Method for paging identity protection in AIOT communication system and related apparatus
The method leverages wireless channel reciprocity to generate and replace paging identifiers in AIoT devices, addressing privacy and energy inefficiencies in AIoT communication systems by ensuring secure and targeted paging.
Patent Information
- Application Number
- PCT/US2025/054960
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-11-20
- Filing Date
- 2025-11-11
- Publication Date
- 2026-05-28
AI Technical Summary
Existing methods for protecting device identifiers in ambient Internet-of-Things (AIoT) communication systems are unsuitable for unregistered, energy-constrained devices, leading to privacy risks and inefficiencies due to the need for device registration and resource-intensive cryptographic processes.
A method involving a radio access network (RAN) node and AIoT devices that utilize wireless channel reciprocity characteristics to generate and replace paging identifiers, ensuring secure and energy-efficient communication by deriving new identifiers from random numbers and initial paging identifiers.
Enhances privacy and security of AIoT devices while reducing energy consumption by enabling targeted paging without disturbing other devices, overcoming limitations of conventional methods.
Smart Images

Figure US2025054960_28052026_PF_FP_ABST
Abstract
Description
Atty. Dkt. No. 10085-01-0183-PCTMETHOD FOR PAGING IDENTITY PROTECTION IN AIOT COMMUNICATION SYSTEM AND RELATED APPARATUSCROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application No. 63 / 722,960, entitled “METHOD AND APPARATUS FOR PAGING IDENTITY PROTECTION IN AMBIENT IOT COMMUNICATION SYSTEM,” filed on November 20, 2024, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD
[0002] The present disclosure relates to the field of communication systems, and more particularly, to a method for paging identity protection in an ambient intemet-of-things (AIoT) communication system method for paging identity protection in an ambient intemet-of-things (AIoT) communication system and a related apparatus.BACKGROUND
[0003] In mobile communication systems, device identifiers must be protected to prevent exposure and tracking. Conventional techniques, such as temporary identifiers or cryptographic concealment, generally require device registration and significant processing resources. Ambient Intemet-of-Things (AIoT) devices, however, are typically unregistered, energy-constrained, and limited in computation. Existing identifier protection methods are therefore unsuitable for paging such devices, leading to privacy risks and inefficiencies in communication.
[0004] Therefore, there is a need for a method for paging identity protection in an ambient intemet-of-things (AIoT) communication system and a related apparatus.SUMMARY
[0005] An object of the present disclosure is to propose a method for paging identity protection in an ambient intemet-of-things (AIoT) communication system and a related apparatus, which can enhance privacy and security of AIoT devices, and / or reduce energy consumption.
[0006] In a first aspect of the present disclosure, a method performed by a radio access network (RAN) node for device authorization in integrated sensing and communication (ISAC) includes determining, by the RAN node, that at least one ambient intemet-of-things (AIoT) device is within a vicinity of a remote object and determining whether the at least one AIoT device is authorized to participate in a sensing session.
[0007] In a second aspect of the present disclosure, a method performed by an ambient intemet-of-things (AIoT) device for device authorization in integrated sensing and communication (ISAC) includes receiving, by the AIoT device, an indication from a radio access network (RAN) node that the AIoT device is located within a vicinity of a remote object and is a candidate to participate in a sensing session and determining, by the AIoT device, whether the AIoT device is authorized to participate in the sensing session based on an authorization information.Atty. Dkt. No. 10085-01-0183-PCT
[0008] In a third aspect of the present disclosure, a reader includes an activator and a replacer. The activator is configured to page an AIoT device using an initial paging identifier, generate, based on wireless channel reciprocity characteristics, a random number, and derive, using the random number and the initial paging identifier, a paging identifier, and the replacer is configured to replace the initial paging identifier with the paging identifier for subsequent paging of the AIoT device.
[0009] In a fourth aspect of the present disclosure, an ambient intemet-of-things (AIoT) device includes an activator and a replacer. The activator is configured to verify an initial paging identifier, generate a random number based on wireless channel reciprocity characteristics, and derive a paging identifier from the random number and the initial paging identifier, and the replacer is configured to replace the initial paging identifier with the paging identifier for subsequent paging.
[0010] In a fifth aspect of the present disclosure, a reader includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The reader is configured to perform the above method.
[0011] In a sixth aspect of the present disclosure, an ambient intemet-of-things (AIoT) device includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The AIoT device is configured to perform the above method.
[0012] In a seventh aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.
[0013] In an eighth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.
[0014] In a ninth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.
[0015] In a tenth aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.
[0016] In an eleventh aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.
[0018] FIG. 1 is a block diagram of a reader and one or more Ambient Internet of Things (AIoT) devices of communication in a communication system according to an embodiment of the present disclosure.
[0019] FIG. 2 is a block diagram of a reader according to an embodiment of the present disclosure.
[0020] FIG. 3 is a block diagram of an AIoT device according to an embodiment of the present disclosure.
[0021] FIG. 4 is a flowchart illustrating a method performed by a reader for paging identity protection in an ambient intemet-of-things (AIoT) communication system according to an embodiment of the present disclosure.Atty. Dkt. No. 10085-01-0183-PCT
[0022] FIG. 5 is a flowchart illustrating a method performed by an ambient internet of things (AIoT) device for paging identity protection in an AIoT communication system according to an embodiment of the present disclosure.
