Authorization of user equipment and authentication of user

The method and device enhance network authentication by correlating device and physical object presence in a designated area, addressing detection limitations and improving security through proactive authentication and granular access control.

WO2025264159A1PCT designated stage Publication Date: 2025-12-26TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050617
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Current authorization and authentication mechanisms in networks have limited detection capabilities, particularly for passive objects, and are complex to operate, leading to security vulnerabilities and inefficiencies in device and user authentication.

Method used

A method and device for authorizing user equipment and authenticating users by detecting the presence of both the device and a physical object in a designated area, using positioning and sensing technologies to correlate their positions and perform authentication procedures.

Benefits of technology

Enables proactive and context-aware authentication, reducing the need for user-initiated actions and providing granular control over access, ensuring device-to-user binding and enhancing security in high-security environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050617_26122025_PF_FP_ABST
    Figure SE2024050617_26122025_PF_FP_ABST
Patent Text Reader

Abstract

There is provided techniques for authorizing a user equipment and authenticating a user of the user equipment. A method is performed by an authorization and authentication device. The method comprises receiving an indication of a successful authorization procedure for the user equipment in a designated area. The method comprises performing an authentication procedure for the user, responsive to determining that a physical object in the designated area matches with the user equipment.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] AUTHORIZATION OF USER EQUIPMENT

[0002] AND AUTHENTICATION OF USER

[0003] TECHNICAL FIELD

[0004] Embodiments presented herein relate to a method, an authorization and authentication device, a computer program, and a computer program product for authorizing a user equipment and authenticating a user of the user equipment 130. Embodiments presented herein further relate to a method, a network node, a computer program, and a computer program product for authorizing the user equipment.

[0005] BACKGROUND

[0006] User authentication, as for example part of internet security, can be used to ensure that only authorized users can access protected resources, such as websites or applications. Authentication mechanisms are configured to establish the identity of the user by verifying credentials as provided by the user. In some non-limiting examples, the credentials might be a combination of a username and a password, digital certificates, or hardware tokens.

[0007] One used authentication mechanism is the Basic Access Authentication, specified in RFC 7617, denoted “The 'Basic' HTTP Authentication Scheme”. This requires the user to provide a username and password combination. This information is sent as a basebq-encoded string with each request, but this approach has some security concerns as it transmits credentials over the network in a form that can be easily intercepted and decoded.

[0008] To address the security concerns of RFC 7617, the “HTTP Digest Access Authentication” was introduced in RFC 7616. In this mechanism, the credentials are hashed and a nonce is used to prevent replay attacks, offering an improvement in security compared to in RFC 7617.

[0009] Another approach to user authentication has been implemented using OAuth (Open Authorization), as in RFC 6749 (“The OAuth 2.0 Authorization Framework”) and RFC 6750 (“The OAuth 2.0 Authorization Framework: Bearer Token Usage"), in general terms, OAuth introduces a token-based authorization mechanism where the users are not required to provide their credentials directly to the service. Instead, the users authenticate with an authorization server that grants service permissions for the users to access specific resources. OAuth allows third-party applications access to user data without revealing sensitive credentials.

[0010] For stronger authentication, two-factor authentication (2FA) or multi-factor authentication (MFA) processes can be employed. These mechanisms provide an additional layer of security by requiring users to provide not only a password but also another piece of information, such as a one-time password (OTP) generated by an application, a hardware token, or some biometric data like a fingerprint. This significantly reduce the risk of unauthorized access even if the user’s primary credentials are compromised.

[0011] Current mechanisms used in networks for authorization devices only have limited detection capabilities (e.g., relying on reports or signals from a device). In particular, current mechanisms are not able to detect passive objects (i.e., objects that did not perform transmissions). Thus, networks alone cannot not be used for detecting and authenticating users unless it could be assumed that the users would always carry a corresponding device.

[0012] Mechanisms which integrate different network elements for performing authorization and authentication may be complex to operate as well as having security issues (e.g., due to a required trust in a third party), etc.

[0013] Hence, there is still a need for improved technologies for authorization of devices and authentication of their users.

[0014] SUMMARY

[0015] An object of embodiments herein is to address the above issues by enabling joint authorization of devices and authentication of their users.

[0016] A particular object is to reduce the effort when needing to authorize multiple devices and authentication multiple users.

[0017] According to a first aspect there is presented a method for authorizing a user equipment and authenticating a user of the user equipment. The method is performed by an authorization and authentication device. The method comprises receiving an indication of a successful authorization procedure for the user equipment in a designated area. The method comprises performing an authentication procedure for the user, responsive to determining that a physical object in the designated area matches with the user equipment.

[0018] According to a second aspect there is presented an authorization and authentication device for authorizing a user equipment and authenticating a user of the user equipment. The authorization and authentication device comprises processing circuitry. The processing circuitry is configured to cause the authorization and authentication device to receive an indication of a successful authorization procedure for the user equipment in a designated area. The processing circuitry is configured to cause the authorization and authentication device to perform an authentication procedure for the user, responsive to determining that a physical object in the designated area matches with the user equipment.

[0019] According to a third aspect there is presented an authorization and authentication device for authorizing a user equipment and authenticating a user of the user equipment. The authorization and authentication device comprises a receive module configured to receive an indication of a successful authorization procedure for the user equipment in a designated area. The authorization and authentication device comprises an authentication module configured to perform an authentication procedure for the user, responsive to determining that a physical object in the designated area matches with the user equipment.

[0020] According to a fourth aspect there is presented a computer program for authorizing a user equipment and authenticating a user of the user equipment. The computer program comprises computer code which, when run on processing circuitry of an authorization and authentication device, causes the authorization and authentication device to perform actions. One action comprises the authorization and authentication device to receive an indication of a successful authorization procedure for the user equipment in a designated area. One action comprises the authorization and authentication device to perform an authentication procedure for the user, responsive to determining that a physical object in the designated area matches with the user equipment.

[0021] According to a fifth aspect there is presented a method for authorizing a user equipment. The method is performed by a network node. The method comprises detecting presence of the user equipment and presence of a physical object in a designated area. The method comprises performing an authorization procedure for the user equipment, responsive to determining that the physical object in the designated area matches with the user equipment.

[0022] According to a sixth aspect there is a network node for authorizing a user equipment. The network node comprises processing circuitry. The processing circuitry is configured to cause the network node to detect presence of the user equipment and presence of a physical object in a designated area. The processing circuitry is configured to cause the network node to perform an authorization procedure for the user equipment, responsive to determining that the physical object in the designated area matches with the user equipment.

