Confidentiality and privacy protection of messages from restricted devices

By generating a hash function between IoT devices and servers, and using device identifiers and current numbers to generate a security key K, the confidentiality and privacy protection issues of environmental energy-powered IoT devices are solved, and low-complexity secure communication is achieved.

CN122095650APending Publication Date: 2026-05-26LENOVO (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2026-05-26

Smart Images

  • Figure CN122095650A_ABST
    Figure CN122095650A_ABST
Patent Text Reader

Abstract

Various aspects of this disclosure relate to implementing confidentiality and / or privacy protection for communications between devices, such as environmental energy supply equipment. In some cases, IoT devices and / or IoT servers can use secret parameters known only to these devices / servers as input to a hash function to perform key generation. For example, IoT servers and IoT devices can utilize device identifiers as secret parameters, which, along with current timestamps, are input into a hash operation or function to generate a secure key (e.g., key K). In some cases, key generation may include time information or other similar information to ensure the freshness of secure K during generation.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-reference to related applications

[0001] This application claims priority to U.S. Patent Application No. 18 / 819,763, filed August 29, 2024, entitled "Confidentiality and Privacy Protection of Messages from Restricted Devices," and U.S. Provisional Patent Application No. 63 / 580,177, filed September 1, 2023, entitled "Confidentiality and Privacy Protection of Messages from Restricted Devices," the entire contents of which are incorporated herein by reference. Technical Field

[0002] This disclosure relates to wireless communications, and more specifically to the protection (e.g., confidentiality and / or privacy) of messages between devices. Background Technology

[0003] A wireless communication system may include one or more network communication devices, such as base stations, which may support wireless communication with one or more user communication devices, also referred to as user equipment (UE) or other suitable terms. The wireless communication system can support wireless communication with one or more user communication devices by utilizing the resources of the wireless communication system (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers, etc.)). Furthermore, the wireless communication system can support wireless communication across various radio access technologies, including third-generation (3G) radio access technology, fourth-generation (4G) radio access technology, fifth-generation (5G) radio access technology, and other suitable radio access technologies other than 5G (e.g., sixth-generation (6G)). Summary of the Invention

[0004] The article “a” preceding an element is unrestricted and should be understood to mean “at least one” or “one or more” of these elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” are interchangeable. As used herein, including in claims, the word “or” used in a list of items (e.g., a list of items beginning with phrases such as “at least one of…” or “one or more of…” or “one or two of…”) indicates an inclusive list, such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase “based on” should not be construed as a reference to a closed set of conditions. For example, an example step described as “based on condition A” could be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase “based on” should be interpreted in the same manner as the phrase “at least partially based on.” Furthermore, as used herein, including in claims, “set” can include one or more elements.

[0005] This disclosure relates to methods, apparatus, and systems for supporting confidentiality and / or privacy protection in communications between devices such as environmental energy supply equipment.

[0006] Some implementations of the methods and apparatus described herein may further include a network entity for wireless communication, the network entity including at least one memory and at least one processor coupled to the at least one memory and configured to cause the network entity to select a UE that has not registered with the network entity; generate a current number based on a device identifier for the selected UE, and also generate a temporary identifier based on the current number and the device identifier; and send a registration request message including the current number and the temporary identifier to the selected UE for registration with the network entity.

[0007] In some implementations of the methods and apparatus described herein, the at least one processor is further configured to cause a network entity to receive a response message from a selected UE, the response message including a temporary identifier and an indication that the temporary identifier received from the network entity matches a corresponding temporary identifier stored in the selected UE.

[0008] In some implementations of the methods and apparatus described herein, the at least one processor is further configured to cause a network entity to register the selected UE in response to a match between a temporary identifier generated by the network entity and a corresponding temporary identifier stored by the selected UE.

[0009] In some implementations of the methods and apparatus described herein, the at least one processor is further configured to cause the network entity to generate a hash based on the current number and the device identifier, and to truncate the hash to generate a security key K, which is used to encrypt the device identifier to derive a temporary identifier, wherein the temporary identifier corresponds to the remaining bits of the hash.

[0010] In some implementations of the methods and apparatus described herein, the processor is further configured to cause a network entity to receive a response message from a selected UE, the response message including a temporary identifier, an indication that the temporary identifier received from the network entity matches a corresponding temporary identifier stored in the selected UE, and one or more parameters encrypted with a security key K and one or more parameters decrypted using the security key K.

[0011] In some implementations of the methods and apparatus described herein, the network entity is an Internet of Things (IoT) server and the UE is an ambient energy-powered IoT device.

[0012] In some implementations of the methods and apparatus described herein, the at least one processor is configured to cause the network entity to generate a hash using a current number and a device identifier.

[0013] In some implementations of the methods and apparatus described herein, the at least one processor is configured to cause a network entity to generate a hash using a current number, a device identifier, the length of the current number, and a root key.

[0014] In some implementations of the methods and apparatus described herein, the at least one processor is configured to cause a network entity to generate a hash as the output of a hash function using one or more parameters, including a device identifier, a random number, or time information.

[0015] In some implementations of the methods and apparatus described in this paper, the current number is the truncated output of a hash function.

[0016] In some implementations of the methods and apparatus described herein, the at least one processor is configured to cause a network entity to generate a hash based on one or more parameters, including random numbers, time information, timers, counters, or additional current numbers.

[0017] In some implementations of the methods and apparatus described herein, the hash includes the most significant bit representing a temporary identifier and the least significant bit representing a security key K.

[0018] In some implementations of the methods and apparatus described herein, the hash includes the least significant bit representing a temporary identifier and the most significant bit representing a security key K.

[0019] Some implementations of the methods and apparatus described herein may also include a UE for wireless communication, the UE including at least one memory and at least one processor coupled to the at least one memory and configured to cause the UE to generate a temporary identifier based on a current number and a device identifier of the UE; and to send a registration request message including the current number and the temporary identifier to a network entity.

[0020] In some implementations of the methods and apparatus described herein, the at least one processor is further configured to cause the UE to receive a response message including a temporary identifier from a network entity.

[0021] In some implementations of the methods and apparatus described herein, the temporary identifier is a truncated portion of the output hash of the current number and the device identifier.

