Devices and methods for an ambient internet of things

A cryptographic key-based authentication mechanism for AIoT devices addresses activation and data transmission challenges, ensuring secure and efficient communication by authorizing only legitimate activators and encrypting data, thus enhancing network reliability.

WO2025162664A1PCT designated stage Publication Date: 2025-08-07NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/087788
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-01
Filing Date
2024-12-20
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing ambient internet of things (AIoT) devices, which are often battery-less or have limited energy storage, face challenges in secure activation and data transmission due to their reliance on energy harvesting, leading to inefficiencies in communication and authentication processes.

Method used

Implementing a cryptographic key-based authentication mechanism that involves receiving challenges and responses, determining activation authorization based on cryptographic keys, and encrypting data to ensure secure and efficient communication between AIoT devices and network entities.

Benefits of technology

Enhances the security and efficiency of activating and transmitting data from AIoT devices by ensuring only authorized activators can activate and decrypt the data, thereby improving the reliability and integrity of AIoT networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024087788_07082025_PF_FP_ABST
    Figure EP2024087788_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Devices (100, 200, 300) and methods for an ambient internet of things, a first method comprising receiving (410) a challenge, an authentication response, and an expected response, wherein the challenge is associated with a network entity (300), wherein the authentication response is associated with an activator (200), wherein the expected response is associated with an ambient internet of things device (100), determining (412) a response depending on the challenge, a cryptographic key, and the authentication response, wherein the cryptographic key is associated with the ambient internet of things device (100) and the network entity (300), and authorizing (414) or deny authorizing the activator (200) to activate the ambient internet of things device (100) depending on a result of a comparison of the response and the expected response.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DEVICES AND METHODS FOR AN AMBIENT INTERNET OF THINGS

[0002] Specification

[0003] Field of the disclosure

[0004] Various examples relate to devices and method for an ambient internet of things.

[0005] Background

[0006] An ambient internet of things (AIoT) is an internet of things (loT) communication network that comprises AIoT devices. An AIoT device is an ambient powered device, e.g., by energy harvesting. The AIoT device may either be battery-less or with limited energy storage capability, e.g., using a capacitor.

[0007] The AIoT device may be used for gathering information. The AIoT device can be equipped with a sensor for gathering the information.

[0008] User equipment (UE) can be used to collect and store the information from the AIoT device before forwarding this information to the communication network.

[0009] Summary

[0010] A first method, wherein the first method comprises receiving a challenge, an authentication response, and an expected response , wherein the challenge is associated with a network entity, wherein the authentication response is associated with an activator, wherein the expected response is associated with an ambient internet of things device , determining a response depending on the challenge , a cryptographic key, and the authentication response , wherein the cryptographic key is associated with the ambient internet of things device and the network entity, and authori zing or deny authori zing the activator to activate the ambient internet of things device depending on a result of a comparison of the response and the expected response .

[0011] According to some examples , the first method comprises activating or deny activating the ambient internet of things device depending on the result .

[0012] According to some examples , the first method comprises sending the result to the activator or the information to a reader .

[0013] According to some examples , the first method comprises encrypting the result with the cryptographic key, and sending the encrypted result to the activator, or encrypting the information and sending the encrypted information to a reader .

[0014] According to some examples , the first method comprises determining a value of a sequence number , and determining the response depending on the value of the sequence number .

[0015] According to some examples , the first method first method comprises receiving a message authentication code for integrity, determining an expected message authentication code for integrity depending on the cryptographic key and the response , and authori zing or deny authori zing the activator depending on a result of a comparison of the expected message authentication code for integrity and the message authentication code for integrity .

[0016] A second method, wherein the second method comprises receiving a challenge , and an expected response , wherein the expected response is associated with an ambient internet of things device , determining an authentication response depending on the challenge and a cryptographic key, wherein the authentication response is associated with an activator, wherein the cryptographic key is associated with the activator and a network entity, and sending the challenge , the authentication response , and the expected response to the ambient internet of things device .