[0023] According to a seventh aspect there is presented a network node for authorizing a user equipment. The network node comprises a detect module configured to detect presence of the user equipment and presence of a physical object in a designated area. The network node comprises an authorization module configured to perform an authorization procedure for the user equipment, responsive to determining that the physical object in the designated area matches with the user equipment.

[0024] According to an eighth aspect there is presented a computer program for authorizing a user equipment. The computer program comprises computer code which, when run on processing circuitry of a network node, causes the network node to perform actions. One action comprises the network node to detect presence of the user equipment and presence of a physical object in a designated area. One action comprises the network node to perform an authorization procedure for the user equipment, responsive to determining that the physical object in the designated area matches with the user equipment.

[0025] According to a ninth aspect there is presented a computer program product comprising a computer program according to at least one of the fourth aspect and the eighth aspect and a computer readable storage medium on which the computer program is stored. The computer readable storage medium could be a non-transitory computer readable storage medium. Advantageously, these aspects provide efficient joint authorization of pieces of user equipment and authentication of their users.

[0026] Advantageously, these aspects enable the physical activity of objects (as represented by users) and devices (as represented by their pieces of user equipment) in a designated area to be correlated with authentication procedures. This provides a context-aware authentication model with more information than traditional authentication (e.g., more than just a username and password combination).

[0027] Advantageously, these aspects ensure that the device-to-user binding is verified. This is a step beyond traditional two-factor authentication (2FA), and enables an additional layer of assurance, especially in high-security environments.

[0028] Advantageously, these aspects involve detection and authentication of both user equipment and users proactively and therefore prevent unauthorized access in the first place. This is in contrast to traditional systems where alarms only are triggered after unauthorized access has occurred.

[0029] Advantageously, since the detection is based on activity in a designated area, the need for user-initiated actions (such as swiping an identity card in a terminal) for authentication is reduced.

[0030] Advantageously, by being able to discern between different objects and devices in an designated area, the herein disclosed aspects enable a more granular control over which user or what user equipment is allowed access. This can be especially useful in environments where different clearance levels are required for different designated areas or resources.

[0031] Other objectives, features and advantages of the enclosed embodiments will be apparent from the following detailed disclosure, from the attached dependent claims as well as from the drawings.

[0032] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, module, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, module, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.

[0033] BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The inventive concept is now described, by way of example, with reference to the accompanying drawings, in which:

[0035] Fig. 1 is a schematic diagram illustrating a communication system according to embodiments;

[0036] Figs. 2 and 3 are flowcharts of methods according to embodiments;

[0037] Figs. 4, 5, 6, and 7 are signaling diagrams of methods according to embodiments;

[0038] Fig. 8 is a schematic diagram showing structural units of an authorization and authentication device according to an embodiment;

[0039] Fig. 9 is a schematic diagram showing functional modules of an authorization and authentication device according to an embodiment;

[0040] Fig. 10 is a schematic diagram showing structural units of a network node according to an embodiment;

[0041] Fig. 11 is a schematic diagram showing functional modules of a network node according to an embodiment; and

[0042] Fig. 12 shows one example of a computer program product comprising computer readable means according to an embodiment.

[0043] DETAILED DESCRIPTION

[0044] The inventive concept will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the inventive concept are shown. This inventive concept may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concept to those skilled in the art. Like numbers refer to like elements throughout the description. Any step or feature illustrated by dashed lines should be regarded as optional.

[0045] Fig. 1 is a schematic diagram illustrating a communication system loo where embodiments presented herein can be applied. It is assumed that at least one user equipment 130-1, 130-2, 130-3 is to be authorized and that a user 140-1, 140-2, 140-3 of each user equipment 130-1, 130-2, 130-3 is to be authenticated for being allowed to be present in a designated area 150, and possibly for entering a restricted area 160 from the designated area 150. The user equipment 130-1, 130-2, 130-3 is generally any type of portable wireless device, such as a mobile station, mobile phone, handset, wireless local loop phone, smartphone, laptop computer, tablet computer, smart wearable, etc. as can be carried by the user 140-1, 140-2, 140-3. Further, it is assumed that each user equipment 130-1, 130-2, 130-3 is located at a respective position 170-1, 170-2, 170-3 and that each user 140-1, 140-2, 140-3 is located at a respective position 180-1, 140-2, 140-3.

[0046] For the purpose of authorizing the user equipment 130-1, 130-2, 130-3 and authenticating the user 140-1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130- 3, the communication system 100 comprises an authorization and authentication device no and a network node 120. In some examples, the authorization and authentication device 110 is provided as a server that is running authentication and authorization software, e.g., OAuth (short for Open Authorization). In some examples, the functionality of the authorization and authentication device no is split between two or more devices. It is assumed that the user equipment 130-1, 130-2, 130-3 and the network node 120 are configured for wireless communication with each other over a wireless link 190. In general terms, the network node 120 could be a (radio) access network node, such as any of a radio base station, base transceiver station, node B (NB), evolved node B (eNB), gNB, access point, access node, integrated access and backhaul (IAN) node, or the like. In this respect, and as will be further disclosed below, operations as performed by the authorization and authentication device no as well as the network node 120, for example, for of authorizing the user equipment 130-1, 130-2, 130-3 and authenticating the user 140- 1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130-3 might be performed by one or more physical devices. Further aspects of the authorization and authentication device 110 as well as the network node 120 will be disclosed below. Reference is now made to Fig. 2 illustrating a method for authorizing the user equipment 130-1, 130-2, 130-3 and authenticating the user 140-1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130-3 as performed by the authorization and authentication device no according to an embodiment.

[0047] S108: The authorization and authentication device 110 receives an indication of a successful authorization procedure for the user equipment 130-1, 130-2, 130-3 in a designated area 150.

[0048] S110: The authorization and authentication device no performs an authentication procedure for the user 140-1, 140-2, 140-3, responsive to determining that a physical object in the designated area 150 matches with the user equipment 130-1, 130-2, 130- 3-

[0049] Embodiments relating to further details of authorizing the user equipment 130-1, 130-2, 130-3 and authenticating the user 140-1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130-3 as performed by the authorization and authentication device 110 will now be disclosed with continued reference to Fig. 2.

[0050] Aspects of detection of the object as performed by the authorization and authentication device no will be disclosed next.