[0022] In some implementations of the methods and apparatus described herein, the at least one processor is configured to cause the UE to generate a security key K, which is used to encrypt a device identifier to derive a temporary identifier.

[0023] Some implementations of the methods and apparatus described herein may also include a processor for wireless communication, the processor including at least one controller coupled to at least one memory and configured to receive from a network server a registration request including a current number and a temporary identifier, compare the temporary identifier received via the registration request with a generated temporary identifier, and when the comparison indicates a match between the temporary identifier received via the registration request and the generated temporary identifier, send a response message to the network server indicating a match between the temporary identifier and the generated temporary identifier.

[0024] In some implementations of the methods and apparatus described herein, the at least one controller is further configured to cause the processor to: generate an output hash using a device identifier associated with the processor and a current number from the registration request, and generate a temporary identifier using the device identifier associated with the processor and the output hash from the registration request.

[0025] Some implementations of the methods and apparatus described herein may also include a method performed by an IoT device, the method comprising receiving a registration request from a network server including a current number and a temporary identifier; generating an output hash using a device identifier for the IoT device and the current number from the registration request; generating a temporary identifier using the device identifier for the IoT device and the current number from the registration request; comparing the temporary identifier received via the registration request with the generated temporary identifier; and sending a response message to the network server indicating a match between the temporary identifier received via the registration request and the generated temporary identifier when the comparison indicates a match between the temporary identifier received via the registration request and the generated temporary identifier. Attached Figure Description

[0026] Figure 1 Examples of wireless communication systems according to various aspects of this disclosure are illustrated.

[0027] Figure 2 The illustration shows an example of message passing between an IoT server and an ambient-powered IoT device according to various aspects of this disclosure.

[0028] Figure 3 The illustration shows an example message flow initiated by an IoT server and an IoT device according to various aspects of this disclosure.

[0029] Figure 4 An example representation of the output hash according to various aspects of this disclosure is illustrated.

[0030] Figure 5 The illustration shows an example device-initiated message flow between an IoT server and an IoT device according to various aspects of this disclosure.

[0031] Figure 6 Examples of user equipment (UE) according to various aspects of this disclosure are illustrated.

[0032] Figure 7 Examples of processors according to various aspects of this disclosure are illustrated.

[0033] Figure 8 Examples of network devices (NEs) according to various aspects of this disclosure are illustrated.

[0034] Figure 9 The diagram illustrates a flowchart of a method performed by a UE according to various aspects of this disclosure.

[0035] Figure 10 The diagram illustrates a flowchart of a method performed by an NE according to various aspects of this disclosure.

[0036] Figure 11The diagram illustrates a flowchart of a method performed by a UE according to various aspects of this disclosure. Detailed Implementation

[0037] Devices that support ambient power, such as Internet of Things (IoT) devices, include battery-free devices with limited storage capacity or other capability limitations (e.g., they use capacitors to store a limited amount of energy). These limited devices can store energy by harvesting energy from the environment in which the IoT device is located, such as via radio waves, light, heat, motion, and other energy sources / power sources available to the IoT device. Example limited devices include location tags or stickers, such as tags attached to objects that enable a web server to track the location of the object. Therefore, a web server can be associated with many limited devices (e.g., hundreds or thousands) over a period of time and / or within a specific deployment.

[0038] Such IoT devices can have low complexity (e.g., low power consumption and few capabilities) to ensure long lifespan (e.g., over 10 years) and usability. Unlike other IoT devices (such as those defined by 3GPP (3rd Generation Partnership Project), ambient power enabled devices may not include a USIM (Universal Subscriber Identity Module) and may therefore lack components capable of securing communications to / from the device. Exemplary ambient power enabled IoT devices may include tags for tracking items on supply chain or e-commerce platforms.

[0039] Lacking USIM or other similar components, these IoT devices cannot employ typical confidentiality or privacy protections for their communications because such technologies are computationally intensive and would likely utilize all or most of the collected energy for protection. Therefore, ambient-powered IoT devices should employ alternative technologies that strike a balance between the resources used for computation and the desired level of security.

[0040] In some embodiments, IoT devices and / or IoT servers can perform key generation using secret parameters known only to the device / server as input to a hash function. For example, IoT servers and IoT devices can utilize a device identifier as a secret parameter, which, along with a current value, is input into a hash operation or function to generate a secure key (e.g., key K). In some cases, key generation may include time information or other similar information to ensure the freshness of secure K during generation.

[0041] Such operations are relatively simple but have an appropriate level of protection, and therefore can be used for IoT devices and other environmentally powered devices when sending confidential and / or privacy-protected messages, such as during registration.

[0042] Various aspects of this disclosure are described in the context of wireless communication systems.

[0043] Figure 1 An example of a wireless communication system 100 according to various aspects of this disclosure is illustrated. The wireless communication system 100 may include one or more NEs 102, one or more UEs 104, and a core network (CN) 106. The wireless communication system 100 may support various radio access technologies. In some implementations, the wireless communication system 100 may be a 4G network, such as an LTE network or an advanced LTE (LTE-A) network. In some other implementations, the wireless communication system 100 may be an NR network, such as a 5G network, an advanced 5G (5G-A) network, or a 5G ultra-wideband (5G-UWB) network. In other implementations, the wireless communication system 100 may be a combination of 4G and 5G networks, or other suitable radio access technologies, including IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20. The wireless communication system 100 may support radio access technologies other than 5G, such as 6G. In addition, the wireless communication system 100 can support technologies such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA).

[0044] One or more NEs 102 may be distributed throughout a geographic area to form a wireless communication system 100. The one or more NEs 102 described herein may be, include, or may be referred to as network nodes, base stations, network elements, network functions, network entities, radio access networks (RANs), Node Bs, eNodeBs (eNBs), next-generation Node Bs (gNBs), or other suitable terms. NEs 102 and UEs 104 may communicate via a communication link, which may be a wireless or wired connection. For example, NEs 102 and UEs 104 may perform wireless communication (e.g., receiving signaling, sending signaling) via a Uu interface.

