Wireless transmission device and system for authenticating such device
The wireless transmission device generates and sends a single message of the encryption device identifier, and uses long-term keys and random numbers to generate and export keys, which solves the problem of lengthy traditional authentication process, realizes fast and lightweight authentication, and improves data transmission efficiency.
Patent Information
- Application Number
- CN202380085460.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-15
- Filing Date
- 2023-11-23
- Publication Date
- 2025-08-12
AI Technical Summary
The traditional authentication and security association process is too verbose for wireless transmission devices, especially in cases of limited power or unstable connections, resulting in high overhead and low efficiency.
A single message containing the encryption device identifier is generated and sent by a wireless transmission device, and a long-term key and random number are used to generate and export keys. It can be quickly authenticated through the authentication system on the network side to avoid bidirectional connection requirements.
A fast and lightweight authentication process is realized when the power of the wireless transmission device is limited or the connection is unstable, reducing the authentication overhead and improving data transmission efficiency.
Smart Images

Figure CN120476566A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to wireless transmission devices and authentication systems. In particular, the present disclosure relates to a wireless transmission device configured to perform transmissions to a network, the network comprising at least a wireless receiving node configured to wirelessly receive transmissions and another network system downstream of the wireless receiving node in the network. The present disclosure also relates to a network system configured to perform transmissions to the wireless device. Background Art
[0002] For a traditional user equipment (UE) to send data transmissions to a telecommunications network, the network typically first authenticates the UE and establishes a secure, bidirectional, end-to-end connection or channel to a node (e.g., a node after a wireless receiving node in the core network). The UE can then securely transmit messages to the network. 3GPP TS 33.501 specifies this authentication process between the UE and the 5G core network (5GC). Summary of the Invention
[0003] The inventors have recognized that new use cases have arisen where wireless transmission devices are unable to securely send messages using traditional authentication and security procedures.
[0004] For example, 3GPP recently published a study on ambient power-enabled Internet of Things (IoT) in technical recommendation 3GPP TR 22.840. The document discloses the use cases and requirements for ambient power-enabled IoT devices (hereinafter also referred to as ambient IoT devices), which are battery-free devices with limited energy storage capabilities (which may include capacitors), where energy is provided by harvesting radio waves, light, motion, heat, or any other suitable power source. The study assumes that 5G networks can be used to send discovery signals to discover ambient IoT devices in an area, and that the ambient IoT devices establish communication with the 5G network to send their identities and, for example, product information to the 5G network for further processing in a management platform. However, since such ambient IoT devices exclusively harvest power from external stimuli, it will be difficult for such ambient IoT devices to perform lengthy procedures to authenticate and establish a two-way association to send messages.
[0005] Likewise, UEs can connect to telecommunication networks via satellites acting as quasi-base stations. If such UEs are required to authenticate and establish security associations using traditional methods to send messages, a bidirectional link to the telecommunication system is required, which may not always be available via satellites providing hop-by-hop connectivity.
[0006] Yet another use case where traditional authentication may be problematic is in the area of vehicle-to-everything (V2X) type communications, where high mobility may result in intermittent connections rather than a stable, bidirectional connection for performing authentication and having a security association.
[0007] Additional use cases have been envisioned, such as using a repeater that is reachable by a wireless transmission device but is not always connected to the network (e.g., a gateway device in a residential or commercial environment). In this case, it is also desirable that the wireless transmission device can transmit small messages without having to first wait for the repeater to (re)connect to the network for authentication and security association.
[0008] It will be appreciated that other considerations may apply to the use of fast authentication messages as disclosed herein. One example would be that the amount of data to be transmitted is small, making it inefficient to perform an extended authentication process and establish a security context. Such procedures would result in higher overhead than is justified for exchanging actual data between the wireless device and the network.
[0009] In order to achieve authenticated transmission in such situations, the inventors propose a wireless transmission device that can transmit authenticatable messages in a short time, which does not require a two-way connection as required in conventional authentication and / or security association procedures.
[0010] To this end, a wireless transmission device is disclosed, the wireless transmission device being configured to perform a transmission to a network comprising at least a wireless receiving node configured to wirelessly receive the transmission and another network system in the network following the wireless receiving node. The transmission is configured to be authenticated in the network without requiring a bidirectional connection between the wireless transmission device and the other network nodes in the network. Therefore, the wireless transmission device may include a long-term key, one or more random numbers, and a device identifier. The wireless transmission device may be configured to generate a derived key from the long-term key and a random number of the one or more random numbers. The transmission may include a single message comprising at least the device identifier encrypted with the derived key for authentication in the network. The other network system (e.g., an authentication system therein) may have access to the long-term key of the wireless transmission device and may have access to the random numbers used by the wireless transmission device.
[0011] Another aspect of the present disclosure relates to an authentication system in a network that has access to a random number used by a wireless transmission device to derive a derivation key and a long-term key for the wireless transmission device. The authentication system is configured to receive a single message from the wireless transmission device, the single message including a device identifier of the wireless transmission device encrypted with the derivation key. The authentication system is further configured to access the long-term key and the random number based on the device identifier of the wireless transmission device accessible to the authentication system to derive the derivation key, and to authenticate the wireless transmission device by decrypting the encrypted device identifier from the single message using the derivation key. The authentication system can determine that the device identifier of the wireless transmission device is authentic, for example, by comparing the decrypted device identifier with the device identifier corresponding to the long-term key. The authentication system does not require a two-way connection with the wireless transmission device.
[0012] The wireless transmission device generates and the authentication system processes a single message containing sufficient information to authenticate the wireless transmission device. This single message eliminates the need for traditional authentication and association procedures, which require multiple bidirectional steps and are inherently lengthy. The wireless transmission device and authentication system provide a lightweight authentication solution for situations where the wireless transmission device is severely power-constrained or where establishing a bidirectional connection between the wireless transmission device and the authentication system is unfeasible.
[0013] It should be understood that the wireless transmission device is defined as containing at least one random number, i.e., a random number that is used only once in encrypted communications. In one embodiment, the wireless transmission device may include a generator that generates a random number based on input parameters, such that the device contains the random number when needed to derive a key. In another embodiment, the wireless transmission device stores one or more random numbers in a storage portion of the device for this purpose. The network (such as an authentication system therein) may be configured to derive the random number based on the same input parameters as used by the random number generator of the wireless transmission device, or the wireless transmission device may transmit the random number or input parameters to the authentication system, for example, in a single message or in a previous single message.