[0051] In some aspects, the authorization and authentication device 110 also performs the detection of the object. Hence, in some embodiments, the authorization and authentication device 110 is configured to perform (optional) step S102.

[0052] S102: The authorization and authentication device 110 obtains an indication of presence of the physical object having been detected in the designated area 150 and an estimate of a position 180-1, 180-2, 180-3 of the physical object in the designated area 150.

[0053] However, in other aspects and as will be further disclosed below, the detection of the object is performed by the network node no.

[0054] In some aspects, the matching of the physical object in the designated area with the user equipment 130-1, 130-2, 130-3 is dependent on the relative distance between the physical object and the user equipment 130-1, 130-2, 130-3. In particular, in some embodiments, the physical object in the designated area matches with the user equipment 130-1, 130-2, 130-3 only in case a position of the physical object in the designated area corresponds to a position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3.

[0055] Aspects of detection of the user equipment 130-1, 130-2, 130-3 as performed by the authorization and authentication device no will be disclosed next.

[0056] In some aspects, the authorization and authentication device no also performs the detection of the user equipment 130-1, 130-2, 130-3. Hence, in some embodiments, the authorization and authentication device 110 is configured to perform (optional) step S104.

[0057] S104: The authorization and authentication device 110 obtains an indication of presence of the user equipment 130-1, 130-2, 130-3 having been detected in the designated area 150 and an estimate of the position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3 in the designated area 150.

[0058] However, in other aspects and as will be further disclosed below, the detection of the user equipment 130-1, 130-2, 130-3 is performed by the network node no.

[0059] In some aspects, the estimated position 180-1, 180-2, 180-3 of the physical object in the designated area 150 and the estimated position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3 in the designated area 150 are correlated with each other as a means to determine whether the object is associated with the user equipment 130-1, 130-2, 130-3 or not. Particularly, in some embodiments, the authorization and authentication device no is configured to perform (optional) step S106.

[0060] S106: The authorization and authentication device 110 establishes the matching between the user equipment 130-1, 130-2, 130-3 and the physical object by correlating the presence and the position 180-1, 180-2, 180-3 of the physical object in the designated area 150 to the presence and the position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3 in the designated area 150.

[0061] Aspects of authorization of the user equipment 130-1, 130-2, 130-3 as performed by the authorization and authentication device no will be disclosed next. In some aspects, the authorization and authentication device no also performs the authorization of the user equipment 130-1, 130-2, 130-3. Hence, in some embodiments, the authorization and authentication device no is configured to perform (optional) step S108-2 as part of step S108.

[0062] S108-2: The authorization and authentication device 110 performs the authorization procedure for the user equipment 130-1.

[0063] In some aspects, the authorization procedure for the user equipment 130-1 is performed upon the authorization and authentication device 110 having established a matching (e.g., as in step S106) between the user equipment 130-1 and the physical object.

[0064] The authorization procedure might comprise performing either a database lookup or checking credentials of the user equipment 130-1, 130-2, 130-3. For example, the authorization and authentication device no might access a database to determine that the user equipment 130-1, 130-2, 130-3 is authorized for designated area 150. That is, in some embodiments, performing the authorization procedure for the user equipment 130-1, 130-2, 130-3 comprises verifying that the user equipment 130-1, 130-2, 130-3 is included in a list of devices for which access to the designated area 150 is allowed. For example, the authorization and authentication device 110 might check whether or not the user equipment 130-1, 130-2, 130-3 is in possession of credentials associated with the designated area 150. That is, in some embodiments, performing the authorization procedure for the user equipment 130-1, 130-2, 130-3 comprises verifying that the user equipment 130-1, 130-2, 130-3 is in possession of credentials required for being allowed access to the designated area 150.

[0065] However, in other aspects and as will be further disclosed below, the authorization of the user equipment 130-1, 130-2, 130-3 is performed by the network node no.

[0066] Aspects of user authentication as performed by the authorization and authentication device no will be disclosed next.

[0067] As disclosed above, the authorization and authentication device 110 in step S110 performs an authentication procedure for the user 140-1, 140-2, 140-3. In this respect, there could be different types of authentication procedures that are performed.

[0068] In some non-limiting examples, performing the authentication procedure for the user 140-1, 140-2, 140-3 comprises at least one of: validating a response received from the user 140-1, 140-2, 140-3 via the user equipment 130-1, 130-2, 130-3 to a challenge sent to the user 140-1, 140-2, 140-3 via the user equipment 130-1, 130-2, 130-3, performing two-factor authentication of the user, performing biometric identification of the user. Further, in some examples the authentication procedure involves using integrated sensing and communication (ISAC). In this respect, ISAC is sometimes also referred to as integrated communication and sensing (ICAS) and joint communication and sending (JCAS). The term ISAC will hereinafter be used to represent all these concepts. Here, the authorization and authentication device no might trigger the user 140-1, 140-2, 140-3 to perform some specified gesture, and the network node 120 performs an ISAC procedure capture a radio wave pattern, resulting from the user 140-1, 140-2, 140-3 performing the gesture. This radio wave pattern could then be compared to a template pattern that corresponds to the gesture, which could involve some movement of the user 140-1, 140-2, 140-3, in order for the authorization and authentication device 110 to determine whether or the user 140-1, 140-2, 140-3 performed the gesture or not. In particular, in some embodiments, the authorization and authentication device no is configured to perform (optional) steps S110-2 and S110-4 as part of step S108.

[0069] S110-2: The authorization and authentication device no sends instructions to the user equipment 130-1, 130-2, 130-3. The instructions prompt the user 140-1, 140-2, 140-3 to perform a gesture as specified in the instructions in the designated area 150.

[0070] S110-4: The authorization and authentication device 110 initiates an integrated sensing and communication procedure in the designated area 150 to validate a performance (by the user 140-1, 140-2, 140-3) of the gesture.

[0071] In case the authentication of the user 140-1, 140-2, 140-3 is successful, the user 140-1, 140-2, 140-3 (and the user equipment 130-1, 130-2, 130-3 belonging to the user 140- 1, 140-2, 140-3) are allowed access to the designated area 150 and / or the restricted area 160. hence, in some embodiments, the authorization and authentication device no is configured to perform (optional) step S112. S112: The authorization and authentication device no grants access for the user equipment 130-1, 130-2, 130-3 and the user 140-1, 140-2, 140-3 to the designated area 150 and / or to a restricted area 160 adjoining the designated area 150 only in case the user 140-1, 140-2, 140-3 is successfully authenticated.

