Downlink message protection for environmental wireless devices
Patent Information
- Application Number
- CN202580010663.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-25
- Filing Date
- 2025-01-10
- Publication Date
- 2026-08-18
Smart Images

Figure CN122603532A_ABST
Abstract
Description
[0001] Cross-referencing
[0002] This patent application claims priority to U.S. Patent Application No. 18 / 423,096, filed January 25, 2024, entitled “DOWNLINK MESSAGE PROTECTION FOR AMBIENT WIRELESS DEVICES”, which is assigned to the assignee of this application and is expressly incorporated herein by reference. Technical Field
[0003] The following text relates to wireless communications, including downlink message protection for environmental wireless devices. Background Technology
[0004] Wireless communication systems are widely deployed to provide various types of communication content, such as voice, video, packet data, message sending and receiving, and broadcasting. These systems can support communication with multiple users by sharing available system resources (e.g., time, frequency, and power). Examples of such multiple access systems include fourth-generation (4G) systems (such as Long Term Evolution (LTE) systems, LTE-A Advanced (LTE-A) systems, or LTE-A Pro systems) and fifth-generation (5G) systems (which may be referred to as New Radio (NR) systems). These systems may employ technologies such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), or Discrete Fourier Transform Extended Orthogonal Frequency Division Multiplexing (DFT-S-OFDM). A wireless multiple access communication system may include one or more base stations, each supporting wireless communication for communication devices, which may be referred to as User Equipment (UE).
[0005] Some wireless communication systems may include environmental wireless devices (e.g., environmental Internet of Things (IoT) devices or tags) that provide one or more services, such as services involving tracking or indicating location. Wireless communication systems may also include application functions, environmental IoT controllers (or tag controllers), and / or user equipment (UEs) that can use one or more messages (such as one or more downlink messages) to facilitate configuring or communicating with environmental wireless devices (e.g., requesting service data). Summary of the Invention
[0006] The described technology relates to improved methods, systems, devices, and apparatuses for supporting downlink message protection for ambient wireless devices. Ambient wireless devices (e.g., ambient Internet of Things (IoT) devices or tags) can verify downlink messages, for example, received from a tag controller, which can generate and / or protect the downlink messages without establishing a secure connection with the tag controller. Downlink messages may include command messages or manifest messages, wherein command messages can be used to update configuration at the ambient wireless device and manifest messages can be used to trigger a response from the ambient wireless device.
[0007] In some examples, the application function may use a shared key shared with the ambient wireless devices to provide end-to-end protection for downlink messages (such as downlink command messages) transmitted through the tag controller. In some examples, the tag controller may use a command protection key provided by the application function to provide protection for downlink command messages, where the downlink message includes a command authentication token, which the ambient wireless devices use to authenticate the tag controller's authorization for the downlink command message. In some examples, the tag controller may use a command protection key provided by the application function to provide protection for the downlink command message and may use a signing key (e.g., a privacy key associated with a verification key or public key certificate) to sign the downlink command message. The verification key associated with the signing key may be used by the ambient wireless devices to verify the command protection key of the downlink command message. In some examples, the tag controller may use a command protection key generated by the tag controller to provide protection for the downlink command message. In some examples, the tag controller may provide downlink manifest messages to multiple ambient wireless devices, for example, in a multicast transmission. The tag controller may receive a manifest key from the application function, or the tag controller may derive the manifest key from a group key received from the application function. The tag controller can use a manifest key to protect downlink manifest messages, and the ambient wireless device can use the manifest key to authenticate downlink manifest messages and authorize the tag controller. The protection techniques described herein facilitate the effective protection of downlink messages sent from the network (e.g., via application functions of the network) to the ambient wireless device without having to establish a secure connection between the network and the ambient wireless device, such as one that is associated with complex processes and / or large amounts of storage space for storing authentication-related data.
[0008] A method for wireless communication by an ambient wireless device is described. The method may include: receiving a downlink message including a first configuration for the ambient wireless device associated with one or more services; enabling one or more services at the ambient wireless device based on the first configuration; receiving an encoded downlink message including a first key; decoding the encoded downlink message based on a second key, the encoded downlink message including a second configuration; and modifying one or more services or activating a response associated with the ambient wireless device based on the second configuration.
[0009] An ambient wireless device for wireless communication is described. The ambient wireless device may include one or more memories storing processor-executable code and one or more processors coupled to the one or more memories. The one or more processors may operate individually or collectively to execute code (e.g., directly, indirectly, after preprocessing, or without preprocessing), thereby enabling the ambient wireless device to: receive a downlink message including a first configuration for the ambient wireless device associated with one or more services; enable one or more services at the ambient wireless device based on the first configuration; receive an encoded downlink message including a first key; decode the encoded downlink message including a second configuration based on a second key; and modify one or more services or activate response transmission associated with the ambient wireless device based on the second configuration.
[0010] Another environmental wireless device for wireless communication is described. This environmental wireless device may include: components for receiving a downlink message including a first configuration of the environmental wireless device associated with one or more services; components for enabling one or more services at the environmental wireless device based on the first configuration; components for receiving an encoded downlink message including a first key; components for decoding the encoded downlink message based on a second key, the encoded downlink message including a second configuration; and components for modifying one or more services or activating response transmission associated with the environmental wireless device based on the second configuration.
[0011] A non-transitory computer-readable medium storing code for wireless communication is described. The code may include instructions executable by one or more processors (e.g., directly, indirectly, after preprocessing, or without preprocessing) to: receive a downlink message including a first configuration for an ambient wireless device associated with one or more services; enable one or more services at the ambient wireless device based on the first configuration; receive an encoded downlink message including a first key; decode the encoded downlink message including a second configuration based on a second key; and modify one or more services or activate response transmission associated with the ambient wireless device based on the second configuration.
[0012] The methods described herein, examples of environmental wireless devices, and non-transitory computer-readable media may also include operations, features, components, or instructions for receiving encoded downlink messages that may be sent based on changes to one or more configurations used for service, responses to requests from environmental wireless devices, or both.
[0013] In some examples of the methods, environmental wireless devices, and nontransitory computer-readable media described herein, the first key and the second key may be a single shared key between the environmental wireless device and the application functionality associated with the network entity.
[0014] In some examples of the methods, environmental wireless devices, and non-transitory computer-readable media described herein, the second key may be based on a shared key between the environmental wireless device and the application functionality associated with the network entity.
[0015] In some examples of the methods, environments, wireless devices, and non-transitory computer-readable media described herein, the second key may be associated with one or more key refresh parameters.
[0016] In some examples of the methods, environments, wireless devices, and non-transitory computer-readable media described herein, the encoded downlink messages also include tokens.
[0017] In some examples of the methods, ambient radio devices, and nontransitory computer-readable media described herein, receiving encoded downlink messages may include operations, features, components, or instructions for: receiving encoded downlink messages from an ambient radio controller associated with a network entity via one or more UEs; and verifying authorization for the ambient radio controller to send encoded downlink messages to the ambient radio device based on a token.
[0018] The methods described herein, examples of environmental wireless devices, and non-transitory computer-readable media may also include operations, features, components, or instructions for decoding encoded downlink messages based on the use of tokens to verify authorization to the environmental wireless controller.
[0019] In some examples of the methods, environmental wireless devices, and non-transitory computer-readable media described herein, the second key may be generated by an environmental wireless controller associated with a network entity.
[0020] In some examples of the methods, environments, wireless devices, and non-transitory computer-readable media described herein, the second key may be generated by application functions associated with network entities.
[0021] In some examples of the methods, ambient wireless devices, and nontransitory computer-readable media described herein, receiving an encoded downlink message may include operations, features, components, or instructions for: receiving an encoded downlink message from an ambient wireless controller associated with a network entity, wherein the encoded downlink message includes a signature; and verifying authorization for the ambient wireless controller to send the encoded downlink message to the ambient wireless device based on the signature.
[0022] In some examples of the methods, environments, wireless devices, and nontransitory computer-readable media described herein, the one or more services may be associated with location or tracking.
[0023] In some examples of the methods, environmental wireless devices, and nontransitory computer-readable media described herein, decoding an encoded downlink message may include operations, features, components, or instructions for decoding the encoded downlink message based on a second key and a third key, wherein the third key includes a group key associated with a set of multiple environmental wireless devices and the second key includes an inventory key associated with the environmental wireless devices.
[0024] In some examples of the methods, environments, wireless devices, and non-transitory computer-readable media described herein, the inventory key may be based on a group key.
[0025] A method for wireless communication by an ambient wireless controller is described. The method may include: receiving a message from an application function associated with a network entity; determining one or more protection applications to be applied to the message; applying the one or more protection applications to the message to obtain an encoded downlink message; and transmitting the encoded downlink message to one or more ambient wireless devices.
[0026] An environmental wireless controller for wireless communication is described. The environmental wireless controller may include one or more memories storing processor-executable code and one or more processors coupled to the one or more memories. The one or more processors may operate individually or collectively to execute the code (e.g., directly, indirectly, after preprocessing, or without preprocessing), thereby enabling the environmental wireless controller to: receive messages from application functions associated with network entities; determine one or more protection applications to be applied to the messages; apply the one or more protection applications to the messages to obtain encoded downlink messages; and transmit the encoded downlink messages to one or more environmental wireless devices.
[0027] Another environmental wireless controller for wireless communication is described. This environmental wireless controller may include: components for receiving messages from application functions associated with a network entity; components for determining one or more protection applications to be applied to the messages; components for applying one or more protection applications to the messages to obtain encoded downlink messages; and components for transmitting the encoded downlink messages to one or more environmental wireless devices.
[0028] A non-transitory computer-readable medium storing code for wireless communication is described. The code may include instructions executable by one or more processors (e.g., directly, indirectly, after preprocessing, or without preprocessing) to: receive a message from an application function associated with a network entity; determine one or more protection applications to be applied to the message; apply one or more protection applications to the message to obtain an encoded downlink message; and transmit the encoded downlink message to one or more wireless devices in an environment.
[0029] In some examples of the methods, environments, wireless controllers, and nontransitory computer-readable media described herein, messages include encoded downlink messages, downlink information used for encoding downlink messages, a first key, a token, or any combination thereof.
[0030] In some examples of the methods, environments, wireless controllers, and nontransitory computer-readable media described herein, one or more protection applications include one or more command protection applications, one or more manifest protection applications, or combinations thereof.
[0031] The methods described herein, environmental wireless controllers, and some examples of nontransitory computer-readable media may also include operations, features, components, or instructions for transmitting encoded downlink messages based on changes to one or more configurations for services provided by one or more environmental wireless devices, responses to requests from one or more environmental wireless devices, or both.
[0032] In some examples of the methods, environmental wireless controllers, and nontransitory computer-readable media described herein, the first key of a message may be based on a shared key between one or more environmental wireless devices and application functions.
[0033] In some examples of the methods, environments, wireless controllers, and non-transitory computer-readable media described herein, the first key of a message may be associated with one or more key refresh parameters.
[0034] In the methods, environments, wireless controllers, and some examples of nontransitory computer-readable media described herein, the encoded downlink messages include a message token.
[0035] In some examples of the methods, environmental radio controllers, and nontransitory computer-readable media described herein, transmitting encoded downlink messages may include operations, features, components, or instructions for transmitting encoded downlink messages to one or more user equipment (UEs) associated with one or more environmental radio devices.
[0036] In some examples of the methods, environments, wireless controllers, and nontransitory computer-readable media described herein, one or more UEs include a network reader, a device reader, or both.
[0037] In some examples of the methods, environmental wireless controllers, and nontransitory computer-readable media described herein, applying one or more protection applications may include operations, features, components, or instructions for: encoding downlink information of a message using a first key from the application function; and transmitting encoded downlink messages for one or more environmental wireless devices.
[0038] In some examples of the methods, environmental wireless controllers, and non-transitory computer-readable media described herein, applying one or more protection applications may include operations, features, components, or instructions for: receiving an authorization token and a first key from the application function; encoding downlink information of a message using the first key; signing the encoded downlink information using a message signing key, wherein the signed encoded downlink information includes the authorization token; and transmitting the encoded downlink message to one or more environmental wireless devices.
[0039] In some examples of the methods, environmental wireless controllers, and nontransitory computer-readable media described herein, applying one or more protection applications may include operations, features, components, or instructions for: generating a first key; using the first key to encode downlink information of a message; and transmitting the encoded downlink message to one or more environmental wireless devices.
[0040] In some examples of the methods, environmental wireless controllers, and nontransitory computer-readable media described herein, applying one or more protection applications may include operations, features, components, or instructions for: receiving a group key associated with at least one or more environmental wireless devices from an application function; encoding downlink information of a message using a manifest key based on the group key; and transmitting the encoded downlink message to one or more environmental wireless devices. Attached Figure Description
[0041] Figure 1 An example of a wireless communication system supporting downlink message protection for an environment of wireless devices is shown, according to one or more aspects of this disclosure.
[0042] Figure 2 An example of a wireless communication system supporting downlink message protection for an environment of wireless devices is shown, according to one or more aspects of this disclosure.
[0043] Figure 3 An example of a process flow supporting downlink message protection for an environment wireless device is shown, according to one or more aspects of this disclosure.
[0044] Figure 4 An example of a process flow supporting downlink message protection for an environment wireless device is shown, according to one or more aspects of this disclosure.
[0045] Figure 5 and Figure 6 A block diagram of a device supporting downlink message protection for an environment wireless device is shown, according to one or more aspects of this disclosure.
[0046] Figure 7 A block diagram is shown of a communication manager supporting downlink message protection for an environment wireless device, according to one or more aspects of this disclosure.
[0047] Figure 8 A diagram is shown of a system including a device that supports downlink message protection for an environment wireless device, according to one or more aspects of this disclosure.
[0048] Figure 9 and Figure 10 A block diagram of a device supporting downlink message protection for an environment wireless device is shown, according to one or more aspects of this disclosure.
[0049] Figure 11 A block diagram is shown of a communication manager supporting downlink message protection for an environment wireless device, according to one or more aspects of this disclosure.
[0050] Figure 12 A diagram is shown of a system including a device that supports downlink message protection for an environment wireless device, according to one or more aspects of this disclosure.
[0051] Figures 13 to 16 A flowchart illustrating a method for downlink message protection for an environmental wireless device, according to one or more aspects of this disclosure, is shown. Detailed Implementation
[0052] Some wireless communication systems may include ambient wireless devices (e.g., ambient Internet of Things (IoT) devices or tags) that provide one or more services, such as those involving tracking or indicating location. Wireless communication systems may also include application functions, ambient IoT controllers (or tag controllers), and / or user equipment (UEs) that can use one or more messages (such as one or more downlink messages) to facilitate the configuration of or communication with the ambient wireless device (e.g., requesting service data). For example, an application function may transmit downlink messages to a tag controller, a tag controller may transmit downlink messages to a UE, and a UE may transmit downlink messages to the ambient wireless device. To provide secure communication between devices in the wireless communication system, keys, tag identifiers (IDs), tokens, or other authentication-related data may be used and / or stored at the device. In some cases, authentication-related data may vary between devices. For example, an ambient wireless device may use different authentication-related data to authenticate authorization for communication with an application function and a tag controller. However, ambient wireless devices may have drawbacks, such as insufficient memory to store various authentication-related data. Furthermore, in some cases, the tag controller may not have credentials shared with the ambient wireless device for the ambient wireless device to authenticate authorization for downlink messages from the tag controller.
[0053] An ambient wireless device (e.g., an IoT device or a tag) can authenticate downlink messages from a tag controller, which can generate and / or protect these downlink messages without establishing a secure connection with the tag controller. Downlink messages can include command messages or manifest messages (and other examples), where command messages can be used to update configurations at the ambient wireless device and manifest messages can be used to trigger responses from the ambient wireless device.
[0054] In some examples, the application function may use a shared key shared with the ambient wireless devices to provide end-to-end protection for downlink command messages transmitted through the tag controller. In some examples, the tag controller may use a command protection key provided by the application function to provide protection for downlink command messages, where the downlink message includes a command authentication token, which the ambient wireless devices use to authenticate the tag controller's authorization for the downlink command message. In some examples, the tag controller may use a command protection key provided by the application function to provide protection for the downlink command message, and may also use a signing key (e.g., a private key associated with a verification key or public key certificate) to sign the downlink command message. The verification key associated with the signing key may be used by the ambient wireless devices to verify the command protection key of the downlink command message. In some examples, the tag controller may use a command protection key generated by the tag controller to provide protection for the downlink command message. In some examples, the tag controller may provide downlink manifest messages to multiple ambient wireless devices, for example, in a multicast transmission. The tag controller may receive a manifest key from the application function, or the tag controller may derive the manifest key from a group key received from the application function. The tag controller can use a manifest key to protect downlink manifest messages, and the ambient wireless device can use the manifest key to verify downlink manifest messages. Among other advantages, the protection techniques described herein facilitate the effective protection of downlink messages transmitted from the network (e.g., via application functions of the network) to the ambient wireless device without having to establish a secure connection between the network and the ambient wireless device, such as one that is associated with complex processes and / or large amounts of storage space for storing verification-related data.