[0014] It should be noted that more than one random number may be used for the transmission of a single message or a single message may be used in the transmission of a single message. For example, additional random numbers may be used in additional encryption functions to encrypt the contents of a single message.
[0015] It should be appreciated that the wireless receiving node provides a radio interface for wireless communication directly with the wireless transmission device. The further network node is a node subsequent to the wireless receiving node, which may have a wireless or wired connection to the wireless receiving node, such as a base station, a satellite, a system that performs control plane functions in 5G or another network generation, such as an access and mobility function AMF, an authentication server function AUSF, a unified data management UDM function, or a dedicated authentication function in a telecommunications network.
[0016] It should be appreciated that prior to sending the single message, a Radio Resource Control, RRC, connection may exist or be established between the wireless transmitting device and the wireless receiving node.
[0017] The single message contains the device identifier in encrypted form to enable authentication of the wireless transmission device. The device identifier may also be of interest as data for purposes other than authentication, for example when merely verifying the presence of the device. However, in one embodiment, the single message may contain a small amount of additional data. Such data may include, without limitation, data collected by sensors of the wireless transmission device or by sensors connected to the wireless transmission device, data representing a state in the wireless transmission device or a state of the wireless transmission device, or data stored in the device. The data may be encrypted with a derived key to protect the data during transmission to the wireless receiving node. Additionally or alternatively, the data may be encrypted with a client key available to the wireless transmission device and the client system to protect the data in the telecommunications network until the data reaches the client system.
[0018] In one embodiment, a single message for a wireless transmission device may also include information representing an identifier associated with the wireless transmission device. This information may be a device identifier, a temporary identifier, or some other form of device identifier that is also used for authentication. The authentication system may use the information representing the device identifier to access a long-term key and / or a random number used to derive a key. It should be appreciated that, alternatively or as a further check, the authentication system may also access the long-term key and random number in another way. One way that the network may know the device is that, for example, a single message enters via a specific channel or link (e.g., on a lower layer protocol, such as RRC signaling), which the network may associate with the device identifier. The wireless receiving node may further forward part or all of the single message to the network, such as to the authentication system, for authentication.
[0019] In one embodiment, a single message from the wireless transmission device may also include information representing a random number from the one or more random numbers used to generate the derived key. In this manner, the authentication system can determine the random number used to derive the derived key from the single message. It should be appreciated that the information representing the random number may include the random number itself, an identifier for the random number, input parameters used to generate the random number, or some other form of random number.
[0020] As mentioned above, one particular use case where rapid authentication is highly desirable involves ambient IoT devices. In one embodiment, the wireless transmission device comprises such an ambient IoT device, which is a battery-free device that receives operating power from the environment (such as from radio signals, light, heat, motion, etc.). An example of an ambient IoT device is the device disclosed in 3GPP TR 22.840. The ambient IoT device can be a simple battery-free device that can be attached to a product, such as a sticker.
[0021] In one embodiment, the wireless transmission device may include at least a power acquisition part configured to acquire power from a power signal such as a radio signal, and a communication part configured to be powered by the power signal and to wirelessly transmit a single message to a wireless receiving node while being powered by the power signal.
[0022] In one embodiment, power may be drawn from a single power pulse of limited duration.Due to the limited period of time during which power is available, such devices benefit from rapid authentication in the network to which a single message is transmitted.
[0023] In one embodiment, the wireless transmission device may include a receiver configured to receive a signal indicating confirmation of successful authentication of the wireless transmission device or successful receipt of a single message in the network. Such confirmation may be received when a connection to the wireless transmission device may be temporarily available and the wireless transmission device is powered. The device may use the confirmation, for example, as an indication to discard data from its storage device.
[0024] In one embodiment, the wireless transmission device may include a receiver for receiving new random number information. In this way, the wireless transmission device can update the random number or set of random numbers it uses to derive the key. The new random number information can come from the network and can be used to ensure that both the wireless transmission device and the network use the same random number to derive the key.
[0025] Alternatively, the wireless transmission device may interpret the new random number information as confirmation of successful authentication of the wireless transmission device in the network or successful receipt of a single message.
[0026] It should be appreciated that, in response to the transmission of a single message, the confirmation signal and / or the new random number information may be transmitted to and received by the wireless transmission device at a later point in time than immediately after transmission. For example, such transmission may be performed when there is a connection from the network to the wireless transmission device.
[0027] More generally, the receiver of a wireless transmission device can be configured to receive additional data or instructions from the network. For wireless transmission devices that draw power from the environment, the network typically does not know when communication with the device is possible. Therefore, responding to a single message from the wireless transmission device may be a good option for attempting to transmit additional data, such as an acknowledgment, random number information, deactivation messages, update information, etc., to be received, processed, and potentially stored by the wireless transmission device.
[0028] In one embodiment, the wireless transmission device can be configured to draw power from at least one of data and instructions received from the network, such as a signal indicating successful authentication or successful transmission of a single message and new random number information. The authentication system can be configured to transmit at least one of these with sufficient power to power the wireless transmission device from which the single message was authenticated. This can increase the chances of enabling surrounding IoT devices to process the data and / or instructions, for example.
[0029] In one embodiment, a wireless transmission device may include a memory portion for storing data. The wireless transmission device may be configured to transmit a plurality of individual messages, each of which includes at least a device identifier encrypted with a derived key and the data stored in the memory portion, or a portion of the data. This embodiment facilitates sending a large amount of data as a plurality of individual messages, wherein each message can be individually authenticated.
