Authentication and device identifier management for passive wireless transmission devices

By managing the identifiers and authentication tokens of passive wireless transmission devices through the system, flexible reuse of identifiers and efficient authentication are achieved, solving the problem of low identifier management efficiency for environmental power-enabled IoT devices and improving the authentication and data transmission efficiency of passive devices.

CN121533044APending Publication Date: 2026-02-13KONINK KPN NV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480047445.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-07-19
Filing Date
2024-07-16
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

In existing technologies, device identifier authentication for environmentally powered IoT devices is inefficient, long identifiers are inefficient to use and unsuitable for power-constrained passive devices, and existing protocols cannot effectively solve the problems of identifier reuse and conflict.

Method used

The configuration system receives and manages device identifiers and authentication tokens for passive wireless transmission devices, allows for the reassignment and revocation of identifiers, enables flexible authentication management by associating authentication tokens with identifiers, supports the use of currently and previously associated identifiers, and reduces the uniqueness requirements of identifiers.

Benefits of technology

It improves the efficiency of identifier management for passive wireless transmitters, reduces energy consumption, and supports efficient authentication and data transmission for a large number of passive devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121533044A_ABST
    Figure CN121533044A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system configured for communication with a plurality of passive wireless transmission devices. The system is configured to receive a first wireless transmission of a passive wireless transmission device, wherein the first wireless transmission includes a first device identifier and a first authentication token. The system may authenticate this transmission, for example, based on an association of the first device identifier and the first authentication token. The system may also be configured to determine a second authentication token for the passive wireless transmission device. The system may further be configured to invalidate the first device identifier for the passive wireless transmission device, for example, because the system has reallocated the first device identifier to another passive wireless transmission device. The system may further be configured to determine a second device identifier for the passive wireless transmission device under consideration. The system may further be configured to store an association of the second authentication token with the second device identifier as a current association for the passive wireless transmission device and an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device. The system may further be configured to receive a second wireless transmission of the passive wireless transmission device. The system may further be configured to authenticate the second wireless transmission if the second wireless transmission includes the second device identifier and the second authentication token according to the current association, and also authenticate the second wireless transmission if the second wireless transmission includes the first device identifier and the second authentication token according to the past association.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to a system and to passive wireless transmission devices. In particular, the present disclosure relates to a system for managing authentication and device identifiers for such passive devices. BACKGROUND

[0002] Future networks are expected to host a significant number of passive wireless transmission devices that store and / or collect data that should be uploaded via the network infrequently or in small amounts. Such devices should be efficiently managed in the network.

[0003] For example, 3GPP recently published a study on environmentally powered Internet of Things, IoT, devices in technical report 3GPP TR 22.840. The document discloses requirements and use cases for environmentally powered IoT devices (hereinafter also referred to as environmental IoT devices), which are battery-less devices with limited energy storage capabilities (may include a capacitor), where energy is provided by harvesting radio waves, light, motion, heat or possibly any other power source suitable. Thus, in this context, energy is a very scarce resource and the use of energy is preferably optimized by limiting the number and size of computations and / or exchanged messages. Moreover, environmental IoT devices can remain passive for an extended period of time before receiving a wake-up signal and starting to transmit data.

[0004] Devices use an identifier to identify themselves to the network, and such an identifier is usually assigned uniquely to the device. The network will usually use this identifier to authenticate the device, i.e. to verify that the device uses this identifier correctly in its transmissions. Authentication is usually performed in a series of transmission steps from both the network and the device. SUMMARY

[0005] The inventors have realized that such authentication and use of device identifiers poses a challenge for passive devices. For example, for environmental IoT devices, it can be necessary to re-use identifiers, as the number of devices can be huge, which would require long identifiers if these devices need to be unique. On the other hand, although environmental IoT devices can usually only and need to transmit a limited amount of data, transmitting long identifiers together with the data is not efficient and usually even problematic given the power constraints of such devices.

[0006] Therefore, the inventors have considered that device identifiers can need to be relatively short. Short device identifiers imply a scarcity of such identifiers, such that re-use of temporarily or permanently unused identifiers is highly desirable. As a result, re-assignment and / or revocation of device identifiers can be necessary in some use cases for passive devices, while at least meeting some level of authentication in the network.

[0007] One aspect of the present disclosure involves a system configured for communication with a plurality of passive wireless transmission devices. The system is configured to receive a first wireless transmission of a passive wireless transmission device, where the first wireless transmission includes a first device identifier and a first authentication token. The system can authenticate the transmission, for example, based on an association of the first device identifier and the first authentication token. The system can also be configured to determine a second authentication token for the passive wireless transmission device. The system can further be configured to invalidate the first device identifier for the passive wireless transmission device, for example, because the system has reassigned the first device identifier to another, second passive wireless transmission device. The system can further be configured to receive a second wireless transmission of the passive wireless transmission device. The system can further be configured to determine a second device identifier for the passive wireless transmission device under consideration. The system can further be configured to store an association of the second authentication token with the second device identifier as a current association for the passive wireless transmission device, and can be configured to store an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device. The system can further be configured to authenticate the second wireless transmission if the second wireless transmission includes the second device identifier and the second authentication token according to the current association, and to also authenticate the second wireless transmission if the second wireless transmission includes the first device identifier and the second authentication token according to the past association.

[0008] Another aspect of the present disclosure relates to a passive wireless transmission device configured for use with a system as disclosed herein. In one embodiment, the passive wireless transmission device is configured to perform a first wireless transmission including at least a first device identifier and a first authentication token. The passive wireless transmission device can further be configured to generate a second encryption token or to receive a second authentication token from the system. The passive wireless transmission device can further be configured to perform a second wireless transmission including the first device identifier and the second authentication token, and to receive a second device identifier from the system in response to the second wireless transmission. Optionally, the passive wireless transmission device can be configured to perform a third wireless transmission including at least the second device identifier and the second authentication token or a third authentication token.

[0009] The system and passive wireless transmission devices enable re-use of device identifiers while allowing for some level of authentication. The system uses authentication tokens for both authentication and for device identification by requiring each wireless transmission to include a new authentication token, while allowing some flexibility in the device identifier used in the transmission. For example, a device identifier can continue to be used by that device as long as the device identifier is associated in the system with the authentication token for the device. This enables the same device identifier to be used by another passive wireless transmission device (but with a different authentication token). Authentication remains possible by the association in the system of the authentication token used for each wireless transmission with the device identifier and authentication token associated in the system. Thus, the system not only allows use of a current association, but also allows use of past associations to manage the distribution of device identifiers by interpreting wireless transmissions associated with past associations as requests for authentication of a new device identifier or even as authenticatable wireless transmissions. As a result, device identifiers do not have to be permanently unique and / or unique among a population of devices, so that shorter device identifiers can be used for large populations of passive (i.e. power-constrained) wireless transmission devices as needed. This improves management of device identifiers and authentication from a central system.

[0010] It should be appreciated that the system can be a stand-alone system in wireless communication with a plurality of passive wireless transmission devices, or a system included in a network such as a telecommunications network, the network including at least a wireless portion for wireless communication with passive wireless transmission devices.

[0011] It should be noted that the length of the authentication token and the device identifier depends on the use case, e.g. the number of devices, the (expected) frequency of data transmissions, etc.

[0012] It should also be appreciated that in one embodiment, if a wireless transmission includes a device identifier and authentication token not found in an association in the system, the wireless transmission will not be accepted, and further actions can be performed such as transmission of an identifier revocation message, or ignoring or discarding the transmission.

