Devices and methods for access security and privacy
A communication method for AIoT devices with limited energy storage addresses security and privacy challenges by managing device identification and security/privacy operations, ensuring efficient and secure communication.
Patent Information
- Application Number
- PCT/CN2024/107126
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-23
- Publication Date
- 2026-01-29
AI Technical Summary
Existing cellular devices are not suitable for ambient internet of things (AIoT) devices with limited energy storage capability due to high peak power consumption, and there is a need for efficient access security and privacy solutions for these devices.
A communication method involving multiple devices with processors to manage device identification and security/privacy operations, including indications for no security, reader identification-based, password/token-based, and mutual security/privacy operations, to facilitate secure and private communication for AIoT devices.
Enables secure and private communication for AIoT devices with limited energy storage by managing device identification and security/privacy operations effectively, ensuring efficient energy usage and compliance with AIoT device characteristics.
Smart Images

Figure CN2024107126_29012026_PF_FP_ABST
Abstract
Description
DEVICES AND METHODS FOR ACCESS SECURITY AND PRIVACYFIELD
[0001] Example embodiments of the present disclosure generally relate to the field of communication techniques and in particular, to devices and methods for access security and privacy for ambient internet of things (AIoT) device.BACKGROUND
[0002] Internet of Things, or internet of things (IoT) , refers to physical devices that can transfer data to one another without human intervention. The automation and digitalization of various industries open numbers of new markets requiring new IoT technologies of supporting battery-less devices with no energy storage capability or devices with energy storage that do not need to be replaced or recharged manually. It may consider devices being either battery-less or with limited energy storage capability (i.e., using a capacitor) and the energy is provided through the harvesting of radio waves, light, motion, heat, or any other power source that could be seen suitable. Considering the limited size and complexity required by practical applications for battery-less devices with no energy storage capability or devices with limited energy storage that do not need to be replaced or recharged manually, the output power of energy harvester is typically from 1μW to a few hundreds of μW. Existing cellular devices may not work well with energy harvesting due to their peak power consumption of higher than 10mW.SUMMARY
[0003] In general, embodiments of the present disclosure provide a solution on access security and privacy for ambient internet of things (AIoT) device.
[0004] In a first aspect, there is provided a first device. The first device comprises: a processor configured to cause the first device to: receive, from a second device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0005] In a second aspect, there is provided a second device. The second device comprises: a processor configured to cause the second device to: transmit, to a first device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0006] In a third aspect, there is provided a third device. The third device comprises: a processor configured to cause the third device to: receive, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the first device, a response to the request.
[0007] In a fourth aspect, there is provided a fourth device. The fourth device comprises: a processor configured to cause the fourth device to: receive, from a first device, a request for a device identification of a fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the fifth device, a further request for the device identification of the fifth device.
[0008] In a fifth aspect, there is provided a fifth device. The fifth device comprises: a processor configured to cause the fifth device to: receive, from a fourth device, a request for an device identification of the fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the fourth device, a response comprising the device identification of the fifth device.
[0009] In a sixth aspect, there is provided a communication method performed by a first device. The method comprises: receiving, from a second device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0010] In a seventh aspect, there is provided a communication method performed by a second device. The method comprises: transmitting, to a first device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0011] In an eighth aspect, there is provided a communication method performed by a third device. The method comprises: receiving, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmitting, to the first device, a response to the request.
[0012] In a ninth aspect, there is provided a communication method performed by a fourth device. The method comprises: receiving, from a first device, a request for a device identification of a fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmitting, to the fifth device, a further request for the device identification of the fifth device.
[0013] In a tenth aspect, there is provided a communication method performed by a fifth device. The method comprises: receiving, from a fourth device, a request for an device identification of the fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmitting, to the fourth device, a response comprising the device identification of the fifth device.
[0014] In an eleventh aspect, there is provided a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to carry out the method according to the sixth, seventh, eighth, ninth, or tenth aspect.
[0015] Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Through the more detailed description of some example embodiments of the present disclosure in the accompanying drawings, the above and other objects, features and advantages of the present disclosure will become more apparent, wherein:
[0017] FIG. 1A illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0018] FIG. 1B illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0019] FIG. 1C illustrates an example architecture of a communication system in accordance with some embodiments of the present disclosure;
[0020] FIG. 1D illustrates an example architecture of a communication system in accordance with some embodiments of the present disclosure;
[0021] FIG. 2 illustrates a signaling flow of a procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0022] FIG. 3 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0023] FIG. 4 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0024] FIG. 5 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0025] FIG. 6 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0026] FIG. 7 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0027] FIG. 8 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0028] FIG. 9 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0029] FIG. 10 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0030] FIG. 11 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0031] FIG. 12 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0032] FIG. 13 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0033] FIG. 14 illustrates a signaling flow of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure;
[0034] FIG. 15 illustrates a flowchart of a communication method implemented at a first device according to some example embodiments of the present disclosure;
[0035] FIG. 16 illustrates a flowchart of a communication method implemented at a second device according to some example embodiments of the present disclosure;
[0036] FIG. 17 illustrates a flowchart of a communication method implemented at a third device according to some example embodiments of the present disclosure;
[0037] FIG. 18 illustrates a flowchart of a communication method implemented at a fourth device according to some example embodiments of the present disclosure;
[0038] FIG. 19 illustrates a flowchart of a communication method implemented at a fifth device according to some example embodiments of the present disclosure; and
[0039] FIG. 20 illustrates a simplified block diagram of an apparatus that is suitable for implementing example embodiments of the present disclosure.
[0040] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0041] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0042] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0043] As used herein, the term ‘terminal device’ refers to any device having wireless or wired communication capabilities. Examples of the terminal device include, but not limited to, user equipment (UE) , personal computers, desktops, mobile phones, cellular phones, smart phones, personal digital assistants (PDAs) , portable computers, tablets, wearable devices, internet of things (IoT) devices, Ultra-reliable and Low Latency Communications (URLLC) devices, Internet of Everything (IoE) devices, machine type communication (MTC) devices, devices on vehicle for V2X communication where X means pedestrian, vehicle, or infrastructure / network, devices for Integrated Access and Backhaul (IAB) , Space borne vehicles or Air borne vehicles in Non-terrestrial networks (NTN) including Satellites and High Altitude Platforms (HAPs) encompassing Unmanned Aircraft Systems (UAS) , eXtended Reality (XR) devices including different types of realities such as Augmented Reality (AR) , Mixed Reality (MR) and Virtual Reality (VR) , the unmanned aerial vehicle (UAV) commonly known as a drone which is an aircraft without any human pilot, devices on high speed train (HST) , or image capture devices such as digital cameras, sensors, gaming devices, music storage and playback appliances, or Internet appliances enabling wireless or wired Internet access and browsing and the like. The ‘terminal device’ can further has ‘multicast / broadcast’ feature, to support public safety and mission critical, V2X applications, transparent IPv4 / IPv6 multicast delivery, IPTV, smart TV, radio services, software delivery over wireless, group communications and IoT applications. It may also incorporate one or multiple Subscriber Identity Module (SIM) as known as Multi-SIM. The term “terminal device” can be used interchangeably with a UE, a mobile station, a subscriber station, a mobile terminal, a user terminal or a wireless device.
[0044] The term “network device” refers to a device which is capable of providing or hosting a cell or coverage where terminal devices can communicate. Examples of a network device include, but not limited to, a Node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a next generation NodeB (gNB) , a transmission reception point (TRP) , a remote radio unit (RRU) , a radio head (RH) , a remote radio head (RRH) , an IAB node, a low power node such as a femto node, a pico node, a reconfigurable intelligent surface (RIS) , and the like.
[0045] The terminal device or the network device may have Artificial intelligence (AI) or Machine learning capability. It generally includes a model which has been trained from numerous collected data for a specific function, and can be used to predict some information.
[0046] The terminal or the network device may work on several frequency ranges, e.g., FR1 (e.g., 450 MHz to 6000 MHz) , FR2 (e.g., 24.25GHz to 52.6GHz) , frequency band larger than 100 GHz as well as Tera Hertz (THz) . It can further work on licensed / unlicensed / shared spectrum. The terminal device may have more than one connection with the network devices under Multi-Radio Dual Connectivity (MR-DC) application scenario. The terminal device or the network device can work on full duplex, flexible duplex and cross division duplex modes.
[0047] The embodiments of the present disclosure may be performed in test equipment, e.g., signal generator, signal analyzer, spectrum analyzer, network analyzer, test terminal device, test network device, channel emulator. In some embodiments, the terminal device may be connected with a first network device and a second network device. One of the first network device and the second network device may be a master node and the other one may be a secondary node. The first network device and the second network device may use different radio access technologies (RATs) . In some embodiments, the first network device may be a first RAT device and the second network device may be a second RAT device. In some embodiments, the first RAT device is eNB and the second RAT device is gNB. Information related with different RATs may be transmitted to the terminal device from at least one of the first network device or the second network device. In some embodiments, first information may be transmitted to the terminal device from the first network device and second information may be transmitted to the terminal device from the second network device directly or via the first network device. In some embodiments, information related with configuration for the terminal device configured by the second network device may be transmitted from the second network device via the first network device. Information related with reconfiguration for the terminal device configured by the second network device may be transmitted to the terminal device from the second network device directly or via the first network device.
[0048] As used herein, the singular forms ‘a’ , ‘an’ and ‘the’ are intended to include the plural forms as well, unless the context clearly indicates otherwise. The term ‘includes’ and its variants are to be read as open terms that mean ‘includes, but is not limited to. ’ The term ‘based on’ is to be read as ‘at least in part based on. ’ The term ‘one embodiment’ and ‘an embodiment’ are to be read as ‘at least one embodiment. ’ The term ‘another embodiment’ is to be read as ‘at least one other embodiment. ’ The terms ‘first, ’ ‘second, ’ and the like may refer to different or same objects. Other definitions, explicit and implicit, may be included below.
[0049] In some examples, values, procedures, or apparatus are referred to as ‘best, ’ ‘lowest, ’ ‘highest, ’ ‘minimum, ’ ‘maximum, ’ or the like. It will be appreciated that such descriptions are intended to indicate that a selection among many used functional alternatives can be made, and such selections need not be better, smaller, higher, or otherwise preferable to other selections.
[0050] As used herein, the term “resource, ” “transmission resource, ” “uplink resource, ” or “downlink resource” may refer to any resource for performing a communication, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0051] The term “ambient IoT device” used herein is a 3GPP IoT device which is much smaller and cheaper compared to previous generations of IoT. The ultimate ambient IoT energy source is that from radio waves. Both Ambient IoT and Ambient computing rely upon energy harvesting as one of the key mechanisms for powering and enabling the technology. Energy harvesting, as it applies to Ambient IoT and Ambient Computing, is the harnessing of the power in ambient radio waves to power tiny computers. Ambient IoT device may have a new radio / air interface to a reader / node. The new radio interface may be frame based or non-frame based. Deploying ambient IoT service on existing system could reduce the operation cost and quickly commercialize the new service.
[0052] Principles and implementations of the present disclosure will be described in detail below with reference to the figures.
[0053] FIG. 1A illustrates a schematic diagram of an example communication environment 100A in which example embodiments of the present disclosure can be implemented. In the communication environment 100A, a plurality of communication devices, including an ambient IoT (AIoT) device 150, a network device 170 can communicate with each other.
[0054] In the example of FIG. 1A, the ambient IoT device 150 communicates bidirectionally with the network device 120. In the communication environment 100A, the network device 170 may be a base station. For example, the network device 170 may be outdoor, and the ambient IoT device 150 may be indoor.
[0055] The network device 170 may be a NG-RAN device. As used herein, the term "RAN" refers to the Radio Access Network, a critical component of wireless communication systems such as LTE and 5G. The RAN connects devices, such as smartphones and IoT devices, to the core network, facilitating the transmission of data and control signals. “NG-RAN” , also known as the next generation RAN, is an important part of the 5G network architecture. In some embodiments of the present disclosure, the netwrok device 170 is sometimes referred to as a NG-RAN device.
