Dynamic internet of things device provisioning using out-of-band mechanisms
Patent Information
- Application Number
- CN202580016124.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-02-23
- Filing Date
- 2025-02-06
- Publication Date
- 2026-09-22
Smart Images

Figure CN122804389A_ABST
Abstract
Description
Technical Field
[0001] Some example embodiments may typically involve mobile or wireless telecommunications systems, such as Long Term Evolution (LTE) or 5G New Radio (NR) access technologies, Beyond 5G, or other communication systems. For example, some example embodiments may involve dynamic Internet of Things (IoT) device provisioning using out-of-band mechanisms. Background Technology
[0002] Examples of mobile or wireless telecommunications systems can include: Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (UTRAN), Evolved UTRAN (E-UTRAN) for Long Term Evolution (LTE), LTE-Advanced (LTE-A), MulteFire, LTE-A Pro, 5G or New Radio (NR) access technologies, and / or 6G. 5G and 6G wireless systems refer to next-generation (NG) wireless systems and network architectures. While 5G and 6G network technologies are largely based on New Radio (NR) technologies, 5G (or NG) networks can also be built on E-UTRAN. NR is estimated to provide bit rates of approximately 10-20 Gbit / s or higher and will support at least Enhanced Mobile Broadband (eMBB) and Ultra-Reliable Low-Latency Communications (URLLC), as well as Massive Machine-Type Communications (mMTC). NR is expected to provide extreme broadband and ultra-robust low-latency connectivity and massive networking to support the Internet of Things (IoT). Summary of the Invention
[0003] Various example embodiments may provide an apparatus including at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: receive an out-of-band request message from a connected device. The apparatus may also cause it to: send the out-of-band request message as a secure packet to a network entity and send a response message received from the network entity to the connected device. The response message may trigger the connected device to complete a completion switching process.
[0004] Some example embodiments may provide an apparatus including at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: perform an initial switching procedure for connection with a network entity of the network. The apparatus may also cause the apparatus to: send an out-of-band request message to a user equipment and, upon completion of the switching procedure, generate a security key based on the generated session key.
[0005] Some example embodiments may provide an apparatus including at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: obtain one or more out-of-band values from a secure packet received from a user equipment. The apparatus may also be caused to: verify the secure packet and send a response message to the user equipment, the response message indicating that the secure packet has been verified. The apparatus may also be caused to: generate a security key based on a generated session key when completing an exchange process with a connected device connected to the user equipment.
[0006] Some example embodiments may provide an apparatus including at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: receive an out-of-band request message from a connected device. The apparatus may also be caused to: protect the out-of-band request message as a secure packet and send it to a network entity. Furthermore, the apparatus may be caused to: send a response message received from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange process for authentication.
[0007] Various example embodiments may provide an apparatus including at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: generate a first network access identifier and, using the first network access identifier, perform an initial switching procedure for connection with a network entity of the network. The apparatus may also cause the apparatus to: send an out-of-band request message to a user equipment and, in response to receiving a response message from the user equipment, and, upon completion of the switching procedure to authenticate the apparatus with the network entity, generate a security key to protect the connection between the apparatus and the network entity.
[0008] Some example embodiments may provide an apparatus including at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: receive a first network access identifier generated by a connected device, and allocate and send a second network access identifier to the connected device. The apparatus may also cause the apparatus to: verify a security packet and send a response message to a user equipment indicating that the security packet has been verified. The apparatus may also cause the apparatus to: generate a security key based on a generated session key when completing an exchange process with a device connected to the user equipment. Attached Figure Description
[0009] To correctly understand the exemplary embodiments, reference should be made to the accompanying drawings, as follows:
[0010] Figure 1 An example of an associated state mechanism is illustrated;
[0011] Figure 2A An example of a signal diagram according to certain example embodiments is illustrated;
[0012] Figure 2B An example of another signal diagram according to various exemplary embodiments is illustrated;
[0013] Figure 2C An example of another signal diagram according to certain exemplary embodiments is illustrated;
[0014] Figure 3 The illustration shows an example of a signal diagram for a reconnection process according to some example embodiments;
[0015] Figure 4 Examples of flowcharts illustrating methods according to various exemplary embodiments are shown;
[0016] Figure 5 An example flowchart illustrating another method according to certain example embodiments is shown;
[0017] Figure 6 An example flowchart illustrating yet another method according to some example embodiments is shown;
[0018] Figure 7 An example flowchart illustrating another method according to certain example embodiments is shown;
[0019] Figure 8 An example flowchart illustrating yet another method according to various exemplary embodiments is shown;
[0020] Figure 9 An example flowchart illustrating another method according to certain example embodiments is shown; and
[0021] Figure 10 The illustrations depict an array of devices according to various example embodiments. Detailed Implementation
[0022] It is readily understood that, as generally described herein and illustrated in the accompanying drawings, components of certain example embodiments may be arranged and designed in a wide variety of different configurations. The following is a detailed description of some example embodiments of systems, methods, apparatuses, and non-transitory computer program products pre-configured for dynamic Internet of Things (IoT) devices using out-of-band mechanisms. Although the devices discussed below and illustrated in the accompanying drawings relate to 6G / 5G or next-generation Node B (gNB) devices and UE devices, this disclosure is not limited to gNBs and UEs.
[0023] It is readily understood that, as generally described herein and illustrated in the accompanying drawings, components of certain example embodiments can be arranged and designed in a wide variety of different configurations. Different reference numerals from the various figures may be used in the description without order to refer to the same elements to illustrate their features or functions. Different functions or processes discussed herein may be performed in different orders and / or simultaneously with each other, if desired. Furthermore, one or more functions or processes described may be optional or may be combined, if desired. Therefore, the following description should be considered as an illustration of the principles and teachings of certain example embodiments, and not as a limitation thereof.
