Privacy preserving two-factor biometric authentication system using integrated sensing and communication
The ISAC system in 3GPP networks collects and transforms biometric data for secure, privacy-preserving two-factor authentication, addressing the integration of sensitive biometric information and reducing computational burden on end-devices, thus enhancing security and compliance.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2026-03-26
AI Technical Summary
Existing authentication systems fail to effectively leverage network assets and integrate sensitive biometric information in Integrated Sensing and Communication (ISAC) systems while ensuring privacy and security, particularly in 3GPP networks.
A method and system that utilizes an ISAC system to collect biometric data, transform it using privacy-preserving mechanisms, and compare it with a transformed reference template within or outside the 3GPP network, offloading computationally expensive operations to the ISAC system, thereby enhancing security and reducing the burden on end-devices.
This approach provides secure, privacy-preserving two-factor authentication by leveraging ISAC systems, reducing computational load on end-devices and enhancing security against spoofing and replay attacks, while ensuring compliance with regulatory traceability requirements.
Smart Images

Figure US2024047490_26032026_PF_FP_ABST
Abstract
Description
PRIVACY PRESERVING TWO-FACTOR BIOMETRIC AUTHENTICATION SYSTEM USING INTEGRATED SENSING AND COMMUNICATIONTECHNICAL FIELD
[0001] The present disclosure relates to biometric authentication and, more specifically, biometric authentication using an Integrated Sensing and Communication (ISAC) system (i.e., a Joint Communication and Sensing (JCAS) system).BACKGROUND
[0002] Authentication is a security mechanism used to verify the identities of users, devices, or systems and protect against unauthorized access to systems and sensitive information. A plethora of authentication methods has emerged over the past decade. In S. Stephenson, B. Pal, S. Fan, E. Fernandes, Y. Zhao and R. Chatterjee, "SoK: Authentication in Augmented and Virtual Reality," 2022 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 2022, pp. 267-284, doi: 10.1109 / SP4621210022.9833742, scholars delineated different authentication methods used in Virtual Reality (VR) to safeguard and ensure a trustworthy communication and access to information.
[0003] Integrated Sensing and Communication (ISAC) systems fuse the communication capabilities of telecommunications systems with the ability to sense features of the environment using the same equipment. ISAC is also known as Joint Communication and Sensing (JCAS). The terms ISAC and JCAS are used herein interchangeably.SUMMARY
[0004] Systems and methods are disclosed for biometric authentication using an Integrated Sensing and Communication (ISAC) system. In one embodiment, a method performed by one or more network nodes of a wireless communications system enabled to perform ISAC comprises receiving, from an authentication service, a request to invoke IS AC-based biometric authentication for a subscriber, determining a location of the subscriber within a coverage area of the wireless communications system, and selecting a ISAC system comprising one or more Radio Access Network (RAN) nodes of the wireless communications system, based on the location of the subscriber within the coverage area of the wireless communications system. The method further comprises configuring the ISAC system for collection of biometric data for the subscriber and requesting the ISAC system to collect biometric data for the subscriber. In this manner, ISAC based biometrics authentication using ISAC collected biometric data is enabled.
[0005] In one embodiment, the method further comprises sending, to the ISAC system, a transform parameter for transforming a collected biometric template for the subscriber into a transformed collected biometric template for the subscriber. The method further comprises transforming a reference biometric template for the subscriber into a transformed reference biometric template, using the transform parameter and sending the transformed reference biometric template for the subscriber to a secure enclave of the wireless communications system. The method further comprises receiving an authentication result from the secure enclave of the wireless communications system, the authentication result being based on a comparison of a transformed reference biometric template for the subscriber and a transformed collected biometric template for the subscriber obtained via the ISAC system. In this manner, ISAC based authentication using collected biometric data in a privacy preserving manner is enabled.
[0006] In one embodiment, the method further comprises receiving an authentication result from the secure enclave of the wireless communications system, the authentication result being based on a comparison of a transformed reference biometric template for the subscriber and a transformed collected biometric template for the subscriber obtained via the ISAC system.
