Dynamic internet of things device provisioning using an out of band mechanism

The enhanced EAP-NOOB procedure using a UE's secure connection for IoT devices addresses the inefficiencies in existing provisioning methods, enabling dynamic, low-power, and cost-effective integration into 5G/NR networks.

WO2025176471A1PCT designated stage Publication Date: 2025-08-28NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/053064
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-23
Filing Date
2025-02-06
Publication Date
2025-08-28

Smart Images

  • Figure EP2025053064_28082025_PF_FP_ABST
    Figure EP2025053064_28082025_PF_FP_ABST
Patent Text Reader

Abstract

Dynamic internet of things device provisioning using an out of band mechanism is provided. A method for dynamic internet of things device provisioning using the out of band mechanism may include receiving an out- of-band request message from a connected device and transmitting the out-of- band request message as a secured packet to a network entity. The method may also include transmitting a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure.
Need to check novelty before this filing date? Find Prior Art

Description

TITLE:DYNAMIC INTERNET OF THINGS DEVICE PROVISIONING USINGAN OUT OF BAND MECHANISMTECHNICAL FIELD:

[0001] Some example embodiments may generally relate to mobile or wireless telecommunication systems, such as Long Term Evolution (LTE) or fifth generation (5G) new radio (NR) access technology, or 5G beyond, or other communications systems. For example, certain example embodiments may relate to dynamic internet of things (IoT) device provisioning using an out of band mechanism.BACKGROUND:

[0002] Examples of mobile or wireless telecommunication systems may include the Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (UTRAN), Long Term Evolution (LTE) Evolved UTRAN (E-UTRAN), LTE- Advanced (LTE- A), MulteFire, LTE-A Pro, fifth generation (5G) radio access technology or new radio (NR) access technology, and / or sixth generation (6G) radio access technology. 5G and 6G wireless systems refer to the next generation (NG) of radio systems and network architecture. 5G and 6G network technology are mostly based on new radio (NR) technology, but the 5G (or NG) network can also build on E- UTRAN radio. It is estimated that NR may provide bitrates on the order of 10- 20 Gbit / s or higher and may support at least enhanced mobile broadband (eMBB) and ultra-reliable low-latency communication (URLLC) as well as massive machine-type communication (mMTC). NR is expected to deliver extreme broadband and ultra-robust, low-latency connectivity and massive networking to support the Internet of Things (IoT).SUMMARY:

[0003] Various exemplary embodiments may provide an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to receive an out-of-band request message from a connected device. The apparatus may also be caused to transmit the out-of-band request message as a secured packet to a network entity and transmit a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure.

[0004] Certain exemplary embodiments may provide an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform an initial exchange procedure for connection with a network entity of a network. The apparatus may also be caused to transmit an out-of-band request message to a user equipment, and upon completing the exchange procedure, generate a security key based on a generated session key.

[0005] Some exemplary embodiments may provide an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to obtain one or more out-of-band values from a secured packet received from a user equipment. The apparatus may further be caused to validate the secured packet and transmit a response message to the user equipment indicating that the secured packet is validated. The apparatus may also be caused to, upon completing an exchange procedure with a connected device connected to the user equipment, generate a security key based on a generated session key.

[0006] Certain exemplary embodiments may provide an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to receive an out-of-band request message from a connected device. The apparatus mayalso be caused to secure and transmit the out-of-band request message as a secured packet to a network entity. The apparatus may further be caused to transmit a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure for authentication.

[0007] Various exemplary embodiments may provide an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to generate a first network access identifier and perform an initial exchange procedure for connection with a network entity of a network using the first network access identifier. The apparatus may also be caused to transmit an out-of-band request message to a user equipment, and in response to receiving a response message from a user equipment and upon completing the exchange procedure to authenticate the apparatus with the network, generate a security key to secure the connection between the apparatus and the network entity.

[0008] Some exemplary embodiments may provide an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to receive a first network access identifier generated by a connected device, and assign and transmit a second network access identifier to the connected device. The apparatus may also be caused to validate the secured packet and transmit a response message to the user equipment indicating that the secured packet is validated. The apparatus may further be caused to, upon completing an exchange procedure with a device connected to the user equipment, generate a security key based on a generated session key.BRIEF DESCRIPTION OF THE DRAWINGS:

[0009] For proper understanding of example embodiments, reference shouldbe made to the accompanying drawings, as follows:

[0010] FIG. 1 illustrates an example of an association state mechanism;

[0011] FIG. 2A illustrates an example of a signal diagram, according to certain exemplary embodiments;

[0012] FIG. 2B illustrates an example of another signal diagram, according to various exemplary embodiments;

[0013] FIG. 2C illustrates an example of a further signal diagram, according to certain exemplary embodiments;

[0014] FIG. 3 illustrates an example of a signal diagram for a reconnection procedure, according to some exemplary embodiments;

[0015] FIG. 4 illustrates an example of a flow diagram of a method, according to various exemplary embodiments;

[0016] FIG. 5 illustrates an example of a flow diagram of another method, according to certain exemplary embodiments;

[0017] FIG. 6 illustrates an example of a flow diagram of a further method, according to some exemplary embodiments;

[0018] FIG. 7 illustrates an example of a flow diagram of another method, according to certain exemplary embodiments;

[0019] FIG. 8 illustrates an example of a flow diagram of a further method, according to various exemplary embodiments;

[0020] FIG. 9 illustrates an example of a flow diagram of another method, according to certain exemplary embodiments; and

[0021] FIG. 10 illustrates a set of apparatuses, according to various exemplary embodiments.DETAILED DESCRIPTION:

[0022] It will be readily understood that the components of certain example embodiments, as generally described and illustrated in the figures herein, may be arranged and designed in a wide variety of different configurations. Thefollowing is a detailed description of some exemplary embodiments of systems, methods, apparatuses, and non-transitory computer program products for dynamic internet of things (IoT) device provisioning using an out of band mechanism. Although the devices discussed below and shown in the figures refer to 6G / 5G or Next Generation NodeB (gNB) devices and UE devices, this disclosure is not limited to only gNBs and UEs.

[0023] It may be readily understood that the components of certain example embodiments, as generally described and illustrated in the figures herein, may be arranged and designed in a wide variety of different configurations. Different reference designations from multiple figures may be used out of sequence in the description, to refer to a same element to illustrate their features or functions. If desired, the different functions or procedures discussed herein may be performed in a different order and / or concurrently with each other. Furthermore, if desired, one or more of the described functions or procedures may be optional or may be combined. As such, the following description should be considered as illustrative of the principles and teachings of certain example embodiments, and not in limitation thereof.