[0013] An ultra-lightweight mutual authentication protocol (UMAP) for low-cost passive RFID tags is described in Security and Communication Networks (Volume 2019 (DOI: 10.1155 / 2019 / 3295616) by M. Khalid, U. Mujadid, and N Muhammad). In this paper, the RFID reader identifies the tag by receiving a pseudo-identification number and a key, which are dynamically generated and updated in the tag and the RFID reader, respectively. This protocol does not enable the reuse of identifiers by re-allocating and / or revoking identifiers from a central network system, avoiding collisions of identifiers. Since the identification number is calculated in the tag and the RFID reader, respectively, the identifiers in the tag can collide, and UMAP does not solve this collision.

[0014] In one embodiment, the system is further configured to transmit a second device identifier to the passive wireless transmission device. The embodiments provide centralized and dynamic coordination of the (re)allocation of device identifiers to enable the reuse of identifiers. For example, the system can transmit the second device identifier when determining the second device identifier or when determining the past association, i.e., in response to receiving the second wireless transmission comprising the first device identifier, which can have been invalidated, and the second authentication token.

[0015] In one embodiment, the system can be further configured to transmit a second authentication token to the passive wireless transmission device. The embodiments provide the advantage of limiting the processing requirements on the passive wireless transmission device and facilitating the coordination of authentication tokens. Moreover, this procedure can be used to refresh authentication tokens, i.e., the refreshed authentication token does not have to be computationally related to the past authentication token.

[0016] In one embodiment, the system is further configured to allocate a first device identifier to a second passive wireless transmission device and store an association of a further authentication token with the first device identifier as a current association for the second passive wireless transmission device. The system can be configured to receive a third wireless transmission from the passive wireless transmission device and authenticate the third wireless transmission as a transmission from the second passive wireless transmission device if the second wireless transmission comprises the first device identifier and the further authentication token according to the current association for the second passive wireless transmission device.

[0017] The embodiments illustrate the allocation of a first device identifier to a further second passive wireless transmission device while using the same device identifier in a past association as the past association for the first passive wireless transmission device. For example, the first device identifier can be allocated to the second wireless transmission device after the first device identifier has been invalidated for the first wireless transmission device.

[0018] In one embodiment, the system is further configured to obtain an associated applicable encryption key for the device identifier and the associated authentication token. Coupling the encryption key to the association of the device identifier and the authentication token facilitates determining the applicable encryption key from at least one of the device identifier and the authentication token.

[0019] In one embodiment, the system is further configured to use the applicable encryption key to at least encrypt a portion of the second device identifier and / or the second authentication token, e.g., upon transmission to the passive wireless transmission device, if transmitted from the system.

[0020] Likewise, the passive wireless transmission device can be configured to include at least one encryption key. In an embodiment, the device is configured to receive the second device identifier and / or the second authentication token from the system at least in encrypted form and use the encryption key to at least decrypt a portion of the second device identifier and / or the second authentication token.

[0021] Embodiments enhance the security of the downlink transmission of the second device identifier and, if the second authentication token is transmitted, also the security of the downlink transmission of the second authentication token.

[0022] In one embodiment, the system is further configured to obtain an updated encryption key for the device identifier and the associated authentication token. The updated encryption key continues or improves the security of the transmission.

[0023] In one embodiment, the system is further configured to receive a wireless transmission of the passive wireless transmission device, wherein a data portion of the wireless transmission is encrypted, and forward the encrypted data in the wireless transmission, such as sensor data, to a data collection entity. The address of the data collection entity can be obtained using at least one of the device identifier and the authentication token in the wireless transmission.

[0024] Likewise, the passive wireless transmission device can be further configured to transmit data, such as sensor data, in at least one of the first, second, and third wireless transmissions. The device can include an applicable encryption key to encrypt the data.

[0025] Embodiments allow transmitting data other than the device identifier and the authentication token in encrypted form upon wireless transmission by the passive wireless transmission device to an operator of the passive wireless transmission device. The encryption key can be known only to the operator, e.g., of the data collection entity. This provides secure transmission of the sensor data.

[0026] In one embodiment, the system is configured to transmit at least one of a random number causing the wireless transmission device to provide or update the applicable encryption key and a key index causing the wireless transmission device to provide or update the applicable encryption key to the passive wireless transmission device.

[0027] Likewise, the passive wireless transmission device can be configured to obtain the applicable encryption key by receiving a random number from the system and inputting the random number in a key generation algorithm to derive the encryption key, or by receiving a key index from the system to select the applicable encryption key from a set of encryption keys stored in the passive wireless transmission device and retrievable via the key index.

[0028] Embodiments provide a secure encryption key provisioning and / or update mechanism. If the passive wireless transmission device has a certain processing power at the right time, it can run a key generation algorithm. If less or only at certain times (e.g. when energy or power is available from a transmission received from the network, such as a transmission comprising a key index) energy is available or power is available, a key update mechanism can use a set of encryption keys to select an updated applicable encryption key.

[0029] In some cases, it can be necessary to update the encryption key via an over-the-air transmission of the key.

[0030] Thus, in one embodiment, the system can be configured to provide a new applicable encryption key that is encrypted using a previously provisioned encryption key.

[0031] Likewise, in one embodiment, the passive wireless transmission device can be configured to obtain the applicable encryption key by decrypting the applicable encryption key received from the system using a previously stored encryption key.

[0032] Embodiments allow secure transmission of the encryption key over the air using a previously stored applicable encryption key. After having received and stored the encryption key, the previously stored applicable encryption key can become outdated.

[0033] In one embodiment, the system can be configured to transmit one or more identifier revocation messages to announce revocation of the first identifier to the passive wireless transmission device.

[0034] Likewise, the passive wireless transmission device can be configured to receive the one or more identifier revocation messages. Optionally, the device can be configured to stop performing wireless transmissions to the system (at least to the system to which transmissions were previously allowed) in response to receiving the one or more identifier revocation messages.

[0035] The wireless transmission device can not be aware that their identifier is no longer valid. While transmissions from a device using a device identifier that has been reassigned to another device will generally no longer be authenticated (as the association between the identifier and the authentication key no longer exists in the network system), it can be beneficial to inform the device of the revocation. Such information can completely stop the device from transmitting, saving network resources.

[0036] As mentioned above, passive wireless transmission devices, such as environmental IoT devices, require external energy to perform operations and transmissions.

[0037] Thus, in one embodiment, the system can be configured to trigger a wireless transmission configured to energize the passive wireless transmission device. In some embodiments, the wireless transmission can include at least one of the second device identifier, the second authentication token, and the identifier revocation message described above.

[0038] Likewise, in one embodiment, the passive wireless transmission device can be configured to include an energy harvesting portion. The energy harvesting portion can be configured to harvest energy from the wireless transmission from the system, such as at least one of the second device identifier, the second authentication token, and the identifier revocation message described above, to perform wireless transmissions to the network.

[0039] Embodiments combine the signaling messages triggered by the system to enable re-use of a device identifier in cases where such a device is provided at least partial energy for. This energy can be used to perform functions in the passive wireless transmission device to enable this re-use.

[0040] In one embodiment, the passive wireless transmission device can be configured to transmit an acknowledgement signal to the system to acknowledge receipt of the second device identifier. This enables the system to confirm that the wireless transmission device has properly received the device identifier.

[0041] In one embodiment, the passive wireless transmission device can be configured to receive an acknowledgement signal from the system to acknowledge receipt of the first and / or second wireless transmission, wherein the wireless transmission device is optionally configured to use the received acknowledgement signal for at least one of: triggering computation of an authentication token, refraining from re-sending data, and energizing the passive wireless transmission device.