[0023] FIG. 6 is a flowchart illustrating an AIoT paging ID protection in an AIoT communication system according to an embodiment of the present disclosure.
[0024] FIG. 7 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.
[0025] FIG. 8 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS
[0026] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.
[0027] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.
[0028] Optionally, a user equipment (UE) mentioned in the embodiments of the present application may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem, an in-vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.
[0029] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.
[0030] 3rd generation partnership project (3GPP) specifies identifiers of user equipment (UE) or device that are protected from being sent over the air in the clear (e.g., permanent identifier in its original format is not sent over the air). Ways of protecting the identifiers have been specified in 3GPP, for example, randomly assignedAtty. Dkt. No. 10085-01-0183-PCT temporary identifiers, e.g., Global Unique Temporary Identifier (GUTI) or Temporary Mobile Subscriber Identifier (TMSI) to a UE for communicating with the network, use of asymmetric cipher algorithms to encrypt the permanent identifier of a UE (e.g., Subscriber Permanent Identifier (SUPI) into or Subscriber Concealed Identifier(SUCI)); other forms of TMSI (e.g., Packet Temporary Mobile Subscriber Identifier (P-TMSI), Servicing Temporary Mobile Subscriber Identifier (S-TMSI), etc.) before sending these identifiers over the air in order to protect the permanent UE identifiers. However, the use of these identifiers is only possible after the UE has been registered in the network. In 3GPP systems, device identifiers are protected using temporary identifiers or cryptographic concealment, but such protection is only available after the UE has registered with the network.
[0031] The existing process for paging a mobile device only happens after the mobile device has been registered to the network through a process at which the devices initiated (e.g., mobile-originated registration or mobile-originated authentication and the network becomes aware of the location or serving area of the mobile device). The existing paging process occurs only after a mobile device has initiated registration or authentication, enabling the network to know its location or serving area. Paging is only possible once a mobile device has registered with the network and its location or serving area is known.
[0032] One major drawback of using any of the above-mentioned mechanisms is that the mobile device has to initiate the network registration process in order for the network to know that the device has been registered in the network. If the device has not been registered in the network, there is no method for which the mobile device can be paged. A major drawback is that if a mobile device has not registered with the network, it cannot be paged.
[0033] Another drawback of using one of the above-mentioned mechanisms, such as the Subscriber Concealed Identifier or SUCI scheme as specified in 3GPP’s TS 33.501 is the use of asymmetric cryptographic algorithm. Since the AIoT devices are characterized by limited power, storage and computing capabilities, these devices are not suitable for executing power and compute intensive asymmetric cryptographic algorithms such as elliptic curve algorithm to protect the AIoT device identifier. In addition, the public-private key pair in the asymmetric cryptographic algorithm is generated and pre-provisioned into the AIoT device, either in the factory or using other offline method. The SUCI scheme relies on asymmetric cryptographic algorithms, which are unsuitable for AIoT devices due to their limited power, storage, and computing capabilities.
[0034] Another drawback is if the protected identifier that is sent over the air remains static (e.g., not changed) over a long period of time, the identifier may also become trackable by attackers.
[0035] Yet another drawback if symmetric cryptographic algorithm based on shared key is used (e.g., encrypting the identifier with keys shared between the device and the network), a provisioned shared secret may be used by the device and the network. In general, provisioned shared secret cannot be used directly without going through key derivation to generate session keys (or intermediary keys) to protect the information. This adds another layer of processing and computing for the power-strained AIoT devices. Using symmetric cryptographic algorithms with shared keys requires additional key derivation, adding processing burdens to power-constrained AIoT devices.
[0036] 5G AIoT service is a new 5G service that can be used to support various use cases such as, automated warehousing, inventory management, smart grid, non-public logistics, industrial manufacturing, loT sensors andAtty. Dkt. No. 10085-01-0183-PCT smart home. AIoT devices collect information related to the use case and report back to the 3GPP network or to an application server via the 3GPP network. Each AIoT device is identifiable by a unique identifier (e.g., permanent identifier) that is assigned to the AIoT device. It is important to protect the AIoT identifier so that the AIoT device cannot be tracked or traced and therefore protecting the privacy of the users or subscribers associated with these devices. It is also important to be able to address (e.g., wake up) each individual AIoT device (e.g., page an AIoT device) without waking up other unrelated AIoT devices. 5G AIoT service supports diverse use cases, making it essential to protect unique device identifiers for privacy while enabling targeted paging of individual devices without disturbing others.
[0037] AIoT devices are characterized by not having a conventional battery (or with limited battery) and is powered by energy harvesting, limited storage, and limited computing capabilities. Energy harvested by AIoT devices typically rely on wireless radio waves, solar, light, motion / vibration, heat, pressure, or other unconventional power sources. As a result, AIoT device can communicate with a UE (e.g., 5G UE) or a base station (e.g., 5G base station) or perform other critical functions such as cryptographic operations when sufficient energy has been harvested to power its internal processor(s) or component(s). AIoT devices rely on energy harvesting and have limited resources, enabling communication or cryptographic operations only when sufficient energy is available.
[0038] AIoT devices are also characterized by not being able to initiate communication to the network without having been paged by the network (e.g., awaken by way of being paged). Targeted paging requires a unique paging identifier to avoid many AIoT devices being woken (e.g., taken out of reduced-power mode) at the same time by the same paging request from the network. AIoT devices cannot initiate communication and require unique paging identifiers to enable targeted wake-up without disturbing other devices.
