Wireless communication method, secure data processing method, AIOT device identifier and related device

By using EPC URI as the identifier for environmental IoT devices, defining the NAI format for SUPI, and combining public-key cryptography and symmetric key mechanisms, the identification and data protection issues of battery-free environmental IoT devices in 5G systems are solved, enabling seamless operation and secure connection of the devices.

CN121729910APending Publication Date: 2026-03-24GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380101382.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-08-16
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing 5G systems lack unique identifiers for IoT devices in environments without batteries or with limited energy storage, and traditional security mechanisms such as USIM smart cards cannot be integrated into these devices, leading to difficulties in data protection and device identification.

Method used

It adopts the Electronic Product Code (EPC) Uniform Resource Identifier (URI) as the identifier for environmental IoT devices, formulates the Network Access Identifier (NAI) format of Subscription Permanent Identifier (SUPI), and uses public key cryptography and symmetric key mechanisms to protect data, providing an identification and security solution compatible with 5G systems.

Benefits of technology

It enables seamless operation and data protection of IoT devices in battery-free environments within 5G systems, and provides a cost-effective identifier solution to ensure the uniqueness and security of devices in 5G systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121729910A_ABST
    Figure CN121729910A_ABST
Patent Text Reader

Abstract

A wireless communication method includes: acquiring an electronic product code (EPC) uniform resource identifier (URI) from an environmental Internet of Things (IoT) device; and formulating a network access identifier (NAI) format subscribing to a permanent identifier (SUPI) based on the acquired EPC URI.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to wireless communication, and more specifically, to wireless communication methods, secure data processing methods, environmental Internet of Things (IoT) device identifiers and related devices. Background Technology

[0002] Communication systems and networks have evolved towards broadband and mobile systems. In cellular wireless communication systems developed under the Third Generation Partnership Project (3GPP), user equipment (UE) connects to the radio access network (RAN) via a radio link. The RAN comprises a set of base stations (BS) and an interface to the core network (CN). This set of base stations provides radio links to UEs located in cells covered by the base stations, and this interface provides overall network control. It will be understood that the RAN and CN each perform corresponding functions relevant to the entire network. 3GPP has developed so-called Long Term Evolution (LTE) systems, namely the Evolved Universal Mobile Telecommunication System Territorial Radio Access Network (E-UTRAN), for mobile access networks where one or more macro cells are supported by base stations called evolved NodeBs (eNodeBs or eNBs). So-called 5G or New Radio (NR) systems evolve from LTE, in which one or more cells are supported by base stations called gNBs.

[0003] The 5G NR standard supports a variety of different services, each with very different requirements. These services include Enhanced Mobile Broadband (eMBB) for high data rate transmission, Ultra-Reliable Low Latency Communication (URLLC) for devices requiring low latency and high link reliability, and Massive Machine-Type Communication (mMTC), which is used to support a large number of low-power devices that require long-running, energy-efficient communication.

[0004] The Internet of Things (IoT) has driven a global connectivity revolution, connecting billions of devices to the internet. Cellular IoT technologies such as LTE-M and NB-IoT have played a significant role in helping various industries address their most pressing challenges. However, battery-powered IoT devices can present several practical limitations. These limitations include deployment in remote or hard-to-reach locations where frequent battery repairs are logistically difficult or expensive; and large-scale IoT implementations where managing battery replacements would be impractical. Similarly, embedding devices within structures, machinery, or even the human body can make battery replacement overly complex or dangerous. Long-term deployments requiring years of unattended operation also present challenges for battery-powered devices. Furthermore, safety-related regulatory restrictions in certain environments or sectors may limit battery use. The environmental impact of large-scale battery manufacturing, replacement, and disposal is also a major concern. By 2025, an estimated 78 million batteries will be discarded globally every day. To address these challenges, advancements in IoT technology have incorporated environmental energy harvesting, a method of extracting energy from the environment, thus avoiding the need for batteries.

[0005] The emergence of Ambient-powered IoT (AIoT) technology promises to unlock new services and use cases for devices that cannot be replaced with batteries. These include personalized healthcare, smart transportation, industrial applications in hazardous locations, smart logistics, smart warehousing, smart homes, and smart cities. AIoT services are characterized by their ability to support the widespread deployment of low-cost, ultra-low-complexity, and feature-limited devices that require only a small amount of infrequent data transmission and do not require batteries.

[0006] For example, 5G AIoT services are cellular IoT communication systems in which AIoT devices use harvested energy to generate radio frequency (RF) signals for bidirectional information transmission over 5G systems. 5G AIoT systems are designed to meet the needs of IoT devices in the environment, which may or may not have energy storage capabilities, as defined in 3GPP specification TR 22.840.

[0007] Meanwhile, the 3GPP RAN plenary meeting approved the Rel-18 research project on environmental IoT. TR 38.848 covers several aspects including deployment scenarios, use cases, and services related to the RAN working group. It defines four connectivity topologies for environmental IoT networks and devices, where environmental IoT devices can receive carrier waveforms from one or more other nodes inside or outside the topology. The work assumptions in the study also presuppose that the complexity of Type A devices is comparable to UHF RFID ISO18000-6C (EPCC1G2), while the complexity target for Type C devices is higher, but several orders of magnitude lower than NB-IoT. However, the complexity of Type B devices should fall between that of Type A and Type C devices.

[0008] Recently, at the 3GPP Rel-19 workshop, 5G environmental IoT was identified as a Rel-19 project to enter the research phase. The identification of environmental IoT devices used in 5G systems will be a key issue requiring further research.

[0009] Current 5G identifiers enable the unique identification and interconnection of various 5G entities and devices. The fundamental identifier in the 5G network architecture is the International Mobile Subscriber Identity (IMSI). The IMSI serves as a globally unique identifier for individual mobile users and is used for authentication and authorization of network access. It allows 5G systems to associate specific services and policies with specific users, ensuring secure and personalized connections.

[0010] Another important identifier in 5G systems is the International Mobile Equipment Identity (IMEI). The IMEI is a unique identifier assigned to each mobile device, including smartphones, tablets, and IoT devices. Using the IMEI, 5G systems can track and manage devices, verify their legitimacy, and support functions such as device blacklisting and stolen device tracking. This helps prevent unauthorized network access and enhances overall security.

[0011] In addition, current 5G systems employ a range of other identifiers to facilitate efficient and secure communication, including:

[0012] 5G Globally Unique Temporary Identifier (5G-GUTI): A temporary identifier assigned / reassigned to the UE by the Access and Mobility Management Function (AMF). 3GPP also specifies a mapping between 5G-GUTI and 4G-GUTI, which is necessary for UE movement between 4G and 5G networks.

[0013] Globally Unique AMF Identifier (GUAMI): An identifier used to uniquely identify AMF entities within the core network in a 5G system. GUAMI consists of a globally unique Mobile Country Code (MCC) and Mobile Network Code (MNC) pair, along with the AMF area ID. GUAMI is crucial for routing and management signaling between the RAN and core network.

[0014] Subscription Permanent Identifier (SUPI): Uniquely identifies a user profile within a network, enabling seamless service continuity and personalized connectivity across different access networks or devices. SUPI is used for authentication, authorization, and user-specific service delivery.

[0015] Subscription Concealed Identifier (SUCI): A temporary identifier used for authentication and authorization purposes in 5G systems. SUCI is derived from SUPI but encrypted to protect user privacy. SUCI allows secure communication between devices and networks without revealing the actual SUPI, thus enhancing privacy and security.

[0016] 5G Temporary Mobile Subscriber Identity (TMSI): A temporary identifier assigned by the network to a mobile device to protect the device's identity during normal operation. 5G-S-TMSI is a shortened version of 5G-GUTI, designed to improve the efficiency of radio signaling procedures such as paging and service requests. 5G-S-TMSI includes the AMF Set ID, AMF Pointer, and 5G-TMSI.

[0017] In addition to these identifiers, 5G systems also include various RAN identifiers, such as the Cell Global Identifier (CGI), Tracking Area Identifier (TAI), and Temporary Mobile Group Identity (TMGI). These identifiers are used in the RAN to manage and track specific cells, coverage areas, and equipment groups, thereby enabling efficient radio resource allocation and mobility management in 5G networks.

[0018] In summary, environmental IoT devices (also known as environmentally enabled IoT devices) are IoT devices powered by energy harvesting. Environmental IoT devices either have no batteries or limited energy storage capacity (e.g., using capacitors). They represent a new class of battery-free devices with limited energy storage capacity that complement existing cellular IoT services. They are characterized by low cost, high density, large deployment volume, extremely low complexity, limited device functionality, and the need for only a small amount of infrequent data transmission.

[0019] For example, to accommodate these new battery-free devices in 5G systems, unique identifiers must be provided for 5G-enabled IoT devices to ensure their seamless operation within 5G systems. However, current 3GPP specifications have not yet defined the identifier structure, format, usage, and operation for these types of devices. Therefore, there is an urgent need to provide unique identifiers for environmental IoT devices.