[0017] According to some examples , the second method comprises receiving a message authentication code for integrity, and sending the message authentication code for integrity, wherein the message authentication code for integrity is associated with the expected response . A third method, wherein the third method comprises determining an expected response depending on a challenge , a cryptographic key , and an expected authentication response , and sending the challenge , and the expected response to an activator, wherein the expected response is associated with an ambient internet of things device , wherein the cryptographic key is associated with the ambient internet of things device and a network entity, and wherein the expected authentication response is associated with the activator .

[0018] According to some examples , the third method comprises receiving an identi fication of the ambient internet of things device and an identi fication of the activator, and authori zing or deny authori zing the activator depending on the identi fications .

[0019] According to some examples , the third method comprises determining a value of a sequence number, and determining the expected response depending on the value of the sequence number .

[0020] According to some examples , the third method comprises determining a message authentication code for integrity depending on the cryptographic key and the expected response , and sending the message authentication code for integrity . According to some examples , the third method comprises determining the expected authentication response depending on a cryptographic key that is associated with the activator and the network entity .

[0021] According to some examples , the third method comprises receiving an encrypted information, and accepting the information only when decrypting the information with the cryptographic key is success ful .

[0022] A first device , wherein the first device comprises means for providing information, wherein the first device comprises means for receiving challenge , an authentication response , and an expected response , wherein the challenge is associated with a network entity, wherein the authentication response is associated with an activator, wherein the expected response is associated with the first device , wherein the first device comprises means for determining a response depending on the challenge , a cryptographic key, and the authentication response , wherein the cryptographic key is associated with the first device and the network entity, and wherein the first device comprises means for authori zing or deny authori zing the activator to activate the ambient internet of things device depending on a result of a comparison of the response and the expected response .

[0023] According to some examples , the first device comprises means for activating or deny activating the first device According to some examples , the first device comprises means for sending the result to the activator or the information to a reader .

[0024] According to some examples , the first device comprises means for encrypting the result with the cryptographic key, and means for sending the encrypted result to the activator or means for encrypting the information with the cryptographic key and means for sending the encrypted information to a reader .

[0025] According to some examples , the first device comprises means for determining a value of a sequence number, and means for determining the response depending on the value of the sequence number .

[0026] According to some examples , the first device comprises means for receiving a message authentication code for integrity, wherein the first device comprises means for determining an expected message authentication code for integrity depending on the cryptographic key and the response , and wherein the first device comprises means for authori zing or deny authori zing the activator depending on a result of a comparison of the expected message authentication code for integrity and the message authentication code for integrity .

[0027] A second device , wherein the second device comprises allenge , and an expected response , wherein the expected response is associated with an ambient internet of things device , wherein the second device comprises means for determining an authentication response depending on the challenge and a cryptographic key, wherein the authentication response is associated with the second device , wherein the cryptographic key is associated with the second device and a network entity, and wherein the second device comprises means for sending the challenge , the authentication response , and the expected response to the ambient internet of things device .

[0028] According to some examples , the second device comprises means for receiving a message authentication code for integrity, and wherein the second device comprises means for sending the message authentication code for integrity, wherein the message authentication code for integrity is associated with the expected response .

[0029] A third device , wherein the third device comprises means for determining an expected response depending on a challenge , a cryptographic key, and an expected authentication response , and wherein the third device comprises means for sending the challenge , and the expected response to an activator, wherein the expected response is associated with an ambient internet of things device , wherein the cryptographic key is associated with the ambient internet of things device and the third device , and wherein the expected authentication response is associated with the activator . According to some examples , the third device comprises means for receiving an identi fication of the ambient internet of things device and an identi fication of the activator, and wherein the third device comprises means for authori zing or deny authori zing the activator depending on the identi fications .

[0030] According to some examples , the third device comprises means for determining a value of a sequence number, and wherein the third device comprises means for determining the expected response depending on the value of the sequence number .

[0031] According to some examples , the third device comprises means for determining a message authentication code for integrity depending on the cryptographic key and the expected response , and wherein the third device comprises means for sending the message authentication code for integrity .

[0032] According to some examples , the third device comprises means for determining the expected authentication response depending on a cryptographic key that is associated with the activator and the network entity .

[0033] According to some examples , the third device comprises means for receiving an encrypted information, and accepting the information only when decrypting the information with the cryptographic key that is associated with the ambient internet of things device is successful .