[0007] Corresponding embodiments of a system are also disclosed. In one embodiment, a system comprises one or more network nodes of a wireless communications system enabled to perform ISAC, where the one or more network nodes are adapted to receive, from an authentication service, a request to invoke ISAC -based biometric authentication for a subscriber, determine a location of the subscriber within a coverage area of the wireless communications system, and select a ISAC system comprising one or more RAN nodes of the wireless communications system, based on the location of the subscriber within the coverage area of the wireless communications system. The one or more network nodes are further adapted to configure the ISAC system for collection of biometric data for the subscriber and request the ISAC system to collect biometric data for the subscriber.
[0008] Embodiments of a method performed by one or more RAN nodes that form an ISAC system within a wireless communications system are also disclosed. In one embodiment, the method comprises receiving, from a network node of the wireless communications system, information that configures the one or more RAN nodes for collection of biometric data for a subscriber via the ISAC system and receiving, from a network node of the wireless communications system, a request for the ISAC system to collect biometric data for the subscriber. The method further comprises receiving, from a network node of the wireless communications system or an external node, a transform parameter associated to the subscriber. The method further comprises collecting biometric data about the subscriber via the ISAC system, creating a collectedbiometric template for the subscriber based on the collected biometric data, and transforming the collected biometric template for the subscriber into a transformed collected biometric template for the subscriber, using the transform parameter associated to the subscriber. The method further comprises sending the transformed collected biometric template for the subscriber to another node for comparison to a transformed reference biometric template for the subscriber.
[0009] In one embodiment, sending the transformed collected biometric template for the subscriber to another node comprises sending the transformed collected biometric template for the subscriber to a secure enclave of the wireless communications system.
[0010] In one embodiment, sending the transformed collected biometric template for the subscriber to another node comprises sending the transformed collected biometric template for the subscriber to a node that is external to the wireless communications system via a secure communication channel.
[0011] Corresponding embodiments of an ISAC system comprising one or more RAN nodes of a wireless communication system are also disclosed. In one embodiment, an ISAC system comprising one or more RAN nodes of a wireless communications system is adapted to receive, from a network node of the wireless communications system, information that configures the one or more RAN nodes for collection of biometric data for a subscriber via the ISAC system and receive, from a network node of the wireless communications system, a request for the ISAC system to collect biometric data for the subscriber. The ISAC system is further adapted to receive, from a network node of the wireless communications system or an external node, a transform parameter associated to the subscriber. The ISAC system is further adapted to collect biometric data about the subscriber via ISAC, create a collected biometric template for the subscriber based on the collected biometric data, transform the collected biometric template for the subscriber into a transformed collected biometric template for the subscriber, using the transform parameter associated to the subscriber, and send the transformed collected biometric template for the subscriber to another node for comparison to a transformed reference biometric template for the subscriber.
[0012] Embodiments of a method performed by a secure enclave of a wireless communications system are also disclosed. In one embodiment, a method performed by a secure enclave of a wireless communications system comprises receiving a transformed reference biometric template for a subscriber, receiving a transformed collected biometric template for the subscriber from a ISAC system comprising one or more RAN nodes of the wireless communications system, wherein the transformed collected biometric template for the subscriber is based on biometric data collected by the ISAC system about the subscriber. In one embodiment,the method further comprises authenticating the subscriber based on a comparison of the transformed reference biometric template and the transformed collected biometric template and sending a result of the authentication to a network node of the wireless communications system.
[0013] Corresponding embodiments of a secure enclave of a wireless communications system are also disclosed. In one embodiment, a secure enclave of a wireless communications system is adapted to receive a transformed reference biometric template for a subscriber and receive a transformed collected biometric template for the subscriber from a ISAC system comprising one or more RAN nodes of the wireless communications system, wherein the transformed collected biometric template for the subscriber is based on biometric data collected by the ISAC system about the subscriber. The secure enclave is further adapted to authenticate the subscriber based on a comparison of the transformed reference biometric template and the transformed collected biometric template and send a result of the authentication to a network node of the wireless communications system.
