Authentication enhancements for personal IoT networks

By using gateway devices and modifying signaling procedures in a personal IoT network (PIN), multiple devices are authenticated during one procedure, solving the problem of inefficient authentication procedures in the prior art, and improving the efficiency and security of registration and authentication.

CN120051967APending Publication Date: 2025-05-27APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380071767.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-08-10
Filing Date
2023-07-07
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The authentication and security procedures for personal IoT networks (PINs) in the prior art are inefficient, resulting in complex and time-consuming registration and authentication processes.

Method used

By using gateway devices and modifying signaling procedures, multiple devices are authenticated during one and the same procedures, rather than running multiple parallel separate procedures. The specific method includes the gateway processor sending a registration request to the AMF, receiving a random number and an authentication token, verifying the token, calculating the gateway authentication response, and sending the random number to each UE.

Benefits of technology

Optimize the registration and authentication process in the PIN network, improve efficiency and security, and reduce complexity and time-consuming.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120051967A_ABST
    Figure CN120051967A_ABST
Patent Text Reader

Abstract

Methods and apparatus for enhancing authentication and security of a personal IoT network (PIN) are disclosed. In an example embodiment, a gateway of the PIN performs operations including: sending a subscriber identifier of the gateway and a subscriber identifier of each of a plurality of user equipments (UEs) in a registration request to an access mobility function (AMF) entity; receiving an authentication request including a random number (RAND) and an authentication token from the AMF, wherein the RAND is associated with both the gateway and the UE; verifying the authentication token; calculating a gateway authentication response; transmitting the RAND to the UE (User Equipment); receiving an authentication response from each of the UEs based on the RAND; transmitting, to the AMF, an authentication response including the gateway authentication response and the authentication response from each of the UEs; and accepting the registration of the gateway and the plurality of UEs by the AMF entity.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims priority to U.S. Provisional Application Serial No. 63 / 396,832, filed on August 10, 2022, the entire content of which is incorporated herein by reference. Technical Field

[0003] The present invention generally relates to the field of wireless communication and, more particularly, to apparatuses and methods for enhancing authentication and security of personal IoT networks (PINs) in a communication network. Other aspects are also described. Background Art

[0004] Due to the increase in the types of user equipment (UE) devices using network resources and the increase in the amount of data and bandwidth used by various applications (such as video streaming) operating on these UEs, the use and complexity of wireless systems, including fourth - generation (4G) networks and fifth - generation (5G) networks, etc., have increased. With a significant increase in the number and diversity of communication devices, especially with the emergence of next - generation (NG) (or new radio (NR) systems), the corresponding network environment (including routers, switches, bridges, gateways, firewalls, and load balancers) has become increasingly complex.

[0005] At the same time, personal Internet of Things (IoT) networks (PINs), including one or more PIN elements communicating with each other, are rapidly evolving. A PIN element (PINE) can be considered as a basic component that constitutes a PIN - user's personal IoT network. A PINE can be an IoT device, a UE, or any type of device that communicates with other PINEs within a PIN network and communicates with an external network through a gateway or another component. It should be understood that the Internet of Things (IoT) describes a network of physical objects, i.e., "things" or IoT devices, which are embedded with sensors, software, and other technologies for the purpose of connecting and exchanging data with other devices and systems via wired networks, wireless networks, the Internet, etc. Thus, an IoT device can be almost any type of computing device. Traditional IoT capabilities have been designed for traditional IoT devices that use cellular networks for communication, such as battery - constrained devices that are expected to have a battery life of several years. Localized personal IoT devices, such as wearable devices and home automation devices, are increasingly being used in personal IoT networks (PINs). For example, a wide variety of wearable IoT devices can be used locally: eyeglass frames, earbuds, blood pressure monitors, pacemakers, rings. Common IoT devices include: wireless sensor networks, control system networks, "smart home" devices (including devices and appliances (such as lighting devices, thermostats, home security systems, cameras, and other home appliances)). This is a very small and limited list of IoT devices for use in PINs.

[0006] A PIN element with gateway capabilities can act as a gateway, providing access to and from a public carrier network (fixed / mobile / wired) and the PIN. For example, the PIN element can have both PIN management capabilities and gateway capabilities. The gateway provides a bridge between the personal domain, the cloud, and IoT devices in other user equipment such as smart phones. Thus, the gateway PINE can be denoted as PINEG.

[0007] Since all PINEs in the PIN need to be registered and authenticated with the network, the number of procedures and signaling messages can become quite large. With the advancement of PIN technology, the current procedures for authentication and security are inefficient. Therefore, a method for optimizing both registration and authentication is sought. SUMMARY OF THE INVENTION

[0008] Methods and apparatus for enhancing and optimizing the authentication and security procedures of a personal IoT network (PIN) in a communication network are disclosed. Specifically, several devices can be authenticated during one and the same procedure by using a gateway device and modifying the signaling procedure, rather than running several parallel separate procedures as currently done, as described below. As described below, methods and apparatus for optimizing both registration and authentication are disclosed.

[0009] In an exemplary embodiment, a gateway of a communication network is disclosed, the gateway comprising: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with the communication network using the at least one antenna; and at least one processor, the at least one processor being coupled to the at least one radio component. The at least one processor can be configured to perform operations including: sending a subscriber identifier of the gateway and a subscriber identifier of each user equipment (UE) among a plurality of user equipments (UEs) in a registration request to an access mobility function (AMF) entity; receiving an authentication request including a random number (RAND) and an authentication token (AUTN) from the AMF, wherein the RAND is associated with both the gateway and the UE; verifying the authentication token; calculating a gateway authentication response; and sending the RAND to the UE. The processor of the gateway further: receives an authentication response from each UE among the UEs based on the RAND; sends an authentication response including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and then accepts registration of the gateway and the plurality of UEs by the AMF entity.

[0010] In some embodiments, multiple UEs and a gateway are configured to communicate in a Personal IoT Network (PIN). The subscriber identifier of each of the multiple UEs may be sequentially sent to the AMF of the communication network in a registration request. The authentication token may be verified by implementing an authentication token parameter check. The authentication request from the AMF may also include a bitmap identifying the UEs to be authenticated sequentially. In addition, the authentication response sent to the AMF, including the gateway authentication response and the authentication response from each of the UEs, may include the responses from the UEs sorted in the same order as in the bitmap of the authentication request.

[0011] In another exemplary embodiment, a method for authenticating multiple user equipments (UEs) to an Access Mobility Function entity (AMF) of a communication network is disclosed. The method includes: sending the subscriber identifier of the gateway and the subscriber identifier of each of the multiple user equipments (UEs) in a registration request to the AMF of the communication network; receiving, from the AMF, an authentication request including a random number (RAND) and an authentication token, where the RAND is associated with both the gateway and the UEs; verifying the authentication token; calculating a gateway authentication response; and sending the RAND to the UEs. The method further includes: receiving, from each of the UEs, an authentication response based on the RAND; and sending an authentication response including the gateway authentication response and the authentication response from each of the UEs to the AMF. The method may then accept the registration of the gateway and the multiple UEs by the AMF of the communication network.

[0012] In some embodiments, multiple UEs and a gateway are configured to communicate in a Personal IoT Network (PIN). The subscriber identifier of each of the multiple UEs is sequentially sent to the AMF of the communication network in a registration request. The authentication token is verified by implementing an authentication token parameter check. The authentication request from the AMF may include a bitmap identifying the UEs to be authenticated sequentially. In addition, the authentication response sent to the AMF, including the gateway authentication response and the authentication response from each of the UEs, includes the responses from the UEs sorted in the same order as in the bitmap of the authentication request.

[0013] In another example implementation, a user equipment (UE) includes: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with a communication network using the at least one antenna; and at least one processor is disclosed, the at least one processor being coupled to the at least one radio component. The at least one processor may be configured to perform operations including: receiving a random number (RAND) from a gateway, wherein the RAND is received from the gateway in an authentication request from an access mobility function entity (AMF) of the communication network, wherein based on a registration request from the gateway to the AMF including subscriber identifiers of the gateway, the UE, and a plurality of other UEs associated with the gateway, the RAND is associated with the gateway, the UE, and the plurality of other UEs; calculating an authentication response to the AMF based on the RAND; and sending the authentication response to the gateway, wherein the gateway sends an authentication response to the AMF, the authentication response including the authentication response of the gateway and the authentication response of the UE. In some implementations, the UE, the plurality of other UEs, and the gateway are configured to communicate in a personal IoT network (PIN). In a registration request to the AMF of the communication network, the subscriber identifiers of the UE and the plurality of other UEs are arranged in sequence. Additionally, the authentication request from the AMF may further include a bitmap identifying the UEs to be authenticated in sequence.