[0034] A computer program comprising instructions, which, when executed by a device, cause the device to at least perform the first method, the second method, or the third method .

[0035] Brief description of the figures

[0036] Fig. 1 schematically depicts a first device according to a first example,

[0037] Fig. 2 schematically depicts a second device according to the first example,

[0038] Fig. 3 schematically depicts a third device according to the first example,

[0039] Fig. 4 depicts a sequence diagram according to the first example,

[0040] Fig. 5 schematically depicts the first device according to a second example,

[0041] Fig. 6 schematically depicts the third device according to the second example,

[0042] Fig. 7 depicts a sequence diagram according to the second example,

[0043] Fig. 8 schematically depicts the first device according to a third example,

[0044] Fig. 9 schematically depicts the second device according to the third example,

[0045] Fig. 10 schematically depicts the third device according to the third example, Fig . 11 depicts a sequence diagram according to the third example .

[0046] Description of the embodiments

[0047] In an AIoT network, an activator may be used to activate an AIoT device . The activator may be user equipment (UE ) or universal subscriber identity module (US IM) .

[0048] The AIoT may be used to gather information and to send the information to a reader in the network . The reader may be used to forward the information to a network entity in the network .

[0049] The network entity is for example a home environment authentication centre (HE / AuC ) or a uni fied data management (UDM) .

[0050] The AIoT device may be configured for activation by an authenticated activator . The AIoT device may be configured for activation by an authori zed activator .

[0051] The activator may be configured to request from the network entity authentication or authori zation to activate the AIoT device .

[0052] The network entity may be configured to authenticate or authori ze the activator to activate the AIoT device . The AIoT device may be configured for sending the information to the reader upon success ful authentication or authori zation of the activator .

[0053] The reader may be configured to receive the information and to send the information to the network entity .

[0054] The network entity and the activator are associated to a cryptographic key K .

[0055] The AIoT device and the network entity are associated to a cryptographic key KAIoT .

[0056] Figure 1 schematically depicts an AIoT device 100 according to a first example .

[0057] The AIoT device 100 comprises a sensor 102 for providing information 104 .

[0058] The sensor 102 may be configured for measuring a physical quantity . The power source may comprise a limited power storage , e . g . , a capacitor .

[0059] The receiver 106 is configured for receiving a challenge 108 , an authentication response 110 , and an expected response 112 .

[0060] The challenges 108 is for example a random challenge (RAND) . The authentication response 110 is for example a user response (RES ) .

[0061] The expected response 112 is for example an expected AIoT response (XRESAIoT ) .

[0062] The challenge 108 is associated with a network entity .

[0063] The authentication response 110 is associated with an activator .

[0064] The expected response 112 is associated with the AIoT device 100 .

[0065] The AIoT device 100 comprises a cryptographic function 114 for determining a response 116 depending on the challenge 108 , the authentication response 110 , and a cryptographic key 118 that is associated with the AIoT device 100 and the network entity .

[0066] The AIoT device 100 may comprise a storage 120 for the cryptographic key 118 . The cryptographic key 118 in the example is the cryptographic key KAIoT that is associated with the AIoT device 100 and the network entity .

[0067] The response 116 is the response RESAIoT of the AIoT device 100 to the random challenge RAND that i s determined with the cryptographic function 114 . The AIoT device 100 comprises a function 122 that i s configured for authori zing or deny authori zing the activator to activate the AIoT device 100 depending on a result of a comparison of the response 116 and the expected response 112 .

[0068] The AIoT device 100 comprises a sender 124 .

[0069] The sender 124 is configured for sending the result to the activator . The sender 124 i s configured for sending the information to the reader .

[0070] The function 122 may be configured for encrypting the result with the cryptographic key 118 .

[0071] The function 122 may be configured for encrypting the information with the cryptographic key 118 .

[0072] The sender 124 may be configured for sending the encrypted result to the activator .

[0073] The sender 124 may be configured for sending the encrypted information to the reader .

[0074] The receiver 106 may be configured for li stening to the network .

[0075] The AIoT device 100 may have di f ferent kinds o f communication pattern that may be dependent on power available for communication . The AIoT device 100 for comprises a power source that is configured for harvesting ambient power for operating the AIoT device 100, and a processor for operating the sensor 102 and the communications module 106.

