Methods, network entities and network nodes for processing sensing data in a secure operating environment
The method addresses the lack of sensing data privacy in JCAS by using secure network entities and nodes to process and transmit data within a secure environment, adhering to the privacy policies of asset owners and ensuring the security of sensing data.
Patent Information
- Application Number
- PCT/SE2024/051094
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-20
- Filing Date
- 2024-12-17
- Publication Date
- 2025-06-26
AI Technical Summary
Current joint communication and sensing (JCAS) solutions do not adequately address sensing data privacy, which is a critical concern when sensing physical objects in public, private, or commercial areas.
The proposed method involves using network entities and nodes to process sensing data in a secure operating environment. This includes creating a sensing data processor (SDP) instance within an enclave, generating encryption information, and managing sensing requests and data transmission securely, while considering the privacy policies of physical asset owners.
This approach ensures the secure processing and transmission of sensing data, respecting the privacy requirements of physical asset owners, and providing a secure operating environment for JCAS applications.
Smart Images

Figure SE2024051094_26062025_PF_FP_ABST
Abstract
Description
METHODS, NETWORK ENTITIES AND NETWORK NODES FOR PROCESSING SENSING DATA IN A SECURE OPERATING ENVIRONMENTTECHNICAL FIELD
[0001] The present disclosure relates to methods, network entities and network nodes for processing sensing data in a secure operating environment. The present disclosure also relates to computer programs and carriers corresponding to the above methods, network entities and network nodes.BACKGROUND
[0002] Recently, radar sensing technology has evolved with the evolution of wireless communication technology. Research on 6thGeneration (6G) wireless communication networks, aka mobile networks, has discussed the use of cellular radio frequencies in a radar-like fashion, to enable the sensing of environment and objects in a target area. The radar-like sensing may involve base stations sending radar-like signals and observing their echoes from the environment. The radar-like sensing may also involve user equipment (UE) to perform sensing.
[0003] When there is a need to detect or sense physical objects in a target area, radio detection and ranging (Radar) technology is often used to fulfill such need. Radar is a detection system that uses radio waves to determine distance, ranging angle, or velocity of objects. Traditionally, it can be used to, e.g. determine aircraft, ships, spacecraft, motor vehicles, weather formations, and terrain. A radar system consists of a transmitter producing electromagnetic waves in the radio or microwaves domain, a transmitting antenna, a receiving antenna, a receiver and a processor to determine properties of the detected objects. Radio waves, pulsed or continuous, transmitted from the transmitter reflect off the object and return to the receiver, giving information about the object's location and speed.
[0004] In other words, radio signal transmissions do not only enable communications, but the radio signals can be observed and measured for the purpose for sensing surrounding objects. Radio signal reflections, attenuations and absorptions provide information about the environment and physical objects in the environment. This is called joint communication and sensing (JCAS) orintegrated sensing and communication (ISAC).The 3rdGeneration Partnership Project (3GPP) document TR 22.837 V 19.1.0 discloses a feasibility study on JCAS / ISAC. The abbreviation ‘JCAS’ is used hereinafter in this application, but can be exchanged with ‘ISAC’.
[0005] The radar-like radio signal sensing can observe the entire environment, including those objects which do not carry a UE. There is also a lot of freedom to choose how and when the sensing is performed, using parameters such as how many antennas, how many base stations, which base stations, how many time slots, and what frequencies are going to be used for sensing. The choices of which of the above parameters to use, dictate the theoretical and practical precision and resolution of the sensing. The choices of the above parameters also influence how much energy and spectrum-time are spent for the sensing. This is essentially an optimization task between radio communication and sensing at the expense of spectrum-time resources, energy, investments and operational costs.
[0006] When utilizing the radio signal for radar-like sensing, multiple measurements can be combined to form a full picture of the environment. For instance, radar returns corresponding to signals sent in different directions can be visualized on the same radar screen, or can be used to create a 3D model.
[0007] Furthermore, it is also possible to combine sensing data from multiple sensing devices. For example, to maximize sensing efficiency and coverage, multiple base stations can be used to acquire a full picture of the environment.
[0008] When performing JCAS, the sensing data privacy issue is of an essential concern. However, this is a complicated and important issue. For example, when the sensing data is generated, which party is then authorized to receive the sensing data related to a public area, e.g., a road? The sensing data may in such a scenario have many different uses, e.g., for collision avoidance, route optimization, and speed limitation. Should this data be accessible to everyone, or should it only be available to certain authorities / organizations? Another example is the sensing of different areas, e.g. private areas, commercial areas, and publicareas. When sensing in these different areas, how should the sensing data be handled?
[0009] In general, there is no JCAS solution which considers sensing data privacy in prior art. Therefore, there is a need to have a JCAS solution which considers sensing data privacy in a proper way.SUMMARY
[0010] It is an object of the invention to enable utilization of JCAS / ISAC while taking privacy into account. It is possible to achieve this object and others by using methods, and one or more network entities as defined in the independent claims. It is another object of embodiments of the invention to perform JCAS considering also data security and / or user authentication. It is possible to achieve one or more of these objects and possibly others by using methods, one or more network entities and network nodes as defined in the attached independent claims.
[0011] A method performed by one or more network entities for processing sensing data is disclosed. The one or more network entities arranged to communicate with a network node of a mobile network, the network node arranged to communicate with at least one object sensing device, the at least one object sensing device being operative for sensing a physical object and for performing wireless communication in the mobile network, the method comprising: receiving a request for a sensing data processor, SDP, instance in the one or more network entities, the request for SDP instance originating from a physical asset owner; obtaining, according to the request for SDP instance, an SDP instance in an enclave of the one or more network entities, the enclave being an isolated operating environment for the SDP instance; generating, by the SDP instance, encryption information; receiving, by the SDP instance, a sensing request originating from the physical asset owner, the sensing request comprising an ownership assertion of the physical asset owner, the ownership assertion of the physical asset owner comprises a physical asset owner identity, identity of a physical asset of the physical asset owner, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating privacyrequirement of the physical asset, the identity of the physical asset of the physical asset owner comprising a geographic position of the physical asset; sending, by the SDP instance, a sensing request to the network node, the sensing request comprising the physical asset owner identity and the identity of the physical asset; receiving, by the SDP instance, an attestation request for the SDP instance from the network node; sending, by the SDP instance, SDP instance authenticity evidence to the network node, the SDP instance authenticity evidence comprises the generated encryption information; receiving, by the SDP instance, sensing data from the object sensing device in a connection encrypted by use of at least a part of the encryption information, the sensing data comprising sensing information that the sensing device has obtained when sensing the physical object in its vicinity; determining, by the SDP instance, information of the physical object in the sensing data based on the received ownership assertion of the physical asset owner; and sending, by the SDP instance, the determined information of the physical object to a communication device of the physical asset owner.
[0012] A method performed by a network node of a mobile network for processing sensing data is disclosed. The network node is arranged to communicate with one or more network entities and with at least one object sensing devices that is operative for sensing a physical object and for performing wireless communication in the mobile network, the method comprises: receiving a sensing request originating from a sensing data processor, SDP, instance of the one or more network entities, the sensing request comprising an identity of a physical asset of a physical asset owner and the physical asset owner identity, the identity of the physical asset of the physical asset owner comprising a geographic position of the physical asset; sending an attestation request to the SDP instance of the one or more network entities ; validating the SDP instance based on SDP instance authenticity evidence provided by the SDP instance, the authenticity evidence comprises an encryption information; validating the identity of the physical asset owner and the received sensing request; selecting at least one object sensing device among the at least one object sensing devices arranged to communicate with the network node, based on the identity of the physical asset of the physical asset owner, the physical asset being located in the vicinity of theselected object sensing device and the selected object sensing device being able to sense the physical asset ; and sending a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense object within the physical asset of the physical asset owner, and for instructing the selected object sensing device to send sensing data to the one or more network entities, the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
[0013] A method performed by one or more network entities, for processing sensing data, the one or more network entities arranged to communicate with a network node of a mobile network, the network node arranged to communicate with at least one object sensing device, the object sensing device being operative for sensing a physical object and performing wireless communication in the mobile network, the method comprising: receiving a request for sensing data processor, SDP instance in the one or more network entities, the request for SDP instance originating from the network node ; obtaining, according to the request for SDP instance, an SDP instance in a enclave of the one or more network entities , the enclave being an isolated operating environment for the SDP instance; generating, by the SDP instance, encryption information; receiving , by the SDP instance, an attestation request from the network node; sending, by the SDP instance, SDP instance authenticity evidence to the network node for attestation, the SDP instance authenticity evidence comprises the generated encryption information; receiving, by the SDP instance, a sensing request from the network node, the sensing request comprising an ownership assertion of a physical asset owner, the ownership assertion of the physical asset owner comprises a physical asset owner identity, identity of physical asset of the physical asset owner, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner comprising geographic position of the physical asset; receiving, by the SDP instance, sensing data from the object sensing device in a connection encrypted by use of at least a part of the generated encryption information, the sensing data comprising sensing information that the at least one sensing device has obtained when sensing the physical object in its vicinity;determining, by the SDP instance, information of the physical object in the sensing data based on the received ownership assertion of the physical asset owner; and sending, by the SDP instance, the determined information of the physical object to the physical asset owner.
[0014] A method performed by a network node of a mobile network for processing sensing data, the network node arranged to communicate with one or more network entities and at least one object sensing device being operative for sensing physical object and performing wireless communication in the mobile network, the method comprises: receiving a request for a sensing data processor, SDP, instance in the one or more network entities, the request for an SDP instance originating from a physical asset owner; sending a request for an SDP instance to the one or more network entities, instructing the one or more network entities to obtain an SDP instance in a enclave of the one or more network entities , the enclave being an isolated operating environment for the SDP instance ; sending an attestation request to the SDP instance of the one or more network entities; validating the SDP instance based on SDP instance authenticity evidence provided by the SDP instance, the SDP instance authenticity evidence comprises encryption information generated by the SDP instance; sending a notification to the physical asset owner notifying that the SDP instance is ready to use; receiving a sensing request originating from the physical asset owner, the sensing request comprising an ownership assertion of the physical asset owner, the ownership assertion of the physical asset owner comprises a physical asset owner identity, identity of physical asset of the physical asset owner, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner comprising geographic position of the physical asset; sending a sensing request to the SDP instance of the one or more network entities, the sensing request comprising the ownership assertion of the physical asset owner; validating the identity of the physical asset owner and the received sensing request; selecting at least one object sensing device among the at least one object sensing devices which being arranged to communicate with the network node, based on the identity of physical asset of the physical asset owner,the physical asset being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset; and sending a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense the object within the physical asset of the physical asset owner, and for instructing the selected object sensing device to send sensing data to the one or more network entities, the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
[0015] According to other aspects, one or more network entities and network node of mobile network are also provided, the details of which will be described in the claims and detailed description.
[0016] According to other aspects, computer programs and carriers are also provided, the details of which will be described in the claims and the detailed description.
[0017] Further possible features and benefits of this solution will become apparent from the detailed description below.BRIEF DESCRIPTION OF DRAWINGS
[0018] The solution will now be described in more detail by means of exemplary embodiments and with reference to the accompanying drawings, in which:
[0019] Fig. 1 is a schematic block diagram of a network arrangement in which the embodiments of the present invention may be used.
[0020] Figs. 2a and 2b are flow charts illustrating a method performed by one or more network entities, according to possible embodiments.
[0021] Fig. 3 is a flow chart illustrating a method performed by a network node of mobile network, according to possible embodiments.