[0014] In yet another example implementation, a baseband processor of a wireless user equipment (UE) of a communication network may be configured to: receive a random number (RAND) from a gateway, wherein the RAND is received from the gateway in an authentication request from an access mobility function entity (AMF) of the communication network, wherein based on a registration request from the gateway to the AMF including subscriber identifiers of the gateway and the UE associated with the gateway, the RAND is associated with both the gateway and the UE associated with the gateway; calculate an authentication response to the AMF based on the RAND; and send the authentication response to the gateway, wherein the gateway sends an authentication response to the AMF, the authentication response including the authentication response of the gateway and the authentication response of the UE. In some implementations, the UE, the plurality of other UEs, and the gateway may be configured to communicate in a personal IoT network (PIN). In a registration request to the AMF of the communication network, the subscriber identifiers of the UE and the plurality of other UEs are arranged in sequence. The authentication request from the AMF may include a bitmap identifying the UEs to be authenticated in sequence.

[0015] In additional example embodiments, a baseband processor of a gateway of a communication network may be configured to perform operations including: sending the subscriber identifier of the gateway and the subscriber identifier of each user equipment (UE) among a plurality of user equipments (UEs) in a registration request to an access mobility function entity (AMF) of the communication network; receiving an authentication request including a random number (RAND) and an authentication token from the AMF, where the RAND is associated with both the gateway and the UE; verifying the authentication token; calculating a gateway authentication response; and sending the RAND to the UE. The baseband processor may also perform operations including: receiving an authentication response from each UE among the UEs based on the RAND; sending an authentication response including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and accepting registration of the gateway and the plurality of UEs by the AMF of the communication network. In some embodiments, the plurality of UEs and the gateway are configured to communicate in a personal IoT network (PIN). The subscriber identifier of each UE among the plurality of UEs may be sent to the AMF of the communication network in sequence in the registration request. The authentication token may be verified by implementing an authentication token parameter check. The authentication request from the AMF may also include a bitmap identifying the UEs to be authenticated in sequence. Further, the authentication response sent to the AMF including the gateway authentication response and the authentication response from each UE among the UEs may include the responses from the UEs sorted in the same order as the bitmap in the authentication request.

[0016] In another type of example embodiment, a gateway of a communication network is disclosed, the gateway including: at least one antenna; at least one radio component, where the at least one radio component is configured to communicate with the communication network using the at least one antenna; and at least one processor, the at least one processor being coupled to the at least one radio component. The at least one processor may be configured to perform operations including: sending the subscriber identifier of the gateway and the subscriber identifier of each user equipment (UE) among a plurality of user equipments (UEs) in a registration request to an access mobility function entity (AMF) of the communication network; receiving an authentication request from the AMF, the authentication request including a RAND associated with the gateway, a random number (RAND) respectively associated with each UE, and an authentication token corresponding to the RAND associated with the gateway; verifying the authentication token; calculating a gateway authentication response; and sending each RAND respectively associated with each UE to each UE. Further, under the control of the at least one processor: receiving an authentication response from each UE among the UEs based on the RAND of each UE; sending an authentication response respectively including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and accepting registration of the gateway and the plurality of UEs by the AMF of the communication network.

[0017] In some embodiments, multiple UEs and a gateway are configured to communicate in a Personal IoT Network (PIN). The subscriber identifier of each of the multiple UEs may be sequentially sent to the AMF of the communication network in a registration request. The authentication token may be verified by implementing an authentication token parameter check. After verifying the authentication token, the UE may be notified that the authentication token has been verified.

[0018] In another embodiment, a method for authenticating multiple User Equipments (UEs) to an Access Mobility Function entity (AMF) of a communication network is disclosed. The method includes the following operations: sending the subscriber identifier of the gateway and the subscriber identifier of each of the multiple User Equipments (UEs) in a registration request to the AMF of the communication network; receiving an authentication request from the AMF, the authentication request including a RAND associated with the gateway, a random number (RAND) respectively associated with each UE, and an authentication token corresponding to the RAND associated with the gateway; verifying the authentication token at the gateway; calculating a gateway authentication response; sending each RAND associated with each UE to each UE respectively; receiving an authentication response from each UE among the UEs based on the RAND of each UE. The method further includes the following operations: sending an authentication response respectively including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and accepting the registration of the gateway and the multiple UEs by the AMF of the communication network. In some embodiments, multiple UEs and a gateway are configured to communicate in a Personal IoT Network (PIN). The subscriber identifier of each of the multiple UEs may be sequentially sent to the AMF of the communication network in a registration request. The authentication token may be verified by implementing an authentication token parameter check. Additionally, after verifying the authentication token, the UE may be notified that the authentication token has been verified.

[0019] In another embodiment, a user equipment (UE) is disclosed, the user equipment (UE) comprising: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with a communication network using the at least one antenna; and at least one processor, the at least one processor being coupled to the at least one radio component. The at least one processor is configured to perform operations including: receiving a random number (RAND) associated with the UE, wherein the RAND for the UE is received from a gateway in an authentication request from an access and mobility management function entity (AMF) of the communication network based on a registration request including the subscriber identifiers of the gateway, the UE, and a plurality of other UEs; calculating an authentication response to the AMF based on the RAND; and sending the authentication response to the gateway, wherein the gateway sends the authentication response to the AMF, and wherein the authentication response includes the authentication response of the gateway and the authentication response of the UE. In some embodiments, a plurality of UEs and the gateway are configured to communicate in a personal IoT network (PIN). The subscriber identifier of each of the plurality of UEs may be sequentially sent to the AMF of the communication network in the registration request. After the authentication token is verified by the gateway, the UE may be notified that the authentication token has been verified.

[0020] In another embodiment, a baseband processor of a wireless user equipment (UE) of a communication network may be configured to perform operations including: receiving a random number (RAND) associated with the UE, wherein the RAND for the UE is received from a gateway in an authentication request from an access and mobility management function entity (AMF) of the communication network based on a registration request including the subscriber identifiers of the gateway, the UE, and a plurality of other UEs; calculating an authentication response to the AMF based on the RAND; and sending the authentication response to the gateway, wherein the gateway sends the authentication response to the AMF, and wherein the authentication response includes the authentication response of the gateway and the authentication response of the UE. In some embodiments, a plurality of UEs and the gateway are configured to communicate in a personal IoT network (PIN). The subscriber identifier of each of the plurality of UEs may be sequentially sent to the AMF of the communication network in the registration request. After the authentication token is verified by the gateway, the UE may be notified that the authentication token has been verified.

[0021] In yet another embodiment, a baseband processor of a gateway of a communication network may be configured to perform operations including: sending a subscriber identifier of the gateway and a subscriber identifier of each of a plurality of user equipments (UEs) in a registration request to an access mobility function entity (AMF) of the communication network; receiving an authentication request from the AMF, the authentication request including a RAND associated with the gateway, a random number (RAND) respectively associated with each UE, and an authentication token corresponding to the RAND associated with the gateway; verifying the authentication token; calculating a gateway authentication response for sending each RAND associated with each UE to each UE respectively; and receiving an authentication response from each UE among the UEs based on the RAND of each UE. The baseband processor of the gateway may also perform operations including: sending an authentication response including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and accepting registration of the gateway and the plurality of UEs by the AMF of the communication network. In some embodiments, the plurality of UEs and the gateway are configured to communicate in a personal IoT network (PIN). The subscriber identifier of each UE among the plurality of UEs is sent to the AMF of the communication network in sequence in the registration request. The authentication token may be verified by implementing an authentication token parameter check. After verifying the authentication token, the UE may be notified that the authentication token has been verified. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The present invention is illustrated by way of example and is not limited to the figures of the various drawings, in which like reference numerals indicate like elements.

[0023] Figure 1 An example wireless communication system according to an embodiment of the present disclosure is illustrated.

[0024] Figure 2 A user equipment communicating directly with a base station (BS) according to an embodiment of the present disclosure is illustrated.

[0025] Figure 3 An example block diagram of a UE according to an embodiment of the present disclosure is illustrated.

[0026] Figure 4 An example block diagram of a BS according to an embodiment of the present disclosure is illustrated.

[0027] Figure 5 An example block diagram of a cellular communication circuit according to an embodiment of the present disclosure is illustrated.

