destined for the A-IoT device. The A-IoT device can then use the tag-RNTI to decode the radio channel message.

[0133] Reader 1204 may receive RRC setup message 1224. The reader may send an association request 1226 to associate A-IoT device 1202 with reader 1204. Association request 1226 may include a temporary identifier (e.g., a tag-RNTI), a reader ID, and a list of one or more authorized readers (also referred to as an authorized reader list). In some examples, the reader may obtain a unique tag ID from RRC setup message 1224 and include the unique tag ID in association request 1226.

[0134] The A-IoT device 1202 may receive an association request 1226. The A-IoT device 1202 may associate at least the unique tag ID with the reader ID in response to the association request 1226. After the A-IoT device 1202 has associated its unique tag ID with at least a temporary identifier, a reader identifier, or a list of one or more authorized readers, the A-IoT device 1202 may send an association complete message 1228.

[0135] Reader 1204 may receive association complete message 1228 and may send RRC setup complete message 1230. In some examples, the RRC setup complete message (eg, RRC setup complete message 1230) confirms successful completion of the RRC connection establishment procedure.

[0136] The A-IoT device 1202, the reader 1204, the network node 1206, and the CN 1208 may each be configured to communicate with the network (e.g., Figure 13 The A-IoT device 1202 may generate a private key at 1232, 1234, 1236, or 1374 based on the public key and the unique tag ID. In some examples, the A-IoT device 1202 may generate a private key at 1232 based on the public key, the unique tag ID, and a reader ID of a reader associated with (e.g., paired with) the A-IoT device 1202.

[0137] The A-IoT device 1202, the reader 1204, the network node 1206, and the CN 1208 can use the private key to communicate between the A-IoT device 1202 and the CN 1208. In some examples, the private key can be used to protect signal transmissions (e.g., data transmissions) from the A-IoT device 1202 and / or signal transmissions received at the A-IoT device 1202 (e.g., integrity protection and encryption of these signal transmissions).

[0138] For example, reference Figure 12At 1235, the A-IoT device 1202 may encrypt a message (e.g., a data message intended for the CN 1208) based on the private key to generate an encrypted message. At 1236, the A-IoT device 1202 may send the encrypted message to the reader 1204. At 1238, the reader 1204 may forward the encrypted message to the network node 1206. At 1240, the network node 1206 may forward the encrypted message to the CN 1208. At 1242, the CN 1208 may decrypt the encrypted message using the private key. In some examples, the reader 1204 and / or the network code 1206 may decrypt the encrypted message using the private key.

[0139] Figure 13 is a signal flow diagram including an example of an authentication process 1220 according to various aspects of the present disclosure. Figure 13 It includes an A-IoT device 1202 , a reader 1204 , a network node 1206 , a CN 1208 and an application server 1350 .

[0140] At 1352, the A-IoT device 1202 generates a public key. In some examples, the A-IoT device 1202 generates the public key based on the tag product ID, electronic product code (EPC), and / or other product related information. For example, the tag product ID can be an identifier assigned by the manufacturer or supplier of the tag itself and can be stored in the tag ID (TID) memory of the tag. For example, the EPC can be an identifier that gives a unique identification to a specific product (e.g., the A-IoT device 1202) that includes the tag. In some examples, the EPC can be used with a database such as EPCglobal ™ In other examples, the EPC code may be non-EPCglobal ™ application.

[0141] In some aspects, the public key may be decrypted only by the application server 1350 or the CN 1208. For example, a network function at the CN 1208 may decrypt the public key. In some aspects, no reader may be able to decrypt the public key under the authorization of the CN 1208.

[0142] At 1354, the A-IoT device 1202 may protect information associated with the A-IoT device 1202 (e.g., product information) based on the public key to generate protected information 1356. In some examples, the product information may include at least a TID and an EPC associated with the A-IoT device 1202. In some examples, the A-IoT device 1202 may generate the protected information based on the public key by applying a key encapsulation mechanism (KEM) to encapsulate the information.

[0143] At 1356, the A-IoT device 1202 may send the protected information to the CN 1208 (e.g., via the reader 1204 and the network node 1206) to establish a secure tunnel between the A-IoT device 1202 and the CN 1208 or the application server 1350. In some aspects, the network function of the CN 1208 or the application server 1350 may decode the protected information. In these aspects, other network entities (e.g., the reader 1204, the network node 1206) may not decode the protected information. In some aspects, the reader 1204 is not allowed to transmit user data to and / or receive user data from the A-IoT device 1202 until the authentication process 1220 is complete.

[0144] At 1358, reader 1204 may forward the protected information to network node 1206. At 1360, network node 1206 may forward the protected information to CN 1208. At 1362, CN 1208 may decode the protected information.

[0145] CN 1208 or application server 1350 may be responsible for manufacturer information and application information verification and authorization. For example, at 1364, CN 1208 may attempt to verify product information. In some aspects, CN 1208 may optionally request application server 1350 to verify product information. For example, CN 1208 may send a verification request 1366 including product information for A-IoT device 1202. At 1368, application server 1350 may perform a verification operation on the product information in response to verification request 1366. Application server 1350 may send verification operation results 1370 to CN 1208.

[0146] If the CN 1208 determines (e.g., at 1364 or via the verification operation result 1370) that the product information is valid and is allowed to access the mobile network, the CN 1208 may deem the A-IoT device 1202 valid and may generate a unique tag ID for the A-IoT device 1202 at 1372. The A-IoT device 1202 may use the unique tag ID to communicate with the reader 1204.

[0147] CN 1208 can use different types of information to generate a unique tag ID. In one example, CN 1208 can generate a unique tag ID based on the previously described tag product ID (e.g., the tag ID stored in the TID memory) or a portion of the tag product ID and the EPC. For example, CN 1208 can generate a unique tag ID by concatenating the tag ID stored in the TID memory with the EPC. The EPC can be similar to the EPC of a radio frequency ID (RFID) product that complies with RFID specifications and can be verified by application server 1350. In some examples, other entities (e.g., reader 1204, network node 1206, CN 1208) may not be able to verify the EPC.

[0148] In another example, the CN 1208 may generate a unique tag ID by assigning a value that uniquely identifies the A-IoT device 1202 within the tracking area. In some examples, the value may be a temporary mobile subscriber identity (TMSI). For example, the unique tag ID is assigned by the CN 1208 when the A-IoT device 1202 has registered with the CN 1208 and the CN 1208 completes the authentication process 1220.

[0149] In another example, if the A-IoT device 1202 is not registered with a mobile network entity (eg, CN 1208 ) or is unable to access the mobile network, the CN 1208 may generate a random value and may assign the random value as the unique tag ID.

[0150] Figure 14 is a signal flow diagram 1400 according to various aspects of the present disclosure. Figure 14 A plurality of A-IoT devices are included, such as a first A-IoT device 1402 , a second A-IoT device 1404 , and an N th A-IoT device 1406 (eg, where N is a positive integer). Figure 14 Also included are a reader 1408, a network node 1410, and a core network (CN) 1412. Figure 14 , reader 1408 and network node 1410 can perform relay operations (e.g., operations similar to layer 2 and / or layer 3 relays) between A-IoT devices 1402, 1404, 1406 and CN 1412. In some aspects, signal flow diagram 1400 represents a connection establishment process (e.g., an RRC connection establishment process).

[0151] The reader 1408 may send a group query command 1414. In some aspects, the group query command 1414 may be included in one or more broadcast messages 1416, 1418, 1420 to the plurality of A-IoT devices 1402, 1404, 1406. In some examples, the group query command 1414 may be included in a single broadcast message that may be received at each of the A-IoT devices 1402, 1404, 1406.

[0152] In some examples, the group query command 1414 may include identifiers of the A-IoT devices 1402, 1404, 1406 (e.g., unique tag IDs assigned by the CN 1412). For example, the group query command 1414 may include a first unique tag ID associated with the first A-IoT device 1402, a second unique tag ID associated with the second A-IoT device 1404, and so on.

[0153] Each of the A-IoT devices 1402, 1404, 1406 may send a response message in response to the group query command 1414. For example, the first A-IoT device 1402 may send a first response message 1422, the second A-IoT device 1404 may send a second response message 1424, and the Nth A-IoT device 1406 may send an Nth response message 1426. In some examples, each of the response messages 1422, 1424, 1426 may include a unique tag ID of the sending A-IoT device. For example, the first response message 1422 may include the unique tag ID of the first A-IoT device 1402, the second response message 1424 may include the unique tag ID of the second A-IoT device 1404, and the Nth response message 1426 may include the unique tag ID of the Nth A-IoT device 1406.

[0154] In some examples, one or more of the response messages 1422, 1424, 1426 may include a reader ID with a unique tag ID. In some examples, the reader ID may identify the reader from which the A-IoT device received the unique tag ID of the A-IoT device. In one example scenario, if each of the A-IoT devices 1402, 1404, 1406 previously received a unique tag ID from reader 1408, each of the response messages 1422, 1424, 1426 may include a reader ID associated with reader 1408.

[0155] In some examples, each of the response messages 1422, 1424, and 1426 may include security information. For example, the security information may be a value that enables an integrity check of the response message at the receiving device. For example, the first A-IoT device 1402 may include first security information in the response message 1422, the second A-IoT device 1404 may include second security information in the response message 1424, and the Nth A-IoT device 1406 may include Nth security information in the response message 1426.

[0156] If the A-IoT devices 1402, 1404, 1406 are not currently connected to the network node 1410, the reader 1408 may assist the A-IoT devices 1402, 1404, 1406 in initiating a group RRC connection establishment with the network node 1410. For example, the reader 1408 may send an RRC setup request 1428 to the network node 1410 to assist the A-IoT devices 1402, 1404, 1406 in establishing an RRC connection with the network node 1410.

[0157] CN 1412 may perform an authentication process 1432 in response to initiating tag context setup message 1430. In some examples, CN 1412 may perform authentication process 1432 to determine whether each of A-IoT devices 1402, 1404, 1406 is allowed to access CN 1412, application servers, and / or other mobile network entities. CN 1412 may send a tag context setup message 1434 after completing authentication process 1432. Network node 1410 may receive tag context setup message 1434.

[0158] The network node 1410 may send an RRC setup message 1436 to the A-IoT devices 1402, 1404, and 1406 in response to the tag context setup message 1434. In some examples, the RRC setup message 1436 may include a temporary identifier. For example, the temporary identifier may be a radio network temporary identifier (RNTI) (also referred to as a group tag-RNTI) for the A-IoT devices 1402, 1404, and 1406. The A-IoT devices 1402, 1404, and 1406 may use the temporary identifier (e.g., the group tag-RNTI) to monitor a physical (PHY) channel.

[0159] The reader 1408 may receive the RRC setup message 1436. The reader may send a group association request 1438 (also referred to as a group association request message) to associate the A-IoT devices 1402, 1404, 1406 with the reader 1408. The group association request 1438 may include a set of unique tag IDs associated with the A-IoT devices 1402, 1404, 1406, a temporary identifier (e.g., a group tag-RNTI), a reader ID, and a list of one or more authorized readers (also referred to as an authorized reader list).

[0160] The A-IoT devices 1402, 1404, 1406 may receive a group association request 1438. In some aspects, the group association request 1438 may be included in one or more broadcast messages 1440, 1442, 1444 to the A-IoT devices 1402, 1404, 1406. In some examples, the group association request 1438 may be included in a single broadcast message that may be received at each of the A-IoT devices 1402, 1404, 1406.

[0161] At 1446, each of the A-IoT devices 1402, 1404, and 1406 may store association information based on the group association request 1438. As used herein, "association information" may include a tag-RNTI, a reader ID, a list of authorized readers, and / or other suitable information that the A-IoT device may use when associating with a reader (e.g., a serving reader) and / or when switching association to a different reader (e.g., a target reader). For example, at 1446, each of the A-IoT devices 1402, 1404, and 1406 may store the group tag-RNTI, the reader ID of the reader 1408 (also referred to as the serving reader), and the list of authorized readers.

[0162] Each of the A-IoT devices 1402, 1404, and 1406 may send an association complete message after storing the association information (e.g., at 1446). For example, the first A-IoT device 1402 may send a first association complete message 1448, the second A-IoT device 1404 may send a second association complete message 1450, and the Nth A-IoT device 1406 may send an Nth association complete message 1452. The reader 1408 may receive the association complete messages 1448, 1450, and 1452 and may send an RRC setup complete message 1454.

[0163] refer to Figure 14The described group signaling (e.g., group query command 1414 and group association request 1438) can reduce signaling overhead at reader 1408 and network node 1410. Considering typical large-scale IoT device scenarios, this reduction in signaling overhead can significantly improve network performance as the number of A-IoT devices increases. Group signaling can also reduce power consumption at reader 1408. Therefore, if reader 1408 is a battery-powered wireless communication device (such as a UE), this group signaling can extend the battery life of reader 1408 when supporting multiple A-IoT devices.

[0164] A-IoT device status

[0165] Figure 15 1500 is a diagram illustrating an example set of available states 1500 for an A-IoT device (e.g., A-IoT device 1202) as described herein. In some aspects, an A-IoT device can be in one of the available states 1500 at a given time.