[0076] The power available for communication may be dependent on harvesting or the availability of power storage capability or a use case.

[0077] In a first operation pattern, the AIoT device 100 may have power available continuously or at least for significant amounts of time, for example, because there is continuous power harvesting, in particular in combination with limited storage capability, e.g. a capacitor, that is sufficiently large to overcome momentary variations in power harvesting.

[0078] An effect of the first operation pattern is that the processor and communications module in the AIoT device 100 can be continuously active. The communications module can listen to the network, e.g., at regular intervals to determine if there is mobile terminated traffic, e.g., trigger messages, and can transmit the information when relevant.

[0079] In a second operation pattern, the AIoT device 100 may have power available only intermittently. An effect of the second operation pattern is that the AIoT device 100 can only be active for short periods of time, and the AIoT device 100 decides when to communicate with the network. The AIoT device 100 is not able to listen to the network for mobile terminated traffic when it has no power available.

[0080] In a third operation pattern, the AIoT device 100 may be configured for on demand operation.

[0081] According to the third operation pattern, the network may wake up and trigger the AIoT device 100 to communicate . An effect of the third operation pattern is that the network triggers the communication.

[0082] In the third operation pattern, the AIoT device 100 may or may not be configured to also determine when to communicate.

[0083] Waking up of the AIoT device 100 may be combined with a trigger to perform a specific action of the AIoT device 100. The specific action may comprise providing the information, e.g., doing a measurement, or communicating, e.g., sending the information or an identifier of the AIoT device 100. Waking up may also imply that the AIoT device 100 starts listening to the network for further instructions. Figure 2 schematically depicts an activator 200 according to the first example.

[0084] The activator 200 may be provided by a UE or USIM.

[0085] The activator 200 comprises a receiver 202.

[0086] The receiver 202 is configured for receiving the challenge 108, e.g., RAND.

[0087] The receiver 202 is configured for receiving the expected response 110, e.g., XRESAIoT.

[0088] The expected response 112, e.g., XRESAIoT, is associated with the AIoT device 100.

[0089] The activator 200 comprises a cryptographic function 204for determining an authentication response 110, e.g., RES, that is associated with the activator 200, depending on the challenge 108, e.g., RAND, and a cryptographic key 206 that is associated with the activator 200 and the network entity. The activator 200 may comprise a storage 208 for the cryptographic key 206. The cryptographic key 206 in the example is the cryptographic key K that is associated with the activator 200 and the network entity.

[0090] The activator 200 comprises a sender 210 for sending the challenge 108, e.g., RAND, the authentication response 110, e.g., RES, and the expected response 112, e.g., XRESAIoT, to the AIoT device 100.

[0091] Figure 3 schematically depicts a network entity 300 according to the first example.

[0092] The network entity 300 may be a HE / AuC or UDM.

[0093] The network entity 300 comprises a receiver 302.

[0094] The receiver 302 is configured for receiving an identification 304, e.g., AIoT ID, of the AIoT device 100, and an identification 306, e.g., SUCI or 5G-GUTI, of the activator 200.

[0095] According to an example, the receiving the identification 304, e.g., AIoT ID, of the AIoT device 100, and the identification 306, e.g., SUCI or 5G-GUTI, of the activator 200, represents a request for authentication or authorization of the activator 200 to activate the AIoT device 100.

[0096] The receiver 302 may be configured for receiving an encrypted information, and accepting the information only when decrypting the information with the cryptographic key 118, e.g., KAIoT, that is associated with the AIoT device 100 is successful.

[0097] The network entity 300 comprises a function 308 for authorizing or deny authorizing the activator 200 depending on the identifications 304, 306. The network entity 300 comprises a function 310 for determining the expected authentication response 312, e.g., XRES, depending on the cryptographic key 206, e.g., K, that is associated with the activator 200 and the network entity 300.

[0098] The network entity 300 comprises a cryptographic function 314 for determining the expected response 112, e.g., XRESAIoT, that is associated with the AIoT device 100, depending on the challenge 108, e.g., RAND, the cryptographic key 118, e.g., KAIoT, that is associated with the AIoT device 100 and the network entity 300, and the expected authentication response 312, e.g., XRES, that is associated with the activator 200.