[0045] NE 102 can provide a geographic coverage area, and NE 102 can support the services of one or more UE 104s within that geographic coverage area. For example, NE 102 and UE 104 can support wireless communication of signals associated with services (e.g., voice, video, packet data, messaging, broadcasting, etc.) based on one or more radio access technologies. In some implementations, NE 102 can be mobile, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies can overlap, but different geographic coverage areas can be associated with different NE 102s.

[0046] One or more UEs 104 may be distributed throughout the geographic area of ​​the wireless communication system 100. UE 104 may include or be referred to as a remote unit, mobile device, wireless device, remote device, subscriber device, transmitter device, receiver device, or some other suitable term. In some implementations, among other examples, UE 104 may be referred to as a unit, station, terminal, or client. Additionally or alternatively, UE 104 may be referred to as an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a Machine Type Communication (MTC) device, etc.

[0047] UE 104 may be able to support direct wireless communication with other UE 104s via a communication link. For example, UE 104 may support direct wireless communication with another UE 104 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular V2X deployments, the communication link may be referred to as a sidelink. For example, UE 104 may support direct wireless communication with another UE 104 via a PC5 interface.

[0048] NE 102 can support communication with CN 106 or with another NE 102, or both. For example, NE 102 can interface with other NE 102 or CN 106 via one or more backhaul links (e.g., S1, N2, N2, or network interfaces). In some implementations, NE 102 can communicate directly with each other. In some other implementations, NE 102 can communicate indirectly with each other (e.g., via CN 106). In some implementations, one or more NE 102 may include sub-components, such as access network entities, which may be examples of access node controllers (ANCs). The ANC can communicate with one or more UE 104s via one or more other access network transport entities (which may be referred to as radio headends, smart radio headends, or transmit-receive points (TRPs)).

[0049] CN 106 can support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. CN 106 can be an evolved packet core (EPC) or a 5G core (5GC), which may include control plane entities that manage access and mobility (e.g., a mobility management entity (MME), access and mobility management functions (AMF)) and user plane entities that route packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entities may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signaling bearers, etc.) for one or more UEs 104 served by one or more NEs 102 associated with CN 106.

[0050] CN 106 can communicate with the packet data network via one or more backhaul links (e.g., via S1, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 can communicate with the application server. UE 104 can establish a session with CN 106 via NE 102 (e.g., a Protocol Data Unit (PDU) session, etc.). CN 106 can use the established session (e.g., an established PDU session) to route services (e.g., control information, data, etc.) between UE 104 and the application server. The PDU session may be an example of a logical connection between UE 104 and CN 106 (e.g., one or more network functions of CN 106).

[0051] In the wireless communication system 100, NE 102 and UE 104 can use the resources of the wireless communication system 100 (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some implementations, NE 102 and UE 104 can support different resource structures. For example, NE 102 and UE 104 can support different frame structures. In some implementations, such as in 4G, NE 102 and UE 104 can support a single frame structure. In some other implementations, such as in 5G and other suitable radio access technologies, NE 102 and UE 104 can support various frame structures (i.e., multiple frame structures). NE 102 and UE 104 can support various frame structures based on one or more digital technologies.

[0052] One or more digital technologies may be supported in the wireless communication system 100, and the digital technologies may include subcarrier spacing and cyclic prefix. The first digital technology (e.g., μ=0) can be associated with the first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first digital technique (e.g., ...) associated with the first subcarrier spacing (e.g., 15 kHz) is... μ =0) can utilize one time slot per subframe. Second digital technologies (e.g., μ =1) can be associated with the second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. The third digital technology (e.g., μ =2) can be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth digital technology (e.g., μ =3) can be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth digital technology (e.g., μ =4) can be associated with the fifth subcarrier spacing (e.g., 240 kHz) and the normal cyclic prefix.

[0053] Time intervals for resources (e.g., communication resources) can be organized according to frames (also known as radio frames). Each frame can have a duration, for example, 10 milliseconds (ms). In some implementations, each frame can include multiple subframes. For example, each frame can include 10 subframes, and each subframe can have a duration, for example, 1 ms. In some implementations, each frame can have the same duration. In some implementations, each subframe of a frame can have the same duration.

[0054] Alternatively or concurrently, the time intervals of resources (e.g., communication resources) can be organized according to time slots. For example, a subframe may include a certain number (e.g., quantity) of time slots. The number of time slots in each subframe may also depend on one or more digital technologies supported in the wireless communication system 100. For example, a first digital technology, a second digital technology, a third digital technology, a fourth digital technology, and a fifth digital technology (i.e., ...) associated with corresponding subcarrier intervals of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz. μ =0、 μ =1、 μ =2、 μ =3、 μ=4) One time slot per subframe, two time slots per subframe, four time slots per subframe, eight time slots per subframe, and 16 time slots per subframe can be used, respectively. Each time slot can include a certain number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of time slots in a subframe can depend on the digital technique. For a normal cyclic prefix, a time slot can include 14 symbols. For an extended cyclic prefix (e.g., for a 60kHz subcarrier spacing), a time slot can include 12 symbols. The relationship between the number of symbols per time slot, the number of time slots per subframe, and the number of time slots per frame for both normal and extended cyclic prefixes can depend on the digital technique. It should be understood that the first digital technique (e.g., quantity) associated with the first subcarrier spacing (e.g., 15kHz) can be... μ The reference of =0 can be used interchangeably between subframes and time slots.

[0055] In the wireless communication system 100, the electromagnetic (EM) spectrum can be divided into various categories, frequency bands, frequency channels, etc., based on frequency or wavelength. By way of example, the wireless communication system 100 can support one or more operating frequency bands, such as frequency range names FR1 (410MHz-7.125GHz), FR2 (24.25GHz-52.6GHz), FR3 (7.125GHz-24.25GHz), FR4 (52.6GHz-114.25GHz), FR4a or FR4-1 (52.6GHz-71GHz), and FR5 (114.25GHz-300GHz). In some implementations, NE 102 and UE 104 can perform wireless communication on one or more operating frequency bands. In some implementations, FR1 can be used by NE 102 and UE 104, as well as other devices or apparatuses, for cellular communication services (e.g., control information, data). In some implementations, FR2 can be used by NE 102 and UE 104, as well as other devices or apparatuses, for short-range, high-data-rate capabilities.

