Authentication and device identifier management for passive wireless transmission devices

EP4748102A1Pending Publication Date: 2026-05-27KONINK KPN NV +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
KONINK KPN NV
Filing Date
2024-07-16
Publication Date
2026-05-27

AI Technical Summary

Technical Problem

Passive wireless transmission devices, such as ambient IoT devices, face challenges in authentication and device identifier management due to power restrictions and the need for efficient energy use, particularly when reusing device identifiers is necessary.

Method used

A system and method that allow for the reuse of device identifiers by using short, reusable identifiers and associated authentication tokens, where the system manages associations between identifiers and tokens, enabling both present and past associations for authentication and identifier management.

Benefits of technology

This approach enables efficient management of device identifiers and authentication for large populations of passive wireless transmission devices, optimizing energy use and allowing for flexible identifier reuse while maintaining authentication integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024070159_23012025_PF_FP_ABST
    Figure EP2024070159_23012025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure pertains to a system configured for communication with a plurality of passive wireless transmission devices. The system is configured to receive a first wireless transmission of a passive wireless transmission device, wherein the first wireless transmission comprises a first device identifier and a first authentication token. The system may, for example, authenticate this transmission based on the association of the first device identifier and the first authentication token. The system may also be configured to determine a second authentication token for the passive wireless transmission device. The system may further be configured to invalidate the first device identifier for the passive wireless transmission device, for example because the system has re-assigned the first device identifier to another passive wireless transmission device. The system may further be configured to determine a second device identifier for the passive wireless transmission device under consideration. The system may further be configured to store an association of the second authentication token with a second device identifier as a present association for the passive wireless transmission device and to store an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device. The system may further be configured to receive a second wireless transmission of the passive wireless transmission device. The system may further be configured to authenticate the second wireless transmission if the second wireless transmission contains the second device identifier and the second authentication token in accordance with the present association and to also authenticate the second wireless transmission if the second wireless transmission contains the first device identifier and the second authentication token in accordance with the past association.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Authentication and device identifier management for passive wireless transmission devices

[0002] TECHNICAL FIELD

[0003] The present disclosure relates to a system and passive wireless transmission device. In particular, the disclosure relates to a system for management of authentication and device identifiers for such passive devices.

[0004] BACKGROUND

[0005] Future networks are expected to host sizable numbers of passive wireless transmission devices that store and / or collect data that should be uploaded via a network infrequently or in small amounts. Such devices should be managed efficiently in a network.

[0006] For example, 3GPP recently issued a study on ambient power-enabled Internet of Things, loT, devices in Technical Recommendation 3GPP TR 22.840. The document discloses use cases and requirements for ambient power-enabled loT devices, hereinafter also referred to as ambient loT devices, being battery-less devices with limited energy storage capability (a capacitor may be included) wherein the energy is provided through the harvesting of radio waves, light, motion, heat or any other power source that could be suitable. Thus, energy is a very scarce resource in this context, and its usage is preferably optimized by limiting computations and / or the number and size of exchanged messages. Additionally, an ambient loT device may remain passive for extended periods of time before receiving a wake-up signal and starting to send data.

[0007] Devices use an identifier to identify themselves to the network and such identifiers are typically assigned uniquely to a device. The network will typically authenticate a device using this identifier, i.e., verify that the device is rightfully using this identifier in its transmissions. The authentication normally proceeds in a series of steps of transmissions from both the network and the device.

[0008] SUMMARY

[0009] The inventors have realized that such authentication and use of device identifiers constitutes a challenge for passive devices. For example, for ambient loT devices it may be needed to re-use identifiers since the number of devices may be huge, which would require long identifiers if these need to be unique. On the other hand, whereas ambient loT devices normally only can and need to transmit limited amounts of data, transmitting long identifiers alongside the data is not efficient and normally even problematic given the power restrictions for such devices.

[0010] Hence, the inventors have considered that device identifiers may need to be relatively short. Short device identifiers imply scarcity of such identifiers, so that re-use of temporarily or permanently unused identifiers is highly desirable. As a result, re-assignment and / or revocation of device identifiers may be needed in some use cases for passive devices, while satisfying at least some degree of authentication in the network.

[0011] One aspect of the disclosure involves a system configured for communication with a plurality of passive wireless transmission devices. The system is configured to receive a first wireless transmission of a passive wireless transmission device, wherein the first wireless transmission comprises a first device identifier and a first authentication token. The system may, for example, authenticate this transmission based on the association of the first device identifier and the first authentication token. The system may also be configured to determine a second authentication token for the passive wireless transmission device. The system may further be configured to invalidate the first device identifier for the passive wireless transmission device, for example because the system has re-assigned the first device identifier to another, second, passive wireless transmission device. The system may further be configured to receive a second wireless transmission of the passive wireless transmission device. The system may further be configured to determine a second device identifier for the passive wireless transmission device under consideration. The system may further be configured to store an association of the second authentication token with a second device identifier as a present association for the passive wireless transmission device and may be configured to store an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device. The system may further be configured to authenticate the second wireless transmission if the second wireless transmission contains the second device identifier and the second authentication token in accordance with the present association and to also authenticate the second wireless transmission if the second wireless transmission contains the first device identifier and the second authentication token in accordance with the past association.

[0012] Another aspect of the disclosure pertains to a passive wireless transmission device configured to be used with a system as disclosed herein. In one embodiment, the passive wireless transmission device is configured to perform a first wireless transmission comprising at least a first device identifier and a first authentication token. The passive wireless transmission device may further be configured to generate a second encryption token or receive a second authentication token from the system. The passive wireless transmission device may further be configured to perform a second wireless transmission comprising the first device identifier and the second authentication token and receive a second device identifier from the system in response to the second wireless transmission. Optionally, the passive wireless transmission device may be configured to perform a third wireless transmission comprising at least the second device identifier and the second authentication token or a third authentication token.

[0013] The system and passive wireless transmission device enable re-use of device identifiers while allowing for some degree of authentication. The system uses the authentication token both for authentication and for device identification by requiring each wireless transmission to contain a preferably new authentication token while allowing some flexibility in the device identifier used in the transmission. A device identifier can, for example, continue to be used by a device as long as the device identifier is associated in the system with an authentication token forthat device. This enables the use of the same device identifier by another passive wireless transmission device (but with a different authentication token). Authentication remains possible by association in the system of an authentication token for each wireless transmission with a device identifier and authentication token associated in the system. The system thus allows use of not only present associations but also past associations to manage the distribution of device identifiers by interpreting wireless transmissions associated with past associations as authenticated requests for a new device identifier or even as an authenticatable wireless transmission. As a result, device identifiers do not have to be unique permanently and / or amongst the population of the devices, so that shorter device identifiers may be used as needed for a large population of passive, i.e. power-restricted, wireless transmission devices. This improves the management of device identifiers and authentication from a central system.

[0014] It should be appreciated that the system may be a stand-alone system in wireless communication with a plurality of passive wireless transmission devices or be a system contained in a network, such as a telecommunications network, that contains at least a wireless part for wireless communication with passive wireless transmission devices.

[0015] It should be noted that the length of the device identifier and the authentication token depends on the use case, for example, the number of devices, the (expected) frequency of data transmissions, etc.

[0016] It should also be appreciated that, in one embodiment, if a wireless transmission comprises a device identifier and authentication token not found in the association in the system, the wireless transmission will not be accepted and further actions may be performed, such as the transmission of an identifier revoke message, or ignoring or discarding the transmission.