[0056] FIG. 1B illustrates a schematic diagram of an example communication environment 100B in which example embodiments of the present disclosure can be implemented. In the communication environment 100B, a plurality of communication devices, including an ambient IoT (AIoT) device 150, a network device 170, and an intermediate node 160, can communicate with each other.
[0057] In the example of FIG. 1B, the ambient IoT device 150 communicates bidirectionally with an intermediate node 160 between the ambient IoT device 150 and the network device 170. In the communication environment 100A, the network device 170 may be a base station serving an intermediate node 160. The intermediate node 160 may be a UE, a relay, an IAB node, a repeater, and the like which is capable of Ambient IoT. The intermediate node 160 may transfer Ambient IoT data and / or signaling between the ambient IoT device 150 and the network device 170, and a UE may act as an intermediate node 160 which is under the control of the network device 170. For example, the network device 170 may be outdoor, and the ambient IoT device 150 may be indoor.
[0058] It is to be understood that the number of devices and their connections shown in FIGS. 1A and 1B are only for the purpose of illustration without suggesting any limitation. The communication environment 100A and 100B may include any suitable number of devices configured to implementing example embodiments of the present disclosure. Although not shown, it would be appreciated that one or more additional devices may be located in the cell, and one or more additional cells may be deployed in the communication environment 100A or 100B. It is noted that although illustrated as a network device, the network device 170 may be another device than a network device. Although illustrated as a terminal device, the intermediate node 160 may be other device than a terminal device.
[0059] In the following, for the purpose of illustration, some example embodiments are described with the intermediate node 160 operating as a UE which may be authorized to be an intermediate node, and the network device 170 operating as a base station. However, in some example embodiments, operations described in connection with a terminal device may be implemented at a network device or other device, and operations described in connection with a network device may be implemented at a terminal device or other device.
[0060] In some example embodiments, the AIoT device 150 may be a terminal device (e.g., UE) and the network device 170 may be a base station (e.g., gNB) . In this case, a link from the network device 170 to the AIoT device 150 may be referred to as a downlink (DL) , while a link from the AIoT device 150 to the network device 170 may be referred to as an uplink (UL) . In DL, the network device 170 is a transmitting (TX) device (or a transmitter) and the AIoT device 150 is a receiving (RX) device (or a receiver) . In UL, the AIoT device 150 is a TX device (or a transmitter) and the network device 170 is a RX device (or a receiver) .
[0061] The communications in the communication environment 100 may conform to any suitable standards including, but not limited to, Global System for Mobile Communications (GSM) , Long Term Evolution (LTE) , LTE-Evolution, LTE-Advanced (LTE-A) , New Radio (NR) , Wideband Code Division Multiple Access (WCDMA) , Code Division Multiple Access (CDMA) , GSM EDGE Radio Access Network (GERAN) , Machine Type Communication (MTC) and the like. The embodiments of the present disclosure may be performed according to any generation communication protocols either currently known or to be developed in the future. Examples of the communication protocols include, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the fifth generation (5G) communication protocols, 5.5G, 5G-Advanced networks, or the sixth generation (6G) networks.
[0062] The AIoT may refer to a new class of IoT devices primarily powered by harvesting ambient energy from radio waves, light, motion, heat, or any other viable ambient energy source. In addition, the AIoT is an extension of the existing IoT. AIoT devices carry out many of the same functions as IoT devices and target many of the same use cases but require additional design choices to meet solution demands. By relying on energy harvested from ambient sources, the AIoT makes it possible to develop lower-cost, smaller, and maintenance-free devices, allowing the IoT to become more scalable in existing use cases and in use cases still to be developed. Harvesting energy from ambient sources generates only minimal amounts of power. This creates the inherent requirement for AIoT devices to be less complex and more power efficient.
[0063] In the embodiments shown in FIGS. 1A and 1B, the AIoT device 150 may include an energy harvesting module and a backscattering module. The intermediate node 160 (e.g., UE or a reader) transmits an energy supply or command to the AIoT device 150. In response to receiving the energy supply and command, the AIoT device 150 backscatters to the intermediate node 160.
[0064] In an example, the peak power consumption of the AIoT device 150 may be less than 1 μW, and such AIoT device 150 may have energy storage. Moreover, the initial sampling frequency offset (SFO) may be less than to 10X ppm. Further, there is neither DL nor UL amplification in the device. The device’s UL transmission is backscattered on a carrier wave provided externally.
[0065] In another example, the peak power consumption of the AIoT device 150 may be less than a few hundred μW, and such AIoT device 150 may have energy storage. There may be DL and UL amplification in the device. In addition, the device’s UL transmission may be generated internally by the device, or be backscattered on a carrier wave provided externally. Furthermore, the device’s UL transmission may be generated internally by the device.
[0066] In some predefined standard, the issues on the system architecture and procedure to support 5G AIoT services are described. For example, a UE acting as the intermediate node may be responsible for transferring the information between an AIoT device and 5GS. The AIoT may be validated by the UE. The authentication and authorization of the AIoT device may be the validation of the AIoT device identifier. In the example involving authorization and management of AIoT devices to support AIoT services, considering that AIoT device is a new type of reduced capabilities devices, the existing subscription model may not be suitable. Specifically, there is the need to study the device identification method to support Ambient IoT devices which are under operator control.
[0067] Furthermore, it is necessary to study whether subscription management, registration management and / or connection management are necessary for an AIoT device or a group of Ambient IoT devices, and if so, it is needed to identify the necessary state machine (s) , procedures and functionality considering the AIoT devices capability and characteristics. In addition, it is also necessary to study whether and how reachability and paging apply to AIoT device (s) considering the AIoT devices capability and characteristics, and if so, what the impacts are. Moreover, it is needed to study how to identify AIoT device or group of devices and how to format the identifier.
[0068] To solve the above and other related / potential issues, embodiments of the present disclosure propose an example architecture of AIoT system and related solution (s) . In a solution, one or more indications related to different levels of security and / or privacy operations are proposed, which include, for example, indications for indicating no security and / or privacy operation is allowed, a reader identification based security and / or privacy operation is allowed, a password / token based security and / or privacy operation is allowed, a password / token based security and / or privacy operation for network access is allowed, a password / token based mutual security and / or privacy operation is allowed, and / or the like.
[0069] FIGS. 1C and 1D illustrate example architectures 100C and 100D of a communication system in accordance with some embodiments of the present disclosure, respectively. These example architectures each include a plurality of devices which can communicate with each other. As shown in the example architecture 100C of FIG. 1C, the plurality of devices include the AIoT device 150, an AIoT controller 110, a device implementing an Application Function (AF) 120, which is also referred to as AF 120 for purpose of discussion, a device implementing an AIoT device management function 130, which is also referred to as AIoT device management function 130 or AIoT device management 130 for purpose of discussion, and an AIoT reader 140.
[0070] The AIoT controller 110 may be a core network entity that enables AIoT scenarios. It may be a network function implemented in the core netwrok. In some embodiments, the AIoT controller 110 may be implemented at an existing core network entity or as a part of an existing netwrok function. Alternatively, it may be implemented as a new network function. It is to be understood that the above are discussed for purpose of illustration, rather than suggesting any limitations.
[0071] The AIoT controller 110 may work alongside core network functions, such as Application Function (AF) 120, AIoT device management function 130, AIoT reader 140 and / or the like.
[0072] The Application Function (AF) 120 may be a network service provider. For example, the AF 120 may be a functional device immediate response to changing conditions or requirements, such as adjusting irrigation schedules based on real time data.
[0073] The AIoT device management function 130 may be a combination of devices and functionalities implemented within the AIoT system for overseeing and controlling AIoT devices. For example, the AIoT device management function 130 may be a security enhancement module or a efficiency improvement module of a AIoT system.
[0074] The AIoT reader 140 may be a device that reads and interprets data gathered from the AIoT device 150. The AIoT reader 140 may extract meaningful information from the vast amount of data produced by the ambient environment, making it useful for various applications.
[0075] As shown in the example architecture 100D of FIG. 1D, the plurality of devices include an AIoT controller 110, an AF 120, an AIoT device management function 130, an AIoT device 150, an intermediate node 160, an access and mobility management function (AMF) device or node (also referred to as AMF for discussion) 165, a network device (also referred to as next generation radio access network (NG-RAN) or NG-RAN device for discussion) 170, a unified data management (UDM) device or node (also referred to as UDM for discussion) 180, a session management function (SMF) device or node (also referred to as SMF for discussion) 190, and a user plane function (UPF) device or node (also referred to as UPF for discussion) 195.
[0076] The AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, the AIoT device 150, intermediate node 160 and the NG-RAN device 170 are similar as those discussed with respect to FIGS. 1A-1C. For example, in the example of FIG. 1D, the NG-RAN 170 may be a network device such as base station serving the intermediate node 160. The intermediate node 160 may act as an A-IoT reader 140 and / or a UE. For instance, the intermediate node 160 may transfer AIoT data and / or signaling between the AIoT device 150 and the NG-RAN 170.
[0077] The AMF 165 refers to the Access and Mobility Management Function in 5G network architecture. The AMF is responsible for managing registration, connection, reachability, mobility, and access authorization for User Equipment (UE) .
[0078] The UDM 180 refers to the Unified Data Management function in 5G network architecture. The UDM 180 is responsible for handling user subscription data and profiles, enabling network services such as authentication, authorization, and user mobility management.
[0079] The SMF 190 may be a functional module in communication system that manages the lifecycle of user sessions, including establishing, modifying, and terminating sessions, ensuring that user devices can maintain continuous and seamless connectivity. Moreover, the UPF 195 may be a device being responsible for routing and forwarding user data packets between the user equipment (UE) and external data networks. The UPF 195 may handle the data plane traffic, ensuring efficient and low-latency data transmission.
[0080] More details of the architecture shown in FIGS. 1C and 1D will be discussed with respect to FIGS. 2-12 as follows.
[0081] Reference is made to FIG. 2, which illustrates a signaling flow 200 of a procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. As shown in FIG. 2, the signaling flow 200 involves a first device 210, a second device 220, a third device 230, a fourth device 240 and a fifth device 250.
[0082] In some embodiments, the first device 210 may be implemented as the AIoT controller 110 in the example architecture of AIoT system of FIGS. 1C and 1D, which may be a core network device for example. The second device 220 may be implemented as the AF 120 in the example architecture of AIoT system of FIGS. 1C and 1D. The third device 230 may be implemented as the AIoT device management 130, which may be a management function in the core network. The fourth device 240 may be implemented as the AIoT reader 140. Ther fifth device 250 may be implemented as the AIoT device 150.
[0083] In the signaling flow 200, the second device 220 transmits (2010) , to the first device 210, a first request for a device identification of a fifth device 250 associated with a target reader. Correspondingly, the first device 210 receives (2020) , from the second device 220, the indication to obtain the device identification of the fifth device 250.
[0084] The first request may include one or indications, including but not limited to, a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, and / or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0085] In some embodiment, if the first device 210 receives the first request from the second device 220, it may determine whether or how to obtain the device identification of AIoT device. In other words, the first device 210 may determine the authentication and / or authorization for the AIoT device.
[0086] Then, the first device 210 transmits (2030) , to the third device 230, a request for verifying whether an operation related to security and / or privacy is allowed. The request may be associated with the first request received from the second device 220. The third device 230 receives (2040) the request from the first device 210. In response, the third device 230 transmits (2050) , to the first device 210, a response to the request. The first device 210 receives (2060) the response to the request.
[0087] Subsequently, the first device 210, transmits (2070) , to the fourth device 240, a request for a device identification of the fifth device 250. That is, in response to receiving the response from the third device 230, the first device 210 may indicate the fourth device 240 to obtain the device identification of the fifth device 250. In other words, the fourth device 240 receives (2080) the request from the first device 210.
[0088] Furthermore, the fourth device 240 transmits (2090) , to the fifth device 250, a further request for the device identification of the fifth device 250. The request may be associated with the first request. In response to the request received (2100) from the fourth device 240, the fifth device 250 transmits (2110) , to the fourth device 240, a response including the device identification of the fifth device. Accordingly, the fourth device 240, receives (2120) the response including the device identification from the fifth device 250.