[0099] The third device 300 comprises a sender 316.

[0100] The sender 316 is configured for sending the challenge 108, e.g., RAND, and the expected response 112, e.g., XRESAIoT, that is associated with the AIoT device 100, to the activator 200.

[0101] Figure 4 depicts a sequence diagram according to the first example.

[0102] In a step 402, the identification AIoT ID of the AIoT device 100, and the identification SUCI or 5G-GUTI of the activator 200 are sent from the activator 200 to the network entity 300. In a step 404 the network entity 300 authori zes or denies authori zing the activator 200 depending on the identi fications .

[0103] In a step 406 the challenge RAND, and the expected response XRESAIoT are sent from the network entity 300 to the activator 200 .

[0104] In a step 408 the authentication response RES is determined depending on the challenge RAND and the cryptographic key K .

[0105] In a step 410 , the challenge RAND, the authentication response RES , and the expected response XRESAIoT are sent from the activator 200 to the AIoT device .

[0106] In a step 412 the response RESAIoT is determined by the AIoT device 100 depending on the challenge RAND the cryptographic key KAIoT , and the authentication response RES .

[0107] In a step 414 , the activator 200 is authori zed by the AIoT device 100 to activate the AIoT device 100 , or authori zing the activator 200 to activate the AIoT device 100 is denied by the AIoT device 100 , UE ; US IM) depending on a result of a comparison of the response RESAIoT and the expected response XRESAIoT .

[0108] In a step 416 , the information is sent to the reader 400 . In a step 417, the result of the comparison may be sent to the activator 200.

[0109] In a step 418, the information is sent from the reader 400 to the network entity 300.

[0110] In a step 420, the information is accepted.

[0111] The information may be encrypted with the cryptographic key KAIoT in step 416, and the encrypted information may be sent to the reader 400 and forwarded by the reader 400 to the network entity.

[0112] The step 420 may comprise accepting the information only when decrypting the information with the cryptographic key KAIoT is successful.

[0113] Figure 5 schematically depicts the AIoT device 100 according to a second example.

[0114] The AIoT device 100 according to the second example is configured as the AIoT device 100 according to the first example. According to the second example, the AIoT device 100 comprises a function 502 for determining a value of a sequence number 504, e.g., SQNAIoT, that is associated with the AIoT device 100.

[0115] According to the second example, the function 114 for determining the response 116, e.g., RESAIoT, that is associated with the AIoT device 100, is configured to determine the response 116, e.g., RESAIoT, that is associated with the AIoT device 100, depending on the value of the sequence number 504, e.g., SQNAIoT, that is associated with the AIoT device 100.

[0116] Figure 6 schematically depicts the network entity 300 according to the second example.

[0117] The network entity 300 according to the second example is configured as the network entity 300 according to the first example. According to the second example, the network entity 300 comprises a function 602 for determining a value of a sequence number 604, e.g., SQNAIoT, that is associated with the AIoT device 100.

[0118] According to the second example, the function 314 for determining the expected response 112, e.g., XRESAIoT, that is associated with the AIoT device 100, is configured to determine the expected response 112, e.g., XRESAIoT, that is associated with the AIoT device 100, depending on the value of the sequence number 604, e.g., SQNAIoT, that is associated with the AIoT device 100.

[0119] For example, the network entity 300 is configured for incrementing the sequence number 604, e.g., SQNAIoT, upon receipt of the identification 304, e.g., AIoT ID, of the AIoT device 100, and the identification 306, e.g., SUCI or 5G-GUTI, of the activator 200. According to an example, the network entity 300 is configured for incrementing the sequence number 604, e.g., SQNAIoT, upon receipt of the identification 304, e.g., AIoT ID, of the AIoT device 100, and another identification, e.g., SUCI or 5G-GUTI, of another activator .

[0120] Figure 7 depicts a sequence diagram according to the second example.

[0121] The sequence in the sequence diagram according to the second example is the sequence of the sequence diagram according to the first example.

[0122] According to the second example, the sequence comprises a step 702 between the step 402 and the step 404.

[0123] The step 702 comprises determining a value of the sequence number SQNAIoT in the network entity 300.