[0055] The aspects of this disclosure are first described in the context of a wireless communication system. These aspects are further illustrated and described with reference to apparatus diagrams, system diagrams, and flowcharts relating to downlink message protection for environmental wireless devices. As discussed herein, an “environmental wireless device” refers to a device that extracts energy from its surrounding environment. An environmental wireless device may backscatter and / or store energy received from the surrounding environment, such as from radio frequency waves, and convert the energy into usable power to transmit signals. An “environmental wireless device” may include tags or environmental IoT devices in an IoT system. Therefore, “environmental wireless device” may refer to “tag” and / or “environmental IoT” and / or be used interchangeably with “tag” and / or “environmental IoT”.
[0056] Figure 1An example of a wireless communication system 100 supporting downlink message protection for environmental wireless devices according to one or more aspects of this disclosure is shown. The wireless communication system 100 may include one or more network entities 105, one or more UEs 115, and a core network 130. In some examples, the wireless communication system 100 may be a Long Term Evolution (LTE) network, an Advanced LTE (LTE-A) network, an LTE-A Pro network, a New Radio (NR) network, or a network operating under other systems and radio technologies, including future systems and radio technologies not explicitly mentioned herein.
[0057] Network entity 105 may be distributed across a geographical area to form wireless communication system 100, and may include devices employing different forms or having different capabilities. In various examples, network entity 105 may be referred to as a network element, mobility element, radio access network (RAN) node, or network equipment, etc. In some examples, network entity 105 and UE 115 may wirelessly communicate via one or more communication links 125 (e.g., radio frequency (RF) access links). For example, network entity 105 may support coverage area 110 (e.g., a geographical coverage area) within which UE 115 and network entity 105 may establish one or more communication links 125. Coverage area 110 may be an example of a geographical area within which network entity 105 and UE 115 may support the transmission of signals according to one or more radio access technologies (RATs).
[0058] UE 115 can be distributed throughout the coverage area 110 of wireless communication system 100, and each UE 115 can be stationary or mobile, or stationary and mobile at different times. UE 115 can be devices in different forms or with different capabilities. Figure 1 Some example UE 115s are illustrated herein. The UE 115 described herein can be able to support various types of devices (such as, e.g., ...). Figure 1 It communicates with other UEs (115 or network entity 105) as shown.
[0059] As described herein, a node in the wireless communication system 100 (which may be referred to as a network node or wireless node) may be a network entity 105 (e.g., any network entity described herein), a UE 115 (e.g., any UE described herein), a network controller, apparatus, device, computing system, one or more components, or another suitable processing entity configured to perform any of the techniques described herein. For example, a node may be UE 115. As another example, a node may be network entity 105. As another example, a first node may be configured to communicate with a second node or a third node. In one aspect of this example, the first node may be UE 115, the second node may be network entity 105, and the third node may be UE 115. In another aspect of this example, the first node may be UE 115, the second node may be network entity 105, and the third node may be network entity 105. In other aspects of this example, the first node, the second node, and the third node may be different from these examples. Similarly, references to UE 115, network entity 105, device, equipment, computing system (and other examples) may include disclosures of UE 115, network entity 105, device, equipment, computing system (and other examples) as nodes. For example, a disclosure that UE 115 is configured to receive information from network entity 105 also discloses that a first node is configured to receive information from a second node.
[0060] In some examples, network entity 105 may communicate with core network 130, communicate with each other, or both. For example, network entity 105 may communicate with core network 130 via one or more backhaul communication links 120 (e.g., according to S1, N2, N3, or other interface protocols). In some examples, network entities 105 may communicate with each other directly (e.g., directly between network entities 105) or indirectly (e.g., via core network 130) via backhaul communication links 120 (e.g., according to X2, Xn, or other interface protocols). In some examples, network entities 105 may communicate with each other via midhaul communication link 162 (e.g., according to midhaul interface protocol) or fronthaul communication link 168 (e.g., according to fronthaul interface protocol) or any combination thereof. The backhaul communication link 120, midhaul communication link 162, or fronthaul communication link 168 may be one or more wired links (e.g., electrical links, fiber optic links), one or more wireless links (e.g., radio links, wireless optical links), etc., or various combinations thereof, or may include one or more wired links (e.g., electrical links, fiber optic links), one or more wireless links (e.g., radio links, wireless optical links), etc., or various combinations thereof. UE 115 may communicate with the core network 130 via communication link 155.
[0061] One or more network entities in network entity 105 described herein may include or be referred to as base station 140 (e.g., transceiver base station, radio base station, NR base station, access point, radio transceiver, node B, eNodeB (eNB), next-generation node B or gigabit node B (any of which may be referred to as gNB), 5G NB, next-generation eNB (ng-eNB), home node B, home evolution node B, or other suitable terms). In some examples, network entity 105 (e.g., base station 140) may be implemented in an aggregated (e.g., monolithic, standalone) base station architecture that may be configured to utilize a protocol stack that is physically or logically integrated within a single network entity 105 (e.g., a single RAN node, such as base station 140).
[0062] In some examples, network entity 105 may be implemented in a decomposed architecture (e.g., a decomposed base station architecture, a decomposed RAN architecture) that can be configured to utilize protocol stacks physically or logically distributed across two or more network entities 105, such as an integrated access backhaul (IAB) network, an open RAN (O-RAN) (e.g., a network configuration sponsored by the O-RAN Alliance), or a virtualized RAN (vRAN) (e.g., a cloud RAN (C-RAN)). For example, network entity 105 may include one or more of the following: a central unit (CU) 160, a distributed unit (DU) 165, a radio unit (RU) 170, a RAN intelligent controller (RIC) 175 (e.g., a near real-time RIC, a non-real-time RIC), a service management and orchestration (SMO) 180 system, or any combination thereof. 170 may also be referred to as a radio headend, intelligent radio headend, remote radio headend (RRH), remote radio unit (RRU), or transmit / receive point (TRP). One or more components of network entity 105 in a decomposed RAN architecture may be co-located, or one or more components of network entity 105 may be located in distributed locations (e.g., separate physical locations). In some examples, one or more network entities 105 in a decomposed RAN architecture may be implemented as virtual units (e.g., virtual CU (VCU), virtual DU (VDU), virtual RU (VRU)).
[0063] The functional splitting among CU 160, DU 165, and RU 170 is flexible and can support different functionalities depending on which functions (e.g., network layer functions, protocol layer functions, baseband functions, RF functions, and any combination thereof) are performed at CU 160, DU 165, or RU 170. For example, a protocol stack functional splitting can be used between CU 160 and DU 165, allowing CU 160 to support one or more layers of the protocol stack, and DU 165 to support one or more different layers of the protocol stack. In some examples, CU 160 can host higher protocol layer (e.g., Layer 3 (L3), Layer 2 (L2)) functionalities and signaling (e.g., Radio Resource Control (RRC), Serving Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP)). CU 160 can connect to one or more DU 165 or RU 170, and one or more DU 165 or RU 170 can host lower protocol layers, such as Layer 1 (L1) (e.g., Physical (PHY) layer) or L2 (e.g., Radio Link Control (RLC) layer, Medium Access Control (MAC) layer) functionality and signaling, and each can be at least partially controlled by CU 160. Additionally or alternatively, a protocol stack functional split can be employed between DU 165 and RU 170, such that DU 165 can support one or more layers of the protocol stack, and RU 170 can support one or more different layers of the protocol stack. DU 165 can support one or more different cells (e.g., via one or more RU 170). In some cases, functional decomposition between CU 160 and DU 165, or between DU 165 and RU 170, can be performed within the protocol layer (e.g., some functions of the protocol layer can be performed by one of CU 160, DU 165, or RU 170, while other functions of the protocol layer can be performed by different of CU 160, DU 165, or RU 170). CU 160 can be further functionally decomposed into CU control plane (CU-CP) functions and CU user plane (CU-UP) functions. CU 160 can be connected to one or more DU 165 via midhaul communication link 162 (e.g., F1, F1-c, F1-u), and DU 165 can be connected to one or more RU 170 via fronthaul communication link 168 (e.g., open fronthaul (FH) interface). In some examples, the midhaul communication link 162 or the fronthaul communication link 168 may be implemented based on the interfaces (e.g., channels) between the layers of the protocol stack, which are supported by the corresponding network entities 105 communicating via such communication links.
[0064] In a wireless communication system (e.g., wireless communication system 100), the infrastructure and spectrum resources for radio access can support wireless backhaul link capabilities to supplement wired backhaul connections, thereby providing an IAB network architecture (e.g., to core network 130). In some cases, in an IAB network, one or more network entities 105 (e.g., IAB node 104) may be partially controlled by each other. One or more IAB nodes 104 may be referred to as donor entities or IAB donors. One or more DU 165s or one or more RU 170s may be partially controlled by one or more CU 160s associated with donor network entity 105 (e.g., donor base station 140). One or more donor network entities 105 (e.g., IAB donors) may communicate with one or more additional network entities 105 (e.g., IAB node 104) via supported access and backhaul links (e.g., backhaul communication link 120). IAB node 104 may include an IAB mobile terminal (IAB-MT) controlled (e.g., scheduled) by a DU 165 of a coupled IAB donor. The IAB-MT may include a separate set of antennas for relaying communication with UE 115, or may share the same antennas (e.g., those of RU 170) for access to IAB node 104 via DU 165 of IAB node 104. (e.g., referred to as a virtual IAB-MT (vIAB-MT)). In some examples, IAB node 104 may include a DU 165 that supports communication links with additional entities (e.g., IAB node 104, UE 115) within a relay chain or configuration (e.g., downstream) of the access network. In such cases, one or more components of the decomposed RAN architecture (e.g., one or more IAB nodes 104 or components of IAB node 104) may be configured to operate according to the techniques described herein.
[0065] In the context of applying the techniques described herein to a decomposed RAN architecture, one or more components of the decomposed RAN architecture can be configured to support downlink message protection for environmental radio devices as described herein. For example, some operations described as being performed by UE 115 or network entity 105 (e.g., base station 140) may additionally or alternatively be performed by one or more components of the decomposed RAN architecture (e.g., IAB node 104, DU 165, CU 160, RU 170, RIC 175, SMO 180).
[0066] UE 115 may include or be referred to as a mobile device, wireless device, remote device, handheld device, or subscriber device, or any other suitable term, wherein “device” may also be referred to as a unit, station, terminal, or client, etc. UE 115 may also include or be referred to as personal electronic devices, such as cellular phones, personal digital assistants (PDAs), multimedia / entertainment devices (e.g., radios, MP3 players, or video devices), cameras, gaming devices, navigation / positioning devices (e.g., GNSS (Global Navigation Satellite System) devices based on, for example, GPS (Global Positioning System), BeiDou system, GLONASS or Galileo system, ground-based devices, etc.), tablet computers, laptop computers, netbooks, smartbooks, personal computers, smart devices, wearable devices (e.g., smartwatches, smart clothing, smart glasses, virtual reality goggles, smart wristbands, smart jewelry (e.g., smart rings, smart bracelets)), drones, robots / robotic devices, vehicles, vehicle equipment, meters (e.g., parking timers, electricity meters, gas meters, water meters), monitors, air pumps, electrical appliances (e.g., kitchen appliances, washing machines, dryers), location tags, medical / healthcare devices, implants, sensors / actuators, displays, or any other suitable device configured to communicate via wireless or wired media. In some examples, UE 115 may include, or may be referred to as, a wireless local loop (WLL) station, an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a machine-type communication (MTC) device, etc., which can be implemented in various objects such as appliances or vehicles, meters, etc. In one aspect, the technologies disclosed herein are applicable to MTC or IoT UEs. MTC or IoT UEs may include MTC / enhanced MTC (eMTC, also known as CAT-M, Cat M1) UEs, NB-IoT (also known as CAT NB1) UEs, and other types of UEs. eMTC and NB-IoT may refer to future technologies that may evolve from or be based on these technologies. For example, eMTC may include FeMTC (further eMTC), eFeMTC (further enhanced eMTC), and mMTC (massive MTC), while NB-IoT may include eNB-IoT (enhanced NB-IoT) and FeNB-IoT (further enhanced NB-IoT).
[0067] The UE 115 described herein can communicate with various types of devices, such as other UEs 115 that sometimes act as relays, network entities 105, and network equipment including macro eNBs or gNBs, small cell eNBs or gNBs, or relay base stations, etc. Figure 1 As shown.
[0068] UE 115 and network entity 105 can wirelessly communicate with each other via one or more communication links 125 (e.g., access links) using resources associated with one or more carriers. The term "carrier" can refer to a set of RF spectrum resources having a defined physical layer structure for supporting communication link 125. For example, a carrier for communication link 125 may include a portion of the RF spectrum band (e.g., a bandwidth portion (BWP)) operating according to one or more physical layer channels for a given radio access technology (e.g., LTE, LTE-A, LTE-A Pro, NR). Each physical layer channel may carry acquisition signaling (e.g., synchronization signals, system information), control signaling coordinating carrier operation, user data, or other signaling. Wireless communication system 100 can support communication with UE 115 using carrier aggregation or multi-carrier operation. Depending on the carrier aggregation configuration, UE 115 can be configured using multiple downlink component carriers and one or more uplink component carriers. Carrier aggregation can be used in conjunction with both frequency division duplex (FDD) component carriers and time division duplex (TDD) component carriers. Communication between network entity 105 and other devices can refer to communication between these devices and any part of network entity 105 (e.g., entity, sub-entity). For example, the terms “send,” “receive,” or “communicate” when referring to network entity 105 can refer to any part of the RAN’s network entity 105 (e.g., base station 140, CU160, DU 165, RU 170) communicating with another device (e.g., directly or via one or more other network entities 105).
[0069] In some examples, such as in carrier aggregation configurations, a carrier may also have acquisition signaling or control signaling to coordinate the operation of other carriers. A carrier may be associated with a frequency channel (e.g., an Evolved Universal Mobile Telecommunications System Terrestrial Radio Access (E-UTRA) Absolute RF Channel Number (EARFCN)) and may be identified according to a channel grating used for discovery by UE 115. A carrier may operate in standalone mode, in which case initial acquisition and connection can be performed by UE 115 via that carrier, or the carrier may operate in non-standalone mode, in which case different carriers (e.g., the same or different radio access technologies) are used to anchor the connection.
[0070] The communication link 125 shown in the wireless communication system 100 may include downlink transmission (e.g., forward link transmission) from network entity 105 to UE 115, uplink transmission (e.g., return link transmission) from UE 115 to network entity 105, or both, as well as other transmission configurations. A carrier may carry downlink communication or uplink communication (e.g., in FDD mode), or may be configured to carry both downlink and uplink communication (e.g., in TDD mode).
[0071] A carrier may be associated with a specific bandwidth of the RF spectrum, and in some examples, the carrier bandwidth may be referred to as the carrier or the “system bandwidth” of the wireless communication system 100. For example, the carrier bandwidth may be one bandwidth in a set of bandwidths for a particular radio access technology (e.g., 1.4 MHz, 3 MHz, 5 MHz, 10 MHz, 15 MHz, 20 MHz, 40 MHz, or 80 MHz). Devices of the wireless communication system 100 (e.g., network entity 105, UE 115, or both) may have hardware configurations that support communication using a specific carrier bandwidth, or may be configured to support communication using one of the carrier bandwidths in a set of carrier bandwidths. In some examples, the wireless communication system 100 may include network entity 105 or UE 115 that supports concurrent communication using carriers associated with multiple carrier bandwidths. In some examples, each served UE 115 may be configured to operate using a portion (e.g., subband, BWP) or all of the carrier bandwidth.
[0072] The signal waveform transmitted via a carrier may include multiple subcarriers (e.g., using multi-carrier modulation (MCM) techniques, such as orthogonal frequency division multiplexing (OFDM) or discrete Fourier transform extended OFDM (DFT-S-OFDM)). In a system employing MCM, a resource element may refer to a resource of one symbol period (e.g., the duration of one modulation symbol) and one subcarrier, in which case the symbol period and subcarrier spacing may be inversely related. The number of bits carried by each resource element may depend on the modulation scheme (e.g., the order of the modulation scheme, the decoding rate of the modulation scheme, or both), such that a relatively high number of resource elements (e.g., in the transmission duration) and a relatively high modulation scheme order correspond to a relatively high communication rate. Wireless communication resources may refer to a combination of RF spectrum resources, temporal resources, and spatial resources (e.g., spatial layers or beams), and the use of multiple spatial resources may increase the data rate or data integrity used for communication with UE 115.