[0089] In some embodiments, after the second device 220 transmits (2010) , to the first device 210, the first request for a device identification of the fifth device 250 associated with a target reader, the first device 210 may transmit a further request to other devices, e.g., it may transmit a request to the third device 230 for authorization or verification, or transmit another request to the fourth device 240 for the device identification of a fifth device 250. After receiving the device identification of the fifth device 250, the first device may transmit a first response to the first request to the second device 220. The first response may include at least one of the device identification of the fifth device 250, or a reader identification of the target reader. Upon receiving the first response, the second device 220 may have the knowledge of the device identification of the fifth device 250, a reader identification of the target reader, and / or the like.
[0090] Specifically, the first device 210 may transmit to the third device 230, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to the first request. Moreover, the third device 230 may transmit, to the first device 210, a response to the request.
[0091] As for the fourth device 240, it may receive, from a first device 210, a request for a device identification of a fifth device, the request being transmitted based on a first request. Moreover, the fourth device 240 may transmit, to the fifth device 250, a further request for the device identification of the fifth device 250.
[0092] The fifth device 250 may receive, from a fourth device 240, a request for an device identification of the fifth device 250, the request being transmitted based on a first request. Moreover, the fifth device 250 may transmit, to the fourth device 240, a response including the device identification of the fifth device 250.
[0093] As a first option, in some embodiments, in response to receiving the first request including the first indication, the first device 210 may transmit, to a third device 230, a second request for verifying whether the no security and / or privacy operation is allowed for the target reader.
[0094] The third device 230 may receive, from the first device 210, a second request for verifying whether the no security and / or privacy operation is allowed for a target reader. The third device 230 may also transmit, to the first device 210, a second response to the second request. The second response may include at least one of: a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device or an indication indicating that the no security and / or privacy operation is allowed for the target reader. Upon receiving the second response from the third device 230, the first device 210 may be aware of the above information / indication included in the second response.
[0095] If the second response includes a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device 230, the first device 210 may determine whether the target reader belongs to the list of readers. In addition, the first device 210 may transmit, to the fourth device 240, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device 250, in response to determining that the target reader belongs to the list of readers.
[0096] Alternatively, if the second response directly indicates that the no security and / or privacy operation is allowed for the target reader, that is, the third device 230 has verified the no security and / or privacy operation, the first device 210 may transmit, to the fourth device 240, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device 250. In some embodiments, the second response may include a reader identification of the target reader. Alternatively, the second response may include a third request including at least one of: the identification of a fifth device, or the first indication.
[0097] The fourth device 240 may receive, from the first device 210, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device; and may transmit, to the fifth device 250, the further request including the device identification of the fifth device.
[0098] The fifth device 250, upon receiving, from the fourth device 240, the request including the device identification of the fifth device 250, may transmit, to the fourth device, a response including the device identification of the fifth device 250. Thus, the fourth device 240 may receive, from the fifth device 250, a response including the device identification of the fifth device; and may transmit, to the first device 210, a further response including the device identification of the fifth device 250.
[0099] As a second option, the first request may include the second indication. In this case, the first device 210 may transmit, to the third device 230, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for the target reader. The fourth request may include a reader identification of the reader obtained from the first request.
[0100] In these case, the third device 230 may receive, from the first device 210, the fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for a target reader. Moreover, the third device may transmit, to the first device 210, a third response to the fourth request.
[0101] In some embodiments, the third response may include at least one of: a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device 230 or an indication indicating that the reader identification based security and / or privacy operation is allowed for the target reader.
[0102] After the verification is passed, the first device 210 may transmit to the fourth device 240, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device 250. Then, the fourth device 240 may transmit, to the fifth device 250, the further request including at least one of the device identification of the fifth device 250, or the reader identification of the target reader.
[0103] The fifth device 250 may receive, from the fourth device 240, the request including at least one of the device identification of the fifth device 250, or the reader identification of the target reader. Moreover, the fifth device 250 may determine whether the reader identification of the target reader is allowed. In response to determining that the reader identification of the target reader is allowed, the fifth device 250 may transmit, to the fourth device 240, a response including the device identification of the fifth device 250.
[0104] In the case where the third response includes a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device 230. Moreover, the first device 210 may determine whether the target reader belongs to the list of readers. If yes, the first device 210 may transmit, to the fourth device 240, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device 250.
[0105] In these case where the third response indicate that the reader identification based security and / or privacy operation is allowed for the target reader, that is, the third device 230 has verified the reader identification based security and / or privacy operation, the first device 210 may transmit, to a fourth device 240, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device 250.
[0106] In some implementations, the third response may include at least one of: a reader identification of the target reader, the device identification of the fifth device 250, or the second indication. Alternatively, the fifth request may include at least one of: the device identification of a fifth device 250, or the second indication.
[0107] As a third option, the first request may include the third indication. Moreover, the first device 210 may transmit, to a third device 230, a sixth request for verifying whether the password / token based security and / or privacy operation is allowed for the target reader.
[0108] In these case, the third device 230 may receive, from the first device 210, the sixth request for verifying whether the password / token based security and / or privacy operation is allowed for a target reader. The third device 230 may verify by itself or just provide some information for the verification. Then, the third device 230 may transmit, to the first device 210, a fourth response to the second request.
[0109] In some embodiments, the first request may further include a first password / token, and the fourth response may include at least one of: a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device or an indication indicating that the password / token based security and / or privacy operation is allowed for the target reader.
[0110] In some alternative embodiments, the first request may exclude a first password / token, and the fourth response may include a second password / token, the fourth response includes at least one of: a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, or an indication indicating that the password / token based security and / or privacy operation is allowed for the target reader.
[0111] In some embodiments, the first device 210 may transmit to the fourth device 240 a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device 250. The seventh request may include at least one of: the identification of the fifth device 250, the third indication, the first password / token, or the second password / token. Further, the fourth device 240 may transmit, to the fifth device 250, the further request including at least one of the device identification of the fifth device 250, the first password / token, or the second password / token.
[0112] Moreover, the fourth device 240 may receive, from the fifth device 250, a response including the device identification of the fifth device; and may transmit, to the first device 210, a further response including at least one of the device identification of the fifth device 250, or the reader identification of the target reader.
[0113] Further, the fifth device 250 may receive, from the fourth device, the request including at least one of the device identification of the fifth device, a password / token. The fifth device 250 may determine whether the password / token is allowed, and transmit, to the fourth device, a response including the device identification of the fifth device, in response to determining that the password / token is allowed.
[0114] In an example implementation, the first request may further include a first password / token, and the fourth response may include a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device 230. The first device 210 may determine whether the target reader belongs to the list of readers. Moreover, in response to determining that the target reader belongs to the list of readers, the first device 210 may transmit, to a fourth device 240, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device 250. The seventh request may include at least one of: the device identification of the fifth device 250, the third indication, the first password / token, or the second password / token.
[0115] In these case, the fourth device 240 may receive, from the first device 210, a seventh request indicating that the password / token based security and / or privacy operation for network access is to be performed with respect to the fifth device 250, and may transmit, to the fifth device, the further request including at least one of the device identification of the fifth device 250, a request for a third password / token from the fifth device 250.
[0116] In another example implementation, the first request may include a first password / token, the fourth response indicates that the password / token based security and / or privacy operation is allowed for the target reader. The first device 210 may transmit, to a fourth device 240, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device 250. The seventh request may include at least one of: the device identification of the fifth device, the third indication, or the first password / token.
[0117] In these case, the sixth request may include at least one of the identification of the fifth device 250, or a reader identification of the target reader. Alternatively, the fourth response may include at least one of: the identification of the fifth device 250, the third indication, the reader identification of the targe reader, or the first password / token.
[0118] As a fourth option, in some embodiments, the first request may exclude a first password / token, and the fourth response may include a second password / token and a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device 230. Further, the first device 210 may determine whether the target reader belongs to the list of readers. Additionally, in response to determining that the target reader belongs to the list of readers, the first device 210 may transmit, to a fourth device 240, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device 250. The seventh request may include at least one of: the device identification of the fifth device 250, the third indication, or the second password / token.
[0119] In some alternative embodiments, the first request may exclude a first password / token, and the fourth response may include a second password / token and indicates that the password / token based security and / or privacy operation is allowed for the target reader. Moreover, the first device 210 may transmit, to a fourth device 240, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device 250. The seventh request may include at least one of: the device identification of the fifth device 250, the third indication, or the second password / token.
[0120] Alternatively, the sixth request may include at least one of the device identification of the fifth device 250, or the reader identification of the target reader. The fourth response may include the second password / token and at least one of: the device identification of the fifth device 250, the third indication, or the reader identification of the target reader.
[0121] Furthermore, the first device 210 may receive, from the fourth device 240, a response including at least one of the device identification of the fifth device 250, a reader identification of the target reader, or a third password / token from the fifth device.
[0122] As a fifth option, the first request may include the fourth indication, and the response received from the fourth device may include the third password / token. In this case, the first device 210 may determine whether the third password / token can be used for accessing network. Moreover, in response to determine that the third password / token can be used for accessing the network, the first device 210 may transmit, to the second device 220, a first response including at least one of the device identification of the fifth device 250 or the reader identification.
[0123] Further, the fourth device 240 may receive, from the fifth device 250, a response including at least one of the device identification of the fifth device or the third password / token, and may transmit, to the first device210, a further response including at least one of the device identification of the fifth device 250, the reader identification of the target reader, or the third password / token.
[0124] In some embodiments, the fifth device 250 may receive, from the fourth device 240, the request including at least one of the device identification of the fifth device, a request for a password / token from the fifth device. Further, the fifth device 250 may transmit, to the fourth device 240, a response including at least one of the device identification of the fifth device or the password / token.
[0125] As a sixth option, the first request may include the fifth indication. In this case, mutual authentication / authorization may be performed between the fifth device 250 (e.g., the AIoT device) and the network, e.g., the second device 220, including the combinations between device authorizing network and network authorizing device. The password / token in the AIoT device and the network from AF may be different. More details in this regard will be discussed with respect to FIGS. 13-14.
[0126] In view of the above, the device identification of the AIoT device can be obtained in a selected mode according to the security and / or privacy requirements of the network and the capability of the AIoT device.
[0127] Now more detailed embodiments will be further discussed below. FIG. 3 illustrates a signaling flow 300 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 300 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 3, the signaling flow 300 involves the AIoT controller 110, the AF 120, the AIoT device management function 130 (also referred to as the AIoT device management 130) , the AIoT reader 140, and the AIoT device 150.
[0128] In the embodiment of FIG. 3, the AIoT controller 110 is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, and the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0129] In this case, the device does not have any security or privacy mechanism internally. From the core network and 3rd party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to a reader when the reader requests for inventory. The AIoT controller 110 authorizes the no security and privacy operation.
[0130] In the signaling flow 300, at 3010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the first indication. That is, the inventory request indicates no security and / or privacy operation is allowed. In other words, the example procedure in this embodiments includes no security and / or privacy operation internally. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. The inventory request transmitted by the AF 120 may include reader ID, device ID and no security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included.
[0131] At 3020, the AIoT controller 110 may transmit a device information request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The device information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0132] At 3030, in response to receiving the device information request, the AIoT device management function 130 may determine whether the reader is allowed to perform no security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, device information response, which may include the device ID, no security and / or privacy operation allowed indication, and no security and / or privacy operation allowed reader ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0133] At 3040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the no security and privacy operation for the AIoT device 150 with reader 140. The reader ID (s) shall be the common parts both from the reader ID in 3010 and 3030, and the differences between them shall be excluded. The AIoT controller may transmit the inventory request to the reader (s) , which includes device ID, no security and privacy operation allowed indication.
[0134] At 3050, the reader 140 may transmit inventory request to the AIoT device 150, which includes the device ID.
[0135] At 3060, If the received device ID is matched with the device ID stored in the AIoT device 150, the AIoT device 150 may transmit inventory response to the reader (s) with its device ID.
[0136] Then, at 3070, the reader 140 may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0137] Finally, at 3080, the AIoT controller 110 may store the device ID and the Reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0138] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with no security and / or privacy operation in an efficient and simplified way.