[0028] Figure 6 A scenario in which a gateway in a personal Internet of Things (IoT) network (PIN network) communicates with a core network in a wireless communication network to register and authenticate the gateway and a plurality of UEs according to an embodiment of the present disclosure is illustrated.

[0029] Figure 7 It is a flowchart illustrating a process for a gateway to register and authenticate IoT devices and UEs with a core network according to an embodiment of the present disclosure.

[0030] Figure 8 It is a more detailed flowchart illustrating a process for a gateway to register and authenticate IoT devices and UEs with the AMF of a core network according to an embodiment of the present disclosure.

[0031] Figure 9 It is a flowchart illustrating a process for a gateway to register and authenticate IoT devices and UEs with a core network according to another embodiment of the present disclosure.

[0032] Figure 10 It is a more detailed flowchart illustrating a process for a gateway to register and authenticate IoT devices and UEs with the AMF of a core network according to an embodiment of the present disclosure. Detailed Description

[0033] Methods and apparatuses for enhancing and optimizing authentication and security procedures for personal IoT networks (PINs) in a communication network are disclosed. Specifically, several devices can be authenticated during one and the same procedure by using a gateway device and modifying signaling procedures, rather than running several parallel separate procedures as currently done, as described below. As described below, methods and apparatuses for optimizing both registration and authentication are disclosed.

[0034] In an exemplary embodiment, a gateway of a communication network is disclosed, the gateway including: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with the communication network using the at least one antenna; and at least one processor, the at least one processor being coupled to the at least one radio component. The at least one processor may be configured to perform operations including: sending a subscriber identifier of the gateway and a subscriber identifier of each user equipment (UE) among a plurality of user equipments (UEs) in a registration request to an access mobility function (AMF) entity; receiving an authentication request including a random number (RAND) and an authentication token from the AMF, wherein the RAND is associated with both the gateway and the UE; verifying the authentication token; calculating a gateway authentication response; and sending the RAND to the UE. The processor of the gateway further: receives an authentication response from each UE among the UEs based on the RAND; sends an authentication response including the gateway authentication response and the authentication responses from each UE among the UEs to the AMF; and then accepts registration of the gateway and the plurality of UEs by the AMF entity.

[0035] In the following description, numerous specific details are set forth to provide a thorough explanation of embodiments of the present invention. However, it will be apparent to those skilled in the art that embodiments of the present invention may be implemented without these specific details. In other instances, well-known components, structures, and techniques have not been shown in detail to avoid obscuring an understanding of this description.

[0036] Reference to "some embodiments" or "embodiments" in this specification means that a particular feature, structure, or characteristic described in conjunction with the embodiment may be included in at least one embodiment of the present invention. The phrase "in some embodiments" appearing in various places in this specification does not necessarily refer to the same embodiment.

[0037] In the following description and claims, the terms "coupled" and "connected" and their derivatives may be used. It should be understood that these terms are not intended to be synonymous with each other. "Coupled" is used to indicate that two or more elements that may or may not be in direct physical or electrical contact with each other cooperate or interact with each other. "Connected" is used to indicate the establishment of communication between two or more elements that are coupled to each other.

[0038] The processes shown in the following figures are performed by processing logic, which includes hardware (e.g., circuits, dedicated logic, etc.), software (such as software running on a general-purpose computer system or a dedicated machine), or a combination of both. Although the following describes these processes as certain sequential operations, it should be understood that certain operations described may be performed in a different order. In addition, certain operations may also be performed in parallel rather than in sequence.

[0039] The terms "server," "client," and "device" are intended to refer generally to a data processing system rather than to specific form factors of a server, client, and / or device.

[0040] Figure 1 A simplified example wireless communication system according to one aspect of the present disclosure is illustrated. Note that Figure 1 The system is only one example of possible systems, and features of the present disclosure may be implemented in any of a variety of systems as desired.

[0041] As shown, the example wireless communication system includes a base station 102A, which communicates with one or more user equipment 106A, user equipment 106B to user equipment 106N, etc. through a transmission medium. Each user equipment in the user equipment may be referred to as a "user equipment" (UE) in this article. Therefore, user equipment 106 is referred to as UE or UE device.

[0042] The base station (BS) 102A can be a transceiver base station (BTS) or a cell site (“cellular base station”), and can include hardware that enables wireless communication with UEs 106A to 106N.

[0043] The communication area (or coverage area) of the base station can be referred to as a “cell”. The base station 102A and the UE 106 can be configured to communicate via a transmission medium using any of a variety of radio access technologies (RATs), which are also referred to as wireless communication technologies or telecommunication standards, such as GSM, UMTS (associated with, for example, WCDMA or TD-SCDMA air interfaces), LTE, advanced LTE (LTE-A), 5G new radio (5G NR), HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), etc. Note that if the base station 102A is implemented in the context of LTE, it may alternatively be referred to as an “eNodeB” or “eNB”. It should be noted that if the base station 102A is implemented in the context of 5G NR, it may alternatively be referred to as a “gNodeB” or “gNB”.

[0044] As shown in the figure, the base station 102A can also be equipped to communicate with the network 100 (e.g., in various possibilities, the core network of a cellular service provider, a telecommunication network such as the public switched telephone network (PSTN) and / or the Internet). Thus, the base station 102A can facilitate communication between user devices and / or between user devices and the network 100. Specifically, the cellular base station 102A can provide the UE 106 with various telecommunication capabilities such as voice, SMS, and / or data services.

[0045] Base stations 102A and other similar base stations (such as base stations 102B... 102N) operating according to the same or different cellular communication standards can thus provide a network of cells that can provide continuous or nearly continuous overlapping services to UEs 106A-N and similar devices over a geographical area via one or more cellular communication standards.

[0046] Thus, although the base station 102A can act as the “serving cell” of the UEs 106A-N as exemplified in Figure 1 each UE 106 may also be able to receive signals (and potentially be within its communication range) from one or more other cells (which may be provided by base stations 102B-N and / or any other base stations), and the one or more other cells can be referred to as “neighboring cells”. Such cells may also be able to facilitate communication between user devices and / or between user devices and the network 100. Such cells can include “macro” cells, “micro” cells, “pico” cells, and / or any various other granularities of cells providing service area sizes. For example, inFigure 1 The base stations 102A - B illustrated in [example] can be macro cells, while the base station 102N can be a micro cell. Other configurations are also possible.

[0047] In some embodiments, the base station 102A can be a next-generation base station, e.g., a 5G New Radio (5G NR) base station or a "gNB". In some embodiments, the gNB can be connected to a legacy Evolved Packet Core (EPC) network and / or connected to a NR Core (NRC) network. Additionally, a gNB cell can include one or more Transmission and Reception Points (TRPs). Further, a UE capable of operating according to 5G NR can be connected to one or more TRPs within one or more gNBs.

[0048] Note that the UE 106 may be capable of communicating using multiple wireless communication standards. For example, the UE 106 can be configured to communicate using wireless networking (e.g., Wi-Fi) and / or peer-to-peer wireless communication protocols (e.g., Bluetooth, Wi-Fi peer-to-peer, etc.) in addition to at least one cellular communication protocol (e.g., GSM, UMTS (associated with, e.g., WCDMA or TD-SCDMA air interfaces), LTE, LTE-A, 5G NR, HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), etc.). Optionally or alternatively, the UE 106 can also be configured to communicate using one or more Global Navigation Satellite Systems (GNSS, e.g., GPS or GLONASS), one or more mobile television broadcast standards (e.g., ATSC-M / H or DVB-H), and / or any other wireless communication protocol if needed. Other combinations of wireless communication standards (including more than two wireless communication standards) are also possible.

[0049] Figure 2 Illustrated is a UE 106 that communicates directly with the base station 102 via uplink communication and downlink communication according to one aspect of the present disclosure. The UE 106 can be a device with cellular communication capabilities, such as a mobile phone, a handheld device, a computer, or a tablet computer or virtually any type of wireless device. The UE 106 can include a processor configured to execute program instructions stored in a memory. The UE 106 can perform any of the method embodiments described herein by executing such stored instructions. Alternatively or additionally, the UE 106 can include programmable hardware elements, such as a Field Programmable Gate Array (FPGA) configured to execute any one or any part of any of the method embodiments described herein.