[0017] Ultralightweight mutual authentication protocols (UMAP) for low-cost passive RFID tags are described in Security and Communication Network, volume 2019 by M. Khalid, U. Mujadid and N Muhammad (DOI: 10.1155 / 2019 / 3295616). In this paper, an RFID reader identifies a tag by receiving a pseudo-identification number and keys, which are dynamically generated and updated separately in the tag and the RFID reader. This protocol does not enable re-use of identifiers by re-assigning and / or revoking identifiers from a central network system avoiding collision of identifiers. Since the identification numbers are computed in the tag and the RFID reader separately, identifiers in tags may conflict and UMAP cannot solve this conflict.

[0018] In one embodiment, the system is further configured to transmit the second device identifier to the passive wireless transmission device. The embodiment provides for a centralized and dynamic coordination of the (re-)assignment of device identifiers to enable re-use of identifiers. The system may, for example, transmit the second device identifier when the second device identifier is determined or when the past association is determined, i.e. in response to receiving the second wireless transmission comprising the first device identifier, that may have been invalidated, and the second authentication token.

[0019] In one embodiment, the system may further be configured to transmit the second authentication token to the passive wireless transmission device. The embodiment provides the advantage of limiting processing requirements for the passive wireless transmission device and to facilitate coordination of authentication tokens. Also, the authentication token can be refreshed using this procedure, i.e. the refreshed authentication token does not have to be computationally related to a past authentication token.

[0020] In one embodiment, the system is further configured to assign the first device identifier to a second passive wireless transmission device and store an association of a further authentication token with the first device identifier as a present association for the second passive wireless transmission device. The system may be configured to receive a third wireless transmission from a passive wireless transmission device and authenticate the third wireless transmission as a transmission from the second passive wireless transmission device if the second wireless transmission contains the first device identifier and the further authentication token in accordance with the present association for the second passive wireless transmission device.

[0021] The embodiment exemplifies assignment of the first device identifier to another, second, passive wireless transmission device, while using the same device identifier as a past association for the first passive wireless transmission device in a past association. The first device identifier may, for example, be assigned to the second wireless transmission device after having been invalidated for the first wireless transmission device.

[0022] In one embodiment, the system is further configured to obtain an applicable encryption key for an association of a device identifier and an associated authentication token. Coupling the encryption key to an association of device identifiers and authentication tokens facilitates determination of the applicable encryption key from at least one of the device identifier and authentication token.

[0023] In one embodiment, the system is further configured to encrypt at least a part of the second device identifier and / or the second authentication token, if transmitted from the system, using an applicable encryption key, for example upon transmission to the passive wireless transmission device.

[0024] Likewise, the passive wireless transmission device may be configured to contain at least one encryption key. In an embodiment, the device is configured to receive the second device identifier and / or the second authentication token from the system at least in part in encrypted form and to decrypt at least the part of the second device identifier and / or the second authentication token using the encryption key.

[0025] The embodiment enhances security for the downlink transmission of the second device identifier and, if transmitted, also the second authentication token.

[0026] In one embodiment, the system is further configured to obtain an updated encryption key for a device identifier and associated authentication token. Updating the encryption key continues or improves the security of the transmission.

[0027] In one embodiment, the system is further configured to receive a wireless transmission of a passive wireless transmission device wherein a data part of the wireless transmission is encrypted and forward the encrypted data, such as sensor data, in the wireless transmission to a data collecting entity. The address of the data collecting entity may be obtained using at least one of the device identifier and the authentication token in the wireless transmission.

[0028] Likewise, the passive wireless transmission device may further be configured to transmit data, such as sensor data, in at least one of the first, second and third wireless transmission. The device may contain an applicable encryption key to encrypt the data.

[0029] The embodiment allows for the transmission of data, other than the device identifier and the authentication token, in encrypted form when wirelessly transmitted by the passive wireless transmission device to the operator of the passive wireless transmission devices. The encryption key may be known only to the operator of, for example, the data collecting entity. This provides for a secure transmission of sensor data. In one embodiment, the system is configured to transmit to the passive wireless transmission device at least one of a random number enabling the wireless transmission device to provide or update an applicable encryption key and a key index enabling the wireless transmission device to provide or update an applicable encryption key.

[0030] Likewise, the passive wireless transmission device may be configured to obtain an applicable encryption key by receiving a random number from the system and input the random number in a key generation algorithm to derive the encryption key or by receiving a key index from the system to select an applicable encryption key from a set of encryption keys stored in the passive wireless transmission device and retrievable via the key index.

[0031] The embodiments provide for secure encryption key provision and / or update mechanisms. If the passive wireless transmission device has some processing power at suitable times, it may run an key generation algorithm. If less or energy is available or power is available only at particular times (e.g. when receiving a transmission from the network, such as a transmission including a key index), the key update mechanism may use the set of encryption keys to select an updated applicable encryption key.

[0032] In some situations, it may be necessary to update the encryption keys via transmission of the key over the air.

[0033] Therefore, in one embodiment, the system may be configured to provide a new applicable encryption key encrypted using a previously provided encryption key.

[0034] Likewise, in one embodiment the passive wireless transmission device may be configured to obtain an applicable encryption key by decrypting an applicable encryption key received from the system using a previously stored encryption key.

[0035] The embodiments allow secure transmission of encryption keys over the air using previously stored applicable encryption keys. After having received and stored the encryption key, the previously stored applicable encryption key may become outdated.

[0036] In one embodiment, the system may be configured to transmit one or more identifier revoke messages to announce revocation of the first identifier to the passive wireless transmission device.

[0037] Likewise, the passive wireless transmission device may be configured to receive one or more identifier revoke messages. Optionally, the device may be configured to stop performing wireless transmissions for the system in response to receiving the one or more identifier revoke messages, at least for the system to which transmissions were allowed previously.

[0038] Wireless transmission devices may not be aware that their identifier is no longer valid. While transmissions from a device using a device identifier that has already been re-assigned to another device will typically not be authenticated anymore (because an association between the identifier and the authentication key no longer exists in the network system), it may be beneficial to inform devices of the revocation. Such information may stop devices from transmitting altogether thereby saving network resources.

[0039] As mentioned above, passive wireless transmission devices, such as ambient loT devices, need external energy to perform operations and transmission. Therefore, in one embodiment, the system may be configured to trigger a wireless transmission configured to energize the passive wireless transmission device. In some embodiments, the wireless transmission may contain at least one of the second device identifier, the second authentication token and the identifier revoke message described above.

[0040] Likewise, in one embodiment, the passive wireless transmission device may be configured to comprise an energy harvesting part. The energy harvesting part may be configured to harvest energy from a wireless transmission from the system, such as at least one of the second device identifier, the second authentication token and the identifier revoke message described above, to perform wireless transmissions to the network.

[0041] The embodiments combine signaling messages triggered by the system to enable re-use of device identifiers with providing at least part of the energy for such devices. This energy may be used to perform functions in the passive wireless transmission devices to enable this re-use.

[0042] In one embodiment, the passive wireless transmission device may be configured to transmit an acknowledgement signal to the system to acknowledge receipt of the second device identifier. This enables the system to confirm that the wireless transmission device has appropriately received a device identifier.

[0043] In one embodiment, the passive wireless transmission device may be configured to receive an acknowledgement signal from the system to acknowledge receipt of the first and / or second wireless transmission, wherein the wireless transmission device, optionally, is configured to use the received acknowledgement signal to at least one of trigger calculation of an authentication token, refrain from re-sending data and energize the passive wireless transmission device.