[0124] The step 404 comprises determining the expected response XRESAIoT depending on the value that the sequence number SQNAIoT in the network entity 300 has.

[0125] According to the second example, the sequence comprises a step 704 between the step 410 and the step 412.

[0126] The step 704 comprises determining a value of the sequence number SQNAIoT in the AIoT device 100. According to the second example, the step 412 comprises determining the response RESAIoT depending on the value that the sequence number SQNAIoT in the AIoT device 100 has .

[0127] Figure 8 schematically depicts the AIoT device 100 according to a third example.

[0128] The AIoT device 100 according to the third example is configured as the AIoT device 100 according to the second example .

[0129] According to the third example, the receiver 106 is configured for receiving a message authentication code for integrity 802, e.g., MAC-IAIoT.

[0130] According to the third example, the AIoT device 100 comprises a function 804 for determining an expected message authentication code for integrity 806, e.g., XMAC-IAIoT, depending on the cryptographic key 118, e.g., KAIoT that is associated with the AIoT device 100 and the network entity 300, and depending on the response 116, e.g., RESAIoT, that is associated with the AIoT device 100.

[0131] According to the third example, the function 122 for authorizing or deny authorizing the activator 200 is configured for authorizing or deny authorizing the activator 200 depending on a result of a comparison of the expected message authentication code for integrity 806, e.g., XMAC-IAIoT, and the message authentication code for integrity 802, e.g., MAC-IAIoT.

[0132] Figure 9 schematically depicts the activator 200 according to the third example.

[0133] The activator 200 according to the third example is configured as the activator 200 according to the first example .

[0134] According to the third example, the receiver 202 is configured for receiving a message authentication code for integrity 902, e.g., MAC-IAIoT.

[0135] According to the third example, the sender 210 is configured for sending the message authentication code for integrity 902, e.g., MAC-IAIoT.

[0136] According to the third example, the message authentication code for integrity 902, e.g., MAC-IAIoT, is associated with the expected response 112, e.g., XRESAIoT, that is associated with the AIoT device 100.

[0137] Figure 10 schematically depicts the network entity 300 according to the third example.

[0138] According to the third example, the network entity 300 comprises a function 1002 for determining the message authentication code for integrity 902, e.g., MAC-IAIoT, depending on the cryptographic key 118, e.g., KAIoT, that is associated with the AIoT device 100 and the network entity 300, and depending on the expected response 112, e.g., XRESAIoT, that is associated with the AIoT device 100.

[0139] According to the third example, the sender 316 of the network entity 300is configured for sending the message authentication code for integrity 902, e.g., MAC-IAIoT.

[0140] Figure 11 depicts a sequence diagram according to the third example.

[0141] The sequence in the sequence diagram according to the third example is the sequence of the sequence diagram according to the second example.

[0142] According to the third example, the sequence comprises a step 1102 between the step 402 and the step 702.

[0143] The step 1102 comprises determining the message authentication code for integrity MAC-IAIoT in the network entity 300 depending on the cryptographic key KAIoT and the expected response XRESAIoT.

[0144] According to the third example, the step 406 comprises sending the message authentication code for integrity MAC-IAIoT from the network entity 300 to the activator 200. According to the third example , the sequence comprises a step 1104 between the step 410 and the step 704 .

[0145] The step 1104 comprises determining an expected message authentication code for integrity XMAC- IAIoT in the AIoT device 100 depending on the cryptographic key KAIoT and the response RESAIoT ) .

[0146] According to the third example , the step 414 comprises authori zing or deny authori zing the activator 200 depending on a result of a comparison of the expected message authentication code for integrity XMAC- IAIoT and the message authentication code for integrity MAC- IAIoT .

[0147] In the example , the step 414 comprises authori zing the activator 200 in case the result indicates integrity . In the example , the step 414 comprises denying authori zing the activator 200 in case the result indicates lack of integrity .