[0042] Another aspect of the present disclosure relates to a method for communication with a plurality of passive wireless communication devices, the method comprising one or more of the following steps. The method involves a step of receiving a first wireless transmission of a passive wireless transmission device, the first wireless transmission comprising a first device identifier and a first authentication token. For example, the system can authenticate this transmission based on an association of the first device identifier and the first authentication token. The method can further comprise a step of determining a second authentication token for the passive wireless transmission device. The method can further comprise a step of invalidating the first identifier for the passive wireless transmission device, for example because the system has reassigned the first device identifier to another passive wireless transmission device. The method can further comprise a step of receiving a second wireless transmission of the passive wireless transmission device. The method can further comprise a step of determining a second device identifier for the passive wireless transmission device. The method can further comprise the steps of storing an association of the second authentication token with the second device identifier as a current association for the passive wireless transmission device, and storing an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device. The method can further comprise the steps of authenticating the second wireless transmission if it contains the second device identifier and the second authentication token according to the current association, and also authenticating the second wireless transmission if it contains the first device identifier and the second authentication token according to the past association.

[0043] Another aspect relates to a computer program comprising one or more software code portions, the computer program, if executed on a system, causing the system to perform one or more steps of the method.

[0044] A further aspect of the present disclosure involves a method for a passive wireless communication device for use in a system configured for communication with passive wireless communication devices. The method can involve one or more of the following steps. One step involves performing a first wireless transmission comprising at least a first device identifier and a first authentication token. One further step can involve receiving or generating a second authentication token from the system. Yet another step can involve performing a second wireless transmission comprising the first device identifier and the second authentication token, and receiving a second device identifier from the system in response to the second wireless transmission. A further optional step can comprise performing a third wireless transmission comprising at least the second device identifier and the second authentication token or a third authentication token.

[0045] Another aspect relates to a computer program comprising one or more software code portions, the computer program, if executed on a system, causing the system to perform one or more steps of the method.

[0046] Yet another aspect of the present disclosure relates to a system for communication with a plurality of passive wireless transmission devices and a combination of passive wireless transmission devices as disclosed herein. In particular, such a combination relates to a passive wireless communication system comprising a central system and a plurality of passive wireless communication devices. The passive wireless communication system is configured to performing, at the passive wireless communication device, a first wireless transmission comprising at least a first device identifier and a first authentication token; receiving, at the central system, the first wireless transmission of the passive wireless transmission device, the first wireless transmission comprising the first device identifier and the first authentication token; determining, at least in the central system, and optionally also in the passive wireless communication device, a second authentication token; invalidating, at the central system, the first device identifier for the passive wireless transmission device, and determining a second device identifier for the passive wireless transmission device; performing, at the passive wireless communication device, a second wireless transmission; receiving, at the central system, the second wireless transmission of the passive wireless transmission device; storing, at the central system, an association of the second authentication token with the second device identifier as a current association for the passive wireless transmission device; storing, at the central system, an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device; authenticating, at the central system, the second wireless transmission if it contains the second device identifier and the second authentication token according to the current association, authenticating, at the central system, the second wireless transmission if it contains the first device identifier and the second authentication token according to the past association.

[0047] Optionally, in response to determining the second device identifier and / or the past association, the passive wireless communication system can be configured to transmitting, at the central system, the second device identifier; receiving, at the passive wireless transmission device, the second device identifier; performing, at the passive wireless transmission device, a third wireless transmission comprising the second device identifier and a second authentication token or a third authentication token; authenticating, at the central system, the third wireless transmission on the basis of the second device identifier and the second authentication token from the current association or the second device identifier and the third authentication token as the current association.

[0048] The second authentication token can be transmitted from the central system to the passive wireless transmission device and received by the passive wireless transmission device. The second authentication token can also be generated in the passive wireless transmission device.

[0049] It should also be appreciated that the order of the steps can be changed while achieving the same result.

[0050] As will be appreciated by those skilled in the art, aspects of the present application can be embodied as a system, method, or computer program product. Accordingly, aspects of the present application can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects (all generally referred to herein as a "circuit," "module" or "system"). The functions described in this disclosure can be implemented as an algorithm executed by a processor / microprocessor of a computer. Furthermore, aspects of the present application can take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied (e.g., instaUed) thereon.

[0051] Any combination of one or more computer readable medium(s) can be utilized. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer readable storage medium can include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present application, a computer readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.

[0052] A computer readable signal medium can include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium can be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0053] Program code embodied on a computer readable medium can be used by executing the instructions read from the computer readable medium by one or more processing units, such as a microprocessor(s) or central processing unit(s) (CPU(s)). In this context, a "computer readable medium" can be any media that can be accessed by a computer. By way of example, and not limitation, such computer readable medium can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, or twisted pair, then the coaxial cable, fiber optic cable, or twisted pair are included in the definition of medium. Disk and disc, as used herein, includes compact disc (CD), laser disc, optical disc, Blu-ray® disc, and floppy disk used to store software.

[0054] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0055] These computer program instructions can also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.

[0056] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0057] The computer program product of the present application can be a computer program embedded in a computer readable storage medium, such as, for example, a semiconductor memory, a magnetic or optical disk memory, etc. The computer readable storage medium can be a non-transitory computer readable storage medium. The computer program can also be available for download on the internet and stored on a server and / or a computer of a download platform. The computer program can also be available for download on the internet and stored on a server and / or a computer of a download platform.

[0058] Furthermore, a computer program for performing the methods described herein is provided as is a non-transitory computer readable storage medium storing the computer program.

[0059] Elements and aspects discussed in relation to a particular embodiment or in relation to a particular aspect can be suitably combined with elements and aspects of other embodiments, unless explicitly stated otherwise. Embodiments of the application will be further described with reference to the drawings, which will illustrate schematically embodiments according to the application. It will be understood that the application is not in any way restricted to these specific embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0060] Aspects of the application will be explained by reference to exemplary embodiments shown in the drawings, in which: Figure 1 is a schematic illustration of a central system configured for wireless communication with a plurality of passive wireless transmission devices; Figure 2 is a time diagram of some steps for wireless transmission between a central system and a passive wireless transmission device; Figure 3 is a schematic illustration of another embodiment of a central system in a network configured for wireless communication with a plurality of passive wireless transmission devices; Figure 4 is a schematic illustration of a passive wireless transmission device configured for wireless communication with a central system; Figure 5 is a time diagram of some alternative or additional steps for wireless transmission between a central system and a passive wireless transmission device; Figures 6A-6E various stages of device identifier management according to embodiments of the present disclosure are shown; and Figure 7 depicts an example of a processing system according to embodiments of the central system or parts thereof. Detailed Implementation

[0061] Figure 1 This is a schematic illustration of a passive wireless communication system 100 including a central system 10 and multiple passive wireless transmission devices 20. The central system 10 includes a processing unit 11, a storage device 12 for storing information such as device identifier ID and authentication token T, and a communication interface 13. The communication interface 13 facilitates wireless communication with the passive wireless transmission devices 20.

[0062] Central system 10 can be a standalone system or a system included in a network. When in a standalone system, communication interface 13 can be configured for wireless communication with the passive wireless transmission device itself. In one embodiment, radio signals from central system 100 can be used to power the passive wireless communication device and for exchanging information between them. When the central system is included in a network, see, for example, [link to relevant documentation]. Figure 3 The communication interface 13 can be wirelessly or wiredly connected to the entity responsible for wireless communication.

[0063] Passive wireless transmission device 20 is a power-constrained device, such as an ambient power-enabled IoT device. Such devices may also be referred to as passive IoT devices or ambient IoT devices. These devices can be battery-free devices with limited energy storage capacity (which may include capacitors), where power is provided by harvesting radio waves, light, motion, heat, or any other power source that may be suitable. Therefore, in this context, energy is a very scarce resource and its use is preferably optimized by limiting the amount and size of computations and / or exchanged messages. Furthermore, passive wireless communication devices can remain passive for extended periods before receiving a wake-up signal and beginning to transmit data. (See reference...) Figure 4 An embodiment of the passive wireless transmission device 20 is further described.