[0044] Another aspect of the disclosure relates to a method for communication with a plurality of passive wireless communication devices comprising one or more of the following steps. The method involves a step of receiving a first wireless transmission of a passive wireless transmission device, the first wireless transmission comprising a first device identifier and a first authentication token. The system may, for example, authenticate this transmission based on the association of the first device identifier and the first authentication token. The method may further include the step of determining a second authentication token for the passive wireless transmission device. The method may further include the step of invalidating the first identifier for the passive wireless transmission device, for example because the system has re-assigned the first device identifier to another passive wireless transmission device. The method may further include the step of receiving a second wireless transmission of the passive wireless transmission device. The method may further include the step of determining a second device identifier for the passive wireless transmission device. The method may further include the step of storing an association of the second authentication token with a second device identifier as a present association for the passive wireless transmission device and storing an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device. The method may also include the step of authenticating the second wireless transmission if the second wireless transmission contains the second device identifier and the second authentication token in accordance with the present association and also authenticating the second wireless transmission if the second wireless transmission contains the first device identifier and the second authentication token in accordance with the past association.

[0045] Another aspect pertains to a computer program comprising one or more software code portions that, if executed in the system, cause the system to perform one or more steps of this method.

[0046] A further aspect of the disclosure involves a method for a passive wireless communication device for use in a system configured for communication with passive wireless communication devices. The method may involve one or more of the following steps. One step involves performing a first wireless transmission comprising at least a first device identifier and a first authentication token. One further step may involve generating or receiving a second authentication token from the system. A still further step may involve performing a second wireless transmission comprising the first device identifier and the second authentication token and receiving a second device identifier from the system in response to the second wireless transmission. A further, optional, step may include performing a third wireless transmission comprising at least the second device identifier and the second authentication token or a third authentication token.

[0047] Another aspect pertains to a computer program comprising one or more software code portions that, if executed in the system, cause the system to perform one or more steps of this method.

[0048] A still further aspect of the disclosure involves a combination of a system for communication with a plurality of passive wireless transmission devices and a passive wireless transmission device as disclosed herein. In particular, such a combination involves a passive wireless communication system comprising a central system and a plurality of passive wireless communication devices. The passive wireless communication system is configured to perform, at the passive wireless communication device, a first wireless transmission comprising at least a first device identifier and a first authentication token; receive, at the central system, the first wireless transmission of the passive wireless transmission device, the first wireless transmission comprising the first device identifier and the first authentication token; determine, in at least the central system and, optionally, also in the passive wireless communication device, a second authentication token; invalidate, at the central system, the first device identifier for the passive wireless transmission device and determine a second device identifier for the passive wireless transmission device; perform, at the passive wireless communication device, a second wireless transmission; receive, at the central system, the second wireless transmission of the passive wireless transmission device; store, at the central system, an association of the second authentication token with the second device identifier as a present association for the passive wireless transmission device; store, at the central system, an association of the second authentication token with the first identifier as a past association for the passive wireless transmission device; authenticate, at the central system, the second wireless transmission if the second wireless transmission contains the second device identifier and the second authentication token in accordance with the present association, authenticate, at the central system, the second wireless transmission if the second wireless transmission contains the first device identifier and the second authentication token in accordance with the past association.

[0049] Optionally, in response to determining the second device identifier or / and the past association, the passive wireless communication system may be configured to transmit, at the central system, the second device identifier; receive, at the passive wireless transmission device, the second device identifier; perform, at the passive wireless transmission device, a third wireless transmission comprising the second device identifier and the second authentication token or a third authentication token; authenticate, at the central system, the third wireless transmission on the basis of the second device identifier and second authentication token from the present association or the second device identifier and the third authentication token as a present association.

[0050] The second authentication token may be transmitted from the central system to the passive wireless transmission device and received by the passive wireless transmission device. The second authentication token may also be generated in the passive wireless transmission device.

[0051] It should also be appreciated that the sequence of steps may change while arrive at the same result.

[0052] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as a system, a method or a computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a "circuit," "module" or "system." Functions described in this disclosure may be implemented as an algorithm executed by a processor / microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied, e.g., stored, thereon.

[0053] Any combination of one or more computer readable medium(s) may be utilized. The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer readable storage medium may include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present invention, a computer readable storage medium may be any tangible medium that can contain, or store, a program for use by or in connection with an instruction execution system, apparatus, or device.

[0054] A computer readable signal medium may include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium may be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0055] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber, cable, RF, etc., or any suitable combination of the foregoing. Computer program code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code may execute entirely on the person's computer, partly on the person's computer, as a stand-alone software package, partly on the person's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the person's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0056] Aspects of the present invention are described below with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor, in particular a microprocessor or a central processing unit (CPU), of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer, other programmable data processing apparatus, or other devices create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0057] These computer program instructions may also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.

[0058] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.

[0059] Moreover, a computer program for carrying out the methods described herein, as well as a non- transitory computer readable storage-medium storing the computer program are provided.

[0060] Elements and aspects discussed for or in relation with a particular embodiment may be suitably combined with elements and aspects of other embodiments, unless explicitly stated otherwise. Embodiments of the present invention will be further illustrated with reference to the attached drawings, which schematically will show embodiments according to the invention. It will be understood that the present invention is not in any way restricted to these specific embodiments.

[0061] BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Aspects of the invention will be explained in greater detail by reference to exemplary embodiments shown in the drawings, in which:

[0063] FIG. 1 is a schematic illustration of a central system configured for wireless communication with a plurality of passive wireless transmission devices;

[0064] FIG. 2 is a time chart of some steps for wireless transmissions between a central system and passive wireless transmission devices;

[0065] FIG. 3 is a schematic illustration of another embodiment of a central system in a network configured for wireless communication with a plurality of passive wireless transmission devices;

[0066] FIG. 4 is a schematic illustration of a passive wireless transmission device configured for wireless communication with a central system;

[0067] FIG. 5 is a time chart of some alternative or additional steps for wireless transmission between a central system and a passive wireless transmission device;

[0068] FIGS. 6A-6E show various stages of device identifier management according to an embodiment of the present disclosure; and

[0069] FIG. 7 depicts an example of a processing system according to an embodiment of a central system or a part thereof. DETAILED DESCRIPTION OF THE DRAWINGS

[0070] FIG. 1 is a schematic illustration of a passive wireless communication system 100 comprising a central system 10 and a plurality of passive wireless transmission devices 20. Central system 10 comprises a processing unit 11 , a storage 12 for storing information, such as device identifiers ID and authentication tokens T, and a communication interface 13. Communication interface 13 facilitates wireless communication with the passive wireless transmission devices 20.

[0071] Central system 10 may be a stand-alone system or a system included in a network. When in a stand-alone system, communication interface 13 may be configured for wireless communication with passive wireless transmission devices itself. In one embodiment, radio signals from the central system 100 may both be used to power the passive wireless communication devices and to exchange information between them. When the central system is included in the network, see for example FIG. 3, the communication interface 13 may be connected, wirelessly or wired, with an entity taking care of wireless communication.

[0072] Passive wireless transmission devices 20 are power-restricted devices, such as ambient power- enabled loT devices. Such devices may also be referred to as passive loT devices or ambient loT devices. Such devices may be battery-less devices with limited energy storage capability (a capacitor may be included) wherein the energy is provided through the harvesting of radio waves, light, motion, heat or any other power source that could be suitable. Thus, energy is a very scarce resource in this context, and its usage is preferably optimized by limiting computations and / or the number and size of exchanged messages. Additionally, a passive wireless communication device may remain passive for extended periods of time before receiving a wake-up signal and starting to send data. An embodiment of a passive wireless transmission device 20 will be described further with reference to FIG. 4.