[0024] In 5G / NR technology, Extensible Authentication Protocols (EAPs) can support various types of authentication processes. For example, Flexible Out-of-Band (NOOB) (also known as EAP-NOOB) is an authentication process for NOOB authentication and key derivation. The EAP-NOOB process can provide guidance for various types of IoT devices that may not have pre-configured authentication credentials. The EAP-NOOB process can authenticate in-band key exchanges using user-assisted, one-way OOB messages between the peer device and the authentication server. EAP-NOOB can be executed across two or more EAP sessions, which can be referred to as exchanges. Each exchange can include multiple pairs of EAP requests and responses. At least two separate EAP sessions may be required to give the end-user device sufficient time to deliver OOB messages between the peer device and the authentication server.
[0025] The EAP-NOOB process can begin with an initial exchange, during which four pairs of EAP requests and responses are executed. During the initial exchange, the server can assign or delegate identifiers to the peer, and the server and peer can negotiate (e.g., request or indicate) the protocol version and cipher suite (i.e., cipher algorithm suite) to be used, exchange random numbers, and subsequently perform a temporary elliptic curve Diffie-Hellman (ECDHE) key exchange. An OOB process can then be executed to provide an out-of-band message that can be sent from the peer to the server or from the server to the peer. During the OOB process, the peer can probe the server by reconnecting using EAP-NOOB. When the OOB process has been completed, the peer's probe can produce a completion exchange that completes mutual authentication and key confirmation. Conversely, when the OOB process has not yet been completed, the peer's probe can produce a waiting exchange process, during which the peer can perform another probe after a minimum waiting time defined by the server. The initial exchange process and the waiting exchange process can end with an EAP-failure indication, and the completion of the exchange process can generate an EAP-success indication. Once the peer device and server have successfully completed the exchange process, both the peer device and server acting as endpoints store the created association in persistent storage, and the OOB process can be avoided. Subsequently, a new temporary key, ECDHE key regeneration, and cryptographic algorithm updates can be performed using the reconnection exchange process.
[0026] Figure 1 The diagram illustrates an example of an associated state mechanism used to execute the EAP-NOOB process. The associated state mechanism can be the same for both the server and peer devices. When a peer initiates an EAP-NOOB process, the server can select or determine subsequent message exchanges based on a combination of server state(s) and peer device state(s). Figure 1At point 110, the server and peer can initially be in an unregistered state, in which state information does not need to be stored. The server-peer association state can be set to a temporary state in both the server and peer before the exchange process is successfully completed. A timeout or error can cause one or both of the server or peer to revert to the unregistered state, allowing the initial exchange process to be repeated. For example, an error can be an invalid value, an unexpected value, an unidentified value, or other unsupported value, such as the errors listed in Internet Engineering Task Force (IETF) Request for Comment (RFC) 9140. At point 120, the server or peer can wait for the OOB process, during which an OOB message can be entered, and at point 130, the server or peer can receive the OOB message. The initial exchange process can then be completed, and completion of the exchange process can generate an EAP-success indication. At point 140, the association state can transition from a temporary state to a persistent state, in which the server or peer is registered. User resets or memory failures can cause a server or peer to revert from a persistent state to a temporary state, which may subsequently lead to the re-execution of the initial exchange procedure. At point 150, after a mobility timeout period has expired or an error has occurred, the server or peer can transition to a reconnection procedure and perform a reconnection exchange to return to the registered persistent state. If the reconnection procedure fails, the server or peer reverts to an unregistered state.
[0027] As the number of IoT devices increases, there is a need to implement dynamic processes and mechanisms for adding IoT devices to networks compatible with 3GPP specifications. This can be particularly useful when a user operating their own UE adds an additional IoT device operated by the same user. Examples of IoT devices can include identification (ID) tags, sensors, smart clothing, healthcare devices, and / or logistics objects (e.g., tracking devices). This type of IoT device can also be referred to as an environmental IoT device, which can be powered by energy harvesting, allowing the device to be, for example, battery-free or equipped with limited energy storage capacity (e.g., using capacitors).
[0028] IoT devices can be used to complement existing IoT technologies and extend their use to additional use cases that may require more cost-effectiveness, energy efficiency, and / or battery-free capabilities. The 3GPP (3rd Generation Partnership Project) specifications can define certain IoT devices, such as RedCap devices, to meet the requirements of wide-area IoT communication for low-cost and low-power devices. These IoT devices can consume relatively low power, such as tens or hundreds of milliwatts, during transmission and reception. To achieve the Internet of Things, there is a need for IoT devices with lower cost and lower power consumption, especially for the desired battery-free implementation.
[0029] As part of the process of adding new IoT devices to 5G / 6G networks, it may be necessary to pre-configure new Subscriber Identity Modules (SIMs) / (electronic) Subscriber Identity Modules (eSIMs) for the IoT devices, create subscriptions in Unified Data Management (UDM) and / or Home Subscriber Server (HSS), and / or perform an activation process for each new IoT device. These actions may result in undesirable increases in time and may require manual intervention from end users.
[0030] Various example embodiments can provide technical advantages to address the aforementioned problems and can implement one or more processes to dynamically provision IoT devices via the UE, or by the home network of the mobile network, with reduced or no human intervention. According to various example embodiments, one or more processes can allow dynamic provisioning of IoT devices in the network via an enhanced EAP-NOOB process.
[0031] Some example embodiments may provide one or more procedures in which the UE can connect to an IoT device via a local connection and configure operator details on the IoT device. The UE can establish a secure connection to the mobile network (e.g., a Non-Access Stratum (NAS) connection) and can use this secure connection as an OOB channel to send an (EAP-OOB) OOB request message from the IoT device to the mobile network. Upon receiving a successful (EAP-OOB) OOB response message, the IoT device can perform a completion exchange procedure with the mobile network. After successfully completing the exchange procedure, the IoT device and the mobile network can establish a session key and derive additional security keys based on the session key.
[0032] Figure 2AAn example of a signal diagram according to certain example embodiments is illustrated. The signal diagram provides signaling to implement one or more processes for dynamically provisioning an IoT device via a UE from the home network. The signal diagram illustrates signaling between a User Equipment (UE) 201, a Smart IoT Device 202, a Radio Access Network (RAN) 203, an Access and Mobility Management Function (AMF) 204, and network entities that may function as a Customer Relationship Management (CRM) portal, a Unified Data Management (UDM), and / or an Authentication Server Function (AUSF) 205, which may be collectively referred to herein as UDM / AUSF 205. RAN 203, AMF 204, and UDM / AUSF 205 may be entities of the home network or the mobile network.