[0039] Some embodiments of the present disclosure provide a mechanism using a unique one-time initial paging identifier for securely paging an AIoT device during initial stage and a mechanism for generating subsequent one-time paging identifier for subsequent paging of the AIoT device. Some embodiments of the disclosure introduce a mechanism that uses a unique one-time initial paging identifier and generates subsequent one-time identifiers for secure AIoT device paging.
[0040] FIG. 1 illustrates that, in some embodiments, a reader 10 and one or more AIoT devices 20 of communication in a communication system 40. The communication system 40 includes the reader 10 and the one or more AIoT devices 20. The reader 10 may include a memory 12, a transceiver 13, and a processor 11 coupled to the memory 12 and the transceiver 13. The one or more AIoT devices 20 may include a memory 22, a transceiver 23, and a processor 21 coupled to the memory 22 and the transceiver 23. The processor 11 or 21 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 11 or 21. The memory 12 or 22 is operatively coupled with the processor 11 or 21 and stores a variety of information to operate the processor 11 or 21. The transceiver 13 or 23 is operatively coupled with the processor 11 or 21, and the transceiver 13 or 23 transmits and / or receives a radio signal.
[0041] The processor 11 or 21 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 12 or 22 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. TheAtty. Dkt. No. 10085-01-0183-PCT transceiver 13 or 23 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 12 or 22 and executed by the processor 11 or 21. The memory 12 or 22 can be implemented within the processor 11 or 21 or external to the processor 11 or 21 in which case those can be communicatively coupled to the processor 11 or 21 via various means as is known in the art.
[0042] In some embodiments, the processor 11 is configured to page the AIoT device 20 using an initial paging identifier, generate, based on wireless channel reciprocity characteristics, a random number, derive, using the random number and the initial paging identifier, a paging identifier, and replace the initial paging identifier with the paging identifier for subsequent paging of the AIoT device 20. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can enhance privacy and security of AIoT devices, and / or reduce energy consumption.
[0043] In some embodiments, the processor 11 is further configured to initiate a paging request to the AIoT device 20 using the initial paging identifier that has been pre-provisioned in both the reader 10 and the AIoT device 20, and the transceiver 13 is configured to receive a paging response from the AIoT device 20 indicating a match of the initial paging identifier. In some embodiments, the processor 11 is further configured to perform a link establishment procedure with the AIoT device 20 including obtaining a physical layer measurement including at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier- to-interference ratio (CIR), or a channel state information (CSI), and the processor 11 is further configured to generate the random number based on the wireless channel reciprocity characteristics derived from the physical layer measurement. In some embodiments, the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
[0044] In some embodiments, the processor 11 is further configured to derive the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function. In some embodiments, the paging identifier derivation function includes at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input. In some embodiments, the processor 11 discards the initial paging identifier after deriving the paging identifier. In some embodiments, the memory 12 is configured to store the paging identifier for subsequent paging of the AIoT device 20. In some embodiments, the initial paging identifier is discarded by the AIoT device 20 and the paging identifier derived using the paging identifier derivation function is stored by the AIoT device 20. In some embodiments, the reader 10 is one of a radio access network (RAN) reader or a user equipment (UE) reader.
[0045] In some embodiments, a reader (e.g., RAN reader or UE reader) is configured to page an AIoT device using a pre-provisioned initial paging identifier, receive a paging response, and establish a link by obtaining physical layer measurements such as RSS, RSRP, CIR, or CSI. Based on wireless channel reciprocity characteristics, the reader generates a random number by processing the measurements and derives a new paging identifier from the random number and the initial paging identifier using a derivation function, such as a pseudorandom function, hashing, XOR, or encryption. The initial paging identifier is then discarded and replacedAtty. Dkt. No. 10085-01-0183-PCT with the new paging identifier, which is stored for subsequent paging. This mechanism enhances privacy and security of AIoT devices, reduces energy consumption, and overcomes limitations of prior art.
[0046] In some embodiments, the processor 21 is configured to verify an initial paging identifier, generate a random number based on wireless channel reciprocity characteristics, derive a paging identifier from the random number and the initial paging identifier, and replace the initial paging identifier with the paging identifier for subsequent paging. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can enhance privacy and security of AIoT devices, and / or reduce energy consumption.
[0047] In some embodiments, the transceiver 23 is configured to receive a paging request from the reader 10 using the initial paging identifier that has been pre-provisioned in both the AIoT device and the reader, the processor 21 is configured to determine a match of the initial paging identifier, and the transceiver 23 is configured to transmit a paging response to the reader 10 indicating the match of the initial paging identifier. In some embodiments, the processor 21 is configured to perform a link establishment procedure with the reader 10 including providing a physical layer measurement including at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (OR), or a channel state information (CSI), and the processor 21 is configured to generate the random number from the wireless channel reciprocity characteristics derived from the physical layer measurement. In some embodiments, the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
[0048] In some embodiments, the processor 21 is configured to derive the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function. In some embodiments, the paging identifier derivation function includes at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input. In some embodiments, the processor 21 is configured to discard the initial paging identifier and storing the paging identifier for subsequent paging. In some embodiments, the paging identifier is used once and subsequently replaced with another paging identifier derived from a newly generated random number. In some embodiments, the processor 21 performs a derivation of the paging identifier only when sufficient harvested energy is available to power the AIoT device 20. In some embodiments, the processor 21 uses the random number as a cryptographic key to encrypt the initial paging identifier to derive the paging identifier.