[0056] FR1 can be associated with one or more digital technologies (e.g., at least three digital technologies). For example, FR1 can be associated with a first digital technology (e.g., μ =0) is associated with a subcarrier spacing of 15 kHz; and is associated with a second digital technology (e.g., μ =1) is associated with a subcarrier spacing of 30 kHz; and is associated with a third digital technology (e.g., μ =2) is associated with a subcarrier spacing of 60 kHz. FR2 can be associated with one or more digital technologies (e.g., at least two digital technologies). For example, FR2 can be associated with a third digital technology (e.g., μ=2) is associated with a subcarrier spacing of 60 kHz; and is associated with a fourth digital technology (e.g., μ =3) is associated with a subcarrier spacing of 120 kHz.

[0057] As described in this article, this technology can utilize secret parameters to ensure confidentiality and / or privacy protection between IoT devices (or multiple devices) (such as restricted devices) and IoT servers. Figure 2 An example of message passing 200 between an IoT server 210 and an ambient-powered IoT device 220 according to various aspects of this disclosure is illustrated.

[0058] IoT server 210 sends a registration request message to IoT device 220. For example, the registration request message may include an initial registration request to IoT server 210 for IoT device 220. In response to the request message, IoT device 220 may perform confidentiality and / or privacy protection operations as described herein and send a response message back to IoT server 210 indicating the result of the operations, such as successful registration with IoT server 210. In some cases, IoT device 220 may initiate a registration process with IoT server 210 and send a registration request message to IoT server 210.

[0059] As described herein, IoT device 220 or IoT server 210 may utilize a secret parameter when generating a security key (e.g., key K), which will be used when exchanging messages during registration between IoT device 220 and IoT server 210. For example, IoT server 210 may utilize the device identifier of IoT device 220 as a secret parameter when the device identifier is unique for all devices associated with IoT server 210.

[0060] In some cases, the device identifier can be known to the IoT server 210, such as during the provision of goods via the IoT server 210, IoT device 220, and other similar IoT devices. For example, a warehouse management platform can receive a device ID associated with goods or items delivered to the warehouse (e.g., via scanning a barcode), where the device ID is associated with an IoT device that is tagged or otherwise attached to the goods or items.

[0061] Therefore, a key generation operation or key generator can receive a device identifier and a current number as input and execute a hash function or key derivation function (KDF) to generate a secure key K as the output hash of the executed function. In some cases, the hash function can generate the output hash based on the device identifier, the current number, and the length of the current number (e.g., 0x04), and / or generate the output hash as a truncated hash that depends on the output length of the hash algorithm or function (e.g., MD2, MD4, SHA1, SHA224, etc.).

[0062] To ensure that the security key K is newly generated, the current number may include or be based on time information, such as time information received via a message broadcast from the IoT server 210 to the IoT device. Therefore, in some embodiments, the IoT server 210 may create a current number as an output hash of the device identifier, a random number, and time information, optionally concatenated.

[0063] In some cases, the key generation operation can utilize a KDF to generate a secure key or output an encryption key K. The KDF can accept a current number (e.g., an output hash) and optionally, the length of the current number as input, and can accept a device identifier as an input key, such as an initial root key (e.g., a password) pre-configured for IoT device 220 (and shared with IoT server 210).

[0064] Therefore, the security key K can be a truncated output hash of the most significant or least significant bits (e.g., 32-bit, 48-bit, 64-bit, etc.). The length of the security key K can be based on the encryption algorithm, message length, and / or the storage capacity of the IoT device 220. In some cases, the various functions or algorithms described herein (e.g., encryption algorithms, hash algorithms, or functions), key length, and other parameters can be pre-configured for the IoT device 220 and the IoT server 210.

[0065] In some cases, when addressing one or more IoT devices (e.g., IoT device 220), IoT server 210 may use a temporary device identifier assigned to the IoT device for one-time use (e.g., during initial registration). In other cases, IoT devices may be assigned to a device category, location, or other subset to limit the number of devices initially addressed by IoT server 210 (e.g., IoT server 210 may check only a subset of devices during initial registration).

[0066] During the addressing process of an IoT device, the IoT server 210 can exchange an encrypted device identifier with the IoT device 220 as a temporary identifier. Furthermore, when the security key K is based on a truncated output hash, the remainder of the output hash can be used as a temporary identifier for the IoT device 220.

[0067] In various situations, IoT device 220 may include additional security algorithms for the security protection of messages, while utilizing the techniques described herein to protect the privacy / confidentiality of messages, such as during the registration process.

[0068] Figure 3 An example server-initiated messaging flow 300 between an IoT server 210 and an IoT device 220 according to various aspects of this disclosure is illustrated. The messaging flow 300 can implement various aspects of this disclosure described herein. For example, the messaging flow 300 may include an IoT server 210 and an IoT device 220, which may be examples of an IoT server and an IoT device as described herein. In the following description of the messaging flow 300, operations between the IoT server 210 and the IoT device 220 may be performed in different orders or at different times. Some operations may be omitted, or other operations may be added. Although the IoT server 210 and the IoT device 220 are shown performing operations of the messaging flow 300, some aspects of some operations may also be performed by other entities of the messaging flow 300, or by entities not shown in the messaging flow 300, or by any combination thereof.

[0069] First, in step 0 (e.g., prior to the initiation of this process), IoT server 210 stores or knows all relevant IoT devices, including IoT device 220, via stored device identifiers. As described herein, IoT device 220 can harvest energy to perform operations.

[0070] In step 1, IoT server 210 begins establishing a secure association with IoT device 220, which is identified using a specific device ID. IoT server 210 generates a current number, which can be a random number, random string, etc., with a minimum length to ensure an acceptable level of uniqueness among devices associated with IoT server 210.

[0071] The IoT server 210 generates a hash based on the concatenation of the device ID and the current count, where the output hash = hash(device ID + current count). The output hash can also be based on the length of the current count and the root key. The output hash can be generated using a hash function or a KDF, as described in this document.