[0022] Fig. 4 is a schematic diagram of signal interactions, according to possible embodiments.
[0023] Fig. 5 is a flow chart illustrating a method performed by one or more network entities, according to possible embodiments.
[0024] Fig. 6 is a flow chart illustrating a method performed by a network node of a mobile network, according to possible embodiments.
[0025] Fig. 7 is a schematic diagram of signal interactions, according to possible embodiments.
[0026] Fig. 8 is a block diagram illustrating the network entity in more detail, according to possible embodiments.
[0027] Fig. 9 is a block diagram illustrating the network node of mobile network, according to possible embodiments.DETAILED DESCRIPTION
[0028] Fig. 1 shows a network arrangement according to an embodiment. A physical asset 118 exists in a physical area. The physical asset 118 is a tangible asset and can be seen and touched, with a very identifiable physical presence, e.g., it can be a yard, a building, etc., and there are one or more objects 116 in / on the physical asset 118. The one or more objects are in Fig. 1 illustrated as a single object 116, which can be static or mobile. The physical asset 118 belongs to a physical asset owner 102. The physical asset owner 102 can contact, e.g. via a communication device such as a UE, an authority 104 to verify an ownership and provide certification of the ownership of the physical asset owner 102.
[0029] A basic idea of this invention is that the physical asset owner 102 can communicate with an operator 108, via a communication device, to manage the sensing data which is related to the object 116 in / on the physical asset 118 which belongs to the owner 102. To manage the sensing data according to the requirement of the physical asset owner 102, the operator 108 can create a sensing data processor (SDP) 112 in a secure environment in a cloud 106. The secure environment is known as an enclave 110 in the cloud 106. After the SDP 112 is created and verified by the physical asset owner 102, the SDP 112 can contact a sensing authorization function (SAF) 114 in a mobile network 120. TheSAF 114 can also verify the SDP 112. After verification, The SAF 114 can instruct one or more base station 122 in the mobile network 120 to sense the object 116 in / on the physical asset 118. The base station 122 is capable to executing a JCAS function or at least a part thereof. After sensing, the base station 122 transmits sensing data to the SDP 112 in a secure way. The sensing data is processed in the SDP 112, according to a privacy policy required by the physical asset owner 102, and the result is sent to the physical asset owner 102.
[0030] Hereby, the sensing and processing of the sensing data is performed in a secure way, and privacy requested by the physical asset owner 102 is also considered. Firstly, an SDP 112 is created in a secure environment, the enclave 110. The physical asset owner 102 can verify the SDP 112 to at least make it more sure that the SDP 112 fulfills the owner’s requirement / request of security. Secondly, the sensing data generated by the base station 122 is transmitted to the SDP 112 in a secure way, so that the sensing data would not be compromised.Thirdly, when processing the sensing data in the SDP 112, the privacy requirement or the privacy policy of the physical asset owner 102 will be considered. Therefore, the sensing data can be transmitted and processed in a secure way, and the privacy policy of the physical asset owner will be considered.
[0031] The physical asset owner 102 can be a person or an organization who owns the physical asset 118. The authority 104 can be an organization which is capable of verifying the ownership of the physical asset owner 102 and issuing an ownership assertion, e.g., a government department / governmental organization. The authority 104 can communicate with the physical asset owner 104 via a communication device.
[0032] The operator 108 can be a network operator which provides a network communication function, such as the companies AT&T, Vodafone, and China Mobile. The operator 108 can also be a cloud service provider, such as Amazon, Google, Alibaba, and Oracle.
[0033] The cloud 106 can be realized in one or more network entities. The one or more network entities may be arranged at or in any network node of acommunication network. The network entities and the network node are within the meaning of this description, figures and claims defined as physical devices as opposed to pure software. Alternatively, the one or more network entities may be realized as a group of network nodes, wherein functionality of the one or more network entities 160 is spread out over the group of network nodes. The group of network nodes may be different physical nodes of the network. This alternative realization is therefore called a cloud-solution. In the following text, the cloud 106 may also be called one or more network entities 106.
[0034] An enclave is a secure and protected environment in the cloud 106 which provides hardware level, firmware level or software level isolation and memory encryption, by placing application code and data in / on isolated or separated hardware / firmware / software. In other words, an enclave is a section of a network / cloud that is subdivided from the rest of the network / cloud. Accessibility to the enclave is restricted through the usage of e.g. internal firewalls, VLANs, network admissions control and VPNs. Thus, the enclave is an isolated operating environment for the SDP 112. By using the enclave 110 in the cloud 106, the security of the SDP 112 is significantly improved.
[0035] The mobile network 120 where the SAF 114 and the base station 122 are situated may be any kind of wireless communication network. Example of such wireless communication networks are Global System for Mobile communication (GSM), Enhanced Data Rates for GSM Evolution (EDGE), Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA 2000), Long Term Evolution (LTE) Frequency Division Duplex (FDD) and Time Division Duplex (TDD), LTE Advanced, Wireless Local Area Networks (WLAN), Worldwide Interoperability for Microwave Access (WiMAX), WiMAX Advanced, as well as 5G wireless communication networks based on technology such as New Radio (NR), or even 6G. The SAF 114 is a control device in the mobile network 120 which controls the base station 122 to perform the sensing. The base station 122 is situated in a physical position where the base station 122 is capable of sensing the object 116.
[0036] Furthermore, the base station 122 can also be another kind of network node, depending on the type of the mobile network 120, e.g., a NodeB, eNodeB, and gNodeB, as long as it is a network side device of the mobile network 120, and capable of JCAS. In the following text, the base station 122 can also be called an object sensing device 122, so as to focus on its sensing function. In some embodiment, the object sensing device 122 can also be a UE, since the UE can also be capable of performing JCAS. Radio signals sent and received by the UE can be observed and measured by the UE for the purpose for sensing surrounding objects. Radio signal reflections, attenuations and absorptions provide information about the environment of the UE and physical objects in the environment.
[0037] Figs. 2a and 2b, in conjunction with fig. 4, describe a method performed by one or more network entities 106, for processing sensing data, e.g. in a secure operating environment, the network entities 106 arranged to communicate with the network node 114 of the mobile network 120. The network node 114 is arranged to communicate with at least one object sensing device 122. The sensing device 122 is operative for sensing a physical object and for performing wireless communication in the mobile network 120. The method comprises: receiving 202 a request for a sensing data processor, SDP, instance in the network entities 106, the request for SDP instance originating from a physical asset owner 102. The method further comprises obtaining 204, according to the request for SDP instance, an SDP instance 112 in an enclave 110 of the network entities 106, the enclave 110 being an isolated operating environment for the SDP instance 112. The method further comprises generating 206, by the SDP instance 112, encryption information and receiving 208, by the SDP instance 112, a sensing request originating from the physical asset owner 102, the sensing request comprising an ownership assertion of the physical asset owner 102. The ownership assertion of the physical asset owner 102 comprises a physical asset owner identity of the physical asset owner 102, an identity of at least one physical asset of the physical asset owner 102, and a related physical asset owner privacy policy, the physical asset owner privacy policy indicating one or more privacy requirements of corresponding physical assets, the identity of the physical asset comprising a geographic position of the physical asset. The method furthercomprises sending 210, by the SDP instance 112, a sensing request to the network node 114 of the mobile network 120, the sensing request comprising the physical asset owner identity and the identity of the physical asset. The method further comprises receiving 230, by the SDP instance 112, an attestation request for the SDP instance 112 from the network node 114 and sending 232, by the SDP instance 112, SDP instance authenticity evidence to the network node 114. The SPD authenticity evidence comprises the generated encryption information. The method further comprises receiving 212, by the SDP instance 112, sensing data from the object sensing device 122 in a connection encrypted by use of at least a part of the generated encryption information. The sensing data comprises sensing information that the sensing device 122 has obtained when sensing a physical object in its vicinity. The method further comprises determining 214, by the SDP instance 112, information of the object in the sensing data based on the received 208 ownership assertion of the physical asset owner 102 and sending 216, by the SDP instance 112, the determined 214 information of the object to the physical asset owner 102, e.g. via a communication device which the physical asset owner 102 possesses, e.g. a UE and a laptop.
[0038] As discussed with fig. 1 , in one embodiment the cloud 106 is realized by the network entities 106. The network entities 106 can communicate with the network node 114 of the mobile network 120. The network node 114 comprises the SAF 114 in an embodiment. The network node 114 can communicate with at least one object sensing device 122. The object sensing device 122 is a device that is able to sense one or more physical objects and to perform wireless communication in the mobile network 120. The object sensing device 122 can be the base station 122 in fig. 1 and can also be another network side device of the mobile network 120 which is capable of JCAS. The object sensing device 122 can also be UE which is capable of JCAS.
[0039] In the receiving step 202, the network entities 106 receive a request for SDP instance originated from a physical asset owner 102. Before that, the physical asset owner 102 can communicate with the authority 104, via two communication devices, so that the authority 104 can verify the physical assetowner 102 and issues a signed ownership assertion to the physical asset owner 102. The ownership assertion can also indicate that an access authorization is delegated to another party on behalf of the physical asset owner 102. For example, the communication device on the physical asset owner 102 side generates and sends a request to the communication device on the authority 104 side. The request comprises the identity of the physical asset owner 102. In response, the communication device on the authority 104 side verifies the identity and sends the signed ownership assertion to the communication device on the physical asset owner 102 side. The physical asset owner 102 may also generate the ownership assertion by itself, i.e., the communication device on the physical asset owner 102 side generates the ownership assertion automatically. More details of the ownership assertion will be discussed below. The request for SPD instance indicates that the physical asset owner 102 has a need to sense in / on his / her physical asset and process the sensing data in a secure way. An instance is an occurrence of a software element that is based on a type definition; in the current scenario, the SDP instance is an occurrence of a software element which is of the SDP type.
[0040] In the obtaining step 204, in response to the request for SDP instance, the one or more network entities 106 obtains an SDP instance 112 in an enclave 110 of the one or more network entities 106. As discussed above, the enclave 110 is an isolated and secure operating environment for the SDP instance 112. The network entities 106 can create a new dedicated SDP instance 112, or referring to a pre-existing SPD instance 112. The purpose of obtaining an SDP instance 112 is to provide a confidential computing environment for sensing data processing. The network entities 106 returns an access locator, e.g., a uniform resource locator (URL) for the SDP instance 112. In case the network entities 106 refer to a preexisting SDP instance 112, a shared service model is represented, i.e., by sharing the existed SDP instance 112 with other task.
[0041] In the encryption information generating step 206, encryption information, e.g., an encryption key is generated by the SDP instance 112 of the one or more network entities 106 for future use. The encryption key can bevarious kinds of encryption key, e.g., a cryptographic keypair consisting of a public and private key, a symmetric key, or an asymmetric key, etc. The encryption key can be generated via e.g., an encryption key server, by applications or by a keytool. The encryption keys can be generated using algorithms, e.g., National Institute of Standards and Technology (NIST) PostQuantum algorithms, and protocols, e.g., Transport Layer Security (TLS), Datagram Transport Layer Security (DTLS), Quick UDP Internet Connections (QUIC), proposed within standardization organizations such as 3rd Generation Partnership Project (3GPP), Internet Engineering Task Force (IETF), Internet Research Task Force (IRTF), European Telecommunications Standards Institute (ETSI) Security Algorithms Group of Experts (SAGE). A NIST Post-Quantum algorithm may be anyone of the following three Federal Information Processing Standards (FIPS): FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard; FIPS 204, Module-Lattice-Based Digital Signature Standard; and FIPS 205, Stateless Hash-Based Digital Signature Standard. Further NIST Quantum standards / algorithms may also be envisioned, such as , the algorithm that will be dubbed FN-DSA, short for FFT (fast-Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm (FALCON).