[0166] like Figure 15 As shown, available state set 1500 may include an unregistered state 1502, a registered state 1504, and a terminated state 1510. In the unregistered state 1502, the A-IoT device is not registered with at least one mobile network entity (e.g., 5GCN). In this state, from the perspective of the mobile network (e.g., 5G NR network), the A-IoT device may be considered a new A-IoT device (also referred to as a new tag). After the A-IoT device has been identified and authorized to access the mobile network, it may transition to the registered state 1504.

[0167] The available state set 1500 may also include a registered state 1504. As previously described, an A-IoT device in this state has been identified and authorized to access a mobile network (e.g., a 5G NR network). Therefore, an A-IoT device in this state has been assigned a unique tag ID (e.g., from a core network such as CN 1208) and an RNTI (e.g., Tag-RNTI) from a network node (e.g., a base station) for communication.

[0168] like Figure 15As shown, an A-IoT device in a registered state 1504 can be in RRC_ON mode 1506 or in RRC_OFF mode 1508. In RRC_ON mode 1506, the A-IoT device can receive DL commands or can backscatter data. In RRC_OFF mode 1508, the A-IoT device cannot receive and / or process DL signals and cannot backscatter data. In some examples, the A-IoT device can transition to RRC_OFF mode 1508 when harvesting energy.

[0169] The set of available states 1500 may also include a terminated state 1510. In some aspects, the A-IoT device may transition to the terminated state 1510 in response to a valid terminate command. In the terminated state 1510, the A-IoT device is disabled. In some aspects, the terminated state 1510 may be permanent. In these aspects, the transition to the terminated state 1510 is irreversible, such that the A-IoT device cannot transition from the terminated state 1510 to any other state. For example, an A-IoT device in the terminated state 1510 cannot respond to any inventory messages.

[0170] Figure 16 A signal flow diagram 1600 is illustrated in accordance with various aspects of the present disclosure. Figure 16 It includes an A-IoT device 1602 , a service reader 1604 and a target reader 1606 .

[0171] exist Figure 16 , the A-IoT device 1602 may perform an initial association process 1608 to establish an association with the service reader 1604. For example, the service reader 1604 may send a query command 1610. The A-IoT device 1602 may receive the query command 1610 and may send a response message 1612. In some examples, the response message 1612 may include a unique tag ID associated with the A-IoT device 1602 and security information.

[0172] The serving reader 1604 may send an association request 1614 to associate the A-IoT device 1602 with the serving reader 1604. The association request 1614 may include a temporary identifier (e.g., a tag-RNTI) for communicating with a network node (e.g., a base station), the reader ID of the serving reader 1604, and a list of authorized readers. At 1616, the A-IoT device 1602 may store association information based on the association request 1614. For example, the A-IoT device 1602 may store the tag-RNTI, the reader ID of the serving reader 1604, and the list of authorized readers.

[0173] After storing the association information, the A-IoT device 1602 may send an association completion message 1618 (e.g., at 1616). The service reader 1604 may receive the association completion message 1618. Thereafter, if the A-IoT device 1602 receives a query command from the service reader 1604, the A-IoT device 1602 may send a response message including the reader ID of the service reader 1604.

[0174] exist Figure 16 In the example embodiment, the target reader 1606 may perform a discovery process 1620 to discover the A-IoT device 1602 and establish an association with the target reader 1606. For example, the target reader 1606 may send a discovery message 1622.

[0175] A discovery message can be a message that requests basic information from an A-IoT device (e.g., similar to a query command), but can additionally include a reader ID to indicate the source of the command. In some examples, after receiving a discovery message with a reader ID, the A-IoT device may be required to perform reader ID verification against a list of authorized reader IDs. The A-IoT device 1602 may receive the discovery message 1622 and obtain the reader ID of the target reader 1606 included in the discovery message 1622.

[0176] At 1624, the A-IoT device 1602 may perform a reader verification operation. In some examples, the A-IoT device 1602 may perform a reader verification operation by determining whether the reader ID of the target reader 1606 is included in the authorized reader list. If the reader ID of the target reader 1606 is included in the authorized reader list, the A-IoT device 1602 determines that the target reader 1606 is valid and sends a response message 1626. The response message 1626 may include the unique tag ID associated with the A-IoT device 1602, the reader ID of the serving reader 1604, and security information.

[0177] At 1628, the target reader 1606 communicates with the serving reader 1604 via a communication link (such as a side link or a Uu link) to authenticate the A-IoT device 1602. If authentication of the A-IoT device 1602 at 1628 is successful, the target reader 1606 may send an association reconfiguration message 1630 including a new tag-RNTI, the reader ID of the target reader 1606, and a new reader list. The A-IoT device 1602 may switch from its association with the serving reader 1604 to its association with the target reader 1606 in response to the association reconfiguration message 1630. The A-IoT device 1602 may send an association complete message 1632 indicating that the A-IoT device 1602 has switched to association with the target reader 1606.

[0178] Figure 17 A signal flow diagram 1700 is illustrated in accordance with various aspects of the present disclosure. Figure 17 Included are an A-IoT device 1702, a service reader 1704, a target reader 1706, and a network node 1708. In some aspects, the network node 1708 may include one or more network nodes, such as a base station and / or a core network device.

[0179] exist Figure 17 , the A-IoT device 1702 may perform an association process 1710 to establish an association with the service reader 1704. For example, the service reader 1704 may send a query command 1712. The A-IoT device 1702 may receive the query command 1712 and may send a response message 1714. In some examples, the response message 1714 may include a unique tag ID associated with the A-IoT device 1702 and security information.

[0180] The service reader 1704 may send a tag context acquisition message 1716 in response to the response message 1714. In some examples, the tag context acquisition message 1716 may include a unique tag ID associated with the A-IoT device 1702. The network node 1708 may receive the tag context acquisition message 1716.

[0181] In some aspects, the network node 1708 may store a tag context associated with the A-IoT device 1702 from a previous initial access procedure and connection establishment performed for the A-IoT device 1702. At 1718, the network node 1708 may perform an authentication operation for the A-IoT device 1702 based on the unique tag ID associated with the A-IoT device 1702. The network node 1708 may send a tag context response message 1720 including the result of the authentication operation. For example, if the authentication operation at 1718 is successful, the tag context response message 1720 may include a temporary identifier (e.g., a tag-RNTI) for communicating with the network node 1708, the unique tag ID of the A-IoT device 1702, and a list of authorized readers.

[0182] The serving reader 1704 may send an association request 1722 to associate the A-IoT device 1702 with the serving reader 1704. The association request 1722 may include a temporary identifier (e.g., a tag-RNTI) for communicating with a network node (e.g., a base station), the reader ID of the serving reader 1704, and a list of authorized readers. At 1724, the A-IoT device 1702 may store association information based on the association request 1722. For example, the A-IoT device 1702 may store the tag-RNTI, the reader ID of the serving reader 1704, and the list of authorized readers.

[0183] The A-IoT device 1702 may send an association completion message 1726 after storing the association information (e.g., at 1724). The service reader 1704 may receive the association completion message 1726. Thereafter, if the A-IoT device 1702 receives a query command (e.g., from the service reader 1704 or another reader), the A-IoT device 1702 may send a response message including the reader ID of the service reader 1704.

[0184] exist Figure 17 , the target reader 1706 may perform a discovery process 1728 to discover the A-IoT device 1702 and establish an association with the target reader 1706. For example, the target reader 1706 may send a discovery message 1730. The A-IoT device 1702 may receive the discovery message 1730 and may obtain a reader ID of the target reader 1706 included in the discovery message 1730.

[0185] At 1732, the A-IoT device 1702 may perform a reader verification operation. In some examples, the A-IoT device 1702 may perform the reader verification operation by determining whether the reader ID of the target reader 1706 is included in the authorized reader list. If the reader ID of the target reader 1706 is included in the authorized reader list, the A-IoT device 1702 determines that the target reader 1706 is valid and sends a response message 1734. The response message 1734 may include the unique tag ID associated with the A-IoT device 1702, the reader ID of the serving reader 1704, and security information.

[0186] The target reader 1706 may send a tag context acquisition message 1736 in response to the response message 1734. In some examples, the tag context acquisition message 1736 may include a unique tag ID associated with the A-IoT device 1702. The network node 1708 may receive the tag context acquisition message 1736.

[0187] At 1738, the network node 1708 may perform an authentication operation for the A-IoT device 1702 based on the unique tag ID associated with the A-IoT device 1702. If the authentication operation at 1738 is successful, the network node 1708 may send a tag context release message 1740 to the service reader 1704.

[0188] If the authentication operation at 1738 is successful, the network node 1708 may send a tag context response message 1742 including the result of the authentication operation. The tag context response message 1742 may include a temporary identifier (e.g., Tag-RNTI) for communicating with the network node (e.g., a base station), the unique tag ID of the A-IoT device 1702, and a list of authorized readers.

[0189] The target reader 1706 may send an association reconfiguration message 1744 including the new Tag-RNTI, the reader ID of the target reader 1706, and the authorized reader list. The A-IoT device 1702 may switch from its association with the serving reader 1704 to its association with the target reader 1706 in response to the association reconfiguration message 1744. The A-IoT device 1702 may send an association complete message 1746 indicating that the A-IoT device 1702 has switched to association with the target reader 1706.

[0190] Figure 18 A signal flow diagram 1800 is illustrated in accordance with various aspects of the present disclosure. Figure 18 Included are an A-IoT device 1802, a service reader 1804, a target reader 1806, and a network node 1808. In some aspects, the network node 1808 may be a base station.

[0191] exist Figure 18 , the A-IoT device 1802 may perform an association process 1810 to establish an association with the service reader 1804. For example, the service reader 1804 may send a query command 1812. The A-IoT device 1802 may receive the query command 1812 and may send a response message 1814. In some examples, the response message 1814 may include a unique tag ID associated with the A-IoT device 1802 and security information.

[0192] The service reader 1804 may send a tag context acquisition message 1816 in response to the response message 1814. In some examples, the tag context acquisition message 1816 may include a unique tag ID associated with the A-IoT device 1802. The network node 1808 may receive the tag context acquisition message 1816.

[0193] In some aspects, the network node 1808 may store a tag context associated with the A-IoT device 1802 from a previous initial access procedure and connection establishment performed for the A-IoT device 1802. At 1818, the network node 1808 may perform an authentication operation for the A-IoT device 1802 based on the unique tag ID associated with the A-IoT device 1802. The network node 1808 may send a tag context response message 1820 including the result of the authentication operation. For example, if the authentication operation at 1818 is successful, the tag context response message 1820 may include a temporary identifier (e.g., a tag-RNTI) for communicating with the network node 1808, the unique tag ID of the A-IoT device 1802, and a list of authorized readers.

[0194] The serving reader 1804 may send an association request 1822 to associate the A-IoT device 1802 with the serving reader 1804. The association request 1822 may include a temporary identifier (e.g., a tag-RNTI) for communicating with the network node 1808, the reader ID of the serving reader 1804, and a list of authorized readers. At 1824, the A-IoT device 1802 may store association information based on the association request 1822. For example, the A-IoT device 1802 may store the tag-RNTI, the reader ID of the serving reader 1804, and the list of authorized readers.

[0195] After storing the association information (e.g., at 1824), the A-IoT device 1802 may send an association completion message 1826. The service reader 1804 may receive the association completion message 1826. Thereafter, if the A-IoT device 1802 receives a query command (e.g., from the service reader 1804 or another reader), the A-IoT device 1802 may send a response message including the reader ID of the service reader 1804.

[0196] exist Figure 18 In the example embodiment, the target reader 1806 may perform a discovery process 1828 to discover the A-IoT device 1802 and establish an association with the target reader 1806. For example, the target reader 1806 may send a discovery message 1830. The A-IoT device 1802 may receive the discovery message 1830 and obtain a reader ID of the target reader 1806 included in the discovery message 1830.

[0197] At 1832, the A-IoT device 1802 may perform a reader verification operation. In some examples, the A-IoT device 1802 may perform the reader verification operation by determining whether the reader ID of the target reader 1806 is included in the authorized reader list. If the reader ID of the target reader 1806 is included in the authorized reader list, the A-IoT device 1802 determines that the target reader 1806 is valid and sends a response message 1834. The response message 1834 may include the unique tag ID associated with the A-IoT device 1802, the reader ID of the serving reader 1804, and security information.

[0198] The target reader 1806 may send a tag context acquisition message 1836 in response to the response message 1834. In some examples, the tag context acquisition message 1836 may include a unique tag ID associated with the A-IoT device 1802. The network node 1808 may receive the tag context acquisition message 1836.

[0199] At 1838, the network node 1808 may perform an authentication operation for the A-IoT device 1802 based on the unique tag ID associated with the A-IoT device 1802. If the authentication operation at 1838 is unsuccessful, the network node 1808 may not provide the tag context of the A-IoT device 1802 to the target reader 1806. In some examples, the network node 1808 may send a tag context failure message 1840, which may indicate to the target reader 1806 that the network node 1808 has refused to provide the tag context of the A-IoT device 1802. Therefore, the target reader 1806 may not request an association with the A-IoT device 1802. Figure 18In the example of , the A-IoT device 1802 may not switch from its association with the serving reader 1604 to its association with the target reader 160 .

