Authentication in a communication network environment with an environmental powered device

By exchanging identifiers between activator devices and ambient-powered devices and generating authorization tokens using access points, the security management issues of ambient-powered IoT devices in 5G networks are resolved, improving network efficiency and user convenience.

CN122122930APending Publication Date: 2026-05-29NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2024-11-12
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies have failed to effectively address the security management issues of environmentally powered IoT devices in 5G networks, particularly in the authentication and authorization process between IoT devices and access points, which impacts network efficiency and user convenience.

Method used

Secure communication between devices is ensured by exchanging identifiers between the activator device and the ambient power supply device, and by using access points to generate authorization tokens for authentication, combined with pre-configured keys and encryption technology.

Benefits of technology

It enables secure authentication of ambient-powered IoT devices in 5G networks, improving network efficiency and user convenience, and is applicable to various communication systems, including 5G and future networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122122930A_ABST
    Figure CN122122930A_ABST
Patent Text Reader

Abstract

In one non-limiting example, a method includes, at an activator device, selecting an environmental powered device from a plurality of environmental powered devices supportable by an access point. The method also includes sending, from the activator device to the selected environmental powered device, an identifier of the activator device and an identifier of the selected environmental powered device, where at least the identifier of the activator device is encrypted and sent to the selected environmental powered device in a request to activate the selected environmental powered device, and then receiving, at the activator device from the access point, an authorization token that can be used to authenticate the activator device and the selected environmental powered device for subsequent data. In some alternative examples, a freshness parameter can be used for encryption. In other alternative examples, an encryption key for the selected environmental powered device can be generated from a home network key set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This technical field generally relates to communication networks, and more specifically, but not exclusively, to security management in such communication networks. Background Technology

[0002] This section may help to facilitate a better understanding of aspects of the invention. Therefore, the statements in this section should be read in this light and should not be construed as an admission of what is prior art or what is not prior art.

[0003] While fourth-generation (4G) wireless mobile telecommunications technology, also known as Long Term Evolution (LTE) technology, was designed to provide high-capacity mobile multimedia and high data rates, especially for human interaction, fifth-generation (5G) technology is not only intended for human interaction but also for machine-type communication in so-called Internet of Things (IoT) networks.

[0004] More specifically, 5G networks are designed to enable large-scale IoT services (e.g., a very large number of limited-capacity devices) and mission-critical IoT services (e.g., requiring high reliability), while also providing improvements over traditional mobile communication services in the form of enhanced mobile broadband (eMBB) services, providing improved wireless internet access for mobile devices.

[0005] In the example communication system, user equipment (5G UE in a 5G network, or more broadly, UE) such as mobile terminals (subscribers) communicates with a base station or access point of the access network via an air interface, which is referred to as a 5G AN in a 5G network. An access point (e.g., a gNB) is illustratively part of the access network of the communication system.

[0006] For example, in 5G networks, the access network referred to as 5G AN is described in 5G Technical Specification (TS) 23.501, entitled "Technical Specification Group: Service and System Aspects; System Architecture of 5G Systems," and TS 23.502, entitled "Technical Specification Group: Service and System Aspects; Procedures for 5G Systems (5GS)," the disclosures of which are incorporated herein by reference in their entirety. Generally, an access point (e.g., a gNB) provides the UE with access to the core network (CN or 5GC), which in turn provides the UE with access to other UEs and / or data networks (e.g., packet data networks (e.g., the Internet)). TS 23.501 goes on to define a 5G Service-Based Architecture (SBA) that models services as network functions (NFs) that communicate with each other using a Representational State Transition Application Programming Interface (RESTful API). In addition, TS 33.501, entitled "Technical Specification Group Services and Systems Aspects; Security Architecture and Processes for 5G Systems," whose public content is incorporated herein by reference in its entirety, further describes the security management details associated with 5G networks.

[0007] However, in some cases, devices that are part of an IoT network, i.e., IoT devices, can be configured to communicate with UEs or other communication network devices for one or more purposes, such as data sharing, device programming, etc. One example use case involves so-called ambient IoT devices, which have little or no energy storage capacity and rely at least partially on their operating environment for power (i.e., ambient power). However, the security management issues associated with such ambient power IoT devices can pose significant challenges due to ongoing efforts to improve the architecture and protocols associated with 5G and future networks to enhance network efficiency and / or subscriber convenience. Summary of the Invention

[0008] The illustrative embodiments provide authentication technologies in communication network environments with environmental IoT capabilities.

[0009] In one illustrative embodiment, from the perspective of an activator device, a method includes: at the activator device, selecting an ambient power supply device from a plurality of ambient power supply devices, the plurality of ambient power supply devices being supported by an access point to which the activator device is connected. The method further includes: sending an identifier of the activator device and an identifier of the selected ambient power supply device from the activator device, wherein at least the identifier of the activator device is encrypted, and sent to the selected ambient power supply device in a request to activate the selected ambient power supply device. The method further includes: at the activator device, receiving an authorization token from the access point via the selected ambient power supply device, the authorization token being usable for subsequent data authentication of the activator device and the selected ambient power supply device.

[0010] In some illustrative embodiments, the freshness parameter can be used as an identifier for both the encryption activator device and the ambient power supply device.

[0011] In another illustrative embodiment, from the perspective of an ambient power supply device, a method includes: receiving an identifier of an activator device and an identifier of an ambient power supply device from an activator device at the ambient power supply device, the ambient power supply device being selected from a plurality of ambient power supply devices supported by an access point to which the ambient power supply device is connected, wherein at least the identifier of the activator device is encrypted in a request to activate the ambient power supply device. The method further includes: sending a request from the ambient power supply device to the access point to activate the ambient power supply device. The method further includes: receiving an authorization token from the access point at the ambient power supply device, the authorization token being usable for authenticating the ambient power supply device and the activator device for subsequent data. The method further includes: sending the authorization token from the ambient power supply device to the activator device.

[0012] In another illustrative embodiment, from the perspective of an access point, a method includes: receiving, at the access point, an identifier of an activator device and an identifier of an ambient power supply device from an ambient power supply device, wherein, in a request to activate the ambient power supply device, the ambient power supply device is selected from a plurality of ambient power supply devices supported by the access point, wherein at least the identifier of the activator device is encrypted. The method further includes: the access point authenticating the activator device and the ambient power supply device. The method further includes: the access point generating an authorization token in response to the authentication of the ambient power supply device and the activator device, the authorization token being usable for authenticating the ambient power supply device and the activator device for subsequent data. The method further includes: sending the authorization token from the access point to the ambient power supply device and the activator device.