[0020] In various scenarios, such as personal health, location tracking, and real-time information about critical industrial applications, additional protection may be needed for sensitive data stored on AIoT devices. Traditionally, Universal Integrated Circuit Cards (UICCs) or Universal Subscriber Identity Modules (USIMs) are used to securely store keys on mobile devices. However, leveraging existing UICC or USIM-based security mechanisms in 5G presents challenges for environmental IoT devices. Therefore, there is an urgent need to provide environmental IoT devices with such unique identifiers, or a new identification mechanism, which could effectively address data protection issues, especially when these devices lack UICCs, USIM applications, or IMSIs. Summary of the Invention

[0021] In a first aspect, embodiments of this application provide a wireless communication method, the method comprising: obtaining an Electronic Product Code (EPC) Uniform Resource Identifier (URI) from an Internet of Things (IoT) device; and formulating a Network Access Identifier (NAI) format for a Subscription Permanent Identifier (SUPI) based on the obtained EPC URI.

[0022] In a second aspect, embodiments of this application provide a secure data processing method, the method comprising: receiving user data encrypted using a public key associated with an AIoT service provider from an Ambient Internet of Things (IoT) tag; and decrypting the encrypted user data using a private key associated with the AIoT service provider to obtain decrypted user data of the Ambient IoT tag.

[0023] In a third aspect, embodiments of this application provide a secure data processing method, the method comprising: exchanging a shared symmetric key with an environmental Internet of Things (IoT) tag using public-key cryptography; receiving user data encrypted using the shared symmetric key from the environmental IoT tag; and decrypting the encrypted user data using the shared symmetric key to obtain the decrypted user data of the environmental IoT tag.

[0024] In a fourth aspect, embodiments of this application provide an environmental Internet of Things (IoT) device that includes a memory for storing Electronic Product Code (EPC) Uniform Resource Identifiers (URIs).

[0025] In a fifth aspect, embodiments of this application provide an environmental Internet of Things (IoT) device identifier, which includes a Subscription Permanent Identifier (SUPI) having a Network Access Identifier (NAI) format, wherein the NAI of the SUPI includes a username portion and a domain portion, and the username portion corresponds to the Electronic Product Code (EPC) Uniform Resource Identifier (URI) of the environmental IoT device.

[0026] In a sixth aspect, embodiments of this application provide a communication device including a memory and a processor, wherein the processor is configured to call and execute program instructions stored in the memory to perform the methods of any of the foregoing aspects.

[0027] In a seventh aspect, embodiments of this application provide a non-transitory computer-readable storage medium configured to store a computer program that enables a computer to perform the methods of any of the foregoing aspects.

[0028] In an eighth aspect, embodiments of this application provide a computer-readable storage medium for storing a computer program that enables a computer to perform the methods of any of the foregoing aspects.

[0029] In a ninth aspect, embodiments of this application provide a computer program product comprising computer program instructions that enable a computer to perform the methods of any of the foregoing aspects.

[0030] In a tenth aspect, embodiments of this application provide a computer program that, when run on a computer, enables the computer to perform the methods of any of the foregoing aspects. Attached Figure Description

[0031] To more clearly illustrate the embodiments or related technologies of this application, the accompanying drawings described in the embodiments are briefly introduced below. Obviously, the drawings are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without incurring any cost.

[0032] Figure 1 This is a block diagram illustrating a communication device and an AIoT device in a communication network system according to an embodiment of the present invention.

[0033] Figure 2 This is a flowchart of a wireless communication method according to an embodiment of the present invention.

[0034] Figure 3 This is a schematic diagram illustrating a 5G environment IoT system architecture according to some embodiments of the present invention.

[0035] Figure 4 This is a schematic diagram illustrating the SUCI format of an environmental IoT SUPI according to some embodiments of the present invention.

[0036] Figure 5 This is a schematic diagram illustrating the generation of an AIoT tag with a plain identity EPC URI having a digital signature, according to some embodiments of the present invention.

[0037] Figure 6 This is a flowchart illustrating authentication using digital signatures according to some embodiments of the present invention.

[0038] Figure 7 This is a schematic diagram illustrating an AIoT device with an X.509 certificate according to some embodiments of the present invention.

[0039] Figure 8 This is a flowchart illustrating the use of public keys to enhance data protection according to some embodiments of the present invention.

[0040] Figure 9 This is a schematic diagram illustrating a system architecture for enhancing data protection using symmetric keys according to some embodiments of the present invention.

[0041] Figure 10 This is a flowchart illustrating the use of symmetric keys to enhance data protection according to some embodiments of the present invention. Detailed Implementation

[0042] The embodiments, technical content, structural features, achieved objectives, and effects of this disclosure will be described in detail below with reference to the accompanying drawings. Specifically, the terminology used in the embodiments of this application is only for describing specific embodiments and is not intended to limit this disclosure.

[0043] In this application, combinations such as "at least one of A, B or C", "one or more of A, B or C", "at least one of A, B and C", "one or more of A, B and C" or "A, B and / or C" can be only A, only B, only C, A and B, A and C, B and C or A and B and C, wherein any combination can include one or more members of A, B or C.

[0044] In this application, AIoT stands for Ambient IoT Device, which is defined as follows: An environmental energy-enabled IoT device is an IoT device powered by energy harvesting, without a battery or with limited energy storage capacity (e.g., using a capacitor); ASP stands for Ambient IoT Service Provider, which is defined as follows: A party that provides AIoT services, device management, lifecycle support and / or data management services.

[0045] Environmental IoT devices have very limited capabilities and functionality. According to TR 38.848, the complexity of Type A environmental IoT devices is comparable to UHF RFID ISO18000-6C (EPC C1G2), while Type C devices have a higher complexity target, but are several orders of magnitude lower than NB-IoT. The complexity of Type B devices should fall between that of Type A and Type B devices.

[0046] Traditionally, USIM smart cards have been used to securely store keys on mobile devices, which are larger and have fewer cost constraints compared to environmental IoT devices. Environmental IoT devices target costs between 3 cents and $3, a stark contrast to the approximately $1,000 cost of mobile devices. Given the inherent size and cost limitations of environmental IoT devices, integration with USIM smart cards is simply not feasible. These limitations necessitate more cost-effective and compact alternatives for environmental IoT device identification.

[0047] Electronic Product Codes (EPCs) have been used as unique identifiers for product tracking within the supply chain. An EPC serves as a means of uniquely identifying a specific product, containing relevant details about its manufacturer, product category, and associated attributes. EPC technology is widely used across various industries such as retail, logistics, and healthcare, primarily to optimize inventory management, reduce waste, and improve supply chain visibility.

[0048] The GS1 Tag Data Standard (TDS) represents a fundamental framework that defines the Electronic Product Code (EPC) and the corresponding specifications associated with the data carried by the RAIN RFID tag encoded with the EPC. This includes comprehensive details covering the EPC itself, user memory data, control information, and tag manufacturing information. Notably, TDS 2.0 introduces over 30 encoding schemes and 13 encoding methods for EPCs. Furthermore, TDS 2.0 expands support for increased EPC code lengths to accommodate EPC repository sizes (up to 496 bits), covering various EPC schemes such as SGTIN+ and CPI+. Importantly, TDS 2.0 ensures seamless backward compatibility with previous versions, preserving the validity of all EPC schemes established in earlier TDS iterations.

[0049] However, it is important to note that, for example, in the 5G system domain, EPC encoding devices currently lack the compatibility required to serve as viable identifiers. Therefore, current 5G systems do not provide support for EPC encoding devices within their operational framework.

[0050] In summary, IoT devices in environments with limited device capabilities require cost-effective and compact identification solutions, as these devices cannot practically integrate the USIM smart cards used in larger, more expensive mobile devices. The price of these devices is expected to be between 3 cents and $3, significantly lower than the average cost of mobile devices.

[0051] Electronic Product Codes (EPCs) are traditionally used as unique product identifiers throughout the supply chain. EPCs are defined in the GS1 EPC Tag Data Standard (TDS). The TDS includes detailed information related to the EPC, user memory data, control information, and tag manufacturing information. The updated TDS 2.0 introduces multiple encoding schemes and methods and supports increased EPC code lengths. The updated TDS 2.0 also maintains backward compatibility with previous versions.

[0052] However, although EPC is widely used in many industries such as retail and logistics, current EPC coding equipment is incompatible with 5G systems, which do not support EPC coding equipment in their framework.

[0053] This invention makes the following improvements to environmental IoT devices.

[0054] - For example, providing device identifiers compatible with 5G systems enables IoT devices in battery-free and USIM-free environments to operate seamlessly within 5G systems.

[0055] - For example, the environmental IoT device identifier conforms to the Electronic Product Code (EPC) defined in the TDS 2.0 standard.

[0056] - Plain identity EPC URIs are used as part of the environmental IoT device identifier.