[0033] At procedure 210, UE 201 can perform a registration process and perform mutual authentication between UE 201 and the network via RAN 203, AMF 204, and / or UDM / AUSF 205. At procedure 211, a new IoT device 202 can connect to UE 201, for example via a device-to-device (D2D) connection. Examples of D2D connections could be Bluetooth, WiFi, or another wireless or wired connection between UE 201 and IoT device 202. At procedure 212, UE 201 can access the portal of UDM / AUSF 205 to request a dynamic subscription for IoT device 202 to its home network or to add that dynamic subscription to its home network. UE 201 can also configure the mobile country code and / or mobile network code and / or other known operator information and parameters of IoT device 202 with the network, enabling IoT device 202 to connect to its home network and confirm that the home network is the network it wishes to join. At 213, the Mobile Country Code (MCC) and / or Mobile Network Code (MNC) and / or other known operator information and parameters can be configured for the IoT device 202.
[0034] At position 214, IoT device 202 can establish a Layer 2 (L2) connection with RAN 203, and at position 215, IoT device 202 can use the L2 connection to send a NAS registration request to RAN 203. IoT device 202 can also construct and send a UE ID with a Network Access Identifier (NAI), such as 5gc.mnc. <mnc>.mcc <mcc>.3gppnetwork.org@eap-noob.arpa. At 216, RAN 203 can send a NAS registration request and NAI to AMF 204, and at 217, AMF 204 can send an authentication request including the NAI to UDM / AUSF 205.
[0035] At 218, UDM / AUSF 205 can send an EAP-NOOB request to IoT device 202, and at 219, IoT device 202 can identify the exchange of EAP-NOOB messages based on the message type field of the EAP-NOOB request received from UDM / AUSF 205, and can respond by sending an EAP-NOOB response message to UDM / AUSF 205. The EAP-NOOB response message may include a peer identifier (PeerID) and peer status. At 220, an initial exchange procedure can be performed between one or more public keys of IoT device 202 and one or more public keys of the home network. UDM / AUSF 205 can assign a new NAI and Peer ID to IoT device 202. An ECDHE key can be generated based on a negotiated cryptographic suite. The negotiated cryptographic suite can implement one or more algorithms that will be negotiated and used between two entities (such as IoT device 202 and UDM / AUSF 205), using a key ID that identifies the pair of keys to be used.
[0036] Figure 2B The illustration shows an example of a signal diagram according to certain example embodiments. The signal diagram provides implementations beyond... Figure 2A Signaling for one or more procedures performed outside of procedures 210-220 shown, to dynamically provision IoT devices via the UE from the home network. The signal diagram illustrates the signaling between UE 201, IoT device 202, RAN 203, AMF 204, and UDM / AUSF 205.
[0037] At 221, if authentication cannot be completed, the initial exchange process may end with IoT device 202 receiving an EAP-failure indication from UDM / AUSF 205. At the end of the initial exchange process, UDM / AUSF 205 and IoT device 202 may transition to a waiting state to receive an OOB. At 222, IoT device 202 may trigger the OOB process via UE 201. IoT device 202 may send an OOB message request with PeerID, NOOB value, and hash OOB (HOOB) value. At 223, UE 201 may use an authentication process (using the same process as procedures 214-216), employing NAS and Access Layer (AS) authentication. NAS and AS authentication may protect messages using the AS key between UE 201 and its home network (such as UDM / AUSF 205) and the NAS key between UE 201 and AMF 204. Alternatively, UE 201 can use the Authentication Server Function Key (KAUSF) to generate a Secure Uplink Roaming Guide (SoR) packet or a UE Parameter Update (UPU) packet with a generated Message Authentication Code (MAC-I) for integrity.
[0038] At 224, UE 201 can generate a security packet with PeerID, NOOB value, HOOB value, and KAUSF, and send the security packet to UDM / AUSF 205. At 225, UDM / AUSF 205 can obtain the NOOB value, HOOB value, and PeerID from the security packet of the SoR or UPU packet, and can use KAUSF to verify the MAC-I. At 226, UDM / AUSF 205 can generate an acknowledgment message for the uplink of the packet, and can generate a downlink security packet with ACK and a MAC-I generated for the ACK, so that the response is not modified by the serving network. At 227, an OOB response message can be sent to UE 201, and the OOB response message can include a downlink security packet with verification result and acknowledgment. At 228, UE 201 can forward the OOB response message to IoT device 202.
[0039] At point 229, a completion exchange procedure can be performed, during which multiple pairs of EAP-NOOB request and response messages can be sent between IoT device 202 and its home network (e.g., RAN 203, AMF 204, and / or UDM / AUSF 205). The completion exchange procedure can generate an EAP-success indication, and IoT device 202 and its home network (e.g., UDM / AUSF 205) can be set to a registered state. EAP success can generate a Master Session Key (MSK) for use by IoT device 202 and UDM / AUSF 205.
[0040] Figure 2C The illustration shows an example of a signal diagram according to certain example embodiments. The signal diagram provides implementations beyond... Figure 2A and Figure 2B Signaling for one or more procedures performed outside of procedures 210-229 shown, to dynamically provision IoT devices via the UE from the home network. The signal diagram illustrates the signaling between UE 201, IoT device 202, RAN 203, AMF 204, and UDM / AUSF 205.
[0041] At 230, IoT device 202 can use MSK as a session key, and the peer ID can be used for communication. At 231, IoT device 202 can generate or derive a Security Anchor Function Key (KSEAF) based on the session key. At 232, similar to process 230, UDM / AUSF 205 can use MSK as a session key, and the peer ID can be used for communication, and at 233, UDM / AUSF 205 can generate or derive a KSEAF based on the session key. At 234, UDM / AUSF 205 can send the KSEAF to AMF 204 in an authentication success message. At 235, AMF 204 can generate or derive NAS and AS keys to protect future communication between IoT device 202 and its home network (e.g., RAN 203, AMF 204, and / or UDM / AUSF 205).