[0072] Reference is now made to Fig. 3 illustrating a method for authorizing the user equipment 130-1, 130-2, 130-3 as performed by the network node 120 according to an embodiment.

[0073] S202: The network node 120 detects presence of the user equipment 130-1, 130-2, 130-3 and presence of a physical object in a designated area 150.

[0074] S208: The network node 120 performs an authorization procedure for the user equipment 130-1, 130-2, 130-3, responsive to determining that the physical object in the designated area matches with the user equipment 130-1, 130-2, 130-3.

[0075] Embodiments relating to further details of authorizing the user equipment 130-1, 130-2, 130-3 as performed by the network node 120 will now be disclosed with continued reference to Fig. 3.

[0076] Aspects of detection of the object as performed by the network node 120 will be disclosed next.

[0077] As disclosed above, in some aspects, the matching of the physical object in the designated area with the user equipment 130-1, 130-2, 130-3 is dependent on the relative distance between the physical object and the user equipment 130-1, 130-2, 130-3. That is, in some embodiments, the physical object in the designated area matches with the user equipment 130-1, 130-2, 130-3 only in case a position 180-1, 180-2, 180-3 of the physical object in the designated area 150 corresponds to a position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3.

[0078] As further disclosed above, in some aspects, the estimated position 180-1, 180-2, 180- 3 of the physical object in the designated area 150 and the estimated position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3 in the designated area 150 are correlated with each other as a means to determine whether the object is be associated with the user equipment 130-1, 130-2, 130-3 or not. Particularly, in some embodiments, the network node 120 is configured to perform (optional) step S206. S206: The network node 120 establishes a matching probability between the user equipment 130-1, 130-2, 130-3 and the physical object by correlating presence and position 180-1, 180-2, 180-3 of the physical object in the designated area 150 to presence and position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3 in the designated area 150.

[0079] Aspects of detection of the object as performed by the network node 120 will be disclosed next.

[0080] In some aspects, the network node 120 also performs the detection of the object.

[0081] In particular, in some embodiments, the presence of the physical object is detected by means of a positioning technology, a sensing technology, and / or ISAC technology. In terms of sensing, the object might be detected by the network node 120 transmitting a sensing signal and receiving a corresponding reflection (e.g., from the object). In this respect, the sensing signal could either be a dedicated sensing signal, or a communication signal if ISAC is used. Reception of the reflection may take place in the same network node that transmitted the sensing signal or in a different network node.

[0082] However, in other aspects and as disclosed above, the detection of the object is performed by the authorization and authentication device no.

[0083] In some aspects, the network node 120 also performs estimation of the position 170- 1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3.

[0084] In particular, in some embodiments, the network node 120 is configured to perform (optional) step S204.

[0085] S204: The network node 120 estimates a position 170-1, 170-2, 170-3 of the user equipment 130-1, 130-2, 130-3 in the designated area 150.

[0086] In terms of positioning, the user equipment 130-1, 130-2, 130-3 might be detected by the network node 120 receiving positioning signals, or other types of signals, transmitted by the user equipment 130-1, 130-2, 130-3, or by receiving positioning information (e.g., coordinates) transmitted by the user equipment 130-1, 130-2, 130- 3.The signal transmitted by the user equipment 130-1, 130-2, 130-3 might thus not necessarily be a dedicated positioning signal, but it maybe any signal that can be used by the network node 120 for this purpose. For example, a communication signal or a discovery signal as transmitted by the user equipment 130-1, 130-2, 130-3 can be sed for this purpose.

[0087] However, in other aspects and as disclosed above, the detection of the user equipment 130-1, 130-2, 130-3 is performed by the authorization and authentication device no.

[0088] The network node 120 might also identify the user equipment 130-1, 130-2, 130-3 e.g., in terms of the network identity of the user equipment 130-1, 130-2, 130-3. That is, in some embodiments, the presence of the user equipment 130-1, 130-2, 130-3 is detected by communicating with the user equipment 130-1, 130-2, 130-3, and as part of communicating with the user equipment 130-1, 130-2, 130-3 receiving a device identity of the user equipment 130-1, 130-2, 130-3.

[0089] In some aspects, first object detection is performed, and then user equipment detection is performed, or vice versa. That is, in some embodiments, having detected the presence of the physical object triggers the presence of the user equipment 130-1, 130-2, 130-3 to be detected, or vice versa.

[0090] As disclosed above, the network node 120 in step S208 performs an authorization procedure for the user equipment 130-1, 130-2, 130-3. There could be different examples of such an authorization procedure. In some examples, the network node 120 accesses a database to determine that the user equipment 130-1, 130-2, 130-3 is authorized for designated area 150. That is, in some embodiments, performing the authorization procedure for the user equipment 130-1, 130-2, 130-3 (as in step S208) comprises verifying that the user equipment 130-1, 130-2, 130-3 is included in a list of devices for which access to the designated area 150 is allowed. In some examples, the network node 120 performs authorization based on credentials. That is, in some embodiments, performing the authorization procedure for the user equipment 130-1, 130-2, 130-3 (as in step S208) comprises verifying that the user equipment 130-1, 130-2, 130-3 is in possession of credentials required for being allowed access to the designated area 150. In some aspects, an alarm is issued when the physical object in the designated area fails to match with the user equipment 130-1, 130-2, 130-3. Therefore, in some embodiments, the network node 120 is configured to perform (optional) step S210.

[0091] S210: The network node 120 triggers an alarm event, responsive to determining that the physical object in the designated area fails to match with the user equipment 130- 1, 130-2, 130-3.

[0092] In some aspects, successful authorization of the user equipment 130-1, 130-2, 130-3 triggers user authentication. Therefore, in some embodiments, the network node 120 is configured to perform (optional) step S212.

[0093] S212: The network node 120 triggers an authentication procedure to be performed for a user 140-1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130-3, responsive to having successfully performed the authorization procedure for the user equipment 130-1, 130-2, 130-3.

[0094] As disclosed above, the user authentication might involve ISAC, as in above steps S110-2 and S110-4. For this purpose, the network node 120 might assist the authorization and authentication device no in the authentication procedure for the user 140-1, 140-2, 140-3. In particular, in some embodiments, the network node 120 is configured to perform (optional) step S214.

[0095] S214: The network node 120 assists in the authentication procedure by performing an integrated sensing and communication procedure in the designated area 150 to validate a performance of a gesture.