[0049] In some embodiments, an AIoT device is configured to receive a paging request from a reader using a pre-provisioned initial paging identifier, verify the identifier, and respond accordingly. The device performs a link establishment procedure with the reader by providing physical layer measurements such as RSS, RSRP, OR, or CSI, from which a random number is generated using wireless channel reciprocity characteristics. The random number is then used together with the initial paging identifier to derive a new paging identifier through functions such as pseudorandom generation, hashing, XOR, or encryption. The initial paging identifier is discarded and replaced with the new paging identifier for subsequent paging, which may be updated each time with a newly generated random number. In some embodiments, the derivation is performed only when sufficient harvested energy is available, thereby enhancing privacy and security while reducing energy consumption for AIoT devices.Atty. Dkt. No. 10085-01-0183-PCT
[0050] FIG. 2 illustrates a reader 200 according to an embodiment of the present disclosure. The reader 200 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the reader 200 using any suitably configured hardware and / or software. The reader 200 includes an activator 201 and a replacer 202. The activator 201 is configured to page an AIoT device using an initial paging identifier, generate, based on wireless channel reciprocity characteristics, a random number, and derive, using the random number and the initial paging identifier. The replacer 202 is configured to replace the initial paging identifier with the paging identifier for subsequent paging of the AIoT device. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can enhance privacy and security of AIoT devices, and / or reduce energy consumption.
[0051] In some embodiments, the activator 201 is further configured to initiate a paging request to the AIoT device using the initial paging identifier that has been pre-provisioned in both the reader 200 and the AIoT device, and the activator 201 is configured to receive a paging response from the AIoT device indicating a match of the initial paging identifier. In some embodiments, the activator 201 is further configured to perform a link establishment procedure with the AIoT device including obtaining a physical layer measurement including at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (OR), or a channel state information (CSI), and the activator 201 is further configured to generate the random number based on the wireless channel reciprocity characteristics derived from the physical layer measurement. In some embodiments, the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
[0052] In some embodiments, the activator 201 is further configured to derive the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function. In some embodiments, the paging identifier derivation function includes at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input. In some embodiments, the replacer 202 discards the initial paging identifier after deriving the paging identifier. In some embodiments, the activator 201 is configured to store the paging identifier for subsequent paging of the AIoT device. In some embodiments, the initial paging identifier is discarded by the AIoT device and the paging identifier derived using the paging identifier derivation function is stored by the AIoT device. In some embodiments, the reader 200 is one of a radio access network (RAN) reader or a user equipment (UE) reader.
[0053] FIG. 3 illustrates an AIoT device 300 according to an embodiment of the present disclosure. The AIoT device 300 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the AIoT device 300 using any suitably configured hardware and / or software. The AIoT device 300 includes an activator 301 and a replacer 302. The activator 301 is configured to verily an initial paging identifier, generate a random number based on wireless channel reciprocity characteristics, and derive a paging identifier from the random number and the initial paging identifier. The replacer 302 is configured to replace the initial paging identifier with the paging identifier for subsequent paging. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can enhance privacy and security of AIoT devices, and / or reduce energy consumption.Atty. Dkt. No. 10085-01-0183-PCT
[0054] In some embodiments, the activator 301 is configured to receive a paging request from the reader using the initial paging identifier that has been pre-provisioned in both the AIoT device 300 and the reader, the activator 301 is configured to determine a match of the initial paging identifier, and the activator 301 is configured to transmit a paging response to the reader indicating the match of the initial paging identifier. In some embodiments, the activator 301 is configured to perform a link establishment procedure with the reader including providing a physical layer measurement including at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (CIR), or a channel state information (CSI), and the activator 301 is configured to generate the random number from the wireless channel reciprocity characteristics derived from the physical layer measurement. In some embodiments, the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
[0055] In some embodiments, the activator 301 is configured to derive the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function. In some embodiments, the paging identifier derivation function includes at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input. In some embodiments, the replacer 302 is configured to discard the initial paging identifier and storing the paging identifier for subsequent paging. In some embodiments, the paging identifier is used once and subsequently replaced with another paging identifier derived from a newly generated random number. In some embodiments, the activator 301 performs a derivation of the paging identifier only when sufficient harvested energy is available to power the AIoT device 300. In some embodiments, the activator 301 uses the random number as a cryptographic key to encrypt the initial paging identifier to derive the paging identifier.
[0056] FIG. 4 illustrates a method 400 performed by a reader for paging identity protection in an ambient intemet-of-things (AIoT) communication system according to an embodiment of the present disclosure. The method 400 performed by the reader is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 400 performed by the reader using any suitably configured hardware and / or software. In some embodiments, the method 400 performed by the reader includes: an operation 402, paging an AIoT device using an initial paging identifier, an operation 404, generating, based on wireless channel reciprocity characteristics, a random number, an operation 406, deriving, using the random number and the initial paging identifier, a paging identifier, and an operation 408, replacing the initial paging identifier with the paging identifier for subsequent paging of the AIoT device. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can enhance privacy and security of AIoT devices, and / or reduce energy consumption.
