Method and apparatus for protecting id of ambient IoT device
The method and device for Ambient IoT devices in 5G networks enable secure authentication and identity protection by using random values and keys, addressing the challenges of low-power operation and large-scale deployment in difficult environments.
Patent Information
- Application Number
- PCT/KR2025/012024
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-04-29
- Filing Date
- 2025-08-08
- Publication Date
- 2026-02-12
AI Technical Summary
Ambient IoT devices, which operate at ultra-low power and have limited energy storage and computing capabilities, face challenges in authenticating and protecting their identities within wireless communication systems, especially when deployed in large numbers and difficult environments.
A method and device for Ambient IoT devices that involve receiving a first message with a random value from an AIoTF through a base station, obtaining authentication information using keys, and transmitting a second message with random values or authentication information to the AIoTF, leveraging existing 5G core network functionalities for network registration and management.
Effectively authenticates and protects the identity of Ambient IoT devices, ensuring secure network access while minimizing power consumption and maintaining device integrity in challenging environments.
Smart Images

Figure KR2025012024_12022026_PF_FP_ABST
Abstract
Description
Method and device for protecting the identity of an AMBIENT IOT device
[0001] The present disclosure relates to wireless communication systems, and more particularly to methods and devices for protection and authentication for ultra-low power devices.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz band, such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band (Above 6GHz), also called millimeter wave (mmWave), such as 28GHz and 39GHz. In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz (THz) band (for example, 3 THz band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and ultra-low latency that is reduced to one-tenth.
[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for ultra-wideband services (eMBB: enhanced Mobile Broadband), ultra-reliable / ultra-low-latency communications (URLLC: Ultra-Reliable Low-Latency Communications), and massive Machine-Type Communications (mMTC), including beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple sub-carrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and polar codes for reliable transmission of control information, L2 pre-processing, and specific services. Standardization has been progressed for network slicing, which provides specialized, dedicated networks.
[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.
[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (IIoT: Industrial Internet of Things) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) to provide nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) to simplify random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture: SBA, Service-based Interface: SBI) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.
[0006] When such 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, which will require enhanced functions and performance of 5G mobile communication systems and integrated operation of connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas, and large scale antennas, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, and AI (Artificial Intelligence) from the design stage and internalize end-to-end AI support functions to realize system optimization, and ultra-high-performance communication and computing resources to realize services with complexity that exceeds the limits of terminal computing capabilities. It could serve as a basis for the development of next-generation distributed computing technologies.
[0008] The present disclosure aims to provide a method and device capable of effectively authenticating and protecting the ID of a device in order to provide network services to a device that operates at low power without a battery in a wireless communication system.
[0009] The technical problems to be achieved in the present invention are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present invention belongs from the description below.
[0010] As one aspect of the present disclosure, a method performed by a terminal in a wireless communication system is provided, the method including: receiving a first message including a first random value from an AIoTF (Ambient IoT Function) through a base station; obtaining first authentication information using at least one of a first key, a second key, and the first random value; and transmitting a second message including at least one of a second random value and the first authentication information to the AIoTF through the base station.
[0011] As one aspect of the present disclosure, in a wireless communication system, a terminal includes a transceiver; at least one processor coupled to be communicatively connected with the transceiver; and a memory coupled to be communicatively connected with the at least one processor, wherein the terminal receives a first message including a first random value from an AIoTF (Ambient IoT Function) through a base station, obtains first authentication information using at least one of a first key, a second key, and the first random value, and transmits a second message including at least one of the second random value and the first authentication information to the AIoTF through the base station.
[0012] FIG. 1A illustrates a communication network including core network entities in a wireless communication system according to one embodiment of the present disclosure.
[0013] FIG. 1b illustrates a wireless environment including a core network in a wireless communication system according to an embodiment of the present disclosure.
[0014] FIG. 2a illustrates an example of a functional structure of a terminal according to an embodiment of the present disclosure.
[0015] FIG. 2b illustrates an example of a functional structure of a base station according to an embodiment of the present disclosure.
[0016] FIG. 2c illustrates an example of a functional structure of a core network object according to an embodiment of the present disclosure.
[0017] FIG. 3 illustrates an example of a scenario in which an AIoT device is used in a communication system according to an embodiment of the present disclosure.
[0018] FIG. 4 is a diagram illustrating a process for protecting and authenticating the ID of an AIoT device according to an embodiment of the present disclosure.
[0019] FIG. 5 is a diagram illustrating a process for protecting and authenticating an ID of an AIoT device according to an embodiment of the present disclosure.
[0020] FIG. 6 is a diagram illustrating a process for protecting and authenticating an ID of an AIoT device according to an embodiment of the present disclosure.
[0021] The terms used in this disclosure are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include the plural expression unless the context clearly indicates otherwise. Terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art described in this disclosure. Terms defined in general dictionaries among the terms used in this disclosure may be interpreted as having the same or similar meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even if a term is defined in this disclosure, it cannot be interpreted to exclude embodiments of the present disclosure.
[0022] The various embodiments of the present disclosure described below illustrate a hardware-based approach as an example. However, since the various embodiments of the present disclosure include techniques utilizing both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.
[0023] 3GPP, responsible for cellular mobile communications standards, is standardizing a new core network architecture, dubbed 5G core (5GC), to facilitate the evolution of existing 4G LTE systems into 5G systems. Compared to the evolved packet core (EPC), the network core for existing 4G systems, 5GC supports the following differentiated features:
[0024] First, 5GC introduces network slicing. As a 5G requirement, 5GC must support various terminal types and services (e.g., eMBB, URLLC, or mMTC services). Each type of service has different requirements for the core network. For example, eMBB services require high data rates, while URLLC services require high reliability and low latency. One technology proposed to meet these diverse service requirements is network slicing.
[0025] Network slicing virtualizes a single physical network to create multiple logical networks. Each network slice instance (NSI) can have different characteristics. Therefore, each NSI can satisfy diverse service requirements by possessing a network function (NF) tailored to its characteristics. If each terminal is assigned an NSI that matches the characteristics of the service it requires, multiple 5G services can be efficiently supported.
[0026] Second, 5GC can facilitate support for the network virtualization paradigm by separating mobility management and session management functions. In 4G LTE (long term evolution), services were provided through signaling exchanges with a single core device called the mobility management entity (MME), which was responsible for registration, authentication, mobility management, and session management for all terminals. However, in 5G, the number of terminals increases explosively, and the mobility and traffic / session characteristics that must be supported for each terminal type become more specialized. Therefore, supporting all functions with a single device like the MME inevitably reduces scalability by adding entities for each required function. Therefore, various functions are being developed based on a structure that separates mobility management and session management functions to improve scalability in terms of functional / implementation complexity and signaling load of the core device responsible for the control plane.