[0096] Further aspects of authorizing the user equipment 130-1, 130-2, 130-3 and authenticating the user 140-1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130-3 as performed by the authorization and authentication device no and the network node 120 will be disclosed next with references to Figs. 4, 5, 6, and 7.

[0097] Further aspects of device detection and object detection will be disclosed next with reference to the signaling diagram of Fig. 4.

[0098] Either the authorization and authentication device no or the network node 120 in the network detects an object (that might be a potential user 140-1, 140-2, 140-3) and obtains an estimate of its position 180-1, 180-2, 180-3, step S301. The object can be detected for example by means of sensing. The authorization and authentication device no or the network node 120 determines (e.g., based on the estimated position 180-1, 180-2, 180-3) that the object is in a designated area 150.

[0099] The network node 120 identifies a user equipment (UE) 130-1, 130-2, 130-3 and obtains an estimate of its position 170-1, 170-2, 170-3, step S302.

[0100] Either the authorization and authentication device no or the network node 120, based on the estimate of the position 180-1, 180-2, 180-3 of the object 140-1, 140-2, 140-3 and the estimate of the position 170-1, 170-2, 170-3 of the user equipment 130- 1, 130-2, 130-3, determines whether the object 140-1, 140-2, 140-3 is associated with the user equipment 130-1, 130-2, 130-3 (e.g., by the object 140-1, 140-2, 140-3 being a user that carries the user equipment 130-1, 130-2, 130-3) or not, step S303.

[0101] If the authorization and authentication device 110 or the network node 120 cannot identify any user equipment 130-1, 130-2, 130-3 with an estimated position 170-1, 170-2, 170-3 that is compatible with the estimated position 180-1, 180-2, 180-3 of the object, a procedure of unauthorized access detection is initiated.

[0102] If, on the other hand, the authorization and authentication device no or the network node 120 can identify a user equipment 130-1, 130-2, 130-3 with an estimated position 170-1, 170-2, 170-3 that is compatible with the estimated position 180-1, 180- 2, 180-3 of the object, the procedure in Fig. 5 can be entered. More than one user equipment 130-1, 130-2, 130-3 whose estimated position 170-1, 170-2, 170-3 is close to the estimated position 180-1, 180-2, 180-3 of the object can be identified. In such cases, all such user equipment 130-1, 130-2, 130-3 are considered in the procedure in Fig. 5-

[0103] Detection (of the objects) and identification (of the user equipment 130-1, 130-2, 130- 3) may be performed in any order. In some examples, either the authorization and authentication device no or the network node 120 first detects an object in the designated area 150. This detection can then trigger the identification of a potential user equipment 130-1, 130-2, 130-3 that may, or may not, correspond to the object. In another example, the network node 120 adds newly identified user equipment 130-1, 130-2, 130-3 in the designated area 150 to a list of user equipment 130-1, 130-2, 130- 3, and whenever an object is detected in the designated area 150, the list is used to, if possible, match the object to one of the user equipment 130-1, 130-2, 130-3 in the list.

[0104] Further aspects of device authorization will be disclosed next with reference to the signaling diagram of Fig. 5.

[0105] The network node 120 performs an authorization procedure to determine whether each user equipment 130-1, 130-2, 130-3 identified in the procedure of Fig. 4 is authorized for the designated area 150, steps S401 and S402. The network node 120 triggers an alarm procedure for any user equipment 130-1, 130-2, 130-3 is not authorized for the designated area 150. The procedure in Fig. 6 is entered for any user equipment 130-1, 130-2, 130-3 authorized for the designated area 150.

[0106] In some examples, the authorization of the user equipment 130-1, 130-2, 130-3 is performed by the network node 120 itself. For example, the network node 120 may maintain a list of user equipment 130-1, 130-2, 130-3 allowed in the designated area 150. For example, the network node 120 may maintain a list of IDs (e.g., IMSIs, UUIDs, etc.) of such user equipment 130-1, 130-2, 130-3. In other examples, the authorization of the user equipment 130-1, 130-2, 130-3 is performed by an external entity, such as the authorization and authentication device no or other type of server. For example, the user equipment 130-1, 130-2, 130-3 maybe prompted by the network node 120 to exchange some credentials (e.g., based on key material, etc.) with this external entity.

[0107] Further aspects of user authentication will be disclosed next with reference to the signaling diagram of Fig. 6.

[0108] The network node 120, upon the user 140-1, 140-2, 140-3 having entered the area and having been detected, step S501, triggers an authentication procedure to be performed for the user 140-1, 140-2, 140-3 of the user equipment 130-1, 130-2, 130-3, responsive to having successfully performed the authorization procedure for the user equipment 130-1, 130-2, 130-3 in Fig. 5, steps S501-S508.

[0109] The authentication of the user 140-1, 140-2, 140-3 can be performed using any of the above disclosed embodiments. That is, user authentication may involve one or more of; requesting the user 140-1, 140-2, 140-3 to provide a password or code, verifying the identify of the user 140-1, 140-2, 140-3 using a separate device, for example, by means of biometric identification, etc. In some examples, the authentication of the user 140-1, 140-2, 140-3 is performed by the authorization and authentication device (AAD) no. In some examples, the authentication of the user 140-1, 140-2, 140-3 is performed by the network node 120 itself. For example, a text message, with the challenge (i.e., using 2FA), may be transmitted by the network node 120 to the user equipment 130-1, 130-2, 130-3 of the user 140-1, 140-2, 140-3. In some examples, as disclosed in Fig. 7, the user authentication is based on ISAC. In the example of Fig. 6, the authentication of the user 140-1, 140-2, 140-3 comprises sending an authentication request to the user equipment 130-1, 130-2, 130-3 (step S503), having the user 140-1, 140-2, 140-3 entering a password (step S504), the user equipment 130-1, 130-2, 130-3 responding to the authorization and authentication device no network with the password (step S505), the authorization and authentication device no verifying the password and responding to the network (step S506), the network performing authentication with the user equipment 130-1, 130-2, 130-3 (steps S507, S508).

[0110] Further aspects of user authentication based on ISAC will be disclosed next with reference to the signaling diagram of Fig. 7.