[0030] Alternatively, or in addition to the above, it should be appreciated that the network system can also transmit a single message as disclosed herein to a wireless transmission device (such as a UE or ambient IoT device) via a wireless radio interface. Such a message would not require prior authentication or security context to be established between the network and the wireless transmission device. (In this case, the wireless transmission device would be solely a wireless receiving device or a combined wireless transmission / reception device, as the signaling message would be sent in both the uplink and downlink directions; to encompass these options, the term wireless device is used in the remainder of this paragraph.) The network system can include a network element (e.g., a wireless transmission network node or a core network node) configured to transmit the single message and an authentication system with access to the wireless device's long-term key. If the wireless device is an ambient IoT device, it should be ensured that the wireless device is sufficiently powered, e.g., powered by the single message from the network element, to process the single message. In this example where the network element transmits the single message, the wireless device would be configured to authenticate the network element. The single message can contain a device identifier in plain text, allowing the wireless device to easily verify that the single message is addressed to it. The wireless device may have access to the same random number used by the network to derive the key from the long-term key. Prior to receiving a single message, one or more random numbers may be provided to the wireless device. This single message may contain information indicating the random number in plain text, which is particularly useful if the wireless device has access to multiple random numbers. Alternatively, the single message may contain the random number in plain text, i.e., the random number used itself. In this case, authentication will involve the wireless device verifying that the network element has access to the wireless device's long-term key (directly or indirectly) by decrypting the single message using a derived key derived from the wireless device's long-term key. To this end, the single message again contains encrypted information, such as an encrypted version of the device identifier, an encrypted version of the random number used, or other encrypted data that can be verified as corresponding to known data after decryption by the wireless device. Other examples of such wireless devices and transmitting network elements can be modified accordingly by swapping the roles of the wireless transmitting device and the authentication system in the embodiments disclosed herein. In such examples where the single message contains data, this may be data from the client system (and may alternatively or additionally be encrypted by the client key) or the network to the wireless device, such as instructions, new random number information, etc. In such an example, a single message may even be sent in a power signal (eg as disclosed in application EP22210972.0).
[0031] Thus, aspects of the present disclosure relate to a network system capable of accessing a long-term key associated with a wireless device and accessing one or more random numbers. The network system may be configured to perform a transmission to the wireless device. The wireless device may be configured to wirelessly receive the transmission and may have a device identifier. The transmission may be configured to be authenticated in the wireless device without requiring a bidirectional connection between the wireless device and the network system. The network system may be configured to access the long-term key of the wireless device based on the device identifier or another device identifier. The network system may generate a derived key from the long-term key and a random number from the one or more random numbers. The network system may transmit a transmission consisting of a single message including at least the device identifier, the device identifier encrypted with the derived key for authentication in the wireless device.
[0032] Another aspect of the present disclosure relates to a method in a wireless transmission device for performing a transmission to a network, the network comprising at least a wireless receiving node configured to wirelessly receive the transmission and another network system in the network subsequent to the wireless receiving node. The transmission is configured to be authenticated in the network without requiring a bidirectional connection between the wireless transmission device and the other network nodes in the network. The wireless transmission device may include a long-term key, one or more random numbers, and a device identifier. The method includes the steps of generating a derived key from the long-term key and a random number from the one or more random numbers; and transmitting a single message, the single message including at least the device identifier encrypted with the derived key, for authentication in the network.
[0033] The present disclosure also relates to a computer program comprising one or more software code portions for performing such a method in a wireless transmission device when the program is executed by a processor in the wireless transmission device.
[0034] Yet another aspect of the present disclosure relates to a method in an authentication system that has access to a random number used by a wireless transmission device to derive a derived key and a long-term key for the wireless transmission device. The method may include the steps of receiving a single message from the wireless transmission device including a device identifier of the wireless transmission device encrypted with the derived key, and accessing the long-term key and the random number based on the device identifier of the wireless transmission device accessible to the authentication system to derive the derived key. The method may also include authenticating the wireless transmission device by decrypting the encrypted device identifier from the single message using the derived key.
[0035] The present disclosure also relates to a computer program comprising one or more software code portions for performing such a method in an authentication system when executed by a processor in such a system.
[0036] Yet another aspect of the present disclosure relates to a system comprising the wireless transmission device and the authentication system as disclosed herein.
[0037] As will be appreciated by those skilled in the art, aspects of the present invention may be embodied as systems, methods or computer program products. Thus, aspects of the present invention may take the form of complete hardware embodiments, complete software embodiments (including firmware, resident software, microcode, etc.) or embodiments of combined software and hardware aspects, which may all be summarized herein as "circuits," "modules," or "systems." The functions described in this disclosure may be implemented as algorithms executed by a processor / microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer-readable media having a computer-readable program code embodied thereon, such as stored thereon.
[0038] Any combination of one or more computer-readable media can be utilized. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared or semiconductor system, device or apparatus, or any suitable combination of the foregoing. More specific examples of computer-readable storage media can include, but are not limited to, the following: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device or any suitable combination of the foregoing. In the context of the present invention, a computer-readable storage medium can be any tangible medium that can contain or store a program for use by an instruction execution system, device or apparatus or used in combination with it.
[0039] A computer-readable signal medium may include a propagated data signal having computer-readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium that is not a computer-readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
[0040] The program code embodied in the computer-readable medium can be transmitted using any appropriate medium (including but not limited to wireless, wired, optical fiber, cable, RF, etc. or any suitable combination thereof). The computer program code for performing the operation of aspects of the present invention can be written in any combination of one or more programming languages (including object-oriented programming languages (such as Java, Smalltalk, C++, etc.) and traditional process programming languages (such as "C" programming language)) or similar programming languages. The program code can be executed entirely on a personal computer, partially on a personal computer, as an independent software package, partially on a personal computer and partially on a remote computer, or completely on a remote computer or server. In the latter case, the remote computer can be connected to the personal computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using the Internet of an Internet service provider).
[0041] Aspects of the present invention are described below with reference to flowchart illustrations and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present invention. It will be understood that each frame of the flowchart illustration and / or block diagram and the combination of frames in the flowchart illustration and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor (particularly a microprocessor or central processing unit (CPU)) of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that instructions executed via the processor of the computer, other programmable data processing devices or other devices create components for implementing the function / action specified in one or more frames of the flowchart and / or block diagram.
[0042] These computer program instructions may also be stored in a computer-readable medium, which can direct a computer, other programmable data processing device or other apparatus to operate in a specific manner so that the instructions stored in the computer-readable medium produce an article of manufacture including instructions for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram.