[0072] In some cases, IoT server 210 may use the complete output hash as the encryption key K. In other cases, IoT server 210 may truncate the output hash and use either its most significant bit or least significant bit as the encryption key K, where the remaining bits represent a temporary ID used for addressing purposes, as described herein. In these cases, the remaining bits may have a sufficient or minimum length based on the number of active IoT devices in the service area of ​​IoT server 210 (e.g., when there are a large number of devices, the length of the temporary ID may be larger to avoid multiple IoT devices being addressed using the same temporary ID).

[0073] Figure 4 An example representation of the output hash 400 according to various aspects of this disclosure is illustrated. As shown, the output hash 400 is concatenated with a first portion 410 (most significant bit) representing a temporary identifier and a second portion 420 (least significant bit) representing the encryption key K. Therefore, the output hash 400 is truncated using the least significant bit representing the key K.

[0074] In step 2, the IoT server 210 encrypts the device ID using an encryption key K (as a temporary identifier) ​​and a configured encryption algorithm. Alternatively, the IoT device 220 uses a temporary ID corresponding to the remainder of the output hash of the encryption key K.

[0075] In step 3, IoT server 210 sends an initial registration request message to IoT device 220. This request includes or contains a current count and a temporary ID. As described herein, to limit the number of IoT devices receiving the request (and performing a hash operation), the device profile in IoT server 210 may store the initial temporary device ID as device profile information for one-time use during the initial registration of all devices, and / or may broadcast the request to a subset of IoT devices, as described herein.

[0076] In step 4, IoT device 220 (and possibly other devices) receives an initial registration request from IoT server 210. IoT device 220 calculates or otherwise determines an encryption key K and a temporary ID, as described herein, such as a hash and current number via the device ID (and optionally, the length of the current number and / or the root key).

[0077] IoT device 220 calculates or otherwise determines a temporary ID. For example, IoT device 220 uses a key K to encrypt the device ID, or uses a temporary identifier when key K is a truncated hash. IoT device 220 compares the determined temporary ID with a received temporary ID, and when the compared temporary IDs match, IoT device 220 confirms that it has been successfully located by IoT server 210, and can send the comparison result to IoT server 210.

[0078] As described herein, IoT server 210 may broadcast an initial registration request to multiple devices, such as when there is no direct addressing for IoT device 220. Each device (e.g., a subset of devices) may perform the process described in step 4, or may skip the process if it has already registered with IoT server 210.

[0079] In step 5, IoT device 220 sends an initial registration response message to IoT server 210, which includes or contains the comparison result and the determined temporary ID. However, if the temporary identifiers do not match, IoT device 220 may not send a response message. In this case, IoT device 220 registers with IoT server 210 and may avoid performing additional comparisons for a specific period of time (e.g., tracked by a registration timer).

[0080] In some cases, IoT device 220 may send other or additional information, such as device capabilities and security capabilities, to IoT server 210 via response messages. IoT device 220 may use key K to encrypt the additional information.

[0081] In step 6, IoT server 210 receives a response message. IoT server 210 stores or otherwise marks IoT device 220 as registered. Furthermore, if the response message includes information indicating security capabilities, IoT server 210 may send a second request message to establish a secure association (e.g., using a stronger key), thereby exchanging information with confidentiality protection.

[0082] As described herein, in some embodiments, IoT device 220 may initiate a registration process with IoT server 210. Figure 5The illustration depicts an example device-initiated messaging flow 500 between an IoT server 210 and an IoT device 220 according to various aspects of this disclosure. The messaging flow 500 can implement various aspects of this disclosure described herein. For example, the messaging flow 500 may include an IoT server 210 and an IoT device 220, which may be examples of an IoT server and an IoT device as described herein. In the following description of the messaging flow 500, operations between the IoT server 210 and the IoT device 220 may be performed in different orders or at different times. Some operations may also be omitted, or other operations may be added. Although the IoT server 210 and the IoT device 220 are shown performing operations of the messaging flow 500, some aspects of some operations may also be performed by other entities of the messaging flow 500, or by entities not shown in the messaging flow 500, or by any combination thereof.

[0083] In some respects, message flow 500 may be similar to message flow 300. For example, in step 0 (e.g., prior to the initiation of the process), IoT server 210 stores or knows all relevant IoT devices, including IoT device 220, via stored device identifiers. As described herein, IoT device 220 may harvest energy to perform operations.

[0084] In step 1, IoT device 220 initiates an establishment process to establish a secure association with IoT server 210. IoT device 220 generates a current count, as described herein. Using the current count, IoT device 220 generates a hash based on a concatenation of its associated device identifier and the current count (as described herein), where the hash is generated as output hash = hash(device ID + current count).

[0085] In step 2, IoT device 220 encrypts its associated device identifier using encryption key K and a configured encryption algorithm, which generates a temporary identifier. In some cases, when key K is a truncated hash, IoT device 220 uses a temporary ID corresponding to the remainder of the output hash of encryption key K.

[0086] In step 3, IoT device 220 sends an initial registration request message to IoT server 210. This request includes or contains a current number and a temporary ID. As described herein, the request message may include an initial temporary device identifier, which the IoT server can use to identify IoT device 220.

[0087] In some cases, IoT device 220 can send other or additional information, such as device capabilities and security capabilities, to IoT server 210 via request messages. IoT device 220 can use key K to decrypt the additional information.

[0088] In step 4, IoT server 210 receives an initial registration request. As described herein, IoT device 220 calculates or otherwise determines an encryption key K and a temporary ID, such as a hash and current number of the device ID (and optionally, the length of the current number and / or the root key).

[0089] For a device ID, IoT server 210 selects a profile corresponding to the temporary device ID (if available), selects all unregistered devices belonging to a specified category (e.g., one after another), or selects all unregistered devices.

[0090] IoT device 220 calculates or otherwise determines a temporary ID. For example, IoT device 220 uses a key K to encrypt the device ID, or uses a temporary identifier when key K is a truncated hash. IoT device 220 compares the determined temporary ID with a received temporary ID, and when the compared temporary IDs match, IoT device 220 confirms that it has been successfully located by IoT server 210, and can send the comparison result to IoT server 210.

[0091] When several device IDs are part of a category, or when all device IDs are possible devices, the IoT server 210 repeats the calculation until the calculated temporary ID corresponds to the received temporary ID. Then, the IoT device associated with the matching temporary ID is registered to the IoT server 210.