[0050] UE 106 may include one or more antennas for communicating using one or more wireless communication protocols or technologies. In some embodiments, UE 106 may be configured to communicate using, for example, CDMA2000 (1xRTT, 1xEV-DO, HRPD, eHRPD) or LTE using a single shared radio component and / or GSM or LTE using a single shared radio component. The shared radio component may be coupled to a single antenna or may be coupled to multiple antennas (e.g., for MIMO) for performing wireless communication. Generally, the radio component may include any combination of a baseband processor, analog RF signal processing circuitry (e.g., including filters, mixers, oscillators, amplifiers, etc.) or digital processing circuitry (e.g., for digital modulation and other digital processing). Similarly, the radio component may implement one or more receive chains and transmit chains using the foregoing hardware. For example, UE 106 may share one or more portions of a receive chain and / or a transmit chain among multiple wireless communication technologies such as those discussed above.

[0051] In some embodiments, UE 106 may include separate transmit chains and / or receive chains (e.g., including separate antennas and other radio components) for each wireless communication protocol it is configured to communicate with. As another possibility, UE 106 may include one or more radio components shared among multiple wireless communication protocols and one or more radio components uniquely used by a single wireless communication protocol. For example, UE 106 may include a shared radio component for communicating using either LTE or 5GNR (or LTE or 1xRTT, or LTE or GSM) and separate radio components for communicating using each of Wi-Fi and Bluetooth. Other configurations are possible.

[0052] Figure 3 An example simplified block diagram of communication device 106 in accordance with one aspect of the present disclosure is illustrated. Note that Figure 3The block diagram of the communication device is only an example of a possible communication device. According to an embodiment, in addition to other devices, the communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop, notebook or portable computing device), a tablet computer, and / or a combination of devices. As shown, the communication device 106 may include a set of components 300 configured to perform core functions. For example, the set of components may be implemented as a system on a chip (SOC), which may include portions for various purposes. Alternatively, the set of components 300 may be implemented as separate components or groups of components for various purposes. This set of components 300 may be (e.g., communicatively; directly or indirectly) coupled to various other circuits of the communication device 106.

[0053] For example, the communication device 106 may include various types of memory (e.g., including NAND flash 310), input / output interfaces such as connector I / F 320 (e.g., for connecting to a computer system; docking station; charging station; input devices such as a microphone, camera, keyboard; output devices such as a speaker; etc.), a display 360 that may be integrated with or external to the communication device 106, and cellular communication circuitry 330 such as for 5G NR, LTE, GSM, etc., and short-range to mid-range wireless communication circuitry 329 (e.g., Bluetooth TM and WLAN circuitry). In some embodiments, the communication device 106 may include wired communication circuitry (not shown), such as, for example, a network interface card for Ethernet.

[0054] The cellular communication circuitry 330 may be (e.g., communicatively; directly or indirectly) coupled to one or more antennas, such as the antennas 335 and 336 shown. The short-range to mid-range wireless communication circuitry 329 may also be (e.g., communicatively; directly or indirectly) coupled to one or more antennas, such as the antennas 337 and 338 shown. Alternatively, the short-range to mid-range wireless communication circuitry 329, in addition to (e.g., communicatively; directly or indirectly) being coupled to the antennas 337 and 338 or as an alternative, may be (e.g., communicatively; directly or indirectly) coupled to the antennas 335 and 336. The short-range to mid-range wireless communication circuitry 329 and / or the cellular communication circuitry 330 may include multiple receive chains and / or multiple transmit chains for receiving and / or transmitting multiple spatial streams, such as in a multiple-input multiple-output (MIMO) configuration.

[0055] In some embodiments, as further described below, the cellular communication circuitry 330 may include dedicated receive chains for multiple RATs (including and / or coupled to (e.g., communicatively; directly or indirectly) dedicated processors and / or radio components) (e.g., a first receive chain for LTE and a second receive chain for 5G-NR). Additionally, in some embodiments, the cellular communication circuitry 330 may include a single transmit chain that may switch between radio components dedicated to a particular RAT. For example, a first radio component may be dedicated to a first RAT, such as LTE, and may communicate with a dedicated receive chain and a transmit chain shared with additional radio components, such as a second radio component that may be dedicated to a second RAT (e.g., 5G NR) and may communicate with the dedicated receive chain and the shared transmit chain.

[0056] The communication device 106 may also include one or more user interface elements and / or be configured for use with one or more user interface elements. The user interface elements may include various elements such as a display 360 (which may be a touchscreen display), a keyboard (which may be a discrete keyboard or may be implemented as part of a touchscreen display), a mouse, a microphone and / or speaker, one or more cameras, one or more buttons, and / or any of various other elements capable of providing information to a user and / or receiving or interpreting user input.

[0057] The communication device 106 may also include one or more smart cards 345 having SIM (Subscriber Identity Module) functionality, such as one or more UICCs (Universal Integrated Circuit Cards) 345.

[0058] As shown, the SOC 300 may include a processor 302 and a display circuit 304, the processor may execute program instructions for the communication device 106, and the display circuit may perform graphics processing and provide a display signal to the display 360. The processor 302 may also be coupled to a memory management unit (MMU) 340 (which may be configured to receive addresses from the processor 302 and translate those addresses into locations in a memory (e.g., memory 306, read-only memory (ROM) 350, NAND flash memory 310)) and / or coupled to other circuits or devices (such as the display circuit 304, short-range wireless communication circuitry 229, cellular communication circuitry 330, connector I / F 320, and / or the display 360). The MMU 340 may be configured to perform memory protection and page table translation or setup. In some embodiments, the MMU 340 may be included as part of the processor 302.

[0059] As described above, the communication device 106 may be configured to communicate using wireless and / or wired communication circuitry. The communication device 106 may also be configured to determine physical downlink shared channel scheduling resources for a user equipment device and a base station. Additionally, the communication device 106 may be configured to select and group component carriers (CCs) from a wireless link and determine virtual CCs from the selected CC group. The wireless device may also be configured to perform physical downlink resource mapping based on an aggregated resource matching pattern of the CC group.

[0060] As described herein, the communication device 106 may include hardware and software components for implementing the above-described features for determining physical downlink shared channel scheduling resources for the communication device 106 and a base station. For example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), the processor 302 of the communication device 106 may be configured to implement some or all of the features described herein. Alternatively (or in addition), the processor 302 may be configured as a programmable hardware element, such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC). Alternatively (or in addition), in combination with one or more of the other components 300, 304, 306, 310, 320, 329, 330, 340, 345, 350, 360, the processor 302 of the communication device 106 may be configured to implement some or all of the features described herein.

[0061] Furthermore, as described herein, the processor 302 may include one or more processing elements. Accordingly, the processor 302 may include one or more integrated circuits (ICs) configured to perform the functions of the processor 302. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the processor 302.

[0062] In addition, as described herein, both the cellular communication circuitry 330 and the short-range wireless communication circuitry 329 may include one or more processing elements. In other words, one or more processing elements may be included in the cellular communication circuitry 330, and similarly, one or more processing elements may be included in the short-range wireless communication circuitry 329. Accordingly, the cellular communication circuitry 330 may include one or more integrated circuits (ICs) configured to perform the functions of the cellular communication circuitry 330. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the cellular communication circuitry 230. Similarly, the short-range wireless communication circuitry 329 may include one or more ICs configured to perform the functions of the short-range wireless communication circuitry 32. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the short-range wireless communication circuitry 329.

[0063] Figure 4 FIG. 0 illustrates an example block diagram of base station 102 in accordance with one aspect of the present disclosure. Note that Figure 4 the base station shown is only one example of possible base stations. As shown, base station 102 may include a processor 404 that may execute program instructions for base station 102. Processor 404 may also be coupled to a memory management unit (MMU) 440 or other circuitry or devices, which may be configured to receive addresses from processor 404 and translate those addresses to locations in memory (e.g., memory 460 and read-only memory (ROM) 450).

[0064] Base station 102 may include at least one network port 470. Network port 470 may be configured to couple to a telephone network and provide access to a plurality of devices such as UE 106 to the telephone network as described above in Figure 1 and Figure 2 .

[0065] Network port 470 (or an additional network port) may also be configured or alternatively may be configured to couple to a cellular network, such as a core network of a cellular service provider. The core network may provide mobility-related services and / or other services to a plurality of devices such as UE 106. In some cases, network port 470 may be coupled to the telephone network via the core network, and / or the core network may provide the telephone network (e.g., in other UEs served by the cellular service provider).

[0066] In some embodiments, base station 102 may be a next-generation base station, e.g., a 5G New Radio (5G NR) base station, or a “gNB”. In such embodiments, base station 102 may be connected to a legacy evolved packet core (EPC) network and / or connected to an NR core (NRC) network. Additionally, base station 102 may be considered a 5G NR cell and may include one or more transmission and reception points (TRPs). Additionally, a UE capable of operating according to 5G NR may be connected to one or more TRPs within one or more gNBs.