[0027] Hereinafter, various embodiments will be described in detail with reference to the attached drawings. Furthermore, when describing embodiments of the present disclosure, detailed descriptions of related known functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the embodiments. Furthermore, the terms described below are defined based on their functions in the embodiments, and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the contents throughout this specification.
[0028] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.
[0029] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure that the present disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification.
[0030] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0031] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
[0032] Here, the term '~ unit' used in various embodiments of the present disclosure means a software or hardware component such as an FPGA or ASIC, and the '~ unit' can perform certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Accordingly, as an example, the '~ unit' may include components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. Additionally, components and '~parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.
[0033] Hereinafter, a base station is an entity that performs resource allocation of a terminal, and may be at least one of an eNode B (eNB), a Node B, a BS (base station), a RAN (radio access network), an AN (access network), a RAN node, a NR NB, a gNB, a wireless access unit, a base station controller, or a node on a network. The terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. In various embodiments of the present disclosure, a case where the terminal is a UE will be described as an example. In addition, although various embodiments of the present disclosure are described below using a system based on LTE, LTE-A, or NR as an example, various embodiments of the present disclosure may be applied to other communication systems having a similar technical background or channel type. In addition, various embodiments of the present disclosure may be applied to other communication systems with some modifications within a range that does not significantly depart from the scope thereof at the discretion of a person having skilled technical knowledge.
[0034] The terms used in the following description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, terms referring to various identification information, etc. are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects with equivalent technical meanings may be used.
[0035] Additionally, while this disclosure describes various embodiments using terminology used in certain communication standards (e.g., 3rd Generation Partnership Project (3GPP)), these are merely illustrative examples. The various embodiments of this disclosure can be easily modified and applied to other communication systems. Below, some terms used in the core network of this disclosure are predefined.
[0036] AMF access and mobility management function
[0037] CN core network
[0038] CNF containerized network function
[0039] DNN data network name
[0040] PCF policy control function
[0041] HSS home subscriber server
[0042] SMF session management function
[0043] UDM user data management
[0044] UPF user plane function
[0045] VNF virtual network function
[0046] Ambient IoT devices may have no batteries or very limited energy storage capabilities, and may also have very limited communication and computing capabilities. Consequently, Ambient IoT devices can be very inexpensive, and typically hundreds of thousands to millions of Ambient IoT devices can be deployed in an area of interest and operate to perform common tasks. This disclosure proposes a method for protecting the IDs of Ambient IoT devices with the aforementioned characteristics and authenticating each device when they are registered on a network.
[0047] Typically, an Ambient IoT device may have at least one of the following characteristics:
[0048] - Very low power consumption for device operation (e.g. 1-500μW)
[0049] - The device is very cheap (e.g. $0.01-$0.5)
[0050] - Very low data transfer speed (e.g. operating at less than 10kbps)
[0051] - The number of devices being deployed is very large (e.g. hundreds, thousands, tens of thousands, hundreds of thousands, or even millions or more).
[0052] - It has very low computational power, simple structure, and very small device size.
[0053] - May not include USIM (Universal Subscriber Identity Module)
[0054] - May not include complex communication protocol stacks such as TCP / IP (Transmission Control Protocol / Internet Protocol)
[0055] - It can be deployed mainly in environments that are difficult for people to access, making maintenance after deployment impossible (e.g. high pressure, extremely high / low temperature, humid environment)
[0056] In this disclosure, Ambient IoT devices can be divided into three types depending on whether there is a battery in the device and the type of communication used by the device.
[0057] - Device Type A: No energy storage and independent signal generation / amplification is not possible.
[0058] - Device Type B: Energy storage is available, but independent signal generation / amplification is not possible.
[0059] - Device Type C: Energy storage and independent signal generation / amplification possible
[0060] In the present disclosure, the types of Ambient IoT devices are not limited to the examples above, and it is also possible to distinguish the types of Ambient IoT devices through other criteria.
[0061] FIG. 1A illustrates a communication network (100) including core network entities in a wireless communication system according to an embodiment of the present disclosure. The 5G mobile communication network (100) may be configured to include a 5G user equipment (UE) (110), a 5G radio access network (RAN) (120), and a 5G core network.
[0062] The 5G core network (100) may be configured to include network functions such as an access and mobility management function (AMF) (150) that provides a mobility management function of a UE, a session management function (SMF) (160) that provides a session management function, a user plane function (UPF) (170) that performs a data transfer role, a policy control function (PCF) (180) that provides a policy control function, a unified data management (UDM) (153) that provides a data management function such as subscriber data and policy control data, or a unified data repository (UDR) that stores data of various network functions.
[0063] Referring to FIG. 1A, a user equipment (UE) (110) may communicate with a base station (e.g., an eNB, a gNB) via a wireless channel, i.e., an access network. In one embodiment, the UE (110) may be a device used by a user and configured to provide a user interface (UI). As an example, the UE (110) may be a terminal mounted (equipment) on a vehicle for driving. In one embodiment, the UE (110) may be a device that performs machine type communication (MTC) that operates without user intervention, or may be an autonomous vehicle. UE may be referred to as a 'terminal', 'vehicle terminal', 'user equipment (UE)', 'mobile station', 'subscriber station', 'remote terminal', 'wireless terminal', or 'user device' or other terms having equivalent technical meanings, other than electronic devices. As the terminal, in addition to the UE, a customer-premises equipment (CPE) or a dongle-type terminal may be used. The CPE, while connected to the NG-RAN node like the UE, may also provide a network to other communication devices (e.g., a laptop).
[0064] Referring to FIG. 1A, the AMF (150) provides a function for connection and mobility management per terminal (110), and basically, one AMF (150) can be connected to one terminal (110). Specifically, the AMF (150) can perform at least one of signaling between core network nodes for mobility between 3GPP access networks, an interface (N2 interface) between wireless access networks (e.g., 5G RAN) (120), NAS signaling with the terminal (110), identification of the SMF (160), and provision of transmission of session management (SM) messages between the terminal (110) and the SMF (160). Some or all of the functions of the AMF (150) can be supported within a single instance of one AMF (150).
[0065] Referring to FIG. 1A, the SMF (160) provides a session management function, and when the terminal (110) has multiple sessions, each session may be managed by a different SMF (160). Specifically, the SMF (160) may perform at least one of the following functions: session management (e.g., session establishment, modification, and release, including tunnel maintenance between the UPF (170) and the access network node), selection and control of UP (user plane) functions, traffic steering setup for routing traffic to an appropriate destination in the UPF (170), termination of the SM portion of NAS messages, downlink data notification (DDN), and initiation of AN-specific SM information (e.g., delivery to the access network via the N2 interface via the AMF (150)). Some or all of the functions of the SMF (160) may be supported within a single instance of one SMF (160).