[0043] The computer program instructions may also be loaded onto a computer, other programmable data processing device or other apparatus to cause a series of operating steps to be performed on the computer, other programmable device or other apparatus to produce a computer-implemented process, such that the instructions executed on the computer or other programmable device provide a process for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram.
[0044] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functionality and operation of the system, method and computer program product according to various embodiments of the present invention. In this regard, each frame in the flow chart or block diagram can represent a module, a code segment or a code portion, which includes one or more executable instructions for realizing (one or more) specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the frame may not appear in the order marked in the figure. For example, the two frames shown in succession can actually be performed substantially simultaneously, or the frames can sometimes be performed in reverse order, depending on the functionality involved. It will also be noted that the combination of each frame in the block diagram and / or the flow chart diagram and the frame in the block diagram and / or the flow chart diagram can be realized by a system based on dedicated hardware or a combination of dedicated hardware and computer instructions that performs a specified function or action.
[0045] Furthermore, a computer program for executing the method described herein and a non-transitory computer-readable storage medium storing the computer program are provided.
[0046] Unless otherwise expressly stated, elements and aspects discussed with respect to or in relation to a particular embodiment may be appropriately combined with elements and aspects of other embodiments. Embodiments of the present invention will be further described with reference to the accompanying drawings, which schematically illustrate embodiments according to the present invention. It will be understood that the present invention is not limited in any way to these specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Aspects of the present invention will be explained in more detail with reference to exemplary embodiments shown in the accompanying drawings, in which:
[0048] Figure 1 are schematic diagrams of two use cases in which a wireless transmission device uses fast authentication to transmit a single message;
[0049] Figure 2A and 2B is a schematic diagram of a use case in which a wireless transmission device is a surrounding IoT device and a single message is transmitted using fast authentication and a schematic structure of the surrounding IoT device;
[0050] Figures 3A-3C is a schematic diagram showing various examples of configuring a single message for fast authentication;
[0051] Figure 4 is a timing diagram illustrating a basic embodiment of fast authentication by transmitting a single message to the network;
[0052] Figure 5 is a timing diagram illustrating another embodiment of fast authentication by transmitting a single message to the network; and
[0053] Figure 6 An example of a processing system according to an embodiment of a wireless transmission device or authentication system or a portion thereof is depicted. DETAILED DESCRIPTION
[0054] Figure 1 is a schematic diagram of a system 100 comprising wireless transmission devices 10, 20, 30, 40 configured to transmit a single message S for fast authentication. Figure 1 Multiple use cases for a single message are depicted in one figure, but it should be appreciated that these use cases do not necessarily apply to one system 100 or with one authentication system AUT.
[0055] The wireless transmission device 10 is configured for vehicle-to-everything (V2X) communications, for example, with a roadside infrastructure element 1. Such communications may include small amounts of data, such as vehicle status information, payment information, etc. The roadside infrastructure element 1 is connected to a telecommunications core network (CN), which includes an authentication system (AUT) configured for rapid authentication of the wireless transmission device 10. The core network is connected to a data network (DN) for providing data to a client system (CLIENT).
[0056] In situations involving high mobility of the wireless transmission device 10, end-to-end connectivity may not always exist between the device 10 and the core network CN. For example, the wireless transmission device 10 may connect to the core network CN through a different intermediate node at each moment. This presents a problem because the wireless transmission device 10 may only be connected to one intermediate node for a short period of time. When the device undergoes conventional authentication procedures, it may lose connectivity to the intermediate node before such procedures are completed.
[0057] In the same Figure 1 In the present invention, a wireless transmission device 20 (e.g., a user equipment (UE) as standardized in 3GPP) may want to transmit a single message S to a (non-geostationary) satellite SAT. Such a single message may contain a small amount of data (e.g., a text message). For example, the text message may need to be delivered to another device wirelessly connected to the operator's radio access network (RAN). At the time when the wireless transmission device 20 wants to send the data, the satellite SAT is not connected to the network operator's telecommunications core network. When the satellite SAT has moved and can connect to the network, it may no longer be able to connect to the wireless transmission device 20.
[0058] If the wireless transmission device 20 must authenticate and establish a security association using conventional methods to send messages, it requires a bidirectional end-to-end connection with the network CN. In this case, problems may arise because there may not always be an end-to-end connection between the wireless transmission device 20 and the core network, as the satellite SAT may not be connected to both the wireless transmission device 20 and the network CN at the same time.
[0059] The wireless transmission device 30 is equivalent to the surrounding IoT device and refers to Figure 2A and 2B Described in further detail.
[0060] The wireless transmission device 40 comprises a user device wirelessly connected to a relay node R, which can forward a single message S from the device to the network at a later point in time, for example if connectivity to the network is lacking when the single message is received. This allows the wireless transmission device 40 to transmit the single message S without having to wait for the relay node's connection to the network to be (re)established.
[0061] Note that a network node, such as a core network node (e.g., an authentication system AUT, or an access and mobility function system (AMF), a unified data management (UDM) or authentication server function (AUSF) function) or a base station of a RAN or a satellite SAT) can also transmit a single message as disclosed in the present patent application to the radio transmission node 10, 20, 30, 40. This single message is not in the Figure 1 Shown in.
[0062] Figure 2A 1 is a schematic diagram of a wireless transmission device 30 that transmits a single message S configured for fast authentication to the network via a radio access network RAN of a telecommunications network. The telecommunications network also includes a core network CN, which includes an additional network node, denoted as an authentication system AUT. The additional network node is a node subsequent to the wireless receiving node and may have a wireless or wired connection to the wireless receiving node, such as a base station, a satellite, a system that performs control plane functions in 5G or another network generation, such as an access and mobility function AMF, an authentication server function AUSF, a unified data management (UDM) function, or a dedicated authentication function in the telecommunications network.
[0063] In one embodiment, the telecommunications network may be a 4G, 5G, or 6G network as standardized by 3GPP, or a combination thereof. For example, a base station of the telecommunications network may be a 4G base station (e.g., eNodeB) or a 5G base station (e.g., gNb), while other components of the core network, for example, are standardized as 5G or 6G. In some embodiments, the wireless transmission device 30 is configured to wirelessly communicate with the telecommunications network using a single message S. Communication may also be direct to another device (not shown). In other embodiments, the telecommunications network may be a WiFi network, such as a WiFi6 or WiFi7 network, and the wireless transmission device may transmit a single message S on a WiFi radio channel, or transmit directly to another device using WiFi Direct.