[0024] In 5G / NR technology, Extensible Authentication Protocol (EAP) may provide support for multiple types of authentication procedures. For example, a nimble out-of-band (NOOB), which may also be referred to as EAP-NOOB, is an authentication procedure for NOOB authentication and key derivation. The EAP-NOOB procedure may provide for bootstrapping various types of IoT devices that may not have preconfigured authentication credentials. The EAP-NOOB procedure may use a user-assisted, unidirectional, OOB message between a peer device and an authentication server to authenticate an in-band key exchange. An EAP-NOOB may be executed to span two or more EAP conversations, which may be referred to as exchanges. Each exchange may include multiple pairs of EAP requests and responses. At least two separate EAP conversations may be needed to give an end user device a sufficientamount of time to deliver an OOB message between the peer device and the authentication server.

[0025] The EAP-NOOB procedure may begin with an initial exchange procedure in which four pairs of EAP requests and responses are performed. During the initial exchange procedure, a server may allocate or assign an identifier to the peer device, and the server and peer device may negotiate (e.g., request or instruct) a protocol version and crypto suite (i.e., cryptographic algorithm suite) to be used, exchange nonces, and then may perform an ephemeral elliptic curve Diffie-Hellman (ECDHE) key exchange. An OOB process may then be performed to provide one out-of-band message, either from the peer device to the server or from the server to the peer device. During the OOB process, the peer device may probe the server by reconnecting to it using an EAP-NOOB. When the OOB process has already been completed, the probing by the peer device may result in a completion exchange, which completes the mutual authentication and key confirmation. On the other hand, when the OOB process has not been completed, the probing by the peer device may result in a waiting exchange procedure in which the peer device may perform another probe after a server-defined minimum waiting time. The initial exchange and waiting exchange procedures may end in an EAP-failure indication, and the completion exchange process may result in an EAP-success indication. Once the peer device and the server have performed a successful completion exchange process, both the peer device and the server, serving as endpoints, store a created association in a persistent storage, and the OOB process may not be repeated. Thereafter, new temporal keys, ECDHE rekeying, and updates of cryptographic algorithms may be performed with using a reconnect exchange process.

[0026] FIG. 1 illustrates an example of an association state mechanism to perform the EAP-NOOB procedure. The association state mechanism may be the same for the server and for the peer device. When the peer initiates theEAP-NOOB process, the server may select or determine the ensuing message exchange based on a combination of the server state(s) and the peer device state(s). At 110 in FIG. 1, the server and the peer device may be initially in an unregistered state, in which no state information needs to be stored. Before a successful completion exchange process, the server-peer device association state may be set as ephemeral in both the server and the peer device. A timeout or error may cause one or both of the server or peer deice to revert back to the unregistered state so that the initial exchange procedure may be repeated. The error may be, for example, invalid, unexpected, unrecognized, or other nonsupported values, such as the errors listed in Internet Engineering Task Force (IETF) Request for Comment (RFC) 9140. At 120, the server or peer device may wait for an OOB process in which an OOB message may be input and at 130, the OOB message may be received by the server or the peer device. The initial exchange procedure may then be completed, and the completion exchange process may result in an EAP-success indication. At 140, the association state may transition from the ephemeral state to a persistent state in which the server or the peer device is registered. A user reset or memory failure may cause the return of the server or the peer device from the persistent state to the ephemeral state, which may then result in performing the initial exchange procedure again. At 150, after a mobility timeout period has expired or an error has occurred, the server or the peer device may transition to a reconnecting procedure and perform a reconnect exchange to return to the registered persistent state. If the reconnecting procedure fails, the server or the peer device reverts back to the unregistered state.

[0027] As the amount of loT devices increases, there is a need to implement dynamic procedures and mechanisms for adding loT devices to a network compatible with 3rdGeneration Partnership Project (3GPP) specifications. This may be particularly useful when it is desired for a user operating a its own UE to add additional loT devices to be operated by the same user.Examples of loT devices may include identification (ID) tags, sensors, smart apparel, healthcare devices, and / or logistics objects (e.g., tracking devices). This type of loT device may also be referred to an ambient loT device which may be powered by energy harvesting, such that, for example, the device may be either battery-less or equipped with limited energy storage capabilities (e.g., using a capacitor).

[0028] loT devices may be used to complement existing loT technologies and extend the usage to additional use cases that may demand more cost-effective, power-efficient, and / or battery-less functionalities. 3rdGeneration Partnership Project (3GPP) specifications may define certain loT devices, such as reduced capability (RedCap) devices, to satisfy requirements for low cost and low power devices for wide area loT communication. These loT devices may consume relatively low power, such as tens or hundreds of milliwatts, during transceiving. To achieve the internet of everything, loT devices with lower cost and lower power consumption are needed, especially for implementations in which battery-less devices are desired.

[0029] As part of implementing the procedures for adding new loT devices to a 5G / 6G network, the loT device may need to be provisioned with a new (electronic) subscriber identity module (SIM / eSIM), a subscription may need to be created in a unified data management (UDM) and / or home subscriber server (HSS), and / or an activation procedure may be needed for each new loT device. These actions may require undesired increases in time and may require manual intervention from an end user.

[0030] Various exemplary embodiments may provide technological advantages to address these above-mentioned concerns and may implement one or more procedures to dynamically provision loT devices by a home network of a mobile network via the UE with reduced or no human intervention. The one or more procedures may allow an loT device to be provisioned dynamically in the network via an enhanced EAP-NOOBprocedure, according to various exemplary embodiments.

[0031] Certain exemplary embodiments may provide one or more procedures in which a UE may connect to an loT device via a local connection and may configure operator details on the loT device. The UE may establish a secure connection (e.g., non-access stratum (NAS) connection) to a mobile network and may use the secure connection as an OOB channel to send (EAP-OOB) an OOB request message from the loT device to the mobile network. Upon receiving a successful (EAP-OOB) OOB response message, the loT device may perform a completion exchange procedure with the mobile network. After a successful completion exchange procedure, the loT device and the mobile network may establish a session key and may derive further security keys based on the session key.