[0200] Figure 19 A signal flow diagram 1900 is illustrated in accordance with various aspects of the present disclosure. Figure 19 The system includes an A-IoT device 1902, a serving reader 1904, and a plurality of target readers, such as a first target reader 1906, a second target reader 1908, and an Nth target reader 1910 (eg, where N is a positive integer), and a network node 1912. In some aspects, the network node 1912 may be a base station.

[0201] exist Figure 19 , the A-IoT device 1902 may perform an association process 1914 to establish an association with the service reader 1904. For example, the service reader 1904 may send a query command 1916. The A-IoT device 1902 may receive the query command 1916 and may send a response message 1918. In some examples, the response message 1918 may include a unique tag ID associated with the A-IoT device 1902 and security information.

[0202] The service reader 1904 may send a tag context acquisition message 1920 in response to the response message 1918. In some examples, the tag context acquisition message 1920 may include a unique tag ID associated with the A-IoT device 1902. The network node 1912 may receive the tag context acquisition message 1920.

[0203] In some aspects, the network node 1912 may store a tag context associated with the A-IoT device 1902 from a previous initial access procedure and connection establishment performed for the A-IoT device 1902. At 1922, the network node 1912 may perform an authentication operation for the A-IoT device 1902 based on the unique tag ID associated with the A-IoT device 1902. The network node 1912 may send a tag context response message 1924 including the result of the authentication operation. For example, if the authentication operation at 1922 is successful, the tag context response message 1924 may include a temporary identifier (e.g., a tag-RNTI) for communicating with the network node 1912, the unique tag ID of the A-IoT device 1902, and a list of authorized readers.

[0204] At 1926, network node 1912 may broadcast a list including at least one verified tag ID and an associated tag context to readers connected to network node 1912. For example, first target reader 1906, second target reader 1908, and Nth target reader 1910 may each receive the list including at least one verified tag ID and an associated tag context at 1926. In some examples, network node 1912 may broadcast the list (e.g., at 1926) to readers associated with a certain tracking area.

[0205] The serving reader 1904 may send an association request 1928 to associate the A-IoT device 1902 with the serving reader 1904. The association request 1928 may include a temporary identifier (e.g., a tag-RNTI) for communicating with the network node 1912, the reader ID of the serving reader 1904, and a list of authorized readers. At 1930, the A-IoT device 1902 may store association information based on the association request 1928. For example, the A-IoT device 1902 may store the tag-RNTI, the reader ID of the serving reader 1904, and the list of authorized readers.

[0206] After storing the association information (e.g., at 1930), the A-IoT device 1902 may send an association completion message 1932. The service reader 1904 may receive the association completion message 1932. Thereafter, if the A-IoT device 1902 receives a query command (e.g., from the service reader 1904 or another reader), the A-IoT device 1902 may send a response message including the reader ID of the service reader 1904.

[0207] In some aspects, one of the plurality of target readers, such as the second target reader 1908, may perform a discovery process 1934 to discover the A-IoT device 1902 and establish an association with the second target reader 1908. For example, the second target reader 1908 may send a discovery message 1936. The A-IoT device 1902 may receive the discovery message 1936 and may obtain a reader ID of the second target reader 1986 included in the discovery message 1936.

[0208] At 1938, the A-IoT device 1902 may perform a reader verification operation. In some examples, the A-IoT device 1902 may perform the reader verification operation by determining whether the reader ID of the second target reader 1908 is included in the authorized reader list. If the reader ID of the second target reader 1908 is included in the authorized reader list, the A-IoT device 1902 determines that the second target reader 1908 is valid and sends a response message 1940. The response message 1940 may include the unique tag ID associated with the A-IoT device 1902, the reader ID of the serving reader 1904, and security information.

[0209] At 1942, the second target reader 1908 may perform a tag ID verification operation for the A-IoT device 1902 based on the unique tag ID associated with the A-IoT device 1902. Since the second target reader 1908 has previously received (e.g., at 1926) a list including at least one verified tag ID and an associated tag context, the second target reader 1908 may perform tag ID verification at 1942 by identifying the unique tag ID of the A-IoT device 1902 in the list. In other words, if the unique tag ID is included in the list, the second target reader 1908 may consider the unique tag ID of the A-IoT device 1902 to be valid.

[0210] If the tag ID verification at 1942 is successful, the second target reader 1908 may send an associated reconfiguration message 1944 including a new tag-RNTI, the reader ID of the second target reader 1908, and an authorized reader list. For example, the second target reader 1908 may obtain the new tag-RNTI for the A-IoT device 1902 from the list received at 1926. For example, if the second target reader 1908 identifies a unique tag ID of the A-IoT device 1902 in the list, the second target reader 1908 may obtain the new tag-RNTI from the tag context associated with the unique tag ID in the list.

[0211] The A-IoT device 1902 may switch from its association with the serving reader 1904 to its association with the second target reader 1908 in response to the association reconfiguration message 1944. The A-IoT device 1902 may send an association complete message 1946 indicating that the A-IoT device 1902 has switched to association with the second target reader 1908.

[0212] In some aspects, if the second target reader 1908 cannot identify the unique tag ID of the A-IoT device 1902 in the list, the second target reader 1908 may send a tag context acquisition message including the unique tag ID associated with the A-IoT device 1902. If the A-IoT device 1802 can be authenticated at the network node 1912 based on the unique tag ID of the A-IoT device, the network node 1912 may receive the tag context acquisition message and may provide the tag context to the second target reader 1908.

[0213] It should be noted that reference Figure 19 The described aspects enable a target reader (e.g., the second target reader 1908) to verify the tag ID of the A-IoT device 1902 at the target reader. For example, a previously received list (e.g., at 1926) including at least one verified tag ID and associated tag context enables the second target reader 1908 to verify the tag ID of the A-IoT device 1902 and obtain the tag context of the A-IoT device 1902 without having to send a tag context get message to the network node 1912 and wait for a response from the network node 1912. This can significantly reduce signaling overhead and associated latency.

[0214] Figure 20 is a signal flow diagram 2000 according to various aspects of the present disclosure. Figure 20 Included are multiple A-IoT devices, such as a first A-IoT device 2002 , a second A-IoT device 2004 , and an N th A-IoT device 2006 (eg, where N is a positive integer). Figure 20 Also included is a service reader 2008 and a network node 2010. In some aspects, the network node 2010 may be a base station.

[0215] The service reader 2008 may send a group query command 2012. In some aspects, the group query command 2012 may be included in one or more broadcast messages 2014, 2016, 2018 to the A-IoT devices 2002, 2004, 2006. In some examples, the group query command 2012 may be included in a single broadcast message that may be received at each of the A-IoT devices 2002, 2004, 2006.

[0216] In some examples, the group query command 2012 may include identifiers (e.g., unique tag IDs assigned by the network node 2010) of the A-IoT devices 2002, 2004, and 2006. For example, the group query command 2012 may include a first unique tag ID associated with the first A-IoT device 2002, a second unique tag ID associated with the second A-IoT device 2004, and so on.

[0217] Each of the A-IoT devices 2002, 2004, and 2006 may send a response message in response to the group query command 2012. For example, the first A-IoT device 2002 may send a first response message 2020, the second A-IoT device 2004 may send a second response message 2022, and the Nth A-IoT device 2006 may send an Nth response message 2024. In some examples, each of the response messages 2020, 2022, and 2024 may include a unique tag ID of the sending A-IoT device. For example, the first response message 2020 may include the unique tag ID of the first A-IoT device 2002, the second response message 2022 may include the unique tag ID of the second A-IoT device 2004, and the Nth response message 2024 may include the unique tag ID of the Nth A-IoT device 2006.

[0218] In some examples, one or more of the response messages 2020, 2022, 2024 may include a reader ID with a unique tag ID. In some examples, the reader ID may identify the reader from which the A-IoT device received the unique tag ID of the A-IoT device. In one example scenario, if each of the A-IoT devices 2002, 2004, 2006 previously received a unique tag ID from the serving reader 2008, each of the response messages 2020, 2022, 2024 may include the reader ID associated with the serving reader 2008.

[0219] In some examples, each of the response messages 2020, 2022, 2024 may include security information. For example, the first A-IoT device 2002 may include first security information in the response message 2020, the second A-IoT device 2004 may include second security information in the response message 2022, and the Nth A-IoT device 2006 may include Nth security information in the response message 2024.

[0220] The service reader 2008 may send a tag context acquisition message 2026 (also referred to as a group tag context acquisition message) in response to the response messages 2020, 2022, and 2024. In some aspects, the tag context acquisition message 2026 may include multiple unique tag IDs of A-IoT devices (e.g., a set of unique tag IDs of A-IoT devices). For example, the tag context acquisition message 2026 may include the unique tag ID of the first A-IoT device 2002, the unique tag ID of the second A-IoT device 2004, and the unique tag ID of the Nth A-IoT device 2006. The network node 2010 may receive the tag context acquisition message 2026.

[0221] In some aspects, the network node 2010 may store tag context for one or more of the A-IoT devices 2002, 2004, 2006 from a previous initial access procedure and connection establishment operation performed for the A-IoT devices 2002, 2004, 2006. At 2028, the network node 2010 may perform an authentication operation for the A-IoT devices 2002, 2004, 2006 based on the unique tag IDs associated with the A-IoT devices 2002, 2004, 2006. The network node 2010 may send a tag context response message 2030 (also referred to as a group context response message) including the results of the authentication operation. For example, if the authentication operation at 2028 is successful, the tag context response message 2030 may include a temporary identifier for communicating with the network node 2010, a set of unique tag IDs associated with authorized A-IoT devices, and a list of authorized readers. For example, the temporary identifier may be an RNTI (also referred to as a group tag-RNTI) for the A-IoT devices 2002, 2004, 2006. The A-IoT devices 2002, 2004, 2006 may use the temporary identifier (eg, group tag-RNTI) to monitor a physical (PHY) channel.

[0222] In some cases, the network node 2010 may determine that one or more of the A-IoT devices 2002, 2004, 2006 are not authorized to communicate with the service reader 2008, the network node 2010, the application server, and / or other network entities coupled to the network node 2010. In these cases, the tag context response message 2030 may include a subset (also referred to as a partial set) of the multiple unique tag IDs of the A-IoT devices in the tag context get message 2026, where the subset includes the tag IDs of authorized A-IoT devices and omits the tag IDs of unauthorized A-IoT devices.

[0223] exist Figure 20 In the example, the network node 2010 may determine that the authentication operation of the Nth A-IoT device 2006 at 2028 has failed (e.g., the Nth A-IoT device 2006 is not authorized to communicate with the service reader 2008, the network node 2010, and / or other network entities coupled to the network node 2010), and may omit the unique tag ID of the Nth A-IoT device from the tag context response message 2030. Thus, in this example, the tag context response message 2030 may include the unique tag IDs of the first A-IoT device 2002 and the second A-IoT device 2004, and may not include the unique tag ID of the Nth A-IoT device 2006.

[0224] The service reader 2008 may send a message for authorizing an A-IoT device (e.g., Figure 20 2004) with the serving reader 2008. The group association request 2032 may include a temporary identifier (e.g., a group tag-RNTI), a reader ID, a list of one or more authorized readers (also referred to as an authorized reader list), and a set of unique tag IDs associated with the authorized A-IoT devices. For example, the set of unique tag IDs may include a subset (also referred to as a partial set) of the multiple unique tag IDs of the A-IoT devices in the tag context acquisition message 2026, where the subset includes the unique tag IDs of the first A-IoT device 2002 and the second A-IoT device 2004 and omits the unique tag ID of the Nth A-IoT device 2006.

[0225] The A-IoT devices 2002, 2004, 2006 may receive a group association request 2032. In some aspects, the group association request 2032 may be included in one or more broadcast messages 2034, 2036, 2038 to the plurality of A-IoT devices 2002, 2004, 2006. In some examples, the group association request 2032 may be included in a single broadcast message that may be received at each of the A-IoT devices 2002, 2004, 2006.

[0226] At 2039, the Nth A-IoT device 2006 may determine that it is not authorized to associate with the service reader 2008. In some examples, if the Nth A-IoT device 2006 determines that its unique tag ID is not included in the group association request 2032, the Nth A-IoT device 2006 may determine that it is not authorized to associate with the service reader 2008.

[0227] At 2040, each of the authorized A-IoT devices (e.g., A-IoT devices 2002, 2004) may store association information based on the group association request 2032. For example, each of the A-IoT devices 2002, 2004 may store the group tag-RNTI, the reader ID of the serving reader 2008, and a list of authorized readers.

[0228] Each of the authorized A-IoT devices 2002 and 2004 may send an association completion message after storing the association information (e.g., at 2040). For example, the first A-IoT device 2002 may send a first association completion message 2042, and the second A-IoT device 2004 may send a second association completion message 2044. The service reader 2008 may receive the association completion messages 2042 and 2044.