[0042] Some example implementations may provide one or more procedures in the event that an IoT device enters an inactive or sleep state and then attempts to return to the home network via a globally unique temporary identifier (GUTI), which may be defined in, for example, 3GPP Technical Specification (TS) 23.003. Figure 3 An example signal diagram for a reconnection process is illustrated according to some example embodiments. The signal diagram provides signaling to implement one or more processes to reconnect a previously connected IoT device to the home network. The signal diagram illustrates signaling between UE 301, IoT device 302, RAN 303, AMF 304, and network entities that may function as a Customer Relationship Management (CRM) portal, Unified Data Management (UDM), and / or Authentication Server Function (AUSF) 305, which may be collectively referred to herein as UDM / AUSF 305. RAN 303, AMF 304, and UDM / AUSF 305 may be entities of the home network or mobile network.
[0043] At point 310, IoT devices can use the information mentioned above. Figure 2A and Figure 2B One or more processes are described to securely connect to the home network. At 320, IoT device 302 may enter a sleep or inactive state and subsequently attempt to re-establish its connection to the home network. At 330, IoT device 302 may send a reconnection request to AMF 304. The reconnection request may include a GUTI. At 340 and 350, AMF 304 may decide whether to perform authentication or re-authentication. At 340, AMF 304 may identify IoT device 302 based on the GUTI and may decide to continue or re-establish a secure connection for providing services to IoT device 302 without performing re-authentication of IoT device 302.
[0044] Alternatively, at 350, AMF 304 may decide to perform re-authentication before re-establishing a secure connection for providing services to IoT device 302. At 360, as part of the re-authentication process, AMF 304 may obtain the UE ID (e.g., PeerID) from IoT device 302, and at 370, IoT device 302 may provide AMF 304 with an EAP ID response message including the PeerID. At 380, AMF 304 may send an authentication request including the PeerID to UDM / AUSF 305. At 390, UDM / AUSF 305 may perform authentication using a reconnection message exchange, and after a successful reconnection, UDM / AUSF 305 may assign a new NAI to UE 301 and IoT device 302, subsequently storing the new NAI in each of UE 301 and IoT device 302.
[0045] Some example implementations may provide a specific NAI format. For example, a modified NAI may take one or more of the following forms (1)-(5): homerealm!username@otherrealm (1) Visitedrealm!homerealm!username@otherrealm (2) 5gc.mnc <mnc>.mcc <mcc>.3gppnetwork.org@eap-noob.arpa (3) 5gc.mnc <homemnc>.mcc <homemcc>.3gppnetwork.org (4) !0 <imsi>@aiot.nai.5gc.mnc <visitedmnc>.mcc <visitedmcc>.3gppnetwork.org@eap-noob.arpa (5)
[0046] Some example implementations may provide that the NAI format can include a random number, a hash value, and a NOOB ID, wherein the random number NOOB can be, for example, a 16-byte fresh random byte string, and the HOOB can be defined as: HOOB = H(Dir, Vers, Verp, PeerId, Cryptosuites, Dirs, ServerInfo,Cryptosuitep, Dirp, NAI, PeerInfo, 0, PK HN , N HN , PKp, Np, NOOB) (6)
[0047] Some example implementations can be provided, where the NOOB ID can be defined as: NOOB ID = H("NoobId",Noob) (7)
[0048] When deriving KSEAF from the session key of an IoT device, the following parameters can be used to form the input S of the generic key derivation function (KDF): FC = 0x6C; P0 = <service network name>; L0 = length of <service network name>. The input key used for KDF can be the session key of the IoT device. For example, KDF can be defined in 3GPP TS 33.501 (Appendix A.6).
[0049] Figure 4 An example flowchart illustrating a method according to certain example embodiments is shown. In the example embodiments, Figure 4 The method can be performed by a device or user equipment within a network in a 3GPP system (such as LTE, 5G-NR, or 6G). For example, in an example embodiment, Figure 4 The method can be executed by the UE, which is similar to... Figure 10 The device 1010 shown in the figure.
[0050] According to various example embodiments, Figure 4 The method may include: at 410, receiving an out-of-band request message from a connected device (such as an IoT device); and at 420, sending the out-of-band request message as a secure packet to a network entity. At 430, the method may further include: sending a response message received from the network entity to the connected device. The response message may trigger the connected device to complete the exchange process.
[0051] Some example embodiments may provide a method that further includes connecting to the connected device via an initial exchange procedure. The out-of-band request message can be sent by generating a secure uplink update parameter packet using a previously established secure connection between the device and a network entity during the registration process, or by using an authentication server function key. The method may also include receiving a response message from the network entity, the response message including the result of a verification process for the secure packet.
[0052] Figure 5 An example flowchart illustrating a method according to certain example embodiments is shown. In the example embodiments, Figure 5 The method can be performed by IoT devices in 3GPP systems such as LTE, 5G-NR, or 6G. For example, in an example embodiment, Figure 5 The method can be executed by IoT devices, which are similar to Figure 10 The device 1020 shown in the figure.
[0053] According to various example embodiments, Figure 5 The method may include: at 510, performing an initial exchange procedure for connection to a network entity of the network; and at 520, sending an out-of-band request message to the user equipment. At 530, the method may further include: generating a security key based on the generated session key upon completion of the exchange procedure.
[0054] Some example embodiments may provide that the method may include: receiving a network access identifier assigned by a network entity during an initial exchange process. The out-of-band request message may include at least one of the following: a network access identifier, a flexible out-of-band value, or a hashed out-of-band value. The method may further include: receiving a response message from a user equipment, the response message including an indication that the device has been authenticated by the network. The method may further include: generating a session key based on the response message. A security key may be derived from the generated session key.
[0055] Figure 6 An example flowchart illustrating a method according to certain example embodiments is shown. In the example embodiments, Figure 6 The method can be performed by a network element / entity or a group of multiple network entities in a 3GPP system (such as LTE, 5G-NR, or 6G). For example, in an example embodiment, Figure 6 The method can be performed by network entities (such as CRM / UDM / AUSF), which are similar to Figure 10 The device 1030 shown in the figure.