[0073] It can support one or more sets of parameters for a carrier, and the set of parameters may include subcarrier spacing ( (and cyclic prefix). A carrier can be divided into one or more BWPs with the same or different sets of parameters. In some examples, multiple BWPs can be used to configure UE 115. In some examples, a single BWP of a carrier can be active at a given time, and the communication of UE 115 can be constrained to one or more active BWPs.
[0074] The time interval for network entity 105 or UE 115 can be expressed as a multiple of a basic time unit, such as the sampling period. seconds, of which It can represent the supported subcarrier spacing, and This can represent the supported Discrete Fourier Transform (DFT) size. The time interval of the communication resources can be organized according to radio frames, each with a specified duration (e.g., 10 milliseconds (ms)). Each radio frame can be identified by a System Frame Number (SFN) (e.g., ranging from 0 to 1023).
[0075] Each frame may include multiple consecutively numbered subframes or time slots, and each subframe or time slot may have the same duration. In some examples, a frame may (e.g., in the time domain) be divided into subframes, and each subframe may be further divided into a number of time slots. Alternatively, each frame may include a variable number of time slots, and the number of time slots may depend on the subcarrier spacing. Each time slot may include a number of symbol periods (e.g., depending on the length of the cyclic prefix appended to each symbol period). In some wireless communication systems 100, time slots may be further divided into multiple micro-time slots associated with one or more symbols. Excluding the cyclic prefix, each symbol period may be associated with one or more (e.g., The duration of a symbol period is associated with a (number) sampling period. The duration of a symbol period can depend on the subcarrier spacing or the operating frequency band.
[0076] A subframe, time slot, micro-time slot, or symbol can be the smallest scheduling unit of the wireless communication system 100 (e.g., in the time domain) and can be referred to as a transmission time interval (TTI). In some examples, the duration of the TTI (e.g., the number of symbol periods in the TTI) can be variable. Additionally or alternatively, the smallest scheduling unit of the wireless communication system 100 can be dynamically selected (e.g., in a burst of shortened TTIs (sTTIs)).
[0077] Depending on the technology, carriers can be used to multiplex physical channels for communication. One or more of Time Division Multiplexing (TDM), Frequency Division Multiplexing (FDM), or hybrid TDM-FDM techniques can be used, for example, to multiplex physical control channels and physical data channels for signaling via a downlink carrier. The control region (e.g., control resource set (CORESET)) of the physical control channel can be defined by a set of symbol periods and can extend across the system bandwidth of the carrier or a subset of that bandwidth. One or more control regions (e.g., CORESET) can be configured for a set of UEs 115. For example, one or more UEs in UE 115 can monitor or search for control regions to obtain control information based on one or more search space sets, and each search space set can include one or more control channel candidates in one or more aggregation levels arranged in a concatenated manner. The aggregation level of control channel candidates can refer to the amount of control channel resources (e.g., control channel elements (CCEs)) associated with coded information for a control information format having a given payload size. The search space set may include: a common search space set configured to transmit control information to multiple UEs 115, and a UE-specific search space set used to transmit control information to a specific UE 115.
[0078] In some examples, network entity 105 (e.g., base station 140, RU 170) may be mobile, and thus provide communication coverage to mobile coverage areas 110. In some examples, different coverage areas 110 associated with different technologies may overlap, but the different coverage areas 110 may be supported by the same network entity 105. In some other examples, overlapping coverage areas 110 associated with different technologies may be supported by different network entities 105. The wireless communication system 100 may include, for example, a heterogeneous network in which different types of network entities 105 use the same or different radio access technologies to provide coverage for various coverage areas 110.
[0079] The wireless communication system 100 can support synchronous or asynchronous operation. For synchronous operation, network entities 105 (e.g., base station 140) can have similar frame timings, and transmissions from different network entities 105 can be approximately time-aligned. For asynchronous operation, network entities 105 can have different frame timings, and in some examples, transmissions from different network entities 105 may not be time-aligned. The techniques described herein can be used for both synchronous and asynchronous operation.
[0080] Some UE 115s can be configured to operate in a power-saving mode, such as half-duplex communication (e.g., a mode that supports unidirectional communication via transmission or reception but does not involve concurrent transmission and reception). In some examples, half-duplex communication can be performed at a reduced peak rate. Other power-saving techniques for UE 115s include entering a power-saving deep sleep mode when not engaged in active communication, operating with limited bandwidth (e.g., according to narrowband communication), or a combination of these techniques. For example, some UE 115s can be configured to operate using a narrowband protocol type associated with a defined portion or range (e.g., a set of subcarriers or resource blocks (RBs)) within a carrier, within a carrier's guard band, or outside a carrier.
[0081] Wireless communication system 100 may be configured to support ultra-reliable communication or low-latency communication, or various combinations thereof. For example, wireless communication system 100 may be configured to support ultra-reliable low-latency communication (URLLC). UE 115 may be designed to support ultra-reliable, low-latency, or critical functions. Ultra-reliable communication may include private or group communication and may be supported by one or more services, such as push-to-talk, video, or data. Support for ultra-reliable, low-latency functions may include prioritizing services, and such services may be used for public safety or general business applications. The terms “ultra-reliable,” “low-latency,” and “ultra-reliable low-latency” are used interchangeably herein.
[0082] In some examples, UE 115 may be configured to support direct communication with other UE 115s via device-to-device (D2D) communication link 135 (e.g., according to peer-to-peer (P2P), D2D, or sidelink protocols). In some examples, one or more UE 115s performing D2D communication in a group may be within the coverage area 110 of network entity 105 (e.g., base station 140, RU 170), which may support aspects of such D2D communication configured (e.g., scheduled by network entity 105). In some examples, one or more UE 115s in this group may be outside the coverage area 110 of network entity 105, or may otherwise be unable or not configured to receive transmissions from network entity 105. In some examples, the group of UE 115s communicating via D2D communication may support a one-to-many (1:M) system, where each UE 115 transmits to each of the other UE 115s in the group. In some examples, network entity 105 may facilitate the scheduling of resources used for D2D communication. In other examples, D2D communication may be performed between UEs 115 without involving network entity 105.
[0083] Core network 130 provides user authentication, access authorization, tracking, Internet Protocol (IP) connectivity, and other access, routing, or mobility functions. Core network 130 can be an evolved packet core (EPC) or a 5G core (5GC), which may include at least one control plane entity (e.g., a mobility management entity (MME), access and mobility management function (AMF)) for managing access and mobility, and at least one user plane entity (e.g., a serving gateway (S-GW), packet data network (PDN) gateway (P-GW), or user plane function (UPF)) for routing packets or interconnecting to external networks. The control plane entity manages non-access stratum (NAS) functions, such as mobility, authentication, and bearer management of UE 115 served by network entity 105 (e.g., base station 140) associated with core network 130. User IP packets can be transferred through user plane entities, which provide IP address allocation and other functions. User plane entities can connect to one or more network operator IP services 150. IP services 150 may include access to the Internet, intranets, IP Multimedia Subsystem (IMS), or packet-switched streaming services.
[0084] Wireless communication system 100 can operate using one or more frequency bands in the range of 300 MHz to 300 GHz. Generally, the area from 300 MHz to 3 GHz is referred to as the Ultra High Frequency (UHF) band or decimeter band because the wavelength range is approximately one decimeter to one meter in length. UHF waves may be blocked or redirected by buildings and environmental features (which may be referred to as clusters), but these waves are sufficient to penetrate structures so that macrocells can provide service to UE 115 located indoors. Compared to communication using smaller frequencies and longer wavelengths in the lower frequency (HF) or very high frequency (VHF) portions of the spectrum below 300 MHz, communication using UHF waves can be associated with smaller antennas and shorter ranges (e.g., less than 100 km).
[0085] The wireless communication system 100 can also operate in the Ultra High Frequency (SHF) band (also known as the centimeter band) in the range of 3 GHz to 30 GHz or in the Extremely High Frequency (EHF) band (e.g., 30 GHz to 300 GHz) (also known as the millimeter band). In some examples, the wireless communication system 100 can support millimeter-wave (mmW) communication between the UE 115 and network entity 105 (e.g., base station 140, RU 170), and the EHF antennas of the corresponding devices can be smaller and more closely spaced than UHF antennas. In some examples, such techniques facilitate the use of antenna arrays within the device. However, compared to SHF or UHF transmissions, EHF transmissions may experience even greater attenuation and shorter range. The techniques disclosed herein can be adopted across transmissions using one or more different frequency bands, and the frequency band usage specified across these frequency bands may vary by country or regulatory authority.
[0086] Wireless communication system 100 may utilize both licensed and unlicensed RF spectrum bands. For example, wireless communication system 100 may use unlicensed bands (such as the 5 GHz Industrial, Scientific, and Medical (ISM) band) to employ Licensed Assisted Access (LAA), LTE Unlicensed (LTE-U) radio access technology, or NR technology. When operating with unlicensed RF spectrum, devices such as network entity 105 and UE 115 may employ carrier sensing for collision detection and avoidance. In some examples, operation using unlicensed bands may be combined with component carriers operating with licensed bands based on carrier aggregation configurations (e.g., LAA). Operation using unlicensed spectrum may include downlink transmission, uplink transmission, P2P transmission, or D2D transmission, etc.
[0087] Network entity 105 (e.g., base station 140, RU 170) or UE 115 may be equipped with multiple antennas that can be used to employ techniques such as transmit diversity, receive diversity, multiple-input multiple-output (MIMO) communication, or beamforming. The antennas of network entity 105 or UE 115 may be located within one or more antenna arrays or antenna panels, which can support MIMO operation or transmit or receive beamforming. For example, one or more base station antennas or antenna arrays may be co-located at an antenna assembly (such as an antenna tower). In some examples, the antennas or antenna arrays associated with network entity 105 may be located at different geographical locations. Network entity 105 may include an antenna array having a collection of multiple rows and columns of antenna ports that network entity 105 can use to support beamforming for communication with UE 115. Similarly, UE 115 may include one or more antenna arrays that can support various MIMO or beamforming operations. Additionally or alternatively, the antenna panel may support RF beamforming for signals transmitted via the antenna ports.
[0088] Beamforming (also known as spatial filtering, directional transmission, or directional reception) is a signal processing technique that can be used at a transmitting or receiving device (e.g., network entity 105, UE 115) to shape or guide an antenna beam (e.g., a transmit beam, a receive beam) along a spatial path between the transmitting and receiving devices. Beamforming can be achieved by combining signals transmitted via antenna elements of an antenna array such that some signals propagating along a specific orientation relative to the antenna array experience constructive interference, while other signals experience destructive interference. Adjustments to the signals transmitted via the antenna elements may include applying amplitude shifts, phase shifts, or both to the signals carried via the antenna elements associated with the device. The adjustments associated with each of these antenna elements may be defined by a beamforming weight set associated with a specific orientation (e.g., relative to the antenna array of the transmitting or receiving device or relative to some other orientation).
[0089] The wireless communication system 100 can be a packet-based network operating according to a layered protocol stack. In the user plane, communication at the bearer or PDCP layer can be IP-based. The RLC layer performs packet segmentation and reassembly for transmission via logical channels. The MAC layer performs priority processing and multiplexing of logical channels to transport channels. The MAC layer can also use error detection, error correction, or both to support retransmission to improve link efficiency. In the control plane, the RRC layer provides the establishment, configuration, and maintenance of RRC connections between the UE 115 and network entity 105 or core network 130 that support user plane data radio bearers. The PHY layer maps transport channels to physical channels.
[0090] UE 115 and network entity 105 can support data retransmission to increase the likelihood of successful data reception. Hybrid Automatic Repeat Request (HARQ) feedback is a technique used to increase the likelihood of correctly receiving data via communication links (e.g., communication link 125, D2D communication link 135). HARQ may include a combination of error detection (e.g., using Cyclic Redundancy Check (CRC)), forward error correction (FEC), and retransmission (e.g., Automatic Repeat Request (ARQ)). HARQ can improve throughput at the MAC layer under poor radio conditions (e.g., low signal-to-noise ratio conditions). In some examples, the device may support same-slot HARQ feedback, in which case the device may provide HARQ feedback in a specific time slot for data received via a previous symbol in that time slot. In some other examples, the device may provide HARQ feedback in subsequent time slots or according to a different time interval.
[0091] In some examples, the wireless communication system 100 may include an ambient wireless device (e.g., a tag) that provides one or more services, such as services involving tracking or indicating location. The wireless communication system 100 may also include application functions, a tag controller, and / or a UE 115 that can use downlink messages to facilitate configuring or communicating with the ambient wireless device (e.g., requesting service data).
[0092] To provide secure communication between devices in the wireless communication system 100, various keys, tag identifiers (IDs), tokens, or other authentication-related data can be stored at the devices. However, the ambient wireless devices may not have sufficient memory to store all the authentication-related data. Furthermore, in some cases, the tag controller may not have credentials shared with the ambient wireless devices for the ambient wireless devices to authenticate authorization of downlink messages from the tag controller, which may have already received downlink messages from the application functions.
[0093] As discussed herein, an ambient wireless device can authenticate downlink messages from a tag controller, which can generate and / or protect these downlink messages without establishing a secure connection with the tag controller. Downlink messages may include command messages or manifest messages (and other examples), where command messages can be used to update configuration at the ambient wireless device and manifest messages can be used to trigger a response from the ambient wireless device. In some examples, application functions may use a shared key shared with the ambient wireless device to provide end-to-end protection for downlink command messages via the tag controller. In some examples, the tag controller may use a command protection key provided by the application function to provide protection for downlink command messages, where the downlink messages may include a command authentication token, which the ambient wireless device uses to verify the tag controller's authorization for the downlink command messages. In some examples, the tag controller may use a command protection key provided by the application function to provide protection for downlink command messages, and may also use a signing key (e.g., a private key associated with a certificate) to sign the downlink command messages. The signing key may be used by the ambient wireless device as a command protection key to verify the downlink command messages. In some examples, the tag controller may use, for example, a command protection key generated by the tag controller to provide protection for downlink command messages. In some examples, the tag controller may provide downlink manifest messages to multiple ambient radio devices, for example, in a multicast transmission. The tag controller may receive a group key, and the tag controller may derive a manifest key. The tag controller may use the manifest key to protect downlink manifest messages, and the ambient radio devices may use the manifest key to verify authorization to the tag controller.
[0094] Among other advantages, the protection techniques described herein facilitate the effective protection of downlink messages transmitted from a network (e.g., network entity 105 via application functions of the network) to an ambient wireless device without the need to establish a secure connection between the network and the ambient wireless device. Secure connections can be associated with complex processes and / or substantial storage space for storing authentication-related data.
[0095] Figure 2 An example of a wireless communication system 200 supporting downlink message protection for an environment of wireless devices, according to one or more aspects of this disclosure, is shown. The wireless communication system 200 may implement, or be implemented by, aspects of the wireless communication system 100. For example, the wireless communication system 200 includes a UE 115-a and a network entity 105-a, which may be related to... Figure 1 Examples of UE 115 and network entity 105 described.
[0096] Wireless communication system 200 may include application function 205, clearinghouse 210, tag controller 215, tag reader 230 including network entity 105-a and UE 115-a, and tag 220 (e.g., collectively referred to as “environmental service components”), etc. In some examples, environmental wireless devices (e.g., tag 220) may include device type A, device type B, and / or device type C. Device type A may not have a storage device for storing energy, nor independent signal generation (e.g., backscatter transmission). Device type A may be associated with short-range communication and low data rates, energy harvesting may be received directly from radio frequency (RF) devices, and it has network-initiated-only communication (NICO). Device type B may have a storage device for storing energy, but may not independently generate signals (e.g., backscatter transmission). Device type B may use the stored energy to amplify reflected signals. Device type B may be associated with relatively long-range communication provided by energy harvesting in NICO mode (e.g., the communication range relative to device type A). In some examples, device type A and / or device type B devices may not support 3GPP-defined protocols due to the corresponding overhead. In such examples, device types A and B may operate as UE 115 (e.g., a “special UE” or not a new UE 115) or as a new UE 115. As UE 115, existing CN functions may be adapted to the device type to support the new UE 115. NICO and mobility management aspects may be partially hidden from other network functions by periodic polling (e.g., at time intervals) by the RAN or Access and Mobility Functions (AMF). Device reachability or availability may not be guaranteed. As a new UE 115, device types A and B may be completely or partially invisible to the CN. In some examples, new CN functions may be applied to the new UE 115, such as for mobility management. In some examples, environmental radio devices may include device type C, which may have storage devices for energy storage and may independently generate signals (e.g., active RF components for transmission). Device type C can be capable of transmitting uplink transmissions, which can be signaling indicating a request (e.g., having communication similar to device types A and B). If the uplink transmission supports the request, device type C can operate similarly to device types A and B.