[0057] - The plain identity EPC URI is used as the username in the NAI format of the SUPI as an identifier for the environment IoT device.

[0058] - For example, a method is provided to use device identifiers to develop SUPI and SUCI that are compatible with the identification formats currently used in 5G systems.

[0059] - Several digital signature-based mechanisms are provided to facilitate the authentication of IoT devices in USIM-less environments.

[0060] - Provides a variety of public-key-based encryption mechanisms designed to protect sensitive data on IoT devices in the environment.

[0061] - Provides several hybrid encryption-based mechanisms designed to protect sensitive data on IoT devices in the environment.

[0062] Figure 1 In some embodiments, a communication device 10 and an environmental IoT device 20 for wireless communication in a communication network system according to embodiments of the present invention are shown. (Reference) Figure 1The communication device 10 and the environmental IoT device 20 communicate wirelessly with each other. The communication device 10 and the environmental IoT device 20 perform embodiments of the method according to the invention. The communication device 10 may be a user equipment (UE), customer premises equipment (CPE), base station (BS), or RAN node. The communication device 10 includes a transceiver 12 and a processor 14, which are electrically connected to each other. The transceiver 12 of the communication device 10 is configured to send signals to (and receive signals from) the environmental IoT device 20, and the processor 14 of the communication device 10 processes the signals. Thus, the communication device 10 and the environmental IoT device 20 communicate with each other. At least the processor 14 of the communication device 10 may be configured to implement the functions, processes, and / or methods described herein. The environmental IoT device 20 may include a memory or tag 22 for storing various information, such as identification information, security keys, or user data (sensitive or non-sensitive). The environmental IoT device 20 can be a type A, type B, or type C environmental IoT device as defined in TR 38.848. The communication device 10 can read any signal, information, or data from the environmental IoT device 20, or write it to the environmental IoT device 20.

[0063] Processor 14 may include a general-purpose central processing unit (CPU), an application-specific integrated circuit (ASIC), other chipsets, logic circuits, and / or data processing devices. Communication devices may also include memory (not shown), which may include read-only memory (ROM), random access memory (RAM), flash memory, memory cards, storage media, other storage devices, and / or any combination of memory and storage devices. Transceiver 12 may include baseband circuitry and radio frequency (RF) circuitry to process radio frequency signals. When embodiments are implemented in software, the techniques described herein can be implemented using modules, procedures, functions, and entities that perform the functions described herein. These modules may be stored in memory and executed by the processor. Memory may be implemented within or outside the processor; when memory is implemented outside the processor, it may be communicatively coupled to the processor in various ways known in the art.

[0064] Figure 2 A flowchart of a wireless communication method according to an embodiment of the present invention is shown. See also Figure 2The present invention provides a wireless communication method, the method comprising: obtaining an Electronic Product Code (EPC) Uniform Resource Identifier (URI) from an environmental Internet of Things (IoT) device; and formulating a Network Access Identifier (NAI) format for a Subscription Permanent Identifier (SUPI) based on the obtained EPC URI.

[0065] Optionally, SUPI's NAI follows a first format, which consists of a username portion and a domain portion, whereby the username portion represents a user identifier or device identifier, and the domain portion specifies the authentication scope or authentication domain to which the request is directed.

[0066] Optionally, the username portion corresponds to the EPC URI, while the domain portion identifies the operator that has the subscription.

[0067] Optionally, the username portion may include, in addition to the EPC URI, several components corresponding to other information, which are separated by specific characters.

[0068] Optionally, the domain portion includes the Environmental IoT Service Provider (ASP) ID, and the Environmental IoT Service Provider ID is a globally unique ID whether it is combined with the Public Land Mobile Network (PLMN) ID or independent of the PLMN ID.

[0069] Alternatively, the domain portion is constructed by adding the tags "aiot" and ASP before the network domain name.

[0070] Optionally, SUPI is designed to support environmental IoT service requests, or to allow specific applications to define filtering rules for a set of environmental IoT devices.

[0071] Optionally, when deriving the User Hidden Identifier (SUCI) from SUPI, the Network Specific Identifier (NSI) is used as the SUPI type, or a special type for the environment's IoT device is adopted.

[0072] Optionally, the environmental IoT device has a Subscriber Identity Module (SIM) or a variant thereof embedded in the environmental IoT device.

[0073] Optionally, the method further includes: obtaining a digital signature of the EPC URI from an environmental IoT device; decrypting the digital signature using the public key of the environmental IoT device to obtain a first hash value of the EPC URI; using a hash function to create a second hash value based on the obtained EPC URI; and verifying that the obtained EPC URI has not been altered if the second hash value matches the first hash value.

[0074] Optionally, the method further includes: if the EPC URI is successfully verified, retrieving user data from the environmental IoT device, or retrieving user data associated with the EPC URI from a local database or an AIoT service provider database.

[0075] Optionally, the public key may be received from one of the following: a certificate issued by a Certificate Authority (CA); a SIM installed on an IoT device in the environment; and the associated AIoT network element.

[0076] Optionally, the method further includes: generating a number and encrypting the number using the public key of the environmental IoT device; sending the encrypted number to the environmental IoT device; receiving a decrypted number from the environmental IoT device, the decrypted number being decrypted using the private key of the environmental IoT device; and verifying whether the number is the same as the received decrypted number from the environmental IoT device.

[0077] Optionally, the method further includes: sending a number to an environmental IoT device; receiving a digital signature of the number from the environmental IoT device; and decrypting the digital signature of the number using the public key of the environmental IoT device to confirm whether the number was originally sent to the environmental IoT device.

[0078] Optionally, the certificate is embedded in the environmental IoT device.

[0079] Alternatively, the EPC URI can be obtained from a certificate embedded in the IoT device in the environment.

[0080] Optionally, the certificate embedded in the environmental IoT device may also include the public key of the environmental IoT device or the AIoT service provider.

[0081] Optionally, the certificates embedded in environmental IoT devices are issued by cellular network operators or AIoT service providers.

[0082] Optionally, the method further includes: employing a verification algorithm to verify the digital signature associated with the certificate embedded in the IoT device in the environment; and once the verification is successful, continuing the registration and connection process with the cellular network.

[0083] The present invention also provides a communication device, which includes a memory and a processor, wherein the processor is used to call and run program instructions stored in the memory to perform the above-described method.

[0084] The present invention also provides a non-transitory computer-readable storage medium configured to store a computer program that causes a computer to perform the above-described method.

[0085] The present invention also provides a secure data processing method, the method comprising: receiving user data encrypted using a public key associated with an AIoT service provider from an Ambient Internet of Things (IoT) tag; and decrypting the encrypted user data using a private key associated with the AIoT service provider to obtain decrypted user data of the Ambient IoT tag.

[0086] Optionally, the public key associated with the AIoT service provider comes from a certificate issued by a cellular network operator or from a self-signed certificate of the AIoT service provider.

[0087] Optionally, the method further includes: encrypting specific information using a public key associated with the environmental IoT tag; and transmitting the encrypted specific information to the environmental IoT tag so that the environmental IoT tag decrypts the encrypted specific information using a private key associated with the environmental IoT tag.

[0088] Optionally, the public key associated with the environmental IoT tag is retrieved from the AIoT network operator certification authority (CA) or the AIoT service provider's CA.

[0089] Optionally, the Electronic Product Code (EPC) Uniform Resource Identifier (URI) of the environmental IoT tag is used as an index for retrieving the public key associated with the environmental IoT tag.

[0090] Optionally, the private key associated with the environmental IoT tag is stored in the tamper-proof secure space of the environmental IoT tag.

[0091] The present invention also provides a secure data processing method, the method comprising: exchanging a shared symmetric key with an environmental Internet of Things (IoT) tag using public-key cryptography; receiving user data from the environmental IoT tag encrypted using the shared symmetric key; and decrypting the encrypted user data using the shared symmetric key to obtain the decrypted user data of the environmental IoT tag.

[0092] Optionally, the method further includes: encrypting specific information using a shared symmetric key; and transmitting the encrypted specific information to an environmental IoT tag so that the environmental IoT tag can decrypt the encrypted specific information using the shared symmetric key.

[0093] Optionally, a shared symmetric key is used for symmetric cryptography, including Rivest cipher 4 (RC4), RC5, RC6, Blowfish, Twofish, Data Encryption Standard (DES), Triple DES, or Advanced Encryption Standard (AES).

[0094] Optionally, a key exchange protocol is used when exchanging shared symmetric keys.

[0095] Optionally, the key exchange protocol includes Diffie-Hellman.

[0096] The present invention also provides an environmental Internet of Things (IoT) device, which includes a memory for storing Electronic Product Code (EPC) Uniform Resource Identifiers (URIs).

[0097] Optionally, the environmental IoT device has a user identity module (SIM) or a variant of the SIM embedded in the environmental IoT device.