[0064] Figure 2 This is a timeline depicting one or more steps of a method for enabling the reuse of a device identifier ID in a passive wireless communication system 100. It should be noted that those skilled in the art will envision that the order of some steps can be changed and / or fewer and / or additional steps can be performed.

[0065] In step S1, the central system 10 receives a first wireless transmission of the passive wireless transmission device 20A, the first wireless transmission comprising a first device identifier ID1 and a first authentication token T1. The wireless transmission can use power from a signal, such as a request for information signal, from the central system 10 or from another energy source external to the device 20A. The central system 10 can authenticate the transmission by determining that the first device identifier ID1 and the first authentication token T1 are associated in the central system 10. The central system can confirm successful receipt of the first wireless transmission (not shown).

[0066] In step S2, both the passive wireless transmission device 20A and the central system 10 compute a second authentication token T2. This computation in the device 20A can be triggered by the confirmed receipt of step S1. Computing the second authentication token at the device 20A and the central system 10 respectively limits the signalling over the air interface. The confirmation can power the passive wireless transmission device 20A to perform this computation. The central system 10 can now associate ID1 with T2 in the storage device 12.

[0067] In step S3, the passive wireless transmission device 20A can perform another wireless transmission comprising the first identifier ID1 and the new authentication token T2. Again, the central system can authenticate the transmission based on the new authentication token T2 and the first identifier ID1 being stored in association in the storage device 12. Again, the transmission can be confirmed (not shown).

[0068] In step S4, both the central system 10 and the passive wireless transmission device 20A compute a third authentication token T3. The central system 10 can now associate ID1 with T3 in the storage device 12.

[0069] After some time, in step S5, the central system 10 can receive a transmission from a further passive wireless transmission device 20B. In step S6, the central system 10 can decide to allocate the first identifier ID1 to this further passive wireless transmission device 20B in response to receiving this transmission. In step S7, both the central system 10 and the passive wireless transmission device 20B can compute an authentication token T4. The central system 10 can now associate ID1 with T4 in the storage device 12. The central system 10 can invalidate the device identifier ID1 for the passive wireless transmission device 20A.

[0070] In step S8, the central system 10 authenticates a wireless transmission from the passive wireless transmission device 20B, the wireless transmission comprising the device identifier ID1 and the authentication token T4. Both the wireless device 20B and the central system 10 can compute a further authentication token (not shown), for example in response to a confirmation (not shown) of the transmission.

[0071] After some further time, in step S9, the passive wireless transmission device 20A, which does not know that the device identifier ID1 has been reassigned to the passive wireless transmission device 20B, performs a further wireless transmission comprising the first device identifier ID1 and an authentication token T3 to the central system 10. The central system 10 determines that the first device identifier ID1 has been assigned to a further wireless transmission device. The central system 10 can determine this, for example, by detecting that ID1 is not (any more) associated with the authentication token T3 (but with the authentication token T4, resulting from the reassignment of the device identifier ID1 to the device 20B).

[0072] Still, because the association of the first device identifier ID1 and the authentication token T3 still exists in the central system 10, the system authenticates the transmission of step S9. Therefore, in step S10, the central system 10 assigns a new device identifier ID2 to the passive wireless transmission device 20A and informs it. The transmission in step S10 also contains a refreshed authentication token T5, which is generated and stored in the central system 10. The central system 10 can now associate ID2 with T5 in the storage means 12.

[0073] Optionally, in step S11, the passive wireless transmission device 20A can retransmit a wireless transmission comprising the second device identifier ID2 and the authentication token T5. The central system 10 can authenticate this transmission and return an acknowledgement (not shown). In step S12, this can cause the central system 10 and the passive wireless transmission device 20A to compute an authentication token T6. The central system 10 can now associate ID2 with T6 in the storage means 12.

[0074] The system 10 and the passive wireless transmission device 20A enable the reuse of a device identifier ID1 while allowing some degree of authentication. The system uses the authentication tokens T both for authentication and for device identification by requiring each wireless transmission to contain a new authentication token T while allowing some flexibility in the device identifier used in the transmission. As long as the device identifier ID1 has not been reassigned to another device (such as in step S6), the device identifier ID1 can continue to be used by the device (see step S3). Otherwise, a new device identifier ID2 is assigned (step S10). By the association of the authentication token T used for each transmission with the device identifier, authentication remains possible. As a result, the device identifiers IDx do not have to be permanently unique and / or unique among the population of passive wireless transmission devices 20, so that shorter device identifiers can be used for large populations of passive (i.e. power-constrained) wireless transmission devices 20, if desired.

[0075] Figure 3This is another embodiment of the passive wireless communication system 100, wherein the central system is included in a telecommunications network PLMN. The telecommunications network can be a 4G, 5G, or 6G network. The telecommunications network PLMN can have multiple components as known to those skilled in the art, including base stations, a control plane system, and a data plane system. The central system 10 can be contained in one such component or distributed across several components, such as... Figure 3 As shown in the diagram. For example, wireless transmission interface 13 may be included in a base station that provides wireless radio coverage to multiple passive wireless transmission devices 20. Figure 1 As shown, the processing unit 11 can also be housed in the radio access network or within the core network of the PLMN. Similarly, as... Figure 1 As shown, storage device 12 can be included in a radio access network, a core network (e.g., in a user register, such as a Home Subscriber System (HSS) or a Unified Data Management Function (UDM)) or distributed across the network.

[0076] The telecommunications network PLMN can connect to the operator OP of the passive wireless communication device 20 via another network NW, such as Figure 3 As shown in the image.

[0077] Figure 4 This is a schematic illustration of a passive wireless transmission device 20 configured for wireless communication with a central system 10. Device 20 is configured to receive and process a power signal PS. Device 20 includes a power acquisition section 21, a processing section 22, and a storage section 23 configured to store at least a device identifier and an authentication token. Device 20 also includes a communication section 24 enabling wireless communication COMM. Device 20 may include additional components or functions, such as at least one sensor 25 (or its connector). It should be understood that device 20 may include multiple sensors 25 or their connectors. Examples of sensors include position sensors, temperature sensors, humidity sensors, light sensors, pressure sensors, motion sensors, etc.

[0078] Device 20 is configured to acquire power from a power signal PS (e.g., triggered by central system 10) to at least activate processing section 22, and optionally activate at least one of other sections, such as storage section 23, communication section 24, and sensor 25. Power supply lines to these sections are... Figure 4 The solid line indicates the middle.

[0079] Processing unit 22 is configured to process wireless transmissions of signals received from and transmitted to the central system 10, as shown in reference 10. Figure 2 As described. The signal lines used for this type (one or more) of actions are in Figure 4 The middle is indicated by a dotted line.

[0080] It should be understood that device 20 may include more or fewer components. Essentially, device 20 is a battery-free device with limited (if any) energy storage capacity (which may include one or more capacitors), wherein energy is supplied by harvesting radio waves, light, motion, heat, or any other power source that may be suitable. Device 20 is not able to store any significant power supplied to it in the power signal PS, and uses the supplied power almost immediately to perform its desired action(s). Advantageously, the power signal PS and the communication COMM are combined, such that the excitation and communication for the passive wireless transmission device 20 are integrated. For example, see reference... Figure 2 In steps S5 and / or S9, from the central system 10 (and from...) Figure 2 The signal received by one or more of the acknowledgments (not shown) may contain sufficient energy to excite portions of the passive device 20 to allow processing (e.g., computation), storage, and / or retrieval steps.