[0032] FIG. 2A illustrates an example of a signal diagram, according to certain exemplary embodiments. The signal diagram provides signaling which implements one or more procedures to dynamically provision loT devices by a home network via a UE. The signal diagram shows signaling between a user equipment (UE) 201, a smart loT device 202, a radio access network (RAN) 203, an access and mobility management function (AMF) 204, and a network entity which may serve as a customer relationship management (CRM) portal, a unified data management (UDM), and / or an authentication server function (AUSF) 205, which may be generally referred to herein as UDM / AUSF 205. The RAN 203, AMF 204, and UDM / AUSF 205 may be entities of the home or mobile network.

[0033] At procedure 210, the UE 201 may perform a registration procedure and perform a mutual authentication of the UE 201 and the network via the RAN 203, AMF 204, and / or UDM / AUSF 205. At 211, a new loT device 202 may be connected to the UE 201, such as, for example, via a device-to-device (D2D) connection. Examples of a D2D connection may be Bluetooth, WiFi, or another wireless or wired connection between the UE 201 and the loTdevice 202. At 212, the UE 201 may access a portal of the UDM / AUSF 205 to request or add a dynamic subscription for the loT device 202 to the home network. The UE 201 may also configure with the network a mobile country code and / or mobile network code and / or other known operator information and parameters of the loT device 202 so that the loT device 202 may connect to the home network and confirm that the home network is the desired network to be joined. At 213, the mobile country code (MCC) and / or mobile network code (MNC) and / or other known operator information and parameters may be configured with the loT device 202.

[0034] At 214, the loT device 202 may establish a layer 2 (L2) connection with the RAN 203, and at 215, the loT device 202 may transmit an NAS registration request to the RAN 203 using the L2 connection. The loT device 202 may also construct and transmit a UE ID with network access identifier (NAI) as, for example, 5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org@eap- noob.arpa. At 216, the RAN 203 may transmit the NAS registration request and NAI to the AMF 204, and at 217, the AMF 204 may transmit an authentication request which includes the NAI to the UDM / AUSF 205.

[0035] At 218, the UDM / AUSF 205 may transmit an EAP-NOOB request to the loT device 202, and at 219, the loT device 202 may recognize the exchange of EAP-NOOB messages based on a message type field of the EAP-NOOB request received from the UDM / AUSF 205 and may respond by transmitting an EAP-NOOB response message to the UDM / AUSF 205. The EAP-NOOB response message may include a peer identifier (PeerlD) and a peer state. At 220, an initial exchange procedure of one or more public keys of the loT device 202 and one or more public keys of the home network may be performed. The UDM / AUSF 205 may assign a new NAI and Peer ID to the loT device 202. ECDHE keys may be generated based on a negotiated cryptosuite. The negotiated cryptosuite may implement one or more algorithms to be negotiated and used between two entities, such as the loTdevice 202 and the UDM / AUSF 205, using key IDs which identify a pair of keys to be used.

[0036] FIG. 2B illustrates an example of a signal diagram, according to certain exemplary embodiments. The signal diagram provides signaling which implements one or more procedures performed in addition to procedures 210- 220, shown in FIG. 2A, to dynamically provision loT devices by a home network via a UE. The signal diagram shows signaling between the UE 201, the loT device 202, the RAN 203, the AMF 204, and the UDM / AUSF 205.

[0037] At 221 , the initial exchange procedure may end with the loT device 202 receiving an EAP-failure indication from the UDM / AUSF 205 when authentication cannot yet be completed. At the end of the initial exchange procedure, the UDM / AUSF 205 and the loT device 202 may transition to a waiting state for waiting to receive an OOB. At 222, the loT device 202 may trigger the OOB procedure via the UE 201. The loT device 202 may transmit an OOB message request with the PeerlD, a NOOB value, and a hash OOB (HOOB) value. At 223, the UE 201 may use an authentication process which uses the same processes as procedures 214-216 using NAS and access stratum (AS) authentication. The NAS and AS authentication may use AS keys between the UE 201 and the home network, such as the UDM / AUSF 205, and NAS keys between the UE 201 and the AMF 204 for the protection of the messages. Alternatively, the UE 201 may generate a secured uplink steering of roaming (SoR) packet or a UE parameter update (UPU) packet with a generated message authentication code for integrity (MAC-I) using an authentication server function key (KAUSF).

[0038] At 224, the UE 201 may generate a secured packet with the PeerlD, the NOOB value, the HOOB value, and the KAUSF and transmit the secured packet to the UDM / AUSF 205. At 225, the UDM / AUSF 205 may obtain the NOOB value, HOOB value, and PeerlD from the secured packet of the SoR or UPU packet and may verify the MAC-I using KAUSF. At 226, the UDM / AUSF 205may generate an acknowledgement message for the uplink of the packet and may generate a downlink secured packet with the ACK and an MAC-I generated for the ACK, so that the response is not modified by the serving network. At 227, an OOB response message may be transmitted to the UE 201 and may include the downlink secured packet with the result of the validation and the acknowledgement in the downlink secured packet. At 228, the UE 201 may forward the OOB response message to the loT device 202.

[0039] At 229, a completion exchange procedure may be performed in which multiple pairs of EAP-NOOB request and response messages may be communicated between the loT device 202 and the home network (e.g., the RAN 203, the AMF 204, and / or the UDM / AUSF 205). The completion exchange procedure may result in an EAP-success indication and the loT device 202 and the home network (e.g., the UDM / AUSF 205) may be set to a registered state. The EAP-success may generate a main session key (MSK) to be used by the loT device 202 and the UDM / AUSF 205.

[0040] FIG. 2C illustrates an example of a signal diagram, according to certain exemplary embodiments. The signal diagram provides signaling which implements one or more procedures performed in addition to procedures 210- 229, shown in FIGs. 2A and 2B, to dynamically provision loT devices by a home network via a UE. The signal diagram shows signaling between the UE 201, the loT device 202, the RAN 203, the AMF 204, and the UDM / AUSF 205.

[0041] At 230, the loT device 202 may use the MSK as a session key and the peer ID may be used for communication. At 231 , the loT device 202 may generate or derive a security anchor function key (KSEAF) based on the session key. At 232, and similar to procedure 230, the UDM / AUSF 205 may use the MSK as a session key and the peer ID may be used for communication, and at 233, the UDM / AUSF 205 may generate or derive a KSEAF based on the session key. At 234, the UDM / AUSF 205 may transit the KSEAF in an authenticationsuccess message to the AMF 204. At 235, the MAF 204 may generate or derive NAS and AS keys to secure and protect future communications between the loT device 202 and the home network (e.g., the RAN 203, the AMF 204, and / or the UDM / AUSF 205).