[0066] In the 3GPP system, conceptual links connecting NFs within a 5G system may be referred to as reference points. Reference points may also be referred to as interfaces. The following exemplifies reference points (hereafter, interchangeably referred to as interfaces) included in the 5G system architecture represented throughout various embodiments of the present disclosure.
[0067] - N1: Reference point between UE (110) and AMF (150)
[0068] - N2: Reference point between (R)AN(120) and AMF(150)
[0069] - N3: Reference point between (R)AN(120) and UPF(170)
[0070] - N4: Reference point between SMF (160) and UPF (170)
[0071] - N5: Reference point between PCF (180) and AF (130)
[0072] - N6: Reference point between UPF (170) and DN (140)
[0073] - N7: Reference point between SMF (160) and PCF (180)
[0074] - N8: Reference point between UDM (153) and AMF (150)
[0075] - N9: Reference point between two core UPFs (170)
[0076] - N10: Reference point between UDM (153) and SMF (160)
[0077] - N11: Reference point between AMF (150) and SMF (160)
[0078] - N12: Reference point between AMF (150) and authentication server function (AUSF) (151)
[0079] - N13: Reference point between UDM (153) and authentication server function (151)
[0080] - N14: Reference point between two AMFs (150)
[0081] - N15: For non-roaming scenarios, reference point between PCF (180) and AMF (150), for roaming scenarios, reference point between PCF (180) and AMF (150) within the visited network.
[0082] FIG. 1B illustrates a wireless environment including a core network (200) in a wireless communication system according to an embodiment of the present disclosure. Referring to FIG. 1B, the wireless communication system may include a radio access network (RAN) (120) and a core network (CN) (200).
[0083] The wireless access network (120) is a network that is directly connected to a user device, for example, a terminal (110), and is an infrastructure that provides wireless access to the terminal (110). The wireless access network (120) includes a set of a plurality of base stations including a base station (125), and the plurality of base stations can communicate through interfaces formed between each other. At least some of the interfaces between the plurality of base stations can be wired or wireless. The base station (125) can have a structure that is divided into a central unit (CU) and a distributed unit (DU). In this case, one CU can control a plurality of DUs. The base station (125) can be referred to as an 'access point (AP)', 'next generation node B (gNB)', '5th generation node (5G node)', 'wireless point', 'transmission / reception point (TRP)', or other terms having an equivalent technical meaning thereto in addition to the base station. The terminal (110) can connect to a wireless access network (120) and communicate with a base station (125) via a wireless channel. The terminal (110) may be referred to as a 'user equipment (UE)', a 'mobile station', a 'subscriber station', a 'remote terminal', a 'wireless terminal', a 'user device', or other terms having an equivalent technical meaning.
[0084] The core network (200) is a network that manages the entire system, controls the wireless access network (120), and can process data and control signals for terminals (110) transmitted and received through the wireless access network (120). The core network (200) performs various functions, such as controlling the user plane and the control plane, processing mobility, managing subscriber information, billing, and interworking with other types of systems (e.g., long term evolution (LTE) systems). In order to perform the various functions described above, the core network (200) may include a number of functionally separated entities having different NFs (network functions). For example, the core network (200) may include an access and mobility management function (AMF) (150), a session management function (SMF) (160), a user plane function (UPF) (170), a policy and charging function (PCF) (180), a network repository function (NRF) (159), a unified data management (UDM) (153), a network exposure function (NEF) (155), and a unified data repository (UDR) (157).
[0085] The terminal (110) can be connected to the AMF (150) that performs the mobility management function of the core network by being connected to the wireless access network (120). The AMF (150) may be a function or device that is in charge of both the connection to the wireless access network (120) and the mobility management of the terminal (110). The SMF (160) is an NF that manages sessions. The AMF (150) is connected to the SMF (160), and the AMF (150) can route session-related messages for the terminal (110) to the SMF (160). The SMF (160) is connected to the UPF (170) to allocate user plane resources to be provided to the terminal (110), and establishes a tunnel for transmitting data between the base station (125) and the UPF (170). PCF (180) can control information related to policy and charging for the session used by the terminal (110).
[0086] The NRF (159) can store information about NFs installed in a mobile communication service provider network and perform a function of notifying the stored information. The NRF (159) can be connected to all NFs. When each NF starts operating in the service provider network, it can notify the NRF (159) that the NF is operating within the network by registering with the NRF (159). The UDM (153) is an NF that performs a role similar to the HSS (home subscriber server) of a 4G network, and can store subscription information of the terminal (110) or the context used by the terminal (110) within the network.
[0087] The NEF (155) may connect a third-party server and an NF within a 5G mobile communication system. It may also provide data to, update, or acquire data from the UDR (157). The UDR (157) may store subscription information of the terminal (110), policy information, data exposed externally, or information required by a third-party application. Furthermore, the UDR (157) may also provide stored data to other NFs.
[0088] FIG. 2A illustrates an example of the functional structure of a terminal (110) according to one embodiment of the present disclosure. The configuration illustrated in FIG. 2A can be understood as the configuration of the terminal (110). Terms such as "... unit" and "... device" used hereinafter mean a unit that processes at least one function or operation, which can be implemented by hardware, software, or a combination of hardware and software.
[0089] Referring to FIG. 2a, the terminal (110) may include a communication unit (205), a storage unit (210), and a control unit (215).
[0090] The communication unit (205) can perform functions for transmitting and receiving signals via a wireless channel. For example, the communication unit (205) can perform a conversion function between a baseband signal and a bit stream according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (205) can generate complex symbols by encoding and modulating a transmission bit stream. In addition, when receiving data, the communication unit (205) can restore a reception bit stream by demodulating and decoding the baseband signal. In addition, the communication unit (205) upconverts a baseband signal to an RF band signal and transmits it through an antenna, and downconverts an RF band signal received through the antenna to a baseband signal. For example, the communication unit (205) can include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.
[0091] In addition, the communication unit (205) may include a plurality of transmit / receive paths. Furthermore, the communication unit (205) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (205) may be composed of digital circuits and analog circuits (e.g., radio frequency integrated circuits (RFIC)). Here, the digital circuits and analog circuits may be implemented in a single package. In addition, the communication unit (205) may include a plurality of RF chains. Furthermore, the communication unit (205) may perform beamforming.
[0092] The communication unit (205) can transmit and receive signals as described above. Accordingly, all or part of the communication unit (205) may be referred to as a "transmitter," a "receiver," or a "transmitting and receiving unit." Furthermore, in the following description, transmission and reception performed via a wireless channel may be used to mean that processing as described above is performed by the communication unit (205).
[0093] The storage unit (210) can store data such as basic programs, application programs, and setting information for the operation of the terminal (110). The storage unit (210) can be composed of volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. In addition, the storage unit (210) can provide stored data upon request from the control unit (215).
