Authentication in a personal area network

The implementation of a local management node using extensible authentication protocol messages addresses the challenge of scalable authentication and authorization in Personal IoT Networks, enabling secure communication across multiple domains by synchronizing credential databases.

GB2625993BActive Publication Date: 2025-07-02NOKIA TECHNOLOGIES OY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
GB2023000043
Authority / Receiving Office
GB · GB
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-01-04
Publication Date
2025-07-02
Estimated Expiration
2043-01-04

AI Technical Summary

Technical Problem

Existing Personal Internet of Things (IoT) Network (PIN) architectures face challenges in scalable local authentication and authorization, particularly when PINEs move between different PAN domains, as current methods often require additional configuration and may not support seamless network joining.

Method used

Implementing a local management node (PEMC) within each Personal Area Network (PAN) domain for authentication and authorization using extensible authentication protocol (EAP) messages, with credential information stored in a local database and synchronized with a central database via a 5G connection, allowing for scalable deployments across multiple PAN domains.

Benefits of technology

Enables seamless authentication and authorization of PINEs across multiple PAN domains without additional configuration, ensuring secure and efficient communication within PIN networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_0000
    Figure 00000001_0000
  • Figure 00000002_0000
    Figure 00000002_0000
  • Figure 00000003_0000
    Figure 00000003_0000
Patent Text Reader

Abstract

There is provided an apparatus comprising means for communicating extensible authentication protocol (EAP) messages in a personal area network (PAN) 502 to obtain information for authenticating a netw
Need to check novelty before this filing date? Find Prior Art