[0229] exist Figure 20middle, Figure 20 The tag context acquisition message 2026 and tag context response message 2030 in the group signaling protocol allow the service reader to obtain tag contexts for multiple A-IoT devices. Because the service reader 2008 can obtain tag contexts for multiple A-IoT devices using a single tag context acquisition message (e.g., tag context acquisition message 2026) and a single tag context response message (e.g., tag context response message 2030), signaling overhead between the service reader 2008 and the network node 2010 is reduced. Considering typical large-scale IoT device scenarios, this reduction in signaling overhead can significantly improve network performance as the number of A-IoT devices increases. Group signaling can also reduce power consumption at the service reader 2008. Therefore, if the service reader 2008 is a battery-powered wireless communication device (such as a UE), this group signaling can extend the battery life of the service reader 2008.

[0230] Figure 21A and Figure 21B 21 is a flow chart of a method of wireless communication. The method may be performed by an A-IoT device (e.g., A-IoT device 105, 502, 1202, 1402, 1404, 1406, 1602, 1702, 1802, 1902, 2002, 2004, 2006; apparatus 2302 / 2302′; processing system 2414, which may include memory 510 and may be the entire A-IoT device or a component of the A-IoT device, such as energy harvester 506 and / or control circuit 508). Figure 21A and Figure 21B In the figure, a box indicated by a dotted line indicates an optional box.

[0231] At 2102, the A-IoT device receives a query command. For example, Figure 12 , the A-IoT device 1202 may receive a query command 1212. The query command may be a message requesting basic information (such as a tag ID) from the A-IoT device.

[0232] At 2104, the A-IoT device sends a first message including at least a tag identifier assigned by the mobile network or an unregistered tag indicator in response to the query command. The tag identifier assigned by the mobile network can be a unique tag ID assigned to the A-IoT device at a mobile network entity (e.g., CN 1208). For example, referring to Figure 12 , the A-IoT device 1202 can send a response message 1214 in response to the query command 1212. In some examples, the response message 1214 can include a unique tag ID previously assigned by a mobile network entity such as CN 1208.

[0233] At 2106, the A-IoT device receives a second message including at least a temporary identifier for communicating with the network node, a reader identifier, or a list of authorized readers. In some aspects, the second message may be an association request from the reader. In some aspects, where the first message includes an unregistered tag indicator, the second message includes a tag identifier assigned by the mobile network. For example, referring to Figure 12 , the A-IoT device 1202 may receive an association request 1226 for associating the A-IoT device 1202 with the reader 1204. The association request 1226 may include a temporary identifier (e.g., a tag-RNTI), a reader ID, and a list of one or more authorized readers (also referred to as an authorized reader list). In some examples, the reader may obtain a unique tag ID from the RRC setup message 1224 and may include the unique tag ID in the association request 1226. In some examples, the A-IoT device 1202 is in one of a plurality of available states, where the plurality of available states includes at least an unregistered state, a registered state, and a terminated state.

[0234] At 2108, the A-IoT device associates the tag identifier assigned by the mobile network with at least a temporary identifier, a reader identifier, or an authorized reader list. Figure 12 , the A-IoT device 1202 may associate at least the unique tag ID with the reader ID in response to the association request 1226 .

[0235] At 2110, the A-IoT device sends a third message indicating that the tag identifier assigned by the mobile network has been associated with at least a temporary identifier, a reader identifier, or a list of authorized readers. In some aspects, the third message can be an association completion message. For example, after the A-IoT device 1202 has associated its unique tag ID with at least a temporary identifier, a reader identifier, or a list of one or more authorized readers, the A-IoT device 1202 can send an association completion message 1228.

[0236] At 2112, the A-IoT device enters a radio resource control (RRC) connected mode. For example, when the A-IoT device is in RRC connected mode, the A-IoT device can connect to a network node (e.g., via a reader, such as reader 1204). Thus, the A-IoT device can connect to a network node (e.g., Figure 12 At the network node 1206 in the example, radio resources are allocated to the A-IoT device.

[0237] At 2114, the A-IoT device receives a message from the target reader that includes at least the target reader identifier. In some examples, the message may be a discovery message. The discovery message may be a message that requests basic information from the A-IoT device (e.g., similar to a query command), but may additionally include a reader ID to indicate where the command is coming from. For example, referring to Figure 16 , the A-IoT device 1602 receives a discovery message 1622 from the target reader 1606 .

[0238] At 2116, the A-IoT device performs a verification operation based on the authorized reader list and the target reader identifier. Figure 16 , the A-IoT device 1602 may perform a reader verification operation at 1624 by determining whether the reader ID of the target reader 1606 is included in the authorized reader list. If the reader ID of the target reader 1606 is included in the authorized reader list, the A-IoT device 1602 determines that the target reader 1606 is valid.

[0239] At 2118, the A-IoT device sends a fourth message including at least the mobile network tag identifier and the reader identifier based on the verification operation. The fourth message may be a response message such as Figure 16 For example, if the reader ID of the target reader 1606 (e.g., Figure 16 If the tag ID is determined to be valid at 1624 in the example, the A-IoT device 1602 sends a response message 1626. The response message 1626 may include a unique tag ID associated with the A-IoT device 1602, a reader ID of the service reader 1604, and security information.

[0240] At 2120, the A-IoT device receives a fifth message that includes at least the second temporary identifier for communicating with the network node, the target reader identifier, or the second list of authorized readers. For example, the fifth message may be an association reconfiguration message from the target reader, such as the association reconfiguration message 1630 from the target reader 1606. For example, the second temporary identifier for communicating with the network node may be a new tag-RNTI for communicating with the target reader's network node.

[0241] At 2122, the A-IoT device associates the tag identifier assigned by the mobile network with at least a second temporary identifier, a target reader identifier, or a second list of authorized readers. For example, the A-IoT device 1602 can switch from its association with the serving reader 1604 to its association with the target reader 1606 in response to the association reconfiguration message 1630.

[0242] At 2124, the A-IoT device sends a sixth message indicating that the tag identifier assigned by the mobile network has been associated with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers. For example, the sixth message can be an association completion message such as Figure 16 An association complete message 1632 indicates that the A-IoT device 1602 has switched to association with the target reader 1606.

[0243] Figure 22 2200 is a flow chart of a method for wireless communication. The method may be performed by an A-IoT device (e.g., A-IoT device 105, 502, 1202, 1402, 1404, 1406, 1602, 1702, 1802, 1902, 2002, 2004, 2006; apparatus 2302 / 2302′; processing system 2414, which may include memory 510 and may be the entire A-IoT device or a component of the A-IoT device, such as energy harvester 506 and / or control circuit 508).

[0244] At 2202, the A-IoT device generates a public key. In some examples, refer to Figure 12 , the A-IoT device 1202 generates a public key based on the tag product ID, electronic product code (EPC) and / or other product related information.

[0245] At 2204, the A-IoT device performs a process based on a method for performing ... Figure 13 In some examples, the product information includes at least a label product identifier or an electronic product code of the A-IoT device.

[0246] At 2206 , the A-IoT device generates a private key based on at least the public key, a tag identifier assigned by the mobile network, or a reader identifier.

[0247] At 2208 , the A-IoT device encrypts a message to an entity associated with the mobile network based on the private key to obtain an encrypted message.

[0248] At 2210 , the A-IoT device sends the encrypted message.

[0249] Figure 2323 is a conceptual data flow diagram 2300 illustrating the flow of data between different parts / components in an example apparatus 2302. The apparatus may be an A-IoT device. The apparatus 2302 may communicate with a reader 2350 (such as a UE as described herein). The apparatus includes a receiving component 2304 that receives a signal 2318. The signal 2318 may include at least a forward link. In some examples, the signal 2318 may include a forward link and a continuous wave.

[0250] The apparatus also includes a message sending component 2306 that sends a first message including at least a tag identifier assigned by the mobile network or an unregistered tag indicator in response to a query command (e.g., via signals 2328, 2320 and a sending component 2316); sends at least a portion of product information associated with the A-IoT device based on a public key used to authenticate the apparatus at a mobile network entity or an application server; sends a third message indicating that the tag identifier assigned by the mobile network has been associated with at least a temporary identifier, a reader identifier, or a list of authorized readers; sends an encrypted message; sends a fourth message including at least the mobile network tag identifier and the reader identifier based on a verification operation; and sends a sixth message indicating that the tag identifier assigned by the mobile network has been associated with at least a second temporary identifier, a target reader identifier, or a second list of authorized readers.

[0251] In some aspects, message sending component 2306 receives signal 2332 indicating that the mobile network assigned tag identifier has been associated with at least a temporary identifier, a reader identifier, or a list of authorized readers, or that the mobile network assigned tag identifier has been associated with at least a second temporary identifier, a target reader identifier, or a second list of authorized readers. Mode entry component 2312 can enter radio resource control connected mode in response to signal 2334. In some cases, message sending component 2306 receives signal 2324, which can include information received at message and command receiving component 2308.

[0252] The apparatus also includes a message and command receiving component 2308 that receives (e.g., via signals 2318, 2322 and receiving component 2304) a query command, a second message including at least a temporary identifier for communicating with the network node, a reader identifier, or a list of authorized readers; receives a message from the target reader including at least the target reader identifier; and receives a fifth message including at least a second temporary identifier for communicating with the network node, the target reader identifier, or a second list of authorized readers.

[0253] The apparatus also includes an associating component 2310 that associates the tag identifier assigned by the mobile network with at least a temporary identifier, a reader identifier, or a list of authorized readers; and associates the tag identifier assigned by the mobile network with at least a second temporary identifier, a target reader identifier, or a second list of authorized readers. For example, the associating component 2310 can receive the temporary identifier, the reader identifier, and / or the authorized reader list from the message and command receiving component via signal 2326.

[0254] The apparatus also includes a mode entry component 2312 that enters a radio resource control connected mode. In some aspects, the mode entry component 2312 receives a signal 2334 indicating that the tag identifier assigned by the mobile network has been associated with at least a temporary identifier, a reader identifier, or a list of authorized readers, or that the tag identifier assigned by the mobile network has been associated with at least a second temporary identifier, a target reader identifier, or a second list of authorized readers. The mode entry component 2312 may enter the radio resource control connected mode in response to the signal 2334.

[0255] The apparatus also includes a security management component 2314 that generates a public key; generates a private key based on at least the public key and a tag identifier or reader identifier assigned by the mobile network; encrypts a message to an entity associated with the mobile network based on the private key to obtain an encrypted message; and performs an authentication operation based on the authorized reader list and the target reader identifier. In some examples, the security management component 2314 may decrypt an encrypted message received via signal 2328, or may encrypt a message for transmission and provide the encrypted message via signal 2330.

[0256] The apparatus also includes a transmitting component 2316 that transmits a signal 2320. The signal 2320 can include a backscatter link (eg, a modulated backscatter signal).

[0257] The apparatus may include executing Figure 21A 、 Figure 21B 、 Figure 22 Each of the boxes in the algorithm in the preceding flowchart is an additional component. Therefore, Figure 21A 、 Figure 21B 、 Figure 22 Each block in the aforementioned flow chart may be performed by a component, and the apparatus may include one or more of these components. These components may be one or more hardware components specifically configured to perform the stated process / algorithm, implemented by a processor configured to perform the stated process / algorithm, stored in a computer-readable medium for implementation by a processor, or some combination thereof.

[0258] Figure 2424 is a diagram illustrating an example of a hardware implementation for an apparatus 2302′ employing a processing system 2414. Processing system 2414 may be implemented using a bus architecture, generally represented by bus 2424. Bus 2424 may include any number of interconnecting buses and bridges, depending on the specific application of processing system 2414 and the overall design constraints. Bus 2424 links various circuits together, including one or more processors and / or hardware components (represented by processor 2404, components 2304, 2306, 2308, 2310, 2312, 2314, 2316, and computer-readable medium / memory 2406). Bus 2424 may also link various other circuits, such as timing sources, peripherals, voltage regulators, power management circuits (which may include, for example, energy harvester 2405), etc., which are well known in the art and will not be described further. The bus 2424 may further link a tag ID (TID) memory 2407 for storing an identifier assigned by a manufacturer or supplier of a tag (eg, an A-IoT device).

[0259] Processing system 2414 may be coupled to transceiver 2410. Transceiver 2410 is coupled to one or more antennas 2420. Transceiver 2410 provides components for communicating with various other devices via a transmission medium. Transceiver 2410 receives signals from one or more antennas 2420, extracts information from the received signals, and provides the extracted information to processing system 2414 (specifically, receiving component 2304). Furthermore, transceiver 2410 receives information from processing system 2414 (specifically, transmitting component 2316) and, based on the received information, generates signals (e.g., modulated backscatter signals) to be applied to one or more antennas 2420. Processing system 2414 includes processor 2404 coupled to computer-readable medium / memory 2406. Processor 2404 is responsible for general processing, including executing software stored on computer-readable medium / memory 2406. This software, when executed by processor 2404, enables processing system 2414 to perform the various functions described above for any particular device. The computer-readable medium / memory 2406 may also be used to store data manipulated by the processor 2404 when executing software. The processing system 2414 also includes at least one of the components 2304, 2306, 2308, 2310, 2312, 2314, 2316. These components may be software components running in the processor 2404, residing / stored in the computer-readable medium / memory 2406, one or more hardware components coupled to the processor 2404, or some combination thereof. The processing system 2414 may be a component of the A-IoT device 502 and may include the memory 510 and / or the control circuitry 508. Alternatively, the processing system 2414 may be the entire A-IoT device (e.g., see Figure 5 502).