[0097] Device type C can support uplink transmission indicating requests to the CN in a manner similar to device types A and B. Device type C can support uplink transmission indicating data in a manner similar to low-power (LP) IoT (LP-IoT). As a UE 115, device type C can operate similarly to device types A and B, allowing it to be associated with reduced network-based tracking and polling. As a new UE 115, device type C can operate similarly to devices in LP-IoT within a 5G CN. That is, device type A may have no energy storage and may not generate a signal, device type B may have storage for enhancing or amplifying the signal, and device type C can operate similarly to IoT devices, having storage for energy (e.g., but less than MTC devices) and a short communication range (e.g., for signaling indicating requests or data).
[0098] In some examples, an ambient wireless device (e.g., ambient IoT) labeled 220 may be associated with device type A and / or device type B. For the upper-layer capabilities associated with the ambient wireless device, the ambient wireless device maintains a minimal state, making session context management and / or storage unsupported, and stateless operation may be preferred. The ambient wireless device may not support the 3GPP protocol stack, for example because the cost may exceed a threshold (e.g., too expensive to implement a complex protocol stack for the user plane (U plane) or control plane (C plane). In some examples, the ambient wireless device may lack Subscriber Identity Module (SIM) credentials, for example because the cost associated with the SIM and the SIM-enabled Mobile Network Operator (MNO) may exceed a threshold (e.g., too expensive). In some examples, the ambient wireless device may have limited encryption and / or processing capabilities (e.g., below a process threshold). The ambient wireless device may be associated with simple circuitry that can be used for processing by the ambient wireless device.
[0099] The workflow for providing and supporting ambient wireless services may involve various communications between the network and various devices such as application function 205, clearinghouse 210, tag controller 215, tag reader 230 including network entity 105-a and UE 115-a, and tag 220 (e.g., ambient wireless device). The network's application function 205 (e.g., tag application) may receive tag information and / or service data (e.g., from tag controller 215 and / or clearinghouse 210). Application function 205 may collect tag information and service data across one or more tag controllers 215 to enable services (e.g., tracking). In some examples, application function 205 may provide or facilitate the provision of tag 220 (e.g., out-of-band).
[0100] Tag controller 215 and / or clearinghouse 210 may receive tag information and / or enhancement data (e.g., from tag reader 230). Tag controller 215 and / or clearinghouse 210 may collect tag information and enhancement data across one or more network readers (e.g., network entity 105-a) and / or device readers (e.g., UE 115-a) (collectively, "tag reader" 230). Tag controller 215 and / or clearinghouse 210 may verify the enhancement data and processes used to generate service data. Tag controller 215 may provide or instruct tag applications (e.g., via clearinghouse 210) with tag information and service data.
[0101] Tag reader 230 can send signals (e.g., energy signals) to tag 220 (e.g., energy storage available at tag 220). Tag reader 230 can also receive tag information (e.g., in responses from tag 220). Tag reader 230 can receive tag information and construct augmentation data, such as Global Navigation Satellite System (GNSS) position, neighboring cell identifiers (IDs), sensor data, etc. Tag reader 230 can report tag information and augmentation data to tag controller 215.
[0102] Tag 220 can receive energy signals for active transmission. Tag 220 can (e.g., after receiving an energy signal) send tag information to tag reader 230. Tag information may include tag ID and / or other tag-related data. The tag ID and / or other tag-related data can be protected using provided credentials (e.g., via application function 205). In some examples, some of the workflows can be communicated using a Public Land Mobile Network (PLMN) (e.g., PLMN A) associated with tag controller 215 and / or a PLMN B associated with tag controller 215, where each of the tag controllers 215 is associated with a corresponding PLMN (e.g., a first tag controller is associated with PLMN A and a second tag controller is associated with PLMN B). For example, network flows via PLMN A or PLMN B can be based on one or more tag readers 230 (e.g., a first tag reader 230 sends information to a first tag controller 215, and a second tag controller 215 communicating with tag 220 sends information to a second tag controller 230).
[0103] Environmental wireless devices may be associated with security management involving tag ID and credential management. Tag ID and credential management may include credential management for security and privacy, where tag ID privacy facilitates the avoidance of unauthorized tracking or surveillance, and tag ID authentication facilitates the avoidance of fraudulent reports. In some examples, the credential management entity may include an MNO subscription. However, due to cost, different tags 220 with different security or privacy support based on the service, or different tags 220 with different types of credentials, tag 220 may not be subscribed to an MNO. In some examples, credential management may be supported by different devices (e.g., design choices for credential management), where application functions (AFs) and / or application service providers (ASPs) manage tag credentials according to service security or privacy conditions. MNO management may directly or indirectly manage (e.g., AFs owned by the MNO) tag credentials, for example by verifying tag IDs and filtering or blocking false tag ID reports or associated traffic. In some examples, tag 220 security management may involve end-to-end credential management and security protection, as well as MNO verification of tag IDs.
[0104] In some examples, such as for end-to-end security between tag 220 and the AF associated with the network, tag information can be verified at the AF based on providing a symmetric key or protection key (e.g., a private key or a public key) used by the AF. Tag controller 215 can indirectly verify tag information via the AF, for example, because registered or requested tag information is verified at tag controller 215. The AF can register a list of tag IDs and request service data for the list of tag IDs.
[0105] Tag controller 215 can provide service data for tag ID registration or requested tag information, where charging records are transmitted to the AF (e.g., reverse charging), and tag IDs that do not request protection are considered invalid. Tag information verification at tag controller 215 may include the AF providing a list of valid tag IDs at time intervals (option 1), where the tag ID length exceeds a threshold (e.g., 128 bits) to avoid collisions, while supporting refresh and validity periods associated with the tag ID. Tag information verification at tag controller 215 may include the MNO or a dedicated control channel (DCH) to issue a token to the AF (option 2), where the token is provided at tag 220. Tag 220 may use the protection key of tag controller 215 to encrypt the token for multiple uses. Tag information verification at tag controller 215 may include the AF providing a tag information verification key to the MNO or DCH (option 3). Verification may include only the tag ID (e.g., a temporary ID) or additional information. However, tag information verification may involve a protection key and introduce complex calculations at tag 220.
[0106] In some examples, the network may send downlink messages to tag 220, where the network may include tag controller 215 or an AF via the tag controller (e.g., when tag controller 215 wants to transmit periodic manifest messages or command messages requested by the AF). Downlink messages from the network may be unicast transmissions including command messages or multicast transmissions including manifest messages. Commands may update tag configurations or trigger specific actions at tag 220. Manifest messages may trigger responses at one or more tags 220 (such as a group of tags 220).
[0107] Protecting and verifying downlink messages can be difficult for environmental wireless devices (e.g., passive AIoT devices) because tag 220 (e.g., AIoT passive device) may not have credentials (e.g., subscription credentials) shared with the operator (e.g., MNO) and / or tag controller 215. Protecting and verifying downlink messages can also be difficult because tag 220 may not be registered to the operator network, tag 220 may not be a non-volatile memory used to store the security context for management state, and / or downlink messages may be triggered or created by tag controller 215. This document addresses at least... Figure 3 and Figure 4 The technologies discussed can provide protection and authentication of downlink messages while reducing these difficulties (e.g., tag 220 does not need to be registered to the carrier network, does not need to have storage capacity to store authentication details, etc.).
[0108] In the wireless communication system 200, environmental service components (e.g., application function 205, clearinghouse 210, tag controller 215, tag reader 230 including network entity 105-a and / or UE 115-a, and tag 220) can communicate using communication link 125. In some examples, communication link 125 may include a first channel 225-a for transmitting data from a first environmental service component to a second environmental service component and a second channel 225-b for transmitting data from the second environmental service component to the first environmental service component. Communication link 125 may be an example of transport layer security (TLS), an NR link, or an LTE link (among other examples) between environmental service components. Communication link 125 may include, for example, a bidirectional link enabling both uplink and downlink communication via channel 225. For example, a first environment service component (such as tag controller 215) may use a first channel 225-a (e.g., communication link 125) to send uplink messages 245 (e.g., uplink transmissions), such as uplink control signals or uplink data signals, to application function 205, and application function 205 may use a second channel 225-b (e.g., communication link 125) to send downlink messages 250 (e.g., downlink transmissions), such as downlink control signals or downlink data signals, to tag controller 215. In some examples, downlink message 250 may be part of control signaling sent from the network. Although in some examples the techniques described herein describe tag controller 215 communicating with tag 220, the techniques described herein may involve intermediate tag readers 230. For example, tag controller 215 may communicate with tag reader 230, which may communicate with tag 220, and tag 220 may communicate with tag reader 230 to communicate with tag controller 215 (e.g., relay communication). Moreover, although in some examples the techniques described herein describe application functions 205 that communicate with tag controller 215, the techniques described herein may involve application functions 205 that communicate with clearinghouse 210, which may communicate with tag controller 215.
[0109] In some examples, application function 205 may use a shared key shared with tag 220 (e.g., an ambient wireless device) to provide end-to-end protection for downlink command messages via tag controller 215 (e.g., end-to-end protection of commands by application function 205). For example, application function 205 may use a shared key shared with tag 220 to protect downlink message 250 (e.g., a command message). The shared key can provide encryption, integrity protection, and replay protection in communications.
[0110] In some examples, the freshness of the shared key can be ensured to prevent replay attacks. To provide freshness, a downlink counter can be used. The downlink counter can store the number or count of downlinks for the most recently successful command message. In some examples, the downlink counter can be strictly incremented. To provide freshness, a clock or timer can be used. A timer based on Coordinated Universal Time (UTC) can be used as a freshness parameter. The clock can be synchronized with the downlink message key sharing to provide precision for refreshing the key. For example, downlink key refresh can involve refreshing the key for each downlink message 250. The latest key (which will be used for the next command message) can be stored at tag 220, while other keys may not be stored at tag 220. A random number that can be generated by application function 205 can be used as a freshness parameter. The downlink key can be derived from the shared key. In this example, tag 220 may not have non-volatile memory.
[0111] In some examples, tag controller 215 may use a command protection key (CPK) provided by application function 205 to provide protection for downlink message 250 (e.g., command message), wherein downlink message 250 includes command verification token (CVT), and tag 220 uses command verification token to verify the tag controller 215’s authorization of downlink message 250 (e.g., command message) (e.g., the tag controller uses authorization verification token to protect the command).
[0112] Application function 205 may provide a verifiable CVT at tag 220, for example, using the application function's protection key (PK) or shared secret. The verifiable CVT ensures that command messages (e.g., downlink message 250) are generated by an authorized tag controller 215 and include the tag controller 215's authorization information.
[0113] In some examples, application function 205 may provide the CPK at tag controller 215 (e.g., instead of directly providing it to tag 220), and the CPK may be derived from a shared key between application function 205 and tag 220. The CPK may be PLMN-specific (or a specific tag controller 215), and in some examples, the PLMN and / or tag controller 215 may have limited sessions in the workflow. The PLMN's CPK or tag controller 215 may be associated with a network ID or PLMN ID and a maximum downlink counter, which may be part of a CVT. If multiple PLMNs use the same CPK, the authorized PLMNs may be listed in the token. Tag controller 215 may use the CPK to protect downlink messages 250 (e.g., command messages). Downlink messages 250 may use or include freshness parameters to achieve further message security (e.g., message protection), where the freshness parameter may be a counter, a random number, and / or a unique network parameter. For example, tag 220 may detect duplicates of unique network parameters (e.g., and may discard the entire downlink message 250), or in some examples, duplicates may not affect the validity of tag 220.
[0114] Downlink message 250 may include a CVT, and in some examples, it may be included in downlink message 250 in a single instance. For example, a CVT may be included in downlink message 250 when a CPK is first used. Tag controller 215 may obtain a new CVT after it expires or exceeds a CVT usage threshold. CVT provision may occur at tag 220 (e.g., for initial and updated CVTs).
[0115] In some examples, tag controller 215 may use a CPK provided by application function 205 to provide protection for downlink message 250 (e.g., a command message). Tag controller 215 may sign downlink command message 250 using a signing key (e.g., a private key associated with a certificate (or verification key)). (E.g., the tag controller uses a signature to enhance authorization proof to protect the command.) The certificate (or verification key) may be provided by application function 205 at tag 220 and may be used by tag 220 to verify the CPK of downlink message 250. The signature may provide tag 220 with assurance that downlink message 250 was transmitted by an authorized tag controller 215. For example, a CPK may be used to protect downlink message 250 (e.g., a command message) and may be a private key associated with a certificate or a signing key that may be a verification key associated with tag controller 215's private key or certificate. Tag controller 215 can use the signing key to sign the protected or encoded message again in order to prove the identity of tag controller 215 to tag 220 (e.g., tag verification authorized tag controller 215).
[0116] Application function 205 may provide the PK or certificate of tag controller 215 at tag 220. The PK or certificate may be time-dependent, making it valid for a threshold time. Application function 205 may provide a CPK to tag controller 215. The CPK may be derived from a shared key between application function 205 and tag 220, allowing tag 220 to authenticate messages from tag controller 215 based on the same CPK. The CPK may be specific to a PLMN or tag controller 215 and may expire after the threshold time. The CPK as a PLMN may be implemented using a network ID or PLMN ID and a downlink counter, which may be part of a CVT. In some examples, if the CPK will be used for multiple PLMNs, the PLMN ID may not be part of the CPK derivation. Tag controller 215 may use the CPK to secure downlink message 250 (e.g., a command message). Tag controller 215 may use a key associated with, for example, the PK or certificate in the first downlink message 250 to sign the downlink message 250. Signature verification can verify the CPK, which may not be used for every downlink message 250 (e.g., in subsequent downlink messages 250 after the first downlink message 250).
[0117] An authorization token that can be associated with the signature verification key can be included in the signed message to avoid direct token provision at tag 220. Providing tag controller 215 with the signature to protect downlink message 250 may involve the authorization of the tag controller 215 or PLMN's PK or certificate provision.
[0118] In some examples, tag controller 215 may use a CPK generated by tag controller 215 to provide protection for downlink messages 250 (e.g., command messages) (e.g., tag controller 215 uses its own key to protect downlink messages 250). In such examples, application function 205 may provide the PK or certificate of tag controller 215 at tag 220. The PK or certificate may be time-dependent. Tag controller 215 may generate a CPK and obtain a renewal token from application function 205. The token may be an encrypted CPK with additional authorization information provided by application function 205 (such as PLMN ID, tag controller ID, associated expiration time threshold, allowed commands, etc.). When the CPK expires, tag controller 215 may obtain a renewal token from application function 205 (e.g., token = Enc(shared key (SK), CPK, freshness parameter, authorization information, etc.)), where SK is the shared key between application function 205 and tag 220.
[0119] Tag controller 215 may use a CPK to protect downlink message 250 (e.g., a command message). Downlink message 250 may include a (renewal) token, and the token may not be encrypted because it is used to derive the CPK. Tag controller 215 may sign downlink message 250 using its own PK or certificate. Tag controller 215 may sign the first downlink message 250 but not subsequent downlink messages 250. Downlink message 250 may include a token issued from application function 205. The signature provides an indication of authorized use of the CPK (e.g., authorized transmitting device). Therefore, it is not necessary to use a direct token provided by application function 205. To enable tag controller 215 to protect downlink message 250 with the generated key, a PK or certificate may be provided to the authorized tag controller 215 or PLMN.
[0120] In some examples, tag controller 215 may provide downlink manifest messages (e.g., security manifests or paging) to multiple tags 220, for example, during multicast transmission. Tag controller 215 may receive a group key, and tag controller 215 may derive a manifest key. Tag controller 215 may use the manifest key to secure downlink manifest messages, and tags 220 may use the manifest key to verify authorization to tag controller 215.
[0121] In such examples, the group key K can be provided at multiple tags 220. G This group may include a group of tags 220 that can respond to a specific list downlink message 250. The list key K (used for group signaling) INV It can be derived from the group key. For example, K INV = KDF(K G The parameters include PLM information, frequency band information, time, frame number, etc. In some examples, the parameters may include the group ID provided at tag 220. K may also be provided at tag 220. INV Refresh cycle.
[0122] K INV It can be used to protect inventory downlink message 250 or create key-related waveforms. It can be combined with one or more freshness parameters (e.g., timers, counters, or random numbers) to protect inventory downlink message 250 or waveform generation from replay attacks. Tag 220 can be used with K... INV After verification, a response is given to the inventory message. Tag 220 enables a replay protection mechanism when the random number is used as a freshness parameter.