Description

FIELD The present application relates to a method, apparatus, system and computer program and in particular but not exclusively to personal area networks BACKGROUND A communication system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications path. A communication system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet. The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. One example of a communications system is UTRAN (3G radio). Other examples of communication systems are the long-term evolution (LTE) of the Universal Mobile Telecommunications System (UMTS) radio-access technology and so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP). The Internet of Things (loT) describes physical objects with sensors, processing ability, software and other technologies that connect and exchange data with other devices and systems over the Internet or other communications network. 3GPP is currently studying architecture enhancements for Personal loT Network (PIN). SUMMARY According to some aspects, there is provided the subject-matter of the independent claims. Some examples are defined in the dependent claims. According to a first aspect there is provided an apparatus comprising: means for communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and means for authenticating the network element in the personal area network, using the obtained information. According to a second aspect there is provided an apparatus comprising: means for communicating extensible authentication protocol messages in a personal area network, for authentication and authorization of the apparatus in the personal area network. According to a third aspect there is provided an apparatus comprising: means for communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and means for establishing secure communication with the network element in the personal area network. According to a fourth aspect there is provided a method comprising: communicating, by an apparatus, extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and authenticating the network element in the personal area network, using the obtained information. According to a fifth aspect there is provided a method comprising: communicating, by an apparatus, extensible authentication protocol messages in a personal area network, for authentication and authorization of an apparatus in the personal area network. According to a sixth aspect there is provided a method comprising: communicating, by an apparatus, extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and means for establishing secure communication with the network element in the personal area network. According to a seventh aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and authenticating the network element in the personal area network, using the obtained information. According to an eighth aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network, for authentication and authorization of the apparatus in the personal area network. According to a ninth aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and establishing secure communication with the network element in the personal area network. According to a tenth aspect there is provided an apparatus comprising: means for communicating credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and means for storing the credential information in a credentials database at the apparatus. According to an eleventh aspect there is provided a method comprising: communicating, by an apparatus, credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and storing the credential information in a credentials database at the apparatus. According to a twelfth aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: communicating credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and storing the credential information in a credentials database at the apparatus. DESCRIPTION OF FIGURES Some examples will now be described, by way of example only, with reference to the accompanying Figures in which: Figure 1 shows a representation of a Personal loT Network architecture; Figure 2 schematically shows the architecture of an apparatus according to some examples; Figure 3 is a signalling diagram schematically showing a registration process; Figure 4 is a signalling diagram schematically showing a provisioning and revocation process; Figure 5 is a signalling diagram schematically showing an authentication and authorization method; Figure 6 shows a representation of a user equipment according to some examples; Figure 7 shows a representation of a control apparatus according to some examples; Figure 8 is a flow chart of a method according to an example; Figure 9 is a flow chart of a method according to an example; Figure 10 is a flow chart of a method according to an example; Figure 11 is a flow chart of a method according to an example; Figure 12 shows a schematic representation of non-volatile memory media. DETAILED DESCRIPTION 3GPP is currently studying architecture enhancements for Personal loT Network (PIN). Personal loT Networks (PINs) provide local connectivity between UEs and non 3GPP devices. In examples, a PIN consists of PIN Elements (PINEs) that communicate using PIN Direct Connection or direct network connection and is managed locally, for example using a PIN Element with Management Capability (PEMC). Examples of PINs include networks of wearables and smart home I smart office equipment. Via a PIN Element with Gateway Capability (PEGC), PIN Elements have access to wider network services (such as 5G network services) and can communicate with PIN Elements that are not within range to use PIN Direct Connection. In examples, a PIN includes at least one PIN Element with Gateway Capability (PEGC) and at least one PIN Element with Management Capability (PEMC). In some examples, a PEMC is a PINE that provides a means for an authorised administrator to configure and manage a PIN.. Atypical use case for a PIN is home and building automation. The deployment of the PIN does not necessarily require the presence of a person. In some examples the term "Personal" Network may be considered a short-range communication network (as compared to a long range cellular network) between a limited number of devices, which are owned by a single entity (e.g. a person) and which are operating in a joint context, i.e., home or building automation or factory automation. The results of an SA2 architecture study are documented in TR 23.700-88. The results of a corresponding study on security are documented in TR 33.882. A possible PIN architecture is shown generally at 100 in Figure 1. The PIN architecture comprises a Personal Area Network (PAN) 102, a Network 104 (for example a 5G network), and a Data Network 106. Within the PAN 102, one or more PIN devices 108, 110 are using a PAN network technology to communicate with each other (for example on interfaces IF 1 and IF 2). In some examples, the PIN devices 108, 110 may be referred to or considered as PINE (Personal loT Network Element). In examples, PINE(s) are responsible for the actual PIN application (e.g., a home automaton application) and may not have a further responsibility within the PIN. A PIN element with Gateway Connectivity (PEGC) 112 is responsible for providing connectivity between the PAN 102 and the Data Network 106. For example, PEGC 112 may communicate with data network 106 via a user plane function (UPF) 114 in 5G network 104. In some examples, the PEGC may be considered an authenticator or an authentication apparatus. A PINE Element with Management Capabilities (PEMC) 116 is responsible for the management of the PAN 102. The PEMC 116 can use the 5G system 104 to connect to a PIN Application Function 118 hosted in the Data Network 106 (for example over an interface IF 3). In some examples the PEMC is in the form of a server or server apparatus. The Data Network 106 contains a server part of a PIN. The PIN Application, for instance a home automation application, provides the application layer service to the PINEs 108, 110. PINEs 108, 110 connect to the PIN Application 120 