[0042] In the receiving step 208, the SDP instance 112 of the network entity 106 receives a sensing request from the physical asset owner 102. The sensing request comprises the ownership assertion of the physical asset owner 103. The ownership assertion of the physical asset owner 102 comprises at least three types of information: the identity of the physical asset owner 102, the identity (ies) of the physical asset(s), and at least one physical asset owner privacy policy.
[0043] For the identity of the physical asset owner 102, it can be an identity which uniquely identifies the physical asset owner 102, e.g., a bank identity, a network operator identity, and a government issued electronic identity. Examples of the network operator identity are a mobile phone number / Mobile subscription identification number (MSIN), an International Mobile Subscriber Identity (IMS I), and a Network Access Identity (NAI).
[0044] For the identities of the physical assets, global asset identifiers (GAI) can be used as the identities. A GAI comprises a geographic position of the corresponding physical asset, the geographic position can be a set of geographical coordinates provided by a satellite-based positioning system such as Global Positioning System (GPS), or local coordinates. Local coordinates can be e.g., offsets, distances or directions from known local fixed locations, such as cell towers.
[0045] For the physical asset owner privacy policy, the policy indicates one or more privacy requirements of the corresponding physical assets according to the physical asset owner 102. For example, a physical asset owner 102 may own a land. This land can be identified by the GAI of the land. The physical asset owner 102 also owns a yard on the land, which is significantly smaller than the land.The yard can also be identified by the GAI of the yard. The privacy policies of the land and the yard can be: the land can be sensed, but the yard should not be sensed, and when the yard overlaps with the land, the privacy policy of the yard takes precedence. As another example, when the physical asset is a building or a vehicle, the privacy policy can be: the building and the vehicle can be sensed, however the person inside the building or the vehicle should not be sensed. Other examples of the privacy policies can be, e.g., restrictions for combining sensing data with external data sources; maximum storage time, e.g. for the network operator, of the sensing data; and the allowed frequency of performing sensing. The GAIs and the related policy(ies) can be represented in Yet Another Markup Language (YAML) format.
[0046] In the sending step 210, the SDP instance 112 of the network entities 106 sends a sensing request to the network node 114. The physical asset owner identity and the identities of the physical assets are comprised in the sensing request. The one or more network entities 106 may send the sensing request via a Network Exposure Function (NEF).
[0047] In the receiving step 230, the SDP instance 112 of the network entities 106 receives an attestation request from the network node 114, requiring theSDP instance 112 in the network entities 106 to provide information for attestation.
[0048] In the step 232, in response to step 230, the SDP instance 112 of the one or more network entities 106 sends SDP instance authenticity evidence to the network node 114 for attestation. The SDP instance authenticity evidence includes the generated 206 encryption information. The SDP instance authenticity evidence can also include other information for attestation, e.g., the identity of the SDP instance 112, and certification of the SDP instance 112.
[0049] In the receiving step 212, the sensing data sensed by the object sensing device 122 is received by the SDP instance 112 of the network entities 106 via a connection. This connection is encrypted by the encryption information generated by the one or more network entities 106. The sensing data is the sensing information obtained by the at least one object sensing device 122 when it senses a physical object 116 in its vicinity. The vicinity of the object sensing device 112 refers to a geographic area that the object sensing device 112 can sense, i.e. , its coverage. The object sensing device 112 is not able to sense any physical object located outside its vicinity. The sensing data can be related to the physical assets 118 identified by the identities of the physical assets which are comprised in the sensing request.
[0050] In the determining step 214, information of objects in the sensing data is determined based on the received ownership assertion of the physical asset owner 102. The determination is performed by the SDP instance 112. The determination can use time of flight, signal direction, machine learning, etc. For example, as discussed above, the ownership assertion comprises a GAI of a land and a GAI of a yard, and the related policy is: the land can be sensed, but the yard should not be sensed; when the yard overlaps with the land, the privacy policy of the yard take precedence. In this situation, the determination of the object information should be performed only on the land, but not on the yard. In other words, the information of the object on the land is determined, but the information of the object in the yard is not determined. For another example, the ownership assertion comprises a GAI of a building or a vehicle, and the relatedpolicy is: the building and the vehicle can be sensed, however the person inside the building or the vehicle should not be sensed. In this situation, the determination of the object information can be in a large granularity, or a low resolution / precision. That is, information of an object under a given size is removed. Only information of an object above a given size remains. Alternatively, a voxel-based method can be used so that the unauthorized person information can be filtered away. Other examples of the determination can be: applying time constraints, summarizing the determined object information into single value, etc.
[0051] In the sending step 216, the determined information of the objects is sent to the physical asset owner 102 by the SDP instance 112, so that the physical asset owner 102 obtains the objects information which fulfills the privacy policies.
[0052] By this method, the sensing data is transmitted to the SDP 112 in an encrypted and safe transmission. Then the sensing data is processed in the SDP 112 which is a secure and isolated environment. Furthermore, the determination of the objects takes the privacy policies into account. Therefore, the security of sensing and processing sensing data is guaranteed, and the physical asset owner 102 can require personalized privacy policies when processing the sensing data.
[0053] According to another embodiment, the method further comprises: validating 218, by the SDP instance 112, the ownership assertion of the physical asset owner after the receiving of the sensing request originating from the physical asset owner.
[0054] The ownership assertion comprises the identity of the physical asset owner 102. The identity of the physical asset owner 102 can be verified by using information from the network operator, i.e. , via a Generic Bootstrapping Architecture (GBA). GBA is a technology that enables the authentication of a user. This authentication is possible if the user owns a valid identity on a Home Location Register (HLR) / Home Subscriber Server (HSS) / or a Unified Data Management (UDM). The user authentication is instantiated by a shared secret,one is on the user side, e.g., in a SIM card of a user mobile phone / communication device and the other is on the HLR / HSS. The identity can also be verified by other established identity providers, e.g., banks, governments. That is, the SDP instance 112 communicatively connects a bank / government database and check if the identity of the physical asset owner 102 can be found in the bank / government database as a correct entry. GBA can be used together with Authentication and Key Management for Applications (AKMA) to verify the identity and authenticity of the physical asset owner 102. As a result, the physical asset owner 102 can be authorized to request an action and information from the SDP instance 112.
[0055] The validating of the ownership assertion ideally requires: the physical asset owner 102 is strongly identified; the identities of the physical assets are claimed to be signed by the authority 104; the assertion is made for the physical asset owner 102; the authority’s 104 identity can be verified; and the authority 104 itself is authorized to access the sensing data of the physical assets.
[0056] By such an embodiment, the network entities 106 verifies that it is an authorized physical asset owner 102 which is requiring sensing.
[0057] According to another embodiment, the method further comprises receiving 220, by the SDP instance 112, a notification from the network node 114, notifying that sensing of an object or objects is in progress, after the sending of the sensing request to the network node 114.
[0058] By such an embodiment, the network entities 106 get a notification / confirmation of the sensing in progress.
[0059] According to another embodiment, the method further comprises receiving 222, by the SDP instance 112, an attestation request originating from the physical asset owner 102 after obtaining the SDP instance 112; sending 224, by the SDP instance 112, SDP instance authenticity evidence to the physical asset owner 102 for attestation, in response to the received attestation request. The SDP instance authenticity evidence can for example include the SDP instanceidentity, a certificate of the SDP instance, and / or an identity of the enclave 110, so that the device on the physical asset owner 102 side can check.
[0060] By such an embodiment, the physical asset owner 102 obtains the evidence of authenticity of the SDP instance 112, so that the physical asset owner 102 confirms the authenticity of the SDP instance 112 in the network entities 106.
[0061] According to another embodiment, the method further comprises receiving 226, by the SDP instance 112, sensing authorization information from the network node 114 after the sending 210 of the sensing request to the network node 114.The sensing authorization information comprises selected object sensing device information and a cryptographic token. The selected object sensing device information relates to the object sensing device 122 which is selected to perform sensing of the object. The cryptographic token indicates a sensing instruction to the selected object sensing device 122. The method also comprises sending 228, by the SDP instance 112, a sensing request to the selected at least one sensing device 122, the sensing request comprises the cryptographic token. The cryptographic token contains secret information used to prove identity. In this embodiment, the cryptographic token contains the instruction to the object sensing device 122 in a secret way, so that the instructions can be sent to the selected sensing device 122. Only the selected object sensing device has access to the secret information, i.e. , the instruction. The selected object sensing device prove its identity as an authorized receiver of the cryptographic token by providing its identifier, which is also contained in the overhead of the instruction. Other object sensing device which is not selected has no access to the instruction, since its identifier is not the same as the receiver’s identifier which is contained in the instruction overhead. The selection of the sensing device 122 can be performed based on the position / GAI of the physical asset 118, i.e., the sensing device 122 whose vicinity covers the physical asset 118 is selected. In other words, the sensing device which has capability to sense the physical asset 118 is selected.
[0062] The sensing authorization information may also comprise encryption information of the selected sensing device 122 and radio parameters of the selected at least one sensing device 122, e.g., cells and frequencies. For example,the radio parameters can comprise the ID(s) of cell(s) and / or radio signal frequencies which are used to transmit the sensing data from the selected sensing device 122 to the SDP instance 112. The radio parameters can also comprise the ID(s) of cells(s) and / or radio signal frequencies which are used by the selected sensing device 122 for sensing.
[0063] By such an embodiment, the network entities 106 directly connects with the selected sensing device 122, so that the selected sensing device 122 can perform sensing accordingly.
[0064] According to another embodiment, the determining 214 of the object in the sensing data further comprises identifying one or more objects in the sensing data and filtering one or more unauthorized objects according to the ownership assertion of the physical asset owner 102.
[0065] By such an embodiment, the authorized objects are identified in the sensing data, whereas the unauthorized objects are filtered.
[0066] According to another embodiment, the generated encryption information comprises a cryptographic key pair which comprising a public key and a private key.
[0067] Fig. 3, in conjunction with fig. 4, describes a method performed by a network node 114 of a mobile network 120 for processing sensing data in a secure operating environment. The network node 114 of the mobile network 120 arranged to communicate with one or more network entities 106 and with at least one object sensing device 122 that is operative for sensing physical objects and for performing wireless communication in the mobile network 120. The method comprises: receiving 302 a sensing request originating from a sensing data processor, SDP, instance 112 of the one or more network entities 106, the sensing request comprising the identity of physical asset of a physical asset owner 102 and the physical asset owner 102 identity, the identity of physical asset of the physical asset owner 102 comprising geographic position of the physical assets. The method further comprises validating 304 the physical asset owner 102 and thereceived 302 sensing request. The method further comprises sending 310 an attestation request to the SDP instance 112 of the one or more network entities 106 and validating 312 the SDP instance based on SDP instance authenticity evidence provided by the SDP 112, the authenticity evidence comprises encryption information. The method further comprises selecting 306 at least one object sensing device among the at least one object sensing devices 122 which being arranged to communicate with the network node 114 of the mobile network 120, based on the identity of physical asset of the physical asset owner 102, the physical asset being located in the vicinity of the selected at least one object sensing device and the selected at least one object sensing device being able to sense the physical asset. The method further comprises sending 308 a sensing request to each of the selected at least one object sensing device for instructing the selected at least one object sensing device to sense object within the physical asset of the physical asset owner 102, and for instructing the selected at least one object sensing device to send sensing data to the one or more network entities, the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
[0068] The network node 114 in this embodiment cooperates with the one or more network entities in fig. 2a and 2b. As discussed above, the network node 114 can be an SAF, the one or more network entities 106 can be cloud devices, and the object sensing device 122 can be a base station capable of JCAS.