[0013] In other illustrative embodiments, keys can be generated for selected ambient power devices from one or more sets of keys (e.g., one or more access stratum keys) associated with the home network of the activator device, and used to encrypt data from the activator device.

[0014] Other illustrative embodiments are provided in the form of a non-transient computer-readable storage medium containing executable program code that, when executed by a processor, causes the processor to perform the steps described above. Other illustrative embodiments include an apparatus having a processor and memory configured to perform the steps described above.

[0015] Advantageously, the illustrative embodiments provide authentication techniques for communication network environments with AIoT capabilities.

[0016] These and other features and advantages of the embodiments described herein will become more apparent from the accompanying drawings and the following detailed description. Attached Figure Description

[0017] Figure 1 A communication network environment in which one or more illustrative embodiments can be implemented is shown.

[0018] Figure 2 Devices and entities that can implement one or more illustrative embodiments are shown.

[0019] Figure 3 An authentication process in a communication network environment with environmental IoT functionality is illustrated according to an illustrative embodiment.

[0020] Figure 4A and Figure 4C An authentication process with environmental IoT functionality is illustrated according to another illustrative embodiment.

[0021] Figure 5 An authentication process in a communication network environment with environmental IoT functionality is illustrated according to yet another illustrative embodiment. Detailed Implementation

[0022] This document will illustrate embodiments using example communication systems and related technologies for security management in communication systems. However, it should be understood that the scope of the claims is not limited to the specific type of communication system and / or process disclosed. Embodiments can be implemented using alternative processes and operations in a variety of other types of communication systems. For example, although illustrated in the context of a wireless cellular system utilizing 3GPP system elements (e.g., 3GPP Next Generation System (5G)), the disclosed embodiments are directly applicable to a variety of other types of communication systems, such as 6G communication systems.

[0023] Based on illustrative embodiments implemented in 5G or future communication system environments, one or more 3GPP Technical Specifications (TS) and Technical Reports (TRs) can provide further explanation of network elements / functions and / or operations that may interact with parts of the inventive solution, such as the aforementioned 3GPP TS 23.501, TS 23.502, and TS 33.501. Other 3GPP TS / TR documents can provide additional details that will be recognized by one of ordinary skill in the art. For example, TR 22.840, entitled "Technical Specification Group Service and System Aspects; Ambient Powered Internet of Things Research," the disclosure of which is incorporated herein by reference in its entirety, discloses some background details of IoT devices. Note that 3GPP TS / TR documents are non-limiting examples of communication network standards (e.g., specifications, processes, reports, requirements, recommendations, etc.). However, while well-suited to 3GPP standards related to 5G, embodiments are not necessarily intended to be limited to any particular standard.

[0024] It should be understood that the terms 5G network, etc. (e.g., 5G system, 5G communication system, 5G environment, 5G communication environment, etc.) in some illustrative embodiments may be understood to include all or part of the access network and all or part of the core network. However, the terms 5G network, etc. may sometimes be used interchangeably with the terms 5GC network, etc., without loss of generality, as any distinction will be understood by those skilled in the art.

[0025] Before describing illustrative embodiments, it will be stated below. Figure 1 and Figure 2 A general description of some of the key components of a 5G network within the context of [the context].

[0026] Figure 1 A communication system 100 in which illustrative embodiments are implemented is shown. It should be understood that the elements shown in the communication system 100 are intended to represent some of the main functions provided within the system, such as control plane functions, user plane functions, etc. Therefore, Figure 1 The box references shown provide specific elements in a 5G network for some of these main functions. However, other network elements can be used to implement all or part of the main functions represented. Furthermore, it should be understood that... Figure 1 This document does not depict all the functions of a 5G network. Instead, it shows at least some functions that facilitate the explanation of the illustrative embodiments. Subsequent figures may depict additional elements / functions (i.e., network entities).

[0027] Therefore, as shown in the figure, the communication system 100 includes a user equipment (UE) 102 that communicates with an access point 104 via an air interface. It should be understood that the UE 102 may communicate with a 5GC network using one or more other types of access points (e.g., access functions, networks, etc.) instead of a gNB. By way of example only, the access point 104 may be any 5G access network (gNB), an untrusted non-3GPP access network using non-3GPP interoperability (N3IWF), a trusted non-3GPP network using trusted non-3GPP gateway functionality (TNGF), or a wired access using wired access gateway functionality (W-AGF), or may correspond to a traditional access point (e.g., an eNB). Furthermore, the access point 104 may be a wireless local area network (WLAN) access point, as will be further explained in the illustrative embodiments described herein.

[0028] UE 102 may be a mobile station, and such a mobile station may include, for example, a mobile phone, a computer, or any other type of communication device. Therefore, the term "user equipment" as used herein is intended to be interpreted broadly to encompass various types of mobile stations, subscriber stations, or more generally, communication devices, including examples such as combinations of data cards inserted into a laptop computer or other device (e.g., a smartphone). Such communication devices are also intended to encompass devices commonly referred to as access terminals.

[0029] In one illustrative embodiment, UE 102 comprises a Universal Integrated Circuit Card (UICC) portion and a Mobile Equipment (ME) portion. The UICC is the user-related portion of the UE, containing at least one Universal Subscriber Identity Module (USIM) and appropriate application software. The USIM securely stores a persistent subscription identifier and its associated key for uniquely identifying and authenticating the subscriber for network access. The ME is the user-independent portion of the UE, containing Terminal Equipment (TE) functionality and various Mobile Terminal (MT) functions. Alternative illustrative embodiments may not use UICC-based authentication, for example, using a Non-Public (NPN) network.

[0030] Note that in one example, the permanent subscription identifier is the International Mobile Subscriber Identity (IMSI), which is unique to the UE. In one embodiment, the IMSI is a fixed 15-bit length, consisting of a 3-bit Mobile Country Code (MCC), a 3-bit Mobile Network Code (MNC), and a 9-bit Mobile Station Identifier (MSIN). In 5G communication systems, the IMSI is called the Subscription Permanent Identifier (SUPI). When the IMSI is used as the SUPI, the MSIN provides the subscriber identity. Therefore, typically only the MSIN portion of the IMSI needs to be encrypted. The MNC and MCC portions of the IMSI provide routing information used by the serving network to route to the correct home network. When the MSIN of the SUPI is encrypted, it is called the Subscription Hidden Identifier (SUCI). Another example of the SUPI uses the Network Access Identifier (NAI). NAIs are commonly used in IoT communications.