[0014] Corresponding embodiments of a computing system that provides the functionality of the secure enclave of the wireless communication system are also disclosed.
[0015] Embodiments of a method performed by an authentication service are also disclosed. In one embodiment, a method performed by an authentication service for second factor authentication of a user (or an associated device) via ISAC based biometric data collection provided by a wireless communications system comprises performing a first factor authentication of a user and sending, to a network node of a wireless communications system, a request to invoke IS AC -based collection of biometric data of the user for second factor authentication. The method further comprises sending a transform parameter associated to the user to an ISAC system of the wireless communications system, the ISAC system comprising one or more RAN nodes of the wireless communications system. The method further comprises generating a transformed reference biometric template for the user using the transform parameter and a reference biometric template for the user. The method further comprises receiving a transformed collected biometric template for the user from the ISAC system of the wireless communications system and authenticating the user based on a comparison of the transformed reference biometric template and the transformed collected biometric template.
[0016] In one embodiment, the method further comprises sending the result of the authentication to a device of the user.
[0017] Corresponding embodiments of a computing system for implementing an authentication service are also disclosed. In one embodiment, a computing system for implementing an authentication service for second factor authentication of a user via ISAC basedbiometric data collection provided by a wireless communications system is adapted to perform a first factor authentication of a user and send, to a network node of a wireless communications system, a request to invoke ISAC-based collection of biometric data of the user for second factor authentication. The computing system is further adapted to send a transform parameter associated to the user to an ISAC system of the wireless communications system, the ISAC system comprising one or more RAN nodes of the wireless communications system. The computing system is further adapted to generate a transformed reference biometric template for the user, using the parameter and a reference biometric template for the user. The computing system is further adapted to receive a transformed collected biometric template for the user from the ISAC system of the wireless communications system and authenticate the user based on a comparison of the transformed reference biometric template and the transformed collected biometric template.BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.
[0019] Figure 1 is an illustration of an authentication procedure and the entities involved in the authentication procedure, in accordance with embodiments of the present disclosure;
[0020] Figures 2A, 2B, 2C, and 2D illustrate the authentication procedure of Figure 1 in more detail, in accordance with embodiments of the present disclosure;
[0021] Figure 3 shows an example of a communication system in accordance with some embodiments of the present disclosure;
[0022] Figure 4 shows a user equipment in accordance with some embodiments of the present disclosure;
[0023] Figure 5 shows a network node in accordance with some embodiments of the present disclosure;
[0024] Figure 6 is a block diagram illustrating a virtualization environment in which functions implemented by some embodiments may be virtualized in accordance with some embodiments of the present disclosure; and
[0025] Figure 7 is a schematic block diagram of an example embodiment of a computing system.DETAILED DESCRIPTION
[0026] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.
[0027] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
[0028] There currently exist certain challenge(s). The problem to be solved is twofold:1. How to leverage network assets and confidential biometric information to authenticate users2. How to integrate sensitive observation and exchange of information into systems designed for Integrated Sensing and Communication (ISAC)
[0029] U.S. Patent Application Publications 2015 / 0341349A1 entitled “Privacy-Preserving Biometric Authentication” (hereinafter referred to as “the ‘349 Application”) and 2021 / 0194874A1 also entitled “Privacy-Preserving Biometric Authentication” (hereinafter referred to as “the ‘874 Application”) address privacy-preserving authentication methods for constructing and transmitting biometric information, but do not establish a network-based protocol for using network capabilities to construct and intelligently verify this information. Each of these U.S. Patent Application Publications can be summarized as follows:
[0030] The ‘349 Application teaches a method that involves receiving a registration input containing a user identifier and a first raw biometric template representing unique user biometric characteristics. A first transformed biometric template is generated by applying random projection to the first raw biometric template. This transformed template, along with the user identifier, is sent to an authentication server. Later, a challenge input with a second raw biometric template and the user identifier is received. A second transformed biometric template is created using random projection on the second raw biometric template. This transformed template and the user identifier are also sent to the authentication server. The authentication decision is then received from the server, based on the approximate matching of the two transformed biometric templates. The privacy guarantee assesses the likelihood of unauthorized access to the raw biometric template if the data exchanged between the user module and the authentication module is compromised. Itdepends on the connection between the transformed biometric templates and the raw biometric templates.