[0042] Certain exemplary embodiments may provide for one or more procedures in a situation in which an loT device enters an inactive or sleep state and then attempts to return to the home network via a globally unique temporary identifier (GUTI), which may be defined in, for example, 3 GPP technical Specification (TS) 23.003. FIG. 3 illustrates an example of a signal diagram for a reconnection procedure, according to some exemplary embodiments. The signal diagram provides signaling which implements one or more procedures to reconnect a previously connected loT device to a home network. The signal diagram shows signaling between a UE 301, an loT device 302, a RAN 303, an AMF 304, and a network entity which may serve as a customer relationship management (CRM) portal, a unified data management (UDM), and / or an authentication server function (AUSF) 305, which may be generally referred to herein as UDM / AUSF 305. The RAN 303, AMF 304, and UDM / AUSF 305 may be entities of the home or mobile network.

[0043] At 310, the loT device may be securely connected to the home network using the one or more procedures explain above with respect to FIGs. 2A and 2B. At 320, the loT device 302 may enter a sleep or inactive state and then may attempt to return its connection to the home network. At 330, the loT device 302 may transmit a reconnection request to the AMF 304. The reconnection request may include a GUTI. At 340 and 350, the AMF 304 may decide whether or not to perform authentication or reauthentication. At 340, the AMF 304 may identify the loT device 302 from the GUTI and may decide to continue or reestablish the secure connection for providing services to the loT device 302 without performing reauthentication of the loT device 302.

[0044] Alternatively, at 350, the AMF 304 may decide to perform reauthentication prior to reestablishing a secure connection for providing services to the loT device 302. At 360, as part of the reauthentication process, the AMF 304 may retrieve a UE ID (e.g., PeerlD) from the loT device 302, and at 370, the loT device 302 may provide an EAP ID response message to the AMMF 304 which includes the PeerlD. At 380, the AMF 304 may transmit an authentication request to the UDM / AUSF 305 which includes the PeerlD. At 390, the UDM / AUSF 305 may perform authentication using reconnect message exchanges and, after reconnection is successful, the UDM / AUSF 305 may assign a new NAI to the UE 301 and the loT device 302, which is then stored in each of the UE 301 and the loT device 302.

[0045] Some exemplary embodiments may provide for a specific NAI format. For example, a decorated NAI may be in the form of one or more of (l)-(5): homerealm !usemame@otherrealm (1)V isitedrealm ! homerealm ! usemame@otherrealm (2)5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org@eap-noob.arpa (3)5gc . mnc<homeMN C> . mcc<homeMCC> .3 gppnetwork . org (4)! 0<IMSI>@aiot.nai.5gc.mnc<visitedMNC>.mcc<visitedMCC>.3gpp (5) network. org@eap-noob. arpa

[0046] Certain exemplary embodiments may provide that the NAI format may include a nonce, hash value and NOOB ID in which the nonce NOOB may be, for example, a 16-byte fresh random byte string and HOOB may be defined as:HOOB = H(Dir, Vers, Verp, Peerld, Cryptosuites, Dirs, Serverinfo,Cryptosuitep, Dirp, NAI, Peerinfo, 0, PKHN, NHN, PKp, Np, NOOB) (6)

[0047] Some exemplary embodiments may provide that a NOOB ID may be defined as:NOOB ID = H 'Noobld" ,Noob) (7)

[0048] When deriving the KSEAF from a session key of the loT device, thefollowing parameters may be used to form an input S to a generic key derivation function (KDF): FC = 0x6C; PO = <serving network name>; LO = length of <serving network name>. The input key for the KDF may be the session key of the loT device. For example, the KDF may be defined in 3GPP TS 33.501 (Annex A.6).

[0049] FIG. 4 illustrates an example flow diagram of a method, according to certain exemplary embodiments. In an example embodiment, the method of FIG. 4 may be performed by a device or user equipment within a network in a 3 GPP system, such as LTE, 5G-NR, or 6G. For instance, in an exemplary embodiment, the method of FIG. 4 may be performed by a UE, similar to apparatus 1010 illustrated in FIG. 10.

[0050] According to various exemplary embodiments, the method of FIG. 4 may include, at 410, receiving an out-of-band request message from a connected device, such as an loT device, and at 420, transmitting the out-of- band request message as a secured packet to a network entity. At 430, the method may also include transmitting a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure.

[0051] Certain exemplary embodiments may provide that the method also includes connecting to the connected device via an initial exchange procedure. The out-of-band request message may be transmitted by using a previously established secure connection between the apparatus and the network entity during a registration procedure or generating a secured uplink updated parameter packet using an authentication server function key. The method may further include receiving the response message comprising a result of a validation procedure of the secured packet from the network entity.

[0052] FIG. 5 illustrates an example flow diagram of a method, according to certain exemplary embodiments. In an example embodiment, the method of FIG. 5 may be performed by an loT device in a 3GPP system, such as LTE,5G-NR, or 6G. For instance, in an exemplary embodiment, the method of FIG. 5 may be performed by n loT device, similar to apparatus 1020 illustrated in FIG. 10.

[0053] According to various exemplary embodiments, the method of FIG. 5 may include, at 510, performing an initial exchange procedure for connection with a network entity of a network, and at 520, transmitting an out-of-band request message to a user equipment. At 530, the method may also include upon completing the exchange procedure, generating a security key based on a generated session key.

[0054] Certain exemplary embodiments may provide that the method may include, during the initial exchange procedure, receiving a network access identifier which was assigned by the network entity. The out-of-band request message may include at least one of the network access identifier, a nimble out-of-band value, or a hash out-of-band value. The method may further include receiving, from the user equipment, a response message comprising an indication that the apparatus is authenticated with the network. The method may also include generating a session key based on the response message. A security key may be derived from the generated session key.

[0055] FIG. 6 illustrates an example flow diagram of a method, according to certain exemplary embodiments. In an example embodiment, the method of FIG. 6 may be performed by a network element / entity, or a group of multiple network entities in a 3GPP system, such as LTE, 5G-NR, or 6G. For instance, in an exemplary embodiment, the method of FIG. 6 may be performed by a network entity, such as a CRM / UDM / AUSF, similar to apparatus 1030 illustrated in FIG. 10.