via the PEGC 112 (for example over interface IF 4). In some examples, the PIN AF 118 is responsible for the central management aspects of the PIN. In some examples, PEMC 116 and PEGC 112 may be in the form of 5G UEs, and can connect to the 5G network 104, and via the UPF 114 establish a user plane connection to the servers in the Data Network 106. In some examples the PIN AF 118 can use the NEF 122 of the 5GS 104 to customize the connectivity provided by the 5G system according to the needs of the PIN, for instance, by configuring the quality of service (QoS) between a PINE 108, 110 and a PIN application 120. In some examples a PIN might consist not only of a single PAN domain 102, but of several PAN domains. In such a case each PAN domain contains a PEMC and one or several PEGCs. According to existing conclusions in TR 23.700-88 a PINE 108, 110 is allowed to enter a PIN or PAN (e.g., to use the PEGC 112 to communicate with other PINEs or to use the PEGC 112 to connect to an application server in the data network) only after successful authorization by the PEMC 116. As will be explained in more detail below, the present disclosure aims to address issues surrounding authentication and authorization of a PINE. Some previously proposed ways of dealing with PINE authentication and authorization use a central authorization server. However, some implementers prefer local authentication and authorization. However, local authentication approaches may only offer limited scalability, for example if a PINE is moving from one PAN domain to another PAN domain the PAN might not be able to join the network without additional configuration on the PINE and / or the PEMC. The present disclosure aims to address or at least mitigate some of these issues identified with present approaches. Therefore, according to the present disclosure the PIN architecture and procedures currently defined by 3GPP are enhanced to perform local authentication and authorization by a local management node 116 (e.g. PEMC), which is part of the personal area network 102. The PEMC 116 uses credentials from a local database for execution of the authentication and authorization. According to some examples the local database of a PEMC 116 is updated by a central database locate in a PIN AF 118 through a synchronization mechanism. According to some examples, the PEMC 116 is in the form of a UE with 5G connectivity capability, and the PEMC can therefore connect to the PIN AF 118 using a 5G connection. In this way scalable deployments consisting of several Personal Area Network domains, each represented by a PEMC 116, can be supported. A system or apparatus 200 according to the present disclosure is schematically shown in Figure 2. One or more PAN domains 202, 222 are connected to a central PIN AF 218. Each PAN domain 202, 222 is represented by at least one PEMC, shown at 216 and 224 respectively. Furthermore, each PAN domain 202, 222 contains one or several PEGCs. For example PAN 202 comprises PEGCs 212 and 213, and PAN 222 comprises PEGC 226. Each PAN comprises one or more PINEs. In the example of Figure 2, PAN 202 comprises PINEs 208 and 210 which are in communication with PEGC 212, and PINEs 211 and 215 which are in communication with PEGC 213. PAN 222 comprises PINEs 228 and 230 which are in communication with PEGC 226. In some examples, an association between a PINE and PEGC is not fixed. For example a PINE, which is able to join the PIN via a PEGC, may also use a different PEGC to connect to the PINE, for instance if the PINE is moving from the coverage area of one PAN domain to the coverage area of another PAN domain. In some examples, a PEGC and PEMC are implemented as UEs. For example, PEGC and PEMC may be implemented as 5G cellular UEs. Therefore, in examples the communication between a PIN AF and a PEMC can be performed using the 5G user plane. In one example, a first UE acts as PEGC and a second UE acts as PEMC. In one example, only the PEGC is implemented as a UE. In such a case, communication between the PIN AF and the PEMC may use connectivity provided by the PEGC. For example, the PEGC might establish IP connectivity between the PEGC and the PIN AF using the 5G user plane, and can act as a router between the PIN AF and the PEMC, which is connected to the PEGC via a PAN interface. In one example, the PEGC and the PEMC might be deployed on the same device (e.g. a single UE may act as both PEGC and PEMC). In some examples, communication between PEMC and PEGC occurs via a network technology specific to the PAN. Likewise, communication between PINE and PEGC occurs as part of PAN. Although not specifically limited thereto, examples of relevant PAN technologies include Wi-Fi® or Thread (https: / / www.threadgroup.orQ / What--iS--Thr6ad}. In some examples, a feature of a PAN technology that is chosen includes the ability to transport extensible authentication protocol (EAP) messages. In some examples, before a PINE is able to communicate as part of the personal area network, the PINE is authenticated and authorized. In examples, the authentication and authorization are executed using the EAP protocol. In such examples the PINE is acting as EAP Client, the PEGC as EAP Authenticator and the PEMC as EAP Server. According to examples, each PEMC stores a local authorization database. According to examples, the database contains information (which may be referred to as credentials) used by the PEMC to authenticate and authorize a PINE as part of the execution of the EAP Protocol. Depending on the authentication and authorization method used (for example EAP method) the credentials may differ. For instance, in case of an EAP method using preshared keys, the information may consist of a PINE identifier and the shared key. Where a shared key is used, this can be shared between a PINE acting as an EAP client and a PEMC acting as EAP server. The PEMC receives the key from the PIN AF, and therefore the key is shared between PIN, PEMC and PIN AF. If on the other hand a method using asymmetric cryptography is used, the credentials may include the PINE identifier and a root certificate which can be used to authenticate a certificate from the PINE. In some examples, the same root certificate may be used for several PINEs. In some examples the PINE holds a private key which is not provisioned to or visible on the PEMC or PIN AF. In some examples the PIN AF 218 contains an authorization data base This may be considered a centralized authorization database. According to some examples the centralized authorization database contains copies of the local databases of the PEMCs. Depending on a chosen policy, the PIN AF 218 might hold a single database for all PEMCs 216, 224 or individual data bases for each PEMC 216, 224. According to some examples, the PIN AF 218 does not use the credentials in the authorization database to execute own authorization decisions as part of the execution of EAP protocol. That is, in some examples the PIN AF does not act as an EAP Server, but uses the credentials in its own database to update and synchronize the local databases in various PEMCs. In some examples, the PINAF 218 stores a Registration Database. According to some examples, the Registration Database (RDB) contains a list of all PEMCs 216,224 registered to the PIN AF 218. According to some examples the apparatus 200 uses the following main concepts: (a) PEMC Registration; (b) PINE Provisioning; and (c) PINE Authentication and Authorization. These are discussed in-turn below. Although each of these concepts is discussed in-turn for ease of understanding, it will be understood that elements or features from each may be combined as part of an overall concept. (a) PEMC Registration An example of PEMC Registration is shown with respect to the signalling diagram of Figure 3 which schematically shows communication between a first PEMC 316 which is located in first PAN, a second PEMC 324 which is located in a second, different PAN, and a PIN AF 318. Registration starts with PEMC 316 sending a registration request to the PIN AF 318, as shown at S301. If or when