[0073] FIG. 2 is a time chart depicting one or more steps of a method for the passive wireless communication system 100 to enable re-use of device identifiers ID. It should be noted that the skilled person would envisage that the order of some steps may be changed and / or that fewer and / or additional steps may be performed.

[0074] In step S1 , the central system 10 receives a first wireless transmission of a passive wireless transmission device 20A, the first wireless transmission comprising a first device identifier ID1 and a first authentication token T1 . The wireless transmission may use power from a signal, such as a request for information signal, from the central system 10 or from another energy source external to the device 20A. The central system 10 may authenticate the transmission by determining that the first device identifier ID1 and first authentication token T1 are associated in the central system 10. The central system may acknowledge the successful receipt of the first wireless transmission (not shown).

[0075] In step S2, both the passive wireless transmission device 20A and the central system 10 calculate a second authentication token T2. This calculation in the device 20A may be triggered by the receipt of the acknowledgement of step S1 . Computing the second authentication token separately at both the device 20A and central system 10 limits signaling over the air interface. The acknowledgment may power the passive wireless transmission device 20A to perform this calculation. Central system 10 may now associate ID1 with T2 in storage 12. In step S3, the passive wireless transmission device 20A may perform another wireless transmission comprising the first identifier ID1 and the new authentication token T2. Again, the central system may authenticate the transmission based on first identifier ID1 and new authentication token T2 stored in association in storage 12. Again, the transmission may be acknowledged (not shown).

[0076] In step S4, both the central system 10 and passive wireless transmission device 20A compute a third authentication token T3. Central system 10 may now associate ID1 and T3 in storage 12.

[0077] After some time, the central system 10 may receive a transmission from a further passive wireless transmission device 20B in step S5. The central system 10 may decide, in response to receiving this transmission, to assign the first identifier ID1 to this further passive wireless transmission device 20B in step S6. Both the central system 10 and the passive wireless transmission device 20B may compute an authentication token T4 in step S7. Central system 10 may now associate ID1 with T4 in storage 12. The central system 10 may invalidate device identifier ID1 for passive wireless transmission device 20A.

[0078] In step S8, the central system 10 authenticates a wireless transmission from passive wireless transmission device 20B comprising device identifier ID1 and authentication token T4. Both the wireless device 20B and the central system 10 may compute a further authentication token (not shown), for example in response to an acknowledgement of the transmission (not shown).

[0079] After some further time, the passive wireless transmission device 20A, being unaware of the reassignment of the device identifier ID1 to passive wireless transmission device 20B, performs another wireless transmission in step S9, comprising the first device identifier ID1 and the authentication token T3 to central system 10. The central system 10 determines that the first device identifier ID1 has been assigned to another wireless transmission device. Central system 10 may determine this, for example, by detecting that ID1 is not associated (anymore) with authentication token T3 (but with authentication token T4, resulting from the re-assignment of the device identifier ID1 to device 20B).

[0080] Still, because the association of the first device identifier ID1 and authentication token T3 is still present in the central system 10, the system authenticates the transmission of step S9. Therefore, in step S10, central system 10 assigns a new device identifier ID2 to passive wireless transmission device 20A and informs the passive wireless transmission device 20A thereof. The transmission in step S10 also contains a refreshed authentication token T5 generated in the central system 10 and stored therein. Central system 10 may now associate ID2 with T5 in storage 12.

[0081] Optionally, the passive wireless transmission device 20A may re-transmit the wireless transmission in step S11 comprising the second device identifier ID2 and the authentication token T5. Central system 10 may authenticate this transmission and return an acknowledgement (not shown). This may cause central system 10 and passive wireless transmission device 20A to calculate an authentication token T6 in step S12. Central system 10 may now associate ID2 with T6 in storage 12.

[0082] The system 10 and passive wireless transmission device 20A enable re-use of device identifier ID1 while allowing for some degree of authentication. The system uses the authentication tokens T both for authentication and for device identification by requiring each wireless transmission to contain a new authentication T token while allowing some flexibility in the device identifier used in the transmission. A device identifier ID1 can continue to be used by the device (see step S3) as long as the device identifier is not re-assigned to another device (such as in step S6). Otherwise, a new device identifier ID2 is assigned (step S10). Authentication remains possible by association of an authentication token T with a device identifier for each transmission. As a result, device identifiers IDx do not have to be unique permanently and / or amongst the population of the passive wireless transmission devices 20, so that shorter device identifiers may be used as needed for a large population of passive, i.e. power-restricted, wireless transmission devices 20. This improves the management of device identifiers and authentication from central system 10.

[0083] FIG. 3 is another embodiment of a passive wireless communication system 100 wherein the central system is included in a telecommunications network PLMN. The telecommunications network may be a 4G, 5G or 6G network. The telecommunications network PLMN may have a plurality of components as known to the skilled person, including a base station, a control plane system and a data plane system. The central system 10 may be contained in one such component or be distributed over several components, as shown in FIG. 3. For example, the wireless transmission interface 13 may be included in a base station providing wireless radio coverage to a plurality of passive wireless transmission devices 20. Processing unit 11 , as shown in FIG. 1 , may be housed in the radio access network as well or within the core network of the PLMN. Likewise, storage 12, as shown in FIG. 1 , may be included in the radio access network, core network (e.g. in a user register, such as a Home Subscriber System, HSS, or a Unified Data Management function, UDM) or be distributed over the network.

[0084] The telecommunications network PLMN may be connected over a further network NW to an operator, OP, of the passive wireless communication devices 20 as shown in FIG. 3.

[0085] FIG. 4 is a schematic illustration of a passive wireless transmission device 20 configured for wireless communication with a central system 10. The device 20 is configured to receive and process a power signal PS. The device 20 comprises a power harvesting part 21 , a processing part 22 and a storage part 23 configured to store, at least, a device identifier and an authentication token. The device 20 also comprises a communication part 24 enabling wireless communications COMM. The device 20 may comprise further parts or functions, such as at least one sensor 25 (or a connector therefore). It should be appreciated that device 20 may comprise a plurality of sensors 25 or connectors therefore. Examples of sensors include a location sensor, a temperature sensor, a humidity sensor, a light sensor, a pressure sensor, a motion sensor etc.

[0086] The device 20 is configured to harvest power from a power signal PS, for example triggered by the central system 10, to activate at least the processing part 22 and, optionally, the other parts, such as at least one of the storage part 23, communication part 24 and sensor 25. Power supply lines to these parts are indicated by the solid lines in FIG. 4.

[0087] The processing part 22 is configured to process wireless transmissions for signals received from and transmitted to the central system 10 as described with reference to FIG. 2. Signal lines for such action(s) are indicated by the dashed-dotted lines in FIG. 4.

[0088] It should be appreciated that devices 20 may comprise more or fewer parts. Essentially, the device 20 is a battery-less device with limited, if any, energy storage capability (one or more capacitors may be included) wherein the energy is provided through the harvesting of radio waves, light, motion, heat or any other power source that could be suitable. The device 20 is not capable of storing any significant power provided to it in the power signal PS and uses the supplied power almost immediately in order to complete its desired action(s). Advantageously, power signal PS and communication COMM are combined, so that energizing and communication for the passive wireless transmission device 20 are integrated. For example, with reference to FIG. 2, signals received from the central system 10 in steps S5 and / or S9 (as well as from one or more of the acknowledgements not shown in FIG. 2) may contain sufficient energy to energize parts of the passive device 20 to allow processing (e.g. calculations), storage and / or retrieving steps.