[0139] FIG. 4 illustrates a signaling flow 400 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 400 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 4, the signaling flow 400 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150. Different from the embodiments shown with respect to FIG. 3, in embodiments of FIG. 4, the AIoT device management function 130 authorizes the no security and privacy operation.
[0140] In the signaling flow 400, at 4010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the first indication. That is, the inventory request indicates no security and / or privacy operation is allowed. In other words, the example procedure in this embodiments includes no security and / or privacy operation internally. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. The inventory request transmitted by the AF 120 may include reader ID, device ID and no security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included.
[0141] At 4020, the AIoT controller 110 may transmit the AIoT no security and / or privacy operation authorization request to the AIoT device management 130. The AIoT device management function 130 may receive the request and may transmit, to the AIoT controller, a response to the request. The device information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0142] At 4030, in response to receiving the AIoT no security and / or privacy operation authorization request, the AIoT device management function 130 may indicate whether the no security and / or privacy operation is allowed for the reader. There may be information stored in AIoT device management function 130 related to the reader id of the readers to be authorized for performing the no security and / or privacy operation. The reader ID (s) shall be the common parts both received in 4010 and allowed in 4030. The differences between them shall be excluded. Further, the AIoT device management function 130 transmits, to the AIoT controller 110, the AIoT no security and / or privacy operation authorization response, which may include the device ID, no security and / or privacy operation allowed indication, and no security and / or privacy operation allowed reader ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0143] At 4040, the AIoT controller 110 may transmit inventory request to the reader 140 with the device ID and no security and privacy operation allowed indication. That is, the AIoT controller authorizes the no security and privacy operation for the AIoT device 150 with reader 140. The AIoT controller may transmit the inventory request to the reader (s) , which includes device ID, no security and privacy operation allowed indication.
[0144] At 4050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID.
[0145] At 4060, If the received device ID is matched with the device ID stored in the AIoT device 150, the AIoT device may transmit inventory response to the reader (s) with its device ID.
[0146] Then, at 4070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0147] Finally, at 4080, the AIoT controller 110 may store the Device ID and the Reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0148] In this way, the device ID can be obtained by the authorized reader with no security and / or privacy operation in an efficient and simplified way.
[0149] FIG. 5 illustrates a signaling flow 500 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 500 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 5, the signaling flow 500 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0150] In the embodiment of FIG. 5, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0151] In this case, there is a limited privacy mechanism. There is additional information with Reader ID stored in the AIoT device for authorizing the Reader, which can be Reader ID, Reader ID list, Reader ID with bitmask, Reader group ID.
[0152] In the signaling flow 500, at 5010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the second indication. That is, the inventory request indicates reader ID based security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device 150 only needs to store its device identification (ID) , and response its device ID to an AIoT reader 140 when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID, device ID, and reader ID based security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID and / or reader Group ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140.
[0153] At 5020, the AIoT controller 110 may transmit a device information request (which is also referred to as “AIoT information request” ) to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The device information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0154] At 5030, in response to receiving the device information request (which is also referred to as “AIoT device information response” ) , the AIoT device management function 130 may determine whether the reader is allowed to perform reader ID based security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, device information response, which may include the device ID, reader ID based security and / or privacy operation allowed indication, and reader ID based security and / or privacy operation allowed reader ID (s) and / or reader group ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0155] At 5040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. The reader ID (s) and / or reader group ID (s) shall be the common parts both from the reader ID and / or reader group ID (s) in 5010 and 5030, and the differences between them shall be excluded. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller 110 authorizes the reader ID based security and / or privacy operation for the AIoT device 150 with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, reader ID based security and / or privacy operation indication.
[0156] At 5050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the reader ID or reader group ID of the reader (s) .
[0157] At 5060, in response to receiving the inventory request from the reader 140, the AIoT device may determine whether the reader ID or the reader group ID of the reader is allowed. Further, in response to determining that the reader ID or the reader group ID of the reader is allowed, the AIoT device 150 may transmit, to the reader 140, a response including the device ID of the AIoT device 150.
[0158] Then, at 5070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0159] Finally, at 5080, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0160] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying certain reader ID in an efficient and simplified way. Moreover, the security and / or privacy of the access is improved.
[0161] FIG. 6 illustrates a signaling flow 600 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 600 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 6, the signaling flow 600 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150. In contrast to FIG. 5, in embodiments of FIG. 6, the authorization is performed by the AIoT device management function 130.
[0162] In the embodiment of FIG. 6, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0163] In the signaling flow 600, at 6010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the second indication. That is, the inventory request indicates reader ID based security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID, device ID, and reader ID based security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID and / or reader Group ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140.
[0164] At 6020, the AIoT controller 110 may transmit an AIoT reader id based security and / or privacy operation authorization request to the AIoT device management 130. The AIoT device management may receive the request. The device information request may include device ID and reader ID and / or reader group ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0165] At 6030, in response to receiving the AIoT reader id based security and / or privacy operation authorization request, the AIoT device management function 130 may determine whether the reader is allowed to perform reader id based security and / or privacy operation. The reader ID (s) and / or reader group ID (s) shall be the common parts both from the reader ID and / or reader group ID (s) in 6010 and 6030, and the differences between them shall be excluded. There may be information stored in AIoT device management function 130 related to the reader id and / or reader group id of the readers to be authorized for performing the reader ID based security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, device information response, which may include the device ID, reader ID based security and / or privacy operation allowed indication, and reader ID based security and / or privacy operation allowed reader ID (s) and / or reader group ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0166] At 6040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the reader ID based security and / or privacy operation for the AIoT device 150 with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, reader ID based security and / or privacy operation indication.
[0167] At 6050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the reader ID or reader group ID of the reader (s) .
[0168] At 6060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may determine whether the reader ID or the reader group ID of the reader is allowed. Further, in response to determining that the reader ID or the reader group ID of the reader is allowed, the AIoT device 150 may transmit, to the reader 140, a response including the device ID of the AIoT device 150.
[0169] Then, at 6070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0170] Finally, at 6080, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0171] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying certain reader ID in an efficient and simplified way. Moreover, the security and / or privacy of the access is improved.
[0172] FIG. 7 illustrates a signaling flow 700 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 700 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 7, the signaling flow 700 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150. Different from the above embodiments as shown with FIG. 3 to FIG. 6, embodiments of FIG. 7 use the password / token to access the AIoT device.
[0173] In the embodiment of FIG. 7, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0174] In the signaling flow 700, at 7010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the third indication. That is, the inventory request indicates password / token based security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID, device ID, password / token based security and / or privacy operation indication and the password / token for accessing the AIoT device 150. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID and / or reader Group ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140.
[0175] At 7020, the AIoT controller 110 may transmit a AIoT information request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The AIoT information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0176] At 7030, in response to receiving the AIoT information request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, AIoT information response, which may include the device ID, password / token based security and / or privacy operation allowed indication, and password / token based security and / or privacy operation allowed reader ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0177] At 7040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. The reader ID (s) shall be the common parts both from the reader ID in 7010 and 7030, and the differences between them shall be excluded. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation indication.
[0178] At 7050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the password / token for accessing the AIoT device 150.
[0179] At 7060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may determine whether password / token is allowed. Further, in response to determining that the password / token is allowed, the AIoT device 150 may transmit, to the reader 140, a response including the device ID of the AIoT device 150.
[0180] Then, at 7070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0181] Finally, at 7080, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0182] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying password / token in an efficient and simplified way. The password / token can be determined and input, which further enhances the security and / or privacy.
[0183] FIG. 8 illustrates a signaling flow 800 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 800 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 8, the signaling flow 800 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0184] In the embodiment of FIG. 8, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0185] In the signaling flow 800, at 8010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the third indication. That is, the inventory request indicates password / token based security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID, device ID, password / token based security and / or privacy operation indication and the password / token for accessing the AIoT device 150. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID and / or reader Group ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140.
[0186] At 8020, the AIoT controller 110 may transmit an AIoT password / token based security and / or privacy operation authorization request to the AIoT device management 130. The AIoT device management may receive the request and may transmit. The AIoT password / token based security and / or privacy operation authorization request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0187] At 8030, in response to receiving the AIoT password / token based security and / or privacy operation authorization request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based security and / or privacy operation. The reader ID (s) shall be the common parts both from the reader ID in 8010 and 8030, and the differences between them shall be excluded. There may be information stored in AIoT device management function 130 related to the reader id and / or reader group id of the readers to be authorized for performing the reader ID based security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, AIoT password / token based security and / or privacy operation authorization response, which may include the device ID, password / token based security and / or privacy operation allowed indication, and password / token based security and / or privacy operation allowed reader ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0188] At 8040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation indication.
[0189] At 8050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the password / token for accessing the AIoT device 150.
[0190] At 8060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may determine whether password / token is allowed. Further, in response to determining that the password / token is allowed, the AIoT device 150 may transmit, to the reader 140, a response including the device ID of the AIoT device 150.
[0191] Then, at 8070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0192] Finally, at 8080, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0193] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying password / token in an efficient and simplified way. The password / token can be determined and input, which further enhances the security and / or privacy.
[0194] FIG. 9 illustrates a signaling flow 900 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 900 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 9, the signaling flow 900 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0195] In the embodiment of FIG. 9, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0196] In the signaling flow 900, at 9010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the third indication. That is, the inventory request indicates password / token based security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID , device ID, and password / token based security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID and / or reader Group ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140.
[0197] At 9020, the AIoT controller 110 may transmit a AIoT information request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The AIoT information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0198] At 9030, in response to receiving the AIoT information request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, AIoT information response, which may include the device ID, password / token based security and / or privacy operation allowed indication, password / token based security and / or privacy operation allowed reader ID (s) , and the password / token for accessing the AIoT device. For example, password / token may be predetermined and stored in the AIoT device management 130. If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0199] At 9040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. The reader ID (s) shall be the common parts both from the reader ID in 9010 and 9030, and the differences between them shall be excluded. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation indication.
[0200] At 9050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the password / token for accessing the AIoT device 150.
[0201] At 9060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may determine whether password / token is allowed. Further, in response to determining that the password / token is allowed, the AIoT device 150 may transmit, to the reader 140, a response including the device ID of the AIoT device 150.
[0202] Then, at 9070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0203] Finally, at 9080, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0204] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying password / token in an efficient and simplified way. The password / token can be predetermined and stored, which enhances the efficiency. Moreover, the security and / or privacy of the access is further improved.
[0205] FIG. 10 illustrates a signaling flow 1000 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 1000 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 10, the signaling flow 1000 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0206] In the embodiment of FIG. 10, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0207] In the signaling flow 1000, at 10010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the third indication. That is, the inventory request indicates password / token based security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID, device ID, and password / token based security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID and / or reader Group ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140.
[0208] At 10020, the AIoT controller 110 may transmit an AIoT password / token based security and / or privacy operation authorization request to the AIoT device management 130. The AIoT device management may receive the request and may transmit. The AIoT password / token based security and / or privacy operation authorization request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0209] At 10030, in response to receiving the AIoT password / token based security and / or privacy operation authorization request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based security and / or privacy operation. The reader ID (s) shall be the common parts both from the reader ID in 10010 and 10030, and the differences between them shall be excluded. There may be information stored in AIoT device management function 130 related to the reader id and / or reader group id of the readers to be authorized for performing the reader ID based security and / or privacy operation. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, AIoT password / token based security and / or privacy operation authorization response, which may include the device ID, password / token based security and / or privacy operation allowed indication, password / token based security and / or privacy operation allowed reader ID (s) and the password / token for accessing the AIoT device. For example, password / token may be predetermined and stored in the AIoT device management 130. . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0210] At 10040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation indication.
[0211] At 10050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the password / token for accessing the AIoT device 150.
[0212] At 10060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may determine whether password / token is allowed. Further, in response to determining that the password / token is allowed, the AIoT device 150 may transmit, to the reader 140, a response including the device ID of the AIoT device 150.
[0213] Then, at 10070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID and reader ID.