[0064] The wireless transmission device 30 may be an ambient IoT device. Essentially, the ambient IoT device 30 is a battery-less device with limited (if any) energy storage capabilities (which may include one or more capacitors), where energy is provided by harvesting radio waves, light, motion, heat, or any other suitable power source. The ambient IoT device 30 cannot store any significant power provided to it in the power signal PS, which may have a limited duration, and uses the supplied power almost immediately to complete its desired action. Because such ambient IoT devices draw power exclusively from external stimuli, they cannot perform lengthy procedures to authenticate and establish a bidirectional association to send messages, and therefore benefit from the rapid authentication disclosed herein.
[0065] exist Figure 2B An embodiment of a surrounding IoT device is schematically illustrated in FIG. Figure 2B FIG2 is a schematic diagram of a peripheral IoT device 30 configured to receive a power signal PS. The peripheral IoT device 30 includes a power acquisition portion 31, a processing portion 32, and a storage portion 33 configured to store at least a device identifier. The storage portion 33 may include several forms of memory, including secure memory for storing, for example, encrypted information.
[0066] The ambient IoT device 30 may include at least one of a communication portion 34 and optionally at least one sensor 35 (or a connector thereof). It should be appreciated that the ambient IoT device 30 may include multiple sensors 35 or connectors thereof. Examples of sensors include position sensors, temperature sensors, humidity sensors, light sensors, pressure sensors, motion sensors, and the like. A timestamp generator may also be a function available in the device to store a timestamp with stored data.
[0067] It is to be appreciated that the ambient IoT device 30 may include more or fewer parts.
[0068] The surrounding IoT device 30 is configured to obtain power from the power signal PS and operate at least the processing part 32 and the communication part 34. The power supply line to these parts is at Figure 2B The power signal PS can come from any external power source, such as Figure 2A , or from a separate power source that triggers the surrounding IoT devices 30 with a radio wave power source. However, alternative sources may be used, such as pressure from a manual push of a button or from a light source.
[0069] The processing portion 32 is configured to perform one or more processing steps, for example, based on computer code obtained from the storage portion 33. Signal lines for such processing and for communicating with other portions (including the communication portion 34 and the sensor(s) 3) are provided by Figure 2B The dotted line in .
[0070] Due to lack of end-to-end connectivity to the authentication entity, insufficient transmission time or power limitations of the transmitting device, e.g. Figure 1 and Figure 2A 、 2B The use case depicted in
[15] would benefit from fast authentication as disclosed herein. It will be appreciated that other considerations may apply to the use of fast authentication messages as disclosed herein. One example would be when the amount of data to be transmitted is small, making it inefficient to perform extended authentication procedures and establish a security context. Such procedures would result in higher overhead than the overhead of exchanging actual data proofs between the wireless device and the network.
[0071] It should be understood that Figure 1 The wireless transmission devices 10, 20, 40 depicted in FIG may also have one or more of the parts described above for the surrounding IoT device 30, and Figure 6 30. However, the remaining description will focus on the wireless transmission device including the surrounding IoT device 30.
[0072] The wireless transmission device 30 is configured to perform transmission to a network comprising at least one wireless receiving node, such as Figure 1, an infrastructure element 1 or a base station of a RAN, which is configured to wirelessly receive the transmission. The wireless transmission device 30 may have to or need to establish an RRC connection with a wireless receiving node. Further network systems (such as entities in the core network CN, such as the authentication system AUT) are behind, i.e. in the uplink direction of the wireless transmission device. The transmission is configured to be authenticated in the network without requiring a bidirectional connection or channel between the wireless transmission device 30 and further network nodes in the network. Therefore, the wireless transmission device 30 may contain a long-term key K-LT, one or more random numbers Nonce or information representing random numbers and a device identifier ID DEV One or more of these may be stored, for example, in the storage section 33 of the wireless transmission device 30. The wireless transmission device 30 may be configured to generate a derived key KD from the long-term key K-LT and a random number Nonce from one or more random numbers. The transmission comprises a single message S containing at least the device identifier ID encrypted with the derived key KD. DEV , used for authentication in the network.
[0073] Examples of such device identifiers may include identifiers as defined in 3GPP, such as IMSI, SUPI, etc., or more generally, identifiers associated with a subscription (and the long-term key K-LT as part thereof). Other device identifiers may also be suitable, such as an application layer identifier (e.g., IMEI) or other identifiers, such as a car identifier (e.g., VIN number) of the wireless transmission device 10 or an electronic product code (EPC) for logistics.
[0074] The authentication system AUT is provided in a network that has access to the long-term key K-LT of the wireless transmission device 30 and the random number Nonce used by the wireless transmission device 30 to derive the derived key KD. The authentication system AUT is configured to receive a single message S from the wireless transmission device 30, the single message S containing the device identifier ID of the wireless transmission device 30 encrypted with the derived key KD. DEV The authentication system AUT is further configured to identify the wireless transmission device 30 accessible by the authentication system based on the device identifier ID DEV To access the long-term key K-LT and the random number to derive the derived key KD, and decrypt the encrypted device identifier ID from the single message S by using the derived key KD DEV To authenticate the wireless transmission device 30. The authentication system AUT does not require a two-way connection with the wireless transmission device 30. The authentication system can, for example, compare the decrypted device identifier ID DEV The device identifier ID of the wireless transmission device 30 is determined by the device identifier corresponding to the long-term key accessed by the authentication system AUT. DEVThe authentication system does not require a two-way connection with the wireless transmission device 30.
[0075] In order for the wireless transmission device 30 and the authentication system AUT to derive the same derived key, the random numbers used on both sides should be identical. This can be achieved in a variety of ways. Both sides can store the device's random number or random number set, and signal the random number or information representing the random number before or in conjunction with the transmission of the single message S. The information representing the random number can include an identifier for the random number (rather than the random number itself) or input parameters used to generate the random number on one or both sides. As long as it is not reasonably feasible to reconstruct the long-term key from the random number and the derived key (for example, when an irreversible function is used to derive the derived key from the long-term key and the random number), the random number or information representing the random number can also be sent in plain text. The identifier of the random number or the parameters that can be used to generate the random number (possibly in combination with a previously used random number) can provide a measure to obfuscate the random number and can also reduce the number of bits that need to be sent. The identifier of the random number in the random number set (for example, an ordered list of random numbers) is shorter than the random number itself.