[0089] FIG. 5 is a time chart of some alternative or additional steps for wireless transmission between a system 10 and a passive wireless transmission device 20. FIG. 5 focusses on operation in storage 12 of the central system 10 as shown in FIG. 1 and on encryption key management. Again, the skilled person will recognize that the order of steps may be changed without changing the result of the operations.

[0090] In step S20, central system 10 receives a wireless transmission of passive wireless transmission device 20A. The transmission comprises a first device identifier ID1 , an authentication token T1 and data DATA, e.g. sensor data, encrypted under a data encryption key Kd. Encryption key Kd may be pre-installed in the passive wireless transmission device 20A by the operator OP operating the passive wireless transmission devices. The double-pointed arrow of step S20 indicates acknowledgement of receipt of the wireless transmission.

[0091] The transmission of step S20 is authenticated by the central system 10 using the storage 12 containing a table wherein ID1 and T1 are associated with one another in a present part PRES of the table. From the table, the central system 10 can determine an address AD of the operator using ID1 and / or T1 to forward the data to the operator in step S21 .

[0092] In step S22, both the central system 10 and the passive wireless transmission device 20A calculate a new authentication token T2. Wireless transmission device 20A may use the energy from the acknowledgment signal in step S20 for this purpose. In the central system 10, the table in the storage 12 is updated accordingly by associating device identifier ID1 with authentication token T2 from now on in the present part PRES of the table while moving the previous association of ID1 and T1 to a past part PAST of the table.

[0093] It should be noted that the skilled person will recognize that various alternatives are available for operating storage 12. Alternatives may for example be that the present associations and past associations are stored in separate tables, or each device entry in the table is indicated as either ‘present’ or ‘past’. In the latter alternative, the indication of the association of a device identifier and authentication token can be simply changed from ‘present’ to ‘past’ when it no longer contains the present association, and removed from the table at a later stage when sufficient past associations are stored for a device (which may be a single past association).

[0094] In step S23, the central system 10 updates the table in storage 12 again. The update involves that device identifier ID1 is no longer valid for passive wireless communication device 20A. This may be due to a re-assignment of the device identifier ID1 to another passive wireless transmission device, so that device identifiers can be re-used as coordinated from the central system 10. This is reflected in the table in storage 12 for device 20A by updating the device identifier and authentication token to device identifier ID2 and, preferably, authentication token T3 in the present part PRES of the table. It should be noted that, in another embodiment, authentication token T2 may continue to apply in association with device identifier ID2.

[0095] In addition, the central system 10 may determine a new encryption key K2 as will be explained in further detail below. The former association between ID1 and T2 is moved to the past part PAST of the table.

[0096] In step S24, the central system 10 receives a further wireless transmission with updated data DATA from the passive wireless transmission device 20A, using energy from an external energy source. Because the passive wireless transmission device 20A has not been made aware of the change of the association in the storage 12, the wireless transmission in step S24 comprises the past association of device identifier ID1 and token T2. However, since the central system 10 still stores the past association of ID1 and T2 in the PAST part of the table, the central system 10 is enabled to determine that the wireless transmission is an authenticated request to update the association of a new identifier ID2 and, preferably, new authentication token T3 in the device, because the previous device identifier ID1 is no valid for passive wireless transmission device 20A. This transmission is shown in step S25 and is reflected in the PRES part of the table. This association may already have been updated in the table after step S23.

[0097] It is noted that the central system 10 may decide to accept the transmission comprising ID1 and T2, although not stored in the present part PRES of the storage 12. This is shown by the dashed line of S24’ wherein the data DATA is forwarded to the operator using address AD from the PAST part retrieved based on ID1 and T2. This forwarding may be acknowledged by the central system to the device 20 in step S24.

[0098] As can be observed from FIG. 5, step S25, the new device identifier ID2 and new authentication token T3 are transmitted to the passive wireless transmission device 20A encrypted under encryption key K1 associated with the association of ID1 and T3 (and previously also with the past association) to enhance security. It is assumed that the passive wireless transmission device 20A has access to encryption key K1 , for example because this key was pre-installed or previously provided from the central system 10. The transmission from the central system 10 in step S25 also contains a key index KI pointing the passive wireless transmission device 20A to an encryption key K2 that will be used by the central system 10 for future transmissions to the passive device 20A. To that end, passive wireless transmission device 20A may contain a list of encryption keys, wherein entries can be pointed at by the key index KI. Alternatively, the transmission in step S25 may comprise a random number to be input in a key generation algorithm agreed between the central system 10 and the passive device 20A to generate encryption key 22. Otherwise, the transmission in step S25 may contain the encryption key K2 itself encrypted under the encryption key K1 already present in the passive wireless transmission device 20A.

[0099] Step S25 may also include transmission of an acknowledgement signal from the passive wireless transmission device 20A to the central system 10 to acknowledge appropriate receipt of the new device identifier ID2 (and other information, if contained in the transmission). Transmission of the acknowledgement signal may be energized by the receipt of the signal of S25 from the central system 10. Central system 10 is now ensured that passive wireless transmission device 20A has safely received the new device identifier ID2 which improves device identifier re-use management in the system.

[0100] If step S24’ is not executed, the central system 10 receives a wireless transmission in step S26 comprising the updated association of device identifier ID2 and, preferably, authentication token T3. After consultation of storage 12, the central system 10 forwards in step S27 the data encrypted under Kd to the operator using address AD from the table now association with the new association of ID2 and T3.

[0101] Both the central system 10 and the passive wireless transmission device 20A update the authentication token to T4 in step S28. Passive wireless transmission device 20A may use the acknowledgement of step S26 for this purpose. Central system 10 updates the association in the table of the storage 12 as shown.

[0102] The passive wireless communication system 100 provides a robust and energy-efficient mechanism for re-usable device identifier allocation, where the central system 10 provides the reusable identifier and a temporary (one-time) authentication token that cannot be replayed. The token size is such that it reduces or minimizes energy consumption when computing a new token, while preventing an easy brute force attack. At each communication, the token is updated, so the central system 10 always knows which token to expect next from the device currently using the re-usable identifier. If a passive device 20 from which a re-usable ID has been re-used or revoked starts communicating again by using it, the token value would be different than the one that is expected by the network as illustrated with reference to FIG. 5.

[0103] Using past data (i.e., the authentication token associated with a past allocation of a device identifier), the central system 10 can recognize that the received token corresponds to a past allocation of that identifier, so it can directly trigger a re-allocation by providing a new, possibly encrypted, device identifier to that passive device 20 so that it can continue communicating with the central system 10 (if authenticated, without performing the entire (energy-consuming) authentication process).

[0104] Below a three-stage embodiment for a passive wireless communication system will be described followed by an example for implementation with reference to FIGS. 6A-6E enabling device identifier re-use management.

[0105] In a first stage, a newly created passive wireless transmission device 20 is placed in an environment with no energy limitations. After performing a traditional authentication process which can be based on a traditional non-reusable identifier and associated traditional authentication information, the device 20 is provisioned with a reusable identifier, an initial authentication token, and optionally additional secret and / or other information. The provisioned information is sent in a message that is confidentially protected and / or sent over a confidential link. During this stage the passive wireless transmission device 20 and the central system establish a shared secret key in such a way that preferably no two devices will get the same secret key. In particular, a passive wireless transmission device 20 is placed in an environment with sufficient energy, for example a device factory or operator premises. The device 20 is authenticated in the traditional way based on a permanent identifier PID and associated authentication information in the device and the network. Over the protected link the network provides the device with a reusable identifier ID, an authentication token T and, optionally, other information. Over the protected link the device and the network establish a shared secret key. The reusable identifier ID, authentication token T, and optional other information (for example operator key Kd) and shared secret key K are stored securely in the device 20. The authentication token T, and shared secret key K are stored in the central system 10 in association with the provisioned reusable identifier ID. Optionally the permanent identifier PID of the passive wireless transmission device 20 is stored in association with the reusable identifier ID.