[0111] The authorization and authentication device 110 sends a challenge with instructions to the user equipment 130-1, 130-2, 130-3, steps S601, S602. The instructions prompt the user 140-1, 140-2, 140-3 to perform a gesture as specified in the instructions in the designated area 150. The user 140-1, 140-2, 140-3 performs the requested gesture, step S603. In parallel, the network node 120 performs a sensing procedure (ISAC) to detect the gesture by capturing radio wave patterns caused by the gesture. The radio wave patterns are sent to the authorization and authentication device no, step S604. The authorization and authentication device no performs authentication, involving verifying the radio wave patterns against a template pattern that corresponds to the aforementioned instructions sent to the user equipment 130-1, 130-2, 130-3 to determine whether the gesture complied with the instructions or not, step S605. In case the gesture complied with the instructions, authorization and authentication device no sends a confirmation of the successful authentication to the user equipment 130-1, 130-2, 130-3, step S606. Two non-limiting and illustrative examples where the herein disclosed embodiments are applicable will be disclosed next.

[0112] The first example considers a single user equipment 130-1 having a single user 140-1. Assume that the user 140-1 is walking through an empty corridor with an aim to access a restricted area 160. The user 140-1 carries a user equipment 130-1. The network node 120, through IMSI, identifies the user equipment 130-1 and verifies that the user equipment 130-1 belongs to a user 140-1 that has access privileges for the restricted area 160. Hence, no alarm is triggered. The network node 120 uses ISAC or some other technology to search for moving objects, and detects at least one moving object (which represents the user 140-1). The network node 120 starts a matching procedure to associate different user equipment 130-1, 130-2, 130-3 to different detected objects. Given that the detected object that represents the user 140- 1 and the user equipment 130-1 are very close to each other (i.e., the distance between the positions 170-1 and 180-iis very small in Fig. 1), the network node 120 sends a challenge to the user equipment 130-1 to verify that the user equipment 130-iis carried by the user 140-1 that owns the user equipment 130-1 and not someone else. The user 140-1, through the user equipment 130-1, is, for example, requested to provide their fingerprint for authentication. The user 140-1 complies and the network node 120 assesses that the user equipment 130-1 is owned by the allowed user 140-1. The user 140-1 and the user equipment 130-1 are allowed to access the restricted area 160, e.g., by a locked door to the restricted area 160 being unlocked.

[0113] The second example considers multiple user equipment 130-1, 130-2, 130-3 and multiple users 140-1, 140-2, 140-3. Assume that the network node 120 detects three user equipment 130-1, 130-2, 130-3 and five moving objects (each corresponding to a potential user of one of the user equipment 130-1, 130-2, 130-3). Three objects match the positions of the three user equipment 130-1, 130-2, 130-3, and therefore the network node 120 sends out a challenge to each of the three user equipment 130-1, 130-2, 130-3 to verify that each user equipment 130-1, 130-2, 130-3 is carried by a respective authorized user 140-1, 140-2, 140-3. Each of the three user equipment 130- 1, 130-2, 130-3 receives the challenge for the user 140-1, 140-2, 140-3 to provide a password to an external authentication website. After an authentication attempt per user 140-1, 140-2, 140-3, it is concluded that only the user 140-1 of one of the user equipment 130-1 has the required authorization for the restricted area, whilst the users 140-2, 140-3 of the other two user equipment 130-2, 130-3 lack the right clearance. Only one user 140-1 (and their user equipment 130-1) is therefore granted access to the restricted area 160.

[0114] Fig. 8 schematically illustrates, in terms of a number of structural units, the components of an authorization and authentication device 800 according to an embodiment. Processing circuitry 810 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210a (as in Fig. 12), e.g. in the form of a storage medium 830. The processing circuitry 810 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).

[0115] Particularly, the processing circuitry 810 is configured to cause the authorization and authentication device 800 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 830 may store the set of operations, and the processing circuitry 810 maybe configured to retrieve the set of operations from the storage medium 830 to cause the authorization and authentication device 800 to perform the set of operations. The set of operations maybe provided as a set of executable instructions. Thus the processing circuitry 810 is thereby arranged to execute methods as herein disclosed.

[0116] The storage medium 830 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.

[0117] The authorization and authentication device 800 may further comprise a communications (comm.) interface 820 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 820 may comprise one or more transmitters and receivers, comprising analogue and digital components.

[0118] The processing circuitry 810 controls the general operation of the authorization and authentication device 800 e.g. by sending data and control signals to the communications interface 820 and the storage medium 830, by receiving data and reports from the communications interface 820, and by retrieving data and instructions from the storage medium 830. Other components, as well as the related functionality, of the authorization and authentication device 800 are omitted in order not to obscure the concepts presented herein.

[0119] Fig. 9 schematically illustrates, in terms of a number of functional modules, the components of an authorization and authentication device 900 according to an embodiment. The authorization and authentication device 900 of Fig. 9 comprises a number of functional modules; a receive module 940 configured to perform step S108, and an authentication (Auth.) module 960 configured to perform step S110. The authorization and authentication device 900 of Fig. 9 may further comprise a number of optional functional modules, such as any of an obtain module 910 configured to perform step S102, an obtain module 920 configured to perform step S104, an establish module 930 configured to perform step S106, an authorization (Auth.) module 950 configured to perform step S108-2, a send module 970 configured to perform step S110-2, an initiate module 980 configured to perform step S110-4, and a grant module 990 configured to perform step S112. In general terms, each functional module 910:990 maybe implemented in hardware or in software. Preferably, one or more or all functional modules 910:990 maybe implemented by the processing circuitry 810, possibly in cooperation with the communications interface 820 and / or the storage medium 830. The processing circuitry 810 may thus be arranged to from the storage medium 830 fetch instructions as provided by a functional module 910:990 and to execute these instructions, thereby performing any steps of the authorization and authentication device 800 as disclosed herein.

[0120] Fig. 10 schematically illustrates, in terms of a number of structural units, the components of a network node 1000 according to an embodiment. Processing circuitry 1010 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210b (as in Fig. 12), e.g. in the form of a storage medium 1030. The processing circuitry 1010 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA). Particularly, the processing circuitry 1010 is configured to cause the network node IOOO to perform a set of operations, or steps, as disclosed above. For example, the storage medium 1030 may store the set of operations, and the processing circuitry 1010 may be configured to retrieve the set of operations from the storage medium 1030 to cause the network node 1000 to perform the set of operations. The set of operations maybe provided as a set of executable instructions. Thus the processing circuitry 1010 is thereby arranged to execute methods as herein disclosed.

[0121] The storage medium 1030 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.

[0122] The network node 1000 may further comprise a communications interface 1020 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 1020 may comprise one or more transmitters and receivers, comprising analogue and digital components.