Claims

1. A first method, wherein the first method comprises receiving (410) a challenge (108) , an authentication response (110) , and an expected response (112) , wherein the challenge (108) is associated with a network entity (300) , wherein the authentication response (110) is associated with an activator (200) , wherein the expected response (112) is associated with an ambient internet of things device (100) , determining (412) a response (116) depending on the challenge (108) , a cryptographic key (118) , and the authentication response (110) , wherein the cryptographic key (118) is associated with the ambient internet of things device (100) and the network entity (300) , and authorizing (414) or deny authorizing the activator (200) to activate the ambient internet of things device (100) depending on a result of a comparison of the response (116) and the expected response (112) .

2. The first method according to claim 1, wherein the first method comprises activating (414) or deny activating the ambient internet of things device (100) depending on the result.

3. The first method according to claim 1 or 2, wherein the first method comprises sending (416) the result to the activator (200) or the information to a reader (400) .

4. The first method according to claim 1 or 2, wherein the first method comprises encrypting (414) the result with the cryptographic key (118) , and sending (416) the encrypted result to the activator (200) or the encrypted information to a reader (400) .

5. The first method according to one of the claims 1 to 4, wherein the first method comprises determining (704) a value of a sequence number (504) , and determining (412) the response (116) depending on the value of the sequence number (504) .

6. The first method according to one of the claims 1 to 5, wherein the first method comprises receiving (410) a message authentication code for integrity (802) , determining (1104) an expected message authentication code for integrity (806) depending on the cryptographic key (118) and the response (116) , and authorizing (414) or deny authorizing the activator (200) depending on a result of a comparison of the expected message authentication code for integrity (806) and the message authentication code for integrity (802) .

7. A second method, wherein the second method comprises receiving (406) a challenge (108) , and an expected response (112) , wherein the expected response (112) is associated with an ambient internet of things device (100) , determining (408) an authentication response (110) depending on thechallenge (108) and a cryptographic key (206) , wherein the authentication response (110) is associated with an activator (200) , wherein the cryptographic key (206) is associated with the activator (200) and a network entity (300) , and sending (410) the challenge (108) , the authentication response (110) , and the expected response (112) to the ambient internet of things device (100) .

8. The second method according to claim 7, wherein the second method comprises receiving (406) a message authentication code for integrity (802) , and sending (410) the message authentication code for integrity (802) , wherein the message authentication code for integrity (802) is associated with the expected response (112) .

9. A third method, wherein the third method comprises determining (404) an expected response (112) depending on a challenge (108) , a cryptographic key (118) , and an expected authentication response (312) , and sending (406) the challenge (108) , and the expected response (112) to an activator (200) , wherein the expected response (112) is associated with an ambient internet of things device (100) , wherein the cryptographic key (118) is associated with the ambient internet of things device (100) and a network entity (300) , and wherein the expected authentication response (312) is associated with the activator (200) .

10. The third method according to claim 9, wherein the third method comprises receiving (402) an identification of the ambient internet of things device (100) and an identification of the activator (200) , and authorizing (404) or deny authorizing the activator (200) depending on the identifications .

11. The third method according to claim 9 or 10, wherein the third method comprises determining (702) a value of a sequence number, and determining (404) the expected response (112) depending on the value of the sequence number.

12. The third method according to one of the claims 9 to 11, wherein the third method comprises determining (1102) a message authentication code for integrity depending on the cryptographic key (118) and the expected response (112) , and sending (406) the message authentication code for integrity .

13. The third method according to one of the claims 9 to 12, wherein the third method comprises determining the expected authentication response (312) depending on a cryptographic key (206) that is associated with the activator (200) and the network entity (300) .

14. The third method according to one of the claims 9 to 12, wherein the third method comprises receiving (418) an encrypted information, and accepting (420)the information only when decrypting (420) the information with the cryptographic key (118) is successful .

15. A first device (100) , wherein the first device (100) comprises means (102) for providing information (104) , wherein the first device (100) comprises means (106) for receiving (2e) a challenge (108) , an authentication response (110) , and an expected response (112) , wherein the challenge (108) is associated with a network entity (300) , wherein the authentication response (110) is associated with an activator (200) , wherein the expected response (112) is associated with the first device (100) , wherein the first device (100) comprises means (114) for determining a response (116) depending on the challenge (108) , a cryptographic key (118) , and the authentication response (110) , wherein the cryptographic key (118) is associated with the first device (100) and the network entity (300) , and wherein the first device (100) comprises means (122) for authorizing or deny authorizing the activator (200) to activate the ambient internet of things device (100) depending on a result of a comparison of the response (116) and the expected response (112) .