the PIN AF 318 accepts the registration, the PIN AF 318 adds the PEMC 316 to its RDB as shown at S302. The PIN AF 318 then confirms registration to the registering PEMC 316 in a registration response as shown at S303. In some examples the PEMC 316 uses a UE identity, like SUPI or GPSI, to identity itself to the PIN AF 318. In some examples the 3GPP Authentication and Key Management procedures (AKMA) are used by the PEMC 316 and PIN AF 318 to mutually authenticate each other. After registration, the PIN AF 318 synchronizes its own Credential Database (CDB) to the PEMC 316, as shown at S304. As a result of the synchronization, the PEMC 316 updates its own CDB, as shown at S305. Registration of second PEMC 324 happens in an analogous way to first PEMC 316. That is S306 to S310 for PEMC 324 correspond to S301 to S305 for PEMC 316, and for conciseness are not described in detail. In some examples registration of PEMCs 316 and 324 happens independently from each other. That is, registration of PEMC 324 might happen before registration of PEMC 316, or vice versa. Registration of PEMC 324 and PEMC 316 may occur partially or fully in parallel, in other examples. Furthermore, other events like PINE provisioning might happen in parallel or in between registrations of PEMCs 316 and 324. In some examples PEMC CDB Synchronization (e.g. S304 and S305) happens directly after PEMC registration (e.g. after S303). However, it will be understood that PEMC CDB Synchronization might also be triggered by the PEMC when a PEMC becomes disconnected from the PIN AF 318 and retrieves connectivity again. Furthermore, CDB synchronization might also happen periodically. For example, CDB synchronization may occur depending on time, and independent from a specific trigger. (b) PINE Provisioning and Revocation: An example of PINE Provisioning is shown with respect to the signalling diagram of Figure 4, which schematically shows communication between a first PEMC 416, a second PEMC 424, a PIN AF 418 and a PIN owner 430. In some examples PINE provisioning can take place in a Central fashion, as shown in upper panel 432 in Figure 4. Alternatively, PINE provisioning can take place in a Local fashion, as shown in the lower panel 434 of Figure 4. In both example cases the process is triggered by a PIN Owner 430. The PIN Owner 430 can be a physical entity or a person. For example, the PIN Owner 430 could be a person operating a home automation network, who uses the apparatus (e.g. apparatus 200) to configure whether a PINE should be allowed to join the PIN network. S401C: In this case the PIN Owner 430 sends a PINE Provisioning request to the PIN AF 418. In examples, the provisioning request contains credential information, which can be used later on by a PEMC to authenticate and authorize a PINE. Depending on the EAP method used during PINE authentication, the credential information may differ. For instance, if an EAP method utilizing pre-shared keys is used, the credential information may include the identity of the PINE and the shared secret. If a certificate-based EAP method is used, such as EAP-TLS, the credential information may include the identity of the PINE and a root certificate, which information can be used by a PEMC to verify a certificate presented by a PINE. S402C: The PIN AF 418 stores the received credential information in its CDB database. The PIN AF 418 performs a CDB update accordingly. S403C: The PIN AF 418 retrieves information about all PEMCs, which need to be updated, from the RDB. For example, PIN AF 418 may retrieve information about PEMCs 416 and 424. S404C: CDB synchronization towards PEMC 416 takes place. S405C: As a result of the synchronization at S404C, the PEMC 416 updates its local CDB database. S404C and S405C are executed for all PEMCs retrieved from RDB in S403C. For example, S406C and S407C are analogous to S404C and S405C, but conducted for PEMC 424. A procedure for Local PINE provisioning will now be explained with respect to S401L to S407L. S401L: In case of local provisioning, the PIN Owner 430 uses a local PEMC to perform the provisioning process. For example, where PEMC 416 is local, then PEMC 416 may be used. S402L: The PEMC 416 updates its own CDB with the received credential information. S403L: The PEMC 416 synchronizes its own CDB with the CDB of the PIN AF 418. In this way the PIN AF 418 learns about or is informed of the provisioning of the new PINE. S404L. The PIN AF 418 updates its own CDB with the information received from the PEMC 416. S405L: The PIN AF 418 retrieves information about all PEMCs, which need to be updated, from the RDB. S406L The CDB synchronization towards another PEMC which needs to be updated (identified during S405L) takes place. For example, PIN AF 418 may determine that PEMC 416 also needs to be updated. S407L: As a result of the synchronization, the PEMC 424 updates its local CDB. S406L and S407L are performed for all PEMCs retrieved from RDB in S405L. Revocation: In examples, the two provisioning methods (central or local) are not limited to provisioning a new PINE to the PIN. For example, these methods can also be used to revoke authentication and authorization of a PINE. For example, the PIN Owner 430 may provide the identity of the PINE which shall be deprovisioned (revoked) from the PIN; to either the PIN AF 418 (central provisioning) or to a PEMC 416 / 424 (local provisioning). (c) PINE Authentication and Authorization: An example of PINE Authentication and Authorization is shown with respect to the signalling diagram of Figure 5, which schematically shows communication in a PAN domain 502 between a PINE 508 (functioning as an EAP client), a PEGC 512 (functioning as an EAP authenticator) and a PEMC 516 (functioning as an EAP server). At S501 the PINE 508 sends a connection request to PEGC 512. At S502 the PEGC 512 may send an Identity Request to the PINE 508, if the PINE identity is not included in the message sent in S501. The PEGC 512 then fetches the PIN Identity (PIN ID) in an Identity response message. At S503 the PEGC 512 sends an Access Request to the PEMC 516, which includes the EAP identity of PINE 508. In some examples, protocol suites, like RADIUS or Diameter can be used to convey the Access Request to the PEMC 516. At S504 the PEMC 516 and the PINE 508 exchange several EAP messages, as required by the EAP method. In some examples this exchange may occur via PEGC 512. At S505 the PEMC 516 verifies the PINE request. For example, the PEMC 516 may do this based on provisioned information in its own credential database (CDB), which was previously obtained from central database. In some examples, the central database is located in PIN AF. In some examples, in case of a trusted AF (e.g. PIN AF operated by operator or an entity fully trusted by the operator), this may be internal to 3GPP 5GS. In case of untrusted AF (e.g. a home automation provider), this may be external to 3GPP 5GS. In some examples, irrespective of whether the AF is trusted or untrusted, the central database is external to PEMC. At S506, after successful completion of the authentication procedure, the PEMC 516 sends an EAP success message to the PEGC 512. In some examples this message may contain a secret which was derived as part of the execution of the EAP message exchange, and may be referred to as Master Session Key (MSK). The specific way the MSK is calculated on the PINE 508 and on the PEMC 516 is up to the EAP method that is used. In some examples the PEGC 512 could also save the PIN ID and PEMC 516 in a list for successful authentication / authorization between PINE 508 and a PEGC 512. At S507 an EAP Success message is sent the from the PEGC 512 to the PINE 508. In some examples this completes the authentication procedure. At S508 a further PAN specific handshake may take place to establish secure communication within the PAN 502. As part of this handshake, PEGC 512 and PINE 508 may derive further communication keys from the MSK. A possible wireless communication device will now be described in more detail with reference to Figure 6 showing a schematic, partially