[0031] Furthermore, as shown in the figure, IoT device 103 communicates with access point 104 and UE 102 via an air interface. In an illustrative use case, as will be further described herein, IoT device 103 may be an Ambient IoT (AIoT) device, which, as will be further explained herein, may be a low-power device (i.e., an ambient-powered device). Although Figure 1 Only one UE102 and one IoT device 103 are shown in the diagram, but it should be understood that multiple UEs 102 and multiple IoT devices 103 can typically communicate with access point 104.

[0032] Access point 104 is illustratively a radio access network (RAN), or more simply an access network (AN), part of communication system 100. Such a radio access network may include, for example, a 5G system with multiple base stations. Components of the radio access network may be more generally considered as "radio access entities." In a non-limiting example, access point 104 may be referred to as a base transceiver unit (BTS).

[0033] Furthermore, in this illustrative embodiment, access point 104 is operatively coupled to access and mobility management function (AMF / SEAF) 106. In a 5G network, AMF / SEAF supports, among other things, mobility management (MM) and security anchor (SEAF) functions.

[0034] In this illustrative embodiment, AMF / SEAF 106 is operatively coupled to (e.g., using the following services) other network functions 108. As shown, these other network functions 108 include, but are not limited to, Unified Data Management (UDM) functions and Authentication Server Functions (AUSF). These listed examples of network functions are typically implemented in the UE subscriber's home network (HN), as explained further below. Note that in a 5GC network, the 4G functionality of the HSS (Home Subscriber Server) is split into AMF, UDM, and Unified Data Repository (UDR, not explicitly shown) functions. Typically, AMF authenticates the UE and provides any necessary encryption keys, while UDR stores user data, and UDM manages user data.

[0035] Other network functions 108 may include network functions that can act as service producers (NFp) and / or service consumers (NFc). Note that any network function can be a service producer of one service and a service consumer of another. Furthermore, when the service provided includes data, the NFp providing the data is called a data producer, and the NFc requesting the data is called a data consumer. A data producer can also be an NF that generates data by modifying or otherwise processing data produced by another NF. Note that an NF can, more generally, be considered a "network entity".

[0036] Note that a UE (such as UE 102) typically subscribes to a so-called Home Public Land Mobile Network (HPLMN, or HN for short), where some or all of the functions 106 and 108 reside. Alternatively, a UE (such as UE 102) may receive services from an NPN, where these functions may reside. The HPLMN is also known as the Home Environment (HE). If the UE is roaming (not in the HPLMN), it typically connects to an Access Public Land Mobile Network (VPLMN), also known as the Access Network, while the network currently providing services to the UE is also known as the Serving Network (SN). In roaming situations, some network functions 106 and 108 may reside in the VPLMN, in which case the functions in the VPLMN communicate with the functions in the HPLMN as needed. However, in non-roaming scenarios, Access and Mobility Management function 106 and other network functions 108 reside in the same communication network, i.e., the HPLMN. The embodiments described herein, unless otherwise stated, are not necessarily limited to which functions reside in which PLMN (i.e., HPLMN or VPLMN).

[0037] Access point 104 is also operatively coupled (via one or more of functions 106 and / or 108) to a Session Management Function (SMF) 110, which is operatively coupled to a User Plane Function (UPF) 112. UPF 112 is operatively coupled to a packet data network, such as the Internet 114. Note that in this diagram, the thicker solid line represents the user plane (UP) of the communication network, while the thinner solid line represents the control plane (CP) of the communication network. It should be understood that... Figure 1 The network (e.g., the Internet) 114 in the diagram may additionally or alternatively represent other network infrastructure, including but not limited to cloud computing infrastructure and / or edge computing infrastructure. Further typical operation and functionality of such network elements are not described herein, as they are not the focus of this illustrative embodiment and can be found in the appropriate 3GPP 5G documentation. Note that the functions shown in 106, 108, 110, and 112 are examples of network functions (NFs).

[0038] It should be understood that this particular arrangement of system elements is merely an example, and additional or alternative elements of other types and arrangements may be used to implement the communication system in other embodiments. For example, in other embodiments, the communication system 100 may include other elements / functions not explicitly shown herein.

[0039] therefore, Figure 1 The arrangement shown is just one example configuration for a wireless cellular system; numerous alternative configurations of system elements can be used. For example, although... Figure 1The examples illustrate only a single element / function, but this is merely for the sake of simplicity and clarity. Alternative embodiments may, of course, include a greater number of such system elements, as well as additional or alternative elements typically associated with conventional system implementations.

[0040] It should also be noted that, although Figure 1 While system elements are described as single functional blocks, the various subnetworks that make up a 5G network are divided into so-called network slices. A network slice (network partition) is a logical network that provides specific network capabilities and characteristics, can support corresponding service types, and optionally uses Network Function Virtualization (NFV) on a common physical infrastructure. Through NFV, network slices are instantiated according to the needs of a given service, such as eMBB services, large-scale IoT services, and mission-critical IoT services. Therefore, a network slice or function is instantiated when an instance of that network slice or function is created. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices in the underlying physical infrastructure. UE 102 is configured to access one or more of these services via access point 104.

[0041] Figure 2 This is a block diagram illustrating the computational architecture of each participant in a method according to an illustrative embodiment. More specifically, system 200 is shown as including device 202 and multiple entities 204-1, ..., 204-N. For example, in the illustrative embodiment and with reference to... Figure 1 Device 202 may represent UE 102 or IoT device 103, while entities 204-1, ..., 204-N may represent functions 106 and 108 (i.e., network entities) and access point 104 (i.e., radio access entity). It should be understood that device 202 and entities 204-1, ..., 204-N are configured to interact to provide security management and other technologies described herein.

[0042] Device 202 includes a processor 212 coupled to memory 216 and interface circuitry 210. The processor 212 of device 202 includes a security management processing module 214, which may be implemented at least partially as software executed by the processor. The security management processing module 214 performs security management, as described in conjunction with the following figures and other parts of this document. The memory 216 of device 202 includes a security management storage module 218 that stores data generated or otherwise used during security management operations.