[0094] The control unit (215) can control the overall operations of the terminal (110). For example, the control unit (215) can transmit and receive signals through the communication unit (205). In addition, the control unit (215) can record and read data in the storage unit (210). In addition, the control unit (215) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (215) may include at least one processor or microprocessor, or may be a part of a processor. In addition, a part of the communication unit (205) and the control unit (215) may be referred to as a CP (communication processor). According to various embodiments, the control unit (215) can control to perform synchronization using a wireless communication network. For example, the control unit (215) can control the terminal (110) to perform operations according to various embodiments described below.
[0095] According to various embodiments of the present disclosure, a terminal may be composed of a mobile equipment (ME) and a universal subscriber identity module (USIM). The ME may include a mobile terminal (MT) and terminal equipment (TE). The MT may be a part where a wireless access protocol operates, and the TE may be a part where a control function operates. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and the TE may be integrated, and in the case of a laptop, the MT and the TE may be separate. The present disclosure may express the ME and the USIM as distinct entities depending on the operation of each component, but is not limited thereto, and the various embodiments of the present disclosure may be described by expressing the ME and the USIM as a terminal (e.g., UE), or by expressing the ME as a terminal.
[0096] FIG. 2B illustrates an example of the functional structure of a base station (120) according to embodiments of the present disclosure. The configuration illustrated in FIG. 2B can be understood as the configuration of the base station (120). Terms such as "... unit" and "... unit" used hereinafter mean a unit that processes at least one function or operation, which can be implemented by hardware, software, or a combination of hardware and software.
[0097] Referring to FIG. 2b, the base station (120) may include a wireless communication unit (235), a backhaul communication unit (220), a storage unit (225), and a control unit (230).
[0098] The wireless communication unit (235) can perform functions for transmitting and receiving signals via a wireless channel. For example, the wireless communication unit (235) can perform a conversion function between baseband signals and bit streams according to the physical layer specifications of the system. For example, when transmitting data, the wireless communication unit (235) can generate complex symbols by encoding and modulating the transmitted bit stream. Furthermore, when receiving data, the wireless communication unit (235) can restore the received bit stream by demodulating and decoding the baseband signal.
[0099] In addition, the wireless communication unit (235) can upconvert a baseband signal into an RF (radio frequency) band signal and transmit it through an antenna, and downconvert an RF band signal received through the antenna into a baseband signal. To this end, the wireless communication unit (235) can include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a digital to analog convertor (DAC), an analog to digital convertor (ADC), etc. In addition, the wireless communication unit (235) can include a plurality of transmission and reception paths. Furthermore, the wireless communication unit (235) can include at least one antenna array composed of a plurality of antenna elements.
[0100] In terms of hardware, the wireless communication unit (235) may be composed of a digital unit and an analog unit, and the analog unit may be composed of a plurality of sub-units depending on operating power, operating frequency, etc. The digital unit may be implemented with at least one processor (e.g., a digital signal processor (DSP)).
[0101] The wireless communication unit (235) can transmit and receive signals as described above. Accordingly, all or part of the wireless communication unit (235) may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, in the following description, transmission and reception performed via a wireless channel may be used to mean that the wireless communication unit (235) performs the processing described above.
[0102] The backhaul communication unit (220) can provide an interface for performing communication with other nodes within the network. That is, the backhaul communication unit (220) can convert a bit string transmitted from a base station to another node, such as another access node, another base station, an upper node, a core network, etc., into a physical signal, and can convert a physical signal received from another node into a bit string.
[0103] The storage unit (225) can store data such as basic programs, application programs, and setting information for the operation of the base station. The storage unit (225) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (225) can provide stored data upon request from the control unit (230).
[0104] The control unit (230) can control the overall operations of the base station (120). For example, the control unit (230) can transmit and receive signals through the wireless communication unit (235) or the backhaul communication unit (220). In addition, the control unit (230) can record and read data in the storage unit (225). In addition, the control unit (230) can perform functions of a protocol stack required by a communication standard. According to another implementation example, the protocol stack can be included in the wireless communication unit (235). For this purpose, the control unit (230) can include at least one processor. According to various embodiments, the control unit (230) can control to perform synchronization using a wireless communication network. For example, the control unit (230) can control the base station to perform operations according to various embodiments described below.
[0105] FIG. 2C illustrates an example of a functional structure of a core network object (260) according to an embodiment of the present disclosure. It may represent the configuration of a core network object (260) in a wireless communication system according to various embodiments of the present disclosure. The configuration illustrated in FIG. 2C may be understood as a configuration of a device having the function of at least one of the network entities including the AMF (150) of FIG. 1. Terms such as “... unit” and “... device” used hereinafter mean a unit that processes at least one function or operation, and this may be implemented by hardware, software, or a combination of hardware and software.
[0106] Referring to the above drawing 2c, the core network object (260) may be configured to include a communication unit (240), a storage unit (245), and a control unit (250).
[0107] The communication unit (240) may provide an interface for performing communication with other devices within the network. That is, the communication unit (240) may convert a bit string transmitted from the core network object (260) to another device into a physical signal, and may convert a physical signal received from another device into a bit string. That is, the communication unit (240) may transmit and receive signals. Accordingly, the communication unit (240) may be referred to as a modem, a transmitter, a receiver, or a transceiver. In this case, the communication unit (240) may enable the core network object (260) to communicate with other devices or systems via a backhaul connection (e.g., a wired backhaul or a wireless backhaul) or via a network.
[0108] The storage unit (245) can store data such as basic programs, application programs, and setting information for the operation of the core network object (260). The storage unit (245) can be composed of volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. In addition, the storage unit (245) can provide stored data upon request from the control unit (250).
[0109] The control unit (250) can control the overall operations of the core network object (260). For example, the control unit (250) can transmit and receive signals through the communication unit (240). In addition, the control unit (250) can record and read data in the storage unit (245). For this purpose, the control unit (250) can include at least one processor. According to various embodiments of the present disclosure, the control unit (250) can control synchronization using a wireless communication network. For example, the control unit (250) can control the core network object (260) to perform operations according to various embodiments described below.
[0110] The terms used in the following description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, and terms referring to various identification information are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects with equivalent technical meanings may be used.
[0111] For convenience of explanation, this disclosure uses terms and names defined in the 5GS (5G system) and NR (new radio) standards, the most recent standards defined by the 3GPP organization among the existing communication standards. However, this disclosure is not limited to these terms and names and can be equally applied to wireless communication networks conforming to other standards. In particular, this disclosure can be applied to 3GPP 5th generation mobile communication standards (e.g., 5GS and NR).
[0112] FIG. 3 illustrates an example of a scenario in which an Ambient IoT device is used in a communication system according to an embodiment of the present disclosure.