[0056] According to various example embodiments, Figure 6 The method may include, at 610, obtaining one or more out-of-band values from a secure packet received from the user equipment; and at 620, verifying the secure packet and sending a response message to the user equipment, the response message indicating that the secure packet has been verified. At 630, the method may further include, upon completion of an exchange process with a connected device connected to the user equipment, generating a secure key based on a generated session key.
[0057] Some example embodiments may provide that the method further includes: assigning and sending a peer identifier to the connected device. The security packet may include at least one of the following: a peer identifier, a flexible out-of-band value, a hash out-of-band value, or a media access control identifier. The method may further include: generating an uplink acknowledgment for an uplink packet, or generating a downlink acknowledgment for a security packet. The method may further include: sending a response message, the response message including at least one of an uplink acknowledgment or a downlink acknowledgment.
[0058] Figure 7 An example flowchart illustrating a method according to certain example embodiments is shown. In the example embodiments, Figure 7 The method can be performed by a device or user equipment within a network in a 3GPP system (such as LTE, 5G-NR, or 6G). For example, in an example embodiment, Figure 7 The method can be executed by the UE, which is similar to... Figure 10 The device 1010 shown in the figure.
[0059] According to various example embodiments, Figure 7 The method may include, at 710, receiving an out-of-band request message from a connected device (such as an IoT device); and at 720, protecting the out-of-band request message as a secure packet and sending it to a network entity. At 730, the method may further include sending a response message received from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange process for authentication.
[0060] Some example embodiments may provide that the method further includes: connecting to the connected device via an initial exchange procedure before receiving the out-of-band request message. The out-of-band request message may include: an identifier of the connected device assigned by the network entity, a flexible out-of-band value, and a hashed out-of-band value. The out-of-band request message may be protected as a secure packet and sent via: generating a secure uplink update parameter packet using a previously established secure connection between the device and the network entity during the registration process, or using an authentication server function key. The method may further include: receiving a response message from the network entity in response to sending the secure packet. The response message may include: the result of an authentication process by which the network entity verifies the secure packet.
[0061] Figure 8 An example flowchart illustrating a method according to certain example embodiments is shown. In the example embodiments, Figure 8 The method can be performed by IoT devices in 3GPP systems such as LTE, 5G-NR, or 6G. For example, in an example embodiment, Figure 8 The method can be executed by IoT devices, which are similar to Figure 10 The device 1020 shown in the figure.
[0062] According to various example embodiments, Figure 8 The method may include: at 810, generating a first network access identifier; and at 820, using the first network access identifier, performing an initial exchange procedure for connection with a network entity of the network. At 830, the method may further include: sending an out-of-band request message to a user equipment, and at 840, in response to receiving a response message from the user equipment and upon completion of the exchange procedure for network authentication, generating a security key to protect the connection between the device and the network entity.
[0063] Some example embodiments may provide that the method may further include: receiving a second network access identifier assigned by a network entity during the initial exchange process. The out-of-band request message may include: the second network access identifier, a flexible out-of-band value, and a hashed out-of-band value. The method may further include receiving a response message from the user equipment. The response message may include an indication that the device has been authenticated by the network. The method may further include: generating a session key based on the response message. The generated security key can be derived from the generated session key.
[0064] Figure 9 An example flowchart illustrating a method according to certain example embodiments is shown. In the example embodiments, Figure 9 The method can be performed by a network element / entity or a group of multiple network entities in a 3GPP system (such as LTE, 5G-NR, or 6G). For example, in an example embodiment, Figure 9 The method can be performed by network entities (such as CRM / UDM / AUSF), which are similar to Figure 10 The device 1030 shown in the figure.
[0065] According to various example embodiments, Figure 9 The method may include, at 910, receiving a first network access identifier generated by the connected device; and at 920, assigning and sending a second network access identifier to the connected device. At 930, the method may further include: obtaining one or more out-of-band values from a security packet received from the user equipment; and at 940, verifying the security packet and sending a response message to the user equipment, the response message indicating that the security packet has been verified. At 950, the method may further include: generating a security key based on a generated session key upon completion of an exchange process with a device connected to the user equipment.
[0066] Some example embodiments may provide that the method may further include: assigning and sending a peer identifier to the connected device. The security packet may include: a peer identifier, a flexible out-of-band value, a hash out-of-band value, and a media access control identifier. The method may further include: generating an uplink acknowledgment for the uplink packet, generating a downlink acknowledgment for the security packet, and sending a response message including the uplink acknowledgment and the downlink acknowledgment.
[0067] Figure 10 The illustrations depict a collection of devices 1010, 1020, and 1030 according to various exemplary embodiments. In these various exemplary embodiments, device 1010 may be an element in a communication network, such as an IoT device. For example, IoT devices 202 and 302 according to the various exemplary embodiments discussed above may be examples of device 1010. It should be noted that those skilled in the art will understand that device 1010 may include... Figure 10 Components or features not shown. Furthermore, device 1020 can be an element or network entity in a communication network, such as a UE, RedCap UE, SL UE, mobile equipment (ME), mobile station, mobile device, or other equipment. For example, UE 201 / 301 according to the various example embodiments discussed above can be an example of device 1020. It should be noted that those skilled in the art will understand that device 1020 may include... Figure 10 Components or features not shown. Additionally, device 1030 may be an element in or associated with a network, or may be a network entity such as a CRM / UDM / AUSF. For example, UDM / AUSF 205 / 305 according to the various example embodiments discussed above may be examples of device 1030. It should be noted that those skilled in the art will understand that device 1030 may include... Figure 10 Components or features not shown in the diagram.
[0068] In some example embodiments, devices 1010, 1020, and / or 1030 may include one or more processors, one or more computer-readable storage media (e.g., memory, storage device, etc.), one or more wireless access components (e.g., modem, transceiver, etc.), and / or a user interface. In some example embodiments, devices 1010, 1020, and / or 1030 may be configured to operate using one or more wireless access technologies, such as GSM, LTE, LTE-A, NR, 5G, WLAN, WiFi, NB-IoT, Bluetooth, NFC, MulteFire, and / or any other wireless access technology.