[0081] Figure 5 It is a timeline of some alternative or additional steps used for wireless transmission between system 10 and passive wireless transmission device 20. Figure 5 Focus on Figure 1 The operation of the storage device 12 in the central system 10 shown herein, as well as the focus on encryption key management, are illustrated. Again, those skilled in the art will recognize that the order of the steps can be changed without altering the outcome of the operation.

[0082] In step S20, the central system 10 receives wireless transmissions from the passive wireless transmission device 20A. The transmissions include a first device identifier ID1, an authentication token T1, and data DATA encrypted with a data encryption key Kd, such as sensor data. The encryption key Kd may be pre-installed in the passive wireless transmission device 20A by the operator (OP) operating the device. The bidirectional arrow in step S20 indicates confirmation of receipt of the wireless transmission.

[0083] The transmission in step S20 is authenticated by the central system 10 using a storage device 12 containing a table, where ID1 and T1 are associated with each other in the current portion PRES of the table. From the table, the central system 10 can use ID1 and / or T1 to determine the operator's address AD in order to forward data to the operator in step S21.

[0084] In step S22, both the central system 10 and the passive wireless transmission device 20A calculate a new authentication token T2. ​​The wireless transmission device 20A may use energy from the confirmation signal in step S20 for this purpose. In the central system 10, the table in the storage device 12 is updated accordingly by associating the device identifier ID1 with the authentication token T2 in the current portion PRES of the table from now on, while moving the previous association of ID1 and T1 to the past portion PAST of the table.

[0085] It should be noted that those skilled in the art will recognize that various alternatives may be available for operating storage device 12. For example, an alternative could be that current and past associations are stored in separate tables, or that each device entry in a table is indicated as 'current' or 'past'. In the latter alternative, the indication of the association between the device identifier and the authentication token can simply be changed from 'current' to 'past' (when it no longer contains a current association), and removed from the table at a later stage when sufficient past associations (which may be a single past association) are stored for the device.

[0086] In step S23, the central system 10 updates the table in the storage device 12 again. The update involves device identifier ID1, which is no longer valid for the passive wireless communication device 20A. This may be because the device identifier ID1 has been reassigned to another passive wireless transmission device, allowing the device identifier to be reused as coordinated from the central system 10. This is reflected in the table in the storage device 12 for device 20A by updating the device identifier and authentication token to device identifier ID2 in the current portion PRES of the table, and preferably to authentication token T3. It should be noted that in another embodiment, authentication token T2 may continue to be used in association with device identifier ID2.

[0087] Additionally, the central system 10 can determine a new encryption key K2, as will be explained in further detail below. The previous association between ID1 and T2 is moved to the past part of the table, PAST.

[0088] In step S24, the central system 10 receives an additional wireless transmission with updated data DATA from the passive wireless transmission device 20A, which uses power from an external power source. Since the passive wireless transmission device 20A has not yet been made aware of the change in association in storage device 12, the wireless transmission in step S24 includes the past association of device identifier ID1 and token T2. ​​However, since the central system 10 still stores the past association of ID1 and T2 in the PAST section of the table, the central system 10 is enabled to determine that the wireless transmission is an authentication request to update the association of the new identifier ID2 in the device and preferably the new authentication token T3, because the previous device identifier ID1 was invalid for the passive wireless transmission device 20A. This transmission is shown in step S25 and reflected in the PRES section of the table. This association may have already been updated in the table after step S23.

[0089] Note that the central system 10 can decide to accept a transmission including ID1 and T2 (although not stored in the current portion PRES of storage device 12). This is shown by the dashed line in S24', where the data DATA is forwarded to the operator using the address AD from the PAST portion retrieved based on ID1 and T2. In step S24, this forwarding can be acknowledged by the central system to device 20.

[0090] As from Figure 5 In step S25, a new device identifier ID2 and a new authentication token T3 are transmitted to the passive wireless transmitter 20A. These are encrypted with an encryption key K1 associated with ID1 and T3 (and previously associated with them) to enhance security. It is assumed that the passive wireless transmitter 20A has access to the encryption key K1, for example, because this key is pre-installed or previously provided from the central system 10. The transmission from the central system 10 in step S25 also includes a key index KI that points the passive wireless transmitter 20A to an encryption key K2, which will be used by the central system 10 for future transmissions to the passive device 20A. For this purpose, the passive wireless transmitter 20A may contain a list of encryption keys, where entries can be pointed to by the key index KI. Alternatively, the transmission in step S25 may include a random number to be input into a key generation algorithm agreed upon between the central system 10 and the passive device 20A to generate an encryption key 22. Otherwise, the transmission in step S25 may include the encryption key K2 itself, which is encrypted under the encryption key K1 that already exists in the passive wireless transmission device 20A.

[0091] Step S25 may further include transmitting an acknowledgment signal from the passive wireless transmitter 20A to the central system 10 to confirm the proper reception of the new device identifier ID2 (and other information, if included in the transmission). The transmission of the acknowledgment signal can be triggered by the reception of the signal from the central system 10 in S25. The central system 10 is now assured that the passive wireless transmitter 20A has securely received the new device identifier ID2, which improves device identifier reuse management within the system.

[0092] If step S24' is not performed, then in step S26, the central system 10 receives a wireless transmission including an updated association of device identifier ID2 and preferred authentication token T3. After querying storage device 12, in step S27, the central system 10 forwards data encrypted under Kd to the operator using address AD from the table now associated with the new association of ID2 and T3.

[0093] In step S28, both the central system 10 and the passive wireless transmitter 20A update the authentication token to T4. The passive wireless transmitter 20A may use the confirmation from step S26 for this purpose. The central system 10 updates the association in the table of the storage device 12 as shown.

[0094] The passive wireless communication system 100 provides a robust and energy-efficient mechanism for assigning reusable device identifiers, wherein the central system 10 provides a non-replayable temporary (one-time) authentication token and a reusable identifier. The token size allows it to reduce or minimize energy consumption when calculating a new token, while preventing easy brute-force attacks. The token is updated with each communication, so the central system 10 always knows which token to expect from the device currently using the reusable identifier. If the passive device 20 (from which its reusable ID has been reused or revoked) restarts communication using it, the token value will be different as referenced. Figure 5 The token value as described is expected by the network.

[0095] Using past data (i.e., authentication tokens associated with past assignments of the device identifier), the central system 10 can identify that the received token corresponds to a past assignment of that identifier. Therefore, it can directly trigger reassignment by providing the passive device 20 with a new, possibly encrypted, device identifier, so that it can continue to communicate with the central system 10 (if authenticated, the entire (power-consuming) authentication process is not performed).

[0096] The following describes a three-stage implementation for a passive wireless communication system, followed by references to... Figures 6A-6E An example of an implementation that reuses the enabler identifier for management.

[0097] In the first phase, the newly created passive wireless transmission device 20 is placed in an environment without energy constraints. After performing a conventional authentication process based on conventional, non-reusable identifiers and associated conventional authentication information, a reusable identifier, an initial authentication token, and optionally additional secrets and / or other information are supplied to device 20. The supplied information is sent in a confidential message and / or transmitted via a secure link. During this phase, the passive wireless transmission device 20 and the central system establish a shared secret key in a manner that preferably ensures no two devices will obtain the same secret key.