[0113] The communication system of FIG. 3 may be configured to include a data network including a plurality of Ambient IoT devices deployed in a mountainous area, at least one base station capable of communicating with at least one of the Ambient IoT devices or a base station that can function as a base station in the Ambient IoT communication system (represented as an Intermediate node, and the Intermediate node or base station may also be referred to as a Reader), a base station or core network connected to the Reader (which may also be referred to as a Controller or Ambient IoT Function (AIoTF)), and an AF (Application Function) that is communicatively connected to the core network. Although not shown in the drawing, an Ambient IoT Data Management (ADM) may store credentials of the Ambient IoT devices (e.g., IDs (e.g., permanent ID and / or temporary ID) and keys of the Ambient IoT devices). The basic functions and configuration of the data network including the Reader, the Controller / AIoTF, the ADM, and the AF in FIG. 3 may be understood with reference to the example of FIG. 1.
[0114] Referring to Figure 3, the Korea Forest Service or the National Fire Agency can deploy millions of Ambient IoT devices on mountains for early detection of forest fires. When the number of Ambient IoT devices to be deployed is large, the deployment area is vast, and the Ambient IoT devices must be deployed in areas with limited human access, these deployments are often carried out by air. For the reasons mentioned above, maintenance of these deployed Ambient IoT devices (e.g., battery replacement, replacement of faulty components, etc.) can be challenging. Once deployed, Ambient IoT devices may need to operate for as little as 10 years or as long as 20 years, performing their assigned tasks. Therefore, it is important that Ambient IoT devices be configured to operate with minimal battery consumption. In the scenario of Figure 3, the Ambient IoT devices deployed can monitor fires around the mountain. Among the Ambient IoT devices, at least one Ambient IoT device that detects a fire transmits information notifying the occurrence of a fire to the Reader using a wireless network, and the information can be transmitted to the AF (which may be a 3rd party server / provider or a server operated by a telecommunications carrier, such as the server of the National Fire Agency in the example of FIG. 3) via the Controller / AIoTF and a data network. As in the embodiment of FIG. 3, Ambient IoT devices can be deployed for the same purpose, such as notifying the occurrence of a fire, and the information notifying the occurrence of a fire and / or data related to the information can be transmitted to the AF.Although the scenario of a fire occurring in a mountain is illustrated in Figure 3, Ambient IoT devices can also be deployed to provide relevant information in various disaster situations, places where many people use sports stadiums, or places where various commercial services are provided, such as shopping malls.
[0115] FIG. 4 is a diagram illustrating a process for protecting and authenticating the ID of an AIoT device according to an embodiment of the present disclosure.
[0116] According to Fig. 4, the following conditions may be met:
[0117] - The key (K) and the ID of the AIoT device (AIoT ID) may be shared between the AIoT device and AF.
[0118] - AF is a random value generated by K and AF (RAND AF ) from K AIoT can also be created.
[0119] - The ID of an AIoT device may consist of a common part and a unique part, for example. For example, the common part may be a PLMN ID (which may be assigned to devices using the services of a specific telecommunications operator) or a 3 rd party ID (specific 3 rd It may be composed of (which may be assigned to a device using the party's service), and the non-common part may be a value that can represent a specific AIoT device.
[0120] - K and K AIoT may be the same value.
[0121] In step 1, the AF may send an AIoT Service Request message to the Controller / AIoTF. This request may be delivered via the NEF or directly. The AIoT Service Request message contains the command, AIoT ID, and RAND. AF, or K AIoT May include at least one of:
[0122] In step 2, Controller / AIoTF Counter Con can create a Counter Con can be at least one of a random value, a value based on the current time, or a COUNT value shared with the AIoT device. Controller / AIoTF is K AIoT Encryption key (K) from enc ) or integrity protection key (K int ) can also be generated. Controller / AIoTF is K enc , K int , K AIoT , or Counter Con AIoT ID can also be protected using at least one of the following: AIoT ID and Counter Con The value attached (AIoT ID|Counter Con ) or it may be a protected value by encrypting or hashing the AIoT ID. When protecting the AIoT ID, the common part may not be protected. Or, only the common part may be sent to call multiple AIoTs rather than a specific AIoT ID.
[0123] In step 3, Controller / AIoTF Counter Con , RAND AF , at least one of a protected AIoT ID, a common part of the AIoT ID, or a command can be sent to the AIoT device. At least one of the above information is K AIoT Wow Counter Con It may be encrypted, integrity protected, or hashed using .
[0124] In step 4, the AIoT device can receive an AIoT Service Request. After receiving the protected AIoT ID, the AIoT device can check whether the common part of the content is identical to the common part of the AIoT ID it owns. If so, the AIoT device can use the received RAND AF Using K that is stored with K AIoT can be generated. AIoT devices are K AIoT From K enc or K int can also generate. AIoT devices receive Counter Con , K AIoT , K enc , or K int The protected AIoT ID can be decrypted using at least one of the following methods or the same method calculated by the Controller / AIoTF in step 2 can be used to protect its own ID. For example, this can be done as follows:
[0125] - If an encrypted AIoT ID is received, the AIoT device will be K enc or K AIoT Decryption can be performed using . The decrypted result is your ID|Counter Con Or if your ID appears, Counter Con Check if the value received in these 3 steps is the same as the Counter Con You can check if this is an acceptable value (for example, a value that is not too different from the current time or a value that is not too different from the stored COUNT value). If it is an acceptable value, you can prepare to process the command. Command is also K enc or K AIoT It may be an encrypted value using .
[0126] - If a hashed AIoT ID is received, Counter first ConYou can check if this is an acceptable value. If it is an acceptable value, you can check if it is an acceptable value by adding your AIoT ID and the received Counter. Con The value attached (AIoT|Counter Con ) After calculating the hash, you can check if this value is the same as the protected AIoT ID received in step 3. If so, you can prepare to process the command.
[0127] If the AIoT device recognizes that the three-step AIoT Service Request has come to it through the above process, it can process the received command.
[0128] In step 5, the AIoT device may send an AIoT Service Response to the Controller / AIoTF. The AIoT Service Response is a Counter generated by the AIoT device. AIoT (which may be a random value, a value based on the current time, or at least one of the COUNT values maintained with the Controller / AIoTF), and may also include at least one of the protected AIoT ID, command response, or MAC (Message Authentication Code) values received in step 3. The MAC may be, for example, K AIoT , Counter Con , Counter AIoT , command response or message. The AIoT device may be calculated using at least one of K or K enc , or K AIoT You can also use it to encrypt command responses.