[0057] In some embodiments, paging the AIoT device using the initial paging identifier includes initiating, by the reader, a paging request to the AIoT device using the initial paging identifier that has been pre-provisioned in both the reader and the AIoT device and receiving, by the reader, a paging response from the AIoT device indicating a match of the initial paging identifier. In some embodiments, generating, based on wireless channel reciprocity characteristics, the random number includes performing, by the reader, a link establishment procedure with the AIoT device including obtaining a physical layer measurement including at least one of aAtty. Dkt. No. 10085-01-0183-PCT received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (CIR), or a channel state information (CSI) and generating, by the reader, the random number based on the wireless channel reciprocity characteristics derived from the physical layer measurement. In some embodiments, the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
[0058] In some embodiments, deriving, using the random number and the initial paging identifier, the paging identifier includes deriving, by the reader, the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function. In some embodiments, the paging identifier derivation function includes at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input. In some embodiments, the reader discards the initial paging identifier after deriving the paging identifier. In some embodiments, the method further includes storing, by the reader, the paging identifier for subsequent paging of the AIoT device. In some embodiments, the initial paging identifier is discarded by the AIoT device and the paging identifier derived using the paging identifier derivation function is stored by the AIoT device. In some embodiments, the reader is one of a radio access network (RAN) reader or a user equipment (UE) reader.
[0059] In some embodiments, a reader pages an AIoT device using a pre-provisioned initial paging identifier and receives a response confirming the match. The reader then establishes a link with the device, obtains physical layer measurements such as RSS, RSRP, CIR, or CSI, and generates a random number from wireless channel reciprocity characteristics by processing the measurements into a bit string. Using this random number and the initial paging identifier, the reader derives a new paging identifier through a derivation function such as a pseudorandom function, hashing, XOR, or encryption. The initial paging identifier is discarded, and the new paging identifier is stored for subsequent paging, with the AIoT device likewise discarding the initial identifier and storing the newly derived one. The reader may be implemented as a RAN reader or a UE reader.
[0060] FIG. 5 illustrates a method 500 performed by an ambient internet of things (AIoT) device for paging identity protection in an AIoT communication system according to an embodiment of the present disclosure. The method 500 performed by the AIoT device is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 500 performed by the AIoT device using any suitably configured hardware and / or software. In some embodiments, the method 500 performed by the AIoT device includes: an operation 502, verifying an initial paging identifier, an operation 504, generating a random number based on wireless channel reciprocity characteristics, an operation 506, deriving a paging identifier from the random number and the initial paging identifier, and an operation 508, replacing the initial paging identifier with the paging identifier for subsequent paging. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can enhance privacy and security of AIoT devices, and / or reduce energy consumption.
[0061] In some embodiments, verifying the initial paging identifier includes receiving, by the AIoT device, a paging request from a reader using the initial paging identifier that has been pre-provisioned in both the AIoT device and the reader, determining, by the AIoT device, a match of the initial paging identifier, and transmitting a paging response to the reader indicating the match of the initial paging identifier. In some embodiments,Atty. Dkt. No. 10085-01-0183-PCT generating the random number based on the wireless channel reciprocity characteristics includes performing, by the AIoT device, a link establishment procedure with the reader including providing a physical layer measurement including at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (CIR), or a channel state information (CSI) and generating, by the AIoT device, the random number from the wireless channel reciprocity characteristics derived from the physical layer measurement. In some embodiments, the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
[0062] In some embodiments, deriving the paging identifier from the random number and the initial paging identifier includes deriving, by the AIoT device, the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function. In some embodiments, the paging identifier derivation function includes at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input. In some embodiments, replacing the initial paging identifier with the paging identifier for subsequent paging includes discarding, by the AIoT device, the initial paging identifier and storing the paging identifier for subsequent paging. In some embodiments, the paging identifier is used once and subsequently replaced with another paging identifier derived from a newly generated random number. In some embodiments, the AIoT device performs a derivation of the paging identifier only when sufficient harvested energy is available to power a processor of the AIoT device. In some embodiments, the AIoT device uses the random number as a cryptographic key to encrypt the initial paging identifier to derive the paging identifier.
[0063] In some embodiments, an AIoT device receives a paging request using a pre-provisioned initial paging identifier, verifies the identifier, and responds to the reader. The device then performs a link establishment procedure, provides physical layer measurements such as RSS, RSRP, CIR, or CSI, and generates a random number from wireless channel reciprocity characteristics by processing the measurements into a bit string. Using the random number and the initial paging identifier, the device derives a new paging identifier through a function such as a pseudorandom function, hashing, XOR, or encryption, and replaces the initial paging identifier with the new one for subsequent paging. The new identifier is used once and updated with each newly generated random number, and derivation may be performed only when sufficient harvested energy is available, thereby enhancing privacy and security while conserving device resources.
[0064] Examples:
[0065] Some embodiments of the present disclosure rely on pre-provisioning of a one-time paging identifier that is used to page the AIoT device in the initial stage. The one-time paging identifier may be provisioned at the same time the permanent device identifier and any pre-shared key are provisioned in the AIoT device during manufacturing time at the factory. Once the AIoT device has been paged and responded to the paging, the onetime paging identifier is no longer valid and then is thrown away or removed from the AIoT device. Some embodiments use a pre-provisioned one-time paging identifier for initial paging of an AIoT device, which becomes invalid and is discarded after use.