[0069] In the step 302, the network node 114 receives a sensing request from the SDP 112, so that the network node 114 can instruct the object sensing device 112 to sense. The sensing request comprises the physical asset owner 102 identity and the identity of the physical asset, so that the network node 114 can use the physical asset identity to select proper object sensing device later on. Encryption information is also comprised in the sensing request for future use.
[0070] In the step 310, the network node 114 sends an attestation request to the SDP instance 112 of the one or more network entities 106 so as to require the SDP instance 112 of the one or more network entities 106 to provide information for attestation.
[0071] In the step 312, the network node 114 validates the SDP instance authenticity evidence provided by the SDP instance 112. The encryption information comprised in the SDP instance authenticity evidence is saved for later use.
[0072] In the step 304, the network node 114 validates the physical asset owner 102 and the sensing request to make sure that the physical asset owner 102 and the request are authorized. The validating of the physical asset owner 102 may include checking if the physical asset owner 102 is authorized to use the services of the mobile network 120, and if the physical asset owner 102 is allowed to access and process the sensing data. The validating can be performed by checking if the identity of the physical asset owner 102 is found in a certain database, and by checking corresponding access right of the physical asset owner 102.
[0073] In the step 306, the network node 114 selects at least one proper object sensing device 122 based on the geographic position of the physical asset included in the physical asset identity. The selected object sensing device 122 is situated in vicinity of the physical assets and is able to sense the physical asset.
[0074] In the step 308, the network node 114 sends a sensing request to the selected object sensing device 122 to instruct the selected object sensing device 122 to sense a physical object within the physical asset 118. The term “within” can be interpreted as an in / on attribute of the physical asset 118. For example, if the physical asset 118 is an open area such as a yard, the sensed physical object is on the physical asset 118; if the physical asset is an enclosed area such as a building, the sensed object is in the physical asset 118. The selected object sensing device 122 will perform sensing with pre-defined parameters. The encryption information is comprised in the sensing request, so that the selected object sensing device 122 can send sensing data to the one or more network entities 106 in a secure transmission channel encrypted by the encryption information.
[0075] By such an embodiment, the network node 114 validates the physical asset owner 102, selects at least one proper object sensing device 122, instruct the selected object sensing device 122 to sense the physical asset, and sends an encryption information to the object sensing device 122 for a secure transmission.
[0076] According to another embodiment, the method further comprises sending 314 a notification to the SDP instance 112 of the one or more network entities 106, notifying the sensing of object in progress, after sending 308 the sensing request to each of the selected at least one object sensing device 122.
[0077] According to another embodiment, the method further comprises sending 316 sensing authorization information to the SDP instance 112 of the one or more network entities 106 after selecting 306 the at least one object sensing device, the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the at least one object sensing device which are selected 306 to perform sensing of the objects, the cryptographic token indicating sensing instructions to the selected at least one object sensing device.
[0078] By such an embodiment, the network node 114 can inform the one or more network entities 106 about the information of the selected object sensing device, i.e. , which object sensing device is (are) selected to sense the physical asset. The one or more network entities 106 can send instructions directly to the selected object sensing device.
[0079] Fig. 4 shows a schematic diagram of signal interactions, according to possible embodiments. In step 4.1 , a request for an SDP instance is sent from the physical asset owner 102 to the one or more network entities 106. The one or more network entities 106 obtain an SDP instance in step 4.2. In optional steps 4.3 and 4.4, an attest request is sent from the physical asset owner 102 to the SDP instance of the one or more network entities 106, and SDP instance provides SDP instance authenticity evidence to the physical asset owner 102. The SDP instance generates an encryption information in step 4.5. A sensing request is sent from the physical asset owner 102 to the SDP instance in step 4.6, wherein the sensingrequest comprises the physical asset owner identity, the physical asset identity and ownership assertion. In an optional step 4.7, the SDP instance of the one or more network entities 106 validate the physical asset owner 102 and ownership assertion. In step 4.8, a sensing request is sent to a network node 114. In steps 4.9 and 4.10, an attestation request is sent from the network node 114 to the SDP instance, and the SDP instance provides SDP instance authenticity evidence accordingly. The encryption information is comprised in the SDP instance authenticity evidence. In step 4.11 , the network node 114 validates the physical asset owner 102 and the sensing request. In step 4.12, the network node 114 selects proper object sensing device 122 based on the position of the physical asset. In step 4.13, a sensing request is sent from the network node 114 to the selected object sensing device 122. The sensing request comprises the encryption information. Accordingly, the selected object sensing device 122 senses object in vicinity. Alternatively, in step 4.14, the network node 114 sends sensing authorization information and a token to SDP instance of the one or more network entities 106; SDP instance sends a sensing request to the selected object sensing device in step 4.15. Optionally, in step 4.16 a notification is sent from the network node 114 to the SDP instance, notifying that the sensing is in progress. In step 4.17, sensing data is sent from the selected object sensing device 122 to the SDP instance in an encrypted transmission channel. In step 4.18, the SDP instance determines objects in the sensing data based on privacy policy comprised in the ownership assertion. The determined object information is sent to a communication device of the physical asset owner 102 in step 4.19.
[0080] Referring to fig. 5, in conjunction with fig. 7, a method performed by one or more network entities 106, e.g., in a secure operating environment is disclosed. The method is used for processing sensing data, the one or more network entities 106 arranged to communicate with a network node 114 of a mobile network 120, the network node 114 of the mobile network 120 arranged to communicate with at least one object sensing device 122 , the at least one object sensing device 122 being operative for sensing a physical object and performing wireless communication in the mobile network 120. The method comprises receiving 502 a request for sending data processor, SDP instance in the one or more networkentities 106, the request for SDP instance originating from the network node 114 of the mobile network 120. The method further comprises obtaining 504, according to the request for SDP instance, an SDP instance 112 in an enclave 110 of the one or more network entities 106, the enclave 110 being an isolated operating environment for the SDP instance 112. The method further comprises generating 506, by the SDP instance 112, encryption information. The method further comprises receiving 508, by the SDP instance 112, an attestation request from the network node 114 and sending 510, by the SDP instance 112, SDP instance authenticity evidence to the network node 114 for attestation, the SDP instance authenticity evidence comprises the generated encryption information. The method further comprises receiving 512, by the SDP instance 112, a sensing request from the network node 114 of the mobile network 120, the sensing request comprising an ownership assertion of a physical asset owner 102, the ownership assertion of the physical asset owner 102 comprises a physical asset owner 102 identity, identity of physical asset of the physical asset owner 102, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirements of corresponding physical asset, the identity of physical asset of the physical asset owner 102 comprising geographic position of the physical asset. The method further comprises receiving 516, by the SDP instance 112, sensing data from the at least one object sensing device 122 in a connection encrypted by use of at least a part of the generated encryption information, the sensing data comprising sensing information that the at least one sensing device 122 has obtained when sensing physical object in its vicinity. The method further comprises determining 518, by the SDP instance 112, information of the physical object 116 in the sensing data based on the received ownership assertion of the physical asset owner 102 and sending 520, by the SDP instance 112, the determined 518 information of the physical object to the physical asset owner 102.
[0081] The basic idea of this embodiment is similar to the embodiment shown in fig. 2a and 2b, that is obtaining an SDP instance 112 to process the sensing data transmitted from the object sensing device 122. The difference is that when a physical asset owner 102 attempts to initiate a request for SDP instance via acommunication device then initiate a sensing process, the communication device of the physical asset owner 102 does not interact with the one or more network entities 106, instead it interacts with the network node 114.
[0082] In the step 502, the one or more network entities 106 receives a request for SDP instance from the network node 114. As discussed above, the network node 114 sends the request for SDP instance to the one or more network entities 106 upon receiving a request for SDP instance from the physical asset owner 102.
[0083] In the step 504, the one or more network entities 106 obtains an SDP instance 112 in the same way of the step 204.
[0084] In the step 506, the one or more network entities 106 generates encryption information in the same way of the step 206.
[0085] In the step 508, the one or more network entities 106 receives an attestation request from the network node 114 in the same way of the step 230.
[0086] In the step 510, the one or more network entities 106 sends SDP instance authenticity evidence to the network node 114 in the same way of the step 232.
[0087] In the step 512, the one or more network entities 106 receives a sensing request from the network node 114. The sensing request comprises an ownership assertion. The content of the ownership assertion is the same as the ownership assertion in the step 208. The network node 114 obtains the ownership assertion from a sensing request from the physical asset owner 102.
[0088] In the step 516, the one or more network entities 106 receives sensing data from the object sensing device 122 in the same way as the step 212.
[0089] In the step 518, the one or more network entities 106 determines the information of object in the same way as the step 214.
[0090] In the step 520, the one or more network entities 106 sends the determined information of the object to the physical asset owner 102 in the same way as the step 216.
[0091] By this method, the sensing data is transmitted to the SDP 112 in an encrypted and safe transmission. Then the sensing data is processed in the SDP 112 which is a secure and isolated environment. Furthermore, the determination of the object takes the privacy policy into account. Therefore, the security of sensing and processing sensing data is guaranteed, and the physical asset owner 102 can require personalized privacy policy when processing the sensing data.
[0092] According to another embodiment, the method further comprises receiving 522, by the SDP instance 112, a notification from the network node 114 of the mobile network 120, notifying the sensing of object in progress, after receiving 512 the sensing request from the network node 114 of the mobile network 120.
[0093] According to another embodiment, the method further comprises validating 514, by the SDP instance 112, the ownership assertion of the physical asset owner 102 after receiving 512 the sensing request from the network node 114. The validation 514 is performed in the same way as the step 218.
[0094] According to another embodiment, the method further comprises receiving 524, by the SDP instance 112, an attestation request originating from the physical asset owner 102 after obtaining 504 the SDP instance and sending 526, by the SDP instance 112, SDP instance authenticity evidence to the physical asset owner 102 for attestation in response to the attestation request. The steps 524 and 526 are performed in the same way as steps 222 and 224.
[0095] According to another embodiment, the determining 518 of information of object in the sensing data further comprises identifying object in the sensing data filtering unauthorized objects according to the ownership assertion of the physicalasset owner 102. The identifying and filtering steps are performed in the same way as the embodiment in the fig. 2a and 2b.
[0096] According to another embodiment, the generated 506 encryption information comprises a cryptographic key pair which comprising a public kay and private key.