[0129] In step 6, the Controller / AIoTF generates the corresponding K based on the received protected AIoT ID. AIoT can be found. K int , K AIoT , Counter Con, Counter AIoT , or at least one of the messages can be used to calculate the MAC and check if it is the same as the value received in step 5. If the calculation is Counter AIoT If used, the Controller / AIoTF will use the Counter AIoT You can also first check if the value is acceptable (for example, if it is not too different from the current time or if it is not too different from the stored COUNT value) before performing the calculation.
[0130] In step 7, AIoT devices and Controller / AIoTF are K AIoT Authentication can also be performed based on the Counter received in step 5. For example, the authentication can be performed as follows: Controller / AIoTF receives the Counter received in step 5. AIoT Value K AIoT Send the encrypted or hashed value using and Challenge with it Con can also be sent. The AIoT device that receives this can send the K AIoT After performing decryption or hash calculation using the Challenge, the Controller / AIoTF can be authenticated. Similarly, AIoT devices can also authenticate the Challenge Con to K AIoT After sending the encrypted or hashed value to the Controller / AIoTF, the Controller / AIoTF can authenticate the AIoT device.
[0131] In step 8, the Controller / AIoTF may send the AIoT ID and the received command response to the AF. If the command response was encrypted, the AF may send K or K enc or K AIoT Decryption can also be performed using .
[0132] FIG. 5 is a diagram illustrating a process for protecting and authenticating an ID of an AIoT device according to an embodiment of the present disclosure.
[0133] According to Fig. 5, the following conditions may be met:
[0134] - The key (K) and the ID of the AIoT device (AIoT ID, for example, two IDs may be shared. One may be a permanent ID and the other may be a temporary ID) may be shared between the AIoT device and the AF.
[0135] - AF is a random value generated by K and AF (RAND AF ) from K AIoT can also be created.
[0136] - The ID of an AIoT device may consist of a common part and a unique part, for example. For example, the common part may be a PLMN ID (which may be assigned to devices using the services of a specific telecommunications operator) or a 3 rd party ID (specific 3 rd It may be composed of (which may be assigned to a device using the party's service), and the non-common part may be a value that can represent a specific AIoT device.
[0137] - K and K AIoT may be the same value.
[0138] In step 1, the AF may send an AIoT Service Request message to the AIoTF and / or ADM. This request may be delivered via the NEF or directly. The AIoT Service Request message may include an inventory request, a command request, AIoT ID(s) (for example, multiple AIoT IDs may be sent when transmitting to multiple AIoT devices), an AIoT ID common part (for example, only the common part of the AIoT ID may be sent when performing group paging), and a RAND. AF , or K AIoT (s) (e.g., multiple AIoT IDs may be transmitted when transmitting to multiple AIoT devices) may include at least one of K or K AIoT may be pre-stored in ADM.
[0139] In step 2, AIoTF and / or ADM may send an AIoT Service Request. The AIoT Service Request message includes Counter Con , RAND AF , AIoT ID(s) (e.g., permanent ID of AIoT or temporary ID of AIoT. For example, AF or AIoTF may transmit permanent ID of AIoT when it is determined that synchronization between AIoT device and Temporary AIoT ID is not possible), common part of AIoT ID (e.g., only common part of AIoT ID may be transmitted when group paging is to be performed), command request, or inventory request. Counter Conmay be at least one of a random value, a value based on the current time, or a COUNT value shared with the AIoT device. AIoTF and / or ADM may be K AIoT Wow Counter Con may be used to protect part or all of the message. Protection may mean encryption or hashing. AIoTF provides the ADM with a key (e.g., K or K AIoT ) can be received and then protected, or a message protection request can be made to the ADM. This step can be transmitted through the Reader (e.g. RAN or UE), and the message transmitted from the Reader to the AIoT device can be, for example, a paging request or an AIoT Service Request.
[0140] In step 3, the AIoT device can receive an AIoT Service Request or paging request.
[0141] If an AIoT device receives an AIoT ID, it can determine whether at least one of the received IDs matches its own ID (e.g., a permanent ID or a temporary ID). If they do not match, the AIoT device can ignore the request. If they do match, the AIoT device can then check the received RAND AF Using K that is stored with K AIoT can be created.
[0142] If the message contains only the AIoT ID common part, not the AIoT ID, the AIoT device can determine whether the common part is identical to the common part of its own ID. If not, the AIoT device can ignore the request. It can also check whether the common part of the content is identical to the common part of its own AIoT ID. If so, the AIoT device can use the received RAND AFUsing K that is stored with K AIoT can be created.
[0143] If the AIoT device has learned through the above process that the AIoT Service Request is coming to it and that the message is protected, the AIoT device will receive the Counter Con and K AIoT The protected message can be decrypted using or part or all of the message can be protected using the same method that AIoTF and / or ADM protected in step 2. For example, this can be done as follows:
[0144] - When an encrypted message arrives, the AIoT device sends a K AIoT You can perform decryption using . If your ID is displayed as a result of decryption, the decrypted Counter Con Check if the value received in these 3 steps is the same as the Counter Con You can check if this is an acceptable value (for example, if it is not too different from the current time or the stored COUNT value). If it is an acceptable value, you can prepare to process the command.
[0145] - If a hashed value is received, Counter first Con You can check if this is an acceptable value. If it is an acceptable value, you can check if it is an acceptable value by adding your AIoT ID and the received Counter. Con The value attached (AIoT|Counter Con ) After calculating the hash, you can check whether this value is the same as the hash value received in step 2. If it is the same, you can prepare to process the command.
[0146] If the AIoT device recognizes that the AIoT Service Request in step 2 is coming to it through at least one of the three steps, it may process the received command. The AIoT device may be K, K AIoT, RAND AF , Counter Con , Counter AIoT , or a Temporary AIoT ID may be generated using at least one non-common portion or all of the AIoT ID (permanent ID or temporary ID of AIoT). The Temporary AIoT ID may be used later by the AF or AIoTF and / or ADM to locate the AIoT device. The AIoT device may store the newly generated Temporary AIoT ID to replace the existing stored AIoT ID (temporary ID). The process of the AIoT device generating and storing the Temporary AIoT ID may be performed at any step after step 4.
[0147] In step 4, the AIoT device may send an AIoT Service Response to the AIoTF and / or ADM via the Reader. The AIoT Service Response may be a Counter generated by the AIoT device. AIoT (which may be a random value, a value based on the current time, or at least one of the COUNT values maintained with the AIoTF), an AIoT ID (which may be an AIoT ID received from the AIoTF in step 2, a permanent ID or temporary ID already stored in the AIoT device before step 1, or a newly created Temporary AIoT ID in step 3), a command response, an inventory response, or a MAC value. The MAC may be, for example, K AIoT , Counter Con , Counter AIoT , or may be calculated using at least one of the messages. The AIoT device may be K or K AIoTThe reader can also encrypt all or part of the command or the corresponding message. The reader can collect AIoT Service Responses received from multiple AIoT devices and send them all at once to the AIoTF and / or ADM. Alternatively, the AIoTF can send some or all of the received messages to the ADM. The reader or AIoTF and / or ADM can also send an ACK message to acknowledge receipt of the step 4 message from the AIoT device.