[0092] In step 5, the IoT server 210 sends an initial registration response message (which includes the result of a comparison of the temporary ID) and the temporary ID. Based on the information received via the request message, the IoT server 210 can send additional information to establish a secure association (e.g., using a stronger key), thereby exchanging information with confidentiality protection.

[0093] In various embodiments, the sender (e.g., IoT device 220 or IoT server 210) can initiate a key refresh at any time, such as by calculating a new present number, a new temporary ID2, and a new encryption key K2. The sender sends the new present number (encrypted using the old encryption key K) to the receiver (e.g., another of IoT device 220 or IoT server 210) by addressing the receiver using the old temporary ID. The receiver decrypts the present number 2 and uses the decrypted present number 2 to calculate a new temporary ID2 and encryption key K2. The receiver then sends a response message using the new temporary ID2 and a potential message encryption with the new encryption key K2.

[0094] In some cases, the sender and / or receiver may use additional input parameters, and optionally, parameter length, as input to a hash function or KDF. These parameters may include timers, counters, other current numbers, random numbers, device-specific parameters, etc.

[0095] Figure 6 An example of a UE 600 according to various aspects of this disclosure is illustrated. UE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, memory 604, controller 606, or transceiver 608, or various combinations thereof, or various components thereof, may be examples of parts for performing various aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operational ground, communication ground, functional ground, electronic ground, electrical ground).

[0096] Processor 602, memory 604, controller 606 or transceiver 608, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof, configured or otherwise supporting components for performing the functions described in this disclosure.

[0097] Processor 602 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some implementations, processor 602 may be configured to operate memory 604. In some other implementations, memory 604 may be integrated into processor 602. Processor 602 may be configured to execute computer-readable instructions stored in memory 604 to cause UE 600 to perform various functions of this disclosure.

[0098] Memory 604 may include volatile or non-volatile memory. Memory 604 may store computer-readable, computer-executable code, including instructions that, when executed by processor 602, cause UE 600 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as memory 604 or another type of memory. Computer-readable media include both non-transitory computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0099] In some implementations, processor 602 and memory 604 coupled to processor 602 may be configured to cause UE 600 to perform one or more functions described herein (e.g., processor 602 executes instructions stored in memory 604). For example, according to the examples disclosed herein, processor 602 may support wireless communication at UE 600. UE 600 may be configured to support components for generating a temporary identifier based on the current number and the UE's device identifier, and for sending a registration request message including the current number and the temporary identifier to a network entity.

[0100] UE 600 may also be configured to support components for receiving a registration request from a network server, including a current number and a temporary identifier; components for comparing the temporary identifier received via the registration request with a generated temporary identifier; and components for sending a response message to the network server when the comparison indicates a match between the temporary identifier received via the registration request and the generated temporary identifier, the response message indicating a match between the temporary identifier and the generated temporary identifier.

[0101] Controller 606 can manage the input and output signals of UE 600. Controller 606 can also manage peripheral devices not integrated into UE 600. In some implementations, controller 606 can utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, controller 606 can be implemented as part of processor 602.

[0102] In some implementations, UE 600 may include at least one transceiver 608. In other implementations, UE 600 may have more than one transceiver 608. Transceiver 608 may represent a wireless transceiver. Transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.

[0103] Receiver chain 610 can be configured to receive signals (e.g., control information, data, packets) via a wireless medium. For example, receiver chain 610 may include one or more antennas for receiving signals over the air or via a wireless medium. Receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 610 may include at least one demodulator configured to demodulate the received signal and acquire transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 610 may include at least one decoder for decoding the demodulated signal to receive transmitted data.

[0104] Transmitter chain 612 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal to prepare the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0105] Figure 7 An example of a processor 700 according to various aspects of this disclosure is illustrated. Processor 700 may be an example of a processor configured to perform various operations according to the examples described herein. Processor 700 may include a controller 702 configured to perform various operations according to the examples described herein. Processor 700 may optionally include at least one memory 704, which may be, for example, an L1 / L2 / L3 cache. Additionally or alternatively, processor 700 may optionally include one or more arithmetic logic units (ALUs) 706. One or more of these components may be electronically communicated or otherwise coupled (e.g., operative ground, communicative ground, functional ground, electronic ground, electrical ground) via one or more interfaces (e.g., buses).

[0106] Processor 700 may be a processor chipset and includes a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receive, acquire, retrieve, send, output, forward, store, determine, identify, access, write, read) according to the examples described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to the processor chipset or included in the processor chipset (e.g., processor 700)) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc.).

[0107] Controller 702 can be configured to manage and coordinate various operations of processor 700 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, and reading) to enable processor 700 to support various operations of the UE according to the examples described herein. For example, controller 702 can operate as a control unit of processor 700 to generate control signals for managing the operation of various components of processor 700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory accesses, and coordinating operation timing.

[0108] Controller 702 can be configured to fetch (e.g., fetch, retrieve, receive) instructions from memory 704 and determine subsequent instructions(s) to be executed, enabling processor 700 to support various operations according to the examples described herein. Controller 702 can be configured to track the memory addresses of instructions associated with memory 704. Controller 702 can be configured to decode instructions to determine the operations to be performed and the operands involved. For example, controller 702 can be configured to interpret instructions and determine control signals to be output to other components of processor 700, enabling processor 700 to support various operations according to the examples described herein. Additionally or alternatively, controller 702 can be configured to manage data flow within processor 700. Controller 702 can be configured to control data transfers between registers, arithmetic logic unit (ALU), and other functional units of processor 700.

[0109] Memory 704 may include one or more caches (e.g., memory or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc., local to or included in processor 700). In some implementations, memory 704 may reside within or on the processor chipset (e.g., local to processor 700). In some other implementations, memory 704 may reside outside the processor chipset (e.g., remote from processor 700).

[0110] Memory 704 may store computer-readable, computer-executable code, including instructions that, when executed by processor 700, cause processor 700 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. Controller 702 and / or processor 700 may be configured to execute computer-readable instructions stored in memory 704 to cause processor 700 to perform various functions. For example, processor 700 and / or controller 702 may be coupled to or coupled to memory 704, and processor 700, controller 702, and memory 704 may be configured to perform the various functions described herein. In some examples, processor 700 may include multiple processors, and memory 704 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, which may be configured independently or jointly to perform the various functions described herein.