[0076] The wireless transmission device 30 generates and the authentication system AUT processes a single message S containing sufficient information to authenticate the wireless transmission device 30 or the single message S it sends. The single message S does not require a multi-step authentication and association procedure, as will be explained in more detail below. The wireless transmission device 30 and the authentication system AUT provide a lightweight authentication solution for situations where the wireless transmission device 30 is severely power-limited or where a two-way connection or channel is not guaranteed or required.
[0077] Figure 3A-3C Schematic diagrams illustrating various examples of configuring a single message S for fast authentication. The left-hand side illustrates the transmission side (Tx), i.e., operations at the wireless transmission device. The right-hand side illustrates the reception side (Rx), i.e., the network side. Alternatively or additionally (not shown), the network side and the wireless transmission device may be interchanged (the network side serving as the transmission side (Tx) and the wireless transmission device serving as the reception side (Rx).
[0078] Figure 3A Assume that the wireless transmission device 30 contains a long-term key K-LT and a random number. The random number can also be generated from a random seed generator (e.g., implemented in the processing section 22 of the surrounding IoT device 30), as long as the wireless transmission device 30 and the network use the same set of inputs to such a generator to obtain the same random number. The wireless transmission device 30 derives a derived key KD from K-LT and the random number. The derived key KD is used to encrypt the device identifier ID DEV .
[0079] In the following and accompanying figures, information elements are shown as being encrypted using subscripts with a key. For example, [IDDEV ]KD indicates that ID is encrypted using a security function that uses KD as the encryption key. DEV Encryption is performed. Various security functions known to those skilled in the art can be used here. Some security functions can use another random number (e.g., Nonce2) for encryption. This Nonce2 can be sent with a single message in a similar manner to the Nonce (e.g., plaintext random number, random number identifier, parameters for random number derivation).
[0080] exist Figure 3A In the example, a single message S contains only the device identifier ID DEV This may be sufficient for the operator of the client system CLIENT when searching for the presence of a specific transmitting device 30. For the surrounding IoT devices 30, the transmission of a single message S may have been triggered by a power pulse PS transmitted, for example, from a base station of the RAN.
[0081] At the network side, for example in the authentication system AUT, the network is configured to have access to the long-term key K-LT and the random number Nonce used by the wireless transmission device 30 for deriving the derived key KD.
[0082] One way in which the network can know the device that transmitted the message is, for example, that the single message S comes in via a specific channel or link (e.g., on a lower layer protocol such as RRC signaling) which the network can associate with the device identifier. In this way, the network side can also derive the key KD and thus be able to decrypt the encrypted device identifier ID DEV The authentication system can for example compare the decrypted device identifier ID DEV The device identifier ID of the wireless transmission device 30 is determined by the device identifier corresponding to the long-term key accessed by the authentication system AUT. DEV It is credible.
[0083] Another way to obtain the device identity to access the long-term key K-LT and the random number Nonce is for the device to send it in plain text from which the network can derive the device identifier ID DEV or a device identifier such as a secure device ID (such as SUCI), for example a temporary device identifier (such as TMSI).
[0084] A single message S contains the device identifier ID in encrypted form DEV , to achieve the authentication of wireless transmission devices or their messages. Device Identifier ID DEV It may also be of interest as data for purposes beyond authentication, for example when merely verifying the presence of a device as described above. However, in one embodiment, a single message S may contain additional small amounts of data DATA, such as Figure 3BSuch data may include, but is not limited to, sensor data collected by the sensor 35 of the wireless transmission device 30 or by a sensor 35 connected to the wireless transmission device 30, status information of the device, or data stored in the device 30, such as data stored in the storage portion 33. Figure 3B As shown in , data can be encrypted with a derived key KD to protect the data during transmission to the network. In this way, the network can authenticate the wireless transmission device and receive data from the device.
[0085] Additionally or alternatively, the data may be encrypted using a client key KC available to the wireless transmission device 30 and the client system CLIENT to protect the data in the telecommunication network until the data reaches the client system CLIENT. Figure 3C Depicted in.
[0086] Figure 4 1 is a timing diagram illustrating a basic embodiment of fast authentication of a wireless transmission device 30 by transmitting a single message S to a network comprising a radio access network RAN having a plurality of base stations gNb and a 5G core network 5GC. Such base stations and 5GC are generally known to those skilled in the art and are standardized by 3GPP.
[0087] Assume that the wireless transmission device 30 is pre-equipped with a long-term key K-LT and a random number set 1...n. Figure 3A As described above, the wireless transmission device 30 can derive the key KD from a specific random number Nonce from the set and the long-term key K-LT in step S10 when triggered to perform transmission. DEV In addition, the single message to be transmitted may also contain additional information, such as an information ID associated with the device sent .
[0088] For example, the information representative of the device identifier may be a temporary identifier or some other identifier that may be used in the authentication system AUT to track the long-term key KT and the random number used to derive the derived key KD in that system AUT.
[0089] In step S11, the wireless transmission device 30 transmits Figure 4 A single message S is shown in , wherein the information representing the device identifier remains unencrypted.
[0090] In step S12, the wireless receiving node gNb forwards the entire single message S to the authentication system AUT in the 5GC. The authentication system AUT uses the information ID representing the wireless transmission device 30 sentTo determine the long-term key KT and the random number used to derive the derived key KD in the authentication system AUT. Then, in step S13, the derived key KD is used to obtain the device identifier ID for authentication DEV When the authentication system AUT determines the received ID sent With the decrypted ID dev When correlated, the wireless transmission device and / or the individual messages S are considered authentic.