[0123] Figure 3An example of a process flow 300 supporting downlink message protection for an environment of wireless devices according to one or more aspects of this disclosure is shown. Process 300 may implement, or be implemented by, aspects of wireless communication system 100 or wireless communication system 200. For example, process flow 300 may include tag controller 215-a and tag 220-a, which may be examples of tag controller 215 and tag 220 as described herein. In the following description of process flow 300, operations performed by tag controller 215-a and tag 220-a may be performed in a different order than the exemplary order shown or at different times. Some operations in process flow 300 may also be omitted, or other operations may be added to process flow 300. Furthermore, although operations in process flow 300 are exemplified as being performed by tag controller 215-a and / or tag 220-a, the examples herein should not be construed as limiting, as the described features may be associated with and / or performed by any number of different devices, including devices other than tag controller 215-a and / or tag 220-a, as applicable.
[0124] At 305, tag 220-a (e.g., an ambient wireless device) can receive a downlink message that includes a first configuration for the ambient wireless device associated with one or more services (e.g., ambient wireless communication related services). The one or more services may be associated with location or tracking.
[0125] At 310, tag controller 215-a may enable one or more services at tag 220-a based on a first configuration. At 315, tag 220-a may receive an encoded downlink message including a first key. Receiving the encoded downlink message may be based on a change to one or more configurations for service, a response to a request from an ambient wireless device, or both. Receiving the encoded downlink message may include receiving an encoded downlink message from tag controller 215-a associated with network entity 105, wherein the encoded downlink message includes a signature. Receiving the encoded downlink message may include verifying authorization for tag controller 215-a to send the encoded downlink message to tag 220 based on the signature.
[0126] At 320, tag 220-a can decode the encoded downlink message based on a second key. The encoded downlink message may include a second configuration. The first and second keys may be, for example, a single shared key between the environmental radio device and the application function 205 associated with network entity 105. In some examples, the second key may be based on a shared key between tag 220 and the application function 205 associated with network entity 105. In some examples, the second key may be associated with one or more key refresh parameters. In some examples, the encoded downlink message may include a token. Receiving the encoded downlink message may include receiving the encoded downlink message from tag controller 215-a associated with network entity 105 via one or more UEs 115, and verifying authorization for tag controller 215-a to send the encoded downlink message to tag 220 based on the token. In some examples, the second key may be generated by tag controller 215-a associated with network entity 105. In some examples, the second key may be generated by application function 205 associated with network entity 105.
[0127] In some examples, at 325, decoding the encoded downlink message may include decoding the encoded downlink message based on a second key and a third key, wherein the third key includes a group key associated with a plurality of tags 220 and the second key includes a manifest key associated with the tags 220.
[0128] At 330, tag 220 can modify one or more services or activate response sending associated with tag 220-a based on a second configuration. In some examples, the manifest key can be based on a group key.
[0129] Figure 4An example of a process flow 400 supporting downlink message protection for an environment of wireless devices, according to one or more aspects of this disclosure, is shown. Process 400 may implement, or be implemented by, aspects of wireless communication system 100 or wireless communication system 200. For example, process flow 400 may include application function 205-a, tag controller 215-b, and tag reader 230-a, which may be examples of application function 205, tag controller 215, and tag reader 230 as described herein. In the following description of process flow 400, the operations performed by application function 205-a, tag controller 215-b, and tag reader 230-a may be performed in a different order than the exemplary order shown or at different times. Some operations in process flow 400 may also be omitted, or other operations may be added to process flow 400. Furthermore, although the operations in process flow 400 are illustrated as being performed by application function 205-a, tag controller 215-b, and tag reader 230-a, the examples in this document should not be construed as limiting, as the described features can be associated with any number of different devices.
[0130] At 405, tag controller 215-b may receive a message from application function 205-a associated with network entity 105. This message includes an encoded downlink message, downlink information used for the encoded downlink message, a first key, a token, or any combination thereof. The first key of the message may be based on a shared key between one or more tags 220 and application function 205-a. The first key of the message may be associated with one or more key refresh parameters.
[0131] At 410, the tag controller 215-b can determine one or more protection applications to be applied to the message. The one or more protection applications include one or more command protection applications, one or more manifest protection applications, or a combination thereof.
[0132] At 415, tag controller 215-b may apply one or more protection applications to a message to obtain an encoded downlink message. The encoded downlink message may include a token for the message. Applying one or more protection applications may include encoding downlink information of the message using a first key from application function 205-a, and sending the encoded downlink message for one or more tags 220.
[0133] In some examples, the application of one or more protection applications includes tag controller 215-b receiving an authorization token and a first key from application function 205-a, using the first key to encode downlink information of a message, using a message signing key to sign the encoded downlink information, and sending encoded downlink messages for one or more tags 220.
[0134] In some examples, applying one or more protection applications includes generating a first key at 420, using the first key at 425 to encode downlink information of a message, and sending an encoded downlink message for one or more tags 220. In some examples, applying one or more protection applications includes receiving a group key from application function 205-a, which is associated with at least one or more tags 220, using a manifest key based on the group key to encode downlink information of a message, and sending an encoded downlink message for one or more tags 220.
[0135] At 430, tag controller 215-b may send encoded downlink messages to tag reader 230-a in response to one or more ambient radio devices. Sending the encoded downlink messages may be based on a change to one or more configurations for services provided by one or more tags 220, a response to a request from one or more tags 220, or both. In some examples, sending the encoded downlink messages may include sending encoded downlink messages to one or more UEs 115 associated with one or more tags 220. The one or more UEs 115 may include a network reader, a device reader, or both.
[0136] Figure 5 A block diagram 500 of a device 505 supporting downlink message protection for an environmental wireless device according to one or more aspects of this disclosure is shown. Device 505 may be an example of various aspects of a UE 115 as described herein. Device 505 may include a receiver 510, a transmitter 515, and a communication manager 520. Device 505, or one or more components of device 505 (e.g., receiver 510, transmitter 515, and communication manager 520), may include at least one processor that may be coupled to at least one memory to individually or jointly support or implement the described techniques. Each of these components may communicate with each other (e.g., via one or more buses).
[0137] Receiver 510 may provide components for receiving information (such as packets, user data, control information, or any combination thereof) associated with various information channels (e.g., control channels, data channels, information channels related to downlink message protection for environmental wireless devices). The information may be passed to other components of device 505. Receiver 510 may utilize a single antenna or a collection of antennas.
[0138] Transmitter 515 may provide components for transmitting signals generated by other components of device 505. For example, transmitter 515 may transmit information (such as packets, user data, control information, or any combination thereof) associated with various information channels (e.g., control channels, data channels, information channels related to downlink message protection for environmental wireless devices). In some examples, transmitter 515 may be co-located with receiver 510 in a transceiver module. Transmitter 515 may utilize a single antenna or a collection of multiple antennas.
[0139] The communication manager 520, receiver 510, transmitter 515, or various combinations thereof, or various components thereof, may be examples of components used to perform various aspects of downlink message protection for an environment of wireless devices as described herein. For example, the communication manager 520, receiver 510, transmitter 515, or various combinations thereof, or components thereof, may be able to perform one or more of the functions described herein.
[0140] In some examples, the communication manager 520, receiver 510, transmitter 515, or various combinations or components thereof may be implemented in hardware (e.g., in communication management circuitry). The hardware may include at least one of the following: a processor, digital signal processor (DSP), central processing unit (CPU), graphics processing unit (GPU), neural processing unit (NPU), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, microcontroller, discrete gate or transistor logic component, discrete hardware component, or any combination thereof, configured as or otherwise individually or collectively to support components for performing the functions described herein. In some examples, at least one processor and at least one memory coupled to said at least one processor may be configured to perform one or more of the functions described herein (e.g., instructions stored in at least one memory are executed individually or collectively by one or more processors).
[0141] Additionally or alternatively, the communication manager 520, receiver 510, transmitter 515, or various combinations or components thereof may be implemented in hardware, software (e.g., executed by a processor), or any combination thereof, executed by at least one processor. If implemented in code (e.g., processor-executable code) executed by at least one processor, the functionality of the communication manager 520, receiver 510, transmitter 515, or various combinations or components thereof may be executed by a general-purpose processor, DSP, CPU, GPU, NPU, ASIC, FPGA, microcontroller, or any combination of these or other programmable logic devices (e.g., configured as or otherwise individually or collectively to support components for performing the functions described in this disclosure).
[0142] In some examples, the communication manager 520 may be configured to use a receiver 510, a transmitter 515, or both, or otherwise cooperate with them to perform various operations (e.g., receiving, acquiring, monitoring, outputting, transmitting). For example, the communication manager 520 may receive information from the receiver 510, transmit information to the transmitter 515, or integrate with the receiver 510, the transmitter 515, or both to acquire information, output information, or perform various other operations as described herein.
[0143] Communication manager 520 may support wireless communications according to examples disclosed herein. For example, communication manager 520 may be capable of, configured to, or operable to support components for receiving downlink messages including a first configuration for an ambient wireless device associated with one or more services. Communication manager 520 may be capable of, configured to, or operable to support components for enabling one or more services at the ambient wireless device based on the first configuration. Communication manager 520 may be capable of, configured to, or operable to support components for receiving encoded downlink messages including a first key. Communication manager 520 may be capable of, configured to, or operable to support components for decoding encoded downlink messages based on a second key, the encoded downlink messages including a second configuration. Communication manager 520 may be capable of, configured to, or operable to support components for modifying one or more services or activating response transmission associated with the ambient wireless device based on the second configuration.
[0144] By including or configuring a communication manager 520 according to an example as described herein, device 505 (e.g., controlling receiver 510, transmitter 515, communication manager 520 or a combination thereof or at least one processor otherwise coupled to these devices) can support techniques for facilitating the effective protection of downlink messages sent from a network (e.g., via application functions of the network) to an ambient wireless device without having to establish a secure connection between the network and the ambient wireless device, for example, where a secure connection is associated with complex processes and / or a large amount of storage space for storing authentication-related data.
[0145] Figure 6A block diagram 600 of a device 605 supporting downlink message protection for an environment wireless device according to one or more aspects of this disclosure is shown. Device 605 may be an example of aspects of device 505 or UE 115 as described herein. Device 605 may include a receiver 610, a transmitter 615, and a communication manager 620. Device 605, or one or more components of device 605 (e.g., receiver 610, transmitter 615, and communication manager 620), may include at least one processor that may be coupled to at least one memory to support the described techniques. Each of these components may communicate with each other (e.g., via one or more buses).
[0146] Receiver 610 may provide components for receiving information (such as packets, user data, control information, or any combination thereof) associated with various information channels (e.g., control channels, data channels, information channels related to downlink message protection for environmental wireless devices). The information may be passed to other components of device 605. Receiver 610 may utilize a single antenna or a collection of antennas.
[0147] Transmitter 615 may provide components for transmitting signals generated by other components of device 605. For example, transmitter 615 may transmit information (such as packets, user data, control information, or any combination thereof) associated with various information channels (e.g., control channels, data channels, information channels related to downlink message protection for environmental wireless devices). In some examples, transmitter 615 may be co-located with receiver 610 in a transceiver module. Transmitter 615 may utilize a single antenna or a collection of multiple antennas.
[0148] Device 605 or its various components may be examples of parts used to perform various aspects of downlink message protection for wireless devices in an environment as described herein. For example, communication manager 620 may include message manager 625, service manager 630, decoding manager 635, or any combination thereof. Communication manager 620 may be examples of aspects of communication manager 520 as described herein. In some examples, communication manager 620 or its various components may be configured to use receiver 610, transmitter 615, or both, or otherwise cooperate with them to perform various operations (e.g., receiving, acquiring, monitoring, outputting, transmitting). For example, communication manager 620 may receive information from receiver 610, transmit information to transmitter 615, or be integrated in combination with receiver 610, transmitter 615, or both to acquire information, output information, or perform various other operations as described herein.
[0149] Communication manager 620 can support wireless communication according to examples disclosed herein. Message manager 625 is capable of, configured to, or operable to support components for receiving downlink messages including a first configuration for an ambient wireless device associated with one or more services. Service manager 630 is capable of, configured to, or operable to support components for enabling one or more services at the ambient wireless device based on the first configuration. Message manager 625 is capable of, configured to, or operable to support components for receiving encoded downlink messages including a first key. Decoding manager 635 is capable of, configured to, or operable to support components for decoding encoded downlink messages based on a second key, the encoded downlink messages including a second configuration. Service manager 630 is capable of, configured to, or operable to support components for modifying one or more services or activating response transmission associated with the ambient wireless device based on the second configuration.
[0150] Figure 7 A block diagram 700 is shown of a communication manager 720 supporting downlink message protection for an environmental wireless device according to one or more aspects of this disclosure. The communication manager 720 may be an example of a communication manager 520, a communication manager 620, or aspects thereof as described herein. The communication manager 720 or its various components may be examples of parts for performing various aspects of downlink message protection for an environmental wireless device as described herein. For example, the communication manager 720 may include a message manager 725, a service manager 730, a decoding manager 735, an authorization manager 740, or any combination thereof. Each of these components, or its components or sub-components (e.g., one or more processors, one or more memories), may communicate directly or indirectly with each other (e.g., via one or more buses).
[0151] Communication manager 720 can support wireless communication according to examples disclosed herein. Message manager 725 is capable of, configured to, or operable to support components for receiving downlink messages including a first configuration for an ambient wireless device associated with one or more services. Service manager 730 is capable of, configured to, or operable to support components for enabling one or more services at the ambient wireless device based on the first configuration. In some examples, message manager 725 is capable of, configured to, or operable to support components for receiving encoded downlink messages including a first key. Decoding manager 735 is capable of, configured to, or operable to support components for decoding encoded downlink messages based on a second key, the encoded downlink messages including a second configuration. In some examples, service manager 730 is capable of, configured to, or operable to support components for modifying one or more services or activating response transmission associated with the ambient wireless device based on the second configuration.
[0152] In some examples, received encoded downlink messages are sent based on changes to one or more configurations used for service, responses to requests from ambient wireless devices, or both.
[0153] In some examples, the first key and the second key are a single shared key between the environmental wireless device and the application functions associated with the network entity.
[0154] In some examples, the second key is based on a shared key between the environmental wireless device and the application functionality associated with the network entity.
[0155] In some examples, the second key is associated with one or more key refresh parameters.
[0156] In some examples, the encoded downlink message includes a token.
[0157] In some examples, to support the reception of encoded downlink messages, message manager 725 is capable of, configured to, or operable to support components for receiving encoded downlink messages from an ambient radio controller associated with a network entity via one or more UEs. In some examples, to support the reception of encoded downlink messages, authorization manager 740 is capable of, configured to, or operable to support components for token-based authentication of authorization for the ambient radio controller to send encoded downlink messages to ambient radio devices.
[0158] In some examples, decoding of encoded downlink messages is based on using a token to verify authorization to the environment's wireless controller.
[0159] In some examples, the second key is generated by the environmental wireless controller associated with the network entity.
[0160] In some examples, the second key is generated by application functions associated with the network entity.
[0161] In some examples, to support the reception of encoded downlink messages, message manager 725 is capable of, configured to, or operable to support components for receiving encoded downlink messages from an ambient radio controller associated with a network entity, wherein the encoded downlink messages include a signature. In some examples, to support the reception of encoded downlink messages, authorization manager 740 is capable of, configured to, or operable to support components for verifying authorization of the ambient radio controller to send encoded downlink messages to ambient radio devices based on the signature.
[0162] In some examples, the one or more services are associated with location or tracking.
[0163] In some examples, in order to support the decoding of encoded downlink messages, the decoding manager 735 is capable of, configured to, or operable to support components for decoding encoded downlink messages based on a second key and a third key, wherein the third key includes a group key associated with a set of multiple ambient wireless devices and the second key includes a manifest key associated with the ambient wireless devices.
[0164] In some examples, the manifest key is based on the group key.
[0165] Figure 8 A diagram of a system 800 including device 805 supporting downlink message protection for wireless devices in an environment, according to one or more aspects of this disclosure, is shown. Device 805 may be an example of device 505, device 605, or UE 115 as described herein, or may include components thereof. Device 805 may communicate with one or more network entities 105, one or more UEs 115, or any combination thereof (e.g., wirelessly). Device 805 may include components for bidirectional voice and data communication, including components for transmitting and receiving communications, such as a communication manager 820, an input / output (I / O) controller 810, a transceiver 815, an antenna 825, at least one memory 830, code 835 (e.g., processor-executable code), and at least one processor 840. These components may communicate electronically or be coupled in other ways (e.g., operational ground, communication ground, functional ground, electronic ground, electrical ground) via one or more buses (e.g., bus 845).