[0031] The ‘874 Application teaches a method for authenticating an individual using biometric data obtained from a first transducer. This method employs computer processes to generate and distribute shards from a digital electronic signal characterizing the subject’s biometric data. These shards are stored on an array of servers, enabling data exchange processes using a subset of the shards to establish authentication information. Privacy measures are integrated, restricting access to sensitive information during computations. The method also encompasses optional encoding techniques, including neural nets and metric space representation. The process involves multiparty computation and shard revocation, facilitating secure authentication without requiring the individual’s re-engagement. Communication-efficient processes are described, such as separate shard processing by servers and the use of message authentication codes. Overall, this method emphasizes robust authentication while prioritizing privacy in the handling of sensitive data and computation.
[0032] The method taught by the ‘874 Application combines multiparty computation (MFC) and biometric shards (Attribute Based Encryption) and confidential computing. This method provides a potential privacy-preserving method to embed within the system disclosed herein, and is therefore complementary embodiments of the solution described herein.
[0033] Certain aspects of the disclosure and their embodiments may provide a solution merging the use of biometric data (i.e., data pertaining to the biological and / or physiological features of a user or set of users) with authentication techniques using ISAC systems.
[0034] Embodiments of the solution disclosed herein address the following technological needs:• Privacy-Preservation: The biometrics should be collected, processed, and transmitted for authentication in a privacy preserving manner. More specifically, due to the sensitivity of biometric information which is used in the biometric authentication system, it is paramount to secure the biometric information from security and privacy threats and utilize privacy preserving methodology in biometric data processing.• Enhanced Security / Two-Factor (2F) Authentication: The authentication of user should be done securely. The authentication system should be secure from spoofing, information leakage and replay attacks. To enhance security of such system, 2F authentication should be used.• Offloading of Computation: The User equipment should not bear the cost of (additional) processing due to additional factor of authentication to enhance the security and privacy ofthe authentication system. In other words, there should be offloading of computation heavy operations to a system commensurate of processing power.
[0035] Embodiments of the present disclosure relate to a wireless communication network supported (e.g., a 3rdGeneration Partnership (3GPP) supported) solution that enables a second factor of authentication for two-factor authentication between a user and an external authentication service based on biometric information captured by a ISAC system. This privacy-preserving solution features a flexible array of implementations, offering three options for biometrics template comparison both inside and outside of the wireless communication network and accommodating a variety of use-cases described in more detail below. Note that a 3 GPP network is used in the following description as a preferred example of the wireless communication network; however, other types of wireless communications systems that support ISAC may be used.
[0036] Embodiments of a method are disclosed that enable an external authentication service to trigger a 3GPP network backed second factor of authentication for a user, configure a ISAC system for capturing biometric features from the user, and enable comparing the captured biometric feature with a stored biometric template in secure and privacy preserving way, either inside or outside of the 3 GPP network.