[0214] Finally, at 10080, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0215] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying password / token in an efficient and simplified way. The password / token can be predetermined and stored, which enhances the efficiency. Moreover, the security and / or privacy of the access is further improved.
[0216] FIG. 11 illustrates a signaling flow 1100 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 1100 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 11, the signaling flow 1100 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0217] In the embodiment of FIG. 11, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0218] In the signaling flow 1100, at 11010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the fourth indication. That is, the inventory request indicates password / token based security and / or privacy operation for network access is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID , device ID, and password / token based security and / or privacy operation for network access indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140. The password / token based security and / or privacy operation for network access indication indicates the network shall authenticate and authorize the AIoT device by password / token from the AIoT device.
[0219] At 11020, the AIoT controller 110 may transmit a AIoT information request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The AIoT information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0220] At 11030, in response to receiving the AIoT information request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based security and / or privacy operation for network access. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, AIoT information response, which may include the device ID, password / token based security and / or privacy operation for network access indication, password / token based security and / or privacy operation for network access allowed reader ID (s) , and the password / token for accessing AIoT device accessing the network. For example, password / token may be predetermined and stored in the AIoT device management 130. If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0221] At 11040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. The reader ID (s) shall be the common parts both from the reader ID in 11010 and 11030, and the differences between them shall be excluded. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 accessing the network with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation for network access indication.
[0222] At 11050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the request password / token for the AIoT device accessing the network.
[0223] At 11060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may transmit, to the reader, a response including the device ID and the password / token.
[0224] Then, at 11070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID, reader ID and the password / token.
[0225] Finally, at 11080, the AIoT controller 110 may determine whether the password / token is allowed by comparing the password / token received from the AIoT device management function 130 at 11030 and the password / token received from the reader. In response to determining the two password / token are matched, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0226] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying password / token in an efficient and simplified way. The AIoT controller can verify the AIoT device, which enhances the security and / or privacy of the access is further improved.
[0227] FIG. 12 illustrates a signaling flow 1200 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 1200 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 12, the signaling flow 1200 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0228] In the embodiment of FIG. 12, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0229] In this case, the AIoT device 150 may be pre-configured with the password / token. The network authenticates and authorizes the AIoT device 150 by the password / token from AF 120 and from the AIoT device 150.
[0230] In the signaling flow 1200, at 12010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the fourth indication. That is, the inventory request indicates password / token based security and / or privacy operation for network access is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID , device ID, password / token based security and / or privacy operation for network access indication, and password / token for AIoT device accessing network. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140. The password / token based security and / or privacy operation for network access indication indicates the network shall authenticate and authorize the AIoT device by password / token from the AIoT device.
[0231] At 12020, the AIoT controller 110 may transmit an AIoT password / token based security and / or privacy operation authorization request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The AIoT password / token based security and / or privacy operation authorization request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0232] At 12030, in response to receiving the AIoT password / token based security and / or privacy operation authorization request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based security and / or privacy operation for network access. The reader ID (s) shall be the common parts both from the reader ID in 11010 and 11030, and the differences between them shall be excluded. There may be information stored in AIoT device management function 130 related to the reader id of the readers to be authorized for performing the AIoT password / token based security and / or privacy operation for network access. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, the AIoT password / token based security and / or privacy operation authorization response, which may include the device ID, password / token based security and / or privacy operation for network access indication, password / token based security and / or privacy operation for network access allowed reader ID (s) . If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0233] At 12040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 accessing the network with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation for network access indication.
[0234] At 12050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID and the request password / token for the AIoT device accessing the network.
[0235] At 12060, in response to receiving the inventory request from the reader 140, the AIoT device 150 may transmit, to the reader, a response including the device ID and the password / token.
[0236] Then, at 12070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID, reader ID and the password / token.
[0237] Finally, at 12080, the AIoT controller 110 may determine whether the password / token is allowed by comparing the password / token received from the AIoT device management function 130 at 12030 and the password / token received from the reader. In response to determining the two password / token are matched, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0238] In this way, the device ID of the AIoT device 150 can be obtained by the authorized reader with verifying password / token in an efficient and simplified way. The AIoT controller can verify the AIoT device, which enhances the security and / or privacy of the access is further improved.
[0239] FIG. 13 illustrates a signaling flow 1300 of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 1300 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 13, the signaling flow 1300 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0240] In the embodiment of FIG. 13, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0241] In this case, mutual authentication / authorization is performed between the AIoT device 150 and the network, including the combinations between device authorizing network and network authorizing device. The passwords / tokens in AIoT device 150 and from AF 120 may be different.
[0242] In the signaling flow 1300, at 13010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the fifth indication. That is, the inventory request indicates , password / token based mutual security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID , device ID, password / token based mutual security and / or privacy operation indication, and password / token for network accessing AIoT device, and password / token for AIoT Device accessing the network. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140. The password / token based mutual security and / or privacy operation indication indicates the network shall authenticate and authorize the AIoT device by password / token from the AIoT device.
[0243] At 13020, the AIoT controller 110 may transmit an AIoT information request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The AIoT information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0244] At 13030, in response to receiving the AIoT information request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based mutual security and / or privacy operation. The reader ID (s) shall be the common parts both from the reader ID in 11010 and 11030, and the differences between them shall be excluded. There may be information stored in AIoT device management function 130 related to the reader id of the readers to be authorized for performing the AIoT password / token based security and / or privacy operation for network access. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, the AIoT Device information response, which may include the device ID, password / token based mutual security and / or privacy operation indication, password / token based mutual security and / or privacy operation indication allowed reader ID. If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0245] At 13040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 accessing the network with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation for network access indication, and password / token for network accessing AIoT device. Further, the AIoT controller 110 may store the password / token for AIoT device accessing the network.
[0246] At 13050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID, password / token for network accessing AIoT device, and request password / token for AIoT device accessing the network indication.
[0247] At 13060, in response to receiving the inventory request from the reader 140. The AIoT device 150 may determine whether the password / token for network accessing AIoT device received from the reader 140 is allowed by comparing the received password / token with the password / token stored in the AIoT device 150. Further, in response to determining that the two password / token are matched, the AIoT device 150 may transmit, to the reader, a response including the device ID and password / token for AIoT device accessing the network indication.
[0248] Then, at 13070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID, reader ID and the password / token for AIoT device accessing the network.
[0249] Finally, at 13080, the AIoT controller 110 may determine whether the password / token received from the reader 140 is allowed by comparing the password / token for AIoT device accessing the network with the stored password / token received from the AF 120 at 13010. In response to determining the two password / token are matched, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0250] In this way, the AIoT device and the AIoT controller can verify each other mutually, which improves the security and / or privacy of access of the AIoT device ID.
[0251] FIG. 14 illustrates a signaling flow 1400c of an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure an example procedure of access security and / or privacy for AIoT device in accordance with some embodiments of the present disclosure. For the purposes of discussion, the signaling flow 1400 will be discussed with reference to FIG. 1C and FIG. 1D. As shown in FIG. 14, the signaling flow 1400 involves the AIoT controller 110, the AF 120, the AIoT device management 130, the AIoT reader 140, and the AIoT device 150.
[0252] In the embodiment of FIG. 14, the AIoT controller is an implementation of the first device 210 in FIG. 2, the AF 120 is an implementation of the second device 220 in FIG. 2, the AIoT device management function 130 is an implementation of the third device 230 in FIG. 2, the AIoT reader 140 is an implementation of the fourth device 240 in FIG. 2, the AIoT device 150 is an implementation of the fifth device 250 in FIG. 2. It is to be understood that the above examples are just discussed for illustration, rather than suggesting any limitations.
[0253] In the signaling flow 1400, at 14010, the AF 120 transmits an inventory request to the AIoT controller 110. The inventory request is an implementation of the first request. Moreover, the inventory request may include the fifth indication. That is, the inventory request indicates, password / token based mutual security and / or privacy operation is allowed. From the core network and third party application’s perspectives, the AIoT device only needs to store its device identification (ID) , and response its device ID to an AIoT reader when the AIoT reader requests for inventory. Further, the inventory request transmitted by the AF 120 may include reader ID , device ID, password / token based mutual security and / or privacy operation indication. The reader ID indicates the reader requested for inventory. Further, the device ID indicates the AIoT device for inventory. In an example, multiple device IDs may be included. Furthermore, the inventory request may indicate reader ID shall be transmitted to the AIoT device 150 in the inventory request from reader 140. The password / token based mutual security and / or privacy operation indication indicates the network shall authenticate and authorize the AIoT device by password / token from the AIoT device.
[0254] At 14020, the AIoT controller 110 may transmit an AIoT information request to the AIoT device management 130. The AIoT device management may receive the request and may transmit, to the AIoT controller, a response to the request. The AIoT information request may include device ID. If multiple device IDs are received, AIoT controller may repeat this step per device ID for multiple times, or AIoT controller may transmit the device ID list to AIoT device management in the same message.
[0255] At 14030, in response to receiving the AIoT information request, the AIoT device management function 130 may determine whether the reader is allowed to perform password / token based mutual security and / or privacy operation. The reader ID (s) shall be the common parts both from the reader ID in 11010 and 11030, and the differences between them shall be excluded. There may be information stored in AIoT device management function 130 related to the reader id of the readers to be authorized for performing the AIoT password / token based security and / or privacy operation for network access. Then, the AIoT device management function 130 may transmit, to the AIoT controller 110, the AIoT Device information response, which may include the device ID, password / token based mutual security and / or privacy operation indication, password / token based mutual security and / or privacy operation indication allowed reader ID, password / token for AIoT device accessing the network, and password / token for network accessing AIoT device. The password / token for AIoT device accessing the network and password / token for network accessing AIoT device may be predetermined and stored in the AIoT management 130. If multiple device IDs are received, this message may include all device information corresponding to the device IDs.
[0256] At 14040, the AIoT controller 110 may determine whether the target reader belongs to the list of readers. Further in response to determining that the target reader belongs to the list of readers, the AIoT controller 110 may transmit inventory request to the reader 140. That is, the AIoT controller authorizes the password / token based security and / or privacy operation for the AIoT device 150 accessing the network with reader 140. The AIoT controller 110 may transmit the inventory request to the reader (s) , which includes device ID, password / token based security and / or privacy operation for network access indication, and password / token for network accessing AIoT Device. Further, the AIoT controller 110 may store the password / token for AIoT device accessing the network.
[0257] At 14050, the reader (s) may transmit inventory request to the AIoT device 150, which includes the device ID, password / token for network accessing AIoT device, and request password / token for AIoT device accessing the network indication.
[0258] At 13060, in response to receiving the inventory request from the reader 140. The AIoT device 150 may determine whether the password / token for network accessing AIoT device received from the reader 140 is allowed by comparing the received password / token with the password / token stored in the AIoT device 150. Further, in response to determining that the two password / token are matched, the AIoT device 150 may transmit, to the reader, a response including the device ID and password / token for AIoT device accessing the network indication.
[0259] Then, at 13070, the reader may transmit the inventory response to the AIoT controller 110 with the device ID, reader ID and the password / token for AIoT device accessing the network.
[0260] Finally, at 13080, the AIoT controller 110 may determine whether the password / token received from the reader 140 is allowed by comparing the password / token for AIoT device accessing the network with the stored password / token received from the AF 120 at 13010. In response to determining the two password / token are matched, the AIoT controller 110 may store the device ID and the reader ID. If multiple inventory responses are received from different readers, the AIoT controller 110 may store the device ID and multiple reader IDs. Furthermore, the AIoT controller 110 may transmit the inventory response to AF 120 with the device ID and reader ID (s) .
[0261] In this way, the AIoT device and the AIoT controller can verify each other mutually, which improves the security and / or privacy of access of the AIoT device ID.
[0262] FIG. 15 illustrates a flowchart of a communication method 1500 implemented at a first device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1500 will be described from the perspective of the first device 210 in FIG. 1.
[0263] At block 1510, the first device 210 receives, from a second device, a first request for a device identification of a fifth device associated with a target reader.