[0043] Each entity (referred to herein individually or collectively as 204) includes a processor 222 (222-1, ..., 222-N) coupled to a memory 226 (226-1, ..., 226-N) and interface circuitry 220 (220-1, ..., 220-N). Each processor 222 of each entity 204 includes a security management processing module 224 (224-1, ..., 224-N), which may be implemented at least partially in the form of software executed by the processor 222. The security management processing module 224 performs security management operations, as described in conjunction with the following figures and other parts of this document. Each memory 226 of each entity 204 includes a security management storage module 228 (228-1, ..., 228-N) storing data generated or otherwise used during security management operations.

[0044] Processors 212 and 222 may include, for example, microprocessors such as central processing units (CPUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs) or other types of processing devices, as well as portions or combinations of such elements.

[0045] Memory 216 and 226 may be used to store one or more software programs executed by respective processors 212 and 222 to implement at least some of the functions described herein. For example, security management operations and other functions described in conjunction with the following figures and other parts of this document may be implemented in a direct manner using software code executed by processors 212 and 222.

[0046] One of memories 216 and 226 can therefore be considered as an example of what is more generally referred to herein as a computer program product or, more generally, as a processor-readable storage medium having executable program code embodied therein. Other examples of processor-readable storage media may include any combination of magnetic disks or other types of magnetic or optical media. Illustrative embodiments may include articles of manufacture containing such computer program products or other processor-readable storage media.

[0047] Furthermore, memory 216 and memory 226 may more specifically include, for example, electronic random access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memory such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM), or ferroelectric RAM (FRAM). The term "memory" as used herein is intended to be interpreted broadly and may additionally or alternatively encompass, for example, read-only memory (ROM), disk-based memory, or other types of storage devices, as well as portions or combinations of such devices.

[0048] Interface circuits 210 and 220 illustratively include transceivers or other communication hardware or firmware that allow associated system elements to communicate with each other in the manner described herein.

[0049] from Figure 2 It is evident that device 202 and multiple entities 204 are configured to communicate with each other as security management participants via their respective interface circuits 210 and 220. This communication involves each participant sending data to one or more other participants and / or receiving data from one or more other participants. The term "data" as used herein is intended to be interpreted broadly to encompass any type of information that can be sent between participants, including, but not limited to, identity data, key pairs, key indicators, tokens, secrets, security management messages, registration request / response messages and data, request / response messages, authentication request / response messages and data, metadata, control data, audio, video, multimedia, consent data, other messages, etc.

[0050] It should be understood that Figure 2 The specific arrangement of the components shown is merely an example, and numerous alternative configurations can be used in other embodiments. For example, any given network element / function and / or access point can be configured to include additional or alternative components and support other communication protocols.

[0051] Other system elements, such as access point 104, SMF 110, and UPF 112, can each be configured to include components such as processors, memory, and network interfaces. Furthermore, entities such as third-party applications and network operators can participate in the methods described herein via computing devices configured to include components such as processors, memory, and network interfaces. These elements and devices do not need to be implemented on separate, independent processing platforms, but can, for example, represent different functional portions of a single, common processing platform.

[0052] More generally, Figure 2 "Can be considered as representing processing devices configured to provide their respective security management functions and operatively coupled to each other in a communication system. By way of example only, all or part of each of the device 202 and the plurality of entities 204 (e.g., processors and memory) can be considered as examples of components for performing one or more operations, one or more steps, one or more functions, one or more processes, etc., as described herein."

[0053] As stated above, 3GPP TS 23.501 defines the 5GC network architecture as service-based, for example, service-based architecture (SBA). This document recognizes that when deploying different NFs, there may be many situations where an NF may need to interact with entities outside the SBA-based 5GC network (e.g., including corresponding PLMNs, such as HPLMNs and VPLMNs). Therefore, as used herein, the term "internal" illustratively refers to operations and / or communications within the SBA-based 5GC network (e.g., SBA-based interfaces), and the term "external" illustratively refers to operations and / or communications outside the SBA-based 5GC network (non-SBA interfaces).

[0054] In light of the above general description of certain characteristics of 5GC networks, the problems of existing security methods in communication network environments with environmental IoT capabilities, and the solutions proposed according to illustrative embodiments, will be described below.

[0055] Environmental IoT devices (e.g., IoT device 103) are typically either battery-free or have limited energy storage capabilities (e.g., using capacitors). Therefore, environmental IoT (AIoT) devices are typically powered by energy harvesting, for example, obtaining power from radio waves in the area surrounding the IoT device (i.e., the environment). Such devices may generally be referred to as environmentally powered devices.

[0056] Communication network environments with AIoT capabilities typically also employ a store-and-forward communication model. Store-and-forward communication is an operating mode of 5G systems, in which a single UE can collect and store information from AIoT devices and then forward that information to the 5GC.

[0057] In addition to existing IoT technologies already defined in 3GPP, such as NB-IoT / eMTC and NRRedCap, there is a need for ambient IoT to cover additional use cases that require more cost-effectiveness, energy efficiency, and especially battery-free functionality.

[0058] The number of AIoT devices in communication network environments is likely to increase significantly in the future, and their lifespan should exceed 5 years. Charging all AIoT devices or periodically replacing their batteries would be impractical due to the enormous human and material resources required.

[0059] Some example use cases for AIoT devices include, but are not limited to: (i) identification (ID) tags (e.g., replacing radio frequency ID (RFID) tags with a wider range); (ii) sensors (e.g., temperature, humidity, etc.); (iii) healthcare devices (e.g., monitoring personal medical information); and (iv) logistics (e.g., tracking objects).

[0060] Some system architecture components of a communication network environment with AIoT functionality include, but are not limited to: (i) an activator (also known as an illuminator), which is a device that sends an activation signal intended to wake up a passive AIoT device (more generally, an activator device); (ii) an AIoT device (e.g., a radio or tag, or more generally, an ambient-powered device); and (iii) a reader, which is a device that listens for and detects passive radio signals (note that the reader may be co-located with or separate from the activator).

[0061] There are various types of AIoT devices, including but not limited to the following three types: (i) Device type A (passive): A device that is completely battery-free, has no energy storage capacity, no independent signal generation / amplification capability (i.e., can only perform backscattering), and is completely dependent on the availability of an external energy source; (ii) Device Type B (Semi-passive): Devices with limited energy storage capacity, requiring no manual replacement or charging, and lacking independent signal generation capability, but may exhibit backscattering with reflection gain; and (iiii) Device type C (active): an active transmitting device with limited energy storage capacity based on an environmental energy source.