[0098] Optionally, the memory also stores the digital signature of the EPC URI.

[0099] Optionally, the memory may also store user data.

[0100] Optionally, the memory also stores the certificate.

[0101] Optionally, the certificate includes an EPC URI.

[0102] Optionally, the certificate may include an X.509 certificate, an X.509 certificate extension, an attribute certificate, a CardVerifiable (CV) certificate, a Pretty Good Privacy (PGP) certificate, a WAP certificate, a Simple Public Key Infrastructure (SPKI) certificate, or a traceable anonymous certificate.

[0103] The present invention also provides an environmental Internet of Things (IoT) device identifier, which includes a Subscription Persistent Identifier (SUPI) in the format of a Network Access Identifier (NAI), wherein the NAI of the SUPI includes a username portion and a domain portion, and the username portion corresponds to the Electronic Product Code (EPC) Uniform Resource Identifier (URI) of the environmental IoT device.

[0104] Optionally, the username portion represents a user identifier or device identifier, while the domain portion specifies the authentication scope or authentication domain to which the request is directed.

[0105] Optionally, the domain portion identifies the operator that has the subscription.

[0106] Optionally, the username portion may include, in addition to the EPC URI, several components corresponding to other information, which are separated by specific characters.

[0107] Optionally, the domain portion includes the Environmental IoT Service Provider (ASP) ID, and the Environmental IoT Service Provider ID is a globally unique ID whether combined with the Public Land Mobile Network (PLMN) ID or independent of the PLMN ID.

[0108] Optionally, the domain portion is constructed by adding the tags "aiot" and "ASP" before the network domain name.

[0109] Optionally, SUPI is designed to support environmental IoT service requests, or to allow specific applications to define filtering rules for a set of environmental IoT devices.

[0110] Further details about the invention are provided below.

[0111] 1. Environmental IoT Identifier

[0112] like Figure 3 As shown, this method involves using a suitable reader protocol installed in a user equipment (UE), client equipment (CPE), base station (BS), or RAN node to obtain or capture an EPC URI from an environmental IoT device via a Ua interface. The reader located on the RAN, UE, or other 5G network element formulates a Network Access Identifier (NAI) format for a Subscription Persistent Identifier (SUPI) based on the obtained EPC URI.

[0113] An AIoT service provider is an entity responsible for: AIoT service deployment, AIoT device management, lifecycle support, data management services, energy management, and the billing, invoicing, and security aspects of AIoT services. Servers or data centers maintained by the AIoT service provider store data or information linked to a plain identity EPC URI.

[0114] This invention discloses a method for obtaining an environment IoT device identifier compatible with 5G systems, for example, by using the EPC "plain identity URI" defined in TDS 2.0.

[0115] EPC "Plain Identity URI" is a standardized Uniform Resource Identifier (URI) that serves as a unique identifier for a specific product or item within the EPC global network. It follows this format:

[0116] urn:epc:id:scheme:component1.component2...

[0117] Here, "scheme" represents the EPC scheme, and "component1", "component2" and subsequent parts represent the specific elements of the EPC scheme in use. TDS 2.0 provides detailed format specifications.

[0118] SUPI's NAI follows a first format. For example, the first format can be the username@realm format described in Section 2.2 of IETF RFC 7542. It consists of two parts: a username part and a domain part, separated by the "@" symbol. The username part represents the user identifier or device identifier, and the domain part specifies the authentication scope or authentication domain to which the request is directed.

[0119] NAI's username section allows a variety of characters, including alphanumeric characters and special characters (such as dots, dashes, and underscores). It may also include internationalized characters encoded in UTF-8, thus allowing for multilingual usernames.

[0120] The domain portion of NAI is a string used to identify the authentication domain. It can take the form of a fully qualified domain name (FQDN) or a domain-specific string. The format and interpretation of the domain portion may vary depending on the specific deployment and current administrative policies.

[0121] In SUPI's NAI, the username portion corresponds to the EPC URI, while the domain portion identifies the operator that has the subscription.

[0122] If the operator possesses a Public Land Mobile Network (PLMN) ID, the domain structure is "5gc.asp <asp>.mnc <mnc>.mcc <mcc>.3gppnetwork.org". For example, if the Environmental IoT Service Provider (ASP) ID is "009", PLMNID is MNC 012 and MCC 345, then the domain part will be

[0123] 5gc.asp009.mnc012.mcc345.3gppnetwork.org.

[0124] When used in SUPI, the colon (:) in the original plain identity EPC URI in the username part of SUPI should be converted to a UTF-8 compatible character, such as '-', '_', or simply a dot (.).

[0125] Therefore, SUPI's NAI will be:

[0126] urn-epc-id-sgtin-9521141.012345.4711@5gc.asp009.mnc012.mcc345.3gppnetwork.org, or

[0127] urn_epc_id_sgtin_9521141_012345_4711@5gc.asp009.mnc012.mcc345.3gppnetwork.org

[0128] In another embodiment, the username portion may include several components in a dotted string format, i.e.,

[0129] component 1.comone 2.component2…componentN.EPC URI@domain part

[0130] The component_n can be other information, such as the environmental IoT device type (Type A, Type B, and Type C), environmental IoT manufacturing code, etc. For example,

[0131] TypeA.ManufactureA.urn.epc.id.sgtin_9521141.012345.4711@5gc.asp009.mnc012.mcc345.3gppnetwork.org

[0132] The components and EPC URIs can be arranged in various orders, as long as they ensure unique identification within the domain scope, for example,

[0133] urn.epc.id.sgtin.9521141.012345.4711.TypeA.ManufactureA@5gc.asp009.mnc012.mcc345.3gppetwork.org

[0134] ASP allocation can be achieved through collaboration between environmental IoT service providers and 5G service providers, ensuring the global uniqueness of the combination of ASP ID and PLMN ID. The ASP code is embedded in the AIoT tag's certificate to guarantee its authenticity and integrity.

[0135] The AIoT Service Provider ID is assigned by the 5G network operator. When combined with a PLMN, the AIoT Service Provider ID should be a globally unique ID.

[0136] The global uniqueness of the AIoT service provider ID can also be independent of the PLMN ID. In this case, for example, the AIoT service provider ID can be assigned to the management entity by GS1.

[0137] The AIoT Service Provider ID can be designed as a sufficiently long serial number to accommodate as many service providers as possible within the PLMN. For example, the ID can be constructed as an alphanumeric code of up to 16 characters. It can use various numbering systems, such as hexadecimal (including digits 0-9 and letters A-F), decimal (including digits 0-9), or alphanumeric (including digits 0-9 and uppercase and lowercase letters A-Z), or any combination thereof. These formats support a large number of unique identifier assignments, thus accommodating numerous AIoT service providers within the network.

[0138] AIoT service provider IDs can also take the form of human-readable names or aliases.

[0139] In another embodiment, the EPC class URI syntax can be used to address a class of objects that belong to a given batch or lot number of a given Global Trade Item Number (GTIN).

[0140] In another embodiment, when applying the syntax of the EPC pure identity schema, SUPI is designed to support IoT service requests in 5G environments, or to allow specific applications to define filtering rules for a set of IoT devices in an environment. A typical schema URI takes the following form:

[0141] urn:epc:idpat:sgtin:9521141.*.*

[0142] This pattern represents any EPC SGTIN with the GS1 company prefix 9521141, while the project reference and serial number can have any value.

[0143] In another embodiment, to save storage space in the environmental IoT device, the valid encoding of the plain identity EPC URI should be stored in the environmental IoT device.

[0144] In another embodiment, the environment IoT SUPI domain can be constructed by adding the tag "aiot" before the home network domain name (5gc.mnc.mcc.3gppnetwork.org) and one or more ASP tags assigned by the PLMN, as described below:

[0145] <AIoT Service Provider ID> .aiot.5gc.mnc.mcc.3gppnetwork.org

[0146] This format should identify the "diameter" used as an instance of an AIoT network function.

[0147] In addition, in certain situations (e.g., private 5G networks, SNPN or PNI NPN, or in cooperation with operators), the issuing authority may be responsible for issuing SIM cards for devices with AIoT reader functionality.

[0148] When deriving the User Hidden Identifier (SUCI) from the SUPI, the environment IoT device ID SUPI type should use a Network Specific Identifier (NSI), or the environment IoT device's proprietary type can be reserved, such as... Figure 4 As shown.

[0149] On the other hand, for certain IoT devices in certain environments, if they are equipped with a User Identity Module (SIM) or a variant of the SIM, the SIM may be embedded (usually soldered) onto the AIoT tag and cannot be removed. Lightweight security mechanisms may be required. In this case, the IMSI, composed of MCC, NC, and MSIN, will be used to identify the AIoT subscription. And the SUPI type is IMSI.

[0150] In summary, these embodiments of the present invention enable the generation of environmental IoT device identifiers compatible with 5G systems. Secure and efficient communication within the network can be achieved using EPC "plain identity URIs," supporting improved identification and management of environmental IoT devices.