[0056] According to various exemplary embodiments, the method of FIG. 6 may include, at 610, obtaining one or more out-of-band values from a secured packet received from a user equipment, and at 620, validating the secured packet and transmitting a response message to the user equipment indicatingthat the secured packet is validated. At 630, the method may also include, upon completing an exchange procedure with a connected device connected to the user equipment, generating a security key based on a generated session key.

[0057] Certain exemplary embodiments may provide that the method also include assigning and transmitting a peer identifier to the connected device. The secured packet may include at least one of the peer identifier, a nimble out-of-band value, a hash out-of-band value, or a medium access control identifier. The method may further include generating an uplink acknowledgement for an uplink packet or generating a downlink acknowledgement for the secured packet. The method may also include transmitting the response message including at least one of the uplink acknowledgement or the downlink acknowledgement.

[0058] FIG. 7 illustrates an example flow diagram of a method, according to certain exemplary embodiments. In an example embodiment, the method of FIG. 7 may be performed by a device or user equipment within a network in a 3 GPP system, such as LTE, 5G-NR, or 6G. For instance, in an exemplary embodiment, the method of FIG. 7 may be performed by a UE, similar to apparatus 1010 illustrated in FIG. 10.

[0059] According to various exemplary embodiments, the method of FIG. 7 may include, at 710, receiving an out-of-band request message from a connected device, such as an loT device, and at 720, securing and transmitting the out-of-band request message as a secured packet to a network entity. At 730, the method may also include transmitting a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure for authentication.

[0060] Certain exemplary embodiments may provide that the method also includes, prior to receiving the out-of-band request message, connecting to theconnected device via an initial exchange procedure. The out-of-band request message may include an identifier of the connected device which was assigned by the network entity, a nimble out-of-band value, and a hash out-of-band value. The out-of-band request message may be secured as the secured packet and transmitted by using a previously established secure connection between the apparatus and the network entity during a registration procedure, or generating a secured uplink updated parameter packet using an authentication server function key. The method may further include receiving the response message from the network entity in response to transmitting the secured packet to the network entity. The response message may include a result of a validation procedure of the secured packet by the network entity.

[0061] FIG. 8 illustrates an example flow diagram of a method, according to certain exemplary embodiments. In an example embodiment, the method of FIG. 8 may be performed by an loT device in a 3GPP system, such as LTE, 5G-NR, or 6G. For instance, in an exemplary embodiment, the method of FIG. 8 may be performed by n loT device, similar to apparatus 1020 illustrated in FIG. 10.

[0062] According to various exemplary embodiments, the method of FIG. 8 may include, at 810, generating a first network access identifier, and at 820, performing an initial exchange procedure for connection with a network entity of a network using the first network access identifier. At 830, the method may also include transmitting an out-of-band request message to a user equipment, and at 840, in response to receiving a response message from a user equipment and upon completing the exchange procedure to authenticate the apparatus with the network, generating a security key to secure the connection between the apparatus and the network entity.

[0063] Certain exemplary embodiments may provide that the method may further include, during the initial exchange procedure, receiving a second network access identifier which was assigned by the network entity. The out-of-band request message may include the second network access identifier, a nimble out-of-band value, and a hash out-of-band value. The method may also include receiving the response message from the user equipment. The response message may include an indication that the apparatus is authenticated with the network. The method may further include generating a session key based on the response message. The generated security key may be derived from the generated session key.

[0064] FIG. 9 illustrates an example flow diagram of a method, according to certain exemplary embodiments. In an example embodiment, the method of FIG. 9 may be performed by a network element / entity, or a group of multiple network entities in a 3GPP system, such as LTE, 5G-NR, or 6G. For instance, in an exemplary embodiment, the method of FIG. 9 may be performed by a network entity, such as a CRM / UDM / AUSF, similar to apparatus 1030 illustrated in FIG. 10.

[0065] According to various exemplary embodiments, the method of FIG. 9 may include, at 910, receiving a first network access identifier generated by a connected device, and at 920, assigning and transmitting a second network access identifier to the connected device. At 930, the method may also include obtaining one or more out-of-band values from a secured packet received from a user equipment, and at 940, validating the secured packet and transmitting a response message to the user equipment indicating that the secured packet is validated. At 950, the method may further include, upon completing an exchange procedure with a device connected to the user equipment, generating a security key based on a generated session key.

[0066] Certain exemplary embodiments may provide that the method may also include assigning and transmitting a peer identifier to the connected device. The secured packet may include the peer identifier, a nimble out-of-band value, a hash out-of-band value, and a medium access control identifier. The method may further include generating an uplink acknowledgement for anuplink packet, generating a downlink acknowledgement for the secured packet, and transmitting the response message which includes the uplink acknowledgement and the downlink acknowledgement.

[0067] FIG. 10 illustrates a set of apparatuses 1010, 1020, and 1030 according to various exemplary embodiments. In the various exemplary embodiments, the apparatus 1010 may be an element in a communications network, such as an loT device. For example, loT devices 202 and 302 according to various exemplary embodiments discussed above may be an example of apparatus 1010. It should be noted that one of ordinary skill in the art would understand that apparatus 1010 may include components or features not shown in FIG. 10. Further, apparatus 1020 may be an element in a communications network or network entity, such as UE, RedCap UE, SL UE, mobile equipment (ME), mobile station, mobile device, or other device. For example, UEs 201 / 301 according to various exemplary embodiments discussed above may be examples of apparatus 1020. It should be noted that one of ordinary skill in the art would understand that apparatus 1020 may include components or features not shown in FIG. 10. In addition, apparatus 1030 may be an element in a network or associated with the network, or a network entity, such as a CRM / UDM / AUSF. For example, UDM / AUSF 205 / 305 according to various exemplary embodiments discussed above may be an example of apparatus 1030. It should be noted that one of ordinary skill in the art would understand that apparatus 1030 may include components or features not shown in FIG. 10.

[0068] In some example embodiments, apparatuses 1010, 1020 and / or 1030 may include one or more processors, one or more computer-readable storage medium (for example, memory, storage, or the like), one or more radio access components (for example, a modem, a transceiver, or the like), and / or a user interface. In some example embodiments, apparatuses 1010, 1020 and / or 1030 may be configured to operate using one or more radio access technologies,such as GSM, LTE, LTE-A, NR, 5G, WLAN, WiFi, NB-IoT, Bluetooth, NFC, MulteFire, and / or any other radio access technologies.