16. The first device (100) according to claim 15, wherein the first device (100) comprises means (122) for activating or deny activating the first device (100) depending on the result.

17. The first device (100) according to claim 15 or 16, wherein the first device (100) comprises means (124) for sending the result to the activator (200) or the information to a reader (400) .

18. The first device (100) according to claim 15 or 16, wherein the first device (100) comprises means (122) for encrypting the result with the cryptographic key (118) , and means (124) for sending the encrypted result to a reader (400) .

19. The first device (100) according to one of the claims 15 to 18, wherein the first device (100) comprises means (502) for determining a value of a sequence number (504) , and means (114) for determining the response (116) depending on the value of the sequence number (504) .

20. The first device (100) according to one of the claims 15 to 19, wherein the first device (100) comprises means (106) for receiving a message authentication code for integrity (802) , wherein the first device (100) comprises means (804) for determining an expected message authentication code for integrity (806) depending on the cryptographic key (118) and the response (116) , and wherein the first device comprises means (122) for authorizing or deny authorizing the activator (200) depending on a result of a comparison of the expected message authentication code for integrity (806) and the message authentication code for integrity (802) .

21. A second device (200) , wherein the second device(200) comprises means (202) for receiving a challenge (108) , and an expected response (110) , wherein the expected response (112) is associated with an ambient internet of things device (100) , wherein the second device (200) comprises means (204) for determining an authentication response (110) depending on the challenge (108) and a cryptographic key (206) , wherein the authentication response (110) is associated with the second device (200) , wherein the cryptographic key (206) is associated with the second device (200) and a network entity (300) , and wherein the second device (200) comprises means (210) for sending the challenge (108) , the authentication response (110) , and the expected response (112) to the ambient internet of things device (100) .

22. The second device (200) according to claim 21, wherein the second device (200) comprises means (202) for receiving a message authentication code (902) for integrity, and wherein the second device (200) comprises means (210) for sending the message authentication code for integrity (902) , wherein the message authentication code for integrity (902) is associated with the expected response (112) .

23. A third device (300) , wherein the third device (300) comprises means (314) for determining an expected response (112) depending on a challenge (108) , a cryptographic key (118) , and an expectedauthentication response (312) , and wherein the third device (300) comprises means (316) for sending (2c) the challenge (108) , and the expected response (112) to an activator (200) , wherein the expected response (112) is associated with an ambient internet of things device (100) , wherein the cryptographic key (118) is associated with the ambient internet of things device (100) and the third device (300) , and wherein the expected authentication response (312) is associated with the activator (200) .

24. The third device (300) according to claim 23, wherein the third device (300) comprises means (302) for receiving an identification (304) of the ambient internet of things device (100) and an identification (306) of the activator (200) , and wherein the third device (300) comprises means (308) for authorizing or deny authorizing the activator (200) depending on the identifications (304, 306) .

25. The third device (300) according to claim 23 or 24, wherein the third device (300) comprises means (602) for determining a value of a sequence number (604) , and wherein the third device (300) comprises means (314) for determining the expected response (112) depending on the value of the sequence number (604) .

26. The third device (300) according to one of the claims 23 to 25, wherein the third device (300) comprises means (1002) for determining a message authentication code (902) for integrity depending on the cryptographic key (118) and the expected response (112) , and wherein the third device (300) comprises means (316) for sending the message authentication code for integrity (902) .

27. The third device (300) according to one of the claims 23 to 26, wherein the third device (300) comprises means (310) for determining the expected authentication response (312) depending on a cryptographic key (206) that is associated with the activator (200) and the network entity (300) .

28. The third device (300) according to one of the claims 23 to 27, wherein the third device (300) comprises means (302) for receiving an encrypted information, and accepting the information only when decrypting the information with the cryptographic key (118) that is associated with the ambient internet of things device (100) is successful .

29. A computer program comprising instructions, which, when executed by a device, cause the device to at least perform the first method according to one of the claims 1 to 6, the second method according to one of the claims 7 or 8, or the third method according to one of the claims 9 to 14.