[0062] Various example AIoT device availability scenarios are envisioned, featuring different types of communication modes (operations). These modes may depend on the power available for communication, such as the availability of energy harvesting and storage capabilities, or specific use cases. Non-limiting example modes may include: (i) Normal Operation: In this scenario, the AIoT device has continuous or at least sufficient power available for a considerable period of time due to continuous power harvesting or possibly combined with limited energy storage (e.g., in capacitors) to overcome transient variations in power harvesting. The primary impact of this scenario is that the processor and communication modules within the AIoT device can be continuously active. The communication modules can periodically listen to the network to determine the presence of mobile termination services (e.g., trigger messages) and can send data when relevant.

[0063] (ii) Device-triggered operation: In this scenario, the device has available power only intermittently. The main impact of this scenario is that AIoT devices can only be active for short periods. The AIoT device decides when to communicate with the network. The AIoT device may not be able to listen to the network for mobile-terminated services for extended periods. This has implications for service aspects such as provisioning.

[0064] (iii) On-demand operation: In this scenario, the 5G network will wake up and trigger AIoT devices to communicate in a relevant manner. This scenario only considers network-triggered communication, and the AIoT device cannot determine when to communicate. Wake-up of the AIoT device can be combined with triggering the execution of a specific action (e.g., taking a measurement) or communication (e.g., sending an identifier). Wake-up can also mean that the AIoT device begins listening to the network for further instructions.

[0065] It should be understood that the scenario is not intended to define a device category, but rather to emphasize the service aspects associated with different scenarios.

[0066] While the exemplary use cases and descriptions above present some illustrative details of AIoT functionality (see also 3GPP TR 22.840 cited above), this document recognizes that existing AIoT functionality does not take into account the authentication (and authorization) of tags (i.e., AIoT devices) along with activators or illuminators (e.g., UEs).

[0067] The illustrative embodiments overcome the above-mentioned and other technical deficiencies of existing AIoT functions by providing authentication technology for communication network environments with AIoT capabilities.

[0068] Figure 3 A process 300 for authentication in a communication network environment with environmental IoT functionality, according to an illustrative embodiment, is illustrated. As shown, process 300 involves a first illuminator 302-1, a second illuminator 302-2, a first tag 304, a BTS 306 and an AMF 308 as part of a serving network 310 (e.g., an SN or VPLMN), and a UDM 312 as part of a home network 314 (e.g., an HN, HPLMN, or HE). It should be understood that, as above, the first illuminator 302-1 and the second illuminator 302-2 may also be referred to as activators, and in one or more illustrative embodiments may be UEs (e.g., UE#1 and UE#2). However, in alternative embodiments, one or more of the first illuminator 302-1 and the second illuminator 302-2 may be devices other than UEs, such as access network (AN) components, such as a BTS, or certain other network or independent components. The first tag 304 is identified as Tag ID#1. In this example, the BTS 306 is part of the gNB's receiver (RX).

[0069] Note that the first irradiator 302-1 and the second irradiator 302-2 may be more generally referred to as activator devices, the first tag 304 may be more generally referred to as an ambient power supply device, and the BTS 306 may be more generally referred to as an access point.

[0070] exist Figure 3In the illustrative embodiment, as will be further explained below, the HN, SN, and AN private keys are pre-configured in the gNB (BTS / RX 306), AMF 308, and UDM 312, respectively, and the HN, SN, and AN public keys are pre-configured in the first illuminator 302-1 and the second illuminator 302-2, respectively. In this example (and in the subsequent illustrative process), the illuminator, namely the first illuminator 302-1, encrypts the data using the HN public key and also provides the encrypted data to the TAG_ID (Tag ID#1) of the first tag 304. The authorization token is generated by the BTS 306 and shared with the first illuminator 302-1 via the first tag 304. The first tag 304 can store the authorization token for future verification, since any data from the first illuminator 302-1 is only forwarded to the BTS 306 if the authorization token matches. After the authorization token expires, the same process needs to be repeated to generate a new token.

[0071] Now for reference Figure 3 In process 300, during the pre-configuration phase: Step 1 (sub-steps 1.1, 1.2 and 1.3): The long-term keys for USIM#1 of UE#1 (first illuminator 302-1) and USIM#2 of UE#2 (second illuminator 302-2) are supplied in UDM312 and the corresponding first illuminator 302-1 and second illuminator 302-2 (UE#1 containing USIM#1 and UE#2 containing USIM#2).

[0072] Step 2 (sub-steps 2.1, 2.2 and 2.3): The HN 314 private key is available in UDM312, and the corresponding HN 314 public key is available in the first illuminator 302-1 and the second illuminator 302-2 (UE#1 and UE#2).

[0073] Step 3 (sub-steps 3.1, 3.2 and 3.3): The SN 310 private key and public key pair are generated and supplied, wherein the SN 310 private key is in AMF 308 and the SN 310 public key is in the first and second illuminators 302-1 and 302-2 (UE#1 and UE#2).

[0074] It should be understood that in some illustrative embodiments, the first tag 304 and the first illuminator 302-1 and the second illuminator 302-2 are not intended to be in a roaming scenario, but rather to be stationary entities so that they will be connected to the same service network, such as SN 310. However, alternative embodiments envision one or more of the first tag 304 and the first illuminator 302-1 and the second illuminator 302-2 being mobile.

[0075] Step 4 (substeps 4.1, 4.2, and 4.3): Similar to the key supply for HN 314 and SN 310, the key supply for the access network (including the AN of BTS 306) to which the first tag 304 and the first and second illuminators 302-1 and 302-2 are connected is the same. More specifically, the AN private key is supplied in BTS 306, and the AN public key is supplied in the corresponding first and second illuminators 302-1 and 302-2 (UE#1 and UE#2).

[0076] Step 5: Following the pre-configuration phase, a System Information Type 2 (SIB2) message is broadcast along with a list of Tag IDs supported by BTS306 and a public key ID. The public key ID is used to identify the corresponding HN, SN, and AN public keys in the respective USIMs of the first illuminator 302-1 and the second illuminator 302-2.

[0077] Continue with process 300, during the certification phase: Step 6 (Substeps 6.1a to 6.10): First illuminator 302-1 selects first tag 304 (6.1a). The HN public key is used to encrypt UE_ID#1 (6.1b). An initial access (activation) request is sent to first tag 304 in this message along with the encrypted UE_ID#1 and the plaintext TAG_ID#1 (6.2). First tag 304 forwards the same request to BTS 306 (6.3). BTS 306, together with AMF 308, checks with UDM 312 whether UE_ID#1 is a valid identity (6.4). If verification is successful, BTS 306 generates an authorization token (6.5). Note that in some illustrative embodiments, the AN private key can be used to protect the authorization token or any further communication between BTS 306 and first illuminator 302-1.