[0069] As illustrated in the example of FIG. 10, apparatuses 1010, 1020 and / or 1030 may include or be coupled to processors 1012, 1022, and 1032, respectively, for processing information and executing instructions or operations. Processors 1012, 1022, and 1032 may be any type of general or specific purpose processor. In fact, processors 1012, 1022, and 1032 may include one or more of general-purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), field- programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), and processors based on a multi-core processor architecture, as examples. While a single processor 1012 (and 1022 / 1032) for each of apparatuses 1010, 1020 and / or 1030 is shown in FIG. 10, multiple processors may be utilized according to other example embodiments. For example, it should be understood that, in certain example embodiments, apparatuses 1010, 1020 and / or 1030 may include two or more processors that may form a multiprocessor system (for example, in this case processors 1012, 1022, and 1032 may represent a multiprocessor) that may support multiprocessing. According to certain example embodiments, the multiprocessor system may be tightly coupled or loosely coupled to, for example, form a computer cluster.

[0070] Processors 1012, 1022, and 1032 may perform functions associated with the operation of apparatuses 1010, 1020 and / or 1030, respectively, including, as some examples, precoding of antenna gain / phase parameters, encoding and decoding of individual bits forming a communication message, formatting of information, and overall control of the apparatuses 1010, 1020 and / or 1030, including processes illustrated in FIGs. 2-9.

[0071] Apparatuses 1010, 1020 and / or 1030 may further include or be coupled to memory 1014, 1024, and / or 1034 (internal or external), respectively, which may be coupled to processors 1012, 1022, and 1032, respectively, for storinginformation and instructions that may be executed by processors 1012, 1022, and 1032. Memory 1014 (and memory 1024 and memory 1034) may be one or more memories and of any type suitable to the local application environment, and may be implemented using any suitable volatile or nonvolatile data storage technology such as a semiconductor-based memory device, a magnetic memory device and system, an optical memory device and system, fixed memory, and / or removable memory. For example, memory 1014 (and memory 1024 and memory 1034) can be comprised of any combination of random access memory (RAM), read only memory (ROM), static storage such as a magnetic or optical disk, hard disk drive (HDD), or any other type of non-transitory machine or computer readable media. The instructions stored in memory 1014, memory 1024 and memory 1034 may include program instructions or computer program code that, when executed by processors 1012, 1022, and 1032, enable the apparatuses 1010, 1020 and / or 1030 to perform tasks as described herein.

[0072] In certain example embodiments, apparatuses 1010, 1020 and / or 1030 may further include or be coupled to (internal or external) a drive or port that is configured to accept and read an external computer readable storage medium, such as an optical disc, USB drive, flash drive, or any other storage medium. For example, the external computer readable storage medium may store a computer program or software for execution by processors 1012, 1022, and 1032 and / or apparatuses 1010, 1020 and / or 1030 to perform any of the methods illustrated in FIGs. 2-9.

[0073] According to various exemplary embodiments, the apparatus 1010 may include at least one processor 1012, and at least one memory 1014, as shown in FIG. 10. The memory 1014 may store instructions that, when executed by the processor 1012, cause the apparatus 1010 to receive an out-of-band request message from a connected device and transmit the out-of-band request message as a secured packet to a network entity. The apparatus 1010 may alsobe caused to transmit a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure.

[0074] According to various exemplary embodiments, the apparatus 1020 may include at least one processor 1022, and at least one memory 1024, as shown in FIG. 10. The memory 1024 may store instructions that, when executed by the processor 1022, cause the apparatus 1020 to perform an initial exchange procedure for connection with a network entity of a network and transmit an out-of-band request message to a user equipment. The apparatus 1020 may also be caused to, upon completing the exchange procedure, generate a security key based on a generated session key.

[0075] According to various exemplary embodiments, the apparatus 1030 may include at least one processor 1032, and at least one memory 1034, as shown in FIG. 10. The memory 1034 may store instructions that, when executed by the processor 1032, cause the apparatus 1030 to obtain one or more out-of- band values from a secured packet received from a user equipment, and validate the secured packet and transmit a response message to the user equipment indicating that the secured packet is validated. The apparatus 1030 may also be caused to, upon completing an exchange procedure with a connected device connected to the user equipment, generate a security key based on a generated session key.

[0076] According to various exemplary embodiments, the apparatus 1010 may include at least one processor 1012, and at least one memory 1014, as shown in FIG. 10. The memory 1014 may store instructions that, when executed by the processor 1012, also cause the apparatus 1010 to receive an out-of-band request message from a connected device, and secure and transmit the out-of- band request message as a secured packet to a network entity. The apparatus 1010 may also be caused to transmit a received response message from the network entity to the connected device. The response message may triggerthe connected device to complete a completion exchange procedure for authentication.

[0077] According to various exemplary embodiments, the apparatus 1020 may include at least one processor 1022, and at least one memory 1024, as shown in FIG. 10. The memory 1024 may store instructions that, when executed by the processor 1022, also cause the apparatus 1020 to generate a first network access identifier and perform an initial exchange procedure for connection with a network entity of a network using the first network access identifier. The apparatus 1020 may also be caused to transmit an out-of-band request message to a user equipment, and in response to receiving a response message from a user equipment and upon completing the exchange procedure to authenticate the apparatus with the network, generate a security key to secure the connection between the apparatus and the network entity.

[0078] According to various exemplary embodiments, the apparatus 1030 may include at least one processor 1032, and at least one memory 1034, as shown in FIG. 10. The memory 1034 may store instructions that, when executed by the processor 1032, also cause the apparatus 1030 to receive a first network access identifier generated by a connected device and assign and transmit a second network access identifier to the connected device. The apparatus 1030 may also be caused to obtain one or more out-of-band values from a secured packet received from a user equipment and validate the secured packet and transmit a response message to the user equipment indicating that the secured packet is validated. The apparatus 1030 may further be caused to, upon completing an exchange procedure with a device connected to the user equipment, generate a security key based on a generated session key.