[0091] Optionally, and only when sufficient power is available at the wireless transmission device 30, if authentication is successful or the message is successfully received, the authentication system AUT may enable the 5GC to trigger the transmission of an acknowledgment ACK back to the wireless transmission device 30 in steps S14 and S15. The ACK signal may include a new random number or set of random numbers, thereby generating a signal ACK(random number) of the wireless transmission device 30. In response to receiving the ACK, the wireless transmission device 30 may store the random number or set of random numbers and / or discard the data from its storage device, step S16.
[0092] Depending on the number of random numbers in the random number set, new random number information can be provided before each individual message, or less frequently. An example of the latter is that the size of the set (and the size of the storage portion 23 of the device 30) can provide enough random numbers for a specific period of time or for a specific purpose, such as for the shipment of goods in a box or any container, or for the distribution of products from a factory to a customer. Then, before the next deployment, such as the next shipment or distribution, a new set of random number information can be provided.
[0093] The initial parameters of the random number generator, the initial random number, or the initial random number set can be provided to the wireless transmission device 30 in the same manner as the new random number information. The initial random number information can also be pre-stored in the wireless transmission device 30 before deployment, such as in the storage device par 33.
[0094] Note that there may be error conditions where it is desirable to reset the picking or derivation of the random number when authentication is unsuccessful.
[0095] Figure 5 A more detailed example of a use case is shown, where in step S100 the surrounding IoT devices 30 are triggered by a power pulse to transmit a single message S. The power pulse may be transmitted or coordinated by the network to which the single message is to be sent, but may also come from a separate power pulse generator (not shown).
[0096] In response to the pulse, the surrounding IoT device 30 derives the derived key KD based on the long-term key K-LT and the random number identified by the random number identifier n. As described above, the random number can also be generated from a random seed generator, as long as the device 30 and the network use the same set of inputs to such a generator to obtain the same random number for deriving the derived key KD.
[0097] The data to be transmitted is encrypted with the client key KC (this step may have been performed before receiving the power pulse in step S100, for example when collecting data). The data encrypted with KC and the device identifier ID are then encrypted with KD. DEV Information indicating a random number (here, a random number identifier n) and information indicating the identification device 30 (ID sent ) is also included in the single message S configured in step S101. The information to be sent that identifies the device 30 (ID sent ) can be a temporary identifier obtained from the network (such as TMSI), or a device identifier ID DEV The function can be to encrypt the device identifier ID with the public key of the network. DEV The public key encryption function of , or a function for converting SUPI into SUCI, as known from 5G networks.
[0098] In step S102 , a single message S is transmitted to the network comprising the authentication system, possibly via an intermediate node INT.
[0099] In step S103, the network can identify the device ID sent The long-term key K-LT associated with the surrounding IoT device 30 is identified based on the information of the random number identifier n and the random number. If the information of the identification device is generated by applying the function, the network can check the ID sent The network can derive the key KD from the long-term key K-LT and the random number associated with the random number identifier n. In this way, the device identifier ID DEV can be decrypted, and the single message S is determined to be authentic. If any of the above steps fail, the authentication can be considered unsuccessful.
[0100] If authentic, then in step S104 the network may transmit the data, still encrypted under the client key KC, to the client system CLIENT. Optionally, in step S105 the client system may confirm the successful receipt of the data to the network.
[0101] Optionally, in step S106, the network may confirm to the surrounding IoT devices 30 that the single message S is successfully received in the network and / or that the data is successfully received at the client system CLIENT. Optionally, the network may send a new random number set or information to generate a new random number.
[0102] The transmission in step S106 may be a power pulse that enables the surrounding IoT devices 30 to receive and process the confirmation. The power pulse may be a single power pulse into which the confirmation and / or information representing the new random number set is modulated, or the mere presence of the power pulse may be considered as confirmation.
[0103] Figure 6 Depicted is a block diagram illustrating an exemplary processing system according to the disclosed embodiments, such as a wireless transmission device 20, 40, a network system or network element, or an authentication system AUT as described above for use in system 100. Figure 6 As shown in , processing system 60 may include at least one processor 61 coupled to memory element 62 via a system bus 63. Thus, the processing system may store program code within memory element 62. In addition, processor 61 may execute program code accessed from memory element 62 via system bus 63. In one aspect, the processing system may be implemented as a computer system suitable for storing and / or executing program code. However, it should be appreciated that processing system 60 may be implemented in the form of any system including a processor and memory capable of performing the functions described in this specification.
[0104] The memory element 62 may include one or more physical memory devices, such as, for example, a local memory 64 and one or more mass storage devices 65. Local memory may refer to random access memory or (one or more) other non-persistent memory devices that are typically used during the actual execution of the program code. The mass storage device may be implemented as a hard drive or other persistent data storage device. The processing system 60 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the number of times the program code must be retrieved from the mass storage device 65 during execution.
[0105] Input / output (I / O) devices, depicted as input device 66 and output device 67, may optionally be coupled to the processing system. Examples of input devices may include, but are not limited to, a spatially accessible keyboard, a pointing device such as a mouse, and the like. Examples of output devices may include, but are not limited to, a monitor or display, speakers, and the like. Input and / or output devices may be coupled to the processing system directly or through an intervening I / O controller.
[0106] In an embodiment, the input and output devices may be implemented as a combined input / output device (in Figure 6(illustrated in dashed lines around input device 66 and output device 67 in the figure). An example of such a combined device is a touch-sensitive display, sometimes also referred to as a "touch screen display" or simply a "touch screen" that may be provided with a UE. In such embodiments, input to the device may be provided by moving a physical object, such as, for example, a stylus or a human finger, on or near the touch screen display.
[0107] A network adapter 68 may also be coupled to the processing system to enable it to couple to other systems, computer systems, remote network devices, and / or remote storage devices through intervening private or public networks. The network adapter may include a data receiver for receiving data transmitted to the processing system 60 by the system, device, and / or network, and a data transmitter for transmitting data from the processing system 60 to the system, device, and / or network. Modems, cable modems, and Ethernet cards are examples of different types of network adapters that can be used with the processing system 60.
[0108] like Figure 6 As depicted, the memory element 62 may store applications 69. In various embodiments, the applications 69 may be stored in the local memory 64, in one or more mass storage devices 65, or separately from the local memory and mass storage devices. It should be appreciated that the processing system 60 may further execute an operating system ( Figure 6 ), the operating system may facilitate execution of application 69. Application 69, implemented in the form of executable program code, may be executed by processing system 60, such as by processor 61. In response to executing the application, processing system 60 may be configured to perform one or more operations or method steps described herein.