[0097] Referring to fig. 6, in conjunction with fig. 7, a method performed by a network node 114 of a mobile network 120 for processing sensing data is disclosed. The network node 114 cooperates with the one or more network entities 106 in the embodiment of fig. 5. The network node 114 of the mobile network 120 is arranged to communicate with one or more network entities 106 and at least one object sensing device 122 being operative for sensing physical objects and performing wireless communication in the mobile network 120. The method comprises receiving 602 a request for a sensing data processor, SDP, instance in the one or more network entities 106, the request for an SDP instance originating from a physical asset owner 102. The method further comprises sending 604 a request for an SDP instance to the one or more network entities 106, instructing the one or more network entities 106 to obtain an SDP instance 112 in an enclave 110 of the one or more network entities 106, the enclave 110 being an isolated operating environment for the SDP instance 112. The method further comprises sending 606 an attestation request to the SDP instance 112 of the one or more network entities 106. The method further comprises validating 608 the SDP instance 112 based on SDP instance authenticity evidence provided by the SDP instance 112, the SDP instance authenticity evidence comprises encryption information generated by the SDP instance 112. The method further comprises sending 610 a notification to the physical asset owner 102 notifying that the SDP instance 112 being ready to use. The method further comprises receiving 612 a sensing request originating from the physical asset owner 102, the sensing request comprising an ownership assertion of the physical asset owner 102, the ownership assertion of the physical asset owner 102 comprises a physical asset owner 102 identity, identity of physical asset of the physical asset owner 102, and related physical asset owner privacy policy, the physical asset owner privacypolicy indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner 102 comprising geographic position of the physical asset. The method further comprises sending 614 a sensing request to the SDP instance 112 of the one or more network entities 106, the sensing request comprising the ownership assertion of the physical asset owner 102. The method further comprises validating 616 the identity of the physical asset owner 102 and the received 612 sensing request. The method further comprises selecting 618 at least one object sensing device among the at least one object sensing devices 122 which being arranged to communicate with the network node 114 of the mobile network 120, based on the identity of physical asset of the physical asset owner 102, the physical asset being located in the vicinity of the selected at least one object sensing device and the selected at least one object sensing device being able to sense the physical asset. The method further comprises sending 620 a sensing request to each of the selected at least one object sensing device for instructing the selected at least one object sensing device to sense the objects within the physical assets of the physical asset owner 102, and for instructing the selected at least one object sensing device to send sensing data to the one or more network entities 102, the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
[0098] In the step 602, the network node 114 receives a request for SDP instance in the same way as the step 202.
[0099] In the step 604, the network node 114 sends a request for SDP instance to the one or more network entities 106, so that the one or more network entities 106 can obtain an SDP instance accordingly.[000100] In the step 606, the network node 114 sends an attestation request in the same way as the step 310.[000101] In the step 608, the network node 114 validates the SDP instance 112 in the same way as the step 312.[000102] In the step 610, the network node 114 sends a notification to the physical asset owner 102 to notify that the SDP instance 112 being ready to use, and the physical asset owner 102 can initiate a sensing request via a communication device.[000103] In the step 612, the network node 114 receives a sensing request in the same way as the step 208.[000104] In the step 614, the network node 114 sends a sensing request to the SDP instance 112, the sensing request comprising the ownership assertion for the SDP instance 112 to use when determining the information of objects.[000105] In the step 616, the network node 114 validates the identity of the physical asset owner 102 and the received sensing request in the same way as the step 312.[000106] In the step 618, the network node 114 selects at least one object sensing device in the same way as the step 306.[000107] In the step 620, the network node 114 sends a sensing request to the selected object sensing device in the same way as the step 308.[000108] According to another embodiment, the method further comprises sending 622 a notification to the SDP instance 112 of the one more network entities 106, notifying the sensing of object in progress, after sending 620 the sensing request to each of the selected at least one object sensing device. This step is performed in the same way as the step 314.[000109] Referring to fig. 7, a schematic diagram of signal interactions is shown. In step 7.1 , a request for SDP instance is sent from the physical asset owner 102 to the network node 114. In step 7.2, a request for SDP instance is sent from the network node 114 to the one or more network entities 106. In step 7.3, the one or more network entities 106 obtain an SDP instance therein. In step 7.4, an attestation request is sent from the physical asset owner 102. In step 7.5, SDP instance authenticity evidence is provided from the SDP instance to the physicalasset owner. In the step 7.6, the SDP 112 generates encryption information. In step 7.7, an attestation request is sent from the network node 114 to the SDP instance. In the step 7.8, the network node 114 validates the SDP instance based on the SDP instance authenticity evidence provided by the SDP instance. The SDP instance authenticity evidence comprises the encryption information. In step 7.9, the network node 114 sends a notification to the physical asset owner informing of the SDP instance being ready to use. In step 7.10, a sensing request is sent from the physical asset owner 102 to the network node 114. In the step 7.11 , a sensing request is sent form the network node 114 to the SDP instance. In an optional step 7.12, the SDP instance validates ownership assertion in the received sensing request. In step 7.13, the network node 114 validates the identity of the physical asset owner 102 and the received sensing request. It also selects proper object sensing device based on the sensing request. In step 7.14, a sensing request is sent to each of the selected object sensing device 122. In an optional step 7.15, the network node 114 notifies the SDP instance of the sensing in progress. In step 7.16, the selected object sensing device transmits the sensing data using a transmission link encrypted by the encryption information. In step 7.17, the SDP instance determines information of objects based on the sensing data and ownership assertion, then sending the determined information of objects to the physical asset owner 102 in the step 7.18.[000110] According to other embodiments, one or more network entities 106 operative for processing sensing data, e.g. in a secure operating environment, the one or more network entities 106 arranged to communicate with a network node 114 of a mobile network 120, the network node 114 of the mobile network 120 arranged to communicate with at least one object sensing device 122, the at least one object sensing device 122 being operative for sensing physical objects and for performing wireless communication in the mobile network 120, the one or more network entities 106 comprising a processing circuitry 803 and a memory 804, said memory 804 containing instructions executable by said processing circuitry 803. The one or more network entities 106 is operative for: receiving a request for a sensing data processor, SDP, instance in the one or more network entities 106, the request for SDP instance originating from a physical asset owner 102;obtaining, according to the request for SDP instance, an SDP instance 112 in a enclave 110 of the one or more network entities 106, the enclave 110 being an isolated operating environment for the SDP instance 112. The one or more network entities 106 is further operative for generating, by the SDP instance 112, encryption information and receiving, by the SDP instance 112, a sensing request originating from the physical asset owner 102, the sensing request comprising an ownership assertion of the physical asset owner 102, the ownership assertion of the physical asset owner 102 comprises a physical asset owner 102 identity, identity of physical asset of the physical asset owner 102, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner 102 comprising geographic position of the physical asset. The one or more network entities 106 is further operative for sending, by the SDP instance 112, a sensing request to the network node 114 of the mobile network 120, the sensing request comprising the physical asset owner 102 identity and the identity of the physical asset and receiving, by the SDP instance 112, an attestation request for the SDP instance 112 from the network node 114. The one or more network entities 106 is further operative for sending, by the SDP instance 112, SDP instance authenticity evidence to the network node 114, the SDP instance authenticity evidence comprises the generated 206 encryption information and receiving, by the SDP instance 112, sensing data from the at least one object sensing device 122 in a connection encrypted by use of at least part of the generated 206 encryption information, the sensing data comprising sensing information that the at least one sensing device 122 has obtained when sensing physical object in its vicinity. The one or more network entities 106 is further operative for determining, by the SDP instance 112, information of the physical object in the sensing data based on the received 208 ownership assertion of the physical asset owner 102 and sending, by the SDP instance 112, the determined 214 information of the physical object to a communication device of the physical asset owner 102.[000111] According to other embodiments, the one or more network entities 106 is further operative for validating, by the SDP instance 112, the ownership assertionof the physical asset owner 102 after the receiving of the sensing request originating from the physical asset owner 102.[000112] According to other embodiments, the one or more network entities 106 is further operative for receiving, by the SDP instance 112, a notification from the network node 114 of the mobile network 120, notifying that the sensing of the object 116 in progress, after the sending of the sensing request to the network node 114 of the mobile network 120.[000113] According to other embodiments, the one or more network entities 106 is further operative for receiving, by the SDP instance 112, an attestation request originating from the physical asset owner 102 after obtaining the SDP instance 112; sending, by the SDP instance 112, SDP instance authenticity evidence to the physical asset owner 102 for attestation, in response to the received attestation request.[000114] According to other embodiments, the one or more network entities 106 is further operative for: receiving, by the SDP instance 112, sensing authorization information from the network node 114 of the mobile network 120 after the sending of the sensing request to the network node 114 of the mobile network 120, the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the at least one object sensing device 122 which is selected to perform sensing of the object, the cryptographic token indicating sensing instruction to the at least one object sensing device 122; and sending, by the SDP instance 112, a sensing request to the selected at least one object sensing device 122, the sensing request comprises the cryptographic token.[000115] According to other embodiments, the determining of information of objects in the sensing data further comprises identifying object in the sensing data and filtering unauthorized object according to the ownership assertion of the physical asset owner 102.[000116] According to other embodiments, the generated encryption information comprises a cryptographic key pair which comprising a public key and a private key.[000117] According to other embodiments, a network node 114 of a mobile network 120 operative for processing sensing data is provided. The network node 114 of the mobile network 120 is arranged to communicate with one or more network entities 106 and with at least one object sensing devices 122 that is operative for sensing a physical object 116 and for performing wireless communication in the mobile network 120, the network node 114 comprising a processing circuitry 903 and a memory 904, said memory 904 containing instructions executable by said processing circuitry 903. The network node 114 is operative for receiving a sensing request originating from a sensing data processor, SDP, instance 112 of the one or more network entities 106, the sensing request comprising the identity of physical asset of a physical asset owner 102 and the physical asset owner 102 identity, the identity of physical asset of the physical asset owner 102 comprising geographic position of the physical assets The network node 114 is further operative for sending an attestation request to the SDP instance 112 of the one or more network entities 106 and validating the SDP instance based on SDP instance authenticity evidence provided by the SDP instance 112, the authenticity evidence comprises encryption information. The network node 114 is further operative for validating the identity of the physical asset owner 102 and the received sensing request and selecting at least one object sensing device among the at least one object sensing devices 122 which being arranged to communicate with the network node 114 of the mobile network 120, based on the identity of physical asset of the physical asset owner 102, the physical asset being located in the vicinity of the selected at least one object sensing device and the selected at least one object sensing device being able to sense the physical asset. The network node 114 is further operative for sending a sensing request to each of the selected at least one object sensing device for instructing the selected at least one object sensing device to sense objects within the physical assets of the physical asset owner 102, and for instructing the selected at least one object sensing device to send sensing data to the one ormore network entities 106, the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.[000118] According to other embodiments, the network node 114 is further operative for sending a notification to the SDP instance 112 of the one or more network entities 106, notifying the sensing of object in progress, after sending the sensing request to each of the selected at least one object sensing device 122.[000119] According to other embodiments, the network node 114 is further operative for: sending sensing authorization information to the SDP instance 112 of the one or more network entities 106 after selecting the at least one object sensing device 122, the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the at least one object sensing device which are selected to perform sensing of the object, the cryptographic token indicating sensing instruction to the selected at least one object sensing device.