[0151] With the implementation of the 5G-compatible environmental IoT identification scheme, the process begins with the initialization and successful verification of the identification by the environmental IoT device. Subsequently, the registration process commences, where user equipment (UE), client equipment (CPE), base station, or radio access network (RAN) node with AIoT reader functionality generates a Subscription Permanent Identifier (SUPI) based on the EPC Plain Identity URI. The SUPI is then used to register the AIoT device with the 5G User Data Management (UDM) system. It is worth noting that the primary responsibility for connectivity management lies with the UE. Furthermore, the UE should have already registered with the 5G system (5GS) using its SIM, which has been programmed to support AIoT services.

[0152] In addition to registration, UEs can now retrieve information stored on AIoT tags, such as location data, temperature readings, or other relevant parameters. This information is similar to the Additional Carrier Identifier (ACID+) information stored in the user data repository on the RFID tag. To ensure data confidentiality during transmission, the tag may also use the AIoT service provider's private key to encrypt the content.

[0153] In the following sections (particularly Parts 2 and 3), we will detail methods for embedding these identifiers into AIoT tags using digital signatures and X.509-based certificates, respectively. Certain categories of environmental IoT devices / tags (such as Type B and Type C) may have more available repositories. These may store user data, general information, or even sensitive details related to privacy on the environmental IoT devices or tags. Therefore, to address these issues, we further disclose two unique methods for protecting user data on environmental IoT devices / tags in Parts 4 and 5.

[0154] 2. Digital signature of EPC "pure identity URI"

[0155] Digital signatures use public-key cryptography to verify the authenticity and integrity of digital objects. Compared to traditional handwritten signatures, digital signatures offer enhanced security. They typically use cryptographic algorithms to encrypt a unique hash value using the sender's private key to form the digital signature. When the recipient receives the digital signature, they can use the sender's public key to decode it. This allows the recipient to verify the sender's identity and confirm that the transmitted data has not been compromised.

[0156] Generating a digital signature begins by processing the message or data file using an encryption algorithm to produce a unique hash value. This hash function converts the data into a fixed-size byte string. The sender then encrypts this hash value with their private key, thus creating the digital signature. The original message and its encrypted hash value (i.e., the digital signature) are then transmitted to the recipient. The uniqueness of the hash value ensures that even minor changes to the message will result in a significant change in the hash value, while encryption protects the signature from unauthorized modification.

[0157] Upon receiving a digitally signed object, the receiver uses its public key (obtained from the sender's digital certificate) to decrypt the received digital signature. This reveals the original hash value generated by the sender. Simultaneously, the receiver creates a new hash value based on the received message using the same hash function. If the newly created hash matches the original hash, the message has been verified as unaltered and the signature is authentic. This confirms the integrity of the message and verifies the sender's identity, as only the sender's private key can create a signature that can be decrypted using the sender's public key.

[0158] In the context of environmental IoT, such as Figure 5 As shown, during the production process of environmental IoT tags, the pure identity EPC URI of the AIoT device is digitally signed by the 5G AIoT network operator. This digital signature is attached to the EPC "pure identity URI" on the AIoT tag.

[0159] like Figure 3 As further illustrated, devices equipped with AIoT reader functionality (e.g., UEs and CPEs, base stations, IAB nodes, or repeaters) retrieve data from AIoT tags using the Ua interface. To access the data stored on the tag, the reader functionality within the AIoT-compatible network component wirelessly activates the tag circuitry and communicates through its antenna.

[0160] After obtaining or acquiring the digital signature and plain identity EPC URI, the AIoT-enabled reader device or network component decrypts them using a public key. The AIoT reader then recovers the plain identity EPC URI using the same hash function and compares it to the received EPC URI. If a match is found, a trust relationship is established. If not, the AIoT reader ceases further operations. This process is controlled by a protocol running on the AIoT reader, which is protected by the hardware SoC or executed within a Trusted Execution Environment (TEE) in the AIoT reader or managed device.

[0161] In one embodiment, the public key used by the AIoT reader function to decrypt the obtained or acquired digital signature is transmitted to the AIoT reader via a certificate issued by a Certificate Authority (CA).

[0162] In another embodiment, 5G AIoT network operators, who typically set up and configure AIoT-enabled devices, can provide a SIM card installed on the AIoT reader. This allows the 5G AIoT network operator's public key to be pre-programmed into the SIM card during issuance or added via an Over-the-Air (OTA) procedure typically deployed by 5G network operators. The same public key can also be provided in the operator's AIoT-enabled base stations or other relevant AIoT network elements.

[0163] Subsequently, after successfully verifying the plain identity EPC URI signed by the AIoT operator, the UE or AIoT reader function can formulate an FQDN to reach the AIoT service provider's server, thereby retrieving user data associated with the plain identity EPC URI.

[0164] In one embodiment, the AIoT tag does not store any user data other than a plain identity EPC URI. Any data related to a project linked to the AIoT tag will be retrieved from the AIoT service provider's database.

[0165] In another embodiment, the aforementioned database can be a local database. For example, an AIoT service provider might offer an application residing on the UE or other network functions with AIoT reader functionality. This application includes a local database storing all user data linked to the plain identity EPC URI. In this case, the UE does not need to retrieve user data from the AIoT service provider's database.

[0166] In another embodiment, the AIoT application first attempts to retrieve user data from a local database on the UE. If the UE is unable to retrieve the data from the local database built into the UE's AIoT application, the UE may contact the AIoT service provider's server to retrieve the user data information.

[0167] In another embodiment, user data in a local or remote database can be encrypted using public-key encryption, symmetric-key encryption, or a hybrid algorithm. In the case of public-key encryption, to decrypt user data retrieved from the database, the UE must use the private key of the AIoT reader or AIoT application, which can be stored on the SIM card containing the AIoT reader functionality. In this scenario, the application publisher collaborates with the operator to securely store the private key of the AIoT reader or AIoT application on the SIM card, which is protected against unauthorized access, for example, through a password. Further details regarding user data protection will be disclosed in Parts 4 and 5.

[0168] The above solution introduces a "passive authentication" mechanism, in which the AIoT tag does not have any computational capability to perform encryption or decryption, or both. However, some AIoT tags may possess such capabilities.

[0169] In another embodiment, an active authentication process can be implemented. This process employs a unique cryptographic key pair and a challenge-response protocol to provide additional security against cloning attempts. Various versions of this challenge-response protocol may exist.

[0170] Typically, the UE or AIoT reader generates a random number and encrypts it using the AIoT tag's public key (obtained from the certification authority based on the tag's ID). Upon receiving the challenge, the AIoT tag decrypts the random number using its private key and then sends the decrypted number back to the UE or AIoT reader. This operation confirms that the AIoT tag possesses the private key, thereby verifying whether it is the intended communication target of the UE, AIoT reader, or other network element with AIoT reader functionality.

[0171] In another embodiment, the UE or AIoT reader sends a random number in plaintext to the AIoT tag. When the AIoT tag receives this challenge, it signs the random number using its private key and sends the digital signature back to the UE or AIoT reader. Once the digital signature is received, the UE or AIoT reader can verify whether this is the originally sent number, thus confirming that the tag is indeed the intended target of this transaction.

[0172] Figure 6 The call flow for these embodiments is shown.

[0173] 3. Certificates for AIoT tags

[0174] In this embodiment, such as Figure 7 As shown, operator-signed AIoT service provider certificates are securely embedded in the AIoT tags. These certificates can take various forms, including X.509 certificates, X.509 certificate extensions, attribute certificates, card verifiable (CV) certificates, good privacy (PGP) certificates, WAP certificates, simple public key infrastructure (SPKI) certificates, or traceable anonymous certificates. 5G AIoT network operator certification authorities (CAs) typically issue these certificates. However, AIoT service providers may also self-sign these certificates, effectively acting as their own CAs. The authority to issue, revoke, or renew certificates rests entirely with the CA.

[0175] In addition to the standard structure for each certificate type, the certificate should also include specific information such as the application service provider ID or name, the AIoT service provider's public key, and the EPC plain identity URI (which serves as a unique identifier for the AIoT device). Specifically, the certificate should contain the following:

[0176] Certificate information, including version number, certification authority, etc.

[0177] Certificate serial number: A unique serial number assigned by the issuing authority (in this case, the 5G AIoT network operator).

[0178] Certificate issuer: The entity or organization that issues the certificate, typically a trusted Certificate Authority (CA). The certificate contains the issuer's name, organization, and related identifying details. In this context, the certificate issuer is a 5G AIoT network operator.

[0179] Certificate Effective Date: The date on which the certificate is valid.

[0180] Certificate Expiry Date: The end date of the certificate's validity period.

[0181] Subject Identity: The entity or subject that issued the certificate, including the plain identity EPC URI, the name, organization, email address or other identifying details of the AIoT service provider.