[0109] In one aspect of the invention, one or more components of a base station selection support system as disclosed herein and / or a user device for use with such a base station selection support system may represent the processing system 60 as described herein.
[0110] Various embodiments of the present invention can be implemented as a program product for use with a computer system, wherein the program(s) of the program product define the functionality of the embodiment (including the methods described herein). In one embodiment, the program(s) may be contained on various non-transitory computer-readable storage media, wherein as used herein, the expression "non-transitory computer-readable storage media" includes all computer-readable media with the sole exception of temporary propagation signals. In another embodiment, the program(s) may be contained on various temporary computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media on which information is permanently stored (e.g., a read-only storage device within a computer, such as a CD-ROM disk, a ROM chip, or any type of solid-state non-volatile semiconductor memory that can be read by a CD-ROM drive); and (ii) writable storage media on which variable information is stored (e.g., flash memory, a floppy disk in a floppy disk drive, or a hard disk drive, or any type of solid-state random access semiconductor memory). The computer program can be run on the processor 61 described herein.
[0111] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the terms "include" and / or "comprises," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or combinations thereof.
[0112] The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of the embodiments of the invention is presented for illustrative purposes and is not intended to be exhaustive or limited to implementation in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the claims. The embodiments are chosen and described in order to best explain the principles of the invention and some practical applications, and to enable others of ordinary skill in the art to understand the various embodiments of the invention with various modifications as are suited to the particular use contemplated.
Claims
1. A wireless transmission device configured to perform transmission to a network, the network comprising at least a wireless receiving node configured to wirelessly receive the transmission and another network system in the network following the wireless receiving node, wherein: The transmission is configured to be authenticated in the network without a bidirectional connection between the wireless transmission device and the further network node in the network, wherein the wireless transmission device contains a long-term key, one or more random numbers and a device identifier, wherein the wireless transmission device is configured to generate a derived key from the long-term key and a random number among the one or more random numbers, and Wherein the transmission comprises a single message comprising at least the device identifier encrypted with the derived key for authentication in the network.
2. The wireless transmission device according to claim 1, wherein The single message also contains data collected by or stored in the device, optionally encrypted using at least one of the derived key and a client key stored in the wireless transmission device.
3. The wireless transmission device according to claim 1 or 2, wherein: The single message also includes information indicating at least one of the following: - an identifier associated with the wireless transmission device; - a random number among the one or more random numbers used to generate the derived key.
4. The wireless transmission device according to one or more of the preceding claims, wherein: The device is an ambient IoT device configured to obtain power from ambient power sources, such as electromagnetic waves (radio waves, light), motion, heat, etc.
5. The wireless transmission device according to claim 4, wherein: The apparatus comprises at least: a power acquisition portion configured to acquire power from a power signal such as a radio signal; and a communication portion configured to be powered by the power signal and to wirelessly transmit the single message to the wireless receiving node while being powered by the power signal.
6. The wireless transmission device according to claim 4 or 5, wherein: The wireless transmission device is configured to obtain the power from a single power pulse.
7. The wireless transmission device according to one or more of the preceding claims, wherein: The apparatus comprises a receiver for receiving data and / or instructions from the network, the instructions comprising, for example, at least one of: - a signal indicating confirmation of successful authentication of the wireless transmission device in the network; - New random number information, wherein the new random number information is optionally interpreted in the wireless transmission device as confirmation of successful authentication of the wireless transmission device in the network.
8. The wireless transmission device according to claim 7, wherein: The wireless transmission device is configured to derive power from a signal containing data and / or instructions from the network.
9. The wireless transmission device according to one or more of the preceding claims, wherein: The wireless transmission device includes a storage portion for storing data, and wherein the wireless transmission device is configured to transmit a plurality of single messages, each single message including at least the device identifier encrypted with the derived key and the data stored in the storage portion or a portion of the data.
10. An authentication system for use in a network, the authentication system having access to a random number used by a wireless transmission device to derive a key and a long-term key of the wireless transmission device, wherein: The authentication system is configured to: - receiving a single message from the wireless transmission device, the single message comprising the device identifier of the wireless transmission device encrypted with the derived key, - accessing the random number and the long-term key based on a device identifier of the wireless transmission device accessible by the authentication system to derive the derived key, and - authenticating the wireless transmitting device by decrypting the encrypted device identifier from the single message using the derived key.
11. The authentication system according to claim 10, wherein: The single message further comprises data, optionally encrypted by at least one of the derived key and a client key, wherein the authentication system is configured to enable transmission of the single message encrypted with the client key to the client system where applicable.
12. The authentication system according to claim 10 or 11, wherein: The authentication system is further configured to at least one of: - using information in the single message from the wireless transmission device representing an identifier of the wireless transmission device to access the long-term key and optionally the random number to derive the derived key; - using information representing a random number in said single message from said wireless transmission device together with at least said long-term key to derive said derived key.
13. The authentication system according to one or more of claims 10-12, wherein: The network system is configured to transmit at least one of the following in response to authentication of the wireless transmission device: - a signal indicating confirmation of successful authentication of the wireless transmission device in the network; - New random number information, wherein the new random number information is optionally interpreted in the wireless transmission device as confirmation of successful authentication of the wireless transmission device in the network.
14. The authentication system according to claim 13, wherein: The authentication system is configured to enable transmission of at least one of a signal indicating confirmation of successful authentication and the new random number information with sufficient power to power the wireless transmission device from which the single message has been authenticated.
15. A network system having access to a long-term key associated with a wireless device and having access to one or more random numbers, wherein: The network system is configured to perform a transmission to the wireless device, the wireless device being configured to wirelessly receive the transmission and having a device identifier, wherein the transmission is configured to be authenticated in the wireless device without a bidirectional connection between the wireless device and the network system, wherein the network system is configured to: - accessing the long-term key of the wireless device based on a device identifier or another device identifier; - generating a derived key from the long-term key and a random number from the one or more random numbers; and - transmitting said transmission consisting of a single message comprising at least said device identifier encrypted with said derived key for authentication in said wireless device.