[0067] Base station 102 may include at least one antenna 434 and possibly a plurality of antennas. The at least one antenna 434 may be configured to function as a wireless transceiver and may be further configured to communicate with UE 106 via radio component 430. Antenna 434 communicates with radio component 430 via communication link 432. Communication link 432 may be a receive link, a transmit link, or both. Radio component 430 may be configured to communicate via various wireless communication standards, which include but are not limited to 5G NR, LTE, LTE-A, GSM, UMTS, CDMA2000, Wi-Fi, etc.

[0068] Base station 102 may be configured to perform wireless communication using multiple wireless communication standards. In some instances, base station 102 may include multiple radio components that may enable base station 102 to communicate according to multiple wireless communication technologies. For example, as one possibility, base station 102 may include an LTE radio component for performing communication according to LTE and a 5G NR radio component for performing communication according to 5G NR. In this case, base station 102 may be capable of operating as both an LTE base station and a 5G NR base station. As another possibility, base station 102 may include a multi-mode radio component capable of performing communication according to any one of multiple wireless communication technologies (e.g., 5G NR and Wi-Fi, LTE and Wi-Fi, LTE and UMTS, LTE and CDMA2000, UMTS and GSM, etc.).

[0069] As further described subsequently herein, BS102 may include hardware and software components for implementing or supporting the embodiments of the features described herein. The processor 404 of base station 102 may be configured to implement or support the embodiments of part or all of the methods described herein, for example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium). Alternatively, processor 404 may be configured as a programmable hardware element such as an FPGA (Field Programmable Gate Array), or as an ASIC (Application Specific Integrated Circuit), or a combination thereof. Alternatively (or in addition), in combination with one or more of the other components 430, 432, 434, 440, 450, 460, 470, the processor 404 of BS102 may be configured to implement or support the embodiments of part or all of the features described herein.

[0070] Furthermore, as described herein, processor 404 may be composed of one or more processing elements. In other words, one or more processing elements may be included in processor 404. Thus, processor 404 may include one or more integrated circuits (ICs) configured to perform the functions of processor 404. In addition, each integrated circuit may include circuits (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of processor 404.

[0071] Furthermore, as described herein, radio component 430 may be composed of one or more processing elements. In other words, one or more processing elements may be included in radio component 430. Thus, radio component 430 may include one or more integrated circuits (ICs) configured to perform the functions of radio component 430. In addition, each integrated circuit may include circuits (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of radio component 430.

[0072] Figure 5An example simplified block diagram of a cellular communication circuit in accordance with one aspect of the present disclosure is illustrated. Note that Figure 5 the block diagram of the cellular communication circuit is merely an example of a possible cellular communication circuit. According to an embodiment, the cellular communication circuit 330 may be included in a communication device such as the communication device 106 described above. As described above, the communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop computer, notebook or portable computing device), a tablet computer, and / or a combination of devices, among other things.

[0073] The cellular communication circuit 330 may be (e.g., communicatively; directly or indirectly) coupled to one or more antennas, such as the antennas 335a-b and 336 shown in ( Figure 3 )). In some embodiments, the cellular communication circuit 330 may include dedicated receive chains for multiple RATs (including and / or coupled to (e.g., communicatively; directly or indirectly) dedicated processors and / or radio components) (e.g., a first receive chain for LTE and a second receive chain for 5G NR). For example, as shown in Figure 5 , the cellular communication circuit 330 may include a modem 510 and a modem 520. The modem 510 may be configured for communication according to a first RAT (e.g., such as LTE or LTE-A), and the modem 520 may be configured for communication according to a second RAT (e.g., such as 5G NR).

[0074] As shown, the modem 510 may include one or more processors 512 and a memory 516 communicatively coupled to the processors 512. The modem 510 may communicate with a radio frequency (RF) front end 530. The RF front end 530 may include circuitry for transmitting and receiving radio signals. For example, the RF front end 530 may include a receive circuit (RX) 532 and a transmit circuit (TX) 534. In some embodiments, the receive circuit 532 may communicate with a downlink (DL) front end 550, which may include circuitry for receiving radio signals via the antenna 335a.

[0075] Similarly, the modem 520 may include one or more processors 522 and a memory 526 communicatively coupled to the processors 522. The modem 520 may communicate with an RF front end 540. The RF front end 540 may include circuitry for transmitting and receiving radio signals. For example, the RF front end 540 may include a receive circuit 542 and a transmit circuit 544. In some embodiments, the receive circuit 542 may communicate with a DL front end 560, which may include circuitry for receiving radio signals via the antenna 335b.

[0076] In some embodiments, switch 570 may couple transmit circuit 534 to an uplink (UL) front end 572. Additionally, switch 570 may couple transmit circuit 544 to UL front end 572. UL front end 572 may include circuitry for transmitting radio signals via antenna 336. Thus, when cellular communication circuit 330 receives an instruction to transmit according to a first RAT (e.g., supported via modem 510), switch 570 may be switched to a first state that allows modem 510 to transmit signals according to the first RAT (e.g., via a transmit chain including transmit circuit 534 and UL front end 572). Similarly, when cellular communication circuit 330 receives an instruction to transmit according to a second RAT (e.g., supported via modem 520), switch 570 may be switched to a second state that allows modem 520 to transmit signals according to the second RAT (e.g., via a transmit chain including transmit circuit 544 and UL front end 572).

[0077] As described herein, modem 510 may include hardware and software components for implementing the above-described features or for selecting periodic resource portions for user equipment devices and base stations and for various other techniques described herein. For example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), processor 512 may be configured to implement some or all of the features described herein. Alternatively (or in addition), processor 512 may be configured as a programmable hardware element, such as an FPGA (field programmable gate array) or as an ASIC (application specific integrated circuit). Alternatively (or in addition), in combination with one or more of the other components 530, 532, 534, 550, 570, 572, 335, and 336, processor 512 may be configured to implement some or all of the feature portions described herein.

[0078] Additionally, as described herein, processor 512 may include one or more processing elements. Thus, processor 512 may include one or more integrated circuits (ICs) configured to perform the functions of processor 512. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of processor 512.

[0079] As described herein, the modem 520 may include hardware and software components for implementing the above-described features or for selecting periodic resource portions on a wireless link between a UE and a base station and for various other techniques described herein. For example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), the processor 522 may be configured to implement some or all of the feature portions described herein. Alternatively (or in addition), the processor 522 may be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). Alternatively (or additionally), in combination with one or more of the other components 540, 542, 544, 550, 570, 572, 335, and 336, the processor 522 may be configured to implement some or all of the feature portions described herein.

[0080] Additionally, as described herein, the processor 522 may include one or more processing elements. Thus, the processor 522 may include one or more integrated circuits (ICs) configured to perform the functions of the processor 522. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the processor 522.

[0081] Figure 6 Illustrated is a scenario in which a gateway 620 in a personal Internet of Things (IoT) network (PIN network) 600 communicates with a core network 640 in a wireless communication network to register and authenticate the gateway 620 and a plurality of UEs.

[0082] Brief reference Figure 6, PIN 600 includes multiple PIN elements (PINEs), which can also be considered UEs. As already described, PIN elements (PINEs) can be considered the basic components that make up a PIN-user's personal IoT network. A PINE can be an IoT device, a UE, or any type of device that communicates with other PINEs within the PIN network and communicates with an external core network 640 through a gateway 620. As already described, it should be understood that the Internet of Things (IoT) describes a network of physical objects, i.e., "things" or IoT devices, that are embedded with sensors, software, and other technologies for the purpose of connecting and exchanging data with other devices and systems via wired networks, wireless networks, the Internet, etc. Thus, an IoT device can be almost any type of computing device. Localized personal IoT devices such as wearable devices and home automation devices are increasingly being used in personal IoT networks (PINs). For example, a wide variety of wearable IoT devices can be used locally: eyeglass frames, earbuds, blood pressure monitors, pacemakers, rings. Common IoT devices include: wireless sensor networks, control system networks, "smart home" devices (including devices and appliances such as lighting devices, thermostats, home security systems, cameras, and other home appliances). This is a very small and limited list of examples of IoT devices for use in a PIN.

[0083] For reference Figure 6 As an example, in this PIN 600 example, PIN 600 includes PINEs: UE1 / gate 602, UE2 / motion sensor 604, and UE3 / mobile device 606. These PINEs 602, 604, 606 can wirelessly dock with the gateway 620 directly or through relays 610, 612. A PINE 622 (e.g., a printer) can be directly connected to the gateway 620. It should be understood that this is only an example for illustrative purposes.