[0106] In a second stage, the passive wireless transmission device 20 has obtained a valid reusable identifier ID with which it can communicate with the central system 10. During this stage the device 20 can wirelessly transmit data to the central system 10 using a single message, which contains the reusable identifier ID in combination with a corresponding ‘expected’ authentication token T. The ‘expected’ authentication token is sufficient to verify whether the passive wireless transmission device 20 is authorized to use the reusable identifier ID. After each communication the ‘expected’ authentication token T is changed into a new ‘expected’ authentication token T’ in unpredictable ways based, for example, on secret data and a previous ‘expected’ authentication token T, so that chances are limited device 20 using the same device identifier and token. The newly created ‘expected’ authentication token T’ is stored in preparation for the next communication.

[0107] In particular, when the passive wireless transmission device 20 (with valid reusable identifier ID) is in an environment with limitations on energy use, it may want to send some data to the central system 10 using a single message from device 20. In addition to the data, the message contains the reusable identifier ID and the authentication token T. Based on the received authentication token T (and the reusable identifier ID) the central system 10 verifies the validity of the reusable identifier ID: if the authentication token T in the message corresponds to the authentication token stored in the central system 10 in association with the reusable identifier ID, then the identifier ID is considered valid.

[0108] The data may be encrypted using a shared secret key. To prevent man in the middle attacks that might replace the data field in the message, the encrypted data field may additionally include (part of) the authentication token, re-usable ID or any other shared information element. The central system 10 verifies the authenticity of the packet by decrypting the data field using the secret key associated with the re-usable ID and authentication token T and verifying the shared information element.

[0109] After the transmission of the single message, both the device 20 and the central system 10 calculate a new authentication token (for use in a subsequent message exchange). The calculation of the new authentication token makes use of some or all of the data stored in the passive wireless transmission device 20 and central system 10, such as shared secret key, old authentication token, permanent identifier PID, other information. Authentication tokens T may have the following properties. Authentication tokens used by distinct devices 20 in message sent to the central system 10 should preferably be distinct. Furthermore, it should preferably be avoided that a next authentication token T can be calculated from a past authentication token without access to secret information from the device 20 calculating the next authentication token.

[0110] One example for the algorithm for calculating a new authentication token is as follows. During the first stage, i.e. when the device 20 is in a secure, energy-rich environment, the central system 10 establishes a secret communication key for the passive wireless transmission device 20 and exchanges secret information elements to be used in subsequent communications such as (Pseudo)- Random Numbers RN or the device's permanent PID. After each communication, the new authentication token T i+i can be calculated by both the central system 10 and the device 20 based on the previous authentication token Ti and one or more shared secret information element as the following:

[0111] Ti+i= f (Ti , Secret Key , [RN] , [PID],...) where the function f(x) is a mathematical operation that can be performed by the device 20, and that is robust enough so that the set To...Ti cannot be used to infer Ti+i.... TN without knowledge of the secret information, where N is the maximum number of times where a new token is calculated based on a previous one, before performing a token refresh.

[0112] To implement the function F, multiple lightweight cryptography algorithms for passive devices 20 can be used, such as stream or block cipher algorithms where basic operations such as ADD, XOR, or SHIFT are combined, including Substitution-Permutation Network (SPN), Feistel Network (FN), General Feistel Network (GFN), Add-Rotate-XOR (ARX), Non Linear-Feedback Shift Register (NLFSR). Other lightweight algorithms such as Elliptic Curve Cryptography (ECC) can also be employed. More detailed explanations are provided by Lightweight Cryptography Algorithms for Resource-Constrained loT Devices: A Review, Comparison and Research Opportunities," in IEEE Access, vol. 9, pp. 28177-28193, 2021 from V.A. Thakar et al and Analysis of Lightweight Cryptography Algorithms for loT Communication. In: Sharma, H., Saraswat, M., Yadav, A., Kim, J.H., Bansal, J.C. (eds) Congress on Intelligent Systems CIS 2020.

[0113] Another example algorithm for deriving a new authentication token based on a previous authentication token and a secret key is the Key Derivation Function (KDF) defined in Annex A in 3GPP TS 33.501 , V18.1.0, and Annex B in 3GPP T.S. 33.220, V17.4.0C. The KDF mechanisms can be used to secure communications with passive wireless transmission devices 20 as detailed in clause 6.16.2 of 3GPP TS 33.501 , V18.1 .0.

[0114] Given the limited computational capabilities of the passive wireless transmission device 20, if energy limitations permit, the central system may send a message to the device 20 containing a fresh authentication token T. The sent token T shall be confidentiality protected (encrypted) by using the shared secret key of the device 20. The token refresh may be performed if a (potential) collision of authentication tokens T of distinct devices 20 is expected or detected. The message sent to the device 20 may also be triggered after a preconfigured number of received messages, based on the perceived risk of a potential prediction of authentication tokens. In a third stage, a passive wireless transmission device 20 no longer has a valid identifier ID, for example, because the central system 10 has re-used the device identifier. If the device 20 attempts to send a message to the central system with this invalid identifier ID and an authentication token T, the central system 10 recognizes that the device 20 is using an invalid re-usable device identifier ID, because the received authentication token T is not the expected authentication token T for this reusable identifier ID. The central system 10 may then respond with a single message containing a new re-usable identifier ID and optionally a new initial authentication token T, and optionally a new secret key. The single message may be encrypted using the (old) secret key associated to the device, so that message sent to the device 20 is confidentially protected.

[0115] In particular, the central system 10 may decide to re-assign or revoke a re-usable identifier ID of a certain passive wireless transmission device 20 and re-assign the device identifier ID to another device 20. The passive device 20 may or may not be informed about the revocation of the identifier ID. The revocation of the identifier may be triggered by a long period of inactivity of the device 20. As a result of reassignment of the re-usable identifier ID, a new authentication token T will be associated with the re-usable identifier ID. The new authentication token T will be distinct from any authentication token T that would be expected in the next communications from devices 20 from which the re-usable identifier ID is invalid.

[0116] When the device 20 (with an invalid reusable identifier) is in an environment with limitations on energy use, it still may want to send some data to the central system using a single message from device 20 to the central system 10. The passive device 20 would use the invalid re-usable identifier and the calculated next authentication token T. The central system 10 will recognize the authentication token T as belonging to a device 20 with an invalid device identifier ID which previously had been assigned the re-usable identifier ID. The central system 10 may now decide to provide the device 20 having only the invalid reusable identifier with a new re-usable identifier ID and a new authentication token T by sending a single message to the device 20. The message sent to the device 20 may be encrypted using the secret key of the device 20.

[0117] In order to be able to recognize the device 20 and to be able to use the appropriate secret key, the network may store, for each reusable device identifier ID, for one, some or all of the past associations of this identifier ID, the corresponding authentication token T and the associated secret key. The central system 10 may choose to discard information related to past associations if these exceed a certain storage duration and / or for other reasons (e.g. storage space considerations).

[0118] The central system 10 may or may not decide to accept the data sent by the device 20 having the invalid re-usable identifier ID. The central system 10 may decide not to reassign a reusable identifier ID to the device 20. If it does not want to reassign a re-usable identifier ID, the central system 10 may send a message to the device indicating a permanent revocation of the identifier ID for a certain number of times, before removing all data related to the device 20, in which case the device is un-authorized to transmit any messages for the central system 10.