[000120] According to other embodiments, one or more network entities 106 operative for processing sensing data, e.g. in a secure operating environment, is provided. The one or more network entities 106 is arranged to communicate with a network node 114 of a mobile network 120, the network node 114 of the mobile network 120 arranged to communicate with at least one object sensing device 122, the at least one object sensing device 122 being operative for sensing a physical object 116 and performing wireless communication in the mobile network 120, the one or more network entities 106 comprising a processing circuitry 803 and a memory 804, said memory 804 containing instructions executable by said processing circuitry 803. The one or more network entities 106 is operative for receiving a request for sensing data processor, SDP instance in the one or more network entities 106, the request for SDP instance originating from the network node 114 of the mobile network 120. The one or more network entities 106 is further operative for obtaining, according to the request for SDP instance, an SDP instance 112 in an enclave 110 of the one or more network entities 106, the enclave 110 being an isolated operating environment for the SDP instance 112 and generating, by the SDP instance 112, encryption information. The one or morenetwork entities 106 is further operative for receiving, by the SDP instance 112, an attestation request from the network node 114 and sending, by the SDP instance 112, SDP instance authenticity evidence to the network node 114 for attestation, the SDP instance authenticity evidence comprises the generated encryption information. The one or more network entities 106 is further operative for receiving, by the SDP instance 112, a sensing request from the network node 114 of the mobile network 120, the sensing request comprising an ownership assertion of a physical asset owner 102, the ownership assertion of the physical asset owner 102 comprises a physical asset owner 102 identity, identity of physical asset of the physical asset owner 102, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical assets, the identity of physical asset of the physical asset owner 102 comprising geographic position of the physical asset. The one or more network entities 106 is further operative for receiving, by the SDP instance 112, sensing data from the at least one object sensing device 122 in a connection encrypted by use of at least part of the generated encryption information, the sensing data comprising sensing information that the at least one sensing device 122 has obtained when sensing the physical object in its vicinity. The one or more network entities 106 is further operative for determining, by the SDP instance 112, information of the physical object 116 in the sensing data based on the received ownership assertion of the physical asset owner 102 and sending, by the SDP instance 112, the determined information of the physical object to a communication device of the physical asset owner 102.[000121] According to other embodiments, the one or more network entities 106 is further operative for receiving, by the SDP instance 112, a notification from the network node 114 of the mobile network 120, notifying the sensing of object in progress, after receiving the sensing request from the network node 114 of the mobile network 120.[000122] According to other embodiments, the one or more network entities 106 is further operative for: validating, by the SDP instance 112, the ownership assertionof the physical asset owner 102 after receiving the sensing request from the network node 114.[000123] According to other embodiments, the one or more network entities 106 is further operative for receiving, by the SDP instance 112, an attestation request originating from the physical asset owner 102 after obtaining the SDP instance and sending, by the SDP instance 112, SDP instance authenticity evidence to the physical asset owner 102 for attestation in response to the attestation request.[000124] According to other embodiments, determining of information of objects in the sensing data further comprises identifying object in the sensing data and filtering unauthorized object according to the ownership assertion of the physical asset owner 102.[000125] According to other embodiments, the generated encryption information comprises a cryptographic key pair which comprising a public key and a private key.[000126] According to other embodiments, a network node 114 of a mobile network 120 operative for processing sensing data is provided. The network node 114 of the mobile network 120 is arranged to communicate with one or more network entities 106 and at least one object sensing device 122 being operative for sensing physical object and performing wireless communication in the mobile network 120, the network node 114 comprising a processing circuitry 903 and a memory 904, said memory 904 containing instructions executable by said processing circuitry 903. The network node 114 is operative for receiving request for a sensing data processor, SDP, instance in the one or more network entities 106, the request for an SDP instance originating from a physical asset owner 102. The network node 114 is further operative for sending a request for an SDP instance to the one or more network entities 106, instructing the one or more network entities to obtain an SDP instance 112 in an enclave 110 of the one or more network entities 106, the enclave 110 being an isolated operating environment for the SDP instance 112. The network node 114 is further operative for sending an attestation request to the SDP instance 112 of the one or morenetwork entities 106 and validating the SDP instance 112 based on SDP instance authenticity evidence provided by the SDP instance 112, the SDP instance authenticity evidence comprises encryption information generated by the SDP instance 112. The network node 114 is further operative for sending a notification to the physical asset owner 102 notifying that the SDP instance 112 is ready to use and receiving a sensing request originating from the physical asset owner 102, the sensing request comprising an ownership assertion of the physical asset owner 102, the ownership assertion of the physical asset owner 102 comprises a physical asset owner 102 identity, identity of physical asset of the physical asset owner 102, and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirements of corresponding physical assets, the identity of physical assets of the physical asset owner 102 comprising geographic position of the physical asset. The network node 114 is further operative for sending a sensing request to the SDP instance 112 of the one or more network entities 106, the sensing request comprising the ownership assertion of the physical asset owner 102 and validating the identity of the physical asset owner 102 and the received 612 sensing request. The network node 114 is further operative for selecting 618 at least one object sensing device among the at least one object sensing devices 122 which being arranged to communicate with the network node 114 of the mobile network 120, based on the identity of physical asset of the physical asset owner 102, the physical asset being located in the vicinity of the selected at least one object sensing device and the selected at least one object sensing device being able to sense the physical asset. The network node 114 is further operative for sending a sensing request to each of the selected at least one object sensing device for instructing the selected at least one object sensing device to sense the object within the physical asset of the physical asset owner 102, and for instructing the selected at least one object sensing device to send sensing data to the one or more network entities 102, the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.[000127] According to other embodiments, the network node 114 is further operative for sending a notification to the SDP instance 112 of the one or morenetwork entities 106, notifying the sensing of object in progress, after sending the sensing request to each of the selected at least one object sensing device.[000128] According to other embodiments, referring to fig. 8, the network entity 106 may further comprise a communication unit 802, which may be considered to comprise conventional means for wireless communication with other devices, such as a transceiver for wireless transmission and reception of signals. The instructions executable by said processing circuitry 803 may be arranged as a computer program 805 stored e.g. in said memory 804. The processing circuitry 803 and the memory 804 may be arranged in a sub-arrangement 801 . The subarrangement 801 may be a micro-processor and adequate software and storage therefore, a Programmable Logic Device, PLD, or other electronic component(s) / processing circuit(s) configured to perform the methods mentioned above. The processing circuitry 803 may comprise one or more programmable processor, application-specific integrated circuits, field programmable gate arrays or combinations of these adapted to execute instructions.[000129] The computer program 805 may be arranged such that when its instructions are run in the processing circuitry, they cause network entity 106 to perform the steps described in any of the described embodiments of the network entity 106 and its method. The computer program 805 may be carried by a computer program product connectable to the processing circuitry 803. The computer program product may be the memory 804, or at least arranged in the memory. The memory 804 may be realized as for example a RAM (Randomaccess memory), ROM (Read-Only Memory) or an EEPROM (Electrical Erasable Programmable ROM). In some embodiments, a carrier may contain the computer program 805. The carrier may be one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or computer readable storage medium. The computer-readable storage medium may be e.g. a CD, DVD or flash memory, from which the program could be downloaded into the memory 804. Alternatively, the computer program may be stored on a server or any other entity to which the network entity 106 hasaccess via the communication unit 802. The computer program 805 may then be downloaded from the server into the memory 804.[000130] According to other embodiments, referring to fig. 9, the network node 114 may further comprise a communication unit 902, which may be considered to comprise conventional means for wireless communication with other devices, such as a transceiver for wireless transmission and reception of signals. The instructions executable by said processing circuitry 903 may be arranged as a computer program 905 stored e.g. in said memory 904. The processing circuitry 903 and the memory 904 may be arranged in a sub-arrangement 901 . The subarrangement 901 may be a micro-processor and adequate software and storage therefore, a Programmable Logic Device, PLD, or other electronic component(s) / processing circuit(s) configured to perform the methods mentioned above. The processing circuitry 903 may comprise one or more programmable processor, application-specific integrated circuits, field programmable gate arrays or combinations of these adapted to execute instructions.[000131] The computer program 905 may be arranged such that when its instructions are run in the processing circuitry, they cause network node 114 to perform the steps described in any of the described embodiments of the network node 114 and its method. The computer program 905 may be carried by a computer program product connectable to the processing circuitry 903. The computer program product may be the memory 904, or at least arranged in the memory. The memory 904 may be realized as for example a RAM (Randomaccess memory), ROM (Read-Only Memory) or an EEPROM (Electrical Erasable Programmable ROM). In some embodiments, a carrier may contain the computer program 905. The carrier may be one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or computer readable storage medium. The computer-readable storage medium may be e.g. a CD, DVD or flash memory, from which the program could be downloaded into the memory 904. Alternatively, the computer program may be stored on a server or any other entity to which the network node 114 hasaccess via the communication unit 902. The computer program 905 may then be downloaded from the server into the memory 904.[000132] Although the description above contains a plurality of specificities, these should not be construed as limiting the scope of the concept described herein but as merely providing illustrations of some exemplifying embodiments of the described concept. It will be appreciated that the scope of the presently described concept fully encompasses other embodiments which may become obvious to those skilled in the art, and that the scope of the presently described concept is accordingly not to be limited. Reference to an element in the singular is not intended to mean "one and only one" unless explicitly so stated, but rather "one or more." Further, the term “a number of”, such as in “a number of wireless devices” signifies one or more devices. All structural and functional equivalents to the elements of the above-described embodiments that are known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be encompassed hereby. Moreover, it is not necessary for an apparatus or method to address each and every problem sought to be solved by the presently described concept, for it to be encompassed hereby. In the exemplary figures, a broken line generally signifies that the feature within the broken line is optional.
Claims
CLAIMS1 . A method performed by one or more network entities (106), for processing sensing data, the one or more network entities (106) arranged to communicate with a network node (114) of a mobile network (120), the network node (114) arranged to communicate with at least one object sensing device (122), the at least one object sensing device (122) being operative for sensing a physical object (116) and for performing wireless communication in the mobile network (120), the method comprising: receiving (202) a request for a sensing data processor, SDP, instance in the one or more network entities (106), the request for SDP instance originating from a physical asset owner (102); obtaining (204), according to the request for SDP instance, an SDP instance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); generating (206), by the SDP instance (112), encryption information; receiving (208), by the SDP instance (112), a sensing request originating from the physical asset owner (102), the sensing request comprising an ownership assertion of the physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of a physical asset (118) of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating privacy requirement of the physical asset (118), the identity of the physical asset (118) of the physical asset owner (102) comprising a geographic position of the physical asset (118); sending (210), by the SDP instance (112), a sensing request to the network node (114), the sensing request comprising the physical asset owner (102) identity and the identity of the physical asset (118); receiving (230), by the SDP instance (112), an attestation request for the SDP instance (112) from the network node (114); sending (232), by the SDP instance (112), SDP instance authenticity evidence to the network node (114), the SDP instance authenticity evidence comprises the generated encryption information;receiving (212), by the SDP instance (112), sensing data from the object sensing device (122) in a connection encrypted by use of at least a part of the encryption information, the sensing data comprising sensing information that the sensing device (122) has obtained when sensing the physical object (116) in its vicinity; determining (214), by the SDP instance (112), information of the physical object (116) in the sensing data based on the received ownership assertion of the physical asset owner (102); and sending (216), by the SDP instance (112), the determined information of the physical object (116) to a communication device of the physical asset owner (102).
2. The method as claimed in claim 1 , the method comprises validating (218), by the SDP instance (112), the ownership assertion of the physical asset owner (102) after the receiving of the sensing request originating from the physical asset owner (102).
3. The method as claimed in claim 1 or 2, the method comprises receiving (220), by the SDP instance (112), a notification from the network node (114) , notifying that the sensing of the object (116) in progress, after the sending of the sensing request to the network node (114).
4. The method as claimed in any one of claims 1-3, the method comprises: receiving (222), by the SDP instance (112), an attestation request originating from the physical asset owner (102) after obtaining the SDP instance (112); and sending (224), by the SDP instance (112), SDP instance authenticity evidence to the physical asset owner (102) for attestation, in response to the received attestation request.
5. The method as claimed in any one of claims 1-4, the method comprises: receiving (226), by the SDP instance (112), sensing authorization information from the network node (114) after the sending of the sensing request to the network node (114), the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the at least one object sensing device (122) which is selected to perform sensing of the object, the cryptographic token indicating sensing instruction to the at least one object sensing device (122); sending (228), by the SDP instance (112), a sensing request to the selected at least one object sensing device (122), the sensing request comprises the cryptographic token.