[0098] Specifically, the passive wireless transmitter 20 is placed in an environment with sufficient power, such as a device factory or operator's premises. The device 20 is authenticated in a conventional manner based on associated authentication information and a permanent identifier (PID) in the device and network. Through a protected link, the network provides the device with a reusable identifier (ID), an authentication token (T), and optionally other information. Through the protected link, the device and network establish a shared secret key. The reusable identifier (ID), the authentication token (T), and optional other information (such as an operator key (Kd)) and the shared secret key (K) are securely stored in the device 20. The authentication token (T) and the shared secret key (K) are stored in the central system 10 in association with the supplied reusable identifier (ID). Optionally, the permanent identifier (PID) of the passive wireless transmitter 20 is stored in association with the reusable identifier (ID).

[0099] In the second phase, the passive wireless transmitter 20 has acquired a valid reusable identifier ID, through which it can communicate with the central system 10. During this phase, the device 20 can wirelessly transmit data to the central system 10 using a single message containing the reusable identifier ID combined with a corresponding 'expected' authentication token T. The 'expected' authentication token is sufficient to verify whether the passive wireless transmitter 20 is authorized to use the reusable identifier ID. After each communication, for example based on secret data and the previous 'expected' authentication token T, the 'expected' authentication token T is changed to a new 'expected' authentication token T' in an unpredictable manner, thus limiting the device 20's chance of using the same device identifier and token. The newly created 'expected' authentication token T' is stored ready for use in the next communication.

[0100] Specifically, when the passive wireless transmitter 20 (with a valid reusable identifier ID) is in an environment with limitations on energy usage, it may want to send some data to the central system 10 using a single message from the transmitter 20. In addition to the data, the message contains the reusable identifier ID and an authentication token T. Based on the received authentication token T (and the reusable identifier ID), the central system 10 verifies the validity of the reusable identifier ID: if the authentication token T in the message corresponds to an authentication token stored in the central system 10 in association with the reusable identifier ID, then the identifier ID is considered valid.

[0101] Data can be encrypted using a shared secret key. To prevent man-in-the-middle attacks that could potentially replace data fields in a message, the encrypted data fields may additionally include an authentication token, a reusable ID, or any other shared information element. The central system 10 verifies the authenticity of the packet by decrypting the data fields and verifying the shared information elements using the secret key associated with the reusable ID and authentication token T.

[0102] After transmitting a single message, both device 20 and central system 10 calculate a new authentication token (for use in subsequent message exchanges). The calculation of the new authentication token utilizes some or all of the data stored in passive wireless transmission device 20 and central system 10, such as the shared secret key, the old authentication token, the permanent identifier PID, and other information.

[0103] The authentication token T may have the following properties. The authentication tokens used by different devices 20 in messages sent to the central system 10 should preferably be different. Furthermore, it is preferable to avoid calculating the next authentication token T from past authentication tokens without accessing the secret information from device 20 used to calculate the next authentication token.

[0104] An example of an algorithm for calculating a new authentication token is as follows. During the first phase, when device 20 is in a secure, energy-rich environment, central system 10 establishes a secret communication key for passive wireless transmission device 20 and exchanges secret information elements to be used in subsequent communications, such as a (pseudo)random number RN or the device's permanent PID. After each communication, both central system 10 and device 20 can use the previous authentication token T to... i And one or more shared secret information elements to calculate the new authentication token T i+1 ,as follows: T i+1 = f (T i , Secret Key , [RN], [PID],…) Where the functionf(x) It is a mathematical operation that can be performed by device 20, and is robust enough to allow the set T0...T to be run without knowing the secret information. i Cannot be used to infer T i+1 …. T N , where N is the maximum number of times a new token is calculated based on the previous token before performing a token refresh.

[0105] To implement function F, several lightweight cryptographic algorithms for passive device 20 can be used, such as stream or block cryptography algorithms, which combine basic operations such as ADD, XOR, or SHIFT, including substitution-permutation networks (SPN), Festor networks (FN), generalized Festor networks (GFN), addition-rotation-exclusive (ARX), and nonlinear feedback shift registers (NLFSR). Other lightweight algorithms, such as elliptic curve cryptography (ECC), can also be employed. A more detailed explanation is provided through lightweight cryptographic algorithms for resource-constrained IoT devices: from VA Thakar et al., 2021 IEEE Access, Vol. 9, pp. 28177-28193, "A Review, Comparison and Research Opportunities," and an analysis of lightweight cryptographic algorithms for IoT communications, in: Conference on Intelligent Systems CIS2020, Sharma, H., Saraswat, M., Yadav, A., Kim, JH, Bansal, JC (eds.).

[0106] Another example algorithm for deriving a new authentication token based on a previous authentication token and secret key is the Key Derivation Function (KDF) defined in Appendix A of 3GPP TS 33.501, V18.1.0 and Appendix B of 3GPP TS 33.220, V17.4.0C. The KDF mechanism can be used to secure communication with the passive wireless transmission device 20, as detailed in Clause 6.16.2 of 3GPP TS 33.501, V18.1.0.

[0107] Given the limited computing power of the passive wireless transmission device 20, and if energy constraints permit, the central system can send a message containing a fresh authentication token T to device 20. The sent token T should be protected by confidentiality (encryption) using the shared secret key of device 20, and a token refresh can be performed if a (potential) collision of authentication tokens T from different devices 20 is anticipated or detected. Based on the perceived risk of potential predictions of authentication tokens, messages can also be sent to device 20 after a pre-configured number of received messages.

[0108] In the third phase, the passive wireless transmitter 20 no longer has a valid identifier ID, for example, because the central system 10 has reused the device identifier. If device 20 attempts to send a message to the central system with this invalid identifier ID and authentication token T, the central system 10 determines that device 20 is using an invalid reusable device identifier ID because the received authentication token T is not the expected authentication token T used for this reusable identifier ID. The central system 10 can then respond with a single message containing a new reusable identifier ID and optionally a new initial authentication token T and optionally a new secret key. The single message can be encrypted using the (old) secret key associated with the device, thus protecting the confidentiality of the message sent to device 20.

[0109] Specifically, the central system 10 can decide to reallocate or revoke the reusable identifier ID of a passive wireless transmitter 20, and reallocate a device identifier ID to another device 20. The passive device 20 may or may not be notified of the revocation of the identifier ID. The revocation of the identifier may be triggered by prolonged inactivity of the device 20. As a result of the reallocation of the reusable identifier ID, a new authentication token T will be associated with the reusable identifier ID. The new authentication token T will be different from any authentication token T expected in the next communication from the device 20 (from which the reusable identifier ID is invalid).

[0110] When device 20 (with an invalid reusable identifier) ​​is in an environment with energy usage restrictions, it may still want to send some data to the central system 10 using a single message from device 20 to the central system 10. Passive device 20 will use the invalid reusable identifier and a newly calculated authentication token T. The central system 10 will identify the authentication token T as belonging to device 20, which previously had a reusable identifier ID assigned to it. Now, the central system 10 can decide to provide device 20, which only has an invalid reusable identifier, with a new reusable identifier ID and a new authentication token T by sending a single message to device 20. The message sent to device 20 can be encrypted using device 20's secret key.

[0111] In order to identify device 20 and use the appropriate secret key, the network may store one, some, or all of the past associations of each reusable device identifier ID, the corresponding authentication token T, and the associated secret key. If a past association exceeds a certain storage duration and / or for other reasons (e.g., storage space considerations), the central system 10 may choose to discard the information associated with these past associations.

[0112] Central system 10 may or may not decide to accept data sent by device 20 with an invalid reusable identifier ID. Central system 10 may decide not to reassign a reusable identifier ID to device 20. If it does not want to reassign a reusable identifier ID, central system 10 may send a message indicating permanent revocation of the identifier ID to the device a certain number of times before removing all data associated with device 20, in which case the device is not authorized to transmit any messages to central system 10.