[0260] In one configuration, the apparatus 2302 / 2302' for wireless communication includes: a component for receiving a query command; a component for sending a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command; a component for receiving a second message including at least a temporary identifier, a reader identifier, or an authorized reader list for communicating with a network node; a component for generating a public key; a component for sending at least a portion of product information associated with the apparatus based on the public key for authentication of the apparatus at a mobile network entity or an application server; a component for associating the tag identifier assigned by the mobile network with at least the temporary identifier, the reader identifier, or the authorized reader list; a component for sending a third message indicating that the tag identifier assigned by the mobile network has been associated with at least the temporary identifier, the reader identifier, or the authorized reader list; a component for entering a radio resource control connected mode; a component for authenticating the device based on at least the public key, the tag identifier assigned by the mobile network, and the temporary identifier, the reader identifier, or the authorized reader list. a component for generating a private key based on a tag identifier or a reader identifier assigned by the mobile network; a component for encrypting a message for an entity associated with the mobile network based on the private key to obtain an encrypted message; a component for sending the encrypted message; a component for receiving a message including at least a target reader identifier from a target reader; a component for performing a verification operation based on the authorized reader list and the target reader identifier; a component for sending a fourth message including at least a mobile network tag identifier and a reader identifier based on the verification operation; a component for receiving a fifth message including at least a second temporary identifier for communicating with a network node, a target reader identifier, or a second list of authorized readers; a component for associating the tag identifier assigned by the mobile network with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers; and a component for sending a sixth message indicating that the tag identifier assigned by the mobile network has been associated with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers.

[0261] The aforementioned means may be one or more of the aforementioned components of the processing system 2414 of the device 2302 and / or the device 2302′ configured to perform the functions recited by the aforementioned means. As described above, the processing system 2414 may include the control circuit 508. Therefore, in one configuration, the aforementioned means may be the control circuit 508 configured to perform the functions recited by the aforementioned means.

[0262] Figure 252500 is a flow chart of a method of wireless communication. The method may be performed by a network node (e.g., base station 102, network nodes 1206, 1410, 1708, 1808, 1912, 2010; device 2602 / 2602'; processing system 2714, which may include memory 376 and may be the entire network node or a component of the network node, such as TX processor 316, RX processor 370 and / or controller / processor 375). Figure 25 In the figure, a box indicated by a dotted line indicates an optional box.

[0263] At 2502, the network node receives a radio resource control establishment request for a tag device. Figure 12 , the network node 1206 may receive an RRC establishment request 1216 from the reader 1204 .

[0264] At 2504, the network node sends a request for initiating context establishment for the tag device, wherein the request includes at least a tag identifier assigned by the mobile network or an unregistered tag indicator. In some examples, the request for initiating context establishment for the tag device may be a reference to Figure 12 The described initiation tag context establishment message 1218. For example, refer to Figure 12 , the network node 1206 can attempt to identify the A-IoT device 1202 from the RRC setup request 1216. If the network node 1206 cannot identify the A-IoT device 1202, the network node 1206 can send an initiate tag context setup message 1218. In some examples, the initiate tag context setup message 1218 can be configured to initiate a tag context setup procedure at the CN 1208.

[0265] At 2506, the network node receives a context setup message that includes at least a tag identifier assigned by the mobile network. For example, the context setup message may be tag context setup message 1222. In some examples, tag context setup message 1222 may include a unique tag ID for A-IoT device 1202.

[0266] At 2508, the network node sends a radio resource control (RRC) setup message including at least a temporary identifier for the tag device. For example, the RRC setup message may be a reference Figure 12 The RRC setup message 1224 for the A-IoT device 1202 is described. In some examples, the RRC setup message 1224 can include a unique tag ID. In some examples, the RRC setup message 1224 can include a temporary identifier. For example, the temporary identifier can be a tag-RNTI.

[0267] At 2510, the network node receives a radio resource control (RRC) setup complete message for the tag device. For example, the RRC setup complete message may be Figure 12 RRC establishment completion message 1230 in.

[0268] At 2512, the network node receives a request for one or more tag contexts. For example, the request for one or more tag contexts can be a tag context get message 1716, 1736, 1816, 1836, 1920, 2026 as described herein.

[0269] At 2514, the network node performs an authentication operation based on the tag identifier set in the request. For example, the network node may perform the authentication operations at 1718, 1738, 1818, 1838, 1922, 2028 as described herein.

[0270] At 2516, the network node sends one of a tag context response message or a tag context failure message based on the authentication operation, the tag context response message including at least one tag context of the one or more tag contexts and the authorized reader list. For example, the network node may send the tag context response messages 1720, 1742, 1820, 1924, 2030. For example, the network node may send the tag context failure message 1840.

[0271] At 2518 , the network node sends a tag context release message to the service reader based on the authentication operation. For example, the network node 1708 may send a tag context release message 1740 to the service reader 1704 based on the authentication operation at 1738 .

[0272] At 2520, the network node sends one or more verified tag identifiers to a plurality of target readers, wherein the one or more verified tag identifiers are based on the tag identifier set in the request. Figure 19 At 1926 , the network node 1912 may broadcast a list including at least one verified tag ID and an associated tag context to readers connected to the network node 1912 (eg, the first target reader 1906 , the second target reader 1908 , and the Nth target reader 1910 ).

[0273] Figure 26 26 is a conceptual data flow diagram 2600 illustrating the flow of data between different parts / components in an example apparatus 2602. The apparatus can be a network node. The network includes a receiving component 2604 that receives a UL signal 2614 from a reader 2650 (e.g., a UE) and a signal 2616 from a core network device 2660.

[0274] The apparatus also includes a message and request receiving component 2606 that receives a radio resource control establishment request for a tag device (e.g., via UL signal 2614 and signal 2622); receives a context establishment message including at least a tag identifier assigned by a mobile network (e.g., via signal 2616 and signal 2622); and receives a radio resource control establishment completion message for the tag device (e.g., via UL signal 2614 and signal 2622); and receives a request for one or more tag contexts (e.g., via UL signal 2614 and signal 2622).

[0275] The apparatus also includes a message and request sending component 2608 that sends a request for initiating context establishment for a tag device (e.g., via signal 2630 and signal 2620), wherein the request includes at least a tag identifier assigned by a mobile network or an unregistered tag indicator; sends a radio resource control establishment message (e.g., via signal 2630 and DL signal 2618) that includes at least a temporary identifier for the tag device; sends one of a tag context response message or a tag context failure message based on an authentication operation (e.g., via signal 2630 and DL signal 2618), wherein the tag context response message includes at least one tag context of one or more tag contexts and a list of authorized readers; sends a tag context release message to a serving reader based on the authentication operation (e.g., via signal 2630 and DL signal 2618); and sends one or more verified tag identifiers to a plurality of target readers, wherein the one or more verified tag identifiers are based on the tag identifier set in the request. In some cases, the message and request sending component 2608 receives a signal 2628 , which may include information received at the message and request receiving component 2606 .

[0276] The apparatus also includes an authentication component 2610 that performs an authentication operation based on the tag identifier set in the request. For example, the authentication component 2610 can receive a request including a tag identifier set via signal 2624 and can authenticate one or more tag identifiers in the tag identifier set. The authentication component 2610 can provide a result of the authentication operation via signal 2626.

[0277] The apparatus also includes a transmitting component 2612 that transmits a DL signal 2618 to the reader 2650 and transmits a signal to the core network device 2660 .

[0278] The apparatus may include executing Figure 25 Each of the boxes in the algorithm in the preceding flowchart is an additional component. Therefore, Figure 25Each block in the foregoing flow charts may be performed by a component, and the apparatus may include one or more of those components. These components may be one or more hardware components specifically configured to perform the stated process / algorithm, implemented by a processor configured to perform the stated process / algorithm, stored in a computer-readable medium for implementation by a processor, or some combination thereof.

[0279] Figure 27 FIG27 is a diagram illustrating an example of a hardware implementation for an apparatus 2602′ employing a processing system 2714. The processing system 2714 may be implemented using a bus architecture, generally represented by a bus 2724. The bus 2724 may include any number of interconnecting buses and bridges, depending on the specific application of the processing system 2714 and the overall design constraints. The bus 2724 connects various circuits together, including one or more processors and / or hardware components represented by the processor 2704, components 2604, 2606, 2608, 2610, 2612, and computer-readable medium / memory 2706. The bus 2724 may also link various other circuits, such as timing sources, peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further.

[0280] Processing system 2714 may be coupled to transceiver 2710. Transceiver 2710 is coupled to one or more antennas 2720. Transceiver 2710 provides components for communicating with various other devices via a transmission medium. Transceiver 2710 receives signals from one or more antennas 2720, extracts information from the received signals, and provides the extracted information to processing system 2714 (specifically, receiving component 2604). Furthermore, transceiver 2710 receives information from processing system 2714 (specifically, transmitting component 2612) and, based on the received information, generates signals to be applied to one or more antennas 2720. Processing system 2714 includes processor 2704 coupled to computer-readable medium / memory 2706. Processor 2704 is responsible for general processing, including executing software stored on computer-readable medium / memory 2706. This software, when executed by processor 2704, enables processing system 2714 to perform the various functions described above for any particular device. The computer-readable medium / memory 2706 may also be used to store data that is manipulated by the processor 2704 when executing software. The processing system 2714 also includes at least one of the components 2604, 2606, 2608, 2610, 2612. These components may be software components running in the processor 2704, residing / stored in the computer-readable medium / memory 2706, one or more hardware components coupled to the processor 2704, or some combination thereof. The processing system 2714 may be a component of the base station 310 and may include the memory 376 and / or at least one of the TX processor 316, the RX processor 370, and the controller / processor 375. Alternatively, the processing system 2714 may be the entire base station (e.g., see Figure 3 310).

[0281] In one configuration, an apparatus 2602 / 2602' for wireless communication includes: a component for receiving a radio resource control establishment request for a tag device; a component for sending a request for initiating context establishment for the tag device, wherein the request includes at least a tag identifier assigned by a mobile network or an unregistered tag indicator; a component for receiving a context establishment message including at least a tag identifier assigned by a mobile network; a component for sending a radio resource control establishment message including at least a temporary identifier for the tag device; a component for receiving a radio resource control establishment completion message for the tag device; a component for receiving a request for one or more tag contexts; a component for performing an authentication operation based on a set of tag identifiers in the request; a component for sending one of a tag context response message or a tag context failure message based on the authentication operation, the tag context response message including at least one tag context of the one or more tag contexts and a list of authorized readers; a component for sending a tag context release message to a serving reader based on the authentication operation; and a component for sending one or more verified tag identifiers to a plurality of target readers, wherein the one or more verified tag identifiers are based on the set of tag identifiers in the request.

[0282] The aforementioned means may be one or more of the aforementioned components of the processing system 2714 of the device 2602 and / or the device 2602' configured to perform the functions recited by the aforementioned means. As described above, the processing system 2714 may include the TX processor 316, the RX processor 370, and the controller / processor 375. Therefore, in one configuration, the aforementioned means may be the TX processor 316, the RX processor 370, and the controller / processor 375 configured to perform the functions recited by the aforementioned means.

[0283] Figure 28A and Figure 28B 2800 is a flow chart of a method of wireless communication. The method may be performed by a reader (e.g., UE 104, reader 504, 1204, 1408, 1604, 1606, 1704, 1706, 1804, 1806, 1904, 1906, 1908, 1910, 2008; apparatus 3002 / 3002'; processing system 3114, which may include memory 360 and may be the entire reader or a component of the reader. For example, if the reader is implemented as a UE (e.g., UE 350), the aforementioned components of the reader may be TX processor 368, RX processor 356, and / or controller / processor 359. In Figure 28A and Figure 28B In the figure, a box indicated by a dotted line indicates an optional box.

[0284] refer to Figure 28AAt 2802, the reader sends a query command. Figure 12 , the reader 1204 may send a query command 1212 .

[0285] At 2804, the reader receives a first message including at least a tag identifier assigned by the mobile network or an unregistered tag indicator in response to the query command. Figure 12 , reader 1204 can receive a response message 1214 in response to query command 1212. In some examples, response message 1214 can include a unique tag ID previously assigned by a mobile network entity such as CN 1208.

[0286] In some aspects, the query command is a group query command broadcast to a plurality of tag devices, and the first message is one message in a set of messages from the plurality of tag devices based on the group query command.

[0287] At 2806, the reader sends a radio resource control setup request message including the tag identifier assigned by the mobile network to the network node in response to the first message. Figure 12 , the reader 1204 may send an RRC establishment request 1216 to the network node 1206 .

[0288] At 2808, the reader receives a radio resource control (RRC) setup message from the network node that includes at least a temporary identifier. For example, the RRC setup message may be a reference Figure 12 The RRC setup message 1224 for the A-IoT device 1202 is described. In some examples, the RRC setup message 1224 can include a unique tag ID. In some examples, the RRC setup message 1224 can include a temporary identifier. For example, the temporary identifier can be a tag-RNTI.