[0066] For subsequent paging of the device, a subsequent paging identifier is replaced using a number of schemes, such as both the AIoT device and the network replacing the one-time paging ID by using a randomAtty. Dkt. No. 10085-01-0183-PCT number generation function (e.g., PRF) or a hash function (e.g., HASH), for example: New Paging ID = PRF(initial paging ID, Nonce) or New Pagin ID = HASH(initial paging ID, Nonce) and the initial paging ID can be replaced with the newly generated New Pagin ID and Nonce with another Nonce for subsequent paging ID generation, such as: Pagin_ID2 = PRF (Paging IDl, Nonce2), etc., where the nonce is exchanged in the process of the paging and paging response. For subsequent paging, the paging identifier is updated by the AIoT device and the network using functions such as pseudorandom generation or hashing with exchanged nonces.
[0067] In another example, the new paging identifier can also be generated based on the wireless channel reciprocity characteristics of physical layers between AIoT device and the network. The wireless channel reciprocity characteristics of physical layers is used to generate a pseudorandom number (e.g., RAND) between the AIoT device and the network. The pseudorandom number can be used with a number of mathematical functions to generate a subsequent paging ID, such as: New Paging ID = Initial Paging ID XOR RAND. The initial paging ID can be replaced with the newly generated New Pagin ID and RAND replace with another RAND generated using the wireless channel reciprocity characteristics of physical layers between AIoT device and the network for subsequent paging ID generation, such as: Paging_ID2 = Paging IDl XOR RAND2. A new paging identifier can be generated from wireless channel reciprocity by deriving a pseudorandom number and combining it with the initial identifier using functions such as XOR for subsequent updates.
[0068] In another embodiment when the AIoT device is more capable (e.g., more computing capability, more power, etc.), the pseudorandom number generated using wireless channel reciprocity characteristics of physical layers between AIoT device and the network can be used as a shared key. The shared key can be used in either a keyed hash or used in a cipher algorithm with Paging ID as input to generate a subsequent Paging ID. The Paging ID can then be used by the network for subsequent paging of the AIoT device. In another embodiment, a pseudorandom number from wireless channel reciprocity can serve as a shared key for hashing or encryption to generate subsequent paging identifiers for AIoT devices.
[0069] FIG. 6 illustrates an AIoT paging ID protection in an AIoT communication system according to an embodiment of the present disclosure. In the above example, AIoT device and the network (RAN Reader is considered part of network extension for simplicity) are provisioned with initial paging ID of the AIoT device. FIG. 6 illustrates that, in some embodiments, the AIoT paging ID protection in the AIoT communication system includes at least one of following steps:
[0070] Step 1 : The network (e.g., RAN Reader) initiates a paging request of the AIoT device using the initial paging ID that was previously provisioned.
[0071] Step 2: The AIoT device matches the paging ID so that it knows that the paging is for itself.
[0072] Step 3: Link establishment procedure (including physical layer measurements of various parameters such as RSS, RSRP, CIR, CSI, etc.) are taken. These parameters, using wireless channel reciprocity characteristics, are randomized, quantized, and reconciled to produce a string of bits only know to the AIoT device and the RAN Reader. In Step 3, link establishment uses physical layer measurements and wireless channel reciprocity to generate a bit string known only to the AIoT device and the RAN Reader.
[0073] Step 4: AIoT device derives a random number (RAND) from the string of bits, for example, taking the least significant 128 bits of the string of bits in Step 3. Furthermore, the AIoT device derive a new paging ID. Derivation of new paging ID can be based on a number of methods that is common to both the AIoT device andAtty. Dkt. No. 10085-01-0183-PCT the RAN Reader (e.g., configured to use method X). Examples of such paging ID derivation methods include using a pseudorandom function (PRF), a hashing function (HASH), exclusive-or (XOR) function or cipher (ENCRYPTION) using the RAND and the current paging ID as input to produce a new paging ID. In case of cipher, the RAND can be used as the cipher key to encrypt the current paging ID to produce a new paging ID). AIoT device discards the current paging ID and stores the newly derived paging ID for future use. In Step 4, the AIoT device generates a random number from the bit string, derives a new paging identifier using functions such as PRF, HASH, XOR, or encryption, discards the old identifier, and stores the new one for future use.
[0074] Step 5: RAN Reader derives RAND and derives a new paging ID.
[0075] Step 6: AIoT device replies to the paging with a paging response.
[0076] The new paging ID will be used by the network (e.g., RAN reader or UE Reader) to page the AIoT device. FIG. 6 1 above illustrates an example of using wireless channel reciprocity characteristics to protect the AIoT device paging ID in an AIoT communication system. The various methods for generating new paging ID using a random number generated via wireless channel reciprocity characteristics between AIoT device and RAN reader (also UE reader) do not deviate from the scope of the present disclosure which uses a one-time initial paging ID for initial paging of the AIoT device and generating subsequent paging ID using the initial paging ID for subsequent paging of the AIoT device. Some embodiments use a one-time initial paging identifier and subsequent identifiers derived from wireless channel reciprocity to securely page AIoT devices without departing from its scope.