[0264] In some embodiments, the first request may comprise at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0265] In some example embodiments, the first request may comprise the first indication, and the first device is further caused to: transmit, to a third device, a second request for verifying whether the no security and / or privacy operation is allowed for the target reader; and receive, from the third device, a second response to the second request.
[0266] In some example embodiments, the second response may comprise a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device.
[0267] In some example embodiments, the second response may indicate that the no security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device.
[0268] In some example embodiments, the second response may comprise at least one of: a reader identification of the target reader; and / or wherein the third request comprises at least one of: the identification of a fifth device, or the first indication.
[0269] In some example embodiments, the first request may comprise the second indication, and the first device is further caused to: transmit, to a third device, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for the target reader, wherein the fourth request comprising a reader identification of the reader obtained from the first request; and receive, from the third device, a third response to the fourth request.
[0270] In some example embodiments, the third response may comprise a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device.
[0271] In some example embodiments, the third response may indicate that the reader identification based security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device.
[0272] In some example embodiments, the third response may comprise at least one of: a reader identification of the target reader, the device identification of the fifth device, or the second indication; and / or wherein the fifth request comprises at least one of: the device identification of a fifth device, or the second indication.
[0273] In some example embodiments, the first request may comprise the third indication, and the first device is further caused to: transmit, to a third device, a sixth request for verifying whether the password / token based security and / or privacy operation is allowed for the target reader; and receive, from the third device, a fourth response to the second request.
[0274] In some example embodiments, the first request may further comprise a first password / token, and the fourth response comprises a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, the first password / token, or the second password / token.
[0275] In some example embodiments, the first request may comprise a first password / token, the fourth response indicates that the password / token based security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the first password / token.
[0276] In some example embodiments, the sixth request may comprise at least one of the identification of the fifth device, or a reader identification of the target reader; and / or wherein the fourth response comprises at least one of: the identification of the fifth device, the third indication, the reader identification of the targe reader, or the first password / token.
[0277] In some example embodiments, the first request may exclude a first password / token, the fourth response comprises a second password / token and a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the second password / token.
[0278] In some example embodiments, the first request may exclude a first password / token, and the fourth response comprises a second password / token and indicates that the password / token based security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the second password / token.
[0279] In some example embodiments, the sixth request may comprise at least one of the device identification of the fifth device, or the reader identification of the target reader; and / or wherein the fourth response comprises the second password / token and at least one of: the device identification of the fifth device, the third indication, or the reader identification of the target reader.
[0280] In some example embodiments, the first device may transmit, to the second device, a first response to the first request, the first response comprising at least one of the device identification of the fifth device, or a reader identification of the target reader.
[0281] In some example embodiments, the first device may receive, from the fourth device, a response comprising at least one of the device identification of the fifth device, a reader identification of the target reader, or a third password / token from the fifth device.
[0282] In some example embodiments, the first request may comprise the fourth indication, the response received from the fourth device comprises the third password / token, and the first device is further caused to: determine whether the third password / token can be used for accessing network; and in response to determine that the third password / token can be used for accessing the network, transmit, to the second device, a first response comprising at least one of the device identification of the fifth device or the reader identification.
[0283] In some example embodiments, the first device may comprise an AIoT controller, the second device comprises a device implement an Application Function (AF) , the third device comprises an AIoT device management function, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0284] FIG. 16 illustrates a flowchart of a communication method 1600 implemented at a second device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1600 will be described from the perspective of the second device 220 in FIG. 1.
[0285] At block 1610, the second device 220 transmits, to a first device, a first request for a device identification of a fifth device associated with a target reader.
[0286] The first request may comprise at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0287] In some example embodiments, the second device may receive, from the first device, a first response to the first request, the first response comprising at least one of the device identification of the fifth device, or a reader identification of the target reader.
[0288] In some example embodiments, the first device may comprise an AIoT controller, and the second device comprises a device implement an Application Function (AF) .
[0289] FIG. 17 illustrates a flowchart of a communication method 1700 implemented at a third device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1700 will be described from the perspective of the third device 230 in FIG. 1.
[0290] At block 1710, the third device 230 receives, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed.
[0291] At block 1720, the third device 230 transmits, to the first device, a response to the request.
[0292] The request being transmitted in response to a first request may comprise at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0293] In some example embodiments, the first request may comprise the first indication, and the third device is further caused to: receive, from the first device, a second request for verifying whether the no security and / or privacy operation is allowed for a target reader; and transmit, to the first device, a second response to the second request.
[0294] In some example embodiments, the second response may comprise at least one of: a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device, or an indication indicating that the no security and / or privacy operation is allowed for the target reader.
[0295] In some example embodiments, the first request may comprise the second indication, and the third device is further caused to: receive, from the first device, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for a target reader; and transmit, to the first device, a third response to the fourth request.
[0296] In some example embodiments, the third response may comprise at least one of: a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device, or an indication indicating that the reader identification based security and / or privacy operation is allowed for the target reader.
[0297] In some example embodiments, the first request may comprise the third indication, and the third device is further caused to: receive, from the first device, a sixth request for verifying whether the password / token based security and / or privacy operation is allowed for a target reader; and transmit, to the first device, a fourth response to the second request.
[0298] In some example embodiments, the first request may further comprise a first password / token, and the fourth response comprises at least one of: a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, or an indication indicating that the password / token based security and / or privacy operation is allowed for the target reader.
[0299] In some example embodiments, the sixth request may comprise at least one of the identification of the fifth device, or a reader identification of the target reader; and / or wherein the fourth response comprises at least one of: the identification of the fifth device, the third indication, the reader identification of the targe reader, or the first password / token.
[0300] In some example embodiments, the first request may exclude a first password / token, and the fourth response comprises a second password / token, the fourth response comprises at least one of: a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, or an indication indicating that the password / token based security and / or privacy operation is allowed for the target reader.
[0301] In some example embodiments, the sixth request may comprise at least one of the device identification of the fifth device, or the reader identification of the target reader; and / or wherein the fourth response comprises the second password / token and at least one of: the device identification of the fifth device, the third indication, or the reader identification of the target reader.
[0302] In some example embodiments, the first device may comprise an AIoT controller, the second device comprises a device implement an Application Function (AF) , the third device comprises an AIoT device management function, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0303] FIG. 18 illustrates a flowchart of a communication method 1800 implemented at a fourth device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1800 will be described from the perspective of the fourth device 240 in FIG. 1.
[0304] At block 1810, the fourth device 240 receives, from a first device, a request for a device identification of a fifth device.
[0305] At block 1820, the fourth device 240 transmits, to the fifth device, a further request for the device identification of the fifth device.
[0306] The request being transmitted based on a first request may comprise at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0307] In some example embodiments, the first request may comprise the first indication, and the fourth device is further caused to: receive, from the first device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device; and transmit, to the fifth device, the further request comprising the device identification of the fifth device.
[0308] In some example embodiments, the fourth device may receive, from the fifth device, a response comprising the device identification of the fifth device; and transmit, to the first device, a further response comprising the device identification of the fifth device.
[0309] In some example embodiments, the first request may comprise the second indication, and the fourth device is further caused to: receive, from the first device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device; and transmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, or the reader identification of the target reader.
[0310] In some example embodiments, the first request may comprise the third indication, and the fourth device is further caused to: receive, from the first device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the identification of the fifth device, the third indication, the first password / token, or the second password / token; and transmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, the first password / token, or the second password / token.
[0311] In some example embodiments, the fourth device may receive, from the fifth device, a response comprising the device identification of the fifth device; and transmit, to the first device, a further response comprising at least one of the device identification of the fifth device, or the reader identification of the target reader.
[0312] In some example embodiments, the first request may comprise the fourth indication, and the fourth device is further caused to: receive, from the first device, a seventh request indicating that the password / token based security and / or privacy operation for network access is to be performed with respect to the fifth device; and transmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, a request for a third password / token from the fifth device.
[0313] In some example embodiments, the fourth device 240 may receive, from the fifth device, a response comprising at least one of the device identification of the fifth device or the third password / token; and transmit, to the first device, a further response comprising at least one of the device identification of the fifth device, the reader identification of the target reader, or the third password / token.
[0314] In some example embodiments, the first device may comprise an AIoT controller, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0315] FIG. 19 illustrates a flowchart of a communication method 1900 implemented at a fifth device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1900 will be described from the perspective of the fifth device 250 in FIG. 1.
[0316] At block 1910, the fifth device 250 receives, from a fourth device, a request for an device identification of the fifth device.
[0317] At block 1920, the fifth device 250 transmits, to the fourth device, a response comprising the device identification of the fifth device.
[0318] The request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0319] In some example embodiments, the first request may comprise the first indication, and the fifth device is further caused to: receive, from the fourth device, the request comprising the device identification of the fifth device; and transmit, to the fourth device, a response comprising the device identification of the fifth device.
[0320] In some example embodiments, the first request may comprise the second indication, and the fifth device is further caused to: receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, or the reader identification of the target reader; determine whether the reader identification of the target reader is allowed; and in response to determining that the reader identification of the target reader is allowed, transmit, to the fifth device, a response comprising the device identification of the fifth device.
[0321] In some example embodiments, the first request may comprise the third indication, and the fifth device is further caused to: receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, a password / token; determine whether the password / token is allowed; and in response to determining that the password / token is allowed, transmit, to the fourth device, a response comprising the device identification of the fifth device.
[0322] In some example embodiments, the first request may comprise the fourth indication, and the fourth device is further caused to: receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, a request for a password / token from the fifth device; and transmit, to the fourth device, a response comprising at least one of the device identification of the fifth device or the password / token.
[0323] In some example embodiments, the fourth device may comprise a reader, and the fifth device comprises an AIoT device.
[0324] FIG. 20 is a simplified block diagram of a device 2000 that is suitable for implementing embodiments of the present disclosure. The device 2000 can be considered as a further example implementation of any of the devices as shown in FIG. 1 A, FIG. 1B, FIG. 1C, FIG. 1D and FIG. 2. Accordingly, the device 2000 can be implemented at or as at least a part of the first device 210, the second device 220, the third device 230, the fourth device 240 and the fifth device 250.
[0325] As shown, the device 2000 includes a processor 2010, a memory 2020 coupled to the processor 2010, a suitable transceiver 2040 coupled to the processor 2010, and a communication interface coupled to the transceiver 2040. The memory 2020 stores at least a part of a program 2030. The transceiver 2040 may be for bidirectional communications or a unidirectional communication based on requirements. The transceiver 2040 may include at least one of a transmitter 2042 and a receiver 2044. The transmitter 2042 and the receiver 2044 may be functional modules or physical entities. The transceiver 2040 has at least one antenna to facilitate communication, though in practice an Access Node mentioned in this application may have several ones. The communication interface may represent any interface that is necessary for communication with other network elements, such as X2 / Xn interface for bidirectional communications between eNBs / gNBs, S1 / NG interface for communication between a Mobility Management Entity (MME) / Access and Mobility Management Function (AMF) / SGW / UPF and the eNB / gNB, Un interface for communication between the eNB / gNB and a relay node (RN) , or Uu interface for communication between the eNB / gNB and a terminal device.
[0326] The program 2030 is assumed to include program instructions that, when executed by the associated processor 2010, enable the device 2000 to operate in accordance with the embodiments of the present disclosure, as discussed herein with reference to FIGS. 1 to 19. The embodiments herein may be implemented by computer software executable by the processor 2010 of the device 2000, or by hardware, or by a combination of software and hardware. The processor 2010 may be configured to implement various embodiments of the present disclosure. Furthermore, a combination of the processor 2010 and memory 2020 may form processing means 2050 adapted to implement various embodiments of the present disclosure.
[0327] The memory 2020 may be of any type suitable to the local technical network and may be implemented using any suitable data storage technology, such as a non-transitory computer readable storage medium, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory, as non-limiting examples. While only one memory 2020 is shown in the device 2000, there may be several physically distinct memory modules in the device 2000. The processor 2010 may be of any type suitable to the local technical network, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 2000 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0328] According to embodiments of the present disclosure, a first device comprising a circuitry is provided. The circuitry is configured to: receive, from a second device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the first device as discussed above.