sectioned view of a communication device 600. Such a communication device is often referred to as user equipment (UE) or terminal. The wireless device 600 may receive signals over an air or radio interface 607 via appropriate apparatus for receiving and may transmit signals via appropriate apparatus for transmitting radio signals. In Figure 6 transceiver apparatus is designated schematically by block 606. The transceiver apparatus 606 may be provided for example by means of a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the wireless device. A wireless device is typically provided with at least one data processing entity 601, at least one memory 602 and other possible components 603 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access systems and other communication devices. The data processing, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by reference 604. The user may control the operation of the wireless device by means of a suitable user interface such as key pad 605, voice commands, touch sensitive screen or pad, combinations thereof or the like. A display 608, a speaker and a microphone can be also provided. Furthermore, a wireless communication device may comprise appropriate connectors (either wired or wireless) to other devices and / or for connecting external accessories, for example hands-free equipment, thereto. Figure 7 shows an example of a control apparatus for a communication system, for example to be coupled to and / or for controlling a station of an access system, such as a RAN node, e.g. a base station, gNB, a central unit of a cloud architecture or a node of a core network such as an MME or S-GW, a scheduling entity such as a spectrum management entity, or a server or host. The control apparatus may be integrated with or external to a node or module of a core network or RAN. With reference back to Figure 1, a control apparatus 700 may for example host a PINE 108, or a PEMC 116, or a PEGC 112. In some embodiments, base stations comprise a separate control apparatus unit or module. In other embodiments, the control apparatus can be another network element such as a radio network controller or a spectrum controller. In some embodiments, each base station may have such a control apparatus as well as a control apparatus being provided in a radio network controller. The control apparatus 700 can be arranged to provide control on communications in the service area of the system. The control apparatus 700 comprises at least one memory 701, at least one data processing unit 702, 703 and an input / output interface 704. Via the interface the control apparatus can be coupled to a receiver and a transmitter of the base station. The receiver and / or the transmitter may be implemented as a radio front end or a remote radio head. For example the control apparatus 700 or processor 701 can be configured to execute an appropriate software code to provide the control functions. Figure 8 is a flow chart of a method according to an example. According to some examples, the method of Figure 8 is viewed from the perspective of an apparatus. According to some examples, the apparatus comprises a personal loT network element with management capability (PEMC). As shown at S1, the method comprises communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network. At S2, the method comprises authenticating the network element in the personal area network, using the obtained information. Figure 9 is a flow chart of a method according to an example. According to some examples, the method of Figure 9 is viewed from the perspective of an apparatus. According to some examples, the apparatus comprises a personal loT network element (PINE). As shown at S1, the method comprises communicating extensible authentication protocol messages in a personal area network, for authentication and authorization of an apparatus in the personal area network. Figure 10 is a flow chart of a method according to an example. According to some examples, the method of Figure 10 is viewed from the perspective of an apparatus. According to some examples, the apparatus comprises a personal loT network element with gateway capability (PEGC). As shown at S1, the method comprises communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network. As shown at S2, the method comprises establishing secure communication with the network element in the personal area network. Figure 11 is a flow chart of a method according to an example. According to some examples, the method of Figure 11 is viewed from the perspective of an apparatus. According to some examples, the apparatus comprises a personal loT network application function (PIN AF). As shown at S1, the method comprises communicating credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network. As shown at S2, the method comprises storing the credential information in a credentials database at the apparatus. Figure 12 shows a schematic representation of non-volatile memory media 1200a (e.g. computer disc (CD) or digital versatile disc (DVD)) and 1200b (e.g. universal serial bus (USB) memory stick) storing instructions and / or parameters 1202 which when executed by a processor allow the processor to perform one or more of the steps of the methods of Figures 8 to 11. In general, the various embodiments may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the invention is not limited thereto. While various aspects of the invention may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof. It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities. It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein. It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention. As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or"’, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements. In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof. As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.” This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device. The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it. Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM). The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples. Embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate. The scope of protection sought for various embodiments of the disclosure is set out by the independent claims. The embodiments and features, if any, described in this specification that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various embodiments of the disclosure. The foregoing description has provided by way of non-limiting examples a full and informative description of the exemplary embodiment of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings of this disclosure will still fall within the scope of this invention as defined in the appended claims. Indeed, there is a further embodiment comprising a combination of one or more embodiments with any of the other embodiments previously discussed. A non-exhaustive list of acronyms used in the specification is provided below. CDB Credential Database DN Data Network MSK Master Session Key NEF Network Exposure Function PIN Personal loT Networks PAN Personal Area Network PINE PIN Element PEGC PIN Elements with Gateway Capability PEMC PIN Elements with Management Capability PSP PIN Service Provider RDB Registration Database UE User Equipment UP User Plane UPF User Plane Function TECHNICAL CLAUSES Clause 1. An apparatus comprising: means for communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and means for authenticating the network element in the personal area network, using the obtained information. Clause 2. The apparatus according to clause 1, comprising means for receiving an access request, the access request comprising an extensible authentication protocol identifier of the network element. Clause 3. The apparatus according to clause 1 or clause 2, wherein the means for authenticating is configured to perform the authentication based on information comprised in a database that is stored in the apparatus. Clause 4. The apparatus according to clause 3, wherein the database