[0166] I / O controller 810 manages the input and output signals of device 805. I / O controller 810 can also manage peripheral devices not integrated into device 805. In some cases, I / O controller 810 may represent a physical connection or port to an external peripheral device. In some cases, I / O controller 810 may utilize an operating system such as iOS. ® ANDROID ® MS-DOS ® MS-WINDOWS ® OS / 2 ® UNIX ® LINUX ® Or another known operating system. Additionally or alternatively, the I / O controller 810 may represent or interact with a modem, keyboard, mouse, touchscreen, or similar device. In some cases, the I / O controller 810 may be implemented as part of one or more processors, such as at least one processor 840. In some cases, a user may interact with the device 805 via the I / O controller 810 or via hardware components controlled by the I / O controller 810.
[0167] In some cases, device 805 may include a single antenna 825. However, in other cases, device 805 may have more than one antenna 825, which may be capable of concurrently transmitting or receiving multiple wireless transmissions. Transceiver 815 may communicate bidirectionally via one or more antennas 825, a wired link, or a wireless link as described herein. For example, transceiver 815 may represent a wireless transceiver and may communicate bidirectionally with another wireless transceiver. Transceiver 815 may also include a modem for: modulating packets; providing the modulated packets to one or more antennas 825 for transmission; and demodulating packets received from one or more antennas 825. Transceiver 815, or transceiver 815 and one or more antennas 825, may be an example of transmitter 515, transmitter 615, receiver 510, receiver 610, or any combination thereof or components thereof as described herein.
[0168] At least one memory 830 may include random access memory (RAM) and read-only memory (ROM). At least one memory 830 may store computer-readable, computer-executable code 835, including instructions (e.g., processor-executable code), which, when executed by at least one processor 840, cause device 805 to perform the various functions described herein. Code 835 may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. In some cases, code 835 may not be directly executable by at least one processor 840, but may enable a computer (e.g., when compiled and executed) to perform the functions described herein. In some cases, at least one memory 830 may contain a basic I / O system (BIOS), etc., which controls basic hardware or software operations, such as interaction with peripheral components or devices.
[0169] At least one processor 840 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some cases, at least one processor 840 may be configured to operate a memory array using a memory controller. In some other cases, the memory controller may be integrated into at least one processor 840. At least one processor 840 may be configured to execute computer-readable instructions stored in memory (e.g., at least one memory 830) to cause device 805 to perform various functions (e.g., functions or tasks supporting downlink message protection for environmental wireless devices). For example, device 805 or components of device 805 may include at least one processor 840 and at least one memory 830 coupled to or coupled to at least one processor 840, the at least one processor 840 and at least one memory 830 being configured to perform the various functions described herein. In some examples, at least one processor 840 may include multiple processors, and at least one memory 830 may include multiple memories. One or more of a plurality of processors may be coupled to one or more of a plurality of memories, which may be configured individually or collectively to perform the various functions described herein. In some examples, at least one processor 840 may be a component of a processing system, which may refer to a system of machines (such as a series of machines), circuitry (including, for example, one or both of processor circuitry (which may include at least one processor 840) and memory circuitry (which may include at least one memory 830)) or components that receive or receive input and process the input to produce, generate or obtain a set of outputs. The processing system may be configured to perform one or more of the functions described herein. For example, at least one processor 840 or a processing system including at least one processor 840 may be configured, capable of being configured to, or operable to cause device 805 to perform one or more of the functions described herein. Furthermore, as described herein, “configured to,” “capable of being configured to,” and “operable to” are used interchangeably and may be associated with the ability to perform one or more of the functions described herein when executing code stored in at least one memory 830 or otherwise.
[0170] The communication manager 820 may support wireless communications according to examples disclosed herein. For example, the communication manager 820 may be capable of, configured to, or operable to support components for receiving downlink messages including a first configuration for an ambient wireless device associated with one or more services. The communication manager 820 may be capable of, configured to, or operable to support components for enabling one or more services at the ambient wireless device based on the first configuration. The communication manager 820 may be capable of, configured to, or operable to support components for receiving encoded downlink messages including a first key. The communication manager 820 may be capable of, configured to, or operable to support components for decoding encoded downlink messages based on a second key, the encoded downlink messages including a second configuration. The communication manager 820 may be capable of, configured to, or operable to support components for modifying one or more services or activating response transmission associated with the ambient wireless device based on the second configuration.
[0171] By including or configuring a communication manager 820 according to an example as described herein, device 805 may support techniques for facilitating the effective protection of downlink messages sent from a network (e.g., via application functions of the network) to an ambient wireless device without having to establish a secure connection between the network and the ambient wireless device, for example, where a secure connection is associated with complex processes and / or a large amount of storage space for storing authentication-related data.
[0172] In some examples, the communication manager 820 may be configured to perform various operations (e.g., receiving, monitoring, transmitting) using a transceiver 815, one or more antennas 825, or any combination thereof, or otherwise cooperating with them. Although the communication manager 820 is illustrated as a separate component, in some examples, one or more functions described with reference to the communication manager 820 may be supported or performed by at least one processor 840, at least one memory 830, code 835, or any combination thereof. For example, code 835 may include instructions that can be executed by at least one processor 840 to cause device 805 to perform various aspects of downlink message protection for environmental wireless devices as described herein, or at least one processor 840 and at least one memory 830 may be otherwise configured to perform or support such operations individually or jointly.
[0173] Figure 9A block diagram 900 illustrates a device 905 supporting downlink message protection for an environment of wireless devices according to one or more aspects of this disclosure. Device 905 may be an example of aspects of network entity 105 as described herein. Device 905 may include a receiver 910, a transmitter 915, and a communication manager 920. Device 905, or one or more components of device 905 (e.g., receiver 910, transmitter 915, and communication manager 920), may include at least one processor that may be coupled to at least one memory to individually or jointly support or implement the described techniques. Each of these components may communicate with each other (e.g., via one or more buses).
[0174] Receiver 910 may provide components for acquiring (e.g., receiving, determining, identifying) information (such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units)) associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack). The information may be passed to other components of device 905. In some examples, receiver 910 may support acquiring information by receiving signals via one or more antennas. Additionally or alternatively, receiver 910 may support acquiring information by receiving signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof.
[0175] Transmitter 915 may provide components for outputting (e.g., transmitting, providing, conveying, transmitting) information generated by other components of device 905. For example, transmitter 915 may output information associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack), such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units). In some examples, transmitter 915 may support outputting information by transmitting signals via one or more antennas. Additionally or alternatively, transmitter 915 may support outputting information by transmitting signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof. In some examples, transmitter 915 and receiver 910 may be co-located in a transceiver, which may include or be coupled to a modem.
[0176] The communication manager 920, receiver 910, transmitter 915, or various combinations thereof, or various components thereof, may be examples of components used to perform various aspects of downlink message protection for environmental wireless devices as described herein. For example, the communication manager 920, receiver 910, transmitter 915, or various combinations thereof, or components thereof, may be able to perform one or more of the functions described herein.
[0177] In some examples, the communication manager 920, receiver 910, transmitter 915, or various combinations or components thereof may be implemented in hardware (e.g., in communication management circuitry). The hardware may include at least one of a processor, DSP, CPU, GPU, ASIC, FPGA, or other programmable logic device, microcontroller, discrete gate or transistor logic device, discrete hardware component, or any combination thereof, configured as or otherwise individually or collectively to support components for performing the functions described herein. In some examples, at least one processor and at least one memory coupled to said at least one processor may be configured to perform one or more of the functions described herein (e.g., instructions stored in at least one memory are executed individually or collectively by one or more processors).
[0178] Additionally or alternatively, the communication manager 920, receiver 910, transmitter 915, or various combinations or components thereof may be implemented in code executed by at least one processor (e.g., as communication management software). If implemented in code executed by at least one processor, the functionality of the communication manager 920, receiver 910, transmitter 915, or various combinations or components thereof may be performed by any combination of a general-purpose processor, DSP, CPU, GPU, ASIC, FPGA, microcontroller, or these or other programmable logic devices (e.g., configured as or otherwise individually or jointly to support components for performing the functions described in this disclosure).
[0179] In some examples, the communication manager 920 may be configured to use a receiver 910, a transmitter 915, or both, or otherwise cooperate with them to perform various operations (e.g., receiving, acquiring, monitoring, outputting, transmitting). For example, the communication manager 920 may receive information from the receiver 910, transmit information to the transmitter 915, or integrate with the receiver 910, the transmitter 915, or both to acquire information, output information, or perform various other operations as described herein.
[0180] The communication manager 920 can support wireless communications according to examples disclosed herein. For example, the communication manager 920 can, is configured to, or is operable to support components for receiving messages from application functions associated with network entities. The communication manager 920 can, is configured to, or is operable to support components for determining one or more protection applications to be applied to a message. The communication manager 920 can, is configured to, or is operable to support components for applying one or more protection applications to a message to obtain an encoded downlink message. The communication manager 920 can, is configured to, or is operable to support components for transmitting encoded downlink messages to one or more environmental wireless devices.
[0181] By including or configuring a communication manager 920 according to an example as described herein, device 905 (e.g., controlling receiver 910, transmitter 915, communication manager 920 or a combination thereof, or at least one processor otherwise coupled to these devices) can support techniques for facilitating the effective protection of downlink messages sent from a network (e.g., via application functions of the network) to an ambient wireless device without having to establish a secure connection between the network and the ambient wireless device, for example, where a secure connection is associated with complex processes and / or a large amount of storage space for storing authentication-related data.
[0182] Figure 10 A block diagram 1000 of a device 1005 supporting downlink message protection for an environment of wireless devices, according to one or more aspects of this disclosure, is shown. Device 1005 may be an example of aspects of device 905 or network entity 105 as described herein. Device 1005 may include receiver 1010, transmitter 1015, and communication manager 1020. Device 1005, or one or more components of device 1005 (e.g., receiver 1010, transmitter 1015, and communication manager 1020), may include at least one processor that may be coupled to at least one memory to support the described techniques. Each of these components may communicate with each other (e.g., via one or more buses).
[0183] Receiver 1010 may provide components for acquiring (e.g., receiving, determining, identifying) information (such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units)) associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack). The information may be passed to other components of device 1005. In some examples, receiver 1010 may support acquiring information by receiving signals via one or more antennas. Additionally or alternatively, receiver 1010 may support acquiring information by receiving signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof.
[0184] Transmitter 1015 may provide components for outputting (e.g., transmitting, providing, conveying, transmitting) information generated by other components of device 1005. For example, transmitter 1015 may output information associated with various channels (e.g., control channels, data channels, information channels, channels associated with a protocol stack), such as user data, control information, or any combination thereof (e.g., I / Q samples, symbols, packets, protocol data units, service data units). In some examples, transmitter 1015 may support outputting information by transmitting signals via one or more antennas. Additionally or alternatively, transmitter 1015 may support outputting information by transmitting signals via one or more wired (e.g., electrical, fiber optic) interfaces, wireless interfaces, or any combination thereof. In some examples, transmitter 1015 and receiver 1010 may be co-located in a transceiver, which may include or be coupled to a modem.
[0185] Device 1005 or its various components may be examples of parts used to perform various aspects of downlink message protection for environmental wireless devices as described herein. For example, communication manager 1020 may include message manager 1025, protection application function manager 1030, encoding manager 1035, or any combination thereof. Communication manager 1020 may be examples of aspects of communication manager 920 as described herein. In some examples, communication manager 1020 or its various components may be configured to use receiver 1010, transmitter 1015, or both, or otherwise cooperate with them to perform various operations (e.g., receiving, acquiring, monitoring, outputting, transmitting). For example, communication manager 1020 may receive information from receiver 1010, transmit information to transmitter 1015, or integrate in combination with receiver 1010, transmitter 1015, or both to acquire information, output information, or perform various other operations as described herein.
[0186] Communication manager 1020 can support wireless communication according to examples disclosed herein. Message manager 1025 is capable of, configured to, or operable to support components for receiving messages from application functions associated with network entities. Protection application function manager 1030 is capable of, configured to, or operable to support components for determining one or more protection applications to be applied to a message. Encoding manager 1035 is capable of, configured to, or operable to support components for applying one or more protection applications to a message to obtain an encoded downlink message. Message manager 1025 is capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more environmental wireless devices.
[0187] Figure 11A block diagram 1100 is shown of a communication manager 1120 supporting downlink message protection for an environmental wireless device according to one or more aspects of this disclosure. The communication manager 1120 may be an example of a communication manager 920, a communication manager 1020, or aspects thereof as described herein. The communication manager 1120 or its various components may be examples of parts for performing various aspects of downlink message protection for an environmental wireless device as described herein. For example, the communication manager 1120 may include a message manager 1125, a protection application function manager 1130, an encoding manager 1135, an authentication tag manager 1140, a signature tag manager 1145, a key generator manager 1150, or any combination thereof. Each of these components, or its components or sub-components (e.g., one or more processors, one or more memories), may communicate directly or indirectly with each other (e.g., via one or more buses). This communication may include communication within the protocol layers of the protocol stack, communication associated with logical channels of the protocol stack (e.g., between protocol layers of the protocol stack, within devices, components, or virtualization components associated with network entity 105, between devices, components, or virtualization components associated with network entity 105), or any combination thereof.
[0188] Communication manager 1120 can support wireless communication according to examples disclosed herein. Message manager 1125 is capable of, configured to, or operable to support components for receiving messages from application functions associated with network entities. Protection application function manager 1130 is capable of, configured to, or operable to support components for determining one or more protection applications to be applied to a message. Encoding manager 1135 is capable of, configured to, or operable to support components for applying one or more protection applications to a message to obtain an encoded downlink message. In some examples, message manager 1125 is capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more wireless devices in an environment.
[0189] In some examples, the message includes an encoded downlink message, downlink information used to encode the downlink message, a first key, a token, or any combination thereof.
[0190] In some examples, one or more protection applications include one or more command protection applications, one or more manifest protection applications, or a combination thereof.
[0191] In some examples, the transmission of encoded downlink messages is based on changes to one or more configurations for services provided by one or more ambient wireless devices, responses to requests from one or more ambient wireless devices, or both.
[0192] In some examples, the first key for the message is based on a shared key between one or more environmental wireless devices and the application functionality.
[0193] In some examples, the message's first key is associated with one or more key refresh parameters.
[0194] In some examples, the encoded downlink message includes a message token.
[0195] In some examples, in order to support the transmission of encoded downlink messages, message manager 1125 is capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more UEs associated with one or more environmental radio devices.
[0196] In some examples, one or more UEs include a network reader, a device reader, or both.
[0197] In some examples, to support the application of one or more protection applications, the encoding manager 1135 is capable of, configured to, or operable to support components for encoding downlink information of messages using a first key from the application functionality. In some examples, to support the application of one or more protection applications, the message manager 1125 is capable of, configured to, or operable to support components for transmitting encoded downlink messages for one or more environmental wireless devices.
[0198] In some examples, to support the application of one or more protection applications, the authentication manager 1140 is capable of, configured to, or operable to support components for receiving an authorization token and a first key from the application functionality. In some examples, to support the application of one or more protection applications, the encoding manager 1135 is capable of, configured to, or operable to support components for encoding downlink information of a message using the first key of the message. In some examples, to support the application of one or more protection applications, the signature manager 1145 is capable of, configured to, or operable to support components for signing encoded downlink information using a signature key of the message, wherein the signed encoded downlink information includes an authorization token. In some examples, to support the application of one or more protection applications, the message manager 1125 is capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more wireless devices in an environment.
[0199] In some examples, to support the application of one or more protection applications, the key generator manager 1150 is capable of, configured to, or operable to support components for generating a first key. In some examples, to support the application of one or more protection applications, the encoding manager 1135 is capable of, configured to, or operable to support components for encoding downlink information of a message using the first key. In some examples, to support the application of one or more protection applications, the message manager 1125 is capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more wireless devices in an environment.
[0200] In some examples, to support the application of one or more protection applications, message manager 1125 is capable of, configured to, or operable to support components for receiving a group key from the application function, the group key being associated with at least one or more environmental wireless devices. In some examples, to support the application of one or more protection applications, encoding manager 1135 is capable of, configured to, or operable to support components for encoding downlink information of messages using a manifest key based on the group key. In some examples, to support the application of one or more protection applications, message manager 1125 is capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more environmental wireless devices.
[0201] Figure 12 A diagram of a system 1200 including device 1205 supporting downlink message protection for an environment of wireless devices, according to one or more aspects of this disclosure, is shown. Device 1205 may be an example of device 905, device 1005, or network entity 105 as described herein, or may include components thereof. Device 1205 may communicate with one or more network entities 105, one or more UEs 115, or any combination thereof, and such communication may include communication via one or more wired interfaces, one or more wireless interfaces, or any combination thereof. Device 1205 may include components that support output and enable communication, such as a communication manager 1220, a transceiver 1210, an antenna 1215, at least one memory 1225, code 1230, and at least one processor 1235. These components may communicate electronically or otherwise (e.g., operative ground, communicative ground, functional ground, electronic ground, electrical ground) via one or more buses (e.g., bus 1240).