[0079] In some exemplary embodiments, apparatuses 1010, 1020 and / or 1030 may also include or be coupled to one or more antennas 1015, 1025, and 1035 for receiving a downlink signal and for transmitting via an uplink from apparatuses 1010, 1020 and / or 1030, respectively. Apparatuses 1010, 1020and / or 1030 may further include transceivers 1016, 1026, and 1036, respectively, configured to transmit and receive information. The transceiver 1016, 1026, and 1036 may also include a radio interface that may correspond to a plurality of radio access technologies including one or more of GSM, LTE, LTE-A, 5G, NR, WLAN, NB-IoT, Bluetooth, BT-LE, NFC, RFID, UWB, or the like. The radio interface may include other components, such as filters, converters (for example, digital-to-analog converters or the like), symbol demappers, signal shaping components, an Inverse Fast Fourier Transform (IFFT) module, or the like, to process symbols, such as OFDMA symbols, carried by a downlink or an uplink.

[0080] For instance, transceivers 1016, 1026, and 1036 may be respectively configured to modulate information on to a carrier waveform for transmission and demodulate received information for further processing by other elements of apparatuses 1010, 1020 and / or 1030. In other example embodiments, transceivers 1016, 1026, and 1036 may be capable of transmitting and receiving signals or data directly. Additionally or alternatively, in some example embodiments, apparatuses 1010, 1020 and / or 1030 may include an input and / or output device (I / O device). In certain example embodiments, apparatuses 1010, 1020 and / or 1030 may further include a user interface, such as a graphical user interface or touchscreen.

[0081] In certain example embodiments, memory 1014, 1024, and 1034 store software modules that provide functionality when executed by processors 1012, 1022, and 1032, respectively. The modules may include, for example, an operating system that provides operating system functionality for apparatuses 1010, 1020 and / or 1030. The memory may also store one or more functional modules, such as an application or program, to provide additional functionality for apparatuses 1010, 1020 and / or 1030. The components of apparatuses 1010, 1020 and / or 1030 may be implemented in hardware, or as any suitable combination of hardware and software. According to certainexample embodiments, apparatuses 1010, 1020 and / or 1030 may optionally be configured to communicate with each other via a wireless or wired communications links 1040, 1050, and 1060 according to any radio access technology, such as NR.

[0082] According to certain example embodiments, processors 1012, 1022 and / or 1032, and memory 1014, 1024 and / or 1034 may be included in or may form a part of processing circuitry or control circuitry. In addition, in some example embodiments, transceivers 1016, 1026, and 1036 may be included in or may form a part of transceiving circuitry.

[0083] In some exemplary embodiments, an apparatus (e.g., apparatuses 1010, 1020 and / or 1030) may include means for performing a method, a process, or any of the variants discussed herein. Examples of the means may include one or more processors, memory, controllers, transmitters, receivers, and / or computer program code for causing the performance of the operations.

[0084] Certain exemplary embodiments may be directed to an apparatus 1010 that includes means for receiving an out-of-band request message from a connected device and means for transmitting the out-of-band request message as a secured packet to a network entity. The apparatus 1010 may also include means for transmitting a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure.

[0085] Some exemplary embodiments may be directed to an apparatus 1020 that includes means for performing an initial exchange procedure for connection with a network entity of a network and means for transmitting an out-of-band request message to a user equipment. The apparatus 1020 may also include means for, upon completing the exchange procedure, generating a security key based on a generated session key.

[0086] Various exemplary embodiments may be directed to an apparatus 1030 that includes means for obtaining one or more out-of-band values from a1 secured packet received from a user equipment, means for validating the secured packet and means for transmitting a response message to the user equipment indicating that the secured packet is validated. The apparatus 1030 may also include means for, upon completing an exchange procedure with a connected device connected to the user equipment, generating a security key based on a generated session key.

[0087] Some exemplary embodiments may be directed to an apparatus 1010 that includes means for receiving an out-of-band request message from a connected device, and means for securing and means for transmitting the out- of-band request message as a secured packet to a network entity. The apparatus 1010 may also include means for transmitting a received response message from the network entity to the connected device. The response message may trigger the connected device to complete a completion exchange procedure for authentication.

[0088] Various exemplary embodiments may be directed to an apparatus 1020 that includes means for generating a first network access identifier and means for performing an initial exchange procedure for connection with a network entity of a network using the first network access identifier. The apparatus 1020 may also include means for transmitting an out-of-band request message to a user equipment. The apparatus 1020 may further include, in response to receiving a response message from a user equipment and upon completing the exchange procedure to authenticate the apparatus with the network, means for generating a security key to secure the connection between the apparatus and the network entity.

[0089] Certain exemplary embodiments may be directed to an apparatus 1030 that includes means for receiving a first network access identifier generated by a connected device. The apparatus 1030 may also include means for assigning and means for transmitting a second network access identifier to the connected device. The apparatus 1030 may further include means forobtaining one or more out-of-band values from a secured packet received from a user equipment. The apparatus 1030 may also include means for validating the secured packet and means for transmitting a response message to the user equipment indicating that the secured packet is validated. The apparatus 1030 may include, upon completing an exchange procedure with a device connected to the user equipment, means for generating a security key based on a generated session key.

[0090] As used herein, the term “circuitry” may refer to hardware-only circuitry implementations (for example, analog and / or digital circuitry), combinations of hardware circuits and software, combinations of analog and / or digital hardware circuits with software / firmware, any portions of hardware processor(s) with software, including digital signal processors, that work together to cause an apparatus (for example, apparatus 1010, 1020 and / or 1030) to perform various functions, and / or hardware circuit(s) and / or processor(s), or portions thereof, that use software for operation but where the software may not be present when it is not needed for operation. As a further example, as used herein, the term “circuitry” may also cover an implementation of merely a hardware circuit or processor or multiple processors, or portion of a hardware circuit or processor, and the accompanying software and / or firmware. The term circuitry may also cover, for example, a baseband integrated circuit in a server, cellular network node or device, or other computing or network device.

[0091] A computer program product may include one or more computerexecutable components which, when the program is run, are configured to carry out some example embodiments. The one or more computer-executable components may be at least one software code or portions of it. Modifications and configurations required for implementing functionality of certain example embodiments may be performed as routine(s), which may be implemented as added or updated software routine(s). Software routine(s) may be downloadedinto the apparatus.