[0182] Public key: The subject's public key, representing the public key of the AIoT service provider and the public key of the AIoT tag.

[0183] Digital signature: A digital signature on a certificate, issued by the relevant authority, to ensure the integrity and validity of the certificate.

[0184] Certificate extensions: Provide additional information on specific details or functions, such as intended use, certificate policy, key usage restrictions, or custom attributes of AIoT tags (including their manufacturing process).

[0185] Certificate fingerprint: A hash value calculated based on the certificate content, typically used as a unique identifier or to verify its integrity.

[0186] Revocation Information: Detailed information on how to check certificate revocation status, such as the Certificate Revocation List (CRL) or the Online Certificate Status Protocol (OCSP) responder.

[0187] Figure 7 An AIoT tag with a certificate is shown. (Reference) Figure 7 and its Figure 3 The corresponding interaction in the 5G system shown utilizes the Ua interface when a user equipment (UE), client equipment (CPE), or base station with AIoT functionality interacts with the AIoT tag. This interface wirelessly powers the tag's circuitry and enables communication via its antenna to retrieve data.

[0188] In this embodiment, AIoT-enabled devices are typically supported and configured by 5G network operators. For devices equipped with a Subscriber Identity Module (SIM), the 5G AIoT network operator may include its public key in the SIM and other network elements. These keys facilitate secure communication between the device and the 5G AIoT network operator's network.

[0189] To establish trust and verify the authenticity of AIoT tag data, AIoT-enabled UEs, CPEs, or base stations employ verification algorithms. These algorithms utilize the issuer's public key to verify the digital signature associated with the certificate; in this case, the issuer is the 5G AIoT network operator. Upon successful verification, the AIoT-enabled UE, CPE, or base station can then proceed with 5G registration and connection within the 5G AIoT network operator's network. This process is controlled by a protocol running on the AIoT reader, which is either protected by hardware SoC or executed within a Trusted Execution Environment (TEE) in the AIoT reader or hosting device.

[0190] In summary, this embodiment integrates the operator-signed certificate into the AIoT tag. UE, CPE, or RAN devices interact with the tag via the Ua interface and employ a verification algorithm to verify the digital signature. These devices leverage their association with the 5G AIoT network operator, including the use of a SIM card and public key, to securely register and connect within the 5G network.

[0191] 4. Enhance user data protection using public keys

[0192] Some environmental IoT tags have the ability to store user data. This data may include sensitive information such as location data, personal health information, personally identifiable information, financial data, authentication and authorization data, sensitive business or system operation data, and user behavior data.

[0193] To ensure privacy, supporting user data encryption is crucial. Encryption helps prevent unauthorized modification or tampering, thus maintaining data integrity. It restricts access by unauthorized individuals, reduces the risk of data breaches, and protects sensitive information from unauthorized viewing or reading. Implementing encryption is essential for maintaining privacy and ensuring the security of user data in environmental IoT systems.

[0194] In one embodiment, such as Figure 8 As shown, the EPC plain identity URI is stored in plaintext, while user data on the AIoT tag can be encrypted using the AIoT service provider's public key. The tag obtains this public key from a certificate issued by the aforementioned 5G AIoT network operator or a self-signed certificate from the AIoT service provider. Upon receiving this information, the AIoT service provider decrypts the data using its private key.

[0195] On the other hand, if an AIoT service provider needs to write specific information to a specific AIoT tag, it encrypts the message using the AIoT tag's public key, retrieved from the AIoT network operator's CA or the AIoT service provider's CA. The environmental IoT tag's plain identity EPC URI serves as an index for obtaining the tag's public key. Subsequently, upon receiving the data, the AIoT tag decrypts the information using its own private key. The environmental IoT tag's private key is typically stored in a tamper-proof secure space.

[0196] In summary, in this embodiment, the encrypted information stored in the tag is securely transmitted to Provider A's server. Provider A possesses the decryption capabilities required to retrieve and decrypt the encrypted data. Provider A can decrypt the information for further processing or analysis by utilizing the private key associated with the AIoT service provider.

[0197] 5. Enhance data protection with hybrid encryption.

[0198] The uplink data transmission method disclosed in Part 4 requires AIoT tags to encrypt user data using the public key of the AIoT service provider. However, implementations using public-key cryptography such as RSA may pose challenges for IoT tags in environments with limited computing power.

[0199] As an alternative, a hybrid encryption scheme using either session keys or symmetric keys is employed to protect sensitive user data transmission between AIoT tags and AIoT service providers. These session keys are then securely exchanged between the parties using public-key cryptography. Many symmetric cryptographic systems exist, such as Rivest Cipher 4 (RC4), RC5, RC6, Blowfish, Twofish, Data Encryption Standard (DES), Triple DES, Advanced Encryption Standard (AES), and their derivatives. These symmetric encryption algorithms typically require less computational resources, thus facilitating efficient and secure communication between AIoT tags and AIoT service providers.

[0200] exist Figure 9 In the architecture shown, both parties use the same key for encryption and decryption, which contrasts with the method detailed in Part 4. Nodes seeking to adopt symmetric cryptography must securely establish a shared key.

[0201] In one embodiment, the key management system can transmit a shared key to AIoT tags and AIoT service providers. The system is responsible for distributing the symmetric key and ensuring its periodic rotation to enhance security. It also provides the necessary infrastructure to securely manage the key throughout its lifecycle, including tasks such as key generation, exchange, storage, and revocation.

[0202] In another embodiment, a key exchange protocol such as Diffie-Hellman can be deployed to generate a shared session key. The Diffie-Hellman key exchange protocol provides a secure method for exchanging encryption keys over a public communication channel. As one of the pioneering protocols of public-key cryptography, it utilizes the mathematical principles of modular exponentiation. In this process, each party is equipped with a set of public and private keys and exchanges their public keys. Each party then uses its own private key and the other party's public key to perform specific mathematical operations, thereby generating a shared key, or session key. Due to the computational challenges posed by the discrete logarithm problem, any eavesdropper observing the public key exchange cannot compute this shared key. The established session key can then be used to ensure symmetric encryption for subsequent communications.

[0203] like Figure 10 As shown in the process, the key management system or key exchange protocol generates a symmetric encryption key shared between the AIoT service provider and the AIoT tag. Therefore, both the AIoT tag and the AIoT service provider use the same symmetric encryption key to exchange protected user data. During the uplink process, the AIoT reader transmits data to the AIoT service provider. Upon receiving the user data, the AIoT service provider verifies authorization using business rules, licenses, rights, or policy information. If necessary, the AIoT service provider will request key issuance from the key management system. The data is then processed at the AIoT service provider.

[0204] If an AIoT service provider determines, based on received user data, that further action or response needs to be transmitted back to the AIoT tag, it encrypts the response data using the same symmetric key. The encrypted information is then transmitted back to the AIoT reader, which issues the appropriate command to write the data to the AIoT tag's repository.

[0205] The advantages of this invention are as follows.

[0206] Inventions related to IoT device identifiers for 5G environments will extend support for battery-free devices, such as RFID, to a wider 5G infrastructure coverage, thereby opening up a multitude of applications and use cases.

[0207] The environmental IoT field is expanding rapidly, with widespread applications across various industries. In healthcare, environmental IoT devices can be used for remote patient monitoring, asset tracking, and optimizing healthcare operations. These devices enable healthcare providers to deliver better patient care, reduce costs, and improve overall operational efficiency.

[0208] Manufacturing can leverage environmental IoT devices for real-time monitoring and control of production processes, predictive maintenance, and supply chain optimization. By integrating environmental IoT-enabled devices, manufacturing operations can achieve higher productivity, minimize downtime, and facilitate seamless operational integration.

[0209] Logistics and transportation companies can significantly benefit from environmental IoT devices for asset tracking, cargo monitoring, route optimization, and overall fleet management. These applications streamline operations, reduce delivery times, and improve customer satisfaction.

[0210] In agriculture, environmental IoT devices play a crucial role in precision agriculture, environmental monitoring, and optimizing irrigation and fertilization. By leveraging environmental IoT-enabled agricultural solutions, farmers can adopt sustainable practices, conserve resources, and increase crop yields.

[0211] Furthermore, the emerging market for environmentally powered IoT devices presents significant opportunities. Devices that can utilize energy from environmental sources (such as solar, kinetic, or thermal energy) eliminate the need for traditional power sources or frequent battery replacements. This makes it possible to deploy environmental IoT devices in remote or hard-to-reach locations with limited power infrastructure. Environmental monitoring, asset tracking, and smart infrastructure are just a few areas that can significantly benefit from the use of IoT devices powered by environmental energy.

[0212] Furthermore, given the large number of items in stores, a huge demand for environmental IoT tags can be expected in the retail chain market.

[0213] In summary, the invention of 5G environmental IoT device identifiers has brought tremendous market opportunities to various industries and sectors. The expanding IoT landscape, coupled with the emerging market for IoT devices powered by ambient energy, further enhances the potential for innovative applications and widespread adoption of IoT technology.