[0113] Now the description reference Figures 6A-6E Examples of implementations that reuse the enable device identifier for management. The table below shows examples stored in the central system 10 (e.g., ...). Figure 1 A general overview of the information in the storage device 12 shown in the figure, wherein the listed information indicates any further information, such as data from the sensor, the permanent identifier PID and / or other shared secret information used to calculate the next authentication token.

[0114] The table below shows the storage locations in specific passive wireless transmission devices 20, particularly those stored in, for example... Figure 4 A general view of the data in storage section 23 shown in the figure.

[0115] Figure 6A An exemplary procedure is shown for the initial allocation of a reusable device identifier ID for the passive wireless transmission device 20 in the first phase. It is assumed that device 20 is in an environment without energy limitations on the device. After the initial allocation of the reusable ID, the following records can be added to the storage device 12 in the central system (assuming reusable ID = 123, authentication token = ABC, key = uvw, and information = Inf.1).

[0116] The corresponding data stored in device 20 can be as follows: In the second phase, the passive wireless transmission device 20, which wants to send data to the central system 10 in an energy-limited environment, can perform... Figure 6B The message stream.

[0117] After receiving power from an external power source, device 20 transmits data encrypted using its secret key, along with its reusable ID and authentication token. System 10 uses the reusable ID and authentication token combination to identify device 20 by comparing them to entries in a database (e.g., storage device 12) and retrieving the secret key to decrypt the encrypted data in the message, and to verify the authenticity of the packet by verifying the decrypted shared information elements. The latter can be used to prevent man-in-the-middle attacks, as the device identifier and authentication token are transmitted unencrypted, making it possible for any intercepting entity to obtain the device identifier and authentication token and use any information to replace data fields. Additional information can be added to the encrypted data to ensure that the transmission originates from a genuine passive wireless transmission device.

[0118] After processing the data, the central system 10 sends a command to the device 20 to update the authentication token, which triggers the device 20 and the central system 10 to calculate the next expected authentication token. The calculation of the next authentication token is performed based on the calculation including the previous authentication token, the secret key, and optional additional parameters.

[0119] The central system 10 can also record the number of times a reusable ID is used with a non-fresh authentication token (i.e., messages already received from this device) and the date and time this occurs. This counter can be used to refresh the authentication token after a pre-configured number of communications to increase robustness against brute-force attacks based on the recorded past tokens.

[0120] If device 20 does not receive an update command, the central system 10 can retain the old authentication token in its database, in which case the central system 10 has updated its token to the new token, while the device has not. If device 20 again uses the older authentication token to send data, the central system 10 initiates an authentication token refresh procedure, as shown below. Figure 6C The subject of discussion.

[0121] At this stage, assuming the new authentication token = DEF, the database of the central system 10 can be as follows.

[0122] Central system 10 may retain the second record rec:2 in its database until device 20 sends data using an updated authentication token, in which case the authentication token is updated to the new authentication token. A new entry is added to the table, where the next authentication is expected to be active, and the status of the first record changes from active to updated to record:3 because the authentication token has already been used for communication from the device.

[0123] Correspondingly, after a communication, the information stored in device 20 is as follows: Central System 10 can initiate, for example Figure 6C The image shows a refresh of the authentication token. In contrast to the authentication token update procedure, a refresh operation can generate a completely new authentication token that is computationally independent of the previous authentication token.

[0124] After the authentication token is refreshed (assuming this is GHI), the database in the central system may look like this (assuming only a single SendData message is received). The database will temporarily contain two records for the same passive wireless transmitter 20 because there is no confirmation that the token refresh message has been correctly received and processed. Since device 20 may not have sufficient power to process refresh messages, its reception and processing are generally indeterminate. If, later, the central system 10 has received a message with a reusable ID = 123 and authentication token = GHI, the database will be updated as follows (with the newly calculated next authentication token = JKL).

[0125] Otherwise, if device 20 sends an older token again, it may trigger a new refresh cycle.

[0126] In the third phase, the central system 10 can initiate, for example... Figure 6D The revocation of a reusable ID is shown in the image.

[0127] After a prolonged period of inactivity of the passive wireless transmission device 20, a reusable ID revocation can be initiated. The central system 10 can then revoke the reusable ID and reassign device identifiers to other passive devices 20.

[0128] If the passive device 20 returns by sending a message using a reusable ID, the central system 10 can trigger a reusable ID reallocation (as per reference). Figure 6E (as described), or if device 20 is no longer permitted to communicate with the network, another revocation notification is sent. After revocation, the central system 10 can remove the record of device 20 from its database, but it can optionally store it for a period of time to identify the device if it becomes active again. If the revocation is final, the central system can also record the number of times a revocation message is sent to device 20. In this case, the database can be as follows: The central system 10 can maintain a counter for the number of times a revocation message has been sent to the device 20, and if the revocation message is not properly received or processed by the device, it sends a pre-configured number of messages to the device (from which the ID has been revoked) in response to receiving data from the device 20. The passive wireless communication device 20 can be configured to stop transmitting wirelessly after receiving a revocation message from the central system 10 once or multiple times.

[0129] Central system 10 can assign new device identifiers to passive wireless transmission device 20, such as Figure 6E As shown in the diagram. When device 20 (whose device identifier has been reassigned to another device 20) returns, a reusable ID allocation can be triggered. In this case, the central system 10 identifies device 20 based on a combination of the reusable ID and authentication token already stored in the database. The allocation of a new reusable ID can also be triggered by the network for any other reason. Note that the allocation may include refreshing the authentication token.

[0130] After a new reusable ID is assigned, records from past reusable IDs and authentication tokens can be removed from the database.

[0131] Figure 7 A block diagram illustrating an exemplary processing system according to the disclosed embodiments (e.g., a portion of a central system 10 for use in a passive wireless transmission system 100 as described above) is depicted. Figure 7 As shown, the processing system 70 may include at least one processor 71 coupled to the memory element 72 via a system bus 73. Therefore, the processing system can store program code within the memory element 72. Furthermore, the processor 71 can execute program code accessed from the memory element 72 via the system bus 73. In one aspect, the processing system may be implemented as a computer system suitable for storing and / or executing program code. However, it should be understood that the processing system 70 may be implemented in the form of any system including a processor and memory capable of performing the functions described herein.

[0132] Memory element 72 may include one or more physical memory devices, such as, for example, local memory 74 and one or more mass storage devices 75. Local memory may refer to random access memory or one or more other non-persistent memory devices generally used during the actual execution of the program code. Mass storage devices may be implemented as hard disk drives or other persistent data storage devices. Processing system 70 may also include one or more cache memories (not shown) that provide temporary storage for at least some program code to reduce the number of times program code must be retrieved from mass storage device 75 during execution.

[0133] The input / output (I / O) devices, depicted as input device 76 and output device 77, may optionally be coupled to the processing system. Examples of input devices may include, but are not limited to, a spatial access keyboard, pointing devices (such as a mouse), etc. Examples of output devices may include, but are not limited to, a monitor or display, a speaker, etc. The input and / or output devices may be coupled to the processing system directly or through an intermediate I / O controller.

[0134] In embodiments, the input and output devices can be implemented as a combined input / output device (in... Figure 7 (Illustrated by dashed lines surrounding input device 76 and output device 77). An example of such a combined device is a touch-sensitive display, sometimes also called a “touchscreen display” or simply a “touchscreen” (which may be provided with the UE). In such an embodiment, input to the device can be provided by movement of a physical object (such as, for example, a stylus or a human finger) on or near the touchscreen display.

[0135] Network adapter 78 can also be coupled to the processing system, enabling it to be coupled to other systems, computer systems, remote network devices, and / or remote storage devices via an intermediate private or public network. The network adapter may include a data receiver for receiving data transmitted to the processing system 70 from the systems, devices, and / or networks, and a data transmitter for transmitting data from the processing system 70 to the systems, devices, and / or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapters that can be used with the processing system 70.