[0037] Certain embodiments may provide the following technical advantages. Embodiments of the present disclosure provide the use of an ISAC system for collecting biometrics and performing privacy preserving transformation of the biometrics, thereby offloading the privacy preserving mechanisms to ISAC system. The ISAC system can run the secure and computationally expensive operations included in the privacy protection mechanism. Sometimes, the security related operations (e.g., key generation, key length, secure root of trust, target space for nonces, or the like) get undermined due to computational, storage related constraints on end devices. The offloading of this whole process to the ISAC system will lessen the burden on end-devices and motivate more and more devices / users to migrate to systems with offloaded privacy-preserving collection and biometrics processing. Embodiments of the present disclosure may provide security against replay and spoofing attacks by adding another factor to authentication. By combining biometrics (something a user is) with one or more other factors of authentication (something the user has or something the user knows), the proposed system utilizes multi-factor authentication. The first factor of authentication may be, for example, a password or similar factor of authentication whereas the second factor of authentication is a biometric factor(s) collected with the assistance of an ISAC system.
[0038] Figure 1 is an illustration of an authentication procedure and the entities involved in the authentication procedure, in accordance with embodiments of the present disclosure. Asillustrated, the entities involved in the authentication procedure include a prover 100, an authentication service 102, a network 104, an ISAC system 106, and a secure enclave 108 of the network 104 (i.e., of the wireless communications system). The network 104, the ISAC system 106, and the secure enclave 108 of the network 104 are components of a wireless communications system, which in the preferred embodiments described herein is a 3GPP system such as, e.g., a 5thGeneration System (5G) or a 6thGeneration (6G) system.
[0039] The prover 100 is an entity that wants to authenticate itself in order to access an application. In the description of the preferred embodiments provided herein, the pro ver 100 is an end-user who is a subscriber of the 3GPP system, where the end-user is associated to a UE of the wireless communication system and the UE may be equipped with a Subscriber Identity Module (SIM) or the like. The authentication procedure described herein authenticates the end-user (and optionally thus the UE and optionally the SIM) based on biometric data collected by the ISAC system 106. The authentication service 102 is an entity that invokes two-factor (2F) biometric authentication from the 3 GPP system. The authentication service 102 can be a 3rdparty authentication services or a function of the 3GPP system providing user authentication as a service. The authentication service 102 stores or otherwise has access to enrolled information of a user for verification.
[0040] The network 104 refers to a Radio Access Network (RAN) and Core Network (CN) of the 3GPP system. The network 104 includes network nodes such as, e.g., RAN nodes (e.g., base stations, etc.) and core network nodes (e.g., Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), etc., in the case of a 5G system). The network 104 has access to a subscriber’s information. The network 104 can locate a subscriber within a coverage area of the RAN. Also, the enrolled information of a subscriber (i.e., a user) can also be stored in the CN.
[0041] While illustrated separately from the network 104, the ISAC system 106 is a part of the network 104 and typically includes one or more network nodes of the network 104. The RAN node(s) may be, for example, a base station (e.g., a next generation Node B (gNB)). The ISAC system 106 collects information about a user and the user’s environment via ISAC. This information may include, for example, biometric data of the user, soft biometrics of the user, or geo-velocity of the user, which can be used to authenticate the user. The secure enclave 108 of the network 104 refers to secure enclaves in the 3GPP system that can be used to perform privacypreserving operations on biometrics information of a user.
[0042] Further description of the type of data used in embodiments of the present disclosure is beneficial. As an example, the accuracy of various ‘soft’ biometrics of users useful inAugmented Reality (AR) or Virtual Reality (VR) scenario may be used. Examples of these measures are included in the description below.
[0043] As illustrated in Figure 1, the authentication procedure includes the following operations, or sub-processes. In a first operation 110, the prover 100 accesses the authentication service 102 for authentication. In a second operation 112, the authentication service 102 invokes bio-authentication via IS AC of the network 104. In a third operation 114, the network 104 configures the IS AC system 106 to collect biometric data for the user. Lastly, in a fourth operation 116, a secure comparison of a transformed biometric template derived from the collected biometric data for the user via the IS AC system 106 and a transformed reference (known) biometric template of the user is performed to thereby determine whether the prover 100 is successfully authenticated.