[0077] Some embodiments provide at least one of following technical benefits: Use of initial AIoT Paging ID benefits the security of communication between AIoT device and UE / base station in many ways. Some embodiment provides a mechanism to allow an initial pre-provisioned paging ID to page an unregistered AIoT device (AIoT device cannot initiate communication by itself and therefore cannot initiate registration process toward the network like a normal UE does). Since the initial paging ID is unique to an AIoT device, the paging message cannot be construed as flood paging to page every AIoT device in the serving area. This ensures that unrelated AIoT devices are not being taken out of reduced-power mode by the paging, and therefore, conserve energy consumption for other designated activities (e.g., inventory). The use of an initial pre-provisioned paging identifier enables secure, targeted paging of unregistered AIoT devices while conserving energy by avoiding unnecessary wake-ups.
[0078] Since the initial paging ID is used only once, it cannot be used as an identifier by attacker (either passive or active attacker) to track and trace the AIoT device, and therefore protecting the privacy of the subscriber or user that the AIoT device is associated with. The paging ID is also being updated using wireless channel reciprocity characteristics between the AIoT Device and the network, creating yet another one-time use subsequent paging ID, further protecting the privacy of subscriber or user that the AIoT device is associated with. Using a one-time initial paging identifier and updating it through wireless channel reciprocity prevents tracking and ensures ongoing privacy protection for AIoT devices and their users. Additionally, the use of wireless channel reciprocity characteristics between AIoT device and RAN reader reduces the energy consumption of the AIoT device and reduces or eliminates the explicit exchange of parameters for the purpose of cryptographic operations (e.g., generating and sending nonces for cryptographic key derivation). LeveragingAtty. Dkt. No. 10085-01-0183-PCT wireless channel reciprocity reduces AIoT device energy consumption and minimizes the need for explicit parameter exchanges in cryptographic operations.
[0079] Alternative to using one-time identifier for initial paging of an AIoT device is to use the permanent or long-term identifier of the AIoT device. However, using the permanent identifier of the AIoT device would lead the identity of the device being divulged to external entities (e.g., active or passive eavesdroppers) that may lead to the tracking of the AIoT device. Using a permanent identifier for initial paging risks exposing the AIoT device’s identity to eavesdroppers and enabling tracking.
[0080] Another alternative to using one-time identifier for initial paging of an AIoT device is to do a flood paging of all AIoT devices in a serving area. However, due to the limited power of the AIoT devices, flood paging would force all AIoT devices to respond and may use up all available power of the AIoT devices. Furthermore, the network that initiated the flood paging would analyze the paging responses from all AIoT devise that replied to determine the right response from a targeted AIoT device. Flood paging all AIoT devices forces unnecessary responses, drains limited device power, and requires the network to analyze multiple replies to identify the target device.
[0081] Yet another alternative is to pre-provision a list of one-time (e.g., temporary) identifiers into the AIoT device. This has the drawback of memory requirements on the device and pre-provisioning process that requires synchronization of device and the network to ensure the use of temporary identifiers are fully in sync. Preprovisioning a list of temporary identifiers increases device memory requirements and demands strict synchronization with the network.
[0082] In summary, some embodiments of the present disclosure provide a secure paging mechanism for AIoT devices by using a pre-provisioned one-time initial paging identifier and subsequently updating the identifier through functions such as pseudorandom generation, hashing, XOR, or wireless channel reciprocity. This approach enables targeted paging of unregistered AIoT devices without unnecessary wake-ups, enhances privacy by preventing tracking, and reduces energy consumption by minimizing cryptographic exchanges. In contrast, alternative methods such as using permanent identifiers, flood paging, or pre-provisioned lists of temporary identifiers expose devices to tracking risks, drain limited power, or require additional memory and strict synchronization, making them less efficient and secure.
[0083] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Enhance privacy and security of AIoT devices. 4. Reduce energy consumption. 5. Provide a good communication performance. 6. Provide high reliability. 7. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposedAtty. Dkt. No. 10085-01-0183-PCT solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.
[0084] FIG. 7 is an example of a computing device 1400 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 7 illustrates an example of the computing device 1400 that can implement apparatuses and methods of the above embodiments of FIGs. 1 to 6, using any suitably configured hardware and / or software. In some embodiments, the computing device 1400 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.
[0085] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer- readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer- readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.
[0086] The computing device 1400 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1400. The computing device 1400 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1400 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.Atty. Dkt. No. 10085-01-0183-PCT
[0087] The computing device 1400 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 6. The program code may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.
[0088] The computing device 1400 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1400 can transmit messages as electronic or optical signals via the network interface device 1424.
[0089] FIG. 8 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 8 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (I / O) interface 1580, coupled with each other at least as illustrated.
[0090] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more singlecore or multi-core processors. The processors may include any combination of general-purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 6. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.
[0091] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuitry.
[0092] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wirelessAtty. Dkt. No. 10085-01-0183-PCT networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.
[0093] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1 to 6 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.
[0094] In various embodiments, the I / O interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.
[0095] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.
[0096] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware orAtty. Dkt. No. 10085-01-0183-PCT combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.
[0097] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative coupling operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.
[0098] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.
[0099] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a readonly memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.
[0100] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.