[0214] The concept of this invention involves:

[0215] - Method for deriving environmental IoT device identifiers from EPC plain identity URIs

[0216] - Structure of Environmental IoT SUPI

[0217] - ASP code application in Environmental IoT SUPI

[0218] - Format of Environmental IoT SUPI

[0219] - Mechanism for inserting operator certificates during the production of environmental IoT devices

[0220] - Interaction between UE and environmental IoT devices

[0221] - Mechanism for acquiring or capturing environmental IoT device identifiers and generating SUPIs on UE, CPE, RAN, or other network nodes.

[0222] - A mechanism for inserting certificates into the environmental IoT device ID. Certificates can take the form of X.509, CV, PGP, and many other formats.

[0223] - Environmental IoT-related parameters to be included in the certificate

[0224] - Certificate format specific to environment IoT devices

[0225] - Structure of Environmental IoT Operator Signature Certificates

[0226] - Mechanism for providing ASP code in certificates

[0227] - A mechanism that possesses the operator's private key, public key, ASP public key, ASP private key, and ASP content key on the USIM or UICC.

[0228] - Mechanism for retrieving or writing protected information on environmental IoT devices based on PKI

[0229] - Use SUPI type values ​​4, 5, 6, or 7 as the environmental IoT identifier.

[0230] - Applications of SUPI in Environmental IoT Devices

[0231] - Use SUPI to reach a set of environmental IoT devices that conform to the EPC Plain Identity Mode URI.

[0232] - Format of the username portion for SUPI (Sustainable Internet of Things) devices in the environment

[0233] - Format of the domain portion of SUPI for environmental IoT devices

[0234] - Methods for flexibly configuring the username portion of SUPI for IoT devices in the environment

[0235] Within the AIoT service provider's servers, all information is stored in encrypted format using the AIoT tag's public key or, alternatively, a symmetric encryption scheme. This encryption mechanism ensures that sensitive data remains protected and may only be accessible to authorized parties with the corresponding private key.

[0236] To retrieve encrypted information from the AIoT service provider's server, a secure connection is established between the UE, RAN, or CPE device and the AIoT service provider's public key. These devices use the public key to securely retrieve the encrypted information from the AIoT service provider's server. This ensures that only authorized entities with the corresponding private key can access and decrypt the information, thus maintaining the confidentiality and integrity of the data throughout the communication process.

[0237] - Employs a public-key cryptography mechanism to protect sensitive data on environmental IoT tags.

[0238] - Employ hybrid encryption mechanisms to protect sensitive user data on environmental IoT tags.

[0239] - A method that uses a key management system to generate symmetric keys for environmental IoT tags to perform encryption.

[0240] - A method for generating shared session keys between environmental IoT tags and environmental IoT service providers using a decentralized approach.

[0241] This application also provides a computer-readable storage medium for storing a computer program. This computer-readable storage medium enables a computer to execute a corresponding process implemented by the UE / BS in each of the various methods of the embodiments of this disclosure. For the sake of brevity, it will not be described in detail here.

[0242] This application also provides a computer program product including computer program instructions. This computer program product enables a computer to execute a corresponding process implemented by the UE / BS in each of the various methods of the embodiments of this disclosure. For the sake of brevity, it will not be described in detail here.

[0243] This application also provides a computer program. This computer program enables a computer to execute the corresponding process implemented by the UE / BS in each of the various methods of the embodiments of this disclosure. For the sake of brevity, it will not be described in detail here.

[0244] Although not shown in detail, any device or apparatus forming part of the network may include at least a processor, a storage unit, and a communication interface, wherein the processor unit, storage unit, and communication interface are configured to perform the methods of any aspect of the present invention. Further options and choices are described below.

[0245] The signal processing functions of the gNB and UE in this embodiment of the invention can be implemented using computing systems or architectures known to those skilled in the art. Computing systems can be used, such as desktop computers, laptops or notebook computers, handheld computing devices (personal digital assistants (PDAs), mobile phones, PDAs, etc.), mainframes, servers, clients, or any other type of dedicated or general-purpose computing device suitable for a particular application or environment. The computing system may include one or more processors, which can be implemented using general-purpose or dedicated processing engines (e.g., microprocessors, microcontrollers, or other control modules).

[0246] The computing system may also include main memory, such as random access memory (RAM) or other dynamic memory, which is used to store information and instructions to be executed by the processor. Such main memory can also be used to store temporary variables or other intermediate information during processor instruction execution. The computing system may also include read-only memory (ROM) or other static storage devices for storing static information and processor instructions.

[0247] The computing system may also include an information storage system, which may include, for example, media drives and removable storage interfaces. Media drives may include drives or other mechanisms that support fixed or removable storage media, such as hard disk drives, floppy disk drives, magnetic tape drives, optical disc drives, compact disc (CD) or digital video drives (DVD), read or write (R or RW) drives, or other removable or fixed media drives. Storage media may include, for example, hard disks, floppy disks, magnetic tapes, optical discs, CDs, or DVDs, or other fixed or removable media that can be read and written by a media drive. Storage media may include computer-readable storage media in which specific computer software or data is stored.

[0248] In alternative embodiments, the information storage system may include other similar components that allow computer programs or other instructions or data to be loaded into the computing system. Such components may include, for example, removable storage units and interfaces, such as program boxes and cartridge interfaces, removable memory (e.g., flash memory or other removable memory modules) and memory slots, as well as other removable storage units and interfaces that allow software and data to be transferred from the removable storage units to the computing system.

[0249] The computing system may also include a communication interface. This communication interface allows software and data to be transferred between the computing system and external devices. Examples of communication interfaces may include modems, network interfaces (e.g., Ethernet or other NIC cards), communication ports (e.g., universal serial bus (USB) ports), PCMCIA slots, and cards. Software and data transferred through the communication interface take the form of signals, which can be electronic, electromagnetic, optical, or other signals that can be received by the communication interface medium.

[0250] In this document, terms such as "computer program product" and "computer-readable medium" are generally used to refer to tangible media, such as memory, storage devices, or storage units. These and other forms of computer-readable media may store one or more instructions used by a processor, including a computer system, to cause the processor to perform specified operations. Such instructions are generally referred to as "computer program code" (which may be grouped as computer programs or other groups) that, when executed, enable a computing system to perform the functions of embodiments of the present invention. Note that code may directly cause the processor to perform specified operations, be compiled to perform such operations, and / or be combined with other software, hardware, and / or firmware elements (e.g., libraries for performing standard functions) to perform such operations.

[0251] Non-transitory computer-readable media may include at least one of the following: hard disk, CD-ROM, optical storage device, magnetic storage device, read-only memory, programmable read-only memory, erasable programmable read-only memory, EPROM, electrically erasable programmable read-only memory, and flash memory. In embodiments using software implementation elements, the software may be stored in the computer-readable medium and loaded into a computing system using, for example, a removable storage drive. The control module (in this example, software instructions or executable computer program code), when executed by a processor in the computer system, causes the processor to perform the functions of the invention as described herein.

[0252] Furthermore, the inventive concept can be applied to any circuit performing signal processing functions within a network element. It is further considered that, for example, semiconductor manufacturers can incorporate the inventive concept into the design of a standalone device, such as a microcontroller for a digital signal processor (DSP), or an application-specific integrated circuit (ASIC) and / or any other subsystem element.

[0253] It should be understood that, for clarity, the above description has referred to embodiments of the invention with reference to a single processing logic. However, the inventive concept can also be implemented by a number of different functional units and processors to provide signal processing functionality. Therefore, references to specific functional units should only be considered as references to the appropriate means of providing said functionality, and not as representations of a strict logical or physical structure or organization.

[0254] Various aspects of the present invention can be implemented in any suitable form, including hardware, software, firmware, or any combination thereof. The present invention can optionally be implemented, at least in part, as computer software running on one or more data processors and / or digital signal processors or configurable module components (e.g., field-programmable gate array (FPGA) devices).

[0255] Therefore, the elements and components of the embodiments of the present invention can be implemented physically, functionally, and logically in any suitable manner. In fact, the function can be implemented in a single unit, multiple units, or as part of other functional units. Although the invention has been described in conjunction with some embodiments, it is not limited to the specific forms set forth herein. Rather, the scope of the invention is limited only by the appended claims. Furthermore, although a feature may appear to be described in conjunction with a particular embodiment, those skilled in the art will recognize that the various features of the described embodiments can be combined according to the invention. In the claims, the term "comprising" does not exclude the presence of other elements or steps.

[0256] Furthermore, although listed separately, multiple means, elements, or method steps can be implemented by, for example, a single unit or processor. Moreover, although individual features may be included in different claims, these features may be advantageously combined, and inclusion in different claims does not imply that the combination of features is infeasible and / or disadvantageous. Furthermore, including a feature in a claim of one class does not imply limitation to that class, but rather indicates that the feature is equally applicable to other claim classes (as the case may be).