[0069] like Figure 10 As illustrated in the examples, devices 1010, 1020, and / or 1030 may respectively include or be coupled to processors 1012, 1022, and 1032 for processing information and executing instructions or operations. Processors 1012, 1022, and 1032 can be any type of general-purpose or special-purpose processor. In practice, as an example, processors 1012, 1022, and 1032 may include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), and a processor based on a multi-core processor architecture. Although... Figure 10 A single processor 1012 (and 1022 / 1032) is shown for each of devices 1010, 1020, and / or 1030; however, multiple processors may be used according to other example embodiments. For example, it should be understood that in some example embodiments, devices 1010, 1020, and / or 1030 may include two or more processors, which may form a multiprocessor system capable of supporting multiple processing steps (e.g., in this case, processors 1012, 1022, and 1032 may represent multiple processors). According to some example embodiments, the multiprocessor system may be tightly coupled or loosely coupled, for example, forming a computer cluster.
[0070] Processors 1012, 1022, and 1032 can respectively execute functions associated with the operation of devices 1010, 1020, and / or 1030. As examples, these functions include precoding of antenna gain / phase parameters, encoding and decoding of individual bits forming communication messages, formatting of information, and overall control of devices 1010, 1020, and / or 1030, as shown in Figure 2- Figure 9 The process is illustrated in the diagram.
[0071] Devices 1010, 1020, and / or 1030 may also include or be coupled to memories 1014, 1024, and / or 1034 (internal or external), which may be coupled to processors 1012, 1022, and 1032 for storing information and instructions executable by processors 1012, 1022, and 1032. Memory 1014 (as well as memories 1024 and 1034) may be one or more memories and may be of any type suitable for the local application environment, and may be implemented using any suitable volatile or non-volatile data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and / or removable memory. For example, memory 1014 (and memory 1024 and memory 1034) may include random access memory (RAM), read-only memory (ROM), static storage devices (such as disks or optical discs), hard disk drives (HDDs), or any other type of non-transitory machine-readable or computer-readable medium, and any combination thereof. Instructions stored in memory 1014, memory 1024, and memory 1034 may include program instructions or computer program code that, when executed by processors 1012, 1022, and 1032, enable devices 1010, 1020, and / or 1030 to perform the tasks described herein.
[0072] In some example embodiments, devices 1010, 1020, and / or 1030 may also include a drive or port or coupled to (internal or external) a drive or port configured to accept and read external computer-readable storage media, such as an optical disc, USB drive, flash drive, or any other storage media. For example, the external computer-readable storage medium may store computer programs or software for execution by processors 1012, 1022, and 1032 and / or devices 1010, 1020, and / or 1030, thereby executing the functions shown in Figures 2 to 30. Figure 9 Any of the methods illustrated in the figure.
[0073] According to various example embodiments, such as Figure 10 As shown, device 1010 may include at least one processor 1012 and at least one memory 1014. Memory 1014 may store instructions that, when executed by processor 1012, cause device 1010 to: receive an out-of-band request message from a connected device and send the out-of-band request message as a secure packet to a network entity. Device 1010 may also be caused to: send a response message received from the network entity to the connected device. The response message may trigger the connected device to complete the switching process.
[0074] According to various example embodiments, such as Figure 10 As shown, device 1020 may include at least one processor 1022 and at least one memory 1024. Memory 1024 may store instructions that, when executed by processor 1022, cause device 1020 to: perform an initial switching procedure for connection with network entities of the network and send an out-of-band request message to user equipment. Device 1020 may also be caused to: generate a security key based on the generated session key upon completion of the switching procedure.
[0075] According to various example embodiments, such as Figure 10 As shown, device 1030 may include at least one processor 1032 and at least one memory 1034. Memory 1034 may store instructions that, when executed by processor 1032, cause device 1030 to: obtain one or more out-of-band values from a secure packet received from user equipment, verify the secure packet, and send a response message to user equipment indicating that the secure packet has been verified. Device 1030 may also be caused to: generate a security key based on a generated session key when completing an exchange process with a connected device connected to user equipment.
[0076] According to various example embodiments, such as Figure 10 As shown, device 1010 may include at least one processor 1012 and at least one memory 1014. Memory 1014 may store instructions that, when executed by processor 1012, also cause device 1010 to: receive an out-of-band request message from a connected device, protect the out-of-band request message as a secure packet, and send it to a network entity. Device 1010 may also be caused to: send a response message received from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange process for authentication.
[0077] According to various example embodiments, such as Figure 10 As shown, device 1020 may include at least one processor 1022 and at least one memory 1024. Memory 1024 may store instructions that, when executed by processor 1022, also cause device 1020 to: generate a first network access identifier and, using the first network access identifier, perform an initial switching procedure for connection with a network entity of the network. Device 1020 may also be caused to: send an out-of-band request message to a user equipment and, in response to receiving a response message from the user equipment and upon completion of the switching procedure for network authentication, generate a security key to protect the connection between device 1020 and the network entity.
[0078] According to various example embodiments, such as Figure 10 As shown, device 1030 may include at least one processor 1032 and at least one memory 1034. Memory 1034 may store instructions that, when executed by processor 1032, also cause device 1030 to: receive a first network access identifier generated by a connected device, and allocate and send a second network access identifier to the connected device. Device 1030 may also be caused to: obtain one or more out-of-band values from a security packet received from a user equipment, verify the security packet, and send a response message to the user equipment indicating that the security packet has been verified. Device 1030 may also be caused to: generate a security key based on a generated session key when completing an exchange process with a device connected to the user equipment.
[0079] In some example embodiments, devices 1010, 1020, and / or 1030 may further include one or more antennas 1015, 1025, and 1035, or be coupled to one or more antennas 1015, 1025, and 1035, for receiving downlink signals and for transmitting from devices 1010, 1020, and / or 1030 via an uplink. Devices 1010, 1020, and / or 1030 may also include transceivers 1016, 1026, and 1036, respectively, configured to transmit and receive information. Transceivers 1016, 1026, and 1036 may also include a wireless interface, which may correspond to one or more of the following wireless access technologies: GSM, LTE, LTE-A, 5G, NR, WLAN, NB-IoT, Bluetooth, BT-LE, NFC, RFID, UWB, etc. The wireless interface may include other components such as filters, converters (e.g., digital-to-analog converters), symbol demappers, signal shaping components, inverse fast Fourier transform (IFFT) modules, etc., to process symbols (such as OFDMA symbols) carried by the downlink or uplink.