[0111] One or more ALU 706s can be configured to support a variety of operations as described in the examples herein. In some implementations, one or more ALU 706s may reside within or on a processor chipset (e.g., processor 700). In some other implementations, one or more ALU 706s may reside outside the processor chipset (e.g., processor 700). One or more ALU 706s can perform one or more calculations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU 706s can receive input operands and an opcode that determines the operation to be performed. One or more ALU 706s are configured with various logic and arithmetic circuitry, including adders, subtractors, shifters, and logic gates, to process and manipulate data according to the operations. Alternatively or concurrently, one or more ALU 706s may support logical operations such as AND, OR, XOR, NOR, and NAND, enabling one or more ALU 706s to handle conditional operations, comparisons, and bitwise operations.

[0112] Based on the examples disclosed herein, processor 700 can support wireless communication. Processor 700 can be configured or operable to support components for generating an output hash based on the current number and the UE's device identifier, components for generating a temporary identifier based on the current number and the device identifier, and components for sending a registration request message including the current number and the temporary identifier to a network entity.

[0113] The processor 700 may also be configured to support components for receiving a registration request from a network server, including a current number and a temporary identifier, components for comparing the temporary identifier received via the registration request with a generated temporary identifier, and components for sending a response message to the network server indicating a match between the temporary identifier received via the registration request and the generated temporary identifier when the comparison indicates a match between the temporary identifier received via the registration request and the generated temporary identifier.

[0114] Figure 8 An example of an NE 800 according to various aspects of this disclosure is illustrated. The NE 800 may include a processor 802, a memory 804, a controller 806, and a transceiver 808. The processor 802, memory 804, controller 806, or transceiver 808, or various combinations thereof, or various components thereof, may be examples of parts for performing various aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operational ground, communication ground, functional ground, electronic ground, electrical ground).

[0115] Processor 802, memory 804, controller 806, or transceiver 808, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof, configured or otherwise supporting components for performing the functions described in this disclosure.

[0116] Processor 802 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some implementations, processor 802 may be configured to operate memory 804. In some other implementations, memory 804 may be integrated into processor 802. Processor 802 may be configured to execute computer-readable instructions stored in memory 804 to cause NE 800 to perform various functions of this disclosure.

[0117] Memory 804 may include volatile or non-volatile memory. Memory 804 may store computer-readable, computer-executable code, including instructions that, when executed by processor 802, cause NE 800 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as memory 804 or another type of memory. Computer-readable media include both non-transitory computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0118] In some implementations, processor 802 and memory 804 coupled to processor 802 may be configured such that NE 800 performs one or more functions described herein (e.g., processor 802 executes instructions stored in memory 804). For example, according to the examples disclosed herein, processor 802 may support wireless communication at NE 800. NE 800 may be configured to support components for selecting UEs not registered with a network entity, components for generating a current count based on the device identifier of the selected UE, and also components for generating a temporary identifier based on the current count and the device identifier, and components for sending a registration request message including the current count and the temporary identifier to the selected UE for registration with a network entity.

[0119] Controller 806 manages the input and output signals of NE 800. Controller 806 can also manage peripheral devices not integrated into NE800. In some implementations, controller 806 can utilize operating systems such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, controller 806 can be implemented as part of processor 802.

[0120] In some implementations, NE 800 may include at least one transceiver 808. In other implementations, NE 800 may have more than one transceiver 808. Transceiver 808 may represent a wireless transceiver. Transceiver 808 may include one or more receiver chains 810, one or more transmitter chains 812, or a combination thereof.

[0121] Receiver chain 810 can be configured to receive signals (e.g., control information, data, packets) via a wireless medium. For example, receiver chain 810 may include one or more antennas for receiving signals over the air or via a wireless medium. Receiver chain 810 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 810 may include at least one demodulator configured to demodulate the received signal and acquire transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 810 may include at least one decoder for decoding the demodulated signal to receive transmitted data.

[0122] Transmitter chain 812 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 812 may include at least one modulator for modulating data onto a carrier signal to prepare the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 812 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 812 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0123] Figure 9 A flowchart illustrating a method according to various aspects of this disclosure is shown. The operation of this method can be implemented by a UE as described herein. In some implementations, the UE can execute a set of instructions to control the functional elements of the UE to perform the described functions.

[0124] At 902, the method may include generating a temporary identifier based on the current number and the UE's device identifier. The operation of 902 can be performed according to the examples described herein. In some implementations, aspects of the operation of 902 may be derived from references... Figure 6 The UE is used to execute this.

[0125] At position 904, the method may include sending a registration request message to the network entity, including a current number and a temporary identifier. The operation of position 904 can be performed according to the examples described herein. In some implementations, aspects of the operation of position 904 can be found in the references. Figure 6 The UE is used to execute this.

[0126] It should be noted that the method described in this paper describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are also possible.

[0127] Figure 10 A flowchart illustrating a method according to various aspects of this disclosure is shown. The operation of this method can be implemented by a NE as described herein. In some implementations, the NE can execute an instruction set to control its functional elements to perform the described functions.

[0128] At point 1002, the method may include selecting a UE that is not registered with a network entity. The operation at point 1002 can be performed according to the examples described herein. In some implementations, aspects of the operation at point 1002 may be derived from references. Figure 8 The NE is used to execute this.

[0129] At step 1004, the method may include generating a current number based on the device identifier for the selected UE, and also generating a temporary identifier based on the current number and the device identifier. The operation at step 1004 can be performed according to the examples described herein. In some implementations, aspects of the operation at step 1004 may be derived from references... Figure 8 The NE is used to execute this.

[0130] At point 1006, the method may include sending a registration request message, including a current number and a temporary identifier, to the selected UE for registration with a network entity. The operation at point 1006 can be performed according to the examples described herein. In some implementations, aspects of the operation at point 1006 may be derived from references... Figure 8 The NE is used to execute this.

[0131] It should be noted that the method described in this paper describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are also possible.

[0132] Figure 11 A flowchart illustrating a method according to various aspects of this disclosure is shown. The operation of this method can be implemented by a UE as described herein. In some implementations, the UE can execute a set of instructions to control the functional elements of the UE to perform the described functions.