[0119] An example for implementation with reference to FIGS. 6A-6E enabling device identifier re-use management will now be described. A general overview of information stored in the central system 10, for example in storage 12 as shown in FIG. 1 , is given in the below table, wherein the column information indicates any further information, such as data from a sensor, a permanent identifier PID, and / or other shared secret information to compute a next authentication token.

[0120] A general view of the data stored in a particular passive wireless transmission device 20, in particular in storage part 23 as shown in FIG. 4, is given in the below table.

[0121] FIG. 6A shows an exemplary process for initial assignment of a re-usable device identifier ID in a first stage for a passive wireless transmission device 20. The device 20 is assumed to be in an environment without energy limitations for the device. After initial assignment of a reusable ID, the following record may be added to storage 12 in the central system (assuming re-usable ID = 123, authentication token = ABC, Key = uvw, and Information = Inf. 1).

[0122] The corresponding data stored in the device 20 may be as follows:

[0123] In the second stage, a passive wireless transmission device 20 that wants to send data to the central systemW in an environment with energy limitations may perform the message flow of FIG. 6B

[0124] After having received energy from an external power source, the device 20 sends the data encrypted using its secret key along with its re-usable ID and the authentication token. The system 10 uses the re-usable ID and authentication token combination to identify the device 20 by comparing these with the entries in a database (for example storage 12) and retrieving the secret key to decrypt the encrypted data in the message and confirm the packet’s authenticity by verifying the de-crypted shared information element. The latter may be used to avoid man-in-the-middle attack, since the device identifier and authentication token are sent unencrypted so that any intercepting entity may take the device identifier and authentication token and replace the data field with any information. The additional information may be added in the encrypted data to make sure that the transmission is from an authentic passive wireless transmission device. After having processed the data the central system 10 sends a command to the device 20 to update the authentication token, which triggers the device 20 and the central system 10 to calculate a next expected authentication token. The next authentication token calculation is performed based on a calculation that includes the previous authentication token, the secret key, and optionally additional parameters.

[0125] The central system 10 also may record the number of times the re-usable ID has been used with a non-fresh authentication token (i.e. a message from this device has been received) and the date and time this happened. This counter may be used to refresh the authentication token after a preconfigured number of communications to increase robustness against brute force attacks based on recorded past tokens.

[0126] The central system 10 may keep the past authentication token in its database in case the device 20 does not receive the update command, in which case the central system 10 has updated its token to a new one, while the device did not. If the device 20 sends data again with the older authentication token, the central system 10 initiates the authentication token refresh procedure as discussed with reference to FIG. 6C below.

[0127] At this stage, the database of the central system 10 may be as follows, assuming the new authentication token = DEF.

[0128] The central systemI O may keep the second record rec:2 in its database until the device 20 sends data using the updated authentication token, in which case the authentication token is updated to a new one. A new entry is added to the table with the next authentication to be expected that is active, and the status of the first record changes from active to updated to rec:3, since the authentication token has already been used for a communication from the device.

[0129] Correspondingly, after one communication the information stored in the device 20 is as follows:

[0130] The central systemI O may initiate a refresh of the authentication token as shown in FIG. 6C. In contrast to the authentication token update procedure, the refresh operation may generate a completely new authentication token that is not computationally related to previous ones.

[0131] After a refresh of an authentication token (assuming this is GHI), the database in the central system may be as follows (assuming only a single SendData message has been received)

[0132] The database will temporarily contain two records for the same passive wireless transmission device 20, since it is not yet confirmed that the token refresh message is received and processed correctly. Since the device 20 may not have had enough energy to process the refresh message, its reception and processing in general is uncertain. If, later, the central system 10 has received a message with re-usable ID= 123 and authentication token = GHI, then the database will be updated as follows (with newly calculated next authentication token = JKL).

[0133] Otherwise, if the device 20 sends the older token again, a new refresh cycle may be triggered.

[0134] In the third stage, the central system 10 may initiate a revocation of the re-usable ID as shown in FIG. 6D.

[0135] Re-usable ID revocation may be initiated after a long period of inactivity of the passive wireless transmission device 20. The central systemI O may then revokes the re-usable ID and can re-assign the device identifier to other passive devices 20.

[0136] If the passive device 20 returns by sending a message using the re-usable ID, the central system 10 may either trigger re-usable ID re-assignment as described with reference to FIG. 6E or send another revocation notification if the device 20 is not allowed to communicate with the network anymore. After revocation the central system 10 may remove the record for the device 20 from its database, but it may optionally store it for a certain period to identify the device in case it becomes active again. If the revocation is final, the central system may also record the number of times a revocation message has been sent to the device 20. In this case the database may be as follows:

[0137] The central system 10 may keep a counter of the number of times the revocation message has been sent to the device 20 and send the message a pre-configured number of times to the device from which the ID has been revoked in response to receiving data from the device 20 if the revocation message has not been properly received or processed by the device. The passive wireless communication device 20 may be configured to stop sending wireless transmissions after one or more receipt of a revocation message from the central system 10.

[0138] The central system 10 may assign a new device identifier to a passive wireless transmission device 20 as shown in FIG. 6E. Re-usable ID assignment may be triggered on the return of a device 20 whose device identifier has been re-assigned to another device 20. In that case, the central system 10 recognizes the device 20 based on the combination of the re-usable ID and the authentication token that have been stored in the database. The assignment of the new re-usable ID may also be triggered by the network for any other reason. Note that the assignment may include a refresh of the authentication token.

[0139] After an assignment of a new re-usable ID, the record from the past re-usable ID and authentication token may be removed from the database.

[0140] FIG. 7 depicts a block diagram illustrating an exemplary processing system according to a disclosed embodiment, e.g. a (part of a) central system 10 as described above for use in a passive wireless transmission system 100. As shown in FIG. 7, the processing system 70 may include at least one processor 71 coupled to memory elements 72 through a system bus 73. As such, the processing system may store program code within memory elements 72. Further, the processor 71 may execute the program code accessed from the memory elements 72 via a system bus 73. In one aspect, the processing system may be implemented as a computer system that is suitable for storing and / or executing program code. It should be appreciated, however, that the processing system 70 may be implemented in the form of any system including a processor and a memory that is capable of performing the functions described within this specification.

[0141] The memory elements 72 may include one or more physical memory devices such as, for example, local memory 74 and one or more bulk storage devices 75. The local memory may refer to random access memory or other non-persistent memory device(s) generally used during actual execution of the program code. A bulk storage device may be implemented as a hard drive or other persistent data storage device. The processing system 70 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the number of times program code must be retrieved from the bulk storage device 75 during execution.

[0142] Input / output (I / O) devices depicted as an input device 76 and an output device 77 optionally can be coupled to the processing system. Examples of input devices may include, but are not limited to, a space access keyboard, a pointing device such as a mouse, or the like. Examples of output devices may include, but are not limited to, a monitor or a display, speakers, or the like. Input and / or output devices may be coupled to the processing system either directly or through intervening I / O controllers.

[0143] In an embodiment, the input and the output devices may be implemented as a combined input / output device (illustrated in FIG. 7 with a dashed line surrounding the input device 76 and the output device 77). An example of such a combined device is a touch sensitive display, also sometimes referred to as a “touch screen display” or simply “touch screen” that may be provided with the UE. In such an embodiment, input to the device may be provided by a movement of a physical object, such as e.g. a stylus or a finger of a person, on or near the touch screen display.