[0044] Note that, as used herein, a biometric template (whether it is the reference biometric template or the collected biometric template) is a representation of one or more biometric characteristics of the corresponding biometric data for the entity that needs to be authenticated. For example, a biometric template may be a vector, a set of vectors, a tensor, a set of tensors, a multi-dimensional matrix, or the like, that represents the corresponding biometric data. A transformed biometric template is the result of a transformation of a biometric template. This transformation may be via a defined transform function or transform vector such as, for example, a hash function, a random vector or matrix, or the like, which is applied to the biometric template to generate the transformed biometric template.
[0045] Figures 2A to 2D (collectively referred to herein as Figure 2 or Fig. 2) illustrate the authentication procedure of Figure 1 in more detail, in accordance with embodiments of the present disclosure. Note that the various operations, or sub-processes, of the authentication procedure are denoted by corresponding separators shown in Figure 2. As illustrated in Figure 2, a first factor authentication operation is first performed. This corresponds to operation 110 illustrated in Figure 1. In particular, the prover 100 (e.g., the end-user or device) accesses an application and authenticates with the authentication service 102 according to a first factor authentication procedure (e.g. password, pin, etc.) (step 200). The authentication service 102 sends a request to the prover 100 to request consent for a two-factor authentication (2FA) using IS AC biometric collection (step 202). The prover 100 responds with consent for 2FA using IS AC biometric collection (step 204).
[0046] Next, a 2FA procedure is initiated including initiation of ISAC biometric data collection. This corresponds to operations 112 and 114 of Figure 1. More specifically, the authentication service 102 sends, to the network 104, a request to invoke biometrics-based 2F authentication using ISAC for subscriber P (i.e., the user that corresponds to the prover 100 or theuser of the device that corresponds to the pro ver 100) (step 206). The request may be received by the network 104 via, for example, a network exposure function or the like. The request may indicate one or more specific biometrics for the subscriber P. The requested biometrics may be a subset of biometrics that will be combined with ones captured from the subscriber P or the associated UE, e.g., during an enrollment phase. The network 104 obtains (e.g., looks up) an identifier (ID) (e.g., User Equipment (UE) ID) for the subscriber P (step 208) and locates the IS AC system 106 (e.g., RAN node(s) such as, e.g., base station(s)) in proximity to the subscriber P, based on a known or obtained location of the subscriber P (or the corresponding UE) within the coverage area of the RAN (step 210). The location of the subscriber P (or the associated UE) may be obtained by the network 104 using any type or combination localization technology (e.g., UE- based localization, camera-based localization, subject positions himself / herself in a pre-designated area, or the like). In one example embodiment, the location of the subscriber P can be retrieved by using the procedure described in 3GPP TS 23.273, Figure 6.1.2-1 for location verification functionality. The ISAC system 106 is in proximity to the subscriber P if it is able to perform IS AC in the geographic area in which the subscriber P is located. The network 104 configures the ISAC system 106 and requests the ISAC system 106 to collect the desired biometric data for the subscriber P (step 212). The configuration of the ISAC system 106 may include, for example, configuration of beamforming, antenna tilt, etc. to enable the ISAC system 106 to perform ISAC to collect the desired biometric(s) for the subscriber P. Note that, for frequencies around 100 Gigahertz (GHz) and their typical bandwidths, it is possible to reach resolutions below 1 centimeter (cm). Note that that, in the context of step 212 and other similar steps involving interaction between the network 104 and the ISAC system 106, a network node in the network 104 may interact with (e.g., configure, sending message(s) to, receive message(s) from, etc.) the ISAC system 106, where this network node may be, for example, a core network node. However, other alternatives are possible. For example, the ISAC system 106 may include a base station having a distributed architecture including a central unit (CU) and one or more distributed units (DUs), where in this case the network node in the network 104 that interacts with the ISAC system 106 may a core network node that interacts with the base station by sending and / ore receiving one or more messages to / from the central unit of the base station or, alternatively, the network node 104 that interacts with the ISAC system 106 may be the CU of the base station that interacts with one or more DUs of the base station by sending and / or receiving one or more messages to / from the one or more DUs of the base station.