[0136] like Figure 7 As illustrated, memory element 72 can store application 79. In various embodiments, application 79 can be stored in local memory 74, one or more mass storage devices 75, or stored separately from local memory and mass storage devices. It should be understood that processing system 70 can further execute an operating system that can facilitate the execution of application 79. Figure 7 (Not shown in the document). The application 79, implemented as executable program code, can be executed by the processing system 70 (e.g., by the processor 71). In response to executing the application, the processing system 70 can be configured to perform one or more operational or method steps described herein.

[0137] In one aspect of the invention, one or more components of a base station selection support system as disclosed herein and / or user equipment for use with such a base station selection support system may represent a processing system 70 as described herein.

[0138] Various embodiments of the present invention can be implemented as a program product for use with a computer system, wherein one or more programs of the program product define the functionality of the embodiments (including the methods described herein). In one embodiment, one or more programs may be contained on a variety of non-transitory computer-readable storage media, wherein, as used herein, the expression “non-transitory computer-readable storage media” includes all computer-readable media, with the sole exception of transient propagation signals. In another embodiment, one or more programs may be contained on a variety of transient computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media (e.g., read-only memory devices within a computer, such as CD-ROM discs readable by a CD-ROM drive, ROM chips, or any type of solid-state non-volatile semiconductor memory) permanently storing information thereon; and (ii) writable storage media (e.g., floppy disks within a flash memory, disk drive, or hard disk drive, or any type of solid-state random access semiconductor memory) storing changeable information thereon. The computer program may run on the processor 71 described herein.

[0139] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” are intended to include the plural forms as well. It will be further understood that, when used in this specification, the terms “comprises” and / or “comprising” specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0140] All components or steps plus functional elements in the following claims are intended to include any structure, material, action, and equivalent for performing the function in conjunction with other claimed elements of the specific claim. The description of embodiments of the invention is presented for illustrative purposes and is not intended to be exhaustive or limited to implementations of the disclosed forms. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the claims. The embodiments were chosen and described to best explain the principles of the invention and some practical applications, and to enable others skilled in the art to understand that various embodiments of the invention with various modifications are suitable for the particular intended use.

Claims

1. A system configured for communication with a plurality of environmental Internet of Things (IoT) devices, wherein the system is configured to Receive a first wireless transmission from an environmental IoT device, the first wireless transmission including a first device identifier and a first authentication token; Determine a second authentication token for the IoT device in the environment; The first device identifier used in the IoT device of the environment is invalid; Receive the second wireless transmission from the environmental IoT device; Determine a second device identifier for the IoT device in the environment; The association between the second authentication token and the second device identifier is stored as the current association for the IoT device in the environment; The association between the second authentication token and the first identifier is stored as a past association for the IoT device in the environment; If the second wireless transmission contains the second device identifier and the second authentication token according to the currently associated second wireless transmission, then the second wireless transmission is authenticated. If the second wireless transmission contains the first device identifier and the second authentication token associated with the past, then the second wireless transmission is authenticated.

2. The system according to claim 1, wherein, The system is further configured to transmit the second device identifier to the environmental IoT device after determining the second device identifier.

3. The system according to claim 1 or 2, wherein, The system is further configured to transmit the second authentication token to the environmental IoT device.

4. The system according to one or more of the preceding claims, wherein, The system is further configured as follows: Assign the first device identifier to the second environment IoT device and store the association of the additional authentication token with the first device identifier as the current association for the second environment IoT device; Receive third-party wireless transmissions from environmental IoT devices; If the second wireless transmission contains the first device identifier and the additional authentication token currently associated with the second environment IoT device, then the third wireless transmission is authenticated as a transmission from the second environment IoT device.

5. The system according to one or more of the preceding claims, wherein, The system is further configured to perform at least one of the following operations: Obtain an applicable cryptographic key for the device identifier and associated authentication token; For example, when transmitting to the IoT device in the environment, an applicable encryption key is used to encrypt at least the second device identifier and optionally a portion of the second authentication token; Obtain updated encryption keys for the device identifier and associated authentication token; as well as Receives wireless transmissions from an environmental IoT device having data portions encrypted using an encryption key, and forwards the encrypted data in the wireless transmissions to a data collection entity.

6. The system according to one or more of the preceding claims, wherein, The network system is further configured to transmit at least one of the following to the environmental IoT device. This enables the environmental IoT device to provide or update random numbers for applicable encryption keys; This enables the environmental IoT device to provide or update a key index for which applicable encryption keys can be applied; and An updated, applicable encryption key encrypted using the previously provided encryption key.

7. The system according to one or more of the preceding claims, wherein, The system is configured to send an identifier revocation message to the environmental IoT device to announce the revocation of the first identifier.

8. The system according to one or more of the preceding claims, wherein, The system is configured to trigger wireless transmissions configured to incentivize the environmental IoT device, wherein the wireless transmissions optionally include at least one of the second device identifier claimed in claim 2, the second authentication token claimed in claim 3, and the identifier revocation message claimed in claim 6.

9. An environmental IoT device configured for use with a system according to one or more of the preceding claims, wherein the environmental IoT device is configured to Perform a first wireless transmission that includes at least a first device identifier and a first authentication token; Generate a second authentication token or receive a second authentication token from the system. Perform a second wireless transmission including the first device identifier and the second authentication token; In response to the second wireless transmission, a second device identifier is received from the system; as well as Perform a third wireless transmission that includes at least the second device identifier and the second authentication token or the third authentication token.

10. The environmental IoT device according to claim 9, wherein, The environmental IoT device is configured to generate the third authentication token or receive the third authentication token together with the second device identifier.

11. The environmental IoT device according to claim 9 or 10, wherein, The device further includes at least one encryption key, and the environmental IoT device is configured to The second device identifier and optionally the second authentication token or the third authentication token are received at least partially in encrypted form; as well as The encryption key is used to at least decrypt the second device identifier and, optionally, the portion of the second authentication token or the third authentication token.

12. The environmental IoT device according to one or more of claims 9-11, wherein, The environmental IoT device is configured to obtain an applicable encryption key through the following operations. The system receives a random number and inputs the random number into a key generation algorithm to derive the encryption key. Receive a key index from the system to select an applicable encryption key from a set of encryption keys stored in the IoT device of the environment and retrieved via the key index; or Use the previously stored encryption key to decrypt the applicable encryption key received from the system.

13. The environmental IoT device according to one or more of claims 9-12, wherein, The environmental IoT device is further configured to transmit data, such as sensor data, in at least one of the first, second, and third wireless transmissions, and optionally, the device further includes an applicable encryption key to encrypt the data.

14. The environmental IoT device according to one or more of claims 9 to 13, wherein, The environmental IoT device is configured to receive one or more identifier revocation messages, and the device is configured to stop performing wireless transmissions to the system in response to receiving the one or more identifier revocation messages.

15. An environmental IoT device according to one or more of claims 9-14, wherein, The environmental IoT device includes an energy harvesting section, wherein optionally, the energy harvesting section is configured to harvest energy from a wireless transmission from the system to perform a wireless transmission to the network.

16. An environmental IoT device according to one or more of claims 9-15, wherein, The environmental IoT device is configured to perform at least one of the following operations: Send an acknowledgment signal to the system to confirm receipt of the second device identifier, and The system receives an acknowledgment signal to confirm the reception of the first and / or second wireless transmission, wherein the environmental IoT device is optionally configured to use the received acknowledgment signal for at least one of the following operations. Trigger the calculation of the authentication token; Avoid resending data; and Stimulate the environmental IoT device.