[0148] In step 5, AIoTF and / or ADM generate corresponding K based on the received AIoT ID. AIoT can be found. AIoTF provides ADM with a key (e.g. K or K AIoT ) can also be requested and received. K AIoT , Counter Con , Counter AIoT , or at least one of the messages can be used to calculate the MAC and check if it is the same as the value received in step 4. If the calculation is Counter AIoT If used, AIoTF and / or ADM will be used Counter AIoT It is also possible to first check whether the value is acceptable (e.g., not significantly different from the current time or not significantly different from the stored COUNT value) before performing the calculation. By verifying the MAC, AIoTF and / or ADM can also take over the authentication of AIoT devices. If the ADM has performed the verification, it can also report the results to AIoTF.
[0149] In step 6, AIoT devices and AIoTF and / or ADM are K AIoT Authentication can also be performed based on the Counter received in step 4. For example, the authentication can be performed as follows: AIoTF and / or ADM receive the Counter received in step 4. AIoT Value K AIoTSend the encrypted or hashed value using and Challenge with it Con can be sent. The AIoT device that receives this can store the K AIoT After performing decryption or hash calculation using the AIoTF and / or ADM, the AIoT device can authenticate. Similarly, the AIoT device can also authenticate the Challenge Con to K AIoT After the encrypted or hashed value is transmitted to the AIoTF and / or ADM, the AIoTF and / or ADM may authenticate the AIoT device. If the ADM performs the authentication, it may also notify the AIoTF of the result.
[0150] In step 7, AIoTF and / or ADM send AIoT ID, received command response, inventory response, Counter Con , or Counter AIoT At least one of them may be transmitted to AF.
[0151] In step 8, AF or AIoTF or ADM selects K or K based on the received AIoT ID. AIoT If the command or all or part of the message was encrypted, AF or AIoTF may find K or K AIoT Decryption can also be performed using AF or AIoTF. AF or AIoTF can also process command response or inventory response.
[0152] In step 9, the AF or AIoTF or ADM or AIoT device may also generate a temporary ID. The AF or AIoTF or ADM or AIoT device may generate the ID of the AIoT device (which may be the entirety or a unique part of the permanent ID or temporary ID), K, K AIoT , RAND AF , Counter Con, or Counter AIoT At least one of the following may be used to generate a Temporary AIoT ID. The AF, AIoTF, ADM, or AIoT device may update the temporary ID of the AIoT device it is storing with the newly generated Temporary AIoT ID. If the AF performs the same process after performing steps 1-9, the newly generated Temporary AIoT ID may be used instead of the AIoT ID used in the process.
[0153] FIG. 6 is a diagram illustrating a process for protecting and authenticating the ID of an AIoT device according to an embodiment of the present disclosure.
[0154] According to Fig. 6, the following conditions may be met:
[0155] - The key (K) and the ID of the AIoT device (AIoT ID) may be shared between the AIoT device and AF.
[0156] - AF is a random value generated by K and AF (RAND AF ) from K AIoT can also be created.
[0157] - The ID of an AIoT device may consist of a common part and a unique part, for example. For example, the common part may be a PLMN ID (which may be assigned to devices using the services of a specific telecommunications operator) or a 3 rd party ID (specific 3 rd It may be composed of (which may be assigned to a device using the party's service), and the non-common part may be a value that can represent a specific AIoT device.
[0158] - AF is a value that is the combination of AIoT ID and COUNT value maintained for the corresponding AIoT device (AIoT ID|COUNT) as K or K AIoTAfter encryption using , COUNT+1 can be stored instead of COUNT value. The common part of AIoT ID may not be encrypted.
[0159] - K and K AIoT may be the same value.
[0160] In step 1, the AF may send an AIoT Service Request message to the Controller / AIoTF. This request may be delivered via the NEF or directly. The AIoT Service Request message includes a command, a protected AIoT ID, and a RAND. AF , or K AIoT May include at least one of:
[0161] In step 2, Controller / AIoTF Counter Con , RAND AF , at least one of a protected AIoT ID, a common part of the AIoT ID, or a command can be sent to the AIoT device. At least one of the above information is K AIoT Wow Counter Con It may be encrypted, integrity protected, or hashed using .
[0162] In step 3, the AIoT device can receive an AIoT Service Request. After receiving the protected AIoT ID, the AIoT device can check whether the common part of the content is identical to the common part of the AIoT ID it owns. If so, the AIoT device can use the received RAND AF Using K that is stored with K AIoT can generate. AIoT devices are K or K AIoT Protected AIoT IDs can be decrypted using the following procedure:
[0163] - AIoT devices are K or K AIoT You can perform decryption using . If the decryption result is your ID|COUNT, you can check whether the COUNT value is an acceptable value (for example, a value that is not significantly different from the saved COUNT value).
[0164] Through the above process, if the AIoT Service Request of step 3 is known to have come to you and the COUNT value is an acceptable value, the AIoT device will K AIoT Wow Counter Con The encrypted portion can be decrypted using the same method as performed by the Controller / AIoTF in step 2, or integrity protection or hash value can be calculated. For example, this can be done as follows:
[0165] - When an encrypted message arrives, the AIoT device sends a K AIoT Decryption can be performed using the decrypted Counter Con Check if the value received in step 2 is the same as the Counter Con You can check if this is an acceptable value (for example, if it is not too different from the current time or the stored COUNT value). If it is an acceptable value, you can prepare to process the command.
[0166] - If a hash or integrity protected value is received, Counter first Con You can check if this is an acceptable value. If it is, the value used for hashing or integrity protection is the same as the Counter Con After calculating the value attached, you can check whether this value is the same as the hash or integrity protection value received in step 2. If so, you can prepare to process the command.
[0167] If the above process is successful, the AIoT device can process the received command. The AIoT device may store the COUNT value by adding 1 to its own stored value.
[0168] In step 4, the AIoT device may send an AIoT Service Response to the Controller / AIoTF. The AIoT Service Response is a Counter generated by the AIoT device. AIoT (which may be a random value, a value based on the current time, or at least one of the COUNT values maintained with the Controller / AIoTF), and may also contain at least one of the protected AIoT ID, command, or MAC values received in step 2. The MAC may be, for example, K AIoT , Counter Con , Counter AIoT , or may be calculated using at least one of the messages. The AIoT device may be K or K AIoT You can also encrypt commands using .