[0078] The first tag 304 receives the authorization token (6.6) and stores it for future verification (6.7). An initial response with the authorization token from the BTS 306 is forwarded by the first tag 304 to the first illuminator 302-1 (6.8). The authorization token is valid only for a limited time; after the timer expires, a new request is issued (6.9). The AN public key used to encrypt the data and the authorization token is sent from the first illuminator 302-1 to the first tag 304 (i.e., the first tag 304 verifies the authorization token against the expected authorization token), and if verification is successful, the data from the first illuminator 302-1 is sent to the BTS 306 (6.10).

[0079] Turn now Figure 4A The figure depicts a process 400 for authentication in a communication network environment with environmental IoT functionality, according to another illustrative embodiment. As shown, with... Figure 3 The process is similar to 300. Figure 4A The process 400 involves a first irradiator 302-1, a second irradiator 302-2, a first tag 304, a BTS 306 and an AMF 308 as part of SN 310, and a UDM 312 as part of HN 314.

[0080] In this illustrative embodiment, a symmetric key (such as an access layer (AS) key) is used to generate a new TAG key K. TAG An authorization token is also generated in this embodiment, but it is used only for the first tag 304 and not for the first irradiator 302-1. When data is generated by the first irradiator 302-1 using key K... TAG When encrypting and forwarding to First Label 304, First Label 304 adds the authorization token as an additional parameter along with the encrypted data. BTS 306 uses K. TAG The encrypted data and the MAC-I (Message Authentication Code for Integrity Protection) of the received data are verified. Additionally, the authorization token is verified. Thus, both the first illuminator 302-1 and the first tag 304 are verified.

[0081] As shown in process 400, during the integration authentication phase: Step 1 (sub-steps 1.1, 1.2, and 1.3): with Figure 3 Compared to process 300, only the long-term key for the USIM is supplied in the first illuminator 302-1 and UDM312. BTS 306 broadcasts a System Information Type 2 (SIB2) message containing a list of supported tag IDs.

[0082] Step 2 (sub-step 2.1): A registration request with TAG_ID#1 is requested by the first illuminator 302-1 (UE#1), and primary authentication is successful. NAS and AS security modes are completed.

[0083] Step 3 (sub-steps 3.1, 3.2, 3.3 and 3.4): After the Security Mode Command (SMC) procedure is completed, the KAUSF key is used to export the NAS and AS keys on the network side and the UE side.

[0084] Step 4 (sub-steps 4.1 and 4.2): Use the AS key, key K TAG It was generated in both the first irradiator 302-1 and BTS 306. Figure 4B An illustrative embodiment is shown for generating K. TAG The process 420. For K TAG In this illustrative embodiment, the key K is generated. gNB The key derivation function (KDF) is used together with two other parameters, TAG_ID and the length of TAG_ID, to generate K. TAG .

[0085] Continuing with process 400, in the data processing phase: Step 5 (Substeps 5.1 to 5.8): Data (initially, the data may only be TAG_ID#1) is processed using K. TAG Encryption and integrity protection are performed (5.1). The protected and secure data, along with the MAC-I, is sent to the first tag 304 in the initial request (5.2). Figure 4C An illustrative embodiment is shown for generating MAC-I (e.g., MAC-I). TAG The process 430. For the generation of MAC-I, in this illustrative embodiment, the newly generated key K TAG Together with the data from the first illuminator 302-1 and the length of the data, it was used by the New Radio Integrity Algorithm (NIA) to generate MAC-I. TAG Encryption protection is provided by the New Radio Encryption Algorithm (NEA) in conjunction with the NIA.

[0086] The first tag 304 forwards the initial request content along with the TAG_ID to BTS 306 (5.3). BTS checks whether the TAG_ID is allowed and whether it is authenticated. If it is an allowed TAG_ID, then K... TAG The received MAC-I is used to decrypt data and also to verify that it is the same as the expected MAC-I. If the MAC-I verification is successful, BTS 306 generates an authorization token (5.4). The generated authorization token is sent to the first tag 304 along with the result (ACK / NACK) (5.5). The first tag 304 stores the token for future verification (5.6). Only the result (ACK / NACK) is sent to the first illuminator 302-1 (5.7). Thereafter, the first illuminator 302-1 (UE#1) is allowed to perform tag programming (5.8), that is, UE#1 is allowed to program the first tag 304.

[0087] Figure 5 A process 500 in a communication network environment with environmental IoT functionality is illustrated according to yet another illustrative embodiment. As shown in the figure, with... Figure 3 The process is similar to 300. Figure 5 The process 500 involves a first irradiator 302-1, a second irradiator 302-2, a first tag 304, a BTS 306 and an AMF 308 as part of SN 310, and a UDM 312 as part of HN 314.

[0088] Figure 5The illustrative embodiment can be considered as an asymmetric key-based process with a freshness parameter. More specifically, since all UEs (302-1 and 302-2) can use the same public key of HN 314 to encrypt UE_ID, in this example, the freshness parameter, i.e., the newly generated random number RAND, is generated and used to encrypt UE_ID#n and encrypt Tag_ID#n. The plaintext RAND is also sent from the first illuminator 302-1 to the BTS 306. The first tag 304 adds its own plaintext TAG_ID along with the encrypted UE_ID#1 and encrypted TAG_ID#1 received from the first illuminator 302-1 and sends this information to the BTS 306 so that the BTS 306 can verify the information.

[0089] It should be understood that, in alternative embodiments, parameters other than RAND can be used as freshness parameters. As a further example only, the sequence number or SQN can be used as the encrypted freshness parameter. Therefore, the SQN can be maintained and incremented in the first illuminator 302-1, the second illuminator 302-2, and network entities such as BTS 306.

[0090] Process 500 prevents man-in-the-middle attacks. In the pre-configuration phase, steps 1 to 4 are the same as steps 1 to 4 of Process 300, and so is step 5. Then, in the authentication phase, step 6 (sub-steps 6.1a to 6.10) is the same as step 6 (sub-steps 6.1a to 6.10) of Process 300, with the following exceptions.