[0092] As an example, software or a computer program code or portions of it may be in a source code form, object code form, or in some intermediate form, and it may be stored in some sort of carrier, distribution medium, or computer readable medium, which may be any entity or device capable of carrying the program. Such carriers may include a record medium, computer memory, read-only memory, photoelectrical and / or electrical carrier signal, telecommunications signal, and software distribution package, for example. Depending on the processing power needed, the computer program may be executed in a single electronic digital computer or it may be distributed amongst a number of computers. The computer readable medium or computer readable storage medium may be a non-transitory medium.

[0093] In other example embodiments, the functionality may be performed by hardware or circuitry included in an apparatus (for example, apparatuses 1010, 1020 and / or 1030), for example through the use of an application specific integrated circuit (ASIC), a programmable gate array (PGA), a field programmable gate array (FPGA), or any other combination of hardware and software. In yet another example embodiment, the functionality may be implemented as a signal, a non-tangible means that can be carried by an electromagnetic signal downloaded from the Internet or other network.

[0094] According to certain example embodiments, an apparatus, such as a node, device, or a corresponding component, may be configured as circuitry, a computer or a microprocessor, such as single-chip computer element, or as a chipset, including at least a memory for providing storage capacity used for arithmetic operation and an operation processor for executing the arithmetic operation.

[0095] The features, structures, or characteristics of example embodiments described throughout this specification may be combined in any suitable manner in one or more example embodiments. For example, the usage of thephrases “certain embodiments,” “an example embodiment,” “some embodiments,” or other similar language, throughout this specification refers to the fact that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment. Thus, appearances of the phrases “in certain embodiments,” “an example embodiment,” “in some embodiments,” “in other embodiments,” or other similar language, throughout this specification do not necessarily refer to the same group of embodiments, and the described features, structures, or characteristics may be combined in any suitable maimer in one or more example embodiments. Further, the terms “cell”, “node”, “gNB”, or other similar language throughout this specification may be used interchangeably.

[0096] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or,” mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0097] One having ordinary skill in the art will readily understand that the disclosure as discussed above may be practiced with procedures in a different order, and / or with hardware elements in configurations which are different than those which are disclosed. Therefore, although the disclosure has been described based upon these example embodiments, it would be apparent to those of skill in the art that certain modifications, variations, and alternative constructions would be apparent, while remaining within the spirit and scope of example embodiments. Although the above embodiments refer to 6G, 5G NR and LTE technology, the above embodiments may also apply to any other present or future 3 GPP technology, such as LTE-advanced, and / or fourth generation (4G) technology.

[0098] Partial Glossary:

[0099] 3 GPP 3rd Generation Partnership Project

[0100] 5G 5th Generation

[0101] 6G 6th Generation

[0102] ACK Acknowledgement

[0103] AMF Access and Mobility Function

[0104] AS Access Stratum

[0105] AUSF Authentication Server Function

[0106] CRM Customer Relationship Management

[0107] DL Downlink

[0108] EAP Extensible Authentication Protocol

[0109] ECDHE Ephemeral Elliptic Curve Diffie-Hellman

[0110] EMBB Enhanced Mobile Broadband

[0111] gNB 5G or Next Generation NodeB

[0112] HOOB Hash Out-of-Band

[0113] ID Identifier

[0114] loT Internet of Things

[0115] LTE Long Term Evolution

[0116] NAI Network Access Identifier

[0117] NAS Non-Access Stratum

[0118] NOOB Nimble Out-of-Band

[0119] Ns, Np Nonce of loT Device and Home Network

[0120] NR New Radio

[0121] PK Public Key

[0122] PKHN Public Key Home Network

[0123] RAN Radio Access Network

[0124] UDM Unified Data Management

[0125] UE User Equipment

[0126] UL Uplink

Claims

CLAIMS:

1. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive an out-of-band request message from a connected device; secure and transmit the out-of-band request message as a secured packet to a network entity; and transmit a received response message from the network entity to the connected device, wherein the response message triggers the connected device to complete a completion exchange procedure for authentication.

2. The apparatus according to claim 1, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: prior to receiving the out-of-band request message, connect to the connected device via an initial exchange procedure.

3. The apparatus according to claim 1 or claim 2, wherein the out-of-band request message comprises an identifier of the connected device which was assigned by the network entity, a nimble out-of-band value, and a hash out-of- band value.

4. The apparatus according to any one of claims 1-3, wherein the out-of- band request message is secured as the secured packet and transmitted by: using a previously established secure connection between the apparatus and the network entity during a registration procedure; or generating a secured uplink updated parameter packet using an authentication server function key.

5. The apparatus according to any one of claims 1-4, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: receive the response message from the network entity in response to transmitting the secured packet to the network entity, wherein the response message comprises a result of a validation procedure of the secured packet by the network entity.

6. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: generate a first network access identifier; perform an initial exchange procedure for connection with a network entity of a network using the first network access identifier; transmit an out-of-band request message to a user equipment; and in response to receiving a response message from a user equipment and upon completing the exchange procedure to authenticate the apparatus with the network, generate a security key to secure the connection between the apparatus and the network entity.

7. The apparatus according to claim 6, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: during the initial exchange procedure, receive a second network access identifier which was assigned by the network entity.

8. The apparatus according to claim 7, wherein the out-of-band request message comprises the second network access identifier, a nimble out-of-bandvalue, and a hash out-of-band value.

9. The apparatus according to any one of claims 6-8, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: receive the response message from the user equipment, wherein the response message comprises an indication that the apparatus is authenticated with the network.

10. The apparatus according to any one of claims 6-9, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: generate a session key based on the response message.11 . The apparatus according to claim 10, wherein the generated security key is derived from the generated session key.

12. An apparatus comprising : at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive a first network access identifier generated by a connected device; assign and transmit a second network access identifier to the connected device; obtain one or more out-of-band values from a secured packet received from a user equipment; validate the secured packet and transmit a response message to the user equipment indicating that the secured packet is validated; andupon completing an exchange procedure with a device connected to the user equipment, generate a security key based on a generated session key.

13. The apparatus according to claim 12, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: assign and transmit a peer identifier to the connected device.

14. The apparatus according to claim 13, wherein the secured packet comprises the peer identifier, a nimble out-of-band value, a hash out-of-band value, and a medium access control identifier.

15. The apparatus according to any one of claims 12-14, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: generate an uplink acknowledgement for an uplink packet; generate a downlink acknowledgement for the secured packet; and transmit the response message which comprises the uplink acknowledgement and the downlink acknowledgement.