[0202] Transceiver 1210 may support bidirectional communication via a wired link, a wireless link, or both, as described herein. In some examples, transceiver 1210 may include a wired transceiver and be capable of bidirectional communication with another wired transceiver. Additionally or alternatively, in some examples, transceiver 1210 may include a wireless transceiver and be capable of bidirectional communication with another wireless transceiver. In some examples, device 1205 may include one or more antennas 1215 that are capable of (e.g., concurrently) transmitting or receiving wireless transmissions. Transceiver 1210 may also include a modem for: modulating a signal; providing the modulated signal for transmission (e.g., by one or more antennas 1215, by a wired transmitter); receiving the modulated signal (e.g., from one or more antennas 1215, from a wired receiver); and demodulating the signal. In some embodiments, transceiver 1210 may include one or more interfaces, such as one or more interfaces coupled to one or more antennas 1215 configured to support various receive or acquire operations, or one or more interfaces coupled to one or more antennas 1215 configured to support various transmit or output operations, or combinations thereof. In some embodiments, transceiver 1210 may include one or more processors or one or more memory components, or be configured to couple to such processors or memory components, which are operable to perform or support operations based on received or acquired information or signals, or generate information or other signals for transmission or other output, or any combination thereof. In some embodiments, transceiver 1210, or transceiver 1210 and one or more antennas 1215, or transceiver 1210 and one or more antennas 1215, and one or more processors or one or more memory components (e.g., at least one processor 1235, at least one memory 1225, or both), may be included in a chip or chip assembly mounted in device 1205. In some examples, transceiver 1210 may be able to operate to support communication via one or more communication links (e.g., communication link 125, backhaul communication link 120, midhaul communication link 162, and fronthaul communication link 168).
[0203] At least one memory 1225 may include RAM, ROM, or any combination thereof. At least one memory 1225 may store computer-readable, computer-executable code 1230 including instructions that, when executed by one or more of at least one processor 1235, cause device 1205 to perform the various functions described herein. Code 1230 may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. In some cases, code 1230 may not be directly executable by a processor in at least one processor 1235, but may enable a computer (e.g., when compiled and executed) to perform the functions described herein. In some cases, among others, at least one memory 1225 may also include a BIOS that controls basic hardware or software operations, such as interaction with peripheral components or devices. In some examples, at least one processor 1235 may include multiple processors, and at least one memory 1225 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, which may be configured individually or collectively to perform the various functions described herein (e.g., as part of a processing system).
[0204] At least one processor 1235 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, ASICs, CPUs, GPUs, FPGAs, microcontrollers, programmable logic devices, discrete gate or transistor logic units, discrete hardware components, or any combination thereof). In some cases, at least one processor 1235 may be configured to operate a memory array using a memory controller. In some other cases, the memory controller may be integrated into one or more processors in at least one processor 1235. At least one processor 1235 may be configured to execute computer-readable instructions stored in memory (e.g., one or more of at least one memory 1225) to cause device 1205 to perform various functions (e.g., functions or tasks supporting downlink message protection for environmental wireless devices). For example, device 1205 or components of device 1205 may include at least one processor 1235 and at least one memory 1225 coupled to one or more of at least one processor 1235, wherein at least one processor 1235 and at least one memory 1225 are configured to perform the various functions described herein. At least one processor 1235 may be an example of a cloud computing platform (e.g., one or more physical nodes and supporting software such as an operating system, virtual machine, or container instance) that can (e.g., by executing code 1230) host functions for performing the functions of device 1205. At least one processor 1235 may be any one or more suitable processors capable of executing scripts or instructions of one or more software programs stored in device 1205 (such as within one or more memories of at least one memory 1225). In some examples, at least one processor 1235 may include multiple processors, and at least one memory 1225 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, which may be configured individually or collectively to perform the various functions described herein. In some examples, at least one processor 1235 may be a component of a processing system, which may refer to a system of machines (such as a series of machines), circuits (including, for example, one or both of processor circuitry (which may include at least one processor 1235) and memory circuitry (which may include at least one memory 1225)) or components that receive or acquire input and process the input to produce, generate, or acquire a set of outputs. The processing system may be configured to perform one or more of the functions described herein. For example, at least one processor 1235 or a processing system including at least one processor 1235 may be configured, configured to, or operable to cause the device 1205 to perform one or more of the functions described herein.Furthermore, as described herein, “configured to,” “capable of being configured to,” and “capable of operating to” are used interchangeably and may be associated with the ability to perform one or more of the functions described herein when executing code stored in at least one memory 1225 or otherwise.
[0205] In some examples, bus 1240 may support communication at the protocol layer of the protocol stack (e.g., within a protocol layer). In some examples, bus 1240 may support communication associated with logical channels of the protocol stack (e.g., between protocol layers of the protocol stack), which may include communication performed within components of device 1205, or communication performed between different components of device 1205 that are co-addressable or may be located in different locations (e.g., where device 1205 may refer to a system in which one or more of communication manager 1220, transceiver 1210, at least one memory 1225, code 1230 and at least one processor 1235 may be located in one component of different components or partitioned between different components).
[0206] In some examples, the communication manager 1220 can manage (e.g., via one or more wired or wireless backhaul links) various aspects of communication with the core network 130. For example, the communication manager 1220 can manage the transfer of data communication with client devices, such as one or more UEs 115. In some examples, the communication manager 1220 can manage communication with other network entities 105 and may include a controller or scheduler for cooperating with other network entities 105 to control communication with UE 115. In some examples, the communication manager 1220 may support the X2 interface within LTE / LTE-A wireless communication network technology to provide communication between network entities 105.
[0207] Communication manager 1220 may support wireless communications according to examples disclosed herein. For example, communication manager 1220 may be capable of, configured to, or operable to support components for receiving messages from application functions associated with network entities. Communication manager 1220 may be capable of, configured to, or operable to support components for determining one or more protection applications to be applied to a message. Communication manager 1220 may be capable of, configured to, or operable to support components for applying one or more protection applications to a message to obtain an encoded downlink message. Communication manager 1220 may be capable of, configured to, or operable to support components for transmitting encoded downlink messages to one or more wireless devices in an environment.
[0208] By including or configuring a communication manager 1220 according to an example as described herein, device 1205 may support techniques for facilitating the effective protection of downlink messages sent from a network (e.g., via application functions of the network) to an ambient wireless device without having to establish a secure connection between the network and the ambient wireless device, for example, where a secure connection is associated with complex processes and / or a large amount of storage space for storing authentication-related data.
[0209] In some examples, the communication manager 1220 may be configured to use or otherwise coordinate with the transceiver 1210, one or more antennas 1215 (e.g., where applicable), or any combination thereof to perform various operations (e.g., receive, acquire, monitor, output, transmit). Although the communication manager 1220 is illustrated as a separate component, in some examples, one or more functions described with reference to the communication manager 1220 may be supported or performed by the transceiver 1210, one or more processors in at least one processor 1235, one or more memories in at least one memory 1225, code 1230, or any combination thereof (e.g., by a processing system including at least a portion of at least one processor 1235, at least one memory 1225, code 1230, or any combination thereof). For example, code 1230 may include instructions that can be executed by one or more of at least one processor 1235 to cause device 1205 to perform various aspects of downlink message protection for an environment wireless device as described herein, or at least one processor 1235 and at least one memory 1225 may be otherwise configured to perform or support such operations individually or jointly.
[0210] Figure 13 A flowchart illustrating a method 1300 for supporting downlink message protection for an environmental wireless device according to one or more aspects of this disclosure is shown. Operation of method 1300 may be implemented by a UE or its components as described herein. For example, operation of method 1300 may be performed by, as referenced... Figures 1 to 8 The UE 115 described herein is used to perform this function. In some examples, the UE can execute a set of instructions to control the functional elements of the UE to perform the described function. Additionally or alternatively, the UE may use dedicated hardware to perform aspects of the described function.
[0211] At 1305, the method may include receiving a downlink message including a first configuration for an environmental wireless device associated with one or more services. Operation of block 1305 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1305 may be provided by reference to [reference needed]. Figure 7 The message manager 725 described is used to execute this.
[0212] At 1310, the method may include enabling one or more services at an environmental wireless device, at least in part, based on a first configuration. Operation of block 1310 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1310 may be derived from references... Figure 7 The described service manager 730 is used to execute this.
[0213] At 1315, the method may include receiving an encoded downlink message including a first key. The operation of block 1315 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1315 may be derived from references... Figure 7 The message manager 725 described is used to execute this.
[0214] At 1320, the method may include decoding an encoded downlink message, which includes a second configuration, at least in part based on a second key. The operation of block 1320 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1320 may be derived from references... Figure 7 The described decoding manager 735 is used to execute this.
[0215] At 1325, the method may include modifying one or more services or activating response transmission associated with an environmental wireless device, at least in part, based on a second configuration. Operation of block 1325 may be performed according to examples as disclosed herein. In some examples, aspects of operation of 1325 may be provided by reference to [reference needed]. Figure 7 The described service manager 730 is used to execute this.
[0216] Figure 14 A flowchart illustrating a method 1400 for supporting downlink message protection for an environmental wireless device according to one or more aspects of this disclosure is shown. Operation of method 1400 may be implemented by a UE or its components as described herein. For example, operation of method 1400 may be performed by, as referenced... Figures 1 to 8 The UE 115 described herein is used to perform this function. In some examples, the UE can execute a set of instructions to control the functional elements of the UE to perform the described function. Additionally or alternatively, the UE may use dedicated hardware to perform aspects of the described function.
[0217] At 1405, the method may include receiving a downlink message including a first configuration for an environmental wireless device associated with one or more services. Operation of block 1405 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1405 may be provided by reference to [reference needed]. Figure 7 The message manager 725 described is used to execute this.
[0218] At 1410, the method may include enabling one or more services at an environmental wireless device, at least in part, based on a first configuration. Operation of block 1410 may be performed according to examples as disclosed herein. In some examples, aspects of operation of 1410 may be derived from references... Figure 7 The described service manager 730 is used to execute this.
[0219] At 1415, the method may include receiving an encoded downlink message including a first key. The operation of block 1415 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1415 may be derived from references... Figure 7 The message manager 725 described is used to execute this.
[0220] At 1420, the method may include decoding an encoded downlink message, which includes a second configuration, at least partially based on a second key. The operation of block 1420 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1420 may be derived from references... Figure 7 The described decoding manager 735 is used to execute this.
[0221] At 1425, the method may include decoding the encoded downlink message based at least in part on a second key and a third key, wherein the third key includes a group key associated with a set of multiple ambient radio devices and the second key includes a manifest key associated with the ambient radio devices. The operation of block 1425 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1425 may be derived from references... Figure 7 The described decoding manager 735 is used to execute this.
[0222] At 1430, the method may include modifying one or more services or activating response transmission associated with an environmental wireless device, at least in part, based on a second configuration. Operation of block 1430 may be performed according to examples as disclosed herein. In some examples, aspects of operation of 1430 may be derived from references... Figure 7 The described service manager 730 is used to execute this.
[0223] Figure 15 A flowchart illustrating a method 1500 for downlink message protection for an environment wireless device, according to one or more aspects of this disclosure, is shown. Operation of method 1500 may be implemented by a network entity or its components as described herein. For example, operation of method 1500 may be implemented by, as referenced... Figures 1 to 4 as well as Figures 9 to 12The network entity described is used to perform this function. In some examples, the network entity may execute a set of instructions to control the functional elements of the network entity to perform the described function. Additionally or alternatively, the network entity may use dedicated hardware to perform aspects of the described function.
[0224] At 1505, the method may include receiving a message from an application function associated with a network entity. The operation of box 1505 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1505 may be provided by reference to [reference needed]. Figure 11 The message manager 1125 described is used for execution.
[0225] At 1510, the method may include determining one or more protection applications to be applied to the message. The operation of box 1510 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1510 may be determined by reference to [reference needed]. Figure 11 The described protection application function manager 1130 is used to perform this.
[0226] At 1515, the method may include applying one or more protection applications to a message to obtain an encoded downlink message. The operation of box 1515 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1515 may be provided by reference to [reference needed]. Figure 11 The described encoding manager 1135 is used to execute this.
[0227] At 1520, the method may include transmitting encoded downlink messages to one or more environmental wireless devices. The operation of block 1520 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1520 may be derived from references... Figure 11 The message manager 1125 described is used for execution.
[0228] Figure 16 A flowchart illustrating a method 1600 for downlink message protection for an environment wireless device, according to one or more aspects of this disclosure, is shown. Operation of method 1600 may be implemented by a network entity or its components as described herein. For example, operation of method 1600 may be implemented by, as referenced... Figures 1 to 4 as well as Figures 9 to 12 The network entity described is used to perform this function. In some examples, the network entity may execute a set of instructions to control the functional elements of the network entity to perform the described function. Additionally or alternatively, the network entity may use dedicated hardware to perform aspects of the described function.
[0229] At 1605, the method may include receiving a message from an application function associated with a network entity. The operation of box 1605 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1605 may be derived from references... Figure 11 The message manager 1125 described is used for execution.
[0230] At 1610, the method may include determining one or more protection applications to be applied to the message. The operation of box 1610 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1610 may be determined by reference to [reference needed]. Figure 11 The described protection application function manager 1130 is used to perform this.
[0231] At 1615, the method may include applying one or more protection applications to a message to obtain an encoded downlink message. The operation of box 1615 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1615 may be provided by reference to [reference needed]. Figure 11 The described encoding manager 1135 is used to execute this.
[0232] At 1620, the method may include transmitting encoded downlink messages to one or more environmental wireless devices. Operation of block 1620 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1620 may be derived from references... Figure 11 The message manager 1125 described is used for execution.
[0233] At 1625, the method may include sending an encoded downlink message to one or more UEs associated with one or more environmental radio devices. Operation of block 1625 may be performed according to examples as disclosed herein. In some examples, aspects of the operation of 1625 may be derived from references... Figure 11 The message manager 1125 described is used for execution.
[0234] The following provides an overview of the various aspects of this disclosure: Aspect 1: A method for wireless communication at an ambient wireless device, the method comprising: receiving a downlink message including a first configuration for the ambient wireless device associated with one or more services; enabling the one or more services at the ambient wireless device at least in part based on the first configuration; receiving an encoded downlink message including a first key; decoding the encoded downlink message, including a second configuration, at least in part based on a second key; and modifying the one or more services or activating a response transmission associated with the ambient wireless device at least in part based on the second configuration.
[0235] Aspect 2: According to the method of aspect 1, the reception of the encoded downlink message is based at least in part on a change to one or more configurations for service, a response to a request from a wireless device in the environment, or both.
[0236] Aspect 3: The method according to any one of Aspects 1 to 2, wherein the first key and the second key are a single shared key between the environmental wireless device and the application function associated with the network entity.
[0237] Aspect 4: The method according to any one of Aspects 1 to 3, wherein the second key is at least in part based on a shared key between the environmental wireless device and the application function associated with the network entity.
[0238] Aspect 5: The method according to any one of Aspects 1 to 4, wherein the second key is associated with one or more key refresh parameters.
[0239] Aspect 6: The method according to any one of Aspects 1 to 5, wherein the encoded downlink message further includes a token.
[0240] Aspect 7: According to the method of aspect 6, receiving the encoded downlink message further includes: receiving the encoded downlink message from an ambient radio controller associated with a network entity via one or more UEs; and verifying authorization for the ambient radio controller to send the encoded downlink message to the ambient radio device based at least in part on the token.
[0241] Aspect 8: According to the method of aspect 7, wherein decoding of the encoded downlink message is based at least in part on using the token to verify authorization to the environment's wireless controller.
[0242] Aspect 9: The method according to any one of Aspects 1 to 8, wherein the second key is generated by an environmental wireless controller associated with the network entity.
[0243] Aspect 10: The method according to any one of Aspects 1 to 9, wherein the second key is generated by an application function associated with a network entity.
[0244] Aspect 11: The method according to any one of Aspects 1 to 10, wherein receiving the encoded downlink message further comprises: receiving the encoded downlink message from an ambient radio controller associated with a network entity, wherein the encoded downlink message includes a signature; and verifying, at least in part, an authorization for the ambient radio controller to send the encoded downlink message to the ambient radio device based on the signature.
[0245] Aspect 12: The method according to any one of aspects 1 to 11, wherein the one or more services are associated with location or tracking.
[0246] Aspect 13: The method according to any one of Aspects 1 to 12, wherein decoding the encoded downlink message further comprises: decoding the encoded downlink message at least in part based on the second key and the third key, wherein the third key includes a group key associated with a plurality of environmental wireless devices and the second key includes a manifest key associated with the environmental wireless devices.
[0247] Aspect 14: The method according to aspect 13, wherein the manifest key is at least partially based on the group key.