[0084] The gateway 620 can be a PIN element with gateway capabilities that acts as a gateway for wireless communication with a core network 640 including a base station 102. The gateway 620 can also provide access to a variety of public carrier networks (fixed / mobile / wired) and provide access from such public carrier networks. In this example, the gateway 620 can be a PIN element that can have both PIN management capabilities and gateway capabilities. The gateway 620 can operate as a bridge between IoT devices (602, 604, 606, 622) in the PIN 600, the core network 640 cloud, and other user equipment, such as other mobile devices (e.g., smartphones). Thus, the gateway 620 can be considered a gateway PINE (denoted as PINEG).

[0085] Even more specifically, as described below, the gateway 620 can communicate with the core network 640 in a wireless communication network to register and authenticate multiple UEs (602, 604, 606, etc.) of the gateway 620 and the PIN 600 in an optimized manner. It should be understood that the gateway 620 can be the UE 106 as previously described, and the devices 602, 604, 606 can also operate with the structure and functions of the UE 106 as previously described. In the following description, the terms "IoT device" and "UE" can be used interchangeably. Additionally, in the following description, the terms "base station" and "network" can be used interchangeably.

[0086] Brief reference Figure 7 , Figure 7 is a flowchart illustrating a process for a gateway 620 to register and authenticate IoT devices and UEs (e.g., 602, 604, 606) with a core network 640. It should be understood that the core network includes an Access and Mobility Management Function entity (AMF). In this example implementation, a method 700 for authenticating multiple User Equipments (UEs) to an Access and Mobility Management Function entity (AMF) of a core network of a communication network is disclosed. First, the method includes: sending a subscriber identifier (SI) of the gateway and an SI of each of the multiple User Equipments (UEs) in a registration request to the AMF of the communication network (block 702). Next, the process includes receiving an authentication request from the AMF that includes a random number (RAND) and an authentication token, where the RAND is associated with both the gateway and the UE. Next, the process verifies the authentication token (block 708) and calculates a gateway authentication response (block 710). Then, the process sends the RAND to all of the UEs (block 712). Then, the process: receives an authentication response from each of the UEs based on the RAND (block 714), and sends an authentication response including the gateway authentication response and the authentication responses from each of the UEs to the AMF (block 716). Thereafter, the process accepts registration of the gateway and the multiple UEs by the AMF of the core network (block 718).

[0087] Now refer Figure 8 , Figure 8 is a more detailed flowchart illustrating a process 800 for a gateway 810 to register and authenticate IoT devices and UEs (e.g., 802, 804, 806) with the AMF 812 of the core network 640. As Figure 8As shown, the gateway PINE 810 initiates a registration request. During the registration request, the gateway PINE 810 sends its own subscriber ID (PINE-ID) along with the subscriber IDs of each of the multiple other UEs (UE1802, UE 804, UE3 806) in the PIN to the AMF 812. Other PINEs select the gateway PINE for registration. For example, in a 5G example, these IDs can be Subscription Concealed Identifier / Globally Unique Temporary Identifier (SUCI) / 5G-GUTI. In one example, these UE-IDs are transmitted in sequence, e.g., UE1-ID, UE2-ID, etc. Then, the AMF 812 forwards the request to the Unified Data Management / Authentication Server Function entity (UDM / AUSF) 820 of the network. When the AMF 812 forwards the request to the UDM / AUSF 820 of the Home Public Land Mobile Network (HPLMN), the AMF notifies the HPLMN that all the UE-IDs in the UE-ID (here they are Subscription Concealed Identifiers (SUCI)) belong to the same PIN. This can be done by defining a new message (in which all the SUCI will be transmitted) or by transmitting several requests and creating a link between these several requests by using a link ID, operation ID, etc. When using this operation, the HPLMN UDM / AUSF can use the same RAND for all the PINE devices in these PINE devices belonging to the same PIN, and can create authentication vectors for all the devices and then transmit these authentication vectors to the AMF 812. Subsequently, the HPLMN UDM can provide the AMF with the real UE ID, i.e., the Subscription Permanent Identifier (SUPI).

[0088] Then, the AMF 812 transmits only one RAND in the authentication request message to the gateway pine 810 and only one authentication token (AUTN) corresponding to the RAND of the gateway. In addition, the core network also notifies the gateway pine 810 that this specific authentication request also applies to one or more PINEs with the corresponding UE-ID provided in the registration request message. The core network can do this by including a bitmap (instead of the actual UE-ID) corresponding to the UE that the core network wishes to authenticate.

[0089] Based on the authentication request received from the AMF 812, the gateway PINE 810 can locally verify the authentication request from the network according to the authentication token check. In addition, the gateway PINE 810 can calculate its gateway response. Once the network has been verified by the gateway pine810, the gateway pine 810 transmits the RAND to all other PINE devices (UE1 802, UE2 804, UE3 806). All PINEs in the PINE behind the gateway PINE 810 have been configured to rely on the gateway PINE 810 to verify the network based on the authentication token. As an alternative, the gateway PINE 810 can simply notify the PINE that it has verified the network. Then, each PINE device (UE1 802, UE2 804, UE3 806) calculates its own response (RES1, RES2, RES3) and transmits it to the gateway PINE 810.

[0090] Then, the gateway PINE 810 responds to the network by sending an authentication response message to the AMF 812, which includes the gateway pine response, the UE1 response (RES1), the UE2 response (RES2), and the UE3 response (RES3). The responses from other PINEs are transmitted in the same order and based on the same bitmap that the network transmitted to the gateway PINE 810 in the authentication request message.

[0091] The benefit of this process is that although the AMF 812 only transmits one RAND to the gateway PINE 810, all PINEs in other PINEs (UE1 802, UE2 804, UE3 806) can be authenticated through the same process.

[0092] Brief reference Figure 9 , Figure 9is a flowchart illustrating process 900 for a gateway to register and authenticate IoT devices and UEs with a core network. As described below, the process includes random numbers associated with each UE. In this other exemplary embodiment, a method 900 for authenticating multiple user equipments (UEs) to an access mobility function entity (AMF) of a core network of a communication network is disclosed. First, the method includes: sending a subscriber identifier (SI) of the gateway and an SI of each of the multiple user equipments (UEs) to the AMF of the communication network in a registration request (block 902). Next, the process includes receiving an authentication request from the AMF, the authentication request including a random number (RAND) for each UE, a RAND for the gateway, and an authentication token for the gateway (block 914). Next, the process verifies the authentication token at the gateway (block 908) and calculates a gateway authentication response (block 910). Then, the process sends each RAND for each UE to each UE (block 912). Then, the process: receives an authentication response from each UE among the UEs based on each RAND for each UE (block 914), and sends an authentication response including the gateway authentication response and the authentication responses from each UE among the UEs to the AMF (block 916). Thereafter, the process accepts registration of the gateway and the multiple UEs by the AMF of the core network (block 918).

[0093] Now refer to Figure 10 , Figure 10 is a more detailed flowchart illustrating process 1000 for a gateway 1110 to register and authenticate IoT devices and UEs (e.g., 1002, 1004, 1006) with an AMF 1112 of a core network. As Figure 10 shown, the gateway PINE 1110 initiates a registration request. During the registration request, the gateway PINE 1110 sends its own subscriber ID (PINE-ID) along with the subscriber ID of each of the multiple other UEs (UE1 1002, UE 1004, UE3 1006) in the PIN to the AMF 1112. The other PINE selects the gateway PINE for registration.

[0094] For example, in a 5G example, these IDs can be Subscription Concealed Identifier / Global Unique Temporary Identifier (SUCI / 5G-GUTI). In one example, these UE-IDs are transmitted sequentially, e.g., UE1-ID, UE2-ID, etc. Then, the AMF 1112 transmits the request to the Unified Data Management / Authentication Server Function entity (UDM / AUSF) 1120 of the network. When the AMF 1112 transmits a request to the UDM / AUSF 1120 of the Home Public Land Mobile Network (HPLM), the AMF notifies the HPLMN that all the UE-IDs in the UE-ID (here they are Subscription Permanent Identifiers (SUPI)) belong to the same PIN. This can be done by defining a new message (in which all the SUPIs will be transmitted) or by transmitting several requests and creating a link between these several requests by using a link ID, an operation ID, etc. When using this operation, the HPLMN UDM / AUSF can use a different RAND for each PINE device among the PINE devices belonging to the same PIN, and can create authentication vectors for all the devices among these devices, and then transmit these authentication vectors to the AMF 1112.