comprises a credentials database that stores credentials of one or more network elements. Clause 5. The apparatus according to clause 3 or clause 4, wherein the apparatus comprises means for synchronizing the database with another database that is separate from the apparatus. Clause 6. The apparatus according to clause 5, wherein the another database is stored in an application function, the application function being located in a network to which the apparatus is configured to connect. Clause 7. The apparatus according to any of clauses 1 to 6, wherein the application function is located in a data network to which the apparatus is configured to connect via a cellular network connection. Clause 8. The apparatus according to any of clauses 1 to 6, wherein the information in the database of the apparatus has been previously obtained from a centralized database that is external to the apparatus. Clause 9. The apparatus according to any of clauses 1 to 8 comprising means for, based on successfully authenticating the network element, sending an extensible authentication protocol success message. Clause 10. The apparatus according to any of clauses 1 to 9, comprising means for sending a master session key configured to be used by the network element for establishment of secure communication. Clause 11. The apparatus according to any of clauses 1 to 10, comprising a personal internet of things network element with management capability. Clause 12. The apparatus according to any of clauses 1 to 11, comprising a user equipment with cellular connectivity capability. Clause 13. The apparatus according to any of clauses 1 to 12, wherein the means comprises at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code configured to, with the at least one processor, cause the performance of the apparatus. Clause 14. An apparatus comprising: means for communicating extensible authentication protocol messages in a personal area network, for authentication and authorization of the apparatus in the personal area network. Clause 15. The apparatus of clause 14, wherein the means for communicating is configured to send a connection request in the personal area network, and wherein the means for communicating is also configured to send an identifier of the apparatus. Clause 16. The apparatus of clause 14 or clause 15, comprising means for receiving a success message which indicates successful authentication and authorization of the apparatus in the personal area network. Clause 17. The apparatus of any of clauses 14 to 16, comprising means for using a master session key for establishing secure communication in the personal area network. Clause 18. The apparatus of any of clauses 14 to 17, wherein the means for communicating are configured to communicate with an extensible authentication protocol server apparatus via an extensible authentication protocol authenticator apparatus. Clause 19. The apparatus according to any of clauses 14 to 18, wherein the extensible authentication protocol server apparatus comprises a personal internet of things network element with management capability and the extensible authentication protocol authenticator apparatus comprises a personal internet of things network element with gateway capability. Clause 20. The apparatus according to any of clauses 14 to 19, wherein the apparatus comprises a personal internet of things network element. Clause 21. The apparatus according to any of clauses 14 to 20, wherein the means comprises at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code configured to, with the at least one processor, cause the performance of the apparatus. Clause 22. An apparatus comprising: means for communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and means for establishing secure communication with the network element in the personal area network. Clause 23. The apparatus according to clause 22, wherein the means for communicating are configured to send an access request to a server, the access request including an extensible authentication protocol identity of the network element Clause 24. The apparatus according to clause 22 or clause 23, comprising means for receiving an authentication success message and a master session key from the server. Clause 25. The apparatus according to clause 24, wherein the means for establishing secure communication with the network element is configured to use the master session key. Clause 26. The apparatus according to any of clauses 22 to 25, wherein the network element comprises a personal internet of things network element. Clause 27. The apparatus according to any of clauses 22 to 26, wherein the apparatus comprises a personal internet of things network element with gateway capability. Clause 28. The apparatus according to any of clauses 22 to 27, wherein the means comprises at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code configured to, with the at least one processor, cause the performance of the apparatus. Clause 29. A method comprising: communicating, by an apparatus, extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and authenticating the network element in the personal area network, using the obtained information. Clause 30. The method according to clause 29, comprising receiving an access request, the access request comprising an extensible authentication protocol identifier of the network element. Clause 31. The method according to clause 29 or clause 30, wherein the authenticating comprises performing the authentication based on information comprised in a database that is stored in the apparatus. Clause 32. The method according to clause 31, wherein the database comprises a credentials database that stores credentials of one or more network elements. Clause 33. The method according to clause 31 or clause 32, wherein the method comprises synchronizing the database with another database that is separate from the apparatus. Clause 34. The method according to clause 33, wherein the another database is stored in an application function, the application function being located in a network to which the apparatus is configured to connect. Clause 35. The method according to any of clauses 29 to 34, wherein the application function is located in a data network to which the apparatus is configured to connect via a cellular network connection. Clause 36. The method according to any of clauses 29 to 35, wherein the information in the database of the apparatus has been previously obtained from a centralized database that is external to the apparatus. Clause 37. The method according to any of clauses 29 to 36 comprising, based on successfully authenticating the network element, sending an extensible authentication protocol success message. Clause 38. The method according to any of clauses 29 to 37, comprising sending a master session key configured to be used by the network element for establishment of secure communication. Clause 39. The method according to any of clauses 29 to 38, performed by a personal internet of things network element with management capability. Clause 40. A method according to any of clauses 29 to 39, performed by a user equipment with cellular connectivity capability. Clause 41. A method comprising: communicating, by an apparatus, extensible authentication protocol messages in a personal area network, for authentication and authorization of an apparatus in the personal area network. Clause 42. The method of clause 41, comprising sending a connection request in the personal area network, and sending an identifier of the apparatus. Clause 43. The method of clause 41 or clause 42, comprising receiving a success message which indicates successful authentication and authorization of the apparatus in the personal area network. Clause 44. The method of any of clauses 41 to 43, comprising using a master session key for establishing secure communication in the personal area network. Clause 45. The method of any of clauses 41 to 44, wherein the communicating comprises communicating with an extensible authentication protocol server apparatus via an extensible authentication protocol