[0133] At 1102, the method may include receiving a registration request from a network server, including a current number and a temporary identifier. The operation at 1102 can be performed according to the examples described herein. In some implementations, aspects of the operation at 1102 may be derived from references... Figure 6 The UE is used to execute this.

[0134] At step 1104, the method may include generating an output hash using a device identifier associated with the processor and a current number from the registration request. The operation at step 1104 can be performed according to the examples described herein. In some implementations, aspects of the operation at step 1104 can be derived from references... Figure 6 The UE is used to execute this.

[0135] At 1106, the method may include generating a temporary identifier using the device identifier associated with the processor and the output hash of the current number from the registration request. The operation at 1106 can be performed according to the examples described herein. In some implementations, aspects of the operation at 1106 can be derived from references... Figure 6 The UE is used to execute this.

[0136] At 1108, the method may include comparing a temporary identifier received via a registration request with a generated temporary identifier. The operation at 1108 can be performed according to the examples described herein. In some implementations, aspects of the operation at 1108 may be derived from references... Figure 6 The UE is used to execute this.

[0137] At 1110, the method may include sending a response message to a network server indicating a match between the temporary identifier received via the registration request and the generated temporary identifier, the response message indicating a match between the temporary identifier and the generated temporary identifier. The operation of 1110 can be performed according to the examples described herein. In some implementations, aspects of the operation of 1110 may be derived from references... Figure 6 The UE is used to execute this.

[0138] It should be noted that the method described in this paper describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are also possible.

[0139] The description provided herein is intended to enable those skilled in the art to make or use this disclosure. Various modifications to this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but should be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A network entity for wireless communication, comprising: At least one memory; as well as At least one processor, coupled to the at least one memory, and configured such that the network entity: Select a user equipment (UE) that has not registered with the network entity; A random number is generated based on the device identifier of the selected UE, and a temporary identifier is also generated based on the current number and the device identifier; as well as A registration request message, including the current number and the temporary identifier, is sent to the selected UE for registration with the network entity.

2. The network entity of claim 1, wherein the at least one processor is further configured to cause the network entity to: A response message is received from the selected UE, the response message including the temporary identifier and an indication that the temporary identifier received from the network entity matches a corresponding temporary identifier stored in the selected UE.

3. The network entity of claim 2, wherein the at least one processor is further configured to cause the network entity to: In response to the match between the temporary identifier generated by the network entity and the corresponding temporary identifier stored by the selected UE, the selected UE is registered.

4. The network entity of claim 1, wherein the at least one processor is further configured to cause the network entity to: Generate a hash based on the current number and the device identifier; and The hash is truncated to generate a security key K, which is used to encrypt the device identifier to derive the temporary identifier. The temporary identifier therein corresponds to the remaining bits of the hash.

5. The network entity of claim 4, wherein the at least one processor is further configured to cause the network entity to: A response message is received from the selected UE, the response message including the temporary identifier, an indication that the temporary identifier received from the network entity matches a corresponding temporary identifier stored in the selected UE, and one or more parameters encrypted by the security key K; and Decrypt one or more parameters using the security key K.

6. The network entity of claim 1, wherein the network entity is an Internet of Things (IoT) server and the UE is an environmentally powered IoT device.

7. The network entity of claim 1, wherein the at least one processor is configured to cause the network entity to generate the hash using the current number and the device identifier.

8. The network entity of claim 1, wherein the at least one processor is configured such that the network entity uses the current number, the device identifier, the length of the current number, and the root key to generate the hash.

9. The network entity of claim 8, wherein the at least one processor is configured to cause the network entity to generate the hash as the output of a hash function using one or more parameters, the one or more parameters including the device identifier, a random number, or time information.

10. The network entity of claim 9, wherein the present number is the truncated output of the hash function.

11. The network entity of claim 8, wherein the at least one processor is configured to cause the network entity to generate the hash based on one or more parameters, the one or more parameters including random numbers, time information, timers, counters, or additional current numbers.

12. The network entity of claim 1, wherein the hash comprises: This represents the most significant bit of the temporary identifier; as well as This represents the least significant bit of the security key K.

13. The network entity of claim 1, wherein the hash comprises: The least significant bit of the temporary identifier; as well as This represents the most significant bit of the security key K.

14. A user equipment (UE) for wireless communication, comprising: At least one memory; as well as At least one processor, coupled to the at least one memory, and configured such that the UE: Generate a temporary identifier based on the current number and the device identifier of the UE; and Send a registration request message to the network entity, including the current number and the temporary identifier.

15. The UE of claim 14, wherein the at least one processor is further configured such that the UE: Receive a response message including the temporary identifier from the network entity.

16. The UE of claim 14, wherein the temporary identifier is a truncated portion of the output hash of the current number and the device identifier.

17. The UE of claim 14, wherein the at least one processor is configured to cause the UE to generate a security key K, the security key K being used to encrypt the device identifier to derive the temporary identifier.

18. A processor for wireless communication, comprising: At least one controller, coupled to at least one memory, and configured such that the processor: Receive a registration request from the web server, including the current number and a temporary identifier; The temporary identifier received via the registration request is compared with the generated temporary identifier; as well as When the comparison indicates that the temporary identifier received via the registration request matches the generated temporary identifier, a response message is sent to the network server indicating the match between the temporary identifier and the generated temporary identifier.

19. The processor of claim 18, wherein the at least one controller is further configured to cause the processor to: The output hash is generated using the device identifier associated with the processor and the current number from the registration request; and A temporary identifier is generated using the device identifier associated with the processor and the output hash of the current number from the registration request.

20. A method performed by an IoT (Internet of Things) device, the method comprising: Receive a registration request from the web server, including the current number and a temporary identifier; The output hash is generated using the device identifier for the IoT device and the current number from the registration request; A temporary identifier is generated using the device identifier for the IoT device and the current number from the registration request; The temporary identifier received via the registration request is compared with the generated temporary identifier; as well as When the comparison indicates that the temporary identifier received via the registration request matches the generated temporary identifier, a response message is sent to the network server indicating the match between the temporary identifier and the generated temporary identifier.