[0248] Aspect 15: A method for wireless communication at an ambient wireless controller, the method comprising: receiving a message from an application function associated with a network entity; determining one or more protection applications to be applied to the message; applying the one or more protection applications to the message to obtain an encoded downlink message; and transmitting the encoded downlink message to one or more ambient wireless devices.
[0249] Aspect 16: The method according to aspect 15, wherein the message includes the encoded downlink message, downlink information for the encoded downlink message, a first key, a token, or any combination thereof.
[0250] Aspect 17: The method according to any one of Aspects 15 to 16, wherein the one or more protection applications include one or more command protection applications, one or more manifest protection applications, or a combination thereof.
[0251] Aspect 18: The method according to any one of Aspects 15 to 17, wherein the transmission of the encoded downlink message is based at least in part on a change to one or more configurations for services provided by the one or more environmental wireless devices, a response to a request from the one or more environmental wireless devices, or both.
[0252] Aspect 19: The method according to any one of Aspects 15 to 18, wherein the first key of the message is based at least in part on a shared key between the one or more environmental wireless devices and the application function.
[0253] Aspect 20: The method according to any one of aspects 15 to 19, wherein the first key of the message is associated with one or more key refresh parameters.
[0254] Aspect 21: The method according to any one of Aspects 15 to 20, wherein the encoded downlink message includes a token of the message.
[0255] Aspect 22: The method according to any one of aspects 15 to 21, wherein sending the encoded downlink message further comprises: sending the encoded downlink message to one or more UEs associated with the one or more environmental radio devices.
[0256] Aspect 23: According to the method of aspect 22, the one or more UEs include a network reader, a device reader, or both.
[0257] Aspect 24: The method according to any one of Aspects 15 to 23, wherein applying the one or more protection applications further includes: encoding downlink information of the message using a first key from the application function; and transmitting the encoded downlink message to the one or more environmental wireless devices.
[0258] Aspect 25: The method according to any one of Aspects 15 to 24, wherein applying the one or more protection applications further includes: receiving an authorization token and a first key from the application function; encoding downlink information of the message using the first key of the message; signing the encoded downlink information using a signing key of the message, wherein the signed encoded downlink information includes the authorization token; and transmitting the encoded downlink message to the wireless device of the one or more environments.
[0259] Aspect 26: The method according to any one of Aspects 15 to 25, wherein applying the one or more protection applications further includes: generating a first key; using the first key to encode downlink information of the message; and transmitting the encoded downlink message to the one or more environmental wireless devices.
[0260] Aspect 27: The method according to any one of Aspects 15 to 26, wherein applying the one or more protection applications further comprises: receiving a group key from the application function, the group key being associated with at least the one or more environmental wireless devices; encoding downlink information of the message using a manifest key at least partially based on the group key; and transmitting the encoded downlink message to the one or more environmental wireless devices.
[0261] Aspect 28: An environmental wireless device for wireless communication, the environmental wireless device comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, thereby causing the environmental wireless device to perform the method according to any one of aspects 1 to 14.
[0262] Aspect 29: An environmental wireless device for wireless communication, the environmental wireless device comprising at least one component for performing the method according to any one of aspects 1 to 14.
[0263] Aspect 30: A non-transitory computer-readable medium storing code for wireless communication, said code including instructions executable by one or more processors to perform the method according to any one of aspects 1 to 14.
[0264] Aspect 31: An environmental wireless controller for wireless communication, the environmental wireless controller comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, thereby causing the environmental wireless controller to perform the method according to any one of aspects 15 to 27.
[0265] Aspect 32: An environmental wireless controller for wireless communication, the environmental wireless controller comprising at least one component for performing the method according to any one of aspects 15 to 27.
[0266] Aspect 33: A non-transitory computer-readable medium storing code for wireless communication, said code including instructions executable by one or more processors to perform the method according to any one of aspects 15 to 27.
[0267] It should be noted that the methods described herein describe possible specific implementations, and the operations and steps can be rearranged or otherwise modified, and other specific implementations are also possible. Furthermore, aspects from two or more of these methods can be combined.
[0268] While aspects of LTE, LTE-A, LTE-A Pro, or NR systems may be described for illustrative purposes, and the terms LTE, LTE-A, LTE-A Pro, or NR may be used in most of the description, the techniques described herein are also applicable to networks outside of LTE, LTE-A, LTE-A Pro, or NR networks. For example, the techniques described can be applied to a variety of other wireless communication systems, such as Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash OFDM, and other systems and radio technologies not explicitly mentioned herein, including future systems and radio technologies.
[0269] The information and signals described herein can be represented using any of a variety of different techniques and skills. For example, data, instructions, commands, information, signals, bits, symbols, and chips mentioned throughout the description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or optical particles, or any combination thereof.
[0270] The various exemplary blocks and components described herein can be implemented or performed using a general-purpose processor, DSP, ASIC, CPU, GPU, FPGA, or other programmable logic device, discrete gate or transistor logic unit, discrete hardware component, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but in alternative embodiments, a processor may be any processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration). Any function or operation described herein that can be performed by a processor may be performed by multiple processors capable of performing the described function or operation individually or jointly.
[0271] The functionality described herein can be implemented using hardware, software executed by a processor, or any combination thereof. Software should be broadly interpreted as instructions, instruction sets, code, code segments, program code, programs, subroutines, software modules, applications, software applications, software packages, routines, subroutines, objects, executables, threads of execution, procedures, or functions, whether referred to as software, firmware, middleware, microcode, hardware description languages, or other terms. When implemented using software executed by a processor, the functionality can be stored as one or more instructions or code on a computer-readable medium or transmitted using one or more instructions or code on a computer-readable medium. Other examples and specific implementations are within the scope of this disclosure and the appended claims. For example, due to the nature of software, the functionality described herein can be implemented using software executed by a processor, firmware, hardwired, or any combination thereof. Features implementing the functionality can also be physically located in various locations, including portions distributed such that the functionality is implemented at different physical locations.
[0272] Computer-readable media includes both non-transitory computer storage media and communication media, encompassing any medium that facilitates the transfer of a computer program from one location to another. Non-transitory storage media can be any available medium accessible by a general-purpose or special-purpose computer. By way of example and not limitation, non-transitory computer-readable media may include RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory, phase-change memory, compact disc (CD) ROM or other optical disc storage devices, magnetic disk storage devices or other magnetic storage devices, or any other non-transitory medium that can be used to carry or store desired program code components in the form of instructions or data structures and is accessible by a general-purpose or special-purpose computer or a general-purpose or special-purpose processor. Furthermore, any connection is appropriately referred to as computer-readable media. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included within the definition of computer-readable media. As used herein, disks and optical discs include CDs, laser discs, optical discs, digital multifunction discs (DVDs), floppy disks, and Blu-ray discs. Disks can magnetically reproduce data, and optical discs can optically reproduce data using lasers. Combinations of the above are also included within the scope of computer-readable media. Any function or operation described herein that can be performed by memory can be performed by multiple memories capable of performing the described function or operation individually or jointly.
[0273] As used herein (including in the claims), the word "or" in an enumeration of items (e.g., including enumerations of items ending with phrases such as "at least one of..." or "one or more of...") indicates an inclusive enumeration, such that an enumeration of at least one of, for example, A, B, or C means, for example, A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase "based on" should not be construed as a reference to a closed set of conditions. For example, an example step described as "based on condition A" could be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase "based on" should be interpreted in the same manner as the phrase "at least partially based on". As used herein, when the term "and / or" is used in a list of two or more items, it means that any one of the listed items may be used alone, or any combination of two or more of the listed items may be used. For example, if a composition is described as containing components A, B and / or C, the composition may contain A alone; B alone; C alone; a combination of A and B; a combination of A and C; a combination of B and C; or a combination of A, B and C.
[0274] As used herein, including in claims, the article “a” preceding a noun is open-ended and is understood to refer to “at least one” or “one or more” of those nouns. Therefore, the terms “a,” “at least one,” “one or more,” and “at least one of one or more” are interchangeable. For example, where a claim enumerates “components” performing one or more functions, each of the individual functions may be performed by a single component or by any combination of multiple components. Thus, the term “component” having a characteristic or performing a function may refer to “at least one of one or more components” having a particular characteristic or performing a particular function. Subsequent references to a component introduced with the article “a” using the terms “the” or “the” can refer to any or all of the one or more components. For example, a component introduced with the article “a” can be understood to mean “one or more components,” and subsequent reference to “the component” in a claim can be understood as equivalent to referring to “at least one of the one or more components.” Similarly, subsequent references to a component introduced with the terms “the” or “the” as “one or more components” can refer to any or all of the one or more components. For example, reference to "the one or more components" in the subsequent claims can be understood as equivalent to reference to "at least one of the one or more components".
[0275] The terms "determine" or "identify" encompass a variety of actions, and therefore, "determine" or "identify" can include calculation, computation, processing, derivation, investigation, lookup (such as by searching in a table, database, or other data structure), ascertainment, etc. Additionally, "determine" or "identify" can include receiving (such as receiving information or signaling, e.g., receiving information or signaling for determination, receiving information or signaling for identification) and accessing (such as accessing data in memory or accessing information). Furthermore, "determine" or "identify" can include parsing, obtaining, selecting, choosing, creating, and other similar actions.
[0276] In the accompanying drawings, similar components or features may have the same reference numerals. Furthermore, various components of the same type can be distinguished by adding a dash after the reference numerals and a second reference numeral for differentiation between similar components. If only the first reference numeral is used in the specification, the description can be applied to any component among similar components having the same first reference numeral, regardless of the second or other subsequent reference numerals.
[0277] The description herein, illustrated with reference to the accompanying drawings, describes an example configuration and does not represent all achievable examples or those within the scope of the claims. The term "example" as used herein means "serving as an example, instance, or illustration," not "preferred" or "advantageous over other examples." The detailed description includes specific details used to provide an understanding of the described techniques. However, these techniques can be practiced without these specific details. In some instances, known structures and devices are shown in block diagram form to avoid obscuring the concept of the described examples.
[0278] The description herein is provided to enable those skilled in the art to implement or use this disclosure. Various modifications to this disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but should be granted the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An environmental wireless device, the environmental wireless device comprising: One or more memories, wherein the one or more memories store processor-executable code; and One or more processors, coupled to one or more memories and capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless device to: Receive a downlink message, the downlink message including a first configuration for the wireless device in the environment associated with one or more services; The one or more services are enabled at least in part based on the first configuration at the wireless device in the environment; Receive downlink messages including the encoded first key; The encoded downlink message, including a second configuration, is decoded at least partially based on a second key; and The one or more services may be modified or the response transmission associated with the wireless device in the environment may be activated, at least in part, based on the second configuration.
2. The environmental wireless device of claim 1, wherein receiving the encoded downlink message is based at least in part on a change to one or more configurations for service, a response to a request from the environmental wireless device, or both.
3. The environmental wireless device of claim 1, wherein the first key and the second key are a single shared key between the environmental wireless device and application functions associated with a network entity.
4. The environmental wireless device of claim 1, wherein the second key is at least in part based on a shared key between the environmental wireless device and application functions associated with a network entity.
5. The environmental wireless device of claim 1, wherein the second key is associated with one or more key refresh parameters.
6. The environmental wireless device of claim 1, wherein the encoded downlink message further includes a token.
7. The environmental wireless device of claim 6, wherein, in order to receive the encoded downlink message, the one or more processors are further capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless device to: The encoded downlink message is received from an environmental radio controller associated with a network entity via one or more user equipment; and The authorization to send the encoded downlink message from the ambient wireless controller to the ambient wireless device is verified at least in part based on the token.
8. The ambient wireless device of claim 7, wherein decoding of the encoded downlink message is based at least in part on using the token to verify authorization of the ambient wireless controller.
9. The environmental wireless device of claim 1, wherein the second key is generated by an environmental wireless controller associated with a network entity.
10. The environmental wireless device of claim 1, wherein the second key is generated by an application function associated with a network entity.
11. The environmental wireless device of claim 1, wherein, in order to receive the encoded downlink message, the one or more processors are further capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless device to: The encoded downlink message is received from an environmental radio controller associated with a network entity, wherein the encoded downlink message includes a signature; and The authorization for the environmental wireless controller to send the encoded downlink message to the environmental wireless device is verified at least in part based on the signature.
12. The environmental wireless device of claim 1, wherein the one or more services are associated with location or tracking.
13. The environmental wireless device of claim 1, wherein, in order to decode the encoded downlink message, the one or more processors are further capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless device to: The encoded downlink message is decoded at least in part based on the second key and the third key, wherein the third key includes a group key associated with a plurality of ambient wireless devices and the second key includes a manifest key associated with the ambient wireless devices.
14. The environmental wireless device of claim 13, wherein the inventory key is at least partially based on the group key.
15. An environmental wireless controller, the environmental wireless controller comprising: One or more memories, wherein the one or more memories store processor-executable code; and One or more processors, coupled to the one or more memories and capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless controller to: Receive messages from application functions associated with network entities; Determine one or more protection applications to be applied to the message; Apply the one or more protection applications to the message to obtain an encoded downlink message; as well as The encoded downlink message is sent to one or more environmental wireless devices.
16. The environmental wireless controller of claim 15, wherein the message includes the encoded downlink message, downlink information for the encoded downlink message, a first key, a token, or any combination thereof.
17. The environmental wireless controller of claim 15, wherein the one or more protection applications include one or more command protection applications, one or more inventory protection applications, or a combination thereof.
18. The environmental wireless controller according to claim 15, further comprising: The transmission of the encoded downlink message is based at least in part on a change to one or more service configurations for the one or more environmental wireless devices, a response to a request from the one or more environmental wireless devices, or both.
19. The environmental wireless controller of claim 15, wherein the first key of the message is based at least in part on a shared key between the one or more environmental wireless devices and the application function.
20. The environmental wireless controller of claim 15, wherein the first key of the message is associated with one or more key refresh parameters.
21. The environmental wireless controller of claim 15, wherein the encoded downlink message includes a token of the message.
22. The environmental wireless controller of claim 15, wherein, in order to transmit the encoded downlink message, the one or more processors are further capable of operating individually or jointly to execute the code, thereby causing the environmental wireless controller to: The encoded downlink message is sent to one or more user equipment (UEs) associated with the one or more environmental wireless devices.
23. The environmental wireless controller of claim 22, wherein the one or more UEs include a network reader, a device reader, or both.
24. The environmental wireless controller of claim 15, wherein, in order to apply the one or more protection applications, the one or more processors are also capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless controller to: The downlink information of the message is encoded using a first key from the application function; and The encoded downlink message is sent to the wireless devices in the one or more environments described above.
25. The environmental wireless controller of claim 15, wherein, in order to apply the one or more protection applications, the one or more processors are also capable of operating individually or jointly to execute the code, thereby causing the environmental wireless controller to: Receive the authorization token and the first key from the application function; The first key of the message is used to encode the downlink information of the message; The encoded downlink information is signed using the signing key of the message, wherein the signed encoded downlink information includes the authorization token; as well as The encoded downlink message is sent to the wireless devices in the one or more environments described above.
26. The environmental wireless controller of claim 15, wherein, in order to apply the one or more protection applications, the one or more processors are also capable of operating individually or jointly to execute the code, thereby enabling the environmental wireless controller to: Generate the first key; The first key is used to encode the downlink information of the message; as well as The encoded downlink message is sent to the wireless devices in the one or more environments described above.
27. The environmental wireless controller of claim 15, wherein, in order to apply the one or more protection applications, the one or more processors are also capable of operating individually or jointly to execute the code, thereby causing the environmental wireless controller to: Receive a group key from the application function, the group key being associated with at least one or more of the environmental wireless devices; The downlink information of the message is encoded using a manifest key that is at least partially based on the group key; as well as The encoded downlink message is sent to the wireless devices in the one or more environments described above.
28. A method for wireless communication at an environmental wireless device, the method comprising: Receive a downlink message, the downlink message including a first configuration for the wireless device in the environment associated with one or more services; The one or more services are enabled at least in part based on the first configuration at the wireless device in the environment; Receive downlink messages including the encoded first key; The encoded downlink message, including a second configuration, is decoded at least partially based on a second key; and The one or more services may be modified or the response transmission associated with the wireless device in the environment may be activated, at least in part, based on the second configuration.
29. A method for wireless communication at an environmental wireless controller, the method comprising: Receive messages from application functions associated with network entities; Determine one or more protection applications to be applied to the message; Apply the one or more protection applications to the message to obtain an encoded downlink message; as well as The encoded downlink message is sent to one or more environmental wireless devices.
30. The method of claim 29, wherein the message comprises the encoded downlink message, downlink information for the encoded downlink message, a first key, a token, or any combination thereof.