[0091] In sub-step 6.2 of process 500, the plaintext of the freshness parameter, such as plaintext RAND, is also sent from the first illuminator 302-1 to the first tag 304. In sub-step 6.3, as above, the first tag 304 adds its own plaintext TAG_ID along with the encrypted UE_ID#1 and encrypted TAG_ID#1 received from the first illuminator 302-1 and sends this information to the BTS 306. In sub-steps 6.4a and 6.4b, the BTS 306 verifies with the UDM 312 whether UE_ID#1 and TAG_ID#1 are valid so that the generation of the authorization token can continue. Then, sub-steps 6.5 to 6.10 are performed in the same manner as sub-steps 6.5 to 6.10 of process 300 described above.

[0092] In an alternative embodiment, a symmetric key-based process using a freshness parameter is used. Figure 5 The process is the same as 500. However, for TAG_ID protection, if the identifier TAG_ID#n is defined by a pre-shared key or a derived key (similar to the above for TAG_ID#n), the process will be different. Figure 4BThe process described in 400 (key generation) and RAND are encrypted in the first illuminator 302-1 and sent to the first tag 304. The first tag 304 also includes TAG_ID#n (plaintext) itself in the message sent to BTS 306. BTS 306 will then check, or make check, the decrypted TAG_ID#n and TAG_ID#n itself for verification.

[0093] Advantageously, the embodiments described and supported herein can be implemented in various ways and forms, such as, but not limited to, methods, systems, articles of manufacture, computer program products, devices, etc. As a further example only, embodiments may take the form of a means comprising at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the means to perform at least one or more functions.

[0094] For example, from the perspective of the activator device, the device may include at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the device to at least: select one of a plurality of devices, the plurality of devices being ambient powered and supported by an access point to which the device is connected; send an identifier of the device and an identifier of the selected device, wherein at least the identifier of the device is encrypted and sent to the selected device in a request to activate the selected device; and receive an authorization token from the access point via the selected device, the authorization token being used to authenticate the device and the selected device for subsequent data.

[0095] In some embodiments, the apparatus may also be configured to perform one or more of the following: receive a list identifying a plurality of devices; store a public key associated with a home network, an access network of an access point, and a serving network associated with the access network; receive a public key identifier to enable the apparatus to identify one or more of the home network, the serving network, and the access network; encrypt the identifier of the apparatus and the identifier of the selected device using a freshness parameter; and send the freshness parameter in plaintext, together with the encrypted identifier of the apparatus and the encrypted identifier of the selected device, in a request to activate the selected device.

[0096] In another illustrative embodiment, from the perspective of the activator device, the apparatus may include at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: select one device from a plurality of devices, the plurality of devices being ambient powered and supported by an access point to which the apparatus is connected; send a request to the home network for registering the selected device; generate a key for the selected device from one or more key sets associated with the home network; encrypt data using the key generated for the selected device; and send the encrypted data to the selected device in a request to activate the selected device.

[0097] Furthermore, for example, from the perspective of an ambient power supply device, the device may include at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the device to at least: receive from an activator device an identifier of the activator device and an identifier of the device, the identifier of the activator device and the identifier of the device in a request to activate the device, wherein at least the identifier of the activator device is encrypted, and wherein the device is an ambient power supply device among a plurality of ambient power supply devices that may be supported by an access point to which the device is connected; send a request to activate the device to the access point; receive an authorization token from the access point, the authorization token being usable for subsequent data, authenticating the device and the activator device; and send the authorization token to the activator device.

[0098] In some embodiments, the request received from the activator device may further include a freshness parameter in plaintext, which is used to encrypt the identifier of the activator device and the identifier of the apparatus. The apparatus may also be configured to add its identifier in plaintext to the request and send the request to the access point.

[0099] In another illustrative embodiment, from the perspective of an ambient power supply device, the device may include at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the device to at least: receive data from an activator device in a request to activate the device, wherein the data is encrypted using a key generated for the device from one or more key sets associated with the activator device's home network, and wherein the device is an ambient power supply device among a plurality of ambient power supply devices that may be supported by an access point to which the device is connected; add an identifier of the device to the request; send the request to the access point; receive confirmation from the access point that the device has been verified; and send confirmation to the activator device.

[0100] Furthermore, for example, from the perspective of the access point, the device may include at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the device to at least: receive an identifier of an activator device and an identifier of the ambient power supply device from an ambient power supply device; the ambient power supply device receives the identifier of the activator device and the identifier of the ambient power supply device in a request to activate the ambient power supply device, wherein the ambient power supply device is selected from a plurality of ambient power supply devices supported by the device, wherein at least the identifier of the activator device is encrypted; verify the activator device and the ambient power supply device; generate an authorization token in response to the verification of the ambient power supply device and the activator device, the authorization token being used to authenticate the ambient power supply device and the activator device for subsequent data; and send the authorization token to the ambient power supply device and the activator device.

[0101] In some embodiments, the request received from the ambient power supply device also includes a freshness parameter in plaintext, which is used for the identifier of the encryption activator device and the identifier of the ambient power supply device.

[0102] In another illustrative embodiment, from the perspective of the access point, the device may include at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the device to at least: receive data from an activator device in a request to activate the activator device, wherein the data is encrypted using a key generated from one or more key sets associated with the activator device's home network, and wherein the request also includes an identifier for the activator device; verify the activator device using the identifier; decrypt the encrypted data using the key for the activator device; and send an acknowledgment to the activator device.

[0103] As used herein, it should be understood that the term "communication network" in some embodiments may include two or more separate communication networks. Furthermore, the specific processing operations and other system functions described in conjunction with the figures herein are presented by way of illustrative example only and should not be construed as limiting the scope of this disclosure in any way. Alternative embodiments may use other types of processing operations and messaging protocols. For example, the order of steps may vary in other embodiments, or certain steps may be performed at least partially concurrently with each other rather than sequentially. Furthermore, one or more steps may be repeated periodically, or multiple instances of the method may be performed in parallel with each other.

[0104] It should be emphasized again that the various embodiments described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the claims. For example, alternative embodiments may utilize different communication system configurations, user equipment configurations, base station configurations, configuration and usage procedures, messaging protocols, and message formats than those described above in the context of the illustrative embodiments. These, as well as numerous other alternative embodiments within the scope of the appended claims, will be apparent to those skilled in the art.

Claims

1. An apparatus comprising: A component for selecting one device from a plurality of devices, said plurality of devices being ambient powered and supported by an access point to which said device is connected; A component for sending the identifier of the device and the identifier of the selected device, wherein at least the identifier of the device is encrypted and sent to the selected device in a request to activate the selected device; as well as A component for receiving an authorization token from the access point via a selected device, the authorization token being used to authenticate the device and the selected device for subsequent data.