[0329] According to embodiments of the present disclosure, a second device comprising a circuitry is provided. The circuitry is configured to: transmit, to a first device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the second device as discussed above.
[0330] According to embodiments of the present disclosure, a third device comprising a circuitry is provided. The circuitry is configured to: receive, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the first device, a response to the request. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the third device as discussed above.
[0331] According to embodiments of the present disclosure, a fourth device comprising a circuitry is provided. The circuitry is configured to: receive, from a first device, a request for a device identification of a fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the fifth device, a further request for the device identification of the fifth device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the fourth device as discussed above.
[0332] According to embodiments of the present disclosure, a fifth device comprising a circuitry is provided. The circuitry is configured to: receive, from a fourth device, a request for an device identification of the fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the fourth device, a response comprising the device identification of the fifth device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the fifth device as discussed above.
[0333] The term “circuitry” used herein may refer to hardware circuits and / or combinations of hardware circuits and software. For example, the circuitry may be a combination of analog and / or digital hardware circuits with software / firmware. As a further example, the circuitry may be any portions of hardware processors with software including digital signal processor (s) , software, and memory (ies) that work together to cause an apparatus, such as a terminal device or a network device, to perform various functions. In a still further example, the circuitry may be hardware circuits and or processors, such as a microprocessor or a portion of a microprocessor, that requires software / firmware for operation, but the software may not be present when it is not needed for operation. As used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (s) or a portion of a hardware circuit or processor (s) and its (or their) accompanying software and / or firmware.
[0334] According to embodiments of the present disclosure, a first apparatus is provided. The first apparatus comprises means for receiving, from a second device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: means for a first indication indicating no security and / or privacy operation is allowed, means for a second indication indicating a reader identification based security and / or privacy operation, means for a third indication indicating a password / token based security and / or privacy operation, means for a fourth indication indicating a password / token based security and / or privacy operation for network access, or means for a fifth indication indicating a password / token based mutual security and / or privacy operation. In some embodiments, the first apparatus may comprise means for performing the respective operations of the method 1300. In some example embodiments, the first apparatus may further comprise means for performing other operations in some example embodiments of the method 1300. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0335] According to embodiments of the present disclosure, a second apparatus is provided. The second apparatus comprises means for transmitting, to a first device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: means for a first indication indicating no security and / or privacy operation is allowed, means for a second indication indicating a reader identification based security and / or privacy operation, means for a third indication indicating a password / token based security and / or privacy operation, means for a fourth indication indicating a password / token based security and / or privacy operation for network access, or means for a fifth indication indicating a password / token based mutual security and / or privacy operation. In some embodiments, the second apparatus may comprise means for performing the respective operations of the method 1400. In some example embodiments, the second apparatus may further comprise means for performing other operations in some example embodiments of the method 1400. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0336] According to embodiments of the present disclosure, a third apparatus is provided. The third apparatus comprises means for receiving, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to a first request comprising at least one of the following: means for a first indication indicating no security and / or privacy operation is allowed, means for a second indication indicating a reader identification based security and / or privacy operation, means for a third indication indicating a password / token based security and / or privacy operation, means for a fourth indication indicating a password / token based security and / or privacy operation for network access, or means for a fifth indication indicating a password / token based mutual security and / or privacy operation; and means for transmitting, to the first device, a response to the request. In some embodiments, the third apparatus may comprise means for performing the respective operations of the method 1500. In some example embodiments, the third apparatus may further comprise means for performing other operations in some example embodiments of the method 1500. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0337] According to embodiments of the present disclosure, a fourth apparatus is provided. The fourth apparatus comprises means for receiving, from a first device, a request for a device identification of a fifth device, the request being transmitted based on a first request comprising at least one of the following: means for a first indication indicating no security and / or privacy operation is allowed, means for a second indication indicating a reader identification based security and / or privacy operation, means for a third indication indicating a password / token based security and / or privacy operation, means for a fourth indication indicating a password / token based security and / or privacy operation for network access, or means for a fifth indication indicating a password / token based mutual security and / or privacy operation; and means for transmitting, to the fifth device, a further request for the device identification of the fifth device. In some embodiments, the fourth apparatus may comprise means for performing the respective operations of the method 1600. In some example embodiments, the fourth apparatus may further comprise means for performing other operations in some example embodiments of the method 1600. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0338] According to embodiments of the present disclosure, a fifth apparatus is provided. The fifth apparatus comprises means for receiving, from a fourth device, a request for an device identification of the fifth device, the request being transmitted based on a first request comprising at least one of the following: means for a first indication indicating no security and / or privacy operation is allowed, means for a second indication indicating a reader identification based security and / or privacy operation, means for a third indication indicating a password / token based security and / or privacy operation, means for a fourth indication indicating a password / token based security and / or privacy operation for network access, or means for a fifth indication indicating a password / token based mutual security and / or privacy operation; and means for transmitting, to the fourth device, a response comprising the device identification of the fifth device. In some embodiments, the fifth apparatus may comprise means for performing the respective operations of the method 1700. In some example embodiments, the fifth apparatus may further comprise means for performing other operations in some example embodiments of the method 1700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0339] In summary, embodiments of the present disclosure provide the following aspects.
[0340] In an aspect, it is proposed a first device comprising: a processor configured to cause the first device to: receive, from a second device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0341] In some embodiments, the first request comprises the first indication, and the first device is further caused to: transmit, to a third device, a second request for verifying whether the no security and / or privacy operation is allowed for the target reader; and receive, from the third device, a second response to the second request.
[0342] In some embodiments, the second response comprises a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device.
[0343] In some embodiments, the second response indicates that the no security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device.
[0344] In some embodiments, the second response comprises at least one of: a reader identification of the target reader; and / or wherein the third request comprises at least one of: the identification of a fifth device, or the first indication.
[0345] In some embodiments, the first request comprises the second indication, and the first device is further caused to: transmit, to a third device, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for the target reader, wherein the fourth request comprising a reader identification of the reader obtained from the first request; and receive, from the third device, a third response to the fourth request.
[0346] In some embodiments, the third response comprises a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device.
[0347] In some embodiments, the third response indicates that the reader identification based security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device.
[0348] In some embodiments, the third response comprises at least one of: a reader identification of the target reader, the device identification of the fifth device, or the second indication; and / or wherein the fifth request comprises at least one of: the device identification of a fifth device, or the second indication.
[0349] In some embodiments, the first request comprises the third indication, and the first device is further caused to: transmit, to a third device, a sixth request for verifying whether the password / token based security and / or privacy operation is allowed for the target reader; and receive, from the third device, a fourth response to the second request.
[0350] In some embodiments, the first request further comprises a first password / token, and the fourth response comprises a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, the first password / token, or the second password / token.
[0351] In some embodiments, the first request comprises a first password / token, the fourth response indicates that the password / token based security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the first password / token.
[0352] In some embodiments, the sixth request comprises at least one of the identification of the fifth device, or a reader identification of the target reader; and / or wherein the fourth response comprises at least one of: the identification of the fifth device, the third indication, the reader identification of the targe reader, or the first password / token.
[0353] In some embodiments, the first request excludes a first password / token, the fourth response comprises a second password / token and a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, and the first device is further caused to: determining whether the target reader belongs to the list of readers; and in response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the second password / token.
[0354] In some embodiments, the first request excludes a first password / token, and the fourth response comprises a second password / token and indicates that the password / token based security and / or privacy operation is allowed for the target reader, and the first device is further caused to: transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the second password / token.
[0355] In some embodiments, the sixth request comprises at least one of the device identification of the fifth device, or the reader identification of the target reader; and / or wherein the fourth response comprises the second password / token and at least one of: the device identification of the fifth device, the third indication, or the reader identification of the target reader.
[0356] In some embodiments, the first device is further caused to: transmit, to the second device, a first response to the first request, the first response comprising at least one of the device identification of the fifth device, or a reader identification of the target reader.
[0357] In some embodiments, the first device is further caused to: receive, from the fourth device, a response comprising at least one of the device identification of the fifth device, a reader identification of the target reader, or a third password / token from the fifth device.
[0358] In some embodiments, the first request comprises the fourth indication, the response received from the fourth device comprises the third password / token, and the first device is further caused to: determine whether the third password / token can be used for accessing network; and in response to determine that the third password / token can be used for accessing the network, transmit, to the second device, a first response comprising at least one of the device identification of the fifth device or the reader identification.
[0359] In some embodiments, the first device comprises an AIoT controller, the second device comprises a device implement an Application Function (AF) , the third device comprises an AIoT device management function, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0360] In an aspect, it is proposed a second device comprising: a processor configured to cause the second device to: transmit, to a first device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation.
[0361] In some embodiments, the second device is further caused to: receive, from the first device, a first response to the first request, the first response comprising at least one of the device identification of the fifth device, or a reader identification of the target reader.
[0362] In some embodiments, the first device comprises an AIoT controller, and the second device comprises a device implement an Application Function (AF) .
[0363] In an aspect, it is proposed a third device comprising: a processor configured to cause the third device to: receive, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the first device, a response to the request.
[0364] In some embodiments, the first request comprises the first indication, and the third device is further caused to: receive, from the first device, a second request for verifying whether the no security and / or privacy operation is allowed for a target reader; and transmit, to the first device, a second response to the second request.
[0365] In some embodiments, the second response comprises at least one of: a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device, or an indication indicating that the no security and / or privacy operation is allowed for the target reader.
[0366] In some embodiments, the first request comprises the second indication, and the third device is further caused to: receive, from the first device, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for a target reader; and transmit, to the first device, a third response to the fourth request.
[0367] In some embodiments, the third response comprises at least one of: a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device, or an indication indicating that the reader identification based security and / or privacy operation is allowed for the target reader.
[0368] In some embodiments, the first request comprises the third indication, and the third device is further caused to: receive, from the first device, a sixth request for verifying whether the password / token based security and / or privacy operation is allowed for a target reader; and transmit, to the first device, a fourth response to the second request.
[0369] In some embodiments, the first request further comprises a first password / token, and the fourth response comprises at least one of: a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, or an indication indicating that the password / token based security and / or privacy operation is allowed for the target reader.
[0370] In some embodiments, the sixth request comprises at least one of the identification of the fifth device, or a reader identification of the target reader; and / or wherein the fourth response comprises at least one of: the identification of the fifth device, the third indication, the reader identification of the targe reader, or the first password / token.
[0371] In some embodiments, the first request excludes a first password / token, and the fourth response comprises a second password / token, the fourth response comprises at least one of: a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, or an indication indicating that the password / token based security and / or privacy operation is allowed for the target reader.
[0372] In some embodiments, the sixth request comprises at least one of the device identification of the fifth device, or the reader identification of the target reader; and / or wherein the fourth response comprises the second password / token and at least one of: the device identification of the fifth device, the third indication, or the reader identification of the target reader.
[0373] In some embodiments, the first device comprises an AIoT controller, the second device comprises a device implement an Application Function (AF) , the third device comprises an AIoT device management function, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0374] In an aspect, it is proposed a fourth device comprising: a processor configured to cause the fourth device to: receive, from a first device, a request for a device identification of a fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the fifth device, a further request for the device identification of the fifth device.
[0375] In some embodiments, the first request comprises the first indication, and the fourth device is further caused to: receive, from the first device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device; and transmit, to the fifth device, the further request comprising the device identification of the fifth device.
[0376] In some embodiments, the fourth device is further caused to: receive, from the fifth device, a response comprising the device identification of the fifth device; and transmit, to the first device, a further response comprising the device identification of the fifth device.
[0377] In some embodiments, the first request comprises the second indication, and the fourth device is further caused to: receive, from the first device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device; and transmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, or the reader identification of the target reader.
[0378] In some embodiments, the first request comprises the third indication, and the fourth device is further caused to: receive, from the first device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device, wherein the seventh request comprises at least one of: the identification of the fifth device, the third indication, the first password / token, or the second password / token; and transmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, the first password / token, or the second password / token.
[0379] In some embodiments, the fourth device is further caused to: receive, from the fifth device, a response comprising the device identification of the fifth device; and transmit, to the first device, a further response comprising at least one of the device identification of the fifth device, or the reader identification of the target reader.