[0169] In step 5, the Controller / AIoTF generates the corresponding K based on the received protected AIoT ID. AIoT can be found. K AIoT , Counter Con , Counter AIoT , or at least one of the messages can be used to calculate the MAC and check if it is the same as the value received in step 4. If the calculation is Counter AIoT If used, the Controller / AIoTF will use the Counter AIoT You can also first check if the value is acceptable (for example, if it is not too different from the current time or if it is not too different from the stored COUNT value) before performing the calculation.
[0170] In step 6, AIoT devices and Controller / AIoTF are K AIoT Authentication can also be performed based on the Counter received in step 5. For example, the authentication can be performed as follows: Controller / AIoTF receives the Counter received in step 5. AIoT Value K AIoT Send the encrypted or hashed value using and Challenge with it Con can also be sent. The AIoT device that receives this can send the K AIoT After performing decryption or hash calculation using the Challenge, the Controller / AIoTF can be authenticated. Similarly, AIoT devices can also authenticate the Challenge Con to K AIoT After sending the encrypted or hashed value to the Controller / AIoTF, the Controller / AIoTF can authenticate the AIoT device.
[0171] In step 7, the Controller / AIoTF may send the AIoT ID and the received command to the AF. If the command was encrypted, the AF may send K or K AIoT Decryption can also be performed using .
[0172] The configuration diagrams, diagrams illustrating control / data signal transmission / reception methods, and diagrams illustrating operational procedures, which may be exemplified by FIGS. 1A to 6, do not limit the scope of the embodiments of the present disclosure. That is, not all components, entities, or operational steps exemplified in FIGS. 1A to 6 should be construed as essential components for implementing the disclosure, and implementations may be made within a scope that does not harm the essence of the disclosure even if only some components are included.
[0173] The operations of the embodiments described above can be realized by providing a memory device storing the corresponding program code in any component within the device. That is, the control unit within the device can execute the operations described above by reading and executing the program code stored in the memory device through a processor or a CPU (Central Processing Unit).
[0174] The various components and modules of the entity or terminal device described in the present disclosure may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software, and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates, and application-specific semiconductors.
[0175] The methods according to the embodiments described in the claims or specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.
[0176] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to the embodiments described in the claims or specification of the present disclosure.
[0177] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage devices, compact disc-ROMs (CD-ROMs), digital versatile discs (DVDs) or other forms of optical storage devices, magnetic cassettes, or may be stored in memories formed by a combination of some or all of these. In addition, each configuration memory may include multiple copies.
[0178] Additionally, the program may be stored on an attachable storage device that is accessible via a communication network, such as the Internet, an intranet, a local area network (LAN), a wide area network (WAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device performing an embodiment of the present disclosure.
[0179] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed in the singular or plural form, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural form may be composed of singular elements, or components expressed in the singular form may be composed of plural elements.
[0180] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
Claims
1. In a method performed by a terminal in a wireless communication system, A step of receiving a first message including a first random value from an AIoTF (Ambient IoT Function) through a base station; A step of obtaining first authentication information using at least one of a first key, a second key, and the first random value; and A method comprising the step of transmitting a second message including at least one of a second random value and the first authentication information to the AIoTF through the base station.
2. A method according to claim 1, wherein the first authentication information is verified based on second authentication information obtained using at least one of the first key, the second key, and the first random value.
3. In paragraph 1, The first message further includes identification information, A step of determining whether the above identification information matches; and If the above identification information matches, it further includes a step of obtaining a temporary ID based on at least one of the AIoT ID, the first random value, the first key, and the second key, The second message further includes the temporary ID, The above AIOT ID is transmitted from AIoTF to AF (Application Function), A method wherein the above identification information includes at least one of a Public Land Mobile Network (PLMN) identifier and a third party identifier.
4. In paragraph 3, A method further comprising the step of stopping the operation if the above identification information does not match.
5. In paragraph 1, The first message further includes a first temporary ID, Further comprising a step of obtaining a second temporary ID based on at least one of the first key, the second key, the AIoT ID, the first random value, and the second random value, A method wherein the second message further includes the second temporary ID.
6. In paragraph 1, The first message further includes a first temporary ID, A step of determining whether the first temporary ID and the ID of the terminal match; A step of obtaining a second temporary ID based on at least one of the first key, the first random value, the first temporary ID, and the permanent ID; and Further comprising the step of storing the second temporary ID, A method wherein the second message further includes the first temporary ID.
7. In paragraph 6, The first message including the AIoT ID is transmitted from the AF to the AIoTF via the Network Exposure Function (NEF), A method wherein the second temporary ID is generated and stored by AIOTF or ADM based on at least one of the first key, the first random value, the first temporary ID, and the permanent ID.
8. A method according to claim 1, wherein the first message includes an inventory request message or a paging request message.
9. In a wireless communication system, the terminal, Transmitter and receiver; At least one processor coupled to be capable of communicating with the transceiver; and comprising a memory coupled to be communicatively connected to at least one processor; The above terminal, Receive a first message including a first random value from the base station through AIoTF (Ambient IoT Function), Obtaining first authentication information using at least one of the first key, the second key, and the first random value, A terminal that transmits a second message including at least one of a second random value and the first authentication information to the AIoTF through the base station.
10. In the 9th paragraph, the first authentication information is verified based on second authentication information obtained using at least one of the first key, the second key, and the first random value.
11. In paragraph 9, The first message further includes identification information, The above terminal, Determine whether the above identification information matches, If the above identification information matches, a temporary ID is obtained based on at least one of the AIoT ID, the first random value, the first key, and the second key, The second message further includes the temporary ID, The above AIOT ID is transmitted from AIoTF to AF (Application Function), The terminal, wherein the above identification information includes at least one of a Public Land Mobile Network (PLMN) identifier and a third party identifier.
12. In paragraph 11, The above terminal, A terminal that stops performing an operation if the above identification information does not match.
13. In paragraph 9, The first message further includes a first temporary ID, The above terminal, Obtain a second temporary ID based on at least one of the first key, the second key, the AIoT ID, the first random value, and the second random value; The terminal, wherein the second message further includes the second temporary ID.
14. In paragraph 9, The first message further includes a first temporary ID, The above terminal, Determine whether the first temporary ID and the terminal ID match, Obtain a second temporary ID based on at least one of the first key, the first random value, the first temporary ID, and the permanent ID, Store the above second temporary ID, The terminal, wherein the second message further includes the first temporary ID.
15. In paragraph 14, The first message including the AIoT ID is transmitted from the AF to the AIoTF via the Network Exposure Function (NEF), A terminal wherein the second temporary ID is generated and stored by AIOTF or ADM based on at least one of the first key, the first random value, the first temporary ID, and the permanent ID.
Citation Information
Patent Citations
System and method for authentication of things
US20170214529A1
METHOD AND SYSTEM FOR SECURE IoT DEVICE ONBOARDING USING A BLOCKCHAIN NETWORK
US20220224518A1