[0123] The processing circuitry 1010 controls the general operation of the network node 1000 e.g. by sending data and control signals to the communications interface 1020 and the storage medium 1030, by receiving data and reports from the communications interface 1020, and by retrieving data and instructions from the storage medium 1030. Other components, as well as the related functionality, of the network node 1000 are omitted in order not to obscure the concepts presented herein.

[0124] Fig. 11 schematically illustrates, in terms of a number of functional modules, the components of a network node 1000 according to an embodiment. The network node 1100 of Fig. 11 comprises a number of functional modules; a detect module 1110 configured to perform step S202, and an authorization (Auth.) module 1140 configured to perform step S208. The network node 1000 of Fig. 11 may further comprise a number of optional functional modules, such as any of an estimate module 1120 configured to perform step S204, an establish module 1130 configured to perform step S206, a trigger module 1150 configured to perform step S210, a trigger module 1160 configured to perform step S212, and an assist module 1170 configured to perform step S214. In general terms, each functional module 1110:1170 maybe implemented in hardware or in software. Preferably, one or more or all functional modules 1110:1170 maybe implemented by the processing circuitry 1010, possibly in cooperation with the communications interface 1020 and / or the storage medium 1030. The processing circuitry 1010 may thus be arranged to from the storage medium 1030 fetch instructions as provided by a functional module 1110:1170 and to execute these instructions, thereby performing any steps of the network node 1000 as disclosed herein.

[0125] The authorization and authentication device 800 and / or the network node 1000 may be provided as respective standalone devices or as a part of at least one further device. For example, the authorization and authentication device 800 and / or network node 1000 maybe provided in a node of a (radio) access network or in a node of a core network. Alternatively, functionality of the authorization and authentication device 800 and / or network node 1000 maybe distributed between at least two devices, or nodes. These at least two nodes, or devices, may either be part of the same network part (such as the (radio) access network or the core network) or may be spread between at least two such network parts. In general terms, instructions that are required to be performed in real time may be performed in a device, or node, operatively closer to the cell than instructions that are not required to be performed in real time. A first portion of the instructions performed by the authorization and authentication device 800 / network node 1000 maybe executed in a first device, and a second portion of the instructions performed by the authorization and authentication device 800 / network node 1000 maybe executed in a second device; the herein disclosed embodiments are not limited to any particular number of devices on which the instructions performed by the authorization and authentication device 800 / network node 1000 maybe executed. Hence, the methods according to the herein disclosed embodiments are suitable to be performed by an authorization and authentication device 800 / network node 1000 residing in a cloud computational environment. Therefore, although a single processing circuitry 810, 1010 is illustrated in Figs. 8 and 10 the processing circuitry 810, 1010 maybe distributed among a plurality of devices, or nodes. The same applies to the functional modules 910:990, 1110:1170 of Figs. 9 and 11 and the computer programs 1220a, 1220b of Fig. 12. Fig. 12 shows one example of a computer program product 1210a, 1210b comprising computer readable means 1230. On this computer readable means 1230, a computer program 1220a can be stored, which computer program 1220a can cause the processing circuitry 810 and thereto operatively coupled entities and devices, such as the communications interface 820 and the storage medium 830, to execute methods according to embodiments described herein. The computer program 1220a and / or computer program product 1210a may thus provide means for performing any steps of the authorization and authentication device no, 800, 900 as herein disclosed. On this computer readable means 1230, a computer program 1220b can be stored, which computer program 1220b can cause the processing circuitry 1010 and thereto operatively coupled entities and devices, such as the communications interface 1020 and the storage medium 1030, to execute methods according to embodiments described herein. The computer program 1220b and / or computer program product 1210b may thus provide means for performing any steps of the network node 120, 1000, 1100 as herein disclosed.

[0126] In the example of Fig. 12, the computer program product 1210a, 1210b is illustrated as an optical disc, such as a CD (compact disc) or a DVD (digital versatile disc) or a Blu-Ray disc. The computer program product 1210a, 1210b could also be embodied as a memory, such as a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM) and more particularly as a non-volatile storage medium of a device in an external memory such as a USB (Universal Serial Bus) memory or a Flash memory, such as a compact Flash memory. Thus, while the computer program 1220a, 1220b is here schematically shown as a track on the depicted optical disk, the computer program 1220a, 1220b can be stored in any way which is suitable for the computer program product 1210a, 1210b.

[0127] The inventive concept has mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the inventive concept, as defined by the appended patent claims.

Claims

CLAIMS1. A method for authorizing a user equipment (130-1) and authenticating a user (140-1) of the user equipment (130-1), wherein the method is performed by an authorization and authentication device (110), and wherein the method comprises: receiving (S108) an indication of a successful authorization procedure for the user equipment (130-1) in a designated area (150); and performing (S110) an authentication procedure for the user (140-1), responsive to determining that a physical object in the designated area (150) matches with the user equipment (130-1).

2. The method according to claim 1, wherein the method further comprises: obtaining (S102) an indication of presence of the physical object having been detected in the designated area (150) and an estimate of a position (180-1) of the physical object in the designated area (150).

3. The method according to claim 1 or 2, wherein the physical object in the designated area matches with the user equipment (130-1) only in case a position of the physical object in the designated area corresponds to a position (170-1) of the user equipment (130-1).

4. The method according to claim 3, wherein the method further comprises: obtaining (S104) an indication of presence of the user equipment (130-1) having been detected in the designated area (150) and an estimate of the position (170-1) of the user equipment (130-1) in the designated area (150).

5. The method according to claims 2 and 4, wherein the method further comprises: establishing (S106) the matching between the user equipment (130-1) and the physical object by correlating the presence and the position (180-1) of the physical object in the designated area (150) to the presence and the position (170-1) of the user equipment (130-1) in the designated area (150).

6. The method according to any preceding claim, wherein the method further comprises: performing (S108-2) the authorization procedure for the user equipment (130- 1) upon having established a matching between the user equipment (130-1) and the physical object.

7. The method according to claim 6, wherein performing the authorization procedure for the user equipment (130-1) comprises verifying that the user equipment (130-1) is included in a list of devices for which access to the designated area (150) is allowed.

8. The method according to claim 6, wherein performing the authorization procedure for the user equipment (130-1) comprises verifying that the user equipment (130-1) is in possession of credentials required for being allowed access to the designated area (150).

9. The method according to any preceding claim, wherein performing the authentication procedure for the user (140-1) comprises at least one of:- validating a response received from the user (140-1) via the user equipment (130-1) to a challenge sent to the user (140-1) via the user equipment (130-1),- performing two-factor authentication of the user,- performing biometric identification of the user.