6. The method as claimed in any one of claims 1-5, the determining of information of objects in the sensing data comprises: identifying object in the sensing data; filtering unauthorized object according to the ownership assertion of the physical asset owner (102).
7. The method as claimed in any one of the claims 1-6, the generated (206) encryption information comprises a cryptographic key pair which comprising a public key and a private key.
8. A method performed by a network node (114) of a mobile network (120) for processing sensing data, the network node (114) arranged to communicate with one or more network entities (106) and with at least one object sensing devices (122) that is operative for sensing a physical object (116) and for performing wireless communication in the mobile network (120), the method comprises: receiving (302) a sensing request originating from a sensing data processor, SDP, instance (112) of the one or more network entities (106), the sensing request comprising an identity of a physical asset (118) of a physicalasset owner (102) and the physical asset owner (102) identity, the identity of the physical asset (118) of the physical asset owner (102) comprising a geographic position of the physical asset (118); sending (310) an attestation request to the SDP instance (112) of the one or more network entities (106); validating (312) the SDP instance (112) based on SDP instance authenticity evidence provided by the SDP instance (112), the authenticity evidence comprises an encryption information; validating (304) the identity of the physical asset owner (102) and the received sensing request; selecting (306) at least one object sensing device among the at least one object sensing devices (122) arranged to communicate with the network node (114), based on the identity of the physical asset (118) of the physical asset owner (102), the physical asset (118) being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset (118); and sending (308) a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense object within the physical asset (118) of the physical asset owner (102), and for instructing the selected object sensing device to send sensing data to the one or more network entities (106), the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
9. The method as claimed in claim 8, the method comprises sending (314) a notification to the SDP instance (112) of the one or more network entities (106), notifying the sensing of object in progress, after sending the sensing request to each of the selected at least one object sensing device (122).
10. The method as claimed in any one of the claims 8-9, the method comprises: sending (316) sensing authorization information to the SDP instance (112) of the one or more network entities (106) after selecting the at least one object sensingdevice (122), the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the object sensing device which are selected to perform sensing of the object, the cryptographic token indicating sensing instruction to the selected object sensing device.
11. A method performed by one or more network entities (106), for processing sensing data, the one or more network entities (106) arranged to communicate with a network node (114) of a mobile network (120), the network node (114) arranged to communicate with at least one object sensing device (122), the object sensing device (122) being operative for sensing a physical object (116) and performing wireless communication in the mobile network (120), the method comprising: receiving (502) a request for sensing data processor, SDP instance in the one or more network entities (106), the request for SDP instance originating from the network node (114); obtaining (504), according to the request for SDP instance, an SDP instance (112) in a enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); generating (506), by the SDP instance (112), encryption information; receiving (508), by the SDP instance (112), an attestation request from the network node (114); sending (510), by the SDP instance (112), SDP instance authenticity evidence to the network node (114) for attestation, the SDP instance authenticity evidence comprises the generated encryption information; receiving (512), by the SDP instance (112), a sensing request from the network node (114), the sensing request comprising an ownership assertion of a physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement ofcorresponding physical asset, the identity of physical asset of the physical asset owner (102) comprising geographic position of the physical asset; receiving (516), by the SDP instance (112), sensing data from the object sensing device (122) in a connection encrypted by use of at least a part of the generated encryption information, the sensing data comprising sensing information that the at least one sensing device (122) has obtained when sensing the physical object (116) in its vicinity; determining (518), by the SDP instance (112), information of the physical object (116) in the sensing data based on the received ownership assertion of the physical asset owner (102); and sending (520), by the SDP instance (112), the determined (518) information of the physical object (116) to the physical asset owner (102).
12. The method as claimed in claim 11 , the method comprises receiving (522), by the SDP instance (112), a notification from the network node (114), notifying the sensing of object in progress, after receiving the sensing request from the network node (114).
13. The method as claimed in claim 11 or 12, the method comprises validating (514), by the SDP instance (112), the ownership assertion of the physical asset owner (102) after receiving the sensing request from the network node (114).
14. The method as claimed in any one of the claims 11-13, the method comprises: receiving (524), by the SDP instance (112), an attestation request originating from the physical asset owner (102) after obtaining the SDP instance; and sending (526), by the SDP instance (112), SDP instance authenticity evidence to the physical asset owner (102) for attestation in response to the attestation request.
15. The method as claimed in any one of claims 11-14, the determining (518) of information of object in the sensing data comprises: identifying object in the sensing data; filtering unauthorized object according to the ownership assertion of the physical asset owner (102).
16. The method as claimed in any one of the claims 11-15, the generated (506) encryption information comprises a cryptographic key pair which comprising a public key and a private key.
17. A method performed by a network node (114) of a mobile network (120) for processing sensing data, the network node (114) arranged to communicate with one or more network entities (106) and at least one object sensing device (122) being operative for sensing physical object and performing wireless communication in the mobile network (120), the method comprises: receiving (602) a request for a sensing data processor, SDP, instance in the one or more network entities (106), the request for an SDP instance originating from a physical asset owner (102); sending (604) a request for an SDP instance to the one or more network entities (106), instructing the one or more network entities to obtain an SDP instance (112) in a enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); sending (606) an attestation request to the SDP instance (112) of the one or more network entities (106); validating (608) the SDP instance (112) based on SDP instance authenticity evidence provided by the SDP instance (112), the SDP instance authenticity evidence comprises encryption information generated by the SDP instance (112); sending (610) a notification to the physical asset owner (102) notifying that the SDP instance (112) is ready to use;receiving (612) a sensing request originating from the physical asset owner (102), the sensing request comprising an ownership assertion of the physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner (102) comprising geographic position of the physical asset; sending (614) a sensing request to the SDP instance (112) of the one or more network entities (106), the sensing request comprising the ownership assertion of the physical asset owner (102); validating (616) the identity of the physical asset owner (102) and the received (612) sensing request; selecting (618) at least one object sensing device among the at least one object sensing devices (122) which being arranged to communicate with the network node (114) , based on the identity of physical asset of the physical asset owner (102), the physical asset being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset; and sending (620) a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense the object within the physical asset of the physical asset owner (102), and for instructing the selected object sensing device to send sensing data to the one or more network entities (102), the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
18. The method according to the claim 17, the method comprises sending (622) a notification to the SDP instance (112) of the one more network entities (106), notifying the sensing of object in progress, after sending the sensing request to each of the selected object sensing device.
19. One or more network entities (106) operative for processing sensing data, the one or more network entities (106) arranged to communicate with a network node (114) of a mobile network (120), the network node (114) arranged to communicate with at least one object sensing device (122), the at least one object sensing device (122) being operative for sensing physical objects and for performing wireless communication in the mobile network (120), the one or more network entities (106) comprising a processing circuitry (803) and a memory (804), said memory (804) containing instructions executable by said processing circuitry (803), whereby the one or more network entities (106) is operative to: receive a request for a sensing data processor, SDP, instance in the one or more network entities (106), the request for SDP instance originating from a physical asset owner (102); obtain, according to the request for SDP instance, an SDP instance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); generate, by the SDP instance (112), encryption information; receive, by the SDP instance (112), a sensing request originating from the physical asset owner (102), the sensing request comprising an ownership assertion of the physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of a physical asset (118) of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating privacy requirement of the physical asset (118), the identity of the physical asset (118) of the physical asset owner (102) comprising a geographic position of the physical asset (118); send, by the SDP instance (112), a sensing request to the network node (114), the sensing request comprising the physical asset owner (102) identity and the identity of the physical asset (118); receive, by the SDP instance (112), an attestation request for the SDP instance (112) from the network node (114);send, by the SDP instance (112), SDP instance authenticity evidence to the network node (114), the SDP instance authenticity evidence comprises the generated encryption information; receive, by the SDP instance (112), sensing data from the at least one object sensing device (122) in a connection encrypted by use of at least part of the encryption information, the sensing data comprising sensing information that the sensing device (122) has obtained when sensing the physical object (116) in its vicinity; determine, by the SDP instance (112), information of the physical object (116) in the sensing data based on the received ownership assertion of the physical asset owner (102); send, by the SDP instance (112), the determined information of the physical object (116) to a communication device of the physical asset owner (102).
20. The one or more network entities (106) as claimed in claim 19, the one or more network entities (106) is operative to validate, by the SDP instance (112), the ownership assertion of the physical asset owner (102) after the receiving of the sensing request originating from the physical asset owner (102).21 . The one or more network entities (106) as claimed in the claim 19 or 20, the one or more network entities (106) is operative to receive, by the SDP instance (112), a notification from the network node (114), notifying that the sensing of the object (116) in progress, after the sending of the sensing request to the network node (114).
22. The one or more network entities (106) as claimed in any one of the claims 19-21 , the one or more network entities (106) is operative to: receive, by the SDP instance (112), an attestation request originating from the physical asset owner (102) after obtaining the SDP instance (112); andsend, by the SDP instance (112), SDP instance authenticity evidence to the physical asset owner (102) for attestation, in response to the received attestation request.
23. The one or more network entities (106) as claimed in any one of claims 19-22, wherein the one or more network entities (106) is operative to: receive, by the SDP instance (112), sensing authorization information from the network node (114) after the sending of the sensing request to the network node (114), the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the at least one object sensing device (122) which is selected to perform sensing of the object, the cryptographic token indicating sensing instruction to the at least one object sensing device (122); send, by the SDP instance (112), a sensing request to the selected at least one object sensing device (122), the sensing request comprises the cryptographic token.
24. The one or more network entities (106) as claimed in any one of claims 19-23, the determining of information of objects in the sensing data comprises: identifying object in the sensing data; and filtering unauthorized object according to the ownership assertion of the physical asset owner (102).
25. The one or more network entities (106) as claimed in any one of the claims 19-24, wherein the generated encryption information comprises a cryptographic key pair which comprising a public key and a private key.
26. A network node (114) of a mobile network (120) operative for processing sensing data, the network node (114) arranged to communicate with one or more network entities (106) and with at least one object sensing devices (122) that is operative for sensing a physical object (116) and for performingwireless communication in the mobile network (120), the network node (114) comprising a processing circuitry (903) and a memory (904), said memory (904) containing instructions executable by said processing circuitry (903), whereby the network node (114) is operative to: receive a sensing request originating from a sensing data processor, SDP, instance (112) of the one or more network entities (106), the sensing request comprising an identity of a physical asset (118) of a physical asset owner (102) and the physical asset owner (102) identity, the identity of the physical asset (118) of the physical asset owner (102) comprising a geographic position of the physical assets (118); send an attestation request to the SDP instance (112) of the one or more network entities (106); validate the SDP instance based on SDP instance authenticity evidence provided by the SDP instance (112), the authenticity evidence comprises encryption information; validate the identity of the physical asset owner (102) and the received sensing request; select at least one object sensing device among the at least one object sensing devices (122) arranged to communicate with the network node (114), based on the identity of the physical asset (118) of the physical asset owner (102), the physical asset (118) being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset (118); and send a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense object within the physical asset (118) of the physical asset owner (102), and for instructing the selected object sensing device to send sensing data to the one or more network entities (106), the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
27. The network node (114) as claimed in claim 26, the network node (114) is operative tosend a notification to the SDP instance (112) of the one or more network entities (106), notifying the sensing of object in progress, after sending the sensing request to each of the selected at least one object sensing device (122).