[0080] For example, transceivers 1016, 1026, and 1036 may be configured to modulate information onto a carrier waveform for transmission and demodulate received information for further processing by other elements of devices 1010, 1020, and / or 1030. In other example embodiments, transceivers 1016, 1026, and 1036 may be able to directly transmit and receive signals or data. Additionally or alternatively, in some example embodiments, devices 1010, 1020, and / or 1030 may include input and / or output devices (I / O devices). In some example embodiments, devices 1010, 1020, and / or 1030 may also include a user interface, such as a graphical user interface or a touchscreen.
[0081] In some example embodiments, memories 1014, 1024, and 1034 store software modules that provide functionality when executed by processors 1012, 1022, and 1032, respectively. Modules may include, for example, an operating system that provides operating system functionality for devices 1010, 1020, and / or 1030. The memories may also store one or more functional modules (such as applications or programs) to provide additional functionality for devices 1010, 1020, and / or 1030. Components of devices 1010, 1020, and / or 1030 may be implemented in hardware or any suitable combination of hardware and software. According to some example embodiments, devices 1010, 1020, and / or 1030 may optionally be configured to communicate with each other via wireless or wired communication links 1040, 1050, and 1060 according to any wireless access technology, such as NR.
[0082] According to some example embodiments, processors 1012, 1022, and / or 1032 and memories 1014, 1024, and / or 1034 may be included in or form part of a processing circuitry or control circuitry. Additionally, in some example embodiments, transceivers 1016, 1026, and 1036 may be included in or form part of a transceiver circuitry.
[0083] In some example embodiments, the apparatus (e.g., apparatus 1010, 1020, and / or 1030) may include components for performing methods, processes, or any variations discussed herein. Examples of components may include one or more processors, memory, controllers, transmitters, receivers, and / or computer program code for causing operations to be performed.
[0084] Some example embodiments may relate to apparatus 1010, which includes: components for receiving out-of-band request messages from a connected device, and components for sending the out-of-band request messages as secure packets to a network entity. Apparatus 1010 may further include: components for sending a response message received from the network entity to the connected device. The response message may trigger the connected device to complete the exchange process.
[0085] Some example embodiments may relate to apparatus 1020, which includes: components for performing an initial switching process for connecting to a network entity of the network, and components for sending an out-of-band request message to a user equipment. Apparatus 1020 may also include: components for generating a security key based on the generated session key upon completion of the switching process.
[0086] Various example embodiments may relate to apparatus 1030, which includes: components for obtaining one or more out-of-band values from a security packet received from a user equipment; components for verifying the security packet; and components for sending a response message to the user equipment, the response message indicating that the security packet has been verified. Apparatus 1030 may further include: components for generating a security key based on a generated session key when completing an exchange process with a connected device connected to the user equipment.
[0087] Some example embodiments may relate to apparatus 1010, which includes: components for receiving out-of-band request messages from a connected device, components for protecting the out-of-band request messages as secure packets, and components for sending the out-of-band request messages as secure packets to a network entity. Apparatus 1010 may further include: components for sending a response message received from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange process for authentication.
[0088] Various example embodiments may relate to apparatus 1020, which includes: components for generating a first network access identifier, and components for performing an initial exchange procedure using the first network access identifier for connection with a network entity of the network. Apparatus 1020 may also include: components for sending an out-of-band request message to a user equipment. Apparatus 1020 may further include: components for generating a security key to protect the connection between the apparatus and the network entity in response to receiving a response message from the user equipment and upon completion of the exchange procedure to authenticate the network entity.
[0089] Some example embodiments may relate to apparatus 1030, which includes: means for receiving a first network access identifier generated by a connected device. Apparatus 1030 may further include: means for assigning a second network access identifier to the connected device, and means for sending the second network access identifier to the connected device. Apparatus 1030 may further include: means for obtaining one or more out-of-band values from a security packet received from a user equipment. Apparatus 1030 may further include: means for verifying a security packet and means for sending a response message to the user equipment, the response message indicating that the security packet has been verified. Apparatus 1030 may include: means for generating a security key based on a generated session key when completing an exchange process with a device connected to the user equipment.
[0090] As used herein, the term "circuit system" can refer to a hardware circuit system implementation (e.g., analog and / or digital circuit systems), a combination of hardware circuitry and software, a combination of analog and / or digital hardware circuitry and software / firmware, or any portion of a hardware processor (including a digital signal processor) that works with software to enable a device (e.g., device 1010, 1020, and / or 1030) to perform various functions, and / or to operate using software but may be absent when software is not required for operation. As another example, as used herein, the term "circuit system" can also encompass an implementation of hardware circuitry or a processor or multiple processors, or a portion of hardware circuitry or a processor along with accompanying software and / or firmware. The term "circuit system" can also encompass baseband integrated circuits in, for example, servers, cellular network nodes or devices, or other computing or networking devices.
[0091] A computer program product may include one or more computer-executable components, which are configured to implement some example embodiments during program runtime. The one or more computer-executable components may be at least one piece of software code or a portion thereof. Modifications and configurations required to implement the functionality of certain example embodiments may be executed as routines, which may be implemented as additional or updated software routines. Software routines may be downloaded to a device.
[0092] As an example, software or computer program code, or portions thereof, may be in the form of source code, object code, or some intermediate form, and may be stored on some carrier, distribution medium, or computer-readable medium, which may be any entity or device capable of carrying the program. For example, such a carrier may include recording media, computer memory, read-only memory, photoelectric and / or electrical carrier signals, telecommunication signals, and software distribution packages. Depending on the required processing power, the computer program may execute in a single electronic digital computer or may be distributed among multiple computers. The computer-readable medium or computer-readable storage medium may be a non-transitory medium.
[0093] In other example embodiments, the function may be performed by hardware or circuitry included in the device (e.g., devices 1010, 1020, and / or 1030), for example, by using an application-specific integrated circuit (ASIC), a programmable gate array (PGA), a field-programmable gate array (FPGA), or any other combination of hardware and software. In yet another example embodiment, the function may be implemented as a signal, i.e., an intangible means that can be carried by an electromagnetic signal downloaded from the Internet or other networks.