authenticator apparatus. Clause 46. The method according to any of clauses 41 to 45, wherein the extensible authentication protocol server apparatus comprises a personal internet of things network element with management capability and the extensible authentication protocol authenticator apparatus comprises a personal internet of things network element with gateway capability. Clause 47. The method according to any of clauses 41 to 46, performed by a personal internet of things network element. Clause 48. A method comprising: communicating, by an apparatus, extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and establishing secure communication with the network element in the personal area network. Clause 49. The method according to clause 48, comprising sending an access request to a server, the access request including an extensible authentication protocol identity of the network element. Clause 50. The method according to clause 48 or clause 49, comprising receiving an authentication success message and a master session key from the server. Clause 51. The method according to clause 50, wherein the establishing secure communication with the network element uses the master session key. Clause 52. The method according to any of clauses 48 to 51, wherein the network element comprises a personal internet of things network element. Clause 53. The method according to any of clauses 48 to 52, performed by a personal internet of things network element with gateway capability. Clause 54. The method according to any of clauses 48 to 53, performed by a user equipment with cellular connectivity capability. Clause 55. A computer program comprising instructions for causing an apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and authenticating the network element in the personal area network, using the obtained information. Clause 56. A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and authenticating the network element in the personal area network, using the obtained information. Clause 57. A computer program comprising instructions for causing an apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network, for authentication and authorization of the apparatus in the personal area network. Clause 58. A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network, for authentication and authorization of the apparatus in the personal area network. Clause 59. A computer program comprising instructions for causing an apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and establishing secure communication with the network element in the personal area network. Clause 60. A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and establishing secure communication with the network element in the personal area network. Clause 61. An apparatus comprising: means for communicating credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and means for storing the credential information in a credentials database at the apparatus. Clause 62. The apparatus according to clause 61, wherein the apparatus comprises means for synchronizing the credentials database with one or more other credentials databases stored in one or more respective network elements. Clause 63. The apparatus according to clause 61 or clause 62, wherein the apparatus comprises means for determining a list of the one or more network elements whose credentials databases require updating. Clause 64. The apparatus according to any of clauses 61 to 63, wherein the synchronizing the database is performed based on a synchronization request message received from a network element of the one or more network elements. Clause 65. The apparatus according to any of clauses 61 to 64, wherein the apparatus comprises means for instructing a network element of the one or more network elements to perform synchronization of its credentials database. Clause 66. The apparatus according to any of clauses 61 to 65, wherein the one or more network elements comprises one or more personal internet of things network elements with management capability. Clause 67. The apparatus according to any of clauses 61 to 66, wherein the apparatus comprises a personal internet of things network application function. Clause 68. The apparatus according to any of clauses 61 to 67, wherein the means comprises at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code configured to, with the at least one processor, cause performance of the apparatus. Clause 69. A method comprising: communicating, by an apparatus, credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and storing the credential information in a credentials database at the apparatus. Clause 70. A computer program comprising instructions for causing an apparatus to perform at least the following: communicating credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and storing the credential information in a credentials database at the apparatus. Clause 71. A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: communicating credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and storing the credential information in a credentials database at the apparatus. Clause 72. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: communicate extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; and authenticate the network element in the personal area network, using the obtained information. Clause 73. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: communicate extensible authentication protocol messages in a personal area network, for authentication and authorization of the apparatus in the personal area network. Clause 74. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: communicate extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network; and establish secure communication with the network element in the personal area network. Clause 75. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: communicate credential information using extensible authentication protocol messages, the credential information for authentication of a network element in a personal area network; and store the credential information in a credentials database at the apparatus. Clause 76. A system comprising: means for communicating extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; means for authenticating the network element in the personal area network, using the obtained information; means for communicating extensible authentication protocol messages in the personal area network, for authentication and authorization of an apparatus in the personal area network; means for communicating extensible authentication protocol messages in the personal area network for authentication of the network element in the personal area network; means for establishing secure communication with the network element in the personal area network; means for communicating credential information using extensible authentication protocol messages, the credential information for authentication of the network element in the personal area network; and means for storing the credential information in a credentials database. Clause 77. A system comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: communicate extensible authentication protocol messages in a personal area network to obtain information for authenticating a network element in the personal area network; authenticate the network element in the personal area network, using the obtained information; communicate extensible authentication protocol messages in the personal area network, for authentication and authorization of an apparatus in the personal area network; communicate extensible authentication protocol messages in the personal area network for authentication of the network element in the personal area network; establish secure communication with the network element in the personal area network; communicate credential information using extensible authentication protocol messages, the credential information for authentication of the network element in the personal area network; and store the credential information in a credentials database. 03 01 25