[0095] Then, the AMF 1112 transmits different RANDs to the gateway pine 1110, each RAND belonging to one PINE in the authentication request. For example, the authentication request to the gateway pine 1110 can include a regular RAND corresponding to the gateway pine and then RANDs transmitted as new IEs for each UE, such as: RAND1 for UE1, RAND2 for UE2, RAND3 for UE3. However, the AMF 112 only includes one authentication token (AUTN) corresponding to the 1110RAND of the gateway pine 1110 of the gateway pine. In this implementation, only the gateway pine 1110 verifies the network by locally checking the AUTN. Based on the authentication request received from the AMF 1112, the gateway PINE 1110 can locally verify the authentication request from the network according to the authentication token parameter check. In addition, the gateway PINE 1110 can calculate its gateway response.

[0096] Once the network has been verified by the gateway pine 1110, the gateway pine 1110 will transmit different RANDs to each PINE associated with it (e.g., RAND1 to UE1, RAND2 to UE2, RAND3 to UE3). In this communication, the gateway pine 1110 notifies the PINEs 1002, 1004, and 1006 that it has verified the network.

[0097] Then, each PINE device (UE1 1002, UE2 1004, UE3 1006) calculates its own response (RES1, RES2, RES3) and transmits it to the gateway PINE 1110. Then, the gateway PINE 1110 responds to the network by sending an authentication response message to the AMF 1112, the authentication response message including the gateway pine response, the UE1 response (RES1), the UE2 response (RES2), and the UE3 response (RES3). The responses from the other PINEs are transmitted in the same order as the network transmitted them to the gateway PINE 810 in the authentication request message.

[0098] In some embodiments, in the case where the number of PINEs behind the gateway becomes very large such that the authentication response message becomes too long, the gateway may transmit more than one authentication response to the network. When doing so, subsequent authentication response messages may be chained to the first message and will include the RESs in the same order as described above. These subsequent messages will also have new IEs to inform the network which message is being transmitted (e.g., message number 3) and which message is the last message. Using this method, in the case where a message is lost, the network can simply request the PINE gateway to retransmit that particular message. Additionally, the network can discover when the sequence ends.

[0099] Thus, as previously described, in an example embodiment, a gateway for a communication network is disclosed, the gateway including: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with the communication network using the at least one antenna; and at least one processor, the at least one processor being coupled to the at least one radio component. The at least one processor may be configured to perform operations including: sending the subscriber identifier of the gateway and the subscriber identifier of each user equipment (UE) among a plurality of user equipments (UEs) in a registration request to an access mobility function (AMF) entity; receiving, from the AMF, an authentication request including a random number (RAND) and an authentication token, wherein the RAND is associated with both the gateway and the UE; verifying the authentication token; calculating a gateway authentication response; and sending the RAND to the UE. The processor of the gateway further: receives an authentication response from each UE among the UEs based on the RAND; sends an authentication response including the gateway authentication response and the authentication responses from each UE among the UEs to the AMF; and then accepts registration of the gateway and the plurality of UEs by the AMF entity. In this example embodiment, a single RAND is utilized. In another embodiment, as previously described, a particular RAND number may be specifically associated with each UE.

[0100] In addition, as previously described, in another example implementation, a user equipment (UE) (e.g., IoT) in a PIN may include: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with a communication network using the at least one antenna; and at least one processor is disclosed, the at least one processor being coupled to the at least one radio component. The at least one processor may be configured to perform operations including: receiving a random number (RAND) from a gateway, wherein the RAND is received from the gateway in an authentication request from an access mobility function entity (AMF) of the communication network, wherein based on a registration request from the gateway to the AMF including subscriber identifiers of the gateway, the UE, and a plurality of other UEs associated with the gateway, the RAND is associated with the gateway, the UE, and the plurality of other UEs; calculating an authentication response to the AMF based on the RAND; and sending the authentication response to the gateway, wherein the gateway sends an authentication response including the authentication response of the gateway and the authentication response of the UE to the AMF. In another implementation, as previously described, a specific RAND number may be specifically associated with each UE.

[0101] It should be understood that the gateway pine as previously described may be the UE 106 as previously described, which utilizes the processor, antenna, radio component, etc. as previously described to perform its previously described functions. In addition, the IoT or other types of UEs in the PIN may similarly be the UE 106 as previously described, which utilizes the processor, antenna, radio component, etc. as previously described to perform its previously described functions. However, it should be understood that a specific type of IoT in the PIN network may have other types of processors and communication technologies. Thus, as already described, the terms "IoT device" and "UE" may be used interchangeably. In addition, in the previous description, the terms "base station" and "network" may be used interchangeably. In addition, the baseband processors of the UE and the base station have been previously described. It should also be understood that the baseband processors of the gateway, UE, IoT, etc. may implement the previously described functions.

[0102] The previously described methods, processes, gateways, UEs, and IoT enhance and optimize the authentication and security procedures of a personal IoT network (PIN) in a communication network. Specifically, by utilizing the previously described specific implementations, several devices (e.g., gateway, UE, PINE) can be authenticated during one and the same procedure by enhancing and modifying the signaling procedures using the previously described devices, rather than running several parallel separate procedures as currently done, as previously described.

[0103] Portions of the above-described subject matter can be implemented using logic circuitry such as dedicated logic circuits or using a microcontroller or other form of processing core that executes program code instructions. Thus, program code such as machine-executable instructions can be used to perform the processes taught by the above discussion, the machine-executable instructions causing the machine to execute the instructions to perform certain functions. In this context, a "machine" can be a machine that converts intermediate form (or "abstract") instructions into processor-specific instructions (e.g., an abstract execution environment such as a "virtual machine" (e.g., Java virtual machine), interpreter, common language runtime, high-level language virtual machine, etc.), and / or an electronic circuit disposed on a semiconductor chip (e.g., a "logic circuit" implemented using transistors), the electronic circuit being designed to execute instructions, the processor such as a general-purpose processor and / or a dedicated processor. The processes taught by the above discussion can also be performed by (in place of or in combination with a machine) an electronic circuit that is designed to perform the process (or a portion thereof) without executing program code.

[0104] For example, the described operations can be stored as instructions on a non-transitory computer-readable medium for execution by a computer. The computer-executable instructions are to receive configuration information for measuring and reporting downlink channel characteristics from a communication network, measure channel characteristics of a downlink beam from the communication network to generate channel measurement results based on the configuration information, report the channel measurement results to the communication network to enable the communication network to adapt the downlink beam to a multicast beam to provide multicast services to the UE and other UEs in the multicast group, and receive the multicast beam from the communication network to receive the multicast service.

[0105] The present invention also relates to an apparatus for performing the operations described herein. The apparatus can be specifically constructed for the required purpose or can include a general-purpose computer selectively activated or reconfigured by a computer program stored in the computer. Such a computer program can be stored in a computer-readable storage medium, such as but not limited to any type of disk, including floppy disks, optical disks, CD-ROMs, and magneto-optical disks, read-only memory (ROM), RAM, EPROM, EEPROM, magnetic or optical cards, or any type of medium suitable for storing electronic instructions, and each is coupled to the computer system bus.

[0106] A machine-readable medium includes any mechanism that stores or transmits information in a form readable by a machine (e.g., a computer). For example, a machine-readable medium includes read-only memory ("ROM"); random access memory ("RAM"); magnetic disk storage media; optical storage media; flash devices; etc.

[0107] An article can be used to store program code. The article storing the program code can be implemented as, but not limited to, one or more memories (e.g., one or more flash memories, random access memories (static, dynamic, or others)), optical discs, CD-ROMs, DVD ROMs, EPROMs, EEPROMs, magnetic or optical cards, or other types of machine-readable media suitable for storing electronic instructions. Program code can also be downloaded from a remote computer (e.g., a server) to a requesting computer (e.g., a client) by means of a data signal embodied in a propagated medium (e.g., via a communication link such as a network connection).

[0108] The foregoing detailed description has been presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the tools used by those skilled in the data processing art to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, a self-consistent sequence of operations leading to a desired result. These operations are those requiring physical manipulation of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It has proven convenient at times, principally for reasons of commonality, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc.

[0109] However, it should be borne in mind that all of these and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to these quantities. Unless otherwise specifically stated, it will be apparent from the above discussion that, throughout the specification, discussions using terms such as "select", "determine", "receive", "form", "group", "aggregate", "generate", "remove", etc. refer to actions and processes of a computer system or similar electronic computing device that can manipulate data represented as physical (electronic) quantities in the registers and memories of the computer system and transform them into other data similarly represented as physical quantities in the computer system memory or registers or other such information storage, transmission, or display devices.