[0380] In some embodiments, the first request comprises the fourth indication, and the fourth device is further caused to: receive, from the first device, a seventh request indicating that the password / token based security and / or privacy operation for network access is to be performed with respect to the fifth device; and transmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, a request for a third password / token from the fifth device.
[0381] In some embodiments, the fourth device is further caused to: receive, from the fifth device, a response comprising at least one of the device identification of the fifth device or the third password / token; and transmit, to the first device, a further response comprising at least one of the device identification of the fifth device, the reader identification of the target reader, or the third password / token.
[0382] In some embodiments, the first device comprises an AIoT controller, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0383] In an aspect, it is proposed a fifth device comprising: a processor configured to cause the fifth device to: receive, from a fourth device, a request for an device identification of the fifth device, the request being transmitted based on a first request comprising at least one of the following: a first indication indicating no security and / or privacy operation is allowed, a second indication indicating a reader identification based security and / or privacy operation, a third indication indicating a password / token based security and / or privacy operation, a fourth indication indicating a password / token based security and / or privacy operation for network access, or a fifth indication indicating a password / token based mutual security and / or privacy operation; and transmit, to the fourth device, a response comprising the device identification of the fifth device.
[0384] In some embodiments, the first request comprises the first indication, and the fifth device is further caused to: receive, from the fourth device, the request comprising the device identification of the fifth device; and transmit, to the fourth device, a response comprising the device identification of the fifth device.
[0385] In some embodiments, the first request comprises the second indication, and the fifth device is further caused to: receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, or the reader identification of the target reader; determine whether the reader identification of the target reader is allowed; and in response to determining that the reader identification of the target reader is allowed, transmit, to the fifth device, a response comprising the device identification of the fifth device.
[0386] In some embodiments, the first request comprises the third indication, and the fifth device is further caused to: receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, a password / token; determine whether the password / token is allowed; and in response to determining that the password / token is allowed, transmit, to the fourth device, a response comprising the device identification of the fifth device.
[0387] In some embodiments, the first request comprises the fourth indication, and the fourth device is further caused to: receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, a request for a password / token from the fifth device; and transmit, to the fourth device, a response comprising at least one of the device identification of the fifth device or the password / token.
[0388] In some embodiments, the fourth device comprises a reader, and the fifth device comprises an AIoT device.
[0389] In an aspect, a first device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the first device discussed above.
[0390] In an aspect, a second device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the second device discussed above.
[0391] In an aspect, a third device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the third device discussed above.
[0392] In an aspect, a fourth device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the fourth device discussed above.
[0393] In an aspect, a fifth device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the fifth device discussed above.
[0394] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the first device discussed above.
[0395] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the second device discussed above.
[0396] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the third device discussed above.
[0397] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fourth device discussed above.
[0398] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fifth device discussed above.
[0399] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the first device discussed above.
[0400] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the second device discussed above.
[0401] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the third device discussed above.
[0402] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fourth device discussed above.
[0403] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fifth device discussed above.
[0404] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representation, it will be appreciated that the blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0405] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the process or method as described above with reference to FIGS. 1 to 18. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0406] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0407] The above program code may be embodied on a machine readable medium, which may be any tangible medium that may contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine readable medium may be a machine readable signal medium or a machine readable storage medium. A machine readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0408] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0409] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1.A first device comprising:a processor configured to cause the first device to:receive, from a second device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following:a first indication indicating no security and / or privacy operation is allowed,a second indication indicating a reader identification based security and / or privacy operation,a third indication indicating a password / token based security and / or privacy operation,a fourth indication indicating a password / token based security and / or privacy operation for network access, ora fifth indication indicating a password / token based mutual security and / or privacy operation.2.The device of claim 1, wherein the first request comprises the first indication, and the first device is further caused to:transmit, to a third device, a second request for verifying whether the no security and / or privacy operation is allowed for the target reader; andreceive, from the third device, a second response to the second request.3.The device of claim 2, wherein the second response comprises a list of reader identifications of a list of readers for which the no security and / or privacy operation is allowed by the third device, and the first device is further caused to:determining whether the target reader belongs to the list of readers; andin response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device.4.The device of claim 2, wherein the second response indicates that the no security and / or privacy operation is allowed for the target reader, and the first device is further caused to:transmit, to a fourth device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device.5.The device of claim 3 or 4, wherein the second response comprises at least one of: a reader identification of the target reader; and / orwherein the third request comprises at least one of: the identification of a fifth device, or the first indication.6.The device of claim 1, wherein the first request comprises the second indication, and the first device is further caused to:transmit, to a third device, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for the target reader, wherein the fourth request comprising a reader identification of the reader obtained from the first request; andreceive, from the third device, a third response to the fourth request.7.The device of claim 6, wherein the third response comprises a list of reader identifications of a list of readers for which the reader identification based security and / or privacy operation is allowed by the third device, and the first device is further caused to:determining whether the target reader belongs to the list of readers; andin response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device.8.The device of claim 6, wherein the third response indicates that the reader identification based security and / or privacy operation is allowed for the target reader, and the first device is further caused to:transmit, to a fourth device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device.9.The device of claim 7 or 8, wherein the third response comprises at least one of: a reader identification of the target reader, the device identification of the fifth device, or the second indication; and / orwherein the fifth request comprises at least one of: the device identification of a fifth device, or the second indication.10.The device of claim 1, wherein the first request comprises the third indication, and the first device is further caused to:transmit, to a third device, a sixth request for verifying whether the password / token based security and / or privacy operation is allowed for the target reader; andreceive, from the third device, a fourth response to the second request.11.The device of claim 10, wherein the first request further comprises a first password / token, and the fourth response comprises a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, and the first device is further caused to:determining whether the target reader belongs to the list of readers; andin response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device,wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, the first password / token, or the second password / token.12.The device of claim 10, wherein the first request comprises a first password / token, the fourth response indicates that the password / token based security and / or privacy operation is allowed for the target reader, and the first device is further caused to:transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device,wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the first password / token.13.The device of claim 11 or 12, wherein the sixth request comprises at least one of the identification of the fifth device, or a reader identification of the target reader; and / orwherein the fourth response comprises at least one of: the identification of the fifth device, the third indication, the reader identification of the targe reader, or the first password / token.14.The device of claim 10, wherein the first request excludes a first password / token, the fourth response comprises a second password / token and a list of reader identifications of a list of readers for which the password / token based security and / or privacy operation is allowed by the third device, and the first device is further caused to:determining whether the target reader belongs to the list of readers; andin response to determining that the target reader belongs to the list of readers, transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device,wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the second password / token.15.The device of claim 10, wherein the first request excludes a first password / token, and the fourth response comprises a second password / token and indicates that the password / token based security and / or privacy operation is allowed for the target reader, and the first device is further caused to:transmit, to a fourth device, a seventh request indicating that the password / token based security and / or privacy operation is to be performed with respect to the fifth device,wherein the seventh request comprises at least one of: the device identification of the fifth device, the third indication, or the second password / token.16.The device of claim 14 or 15, wherein the sixth request comprises at least one of the device identification of the fifth device, or the reader identification of the target reader; and / orwherein the fourth response comprises the second password / token and at least one of: the device identification of the fifth device, the third indication, or the reader identification of the target reader.17.The device of any of claims 1 to 16, wherein the first device is further caused to:transmit, to the second device, a first response to the first request, the first response comprising at least one of the device identification of the fifth device, or a reader identification of the target reader.18.The device of any of claims 1 to 17, wherein the first device is further caused to:receive, from the fourth device, a response comprising at least one of the device identification of the fifth device, a reader identification of the target reader, or a third password / token from the fifth device.19.The device of claim 18, wherein the first request comprises the fourth indication, the response received from the fourth device comprises the third password / token, and the first device is further caused to:determine whether the third password / token can be used for accessing network; andin response to determine that the third password / token can be used for accessing the network, transmit, to the second device, a first response comprising at least one of the device identification of the fifth device or the reader identification.20.The device of any of claims 1 to 19, wherein the first device comprises an AIoT controller, the second device comprises a device implement an Application Function (AF) , the third device comprises an AIoT device management function, the fourth device comprises a reader, and the fifth device comprises an AIoT device.21.A second device comprising:a processor configured to cause the second device to:transmit, to a first device, a first request for a device identification of a fifth device associated with a target reader, the first request comprising at least one of the following:a first indication indicating no security and / or privacy operation is allowed,a second indication indicating a reader identification based security and / or privacy operation,a third indication indicating a password / token based security and / or privacy operation,a fourth indication indicating a password / token based security and / or privacy operation for network access, ora fifth indication indicating a password / token based mutual security and / or privacy operation.22.A third device comprising:a processor configured to cause the third device to:receive, from a first device, a request for verifying whether an operation related to security and / or privacy is allowed, the request being transmitted in response to a first request comprising at least one of the following:a first indication indicating no security and / or privacy operation is allowed,a second indication indicating a reader identification based security and / or privacy operation,a third indication indicating a password / token based security and / or privacy operation,a fourth indication indicating a password / token based security and / or privacy operation for network access, ora fifth indication indicating a password / token based mutual security and / or privacy operation; andtransmit, to the first device, a response to the request.23.The device of claim 22, wherein the first request comprises the first indication, and the third device is further caused to:receive, from the first device, a second request for verifying whether the no security and / or privacy operation is allowed for a target reader; andtransmit, to the first device, a second response to the second request.24.The device of claim 22, wherein the first request comprises the second indication, and the third device is further caused to:receive, from the first device, a fourth request for verifying whether the reader identification based security and / or privacy operation is allowed for a target reader; andtransmit, to the first device, a third response to the fourth request.25.A fourth device comprising:a processor configured to cause the fourth device to:receive, from a first device, a request for a device identification of a fifth device, the request being transmitted based on a first request comprising at least one of the following:a first indication indicating no security and / or privacy operation is allowed,a second indication indicating a reader identification based security and / or privacy operation,a third indication indicating a password / token based security and / or privacy operation,a fourth indication indicating a password / token based security and / or privacy operation for network access, ora fifth indication indicating a password / token based mutual security and / or privacy operation; andtransmit, to the fifth device, a further request for the device identification of the fifth device.26.The device of claim 25, wherein the first request comprises the first indication, and the fourth device is further caused to:receive, from the first device, a third request indicating that the no security and / or privacy operation is to be performed with respect to the fifth device; andtransmit, to the fifth device, the further request comprising the device identification of the fifth device.27.The device of claim 25, wherein the first request comprises the second indication, and the fourth device is further caused to:receive, from the first device, a fifth request indicating that the reader identification based security and / or privacy operation is to be performed with respect to the fifth device; andtransmit, to the fifth device, the further request comprising at least one of the device identification of the fifth device, or the reader identification of the target reader.28.A fifth device comprising:a processor configured to cause the fifth device to:receive, from a fourth device, a request for an device identification of the fifth device, the request being transmitted based on a first request comprising at least one of the following:a first indication indicating no security and / or privacy operation is allowed,a second indication indicating a reader identification based security and / or privacy operation,a third indication indicating a password / token based security and / or privacy operation,a fourth indication indicating a password / token based security and / or privacy operation for network access, ora fifth indication indicating a password / token based mutual security and / or privacy operation; andtransmit, to the fourth device, a response comprising the device identification of the fifth device.29.The device of claim 28, wherein the first request comprises the first indication, and the fifth device is further caused to:receive, from the fourth device, the request comprising the device identification of the fifth device; andtransmit, to the fourth device, a response comprising the device identification of the fifth device.30.The device of claim 28, wherein the first request comprises the second indication, and the fifth device is further caused to:receive, from the fourth device, the request comprising at least one of the device identification of the fifth device, or the reader identification of the target reader;determine whether the reader identification of the target reader is allowed; andin response to determining that the reader identification of the target reader is allowed, transmit, to the fifth device, a response comprising the device identification of the fifth device.
Citation Information
Patent Citations
Communication method and device, readable storage medium and chip system
CN116567677A
Internet of Things equipment management method and device
CN117643119A
User equipment (UE) identifier request
US20240064510A1
Access token verification
WO2024016280A1