Claims

1. An apparatus comprising a personal internet of things network element with management capability, PEMC, the apparatus comprising:means for communicating extensible authentication protocol, EAP, messages in a personal area network to obtain information for authenticating a network element in the personal area network;means for authenticating the network element in the personal area network, using the obtained information; andmeans for sending an authentication success message to a personal internet of things network element with gateway capability, PEGC, that comprises a master session key.

2. The apparatus according to claim 1, comprising means for receiving an access request, the access request comprising an extensible authentication protocol identifier of the network element.

3. The apparatus according to claim 1 or claim 2, wherein the means for authenticating is configured to perform the authentication based on information comprised in a database that is stored in the apparatus.

4. The apparatus according to claim 3, wherein the database comprises a credentials database that stores credentials of one or more network elements.

5. The apparatus according to claim 3 or claim 4, wherein the apparatus comprises means for synchronizing the database with another database that is separate from the apparatus.

6. The apparatus according to claim 5, wherein the another database is stored in an application function, the application function being located in a network to which the apparatus is configured to connect.

7. The apparatus according to any of claims 1 to 6 comprising means for, based on successfully authenticating the network element, sending an extensible authentication protocol success message.03 01 258. The apparatus according to any of claims 1 to 7, comprising a user equipment with cellular connectivity capability.

9. An apparatus comprising a personal internet of things network element with gateway capability, PEGC, the apparatus comprising:means for communicating extensible authentication protocol messages in a personal area network for authentication of a network element in the personal area network;means for receiving an authentication success message and a master session key from a personal internet of things network element with management capability, PEMC; andmeans for establishing secure communication with the network element in the personal area network.

10. The apparatus according to claim 9, wherein the means for communicating are configured to send an access request to the PEMC, the access request including an extensible authentication protocol identity of the network element.

11. The apparatus according to claim 10, wherein the means for establishing secure communication with the network element is configured to use the master session key.

12. The apparatus according to any of claims 9 to 11, wherein the apparatus comprises a user equipment with cellular connectivity capability.

13. A method for an apparatus comprising a personal internet of things network element with management capability, PEMC, the method comprising:communicating extensible authentication protocol, EAP, messages in a personal area network to obtain information for authenticating a network element in the personal area network;authenticating the network element in the personal area network, using the obtained information; andsending an authentication success message to a personal internet of things network element with gateway capability, PEGC, that comprises a master session key.

14. A computer program comprising instructions for causing an apparatus comprising a personal internet of things network element with management capability, PEMC, to perform at least the following:communicating extensible authentication protocol, EAP, messages in a personal area network to obtain information for authenticating a network element in the personal area network;authenticating the network element in the personal area network, using the obtained information; andsending an authentication success message to a personal internet of things network element with gateway capability, PEGC, that comprises a master session key.LDCM

Citation Information

Patent Citations

  • Authentication interoperability in a wireless communication system

    EP3413606A1

  • Authentication of 6LoWPAN Nodes Using EAP-GPSK

    US20090103731A1

  • Method and apparatus for passpoint EAP session tracking

    US20170118638A1

  • Protection of the UE Identity During 802.1x Carrier Hotspot and Wi-Fi Calling Authentication

    US20210037604A1

  • Bluetooth device and bluetooth gateway

    WO2021155922A1