2. The apparatus of claim 1, wherein the apparatus further comprises a component for receiving a list identifying the plurality of devices.

3. The apparatus of claim 1, wherein the apparatus further comprises a component for storing a public key associated with: a home network, an access network of the access point, and a service network associated with the access network.

4. The apparatus of claim 3, wherein the apparatus further comprises a component for receiving a public key identifier such that the apparatus can identify one or more of the following: the home network, the serving network, and the access network.

5. The apparatus according to claim 1, wherein the authorization token includes a time period, and a new authorization token needs to be generated after the time period expires.

6. The apparatus of claim 1, wherein the apparatus further comprises a component for encrypting an identifier of the apparatus and an identifier of the selected device using a freshness parameter.

7. The apparatus of claim 6, wherein the component for sending further comprises sending the freshness parameter in plaintext, together with the encrypted identifier of the apparatus and the encrypted identifier of the selected device, in the request for activating the selected device.

8. A method comprising: At the activator device, an environmental power supply device is selected from a plurality of environmental power supply devices, which may be supported by an access point to which the activator device is connected; The activator device sends an identifier of the activator device and an identifier of the selected ambient power supply device from the activator device, wherein at least the identifier of the activator device is encrypted and is sent to the selected ambient power supply device in a request to activate the selected ambient power supply device; as well as At the activator device, an authorization token is received from the access point via the selected ambient power supply device. The authorization token can be used for subsequent data authentication of the activator device and the selected ambient power supply device.

9. An apparatus comprising: A component for receiving an identifier of the activator device and an identifier of the device from an activator device, the identifier of the activator device and the identifier of the device being in a request to activate the device, wherein at least the identifier of the activator device is encrypted, and wherein the device is one of a plurality of ambient power devices supported by an access point to which the device is connected. Components for sending the request to activate the device to the access point; A component for receiving an authorization token from the access point, the authorization token being used to authenticate the device and the activator device for subsequent data; as well as Components used to send the authorization token to the activator device.

10. The apparatus of claim 9, wherein the request received from the activator device further includes a freshness parameter in plaintext, the freshness parameter being used to encrypt the identifier of the activator device and the identifier of the apparatus.

11. The apparatus of claim 10, wherein the apparatus further comprises: Components for adding the identifier of the device to the request in plaintext; as well as Components used to send the request to the access point.

12. A method comprising: The activator device receives an identifier of the activator device and an identifier of the ambient power supply device at the ambient power supply device, the ambient power supply device being selected from a plurality of ambient power supply devices supported by an access point to which the ambient power supply device is connected, wherein at least the identifier of the activator device is encrypted in a request to activate the ambient power supply device; Send the request to activate the ambient power supply device from the ambient power supply device to the access point; The ambient power supply receives an authorization token from the access point, the authorization token being used to authenticate the ambient power supply and the activator device for subsequent data; and The authorization token is sent from the environmental power supply device to the activator device.

13. An apparatus comprising: Components for receiving an identifier of an activator device and an identifier of the ambient power supply device from an ambient power supply device, wherein the identifier of the activator device and the identifier of the ambient power supply device are selected from a plurality of ambient power supply devices supported by the device in a request to activate the ambient power supply device, wherein at least the identifier of the activator device is encrypted; Components for verifying the activator device and the ambient power supply device; A component for generating an authorization token in response to verification of the ambient power supply device and the activator device, the authorization token being used to authenticate the ambient power supply device and the activator device for subsequent data; as well as Components for sending the authorization token to the ambient power supply device and the activator device.

14. The apparatus of claim 13, wherein the request received from the ambient power supply device further includes a freshness parameter in plaintext, the freshness parameter being used to encrypt the identifier of the activator device and the identifier of the ambient power supply device.

15. A method comprising: At the access point, the identifier of the activator device and the identifier of the environmental power supply device are received from the environmental power supply device. In the request to activate the environmental power supply device, the environmental power supply device is selected from a plurality of environmental power supply devices supported by the access point, wherein at least the identifier of the activator device is encrypted. The activator device and the ambient power supply device are verified by the access point; In response to verification by the ambient power supply device and the activator device, the access point generates an authorization token, which can be used to authenticate the ambient power supply device and the activator device for subsequent data; and The authorization token is sent from the access point to the environmental power supply equipment and the activator device.

16. An apparatus comprising: Components for selecting a device from a plurality of devices, said devices being ambient powered and supported by an access point to which the device is connected; Components used to send a request to the home network for the device to register the selected device; A component for generating a key for the selected device from one or more key sets associated with the home network; Components for encrypting data using the key generated for the selected device; as well as Components for sending encrypted data to the selected device in a request to activate the selected device.

17. The apparatus of claim 16, wherein the component for sending at least encrypted data to the selected device in the request for activating the selected device further includes sending a message authentication code in the request, the message authentication code being generated using the key for the selected device.

18. The apparatus of claim 16, wherein the one or more key sets associated with the home network include one or more access stratum keys.

19. The apparatus of claim 16, wherein the data is encrypted using a freshness parameter.

20. An apparatus comprising: Components for receiving data from an activator device in a request to activate the device, wherein the data is encrypted using a key generated for the device from one or more key sets associated with the home network of the activator device, and wherein the device is one of a plurality of ambient power devices that may be supported by an access point to which the device is connected. The component used to add the identifier of the device to the request; Components used to send the request to the access point; A component for receiving confirmation from the access point that the device has been verified; as well as A component used to send the confirmation to the activator device.

21. The apparatus of claim 20, further comprising a component for receiving an authorization token from the access point.

22. The apparatus of claim 20, wherein the component for receiving the encrypted data from the activator device in the request further includes receiving a message authentication code in the request, the message authentication code being generated using the key for the apparatus.

23. An apparatus comprising: Components for receiving data from an activator device from an ambient power supply device supported by the device, the data being in a request to activate the ambient power supply device, wherein the data is encrypted using a key generated for the ambient power supply device from one or more key sets associated with the home network of the activator device, and wherein the request also includes an identifier for the ambient power supply device. Used to verify components of the environmental power supply device using the identifier of the environmental power supply device; A component for decrypting the encrypted data using the key specified for the power supply equipment of the environment; as well as A component used to send confirmation to the environmental power supply equipment.

24. The apparatus of claim 23, further comprising a component for sending an authorization token to the ambient power supply device.

25. The apparatus of claim 23, wherein the component for receiving the encrypted data from the ambient power supply device in the request further includes receiving a message authentication code in the request, the message authentication code being generated using the key for the ambient power supply device.