[0110] The processes and displays presented herein are not inherently related to any particular computer or other device. According to the teachings herein, various general-purpose systems can be used with the program, or it may prove convenient to construct more specialized devices for performing the described operations. The required structure for various such systems will be apparent from the following description. In addition, the present invention has not been described with reference to any particular programming language. It should be understood that a variety of programming languages can be used to implement the teachings of the present invention as described herein.

[0111] The foregoing discussion has described only some exemplary embodiments of the present invention. Those skilled in the art will readily recognize from these discussions, the drawings, and the claims that various modifications can be made without departing from the spirit and scope of the present invention.

Claims

1. A gateway for a communication network, the gateway comprising: at least one antenna; at least one radio component, wherein the at least one radio component is configured to communicate with the communication network using the at least one antenna; and at least one processor or baseband processor, the at least one processor or baseband processor being coupled to the at least one radio component, wherein the at least one processor or baseband processor is configured to perform operations including the following: send the subscriber identifier of the gateway and the subscriber identifier of each user equipment (UE) among a plurality of user equipments (UEs) in a registration request to an access mobility function entity (AMF) of the communication network; receive an authentication request including a random number (RAND) and an authentication token from the AMF, wherein the RAND is associated with both the gateway and the UE; verify the authentication token; calculate a gateway authentication response; send the RAND to the UE; receive an authentication response from each UE among the UEs based on the RAND; send an authentication response including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and accept registration of the gateway and the plurality of UEs by the AMF of the communication network.

2. The gateway according to claim 1, wherein the plurality of UEs and the gateway are configured to communicate in a personal IoT network (PIN).

3. The gateway according to any one of claims 1 and 2, wherein the subscriber identifier of each UE among the plurality of UEs is sent to the AMF of the communication network in sequence in the registration request.

4. The gateway according to any one of claims 1 to 3, wherein the authentication token is verified by implementing an authentication token parameter check.

5. The gateway according to any one of claims 1 to 4, wherein the authentication request from the AMF further includes a bitmap identifying the UEs to be authenticated in sequence.

6. The gateway according to claim 5, wherein the authentication response including the gateway authentication response and the authentication response from each UE among the UEs sent to the AMF includes responses from the UEs sorted in the same order as in the bitmap of the authentication request.

7. A method for authenticating a plurality of user equipments (UEs) to an access mobility function entity (AMF) of a communication network, the method comprising: send the subscriber identifier of a gateway and the subscriber identifier of each user equipment (UE) among the plurality of user equipments (UEs) in a registration request to the AMF of the communication network; receive an authentication request including a random number (RAND) and an authentication token from the AMF, wherein the RAND is associated with both the gateway and the UE; verify the authentication token; calculate a gateway authentication response; send the RAND to the UE; receive an authentication response from each UE among the UEs based on the RAND; send an authentication response including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; and The AMF of the communication network accepts the registration of the gateway and the multiple UEs.

8. The method according to claim 7, wherein the multiple UEs and the gateway are configured to communicate in a Personal IoT Network (PIN).

9. The method according to any one of claims 7 and 8, wherein the subscriber identifier of each of the multiple UEs is sequentially sent to the AMF of the communication network in the registration request.

10. The method according to any one of claims 7 to 9, wherein the authentication token is verified by implementing an authentication token parameter check.

11. The method according to any one of claims 7 to 10, wherein the authentication request from the AMF further includes a bitmap identifying the UEs to be authenticated sequentially.

12. The method according to claim 11, wherein the authentication response sent to the AMF, including the gateway authentication response and the authentication response from each of the UEs, includes responses from the UEs sorted in the same order as in the bitmap of the authentication request.

13. A processor of a wireless user equipment (UE) of a communication network, the processor being configured to: Receive a random number (RAND) from a gateway, wherein the RAND is received from the gateway in an authentication request from an Access and Mobility Function entity (AMF) of the communication network, and wherein the RAND is associated with both the gateway and the UE associated with the gateway based on a registration request from the gateway to the AMF including subscriber identifiers of the gateway, the UE, and multiple other UEs; Calculate an authentication response to the AMF based on the RAND; and Send the authentication response to the gateway, wherein the gateway sends the authentication response to the AMF, and wherein the authentication response includes the authentication response of the gateway and the authentication response of the UE.

14. The processor according to claim 13, wherein the UE, the multiple other UEs, and the gateway are configured to communicate in a Personal IoT Network (PIN).

15. The processor according to any one of claims 13 and 14, wherein in the registration request to the AMF of the communication network, the subscriber identifiers of the UE and the multiple other UEs are arranged in sequence.

16. The processor according to any one of claims 13 to 15, wherein the authentication request from the AMF further includes a bitmap identifying the UEs to be authenticated sequentially.

17. The processor according to any one of claims 13 to 16, wherein the processor is a baseband processor.

18. A gateway of a communication network, the gateway comprises: At least one antenna; At least one radio component, wherein the at least one radio component is configured to communicate with a communication network using the at least one antenna; and At least one processor or baseband processor, the at least one processor or baseband processor being coupled to the at least one radio component, wherein the at least one processor is configured to perform operations including the following: Send the subscriber identifier of the gateway and the subscriber identifier of each user equipment (UE) among multiple user equipments (UEs) in a registration request to the access mobility function entity (AMF) of the communication network; Receive an authentication request from the AMF, the authentication request including a RAND associated with the gateway, random numbers (RANDs) respectively associated with each UE, and an authentication token corresponding to the RAND associated with the gateway; Verify the authentication token; Calculate a gateway authentication response; Send each RAND associated with each UE to each UE respectively; Receive an authentication response from each UE among the UEs based on the RAND of each UE; Send an authentication response respectively including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; And Accept the registration of the gateway and the multiple UEs by the AMF of the communication network.

19. The gateway according to claim 18, wherein the multiple UEs and the gateway are configured to communicate in a personal IoT network (PIN).

20. The gateway according to any one of claims 18 and 19, wherein the subscriber identifier of each UE among the multiple UEs is sent to the AMF of the communication network in sequence in the registration request.

21. The gateway according to any one of claims 18 to 20, wherein the authentication token is verified by implementing an authentication token parameter check.

22. The gateway according to any one of claims 18 to 21, wherein after verifying the authentication token, the UE is notified that the authentication token has been verified.

23. A method for authenticating multiple user equipments (UEs) to an access mobility function entity (AMF) of a communication network, the method comprises: Send the subscriber identifier of the gateway and the subscriber identifier of each user equipment (UE) among the multiple user equipments (UEs) in a registration request to the AMF of the communication network; Receive an authentication request from the AMF, the authentication request including a RAND associated with the gateway, random numbers (RANDs) respectively associated with each UE, and an authentication token corresponding to the RAND associated with the gateway; Verify the authentication token at the gateway; Calculate a gateway authentication response; Send each RAND associated with each UE to each UE respectively; Receive an authentication response from each UE among the UEs based on the RAND of each UE; Send an authentication response respectively including the gateway authentication response and the authentication response from each UE among the UEs to the AMF; And Accept the registration of the gateway and the multiple UEs by the AMF of the communication network.

24. The method according to claim 23, wherein the multiple UEs and the gateway are configured to communicate in a personal IoT network (PIN).

25. The method according to any one of claims 23 and 24, wherein the subscriber identifier of each UE among the plurality of UEs is sequentially sent to the AMF of the communication network in the registration request.

26. The method according to any one of claims 23 to 25, wherein the authentication token is verified by implementing an authentication token parameter check, and after verifying the authentication token, the UE is notified that the authentication token has been verified.

27. A processor of a wireless user equipment (UE) of a communication network, the processor being configured to: Receive a random number (RAND) associated with the UE, wherein the RAND for the UE is received from the gateway in an authentication request from the AMF based on a registration request including the subscriber identifiers of the gateway, the UE, and a plurality of other UEs from the gateway to the access mobility function entity (AMF) of the communication network; Calculate an authentication response to the AMF based on the RAND; And Send the authentication response to the gateway, wherein the gateway sends the authentication response to the AMF, and the authentication response includes the authentication response of the gateway and the authentication response of the UE.

28. The processor according to claim 27, wherein the subscriber identifier of each UE among the plurality of UEs is sequentially sent to the AMF of the communication network in the registration request, and after the authentication token is verified by the gateway, the UE is notified that the authentication token has been verified.

29. The processor according to any one of claims 27 and 28, wherein the processor is a baseband processor.