10. The method according to any preceding claim, wherein performing the authentication procedure for the user (140-1) comprises: sending (S110-2) instructions to the user equipment (130-1), the instructions prompting the user (140-1) to perform a gesture as specified in the instructions in the designated area (150); and initiating (S110-4) an integrated sensing and communication procedure in the designated area (150) to validate a performance of the gesture.

11. The method according to any preceding claim, wherein the method further comprises:granting (S112) access for the user equipment (130-1) and the user (140-1) to the designated area (150) and / or to a restricted area (160) adjoining the designated area (150) only in case the user (140-1) is successfully authenticated.

12. A method for authorizing a user equipment (130-1), wherein the method is performed by a network node (120), and wherein the method comprises: detecting (S202) presence of the user equipment (130-1) and presence of a physical object in a designated area (150); and performing (S208) an authorization procedure for the user equipment (130-1), responsive to determining that the physical object in the designated area matches with the user equipment (130-1).

13. The method according to claim 12, further comprising: triggering (S210) an alarm event, responsive to determining that the physical object in the designated area fails to match with the user equipment (130-1).

14. The method according to claim 12 or 13, wherein the physical object in the designated area matches with the user equipment (130-1) only in case a position of the physical object in the designated area corresponds to a position of the user equipment (130-1).

15. The method according to any of claims 12 to 14, further comprising: establishing (S206) a matching probability between the user equipment (130-1) and the physical object by correlating presence and position (180-1) of the physical object in the designated area (150) to presence and position (170-1) of the user equipment (130-1) in the designated area (150).

16. The method according to any of claims 12 to 15, wherein the presence of the physical object is detected by means of a positioning technology, a sensing technology, and / or an integrated sensing and communication technology.

17. The method according to any of claims 12 to 16, wherein the method further comprises:estimating (S204) a position (170-1) of the user equipment (130-1) in the designated area (150).

18. The method according to claim 17, wherein the presence of the user equipment (130-1) is detected by communicating with the user equipment (130-1), and as part of communicating with the user equipment (130-1) receiving a device identity of the user equipment (130-1).

19. The method according to claim 18, wherein having detected the presence of the physical object triggers the presence of the user equipment (130-1) to be detected, or vice versa.

20. The method according to any of claims 12 to 19, wherein performing the authorization procedure for the user equipment (130-1) comprises verifying that the user equipment (130-1) is included in a list of devices for which access to the designated area (150) is allowed.

21. The method according to any of claims 12 to 20, wherein performing the authorization procedure for the user equipment (130-1) comprises verifying that the user equipment (130-1) is in possession of credentials required for being allowed access to the designated area (150).

22. The method according to any of claims 12 to 21, wherein the method further comprises: triggering (S212) an authentication procedure to be performed for a user (140-1) of the user equipment (130-1), responsive to having successfully performed the authorization procedure for the user equipment (130-1).

23. The method according to claim 22, wherein the method further comprises: assisting (S214) in the authentication procedure by performing an integrated sensing and communication procedure in the designated area (150) to validate a performance of a gesture.

24. An authorization and authentication device (110) for authorizing a user equipment (130-1) and authenticating a user (140-1) of the user equipment (130-1), the authorization and authentication device (110) comprising processing circuitry(8io), the processing circuitry being configured to cause the authorization and authentication device (no) to: receive an indication of a successful authorization procedure for the user equipment (130-1) in a designated area (150); and perform an authentication procedure for the user (140-1), responsive to determining that a physical object in the designated area (150) matches with the user equipment (130-1).

25. An authorization and authentication device (no) for authorizing a user equipment (130-1) and authenticating a user (140-1) of the user equipment (130-1), the authorization and authentication device (no) comprising: a receive module configured to receive an indication of a successful authorization procedure for the user equipment (130-1) in a designated area (150); and an authentication module configured to perform an authentication procedure for the user (140-1), responsive to determining that a physical object in the designated area (150) matches with the user equipment (130-1).

26. The authorization and authentication device (110) according to claim 23 or 24, further being configured to perform the method according to any of claims 2 to 11.

27. A network node (120) for authorizing a user equipment (130-1), the network node (120) comprising processing circuitry (1010), the processing circuitry being configured to cause the network node (120) to: detect presence of the user equipment (130-1) and presence of a physical object in a designated area (150); and perform an authorization procedure for the user equipment (130-1), responsive to determining that the physical object in the designated area matches with the user equipment (130-1X130-1).

28. A network node (120) for authorizing a user equipment (130-1), the network node (120) comprising:a detect module configured to detect presence of the user equipment (130-1) and presence of a physical object in a designated area (150); and an authorization module configured to perform an authorization procedure for the user equipment (130-1), responsive to determining that the physical object in the designated area matches with the user equipment (13O-I)(13O-I).

29. The network node (120) according to claim 27 or 28, further being configured to perform the method according to any of claims 13 to 24.

30. A computer program (1220a) for authorizing a user equipment (130-1) and authenticating a user (140-1) of the user equipment (130-1), the computer program comprising computer code which, when run on processing circuitry (810) of an authorization and authentication device (110), causes the authorization and authentication device (110) to: receive (S108) an indication of a successful authorization procedure for the user equipment (130-1) in a designated area (150); and perform (S110) an authentication procedure for the user (140-1), responsive to determining that a physical object in the designated area (150) matches with the user equipment (130-1).

31. A computer program (1220b) for authorizing a user equipment (130-1), the computer program comprising computer code which, when run on processing circuitry (1010) of a network node (120), causes the network node (120) to: detect (S202) presence of the user equipment (130-1) and presence of a physical object in a designated area (150); and perform (S208) an authorization procedure for the user equipment (130-1), responsive to determining that the physical object in the designated area matches with the user equipment (13O-I)(13O-I).

32. A computer program product (1210a, 1210b) comprising a computer program (1220a, 1220b) according to at least one of claims 30 and 31, and a computer readable storage medium (1230) on which the computer program is stored.

Citation Information

Patent Citations

  • Trusted seamless authentication method for access control

    EP4216180A1

  • Enhanced alternative multifactor authentication

    US20160371475A1

  • Method for changing mobile communications device functionality based upon receipt of a second code and the location of a key device

    US20190286806A1

  • Systems and methods for tiered authentication including position-based credentials

    US20210014213A1

  • Utilizing a High Generation Cellular Network to Authorize an Event

    US20230217247A1