[0289] At 2810, the reader sends a second message including at least a temporary identifier, a reader identifier, or a list of authorized readers for communicating with the network node. For example, the second message may be an association request. Figure 12 For example, reader 1204 may send an association request 1226 to associate A-IoT device 1202 with reader 1204. Association request 1226 may include a temporary identifier (e.g., a tag-RNTI), a reader ID, and a list of one or more authorized readers (also referred to as an authorized reader list). In some examples, the reader may obtain a unique tag ID from RRC setup message 1224 and may include the unique tag ID in association request 1226.

[0290] At 2812, the reader receives a third message indicating that the tag identifier assigned by the mobile network has been associated with at least a temporary identifier, a reader identifier, or a list of authorized readers. In some aspects, the third message can be an association complete message. For example, after the A-IoT device 1202 has associated its unique tag ID with at least a temporary identifier, a reader identifier, or a list of one or more authorized readers, the A-IoT device 1202 can send an association complete message 1228.

[0291] In some aspects, the second message is a group association request message broadcast to multiple tag devices, and the third message is one message in a set of messages from the multiple tag devices based on the group association request message.

[0292] At 2814, the reader receives a broadcast message including a list of verified mobile network assigned tag identifiers and a tag context set associated with the verified mobile network assigned tag identifiers, wherein the authentication operation is based on the list of verified mobile network assigned tag identifiers. Figure 19 At 1926, the network node 1912 may broadcast a list including at least one verified tag ID and an associated tag context to readers connected to the network node 1912. For example, the first target reader 1906, the second target reader 1908, and the Nth target reader 1910 may each receive the list including at least one verified tag ID and an associated tag context at 1926.

[0293] At 2816, the reader sends a radio resource control (RRC) setup complete message for the tag device to the network node. For example, the RRC setup complete message may be Figure 12 RRC establishment completion message 1230 in.

[0294] At 2818, the reader sends a message including at least a reader identifier to the tag device associated with the serving reader. In some examples, the message may be a discovery message. A discovery message may be a message that requests basic information from an A-IoT device (e.g., similar to a query command), but may additionally include a reader ID to indicate where the command is coming from. For example, referring to Figure 16 , the target reader 1606 sends a discovery message 1622 to the A-IoT device 1602 .

[0295] refer to Figure 28B At 2820, the reader receives a response message including at least the tag identifier assigned by the second mobile network and the service reader identifier. For example, if the reader ID of the target reader 1606 (e.g., Figure 16If the tag ID of the serving reader 1604 is determined to be valid, the target reader 1606 receives a response message 1626. The response message 1626 may include a unique tag ID associated with the A-IoT device 1602, a reader ID of the serving reader 1604, and security information.

[0296] At 2822, the reader performs an authentication operation based on at least the tag identifier assigned by the second mobile network.

[0297] At 2824, the reader sends an association reconfiguration message that includes at least a second temporary identifier for communicating with the network node, a reader identifier, or a second list of authorized readers. For example, the target reader 1606 may send the association reconfiguration message 1630. For example, the second temporary identifier for communicating with the network node may be a new tag-RNTI for communicating with the target reader's network node.

[0298] At 2826, the reader receives a message indicating that the second mobile network assigned tag identifier has been associated with at least a second temporary identifier, a reader identifier, or a second list of authorized readers. For example, the message may be an association complete message such as Figure 16 An association complete message 1632 indicates that the A-IoT device 1602 has switched to association with the target reader 1606.

[0299] Figure 29 2900 is a flow chart of a method of wireless communication. The method may be performed by a reader (e.g., UE 104, reader 504, 1204, 1408, 1604, 1606, 1704, 1706, 1804, 1806, 1904, 1906, 1908, 1910, 2008; apparatus 3002 / 3002'; processing system 3114, which may include memory 360 and may be the entire reader or a component of the reader. For example, if the reader is implemented as a UE (e.g., UE 350), the aforementioned components of the reader may be TX processor 368, RX processor 356, and / or controller / processor 359. In Figure 29 In the figure, a box indicated by a dotted line indicates an optional box.

[0300] At 2902, the reader sends a query command. For example, refer to Figure 17 , the service reader 1704 can send a query command 1712.

[0301] At 2904, the reader receives a first message including at least a tag identifier assigned by the mobile network or an unregistered tag indicator in response to the query command. In some examples, the first message may be a response message 1714, which may include a unique tag ID associated with the A-IoT device 1702 and security information.

[0302] At 2906, the reader sends a request for one or more tag contexts, where the request includes a set of mobile network-assigned tag identifiers associated with the one or more tag contexts. In some examples, the request for one or more tag contexts can be a tag context get message 1716. In some examples, the tag context get message 1716 can include a unique tag ID associated with the A-IoT device 1702.

[0303] At 2908, the reader receives a tag context response message or a tag context fail message, wherein the tag context response message includes at least one tag context of the one or more tag contexts and a second list of authorized readers based on the authentication operation, and wherein the tag context failure message indicates that at least one tag context of the one or more tag contexts cannot be provided to the device (e.g., the reader).

[0304] At 2910, the reader sends a second message including at least a temporary identifier, a reader identifier, or a list of authorized readers for communicating with the network node. In some examples, the second message may be an association request, such as a reference to Figure 17 Described association request 1722. The association request 1722 may include a temporary identifier (eg, tag-RNTI) for communicating with a network node (eg, a base station), a reader ID of the serving reader 1704, and a list of authorized readers.

[0305] At 2912, the reader receives a third message indicating that the tag identifier assigned by the mobile network has been associated with at least the temporary identifier, the reader identifier, or the authorized reader list. In some examples, the third message may be an association complete message, such as a reference message. Figure 17 The association is complete message 1726 as described.

[0306] At 2914, the reader receives a tag context release message from the network node based on the result of the authentication operation associated with the tag identifier assigned by the mobile network. For example, if the authentication operation at 1738 is successful, the service reader 1704 may receive a tag context release message 1740.

[0307] Figure 30 is a conceptual data flow diagram 3000 illustrating the flow of data between different parts / components in an example apparatus 3002. The apparatus may be a reader (eg, a UE).

[0308] The apparatus includes a receiving component 3004 that receives a signal 3016 from a first A-IoT device 3050, a signal 3017 from a second A-IoT device 3052, a signal 3018 from a reader device 3070, and a DL signal 3020 from a network node. Signals 3016 and 3017 may include a backscatter link (e.g., a modulated backscatter signal). Signal 3018 may be received via a side link or a Uu link.

[0309] The apparatus includes a message receiving component 3006 that receives, in response to a query command, a first message including at least a mobile network-assigned tag identifier or an unregistered tag indicator (e.g., via a signal 3016 and a signal 3028 from a first A-IoT device 3050); receives, from a network node (e.g., via a DL signal 3020 and a signal 3028 from a network node 3060), a radio resource control setup message including at least a temporary identifier; receives, from a network node (e.g., via a signal 3016 and a signal 3028 from the first A-IoT device 3050), a third message indicating that the mobile network-assigned tag identifier has been associated with at least a temporary identifier, a reader identifier, or an authorized reader list; receives, from a network node (e.g., via a signal 3020 and a signal 3028 from the first A-IoT device 3050), a broadcast message including a list of verified mobile network-assigned tag identifiers and a set of tag contexts associated with the verified mobile network-assigned tag identifiers; and receives, from a second A-IoT device 3052 (e.g., via a signal 3017 and a signal 3028 from the second A-IoT device 3052). 3028) receiving a response message including at least a tag identifier assigned by the second mobile network and a serving reader identifier; receiving a response message (e.g., via signal 3017 and signal 3028 from the second A-IoT device 3052) indicating that the tag identifier assigned by the second mobile network has been associated with at least a second temporary identifier, a reader identifier, or a second list of authorized readers; receiving a tag context response message or a tag context failure message (e.g., via signal 3020 and signal 3028 from the network node 3060), wherein the tag context response message includes at least one tag context of the one or more tag contexts and the second list of authorized readers based on the authentication operation, and wherein the tag context failure message indicates that at least one tag context of the one or more tag contexts cannot be provided to the apparatus; receiving a tag context release message from the network node 3060 based on a result of the authentication operation associated with the tag identifier assigned by the mobile network (e.g., via signal 3020 and signal 3028 from the network node 3060). In some aspects, the message receiving component 3006 can decrypt the encrypted message based on the private key.

[0310] The apparatus includes a message and command sending component 3008 that sends a query command (e.g., via signal 3036 and signal 3022); sends a radio resource control setup request message including a tag identifier assigned by a mobile network to a network node 3060 in response to a first message (e.g., via signal 3036 and UL signal 3026); sends a second message including at least a temporary identifier, a reader identifier, or an authorized reader list for communicating with the network node (e.g., via signal 3036 and signal 3022); For example, a radio resource control establishment completion message for the tag device is sent to the network node 3060 via signal 3036 and UL signal 3026; a message including at least a reader identifier is sent to the tag device associated with the serving reader (e.g., the second A-IoT device 3052) (e.g., via signal 3036 and signal 3023); and an association reconfiguration message including at least a second temporary identifier, a reader identifier, or a second list of authorized readers for communicating with the network node is sent (e.g., via signal 3036 and signal 3023). In some aspects, the message and command sending component 3008 may encrypt the message or command based on a private key before sending. In some cases, the message and command sending component 3008 receives signal 3034, which may include information received at the message receiving component 3006.

[0311] The apparatus includes an authentication component 3010 that performs an authentication operation based on at least a tag identifier assigned by the second mobile network. For example, the authentication component 3010 may receive the tag identifier assigned by the mobile network of the second A-IoT device 3052 via a signal 3030 from the message receiving component, and may perform an authentication operation based on the tag identifier assigned by the mobile network of the second A-IoT device 3052. The authentication component 3010 may provide a result of the authentication operation (e.g., success or failure) to the message and command sending component 3008 via a signal 3032.

[0312] The apparatus includes a tag context request sending component 3012 that sends a request for one or more tag contexts (e.g., via signal 3040 and UL signal 3026), wherein the request includes a set of mobile network-assigned tag identifiers associated with the one or more tag contexts. For example, tag context request sending component 3012 can send the request for one or more tag contexts in response to signal 3038 from message receiving component 3006 that includes the set of mobile network-assigned tag identifiers.

[0313] The apparatus includes a transmitting component 3014 that transmits a signal 3022 to a first A-IoT device 3050, a signal 3023 to a second A-IoT device 3052, a signal 3024 to a reader device 3070, and a UL signal 3026 to a network node 3060. In some examples, the signal 3022 may include at least a forward link. In some examples, the signal 3022 may include a continuous wave and a forward link. The signal 3024 may be transmitted via a side link or a Uu link.

[0314] The apparatus may include executing Figure 28A 、 Figure 28B 、 Figure 29 Each of the boxes in the algorithm in the preceding flowchart is an additional component. Therefore, Figure 28A 、 Figure 28B 、 Figure 29 Each block in the aforementioned flow chart may be performed by a component, and the apparatus may include one or more of these components. These components may be one or more hardware components specifically configured to perform the stated process / algorithm, implemented by a processor configured to perform the stated process / algorithm, stored in a computer-readable medium for implementation by a processor, or some combination thereof.

[0315] Figure 31 FIG31 is a diagram illustrating an example of a hardware implementation for an apparatus 3002′ employing a processing system 3114. Processing system 3114 may be implemented using a bus architecture, generally represented by bus 3124. Bus 3124 may include any number of interconnecting buses and bridges, depending on the specific application of processing system 3114 and the overall design constraints. Bus 3124 links various circuits together, including one or more processors and / or hardware components (represented by processor 3104, components 3004, 3006, 3008, 3010, 3012, 3014, and computer-readable medium / memory 3106). Bus 3124 may also link various other circuits, such as timing sources, peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further.

[0316] The processing system 3114 may be coupled to the transceiver 3110. The transceiver 3110 is coupled to one or more antennas 3120. The transceiver 3110 provides components for communicating with various other devices via a transmission medium. The transceiver 3110 receives signals from the one or more antennas 3120, extracts information from the received signals, and provides the extracted information to the processing system 3114 (specifically, the receiving component 3004). Furthermore, the transceiver 3110 receives information from the processing system 3114 (specifically, the transmitting component 3014) and, based on the received information, generates signals to be applied to the one or more antennas 3120. The processing system 3114 includes a processor 3104 coupled to a computer-readable medium / memory 3106. The processor 3104 is responsible for general processing, including executing software stored on the computer-readable medium / memory 3106. When executed by the processor 3104, this software enables the processing system 3114 to perform the various functions described above for any particular device. The computer-readable medium / memory 3106 may also be used to store data that is manipulated by the processor 3104 when executing software. The processing system 3114 also includes at least one of the components 3004, 3006, 3008, 3010, 3012, 3014. These components may be software components running in the processor 3104, residing / stored in the computer-readable medium / memory 3106, one or more hardware components coupled to the processor 3104, or some combination thereof. The processing system 3114 may be a component of the UE 350 and may include the memory 360 and / or at least one of the TX processor 368, the RX processor 356, and the controller / processor 359. Alternatively, the processing system 3114 may be the entire UE (e.g., see Figure 3 of 350).