Claims
Atty. Dkt. No. 10085-01-0183-PCTWhat is claimed is:
1. A method performed by a reader for paging identity protection in an ambient intemet-of-things (AIoT) communication system, the method comprising: paging an AIoT device using an initial paging identifier; generating, based on wireless channel reciprocity characteristics, a random number; deriving, using the random number and the initial paging identifier, a paging identifier; and replacing the initial paging identifier with the paging identifier for subsequent paging of the AIoT device.
2. The method of claim 1, wherein paging the AIoT device using the initial paging identifier comprises: initiating, by the reader, a paging request to the AIoT device using the initial paging identifier that has been preprovisioned in both the reader and the AIoT device; and receiving, by the reader, a paging response from the AIoT device indicating a match of the initial paging identifier.
3. The method of claim 1, wherein generating, based on wireless channel reciprocity characteristics, the random number comprises: performing, by the reader, a link establishment procedure with the AIoT device including obtaining a physical layer measurement comprising at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (CIR), or a channel state information (CSI); and generating, by the reader, the random number based on the wireless channel reciprocity characteristics derived from the physical layer measurement.
4. The method of claim 3, wherein the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
5. The method of claim 1, wherein deriving, using the random number and the initial paging identifier, the paging identifier comprises: deriving, by the reader, the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function.
6. The method of claim 5, wherein the paging identifier derivation function comprises at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input.
7. The method of claim 1, wherein the reader discards the initial paging identifier after deriving the paging identifier.
8. The method of claim 1, further comprising storing, by the reader, the paging identifier for subsequent paging of the AIoT device.
9. The method of claim 1, wherein the initial paging identifier is discarded by the AIoT device and the paging identifier derived using the paging identifier derivation function is stored by the AIoT device.
10. The method of claim 1 , wherein the reader is one of a radio access network (RAN) reader or a user equipment (UE) reader.
11. A method performed by an ambient internet of things (AIoT) device for paging identity protection in an AIoT communication system, the method comprising:Atty. Dkt. No. 10085-01-0183-PCT verifying an initial paging identifier; generating a random number based on wireless channel reciprocity characteristics; deriving a paging identifier from the random number and the initial paging identifier; and replacing the initial paging identifier with the paging identifier for subsequent paging.
12. The method of claim 11, wherein verifying the initial paging identifier comprises: receiving, by the AIoT device, a paging request from a reader using the initial paging identifier that has been pre-provisioned in both the AIoT device and the reader; determining, by the AIoT device, a match of the initial paging identifier; and transmitting a paging response to the reader indicating the match of the initial paging identifier.
13. The method of claim 11, wherein generating the random number based on the wireless channel reciprocity characteristics comprises: performing, by the AIoT device, a link establishment procedure with the reader including providing a physical layer measurement comprising at least one of a received signal strength (RSS), a reference signal received power (RSRP), a carrier-to-interference ratio (CIR), or a channel state information (CSI); and generating, by the AIoT device, the random number from the wireless channel reciprocity characteristics derived from the physical layer measurement.
14. The method of claim 13, wherein the random number is generated by randomizing, quantizing, and reconciling the physical layer measurement to produce a bit string, and selecting a portion of the bit string as the random number.
15. The method of claim 11, wherein deriving the paging identifier from the random number and the initial paging identifier comprises: deriving, by the AIoT device, the paging identifier based on the random number and the initial paging identifier using a paging identifier derivation function.
16. The method of claim 15, wherein the paging identifier derivation function comprises at least one of a pseudorandom function (PRF), a hashing function (HASH), an exclusive-OR (XOR) function, or an encryption function using the random number as a cipher key and the initial paging identifier as an input.
17. The method of claim 11, wherein replacing the initial paging identifier with the paging identifier for subsequent paging comprises: discarding, by the AIoT device, the initial paging identifier and storing the paging identifier for subsequent paging.
18. The method of claim 11, wherein the paging identifier is used once and subsequently replaced with another paging identifier derived from a newly generated random number.
19. The method of claim 11, wherein the AIoT device performs a derivation of the paging identifier only when sufficient harvested energy is available to power a processor of the AIoT device.
20. The method of claim 11 , wherein the AIoT device uses the random number as a cryptographic key to encrypt the initial paging identifier to derive the paging identifier.
21. A reader, comprising: an activator configured to: page an AIoT device using an initial paging identifier; generate, based on wireless channel reciprocity characteristics, a random number;Atty. Dkt. No. 10085-01-0183-PCT derive, using the random number and the initial paging identifier, a paging identifier; and a replacer configured to replace the initial paging identifier with the paging identifier for subsequent paging of the AIoT device.
22. An ambient internet of things (AIoT) device, comprising: an activator configured to: verify an initial paging identifier; generate a random number based on wireless channel reciprocity characteristics; derive a paging identifier from the random number and the initial paging identifier; and a replacer configured to replace the initial paging identifier with the paging identifier for subsequent paging.
23. A reader, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the reader is configured to perform the method of any one of claims 1 to 10.
24. An ambient intemet-of-things (AIoT) device, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the AIoT device is configured to perform the method of any one of claims 11 to 20.
25. A non-transitory machine-readable storage medium having stored thereon instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 20.
26. A chip, comprising: a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the method of any one of claims 1 to 20.
27. A computer readable storage medium, in which a computer program is stored, wherein the computer program causes a computer to execute the method of any one of claims 1 to 20.
28. A computer program product, including a computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 20.
29. A computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 20.