28. The network node (114) as claimed in any one of the claims 26-27, the network node (114) is operative to: send sensing authorization information to the SDP instance (112) of the one or more network entities (106) after selecting the at least one object sensing device (122), the sensing authorization information comprises selected object sensing device information and a cryptographic token, the selected object sensing device information relates to the object sensing device which are selected to perform sensing of the object, the cryptographic token indicating sensing instruction to the selected object sensing device.
29. One or more network entities (106) operative for processing sensing data , the one or more network entities (106) arranged to communicate with a network node (114) of a mobile network (120), the network node (114) arranged to communicate with at least one object sensing device (122), the object sensing device (122) being operative for sensing a physical object (116) and performing wireless communication in the mobile network (120), the one or more network entities (106) comprising a processing circuitry (803) and a memory (804), said memory (804) containing instructions executable by said processing circuitry (803), whereby the one or more network entities (106) is operative to: receive a request for sensing data processor, SDP instance in the one or more network entities (106), the request for SDP instance originating from the network node (114); obtain, according to the request for SDP instance, an SDP instance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); generate, by the SDP instance (112), encryption information; receive, by the SDP instance (112), an attestation request from the network node (114);send, by the SDP instance (112), SDP instance authenticity evidence to the network node (114) for attestation, the SDP instance authenticity evidence comprises the generated encryption information; receive, by the SDP instance (112), a sensing request from the network node (114), the sensing request comprising an ownership assertion of a physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner (102) comprising geographic position of the physical asset; receive, by the SDP instance (112), sensing data from the at least one object sensing device (122) in a connection encrypted by use of at least part of the generated encryption information, the sensing data comprising sensing information that the at least one sensing device (122) has obtained when sensing the physical object (116) in its vicinity; determine, by the SDP instance (112), information of the physical object (116) in the sensing data based on the received ownership assertion of the physical asset owner (102); and send, by the SDP instance (112), the determined information of the physical object (116) to a communication device of the physical asset owner (102).
30. The one or more network entities (106) as claimed in claims 29, the one or more network entities (106) is operative to receive, by the SDP instance (112), a notification from the network node (114), notifying the sensing of object in progress, after receiving the sensing request from the network node (114).31 . The one or more network entities (106) as claimed in claim 29 or 30, the one or more network entities (106) is operative to validate, by the SDP instance (112), the ownership assertion of the physical asset owner (102) after receiving the sensing request from the network node (114).
32. The one or more network entities (106) as claimed in any one of the claims 29-31 , the one or more network entities (106) is operative to receive, by the SDP instance (112), an attestation request originating from the physical asset owner (102) after obtaining the SDP instance; and send, by the SDP instance (112), SDP instance authenticity evidence to the physical asset owner (102) for attestation in response to the attestation request.
33. The one or more network entities (106) as claimed in any one of claims 29-32, determining of information of objects in the sensing data comprises: identify object in the sensing data; filter unauthorized objects according to the ownership assertion of the physical asset owner (102).
34. The one or more network entities (106) as claimed in any one of the claims 29-33, the generated encryption information comprises a cryptographic key pair which comprising a public key and a private key.
35. A network node (114) of a mobile network (120) operative for processing sensing data, the network node (114) arranged to communicate with one or more network entities (106) and at least one object sensing device (122) being operative for sensing physical object and performing wireless communication in the mobile network (120), the network node (114) comprising a processing circuitry (903) and a memory (904), said memory (904) containing instructions executable by said processing circuitry (903), whereby the network node (114) is operative to: receive request for a sensing data processor, SDP, instance in the one or more network entities (106), the request for an SDP instance originating from a physical asset owner (102); send a request for an SDP instance to the one or more network entities (106), instructing the one or more network entities to obtain an SDPinstance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); send an attestation request to the SDP instance (112) of the one or more network entities (106); validate the SDP instance (112) based on SDP instance authenticity evidence provided by the SDP instance (112), the SDP instance authenticity evidence comprises encryption information generated by the SDP instance (112); send a notification to the physical asset owner (102) notifying that the SDP instance (112) is ready to use; receive a sensing request originating from the physical asset owner (102), the sensing request comprising an ownership assertion of the physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner (102) comprising a geographic position of the physical asset; send a sensing request to the SDP instance (112) of the one or more network entities (106), the sensing request comprising the ownership assertion of the physical asset owner (102); validate the identity of the physical asset owner (102) and the received (612) sensing request; select at least one object sensing device among the at least one object sensing devices (122) which being arranged to communicate with the network node (114), based on the identity of physical asset of the physical asset owner (102), the physical asset being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset; and send a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense the object within the physical asset of the physical asset owner (102), and for instructing the selected object sensing device to send sensing data to the one or more network entities(102), the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
36. The network node (114) according to the claim 35, wherein network node (114) is operative to send a notification to the SDP instance (112) of the one or more network entities (106), notifying the sensing of object in progress, after sending the sensing request to each of the selected object sensing device.
37. A computer program (805) comprising instructions, which, when executed by one or more network entities (106), for processing sensing data, the one or more network entities (106) arranged to communicate with a network node (114) of a mobile network (120), the network node (114) arranged to communicate with at least one object sensing device (122), the at least one object sensing device (122) being operative for sensing a physical object (116) and for performing wireless communication in the mobile network (120), causes the one or more network entities (106) to: receive a request for a sensing data processor, SDP, instance in the one or more network entities (106), the request for SDP instance originating from a physical asset owner (102); obtain, according to the request for SDP instance, an SDP instance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); generate, by the SDP instance (112), encryption information; receive, by the SDP instance (112), a sensing request originating from the physical asset owner (102), the sensing request comprising an ownership assertion of the physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of a physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating privacy requirement of corresponding physical asset, the identity of the physicalasset of the physical asset owner (102) comprising a geographic position of the physical asset (118); send, by the SDP instance (112), a sensing request to the network node (114), the sensing request comprising the physical asset owner (102) identity and the identity of the physical asset (118); receive, by the SDP instance (112), an attestation request for the SDP instance (112) from the network node (114); send, by the SDP instance (112), SDP instance authenticity evidence to the network node (114), the SDP instance authenticity evidence comprises the generated encryption information; receive, by the SDP instance (112), sensing data from the object sensing device (122) in a connection encrypted with the generated encryption information, the sensing data comprising sensing information that the sensing device (122) has obtained when sensing the physical object (116) in its vicinity; determine, by the SDP instance (112), information of the object (116) in the sensing data based on the received ownership assertion of the physical asset owner (102); send, by the SDP instance (112), the determined information of the physical object (116) to a communication device of the physical asset owner (102).
38. A computer program (905) comprising instructions, which, when executed by a network node (114) of a mobile network (120) for processing sensing data, the network node (114) arranged to communicate with one or more network entities (106) and with at least one object sensing devices (122) that is operative for sensing a physical object (116) and for performing wireless communication in the mobile network (120), causes the network node (114) to: receive a sensing request originating from a sensing data processor, SDP, instance (112) of the one or more network entities (106), the sensing request comprising an identity of a physical asset (118) of a physical asset owner (102) and the physical asset owner (102) identity, the identity of physical asset of the physical asset owner (102) comprising a geographic position of the physical assetsend an attestation request to the SDP instance (112) of the one or more network entities (106); validate the SDP instance based on SDP instance authenticity evidence provided by the SDP instance (112), the authenticity evidence comprises encryption information; validate the identity of the physical asset owner (102) and the received (302) sensing request; select at least one object sensing device among the at least one object sensing devices (122) arranged to communicate with the network node (114), based on the identity of the physical asset (118) of the physical asset owner (102), the physical asset (118) being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset (118); send a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense object within the physical asset (118) of the physical asset owner (102), and for instructing the selected object sensing device to send sensing data to the one or more network entities (106), the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.
39. A computer program (805) comprising instructions, which, when executed by one or more network entities (106) for processing sensing data, the one or more network entities (106) arranged to communicate with a network node (114) of a mobile network (120), the network node (114) arranged to communicate with at least one object sensing device (122), the object sensing device (122) being operative for sensing a physical object (116) and performing wireless communication in the mobile network (120), causes the one or more network entities (106) to: receive a request for sensing data processor, SDP instance in the one or more network entities (106), the request for SDP instance originating from the network node (114);obtain, according to the request for SDP instance, an SDP instance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); generate, by the SDP instance (112), encryption information; receive, by the SDP instance (112), an attestation request from the network node (114); send, by the SDP instance (112), SDP instance authenticity evidence to the network node (114) for attestation, the SDP instance authenticity evidence comprises the generated encryption information; receive, by the SDP instance (112), a sensing request from the network node (114), the sensing request comprising an ownership assertion of a physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of a physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policies indicating the privacy requirement of corresponding physical asset, the identity of physical asset of the physical asset owner (102) comprising position of the physical asset; receive, by the SDP instance (112), sensing data from the object sensing device (122) in a connection encrypted by user of at least a part of the generated encryption information, the sensing data comprising sensing information that the at least one sensing device (122) has obtained when sensing the physical object in its vicinity; determine, by the SDP instance (112), information of the physical object (116) in the sensing data based on the received ownership assertion of the physical asset owner (102); send, by the SDP instance (112), the determined (518) information of the physical object (116) to the physical asset owner (102).
40. A computer program (905) comprising instructions, which, when executed by a network node (114) of a mobile network (120) for processing sensing data, the network node (114) arranged to communicate with one or more network entities (106) and at least one object sensing device (122) being operativefor sensing physical object and performing wireless communication in the mobile network (120), causes the network node (114) to: receive a request for a sensing data processor, SDP, instance in the one or more network entities (106), the request for an SDP instance originating from a physical asset owner (102); send a request for an SDP instance to the one or more network entities (106), instructing the one or more network entities to obtain an SDP instance (112) in an enclave (110) of the one or more network entities (106), the enclave (110) being an isolated operating environment for the SDP instance (112); send an attestation request to the SDP instance (112) of the one or more network entities (106); validate the SDP instance (112) based on SDP instance authenticity evidence provided by the SDP instance (112), the SDP instance authenticity evidence comprises encryption information generated by the SDP instance (112); send a notification to the physical asset owner (102) notifying that the SDP instance (112) being ready to use; receive a sensing request originating from the physical asset owner (102), the sensing request comprising an ownership assertion of the physical asset owner (102), the ownership assertion of the physical asset owner (102) comprises a physical asset owner (102) identity, identity of a physical asset of the physical asset owner (102), and related physical asset owner privacy policy, the physical asset owner privacy policy indicating the privacy requirement of corresponding physical asset, the identity of the physical asset of the physical asset owner (102) comprising a geographic position of the physical asset; send a sensing request to the SDP instance (112) of the one or more network entities (106), the sensing request comprising the ownership assertion of the physical asset owner (102); validate the identity of the physical asset owner (102) and the received (612) sensing request; select at least one object sensing device among the at least one object sensing devices (122) which being arranged to communicate with the network node (114), based on the identity of physical asset of the physical assetowner (102), the physical asset being located in the vicinity of the selected object sensing device and the selected object sensing device being able to sense the physical asset; and send a sensing request to each of the selected object sensing device for instructing the selected object sensing device to sense the object within the physical asset of the physical asset owner (102), and for instructing the selected object sensing device to send sensing data to the one or more network entities (102), the sensing request comprising the encryption information with which the sensing data is encrypted when being sent.41 . A carrier containing the computer program (805) according to claim 37 or 39, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, an electric signal, or a computer readable storage medium (804).
42. A carrier containing the computer program (905) according to claim 38 or 40, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, an electric signal, or a computer readable storage medium (904).
Citation Information
Patent Citations
Sensing systems, methods, and apparatus in wireless communication networks
US20230328683A1