[0317] In one configuration, an apparatus 3002 / 3002′ for wireless communication includes: means for sending a query command; means for receiving a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command; means for sending a radio resource control setup request message including the tag identifier assigned by the mobile network to a network node in response to the first message; means for receiving a radio resource control setup message including at least a temporary identifier from the network node; means for sending a second message including at least a temporary identifier, a reader identifier, or an authorized reader list for communicating with the network node; means for receiving a third message indicating that a tag identifier assigned by a mobile network has been associated with at least a temporary identifier, a reader identifier, or an authorized reader list; means for receiving a broadcast message comprising a list of verified tag identifiers assigned by the mobile network and a set of tag contexts associated with the verified tag identifiers assigned by the mobile network, wherein the authentication operation is based on the list of verified tag identifiers assigned by the mobile network; means for sending a radio resource control setup complete message for the tag device to the network node; means for sending a message comprising at least a reader identifier to the tag device associated with the serving reader; a tag context response message or a tag context failure message, wherein the tag context response message includes at least one tag context of the one or more tag contexts and a second list of authorized readers based on the authentication operation, and wherein the tag context failure message indicates that at least one tag context of the one or more tag contexts cannot be provided to the apparatus; and a tag context release message from the network node based on a result of the authentication operation associated with the tag identifier assigned by the mobile network.

[0318] The aforementioned means may be one or more of the aforementioned components of the processing system 3114 of the apparatus 3002 and / or the apparatus 3002′ configured to perform the functions recited by the aforementioned means. As described above, the processing system 3114 may include the TX processor 368, the RX processor 356, and the controller / processor 359. Therefore, in one configuration, the aforementioned means may be the TX processor 368, the RX processor 356, and the controller / processor 359 configured to perform the functions recited by the aforementioned means.

[0319] Figure 32 3200 is a flow chart of a method of wireless communication. The method may be performed by a core network device (eg, CN 1208, 1412; apparatus 3302 / 3302'; processing system 3414). Figure 32 In the figure, a box indicated by a dotted line indicates an optional box.

[0320] At 3202, the core network device receives a request for initiating context establishment for a tag device in a mobile network. In some examples, the request for initiating context establishment for a tag device may be a reference to Figure 12 Described initiate tag context establishment message 1218. In some examples, initiate tag context establishment message 1218 can be configured to initiate a tag context establishment process at a core network device (eg, CN 1208).

[0321] At 3204, the core network device performs an authentication operation for the tag device. Figure 12 , CN 1208 may perform an authentication process 1220 in response to the initiate tag context establishment message 1218. Figure 13 An example of an authentication process 1220 is described.

[0322] At 3206, the core network device assigns a tag identifier to the tag device based on the authentication operation. In some examples, the authentication process 1220 may allow the CN 1208 to register the A-IoT device 1202. For example, the CN 1208 may perform the authentication process 1220 with the A-IoT device 1202 to generate and assign a unique tag ID for the A-IoT device 1202. For example, if the authentication process 1220 is successful, the CN 1208 may generate and assign a unique tag ID for the A-IoT device 1202. In various aspects described herein, when a unique tag ID has been assigned to the A-IoT device 1202, the A-IoT device 1202 may be considered registered with the CN 1208.

[0323] At 3208, the core network device sends a context setup message including at least the tag identifier. For example, CN 1208 may send tag context setup message 1222 after completing authentication process 1220. In some examples, tag context setup message 1222 may include the unique tag ID of A-IoT 1202.

[0324] At 3210, the core network device generates a private key (eg, at 1374) based on at least the public key, the tag identifier, or the reader identifier.

[0325] At 3212, the core network device receives the encrypted message from the tag device. For example, CN 1208 may receive Figure 12 The encrypted message at 1240 in .

[0326] At 3214 , the core network device (eg, at 1242 ) decrypts the encrypted message based on the private key.

[0327] Figure 33 is a conceptual data flow diagram 3300 illustrating the flow of data between different parts / components in an example apparatus 3302. The apparatus may be a core network device.

[0328] The apparatus includes a receiving component 3304 that receives a signal 3316 from a network node 3350 (eg, a base station).

[0329] The apparatus also includes a message and request receiving component 3306 that receives a request to initiate context establishment for a tag device in a mobile network (e.g., via signal 3320 and signal 3316) and receives an encrypted message from the tag device (e.g., via signal 3320 and signal 3316).

[0330] The apparatus also includes a message sending component 3308 that sends a context establishment message including at least the tag identifier (e.g., via signal 3332 and signal 3318). In some cases, message sending component 3308 receives signal 3322, which can include information received at message and request receiving component 3306.

[0331] The apparatus also includes an authentication and security component 3310 that performs authentication operations for the tag device, generates a private key based on at least a public key, a tag identifier, or a reader identifier, decrypts encrypted messages based on the private key, and encrypts messages (e.g., intended for an A-IoT device) based on the private key. For example, the authentication and security component 3310 can receive a message or request from the message and request receiving component via signal 3324. For example, the authentication and security component 3310 can provide the result of the authentication operation (e.g., success or failure) to the tag identifier assignment component 3312 via signal 3326 and / or to the message sending component 3308 via signal 3330.

[0332] The apparatus also includes a tag identifier assigning component 3312 that assigns a tag identifier to the tag device based on the authentication operation. For example, the tag identifier assigning component 3312 may receive a result (e.g., success or failure) of the authentication operation via signal 3326 and, if the authentication operation is successful, may provide a tag identifier (e.g., a unique tag identifier for the A-IoT device) via signal 3328.

[0333] The apparatus also includes a sending component 3314 that sends a signal 3318 to a network node 3350 .

[0334] The apparatus may include executing Figure 32 Each of the boxes in the algorithm in the preceding flowchart is an additional component. Therefore, Figure 32 Each block in the foregoing flow charts may be performed by a component, and the apparatus may include one or more of those components. These components may be one or more hardware components specifically configured to perform the stated process / algorithm, implemented by a processor configured to perform the stated process / algorithm, stored in a computer-readable medium for implementation by a processor, or some combination thereof.

[0335] Figure 34FIG3400 is a diagram illustrating an example of a hardware implementation for an apparatus 3302′ employing a processing system 3414. Processing system 3414 may be implemented using a bus architecture, generally represented by bus 3424. Bus 3424 may include any number of interconnecting buses and bridges, depending on the specific application of processing system 3414 and the overall design constraints. Bus 3424 links various circuits together, including one or more processors and / or hardware components (represented by processor 3404, components 3304, 3306, 3308, 3310, 3312, 3314, and computer-readable medium / memory 3406). Bus 3424 may also link various other circuits, such as timing sources, peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further.

[0336] Processing system 3414 may be coupled to transceiver 3410. Transceiver 3410 is coupled to one or more antennas 3420. Transceiver 3410 provides components for communicating with various other devices via a transmission medium. Transceiver 3410 receives signals from one or more antennas 3420, extracts information from the received signals, and provides the extracted information to processing system 3414 (specifically, receiving component 3304). Furthermore, transceiver 3410 receives information from processing system 3414 (specifically, transmitting component 3314) and, based on the received information, generates signals to be applied to one or more antennas 3420. Processing system 3414 includes processor 3404 coupled to computer-readable medium / memory 3406. Processor 3404 is responsible for general processing, including executing software stored on computer-readable medium / memory 3406. This software, when executed by processor 3404, enables processing system 3414 to perform the various functions described above for any particular device. Computer-readable medium / memory 3406 may also be used to store data manipulated by processor 3404 when executing software. Processing system 3414 also includes at least one of components 3304, 3306, 3308, 3310, 3312, and 3314. These components may be software components running on processor 3404, residing / stored in computer-readable medium / memory 3406, one or more hardware components coupled to processor 3404, or some combination thereof. Processing system 3414 may be a component of a core network device. Alternatively, processing system 3414 may be the entire core network device.

[0337] In one configuration, the apparatus 3302 / 3302' for wireless communication includes: a component for receiving a request for initiating context establishment for a tag device in a mobile network; a component for performing an authentication operation for the tag device; a component for assigning a tag identifier to the tag device based on the authentication operation; a component for sending a context establishment message including at least the tag identifier; a component for generating a private key based on at least a public key, a tag identifier, or a reader identifier; a component for receiving an encrypted message from the tag device; and a component for decrypting the encrypted message based on the private key. The aforementioned components may be one or more of the aforementioned components of the apparatus 3302 and / or the processing system 3414 of the apparatus 3302' configured to perform the functions recited by the aforementioned components.

[0338] The following provides an overview of various aspects of the disclosure:

[0339] Aspect 1: An apparatus for wireless communication, the apparatus comprising: a memory; and at least one processor, the at least one processor being coupled to the memory and configured to: receive a query command; send a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command; and receive a second message including at least a temporary identifier for communicating with a network node, a reader identifier, or an authorized reader list.

[0340] Aspect 2: The apparatus according to Aspect 1, wherein the at least one processor is further configured to: associate the tag identifier assigned by the mobile network with at least the temporary identifier, the reader identifier, or the authorized reader list; send a third message indicating that the tag identifier assigned by the mobile network has been associated with at least the temporary identifier, the reader identifier, or the authorized reader list; and enter a radio resource control connection mode.

[0341] Aspect 3: The apparatus according to aspect 1 or 2, wherein, in a case where the first message includes the unregistered tag indicator, the second message includes a tag identifier assigned by the mobile network.

[0342] Aspect 4: The apparatus according to any one of aspects 1 to 3, wherein the apparatus is in one of a plurality of available states, wherein the plurality of available states include at least an unregistered state, a registered state, and a terminated state.

[0343] Aspect 5: An apparatus according to any one of Aspects 1 to 4, wherein the at least one processor is further configured to: generate a public key; and send at least a portion of product information associated with the apparatus based on the public key for authentication of the apparatus at a mobile network entity or an application server.

[0344] Aspect 6: The apparatus according to any one of aspects 1 to 5, wherein the product information comprises at least a label product identifier or an electronic product code.

[0345] Aspect 7: An apparatus according to any one of Aspects 1 to 6, wherein the at least one processor is further configured to: generate a private key based at least on the public key, a tag identifier or a reader identifier assigned by the mobile network; encrypt a message for an entity associated with the mobile network based on the private key to obtain an encrypted message; and send the encrypted message.

[0346] Aspect 8: An apparatus according to any one of Aspects 1 to 7, wherein the at least one processor is further configured to: receive a message including at least a target reader identifier from a target reader; perform a verification operation based on the authorized reader list and the target reader identifier; send a fourth message including at least the mobile network tag identifier and the reader identifier based on the verification operation; receive a fifth message including at least a second temporary identifier for communicating with the network node, the target reader identifier, or a second list of authorized readers; associate the tag identifier assigned by the mobile network with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers; and send a sixth message indicating that the tag identifier assigned by the mobile network has been associated with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers.

[0347] Aspect 9: An apparatus for wireless communication, the apparatus comprising: a memory; and at least one processor, the at least one processor being coupled to the memory and configured to: receive a radio resource control establishment request for a tag device; send a request for initiating context establishment for the tag device, wherein the request includes at least a tag identifier assigned by a mobile network or an unregistered tag indicator; receive a context establishment message including at least the tag identifier assigned by the mobile network; send a radio resource control establishment message including at least a temporary identifier for the tag device; and receive a radio resource control establishment completion message for the tag device.

[0348] Aspect 10: An apparatus according to Aspect 9, wherein the at least one processor is further configured to: receive a request for one or more tag contexts; perform an authentication operation based on a set of tag identifiers in the request; and send one of a tag context response message or a tag context failure message based on the authentication operation, the tag context response message including at least one tag context of the one or more tag contexts and a list of authorized readers.

[0349] Aspect 11: The apparatus of aspect 9 or 10, wherein the request is received from a target reader, wherein the at least one processor is further configured to: send a tag context release message to a serving reader based on the authentication operation.

[0350] Aspect 12: An apparatus according to any one of Aspects 9 to 11, wherein the at least one processor is further configured to: send one or more verified tag identifiers to a plurality of target readers, wherein the one or more verified tag identifiers are based on the set of tag identifiers in the request.

[0351] Aspect 13: The apparatus according to any one of aspects 9 to 12, wherein the tag context response message includes a subset of the set of tag identifiers associated with the at least one tag context.

[0352] Aspect 14: The apparatus according to any one of aspects 9 to 13, wherein the tag device is in one of a plurality of available states, wherein the plurality of available states at least include an unregistered state, a registered state, and a terminated state.

[0353] Aspect 15: An apparatus for wireless communication, the apparatus comprising: a memory; and at least one processor, the at least one processor being coupled to the memory and configured to: send a query command; receive a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command; and send a second message including at least a temporary identifier for communicating with a network node, a reader identifier, or an authorized reader list.

[0354] Aspect 16: The apparatus according to aspect 15, wherein the at least one processor is further configured to: receive a third message indicating that the mobile network assigned tag identifier has been associated with at least the temporary identifier, the reader identifier, or the authorized reader list.

[0355] Aspect 17: The apparatus according to aspect 15 or 16, wherein, in a case where the first message includes the unregistered tag indicator, the second message includes a tag identifier assigned by the mobile network.

[0356] Aspect 18: An apparatus according to any one of Aspects 15 to 17, wherein the at least one processor is further configured to: send a radio resource control establishment request message including the tag identifier assigned by the mobile network to a network node in response to the first message; receive a radio resource control establishment message including at least the temporary identifier from the network node; and send a radio resource control establishment completion message for the tag device to the network node.