[0257] Furthermore, the order of features in the claims does not imply that the features must be performed in any particular order, and in particular, the order of steps in a method claim does not imply that the steps must be performed in that order. Instead, these steps can be performed in any suitable order. Moreover, singular references do not exclude plural forms. Therefore, references to "a," "an," "first," "second," etc., do not exclude plural forms.

[0258] Although this application has been described in conjunction with what are considered to be the most practical and preferred embodiments, it should be understood that this application is not limited to the disclosed embodiments, but is intended to cover various arrangements made without departing from the broadest interpretation of the appended claims.< / mcc> < / mnc> < / asp>

Claims

1. A wireless communication method, comprising: Obtain the Electronic Product Code (EPC) and Uniform Resource Identifier (URI) from the environmental IoT device; as well as Based on the obtained EPC URI, formulate the Network Access Identifier (NAI) format for the Subscription Permanent Identifier (SUPI).

2. The method according to claim 1, wherein, The NAI of the SUPI follows a first format, which consists of a username portion and a domain portion, wherein the username portion represents a user identifier or device identifier, and the domain portion specifies the authentication scope or authentication domain to which the request is directed.

3. The method according to claim 2, wherein, The username portion corresponds to the EPC URI, while the domain portion identifies the operator that has the subscription.

4. The method according to claim 3, wherein, In addition to the EPC URI, the username portion includes several components corresponding to other information, and these components are separated by specific characters.

5. The method according to claim 2, wherein, The domain portion includes the Environmental IoT Service Provider ID, which is a globally unique ID whether combined with or independent of the Public Land Mobile Network (PLMN) ID.

6. The method according to claim 5, wherein, The domain portion is constructed by adding the tags "aiot" and ASP before the network domain name.

7. The method according to claim 1, wherein, The SUPI is designed to support environmental IoT service requests, or to allow specific applications to define filtering rules for a set of environmental IoT devices.

8. The method according to claim 1, wherein, When deriving the User Hidden Identifier (SUCI) from the SUPI, the Network Specific Identifier (NSI) is used as the SUPI type, or a special type for the IoT device in the environment is adopted.

9. The method according to claim 1, wherein, The environmental IoT device has a user identity module (SIM) or a variant thereof embedded in the environmental IoT device.

10. The method according to claim 1, further comprising: Obtain the digital signature of the EPC URI from the IoT device in the environment; The digital signature is decrypted using the public key of the environmental IoT device to obtain the first hash value of the EPC URI; Use a hash function to create a second hash value based on the obtained EPC URI; as well as If the second hash value matches the first hash value, it verifies that the obtained EPC URI has not been changed.

11. The method of claim 10, further comprising: If the EPC URI is successfully verified, user data is retrieved from the IoT device in the environment, or from a local database or an AIoT service provider database.

12. The method according to claim 10, wherein, The public key is received from one of the following: Certificates issued by a Certificate Authority (CA); The SIM installed on the IoT device in the environment; and Related AIoT network elements.

13. The method according to claim 1, further comprising: Generate a number and encrypt the number using the public key of the IoT device in the environment; Send encrypted digital data to the IoT devices in the environment; Receive a decrypted digital data from the environmental IoT device, the decrypted digital data being decrypted using the private key of the environmental IoT device; and Verify that the number is the same as the decrypted number received from the IoT device in the environment.

14. The method according to claim 1, further comprising: Send a number to the IoT device in the environment; Receive the digital signature of the digital device from the environment's IoT device; as well as The digital signature of the number is decrypted using the public key of the environmental IoT device to confirm whether the number was originally sent to the environmental IoT device.

15. The method according to claim 1, wherein, The certificate is embedded in the IoT device in the environment.

16. The method according to claim 15, wherein, The EPC URI is obtained from the certificate embedded in the IoT device in the environment.

17. The method according to claim 16, wherein, The certificate embedded in the environmental IoT device also includes the public key of the environmental IoT device or the AIoT service provider.

18. The method according to claim 15, wherein, The certificate embedded in the IoT device in the environment is issued by a cellular network operator or an AIoT service provider.

19. The method of claim 15, further comprising: A verification algorithm is used to verify the digital signature associated with the certificate embedded in the IoT device in the environment. as well as Once verification is successful, proceed with the registration and connection process with the cellular network.

20. A communication device, comprising a memory and a processor, wherein, The processor is configured to invoke and execute program instructions stored in memory to perform the method according to any one of claims 1 to 19.

21. A non-transitory computer-readable storage medium configured to store a computer program that enables a computer to perform the method according to any one of claims 1 to 19.

22. A secure data processing method, comprising: Receive user data from environmental IoT tags that is encrypted using a public key associated with an AIoT service provider; as well as The encrypted user data of the environmental IoT tag is obtained by decrypting the encrypted user data using a private key associated with the AIoT service provider.

23. The method according to claim 22, wherein, The public key associated with the AIoT service provider comes from a certificate issued by a cellular network operator or from a self-signed certificate of the AIoT service provider.

24. The method of claim 22, further comprising: Specific information is encrypted using the public key associated with the environmental IoT tag; as well as Encrypted specific information is transmitted to the environmental IoT tag so that the environmental IoT tag can decrypt the encrypted specific information using the private key associated with the environmental IoT tag.

25. The method according to claim 24, wherein, The public key associated with the environmental IoT tag is retrieved from an AIoT network operator certification authority (CA) or an AIoT service provider (CA).

26. The method of claim 25, wherein, The Electronic Product Code (EPC) and Uniform Resource Identifier (URI) of the environmental IoT tag are used as an index for retrieving the public key associated with the environmental IoT tag.

27. The method according to claim 24, wherein, The private key associated with the environmental IoT tag is stored in the tamper-proof secure space of the environmental IoT tag.

28. A secure data processing method, comprising: By utilizing public-key cryptography to exchange and share symmetric keys with environmental IoT tags; Receive user data encrypted using the shared symmetric key from the environmental IoT tag; and The encrypted user data is obtained by decrypting the environmental IoT tag using the shared symmetric key.

29. The method of claim 28, further comprising: Specific information is encrypted using the shared symmetric key; as well as Encrypted specific information is transmitted to the environmental IoT tag so that the environmental IoT tag can decrypt the encrypted specific information using the shared symmetric key.

30. The method according to claim 28, wherein, The shared symmetric key is used for symmetric cryptography, including Rivest Cipher 4 RC4, RC5, RC6, Blowfish, Twofish, Data Encryption Standard (DES), Triple DES, or Advanced Encryption Standard (AES).

31. The method according to claim 28, wherein, The key exchange protocol is used when exchanging the shared symmetric key.

32. The method according to claim 31, wherein, The key exchange protocol includes Diffie-Hellman.

33. An environmental Internet of Things (IoT) device, including a memory for storing Electronic Product Code (EPC) Uniform Resource Identifier (URI).

34. The device according to claim 33, wherein, The environmental IoT device has a user identity module (SIM) or a variant thereof embedded in the environmental IoT device.

35. The device according to claim 33, wherein, The memory also stores the digital signature of the EPC URI.

36. The device according to claim 33, wherein, The memory also stores user data.

37. The device according to claim 33, wherein, The memory also stores certificates.

38. The device according to claim 37, wherein, The certificate includes the EPC URI.

39. The method according to claim 37, wherein, The certificates include X.509 certificates, X.509 certificate extensions, attribute certificates, card-verifiable (CV) certificates, privacy-friendly PGP certificates, WAP certificates, Simple Public Key Infrastructure (SPKI) certificates, or traceable anonymous certificates.

40. An environmental Internet of Things (IoT) device identifier, comprising a subscription persistent identifier (SUPI), wherein the SUPI has a network access identifier (NAI) format, wherein, The NAI of the SUPI includes a username portion and a domain portion, and the username portion corresponds to the Electronic Product Code (EPC) Uniform Resource Identifier (URI) of the environmental IoT device.

41. The AIoT device identifier according to claim 40, wherein, The username portion represents a user identifier or device identifier, and the domain portion specifies the authentication scope or authentication domain to which the request is directed.

42. The AIoT device identifier according to claim 41, wherein, The domain portion identifies the operator that has the subscription.

43. The AIoT device identifier according to claim 42, wherein, In addition to the EPC URI, the username portion includes several components corresponding to other information, and these components are separated by specific characters.

44. The AIoT device identifier according to claim 41, wherein, The domain portion includes the Environmental IoT Service Provider ID, which is a globally unique ID whether combined with or independent of the Public Land Mobile Network (PLMN) ID.

45. The AIoT device identifier according to claim 44, wherein, The domain portion is constructed by adding the tags "aiot" and ASP before the network domain name.

46. ​​The AIoT device identifier according to claim 40, wherein, The SUPI is designed to support environmental IoT service requests, or to allow specific applications to define filtering rules for a set of environmental IoT devices.