[0144] A network adapter 78 may also be coupled to the processing system to enable it to become coupled to other systems, computer systems, remote network devices, and / or remote storage devices through intervening private or public networks. The network adapter may comprise a data receiver for receiving data that is transmitted by said systems, devices and / or networks to the processing system 70, and a data transmitter for transmitting data from the processing system 70 to said systems, devices and / or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapter that may be used with the processing system 70.

[0145] As pictured in FIG. 7, the memory elements 72 may store an application 79. In various embodiments, the application 79 may be stored in the local memory 74, the one or more bulk storage devices 75, or apart from the local memory and the bulk storage devices. It should be appreciated that the processing system 70 may further execute an operating system (not shown in FIG. 7) that can facilitate execution of the application 79. The application 79, being implemented in the form of executable program code, can be executed by the processing system 70, e.g., by the processor 71 . Responsive to executing the application, the processing system 70 may be configured to perform one or more operations or method steps described herein.

[0146] In one aspect of the present invention, one or more components of the base station selection support system and / or user device for use with such a base station selection support system, as disclosed herein may represent processing system 70 as described herein.

[0147] Various embodiments of the invention may be implemented as a program product for use with a computer system, where the program(s) of the program product define functions of the embodiments (including the methods described herein). In one embodiment, the program(s) can be contained on a variety of non-transitory computer-readable storage media, where, as used herein, the expression “non-transitory computer readable storage media” comprises all computer-readable media, with the sole exception being a transitory, propagating signal. In another embodiment, the program(s) can be contained on a variety of transitory computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media (e.g., read-only memory devices within a computer such as CD-ROM disks readable by a CD-ROM drive, ROM chips or any type of solid-state non-volatile semiconductor memory) on which information is permanently stored; and (ii) writable storage media (e.g., flash memory, floppy disks within a diskette drive or hard-disk drive or any type of solid-state random-access semiconductor memory) on which alterable information is stored. The computer program may be run on the processor 71 described herein.

[0148] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0149] The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of embodiments of the present invention has been presented for purposes of illustration but is not intended to be exhaustive or limited to the implementations in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the claims. The embodiments were chosen and described in order to best explain the principles and some practical applications of the present invention, and to enable others of ordinary skill in the art to understand the present invention for various embodiments with various modifications as are suited to the particular use contemplated.

Claims

CLAIMS1 . A system configured for communication with a plurality of ambient Internet of Things, loT, devices, wherein the system is configured to receive a first wireless transmission of an ambient loT device, the first wireless transmission comprising a first device identifier and a first authentication token; determine a second authentication token for the ambient loT device; invalidate the first device identifier for the ambient loT device; receive a second wireless transmission of the ambient loT device; determine a second device identifier for the ambient loT device; store an association of the second authentication token with the second device identifier as a present association for the ambient loT device; store an association of the second authentication token with the first identifier as a past association for the ambient loT device; authenticate the second wireless transmission if the second wireless transmission contains the second device identifier and the second authentication token in accordance with the present association, authenticate the second wireless transmission if the second wireless transmission contains the first device identifier and the second authentication token in accordance with the past association.

2. The system according to claim 1 , wherein the system is further configured to transmit the second device identifier to the ambient loT device after determining the second device identifier.

3. The system according to claim 1 or 2, wherein the system is further configured to transmit the second authentication token to the ambient loT device.

4. The system according to one or more of the preceding claims, wherein the system is further configured to assign the first device identifier to a second ambient loT device and store an association of a further authentication token with the first device identifier as a present association for the second ambient loT device; receive a third wireless transmission from an ambient loT device; authenticate the third wireless transmission as a transmission from the second ambient loT device if the second wireless transmission contains the first device identifier and the further authentication token in accordance with the present association for the second ambient loT device.

5. The system according to one or more of the preceding claims, wherein the system is further configured to at least one of: obtain an applicable encryption key for a device identifier and an associated authentication token; encrypt at least a part of the second device identifier and, optionally, the second authentication token using an applicable encryption key, for example, upon transmission to the ambient loT device; obtain an updated encryption key for a device identifier and associated authentication token; and receive a wireless transmission of an ambient loT device having a data part encrypted using an encryption key and forward encrypted data in the wireless transmission to a data collecting entity.

6. The system according to one or more of the preceding claims, wherein the network system is further configured to transmit to the ambient loT device at least one of a random number enabling the ambient loT device to provide or update an applicable encryption key; a key index enabling the ambient loT device to provide or update an applicable encryption key; and an updated applicable encryption key encrypted using a previously provided encryption key.

7. The system according to one or more of the preceding claims, wherein the system is configured to transmit an identifier revoke message to announce revocation of the first identifier to the ambient loT device.

8. The system according to according to one or more of the preceding claims, wherein the system is configured to trigger a wireless transmission configured to energize the ambient loT device, wherein the wireless transmission, optionally comprises at least one of the second device identifier as claimed in claim 2, the second authentication token as claimed in claim 3 and the identifier revoke message as claimed in claim 6.

9. An ambient Internet of Things, loT, device configured to be used with a system according to one or more of the preceding claims, wherein the ambient loT device is configured to perform a first wireless transmission comprising at least a first device identifier and a first authentication token; generate a second authentication token or receive a second authentication token from the system, perform a second wireless transmission comprising the first device identifier and the second authentication token;receive a second device identifier from the system in response to the second wireless transmission; and perform a third wireless transmission comprising at least the second device identifier and the second authentication token or a third authentication token.

10. The ambient loT device according to claim 9, wherein the ambient loT device is configured to generate the third authentication token or receive the third authentication token with the second device identifier.11 . The ambient loT device according to claim 9 or 10, wherein the device further contains at least one encryption key and wherein the ambient loT device is configured to receive the second device identifier and, optionally the second or third authentication token, at least in part in encrypted form; and decrypt at least the part of the second device identifier and, optionally, the second or third authentication token using the encryption key.

12. The ambient loT device according to one or more of the preceding claims 9-11 , wherein the ambient loT device is configured to obtain an applicable encryption key by receiving a random number from the system and input the random number in a key generation algorithm to derive the encryption key; receiving a key index from the system to select an applicable encryption key from a set of encryption keys stored in the ambient loT device and retrievable via the key index; or decrypting an applicable encryption key received from the system using a previously stored encryption key.

13. The ambient loT device according to one or more of the preceding claims 9-12, wherein the ambient loT device is further configured to transmit data, such as sensor data, in at least one of the first, second and third wireless transmission, and wherein, optionally, the device further contains an applicable encryption key to encrypt the data.

14. The ambient loT device according to one or more of the preceding claims 9-13, wherein the ambient loT device is configured to receive one or more identifier revoke messages and wherein the device is configured to stop performing wireless transmissions for the system in response to receiving the one or more identifier revoke messages.

15. The ambient loT device according to one or more of the preceding claims 9-14, wherein the ambient loT device comprises an energy harvesting part, wherein, optionally, the energy harvesting part is configured to harvest energy from a wireless transmission from the system to perform wireless transmissions to the network.

16. The ambient loT device according to one or more of the preceding claims 9-15, wherein the ambient loT device is configured to at least one of transmit an acknowledgement signal to the system to acknowledge receipt of the second device identifier, and receive an acknowledgement signal from the system to acknowledge receipt of the first and / or second wireless transmission, wherein the ambient loT device, optionally, is configured to use the received acknowledgement signal to at least one of trigger calculation of an authentication token; refrain from re-sending data; and energize the ambient loT device.