[0357] Aspect 19: The apparatus according to any one of aspects 15 to 18, wherein the tag device is in one of a plurality of available states, wherein the plurality of available states at least include an unregistered state, a registered state, and a terminated state.

[0358] Aspect 20: An apparatus according to any one of Aspects 15 to 19, wherein the query command is a group query command broadcast to multiple tag devices, and the first message is one message in a set of messages from the multiple tag devices based on the group query command.

[0359] Aspect 21: An apparatus according to any one of Aspects 15 to 20, wherein the second message is a group association request message broadcast to multiple tag devices, and the third message is one message in a set of messages from the multiple tag devices based on the group association request message.

[0360] Aspect 22: An apparatus according to any one of Aspects 15 to 21, wherein the at least one processor is further configured to: send a request for one or more tag contexts, wherein the request includes a set of mobile network-assigned tag identifiers associated with the one or more tag contexts; and receive a tag context response message or a tag context failure message, wherein the tag context response message includes at least one tag context of the one or more tag contexts and a second list of authorized readers based on an authentication operation, and wherein the tag context failure message indicates that the at least one tag context of the one or more tag contexts cannot be provided to the apparatus.

[0361] Aspect 23: An apparatus according to any one of aspects 15 to 22, wherein the request is received from a target reader, wherein the at least one processor is further configured to: receive a tag context release message from the network node based on a result of an authentication operation associated with the tag identifier assigned by the mobile network.

[0362] Aspect 24: An apparatus according to any one of Aspects 15 to 23, wherein the at least one processor is further configured to: send a message including at least the reader identifier to a tag device associated with a service reader; receive a response message including at least a tag identifier assigned by a second mobile network and a service reader identifier; perform an authentication operation based at least on the tag identifier assigned by the second mobile network; send an association reconfiguration message including at least a second temporary identifier for communicating with a network node, the reader identifier or a second list of authorized readers; and receive a message indicating that the tag identifier assigned by the second mobile network has been associated with at least the second temporary identifier, the reader identifier or the second list of authorized readers.

[0363] Aspect 25: An apparatus according to any one of Aspects 15 to 24, wherein the at least one processor is further configured to: send a request for a tag context associated with a tag identifier assigned by the second mobile network; and receive a tag context response message including the tag context and the second list of authorized readers.

[0364] Aspect 26: An apparatus according to any one of Aspects 15 to 25, wherein the at least one processor is further configured to: receive a broadcast message comprising a list of verified mobile network assigned tag identifiers and a set of tag contexts associated with the verified mobile network assigned tag identifiers, wherein the authentication operation is based on the list of verified mobile network assigned tag identifiers.

[0365] Aspect 27: An apparatus for wireless communication, the apparatus comprising: a memory; and at least one processor, the at least one processor being coupled to the memory and configured to: receive a request for initiating context establishment for a tag device in a mobile network; perform an authentication operation for the tag device; assign a tag identifier to the tag device based on the authentication operation; and send a context establishment message including at least the tag identifier.

[0366] Aspect 28: An apparatus according to Aspect 27, wherein the at least one processor configured to perform the authentication operation for the tag device is further configured to: receive at least a portion of product information associated with the tag device, wherein the portion of the product information is protected based on a public key; and verify the portion of the product information.

[0367] Aspect 29: The apparatus according to aspect 27 or 28, wherein the product information comprises at least a label product identifier or an electronic product code.

[0368] Aspect 30: An apparatus according to any one of Aspects 27 to 29, wherein the at least one processor is further configured to: generate a private key based at least on the public key, the tag identifier, or the reader identifier; receive an encrypted message from the tag device; and decrypt the encrypted message based on the private key.

[0369] It should be understood that the specific order or hierarchy of blocks in the disclosed process / flowchart is merely illustrative of exemplary methods. It should be understood that the specific order or hierarchy of blocks in the process / flowchart may be rearranged based on design preferences. In addition, some blocks may be combined or omitted. The accompanying method claims present elements of various blocks in a sample order, but are not intended to be limited to the specific order or hierarchy presented.

[0370] The foregoing description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects. Therefore, the claims are not intended to be limited to the aspects shown herein, but to conform to the full scope consistent with the language claims, wherein elements mentioned in the singular are not intended to represent "one and only one", unless specifically stated so, but rather "one or more". The word "exemplary" is used herein to mean "serving as an example, instance, or illustration". Any aspect described herein as "exemplary" is not necessarily interpreted as being preferred or having advantages over other aspects. Unless otherwise specifically stated, the term "some" refers to one or more. Combinations such as "at least one of A, B, or C", "one or more of A, B, or C", "at least one of A, B, and C", "one or more of A, B, and C", and "A, B, C, or any combination thereof" include any combination of A, B, and / or C, which may include multiple A, multiple B, or multiple C. Specifically, combinations such as “at least one of A, B, or C,” “one or more of A, B, or C,” “at least one of A, B, and C,” “one or more of A, B, and C,” and “A, B, C, or any combination thereof” may be A only, B only, C only, A and B, A and C, B and C, or A and B and C, where any such combination may include one or more members of A, B, or C. All structural and functional equivalents to the elements of the various aspects described throughout this disclosure that are or later become known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be encompassed by the claims. In addition, nothing disclosed herein is intended to be dedicated to the public regardless of whether such disclosure is expressly recited in the claims. Words such as “module,” “mechanism,” “element,” “device,” etc. are not intended to be substituted for the word “component.” Thus, no claim element is to be construed as part-plus-function unless the element is expressly recited using the phrase “component for….”

Claims

1. A device for wireless communication, the device comprising: Memory; and at least one processor coupled to the memory and configured to: Receive query commands; sending a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command; and A second message is received including at least a temporary identifier for communicating with the network node, a reader identifier, or a list of authorized readers.

2. The apparatus of claim 1 , wherein the at least one processor is further configured to: associating the mobile network assigned tag identifier with at least the temporary identifier, the reader identifier, or the authorized reader list; sending a third message indicating that the mobile network assigned tag identifier has been associated with at least the temporary identifier, the reader identifier, or the authorized reader list; and Enter RRC connected mode. 3 . The apparatus of claim 1 , wherein if the first message includes the unregistered tag indicator, the second message includes a tag identifier assigned by the mobile network. 4 . The apparatus according to claim 1 , wherein the apparatus is in one of a plurality of available states, wherein the plurality of available states include at least an unregistered state, a registered state, and a terminated state.

5. The apparatus of claim 1 , wherein the at least one processor is further configured to: Generate a public key; and At least a portion of product information associated with the device is sent based on the public key for authentication of the device at a mobile network entity or an application server. The apparatus according to claim 5 , wherein the product information comprises at least a label product identifier or an electronic product code.

7. The apparatus of claim 5, wherein the at least one processor is further configured to: generating a private key based on at least the public key and a tag identifier or a reader identifier assigned by the mobile network; encrypting a message directed to an entity associated with the mobile network based on the private key to obtain an encrypted message; and The encrypted message is sent.

8. The apparatus of claim 2, wherein the at least one processor is further configured to: receiving a message from a target reader including at least a target reader identifier; performing an authentication operation based on the authorized reader list and the target reader identifier; sending a fourth message including at least the mobile network tag identifier and the reader identifier based on the verification operation; receiving a fifth message comprising at least a second temporary identifier for communicating with the network node, the target reader identifier, or a second list of authorized readers; associating the mobile network-assigned tag identifier with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers; as well as A sixth message is sent indicating that the mobile network-assigned tag identifier has been associated with at least the second temporary identifier, the target reader identifier, or the second list of authorized readers.

9. An apparatus for wireless communication, the apparatus comprising: Memory; and at least one processor coupled to the memory and configured to: receiving a radio resource control establishment request for a tag device; Sending a request for initiating context establishment for the tag device, wherein the request includes at least a tag identifier assigned by a mobile network or an unregistered tag indicator; receiving a context establishment message including at least a tag identifier assigned by the mobile network; sending a radio resource control setup message including at least a temporary identifier for the tag device; as well as A radio resource control establishment completion message for the tag device is received.

10. The apparatus of claim 9, wherein the at least one processor is further configured to: receiving a request for one or more tag contexts; performing an authentication operation based on the tag identifier set in the request; and One of a tag context response message or a tag context failure message is sent based on the authentication operation, the tag context response message including at least one tag context of the one or more tag contexts and an authorized reader list.

11. The apparatus of claim 10, wherein the request is received from a target reader, wherein the at least one processor is further configured to: A tag context release message is sent to a service reader based on the authentication operation.

12. The apparatus of claim 10, wherein the at least one processor is further configured to: One or more verified tag identifiers are sent to a plurality of target readers, wherein the one or more verified tag identifiers are based on the set of tag identifiers in the request.

13. The apparatus of claim 10, wherein the tag context response message comprises a subset of the set of tag identifiers associated with the at least one tag context. 14 . The apparatus according to claim 9 , wherein the tag device is in one of a plurality of available states, wherein the plurality of available states at least include an unregistered state, a registered state, and a terminated state.

15. An apparatus for wireless communication, the apparatus comprising: Memory; and at least one processor coupled to the memory and configured to: Send query command; receiving a first message including at least a tag identifier assigned by a mobile network or an unregistered tag indicator in response to the query command; and A second message is sent including at least a temporary identifier for communicating with the network node, a reader identifier, or a list of authorized readers.

16. The apparatus of claim 15, wherein the at least one processor is further configured to: A third message is received indicating that the mobile network-assigned tag identifier has been associated with at least the temporary identifier, the reader identifier, or the authorized reader list.

17. The apparatus of claim 15, wherein if the first message includes the unregistered tag indicator, the second message includes a tag identifier assigned by the mobile network.

18. The apparatus of claim 15, wherein the at least one processor is further configured to: sending, in response to the first message, a radio resource control setup request message including the mobile network assigned tag identifier to a network node; receiving a radio resource control setup message from the network node including at least the temporary identifier; and A radio resource control establishment completion message for the tag device is sent to the network node. 19 . The apparatus according to claim 18 , wherein the tag device is in one of a plurality of available states, wherein the plurality of available states at least include an unregistered state, a registered state, and a terminated state. 20 . The apparatus according to claim 15 , wherein the query command is a group query command broadcast to a plurality of tag devices, and the first message is one message in a set of messages from the plurality of tag devices based on the group query command. 21 . The apparatus according to claim 16 , wherein the second message is a group association request message broadcast to a plurality of tag devices, and the third message is one message in a set of messages from the plurality of tag devices based on the group association request message.

22. The apparatus of claim 15, wherein the at least one processor is further configured to: sending a request for one or more tag contexts, wherein the request includes a set of mobile network-assigned tag identifiers associated with the one or more tag contexts; and A tag context response message or a tag context failure message is received, wherein the tag context response message includes at least one tag context of the one or more tag contexts and a second list of authorized readers based on the authentication operation, and wherein the tag context failure message indicates that the at least one tag context of the one or more tag contexts cannot be provided to the device.

23. The apparatus of claim 15, wherein the request is received from a target reader, wherein the at least one processor is further configured to: A tag context release message is received from the network node based on a result of an authentication operation associated with the mobile network assigned tag identifier.

24. The apparatus of claim 15, wherein the at least one processor is further configured to: sending a message including at least the reader identifier to a tag device associated with a serving reader; receiving a response message including at least a tag identifier assigned by the second mobile network and a serving reader identifier; performing an authentication operation based at least on the tag identifier assigned by the second mobile network; sending an association reconfiguration message comprising at least a second temporary identifier for communicating with the network node, the reader identifier or a second list of authorized readers; as well as A message is received indicating that the second mobile network assigned tag identifier has been associated with at least the second temporary identifier, the reader identifier, or the second list of authorized readers.

25. The apparatus of claim 24, wherein the at least one processor is further configured to: sending a request for a tag context associated with the tag identifier assigned by the second mobile network; and A tag context response message is received that includes the tag context and the second list of authorized readers.

26. The apparatus of claim 24, wherein the at least one processor is further configured to: A broadcast message is received that includes a list of verified mobile network assigned tag identifiers and a set of tag contexts associated with the verified mobile network assigned tag identifiers, wherein the authentication operation is based on the list of verified mobile network assigned tag identifiers.

27. An apparatus for wireless communication, the apparatus comprising: Memory; and at least one processor coupled to the memory and configured to: receiving a request for initiating context establishment for a tag device in a mobile network; Performing an authentication operation on the tag device; assigning a tag identifier to the tag device based on the authentication operation; as well as A context establishment message including at least the tag identifier is sent.

28. The apparatus of claim 24, wherein the at least one processor configured to perform the authentication operation for the tag device is further configured to: receiving at least a portion of product information associated with the tag device, wherein the portion of the product information is protected based on a public key; and The portion of the product information is verified.

29. The apparatus of claim 28, wherein the product information comprises at least a label product identifier or an electronic product code.

30. The apparatus of claim 28, wherein the at least one processor is further configured to: generating a private key based on at least the public key, the tag identifier, or the reader identifier; receiving an encrypted message from the tag device; and The encrypted message is decrypted based on the private key.

Citation Information

Cited By

  • Self-management trust in internet of things network

    CN115968473A