[0094] According to certain example embodiments, the apparatus (such as a node, device, or corresponding component) may be configured as a circuit system, a computer, or a microprocessor (such as a single-chip computer element), or may be configured as a chipset that includes at least a memory for providing storage capacity for arithmetic operations and an arithmetic processor for performing arithmetic operations.
[0095] The features, structures, or characteristics of the exemplary embodiments described throughout this specification can be combined in any suitable manner in one or more exemplary embodiments. For example, the use of the phrases "some embodiments," "exemplary embodiments," "some embodiments," or other similar language throughout this specification means that a particular feature, structure, or characteristic described in connection with an embodiment can be included in at least one embodiment. Therefore, the phrases "some embodiments," "exemplary embodiments," "some embodiments," "other embodiments," or other similar language appearing throughout this specification do not necessarily refer to the same set of embodiments, and the described features, structures, or characteristics can be combined in any suitable manner in one or more exemplary embodiments. Furthermore, throughout this specification, the terms "cell," "node," "gNB," or other similar language are used interchangeably.
[0096] As used herein, "at least one of the following: " and "at least one of the " and similar wording, wherein the list of two or more elements is connected by "and" or "or", means at least any one of the elements, at least any two or more of the elements, or at least all of the elements.
[0097] It will be readily understood by those skilled in the art that the present disclosure discussed above can be practiced using procedures of different sequences and / or using hardware elements in configurations different from the disclosed configuration. Therefore, although the present disclosure has been described based on these exemplary embodiments, it will be apparent to those skilled in the art that certain modifications, variations, and alternative constructions will be readily apparent while remaining within the spirit and scope of the exemplary embodiments. While the above embodiments relate to 6G, 5G NR, and LTE technologies, they can also be applied to any other current or future 3GPP technologies, such as Advanced LTE and / or fourth-generation (4G) technologies.
[0098] Partial Glossary:
[0099] 3GPP Third Generation Partnership Project
[0100] 5G (Fifth Generation)
[0101] 6G sixth generation
[0102] ACK confirmation
[0103] AMF Access and Mobility Management Functions
[0104] AS Access Layer
[0105] AUSF Authentication Server Functionality
[0106] CRM (Customer Relationship Management)
[0107] DL downlink
[0108] EAP Extensible Authentication Protocol
[0109] ECDHE Temporary Elliptic Curve Diffie-Hellman
[0110] EMBB Enhanced Mobile Broadband
[0111] gNB 5G or next-generation node B
[0112] HOOB Hashout
[0113] ID identifier
[0114] IoT (Internet of Things)
[0115] LTE Long Term Evolution
[0116] NAI Network Access Identifier
[0117] NAS Non-Access Layer
[0118] NOOB Flexible Out-of-Band
[0119] Ns, Np are random numbers for IoT devices and their home networks.
[0120] NR New Wireless
[0121] PK public key
[0122] PKHN Public Key Ownership Network
[0123] RAN (Radio Access Network)
[0124] UDM Unified Data Management
[0125] UE User Equipment
[0126] UL uplink< / visitedmcc> < / visitedmnc> < / imsi> < / homemcc> < / homemnc> < / mcc> < / mnc> < / mcc> < / mnc>
Claims
1. An apparatus comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the device to perform at least the following: Receive out-of-band request messages from the connected device; The out-of-band request message is protected as a secure packet and sent to the network entity; and Send a response message received from the network entity to the connected device, wherein the response message triggers the connected device to complete a completion exchange process for authentication.
2. The apparatus of claim 1, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform: Before receiving the out-of-band request message, the device is connected via an initial exchange procedure.
3. The apparatus according to claim 1 or claim 2, wherein the out-of-band request message includes: The identifier, flexible out-of-band value, and hash out-of-band value of the connected device assigned by the network entity.
4. The apparatus according to any one of claims 1 to 3, wherein the out-of-band request message is protected as the secure packet and is sent via: During the registration process, a previously established secure connection is used between the device and the network entity; or Use the authentication server function key to generate secure uplink update parameter packets.
5. The apparatus according to any one of claims 1 to 4, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform: In response to sending the security packet to the network entity, the response message is received from the network entity, wherein the response message includes: The result of the network entity's verification process for the security packet.
6. An apparatus comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the device to at least: Generate the first network access identifier; Using the first network access identifier, perform an initial switching procedure for connection to network entities of the network; Send an out-of-band request message to the user equipment; as well as In response to receiving a response message from a user equipment and upon completing the exchange process to authenticate the device with the network, a security key is generated to protect the connection between the device and the network entity.
7. The apparatus of claim 6, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform: During the initial exchange process, a second network access identifier assigned by the network entity is received.
8. The apparatus of claim 7, wherein the out-of-band request message comprises: The second network access identifier, flexible out-of-band value, and hash out-of-band value.
9. The apparatus according to any one of claims 6 to 8, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: The response message is received from the user equipment, wherein the response message includes an indication that the device has been authenticated by the network.
10. The apparatus according to any one of claims 6 to 9, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: A session key is generated based on the response message.
11. The apparatus of claim 10, wherein the generated security key is derived from the generated session key.
12. An apparatus comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the device to at least: Receive the first network access identifier generated by the connected device; Assign and send a second network access identifier to the connected device; Obtain one or more out-of-band values from the security packets received from the user equipment; The security packet is verified and a response message is sent to the user equipment, the response message indicating that the security packet has been verified; as well as When completing the exchange process with the device connected to the user equipment, a security key is generated based on the generated session key.
13. The apparatus of claim 12, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform: Assign and send peer identifiers to the connected devices.
14. The apparatus of claim 13, wherein the security group comprises: The peer identifier, flexible out-of-band value, hash out-of-band value, and media access control identifier.
15. The apparatus according to any one of claims 12 to 14, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform: Generate uplink acknowledgments for uplink packets; Generate downlink acknowledgments for the security packets; and Send the response message, which includes the uplink acknowledgment and the downlink acknowledgment.