[0047] Next, a privacy preserving, secure process is used to collect the biometric(s) of the subscriber P and perform the 2F authentication using the collected biometric(s). This processcorresponds to operations 114 and 116 of Figure 1. In general, the IS AC system 106 collects biometrics from the subscriber P and creates a biometric template, which is referred to herein as a collected biometric template. Then, the IS AC system 106 applies one or more privacy preserving mechanisms (e.g., Biohashing, cancellable biometrics, homomorphic encryption-HME, etc.) to transform the collected biometric template into an encrypted or non-reversibly transformed biometric template, which is referred to herein as a transformed collected biometric template, in the IS AC system 106. Note that these privacy preserving mechanisms ensure un-linkability and irreversibility property on the raw biometric template.
[0048] Three options are shown in Figure 2. For Option 1 , a reference biometric template for the subscriber P is stored in the network 104. The network 104 sends a transform parameter (t_id) associated to the subscriber ID, which in the illustrated example is a UE ID (UE_id) of the UE of the subscriber P, to the ISAC system 106 (step 214.1). Note that the network node that sends the transform parameter to the ISAC system 106 may or may not be the same network node that that configured the ISAC system 106 in step 212 above. This applies to all steps involving interactions between the network 104 and the ISAC system 106 (i.e., the same or different network nodes in the network node 104 may be involved in the various interactions with the ISAC system 106 shown in Figures 2A to 2D. The transform parameter may be, for example, a transform vector, an input parameter for a transform function, or the like. The network 104 sends, to the secure enclave 108 of the network 104, a transformed reference biometric template for the subscriber P, which is denoted in Figure 2 as BioT_t_id (step 214.2). The network 104 creates the transformed reference biometric template for the subscriber P by transforming the reference biometric template of the subscriber P using the transform parameter (t_id) (e.g., using the same transform function with the same input parameter or using the same transform vector). In Option 1, the reference biometric template for the subscriber P is stored by the network 104. The reference biometric template for the subscriber P may have been previously obtained (e.g., via ISAC or otherwise) during an enrollment phase.
[0049] The ISAC system 106 captures the IS AC-based biometric data for the subscriber P, creates a collected biometric template (e.g., formulates the collected biometric data into a particular representation such as, e.g., a vector of numerical values, a set of vectors of numerical values, a tensor, a set of tensors, a matrix including numerical values, representing one or more characteristics of the collected biometric data), and transforms the collected biometric template using a same transform parameter (t_id) (e.g., the same transform function using the same input parameter, the same transform vector, or the like) as was used to create the transformed reference biometric template to thereby create a transformed collected biometric template for the subscriberP, which is denoted in Figure 2 as JBioT_t_id (step 214.3). Note that for the collection of the IS AC -based biometric data there is no communication with the subscriber P or the UE of the subscriber P. The collected ISAC -based biometric data may include, for example, one or more biometrics of the subscriber P and / or one or more soft biometrics of the subscriber P, e.g., height of the subscriber P, gait of the subscriber P, body proportions of the subscriber P, and / or geovelocity of the subscriber P, and / or the like.
[0050] The ISAC system 106 sends the transformed collected biometric template to the secure enclave 108 of the network 104 (step 214.4). The secure enclave 108 of the network 104 compares the transformed collected biometric template to the transformed reference biometric template for the subscriber P (step 214.5). If there is a match (e.g., if the two transformed biometric templates match at least to a predefined threshold degree or a hamming distance between the two transformed biometric templates is less than a predefined threshold hamming distance or similar metric), then the 2F authentication of the prover 100 is a success; otherwise, 2F authentication of the prover 100 fails. The secure enclave 108 of the network 104 sends a verification (i.e., authentication) result (e.g., success or fail) to the network 104 (step 214.6), and the network 104 sends the verification result to the authentication service 102 (step 214.7).
[0051] In Option 2, the reference biometric template of the subscriber P is stored at the authentication service 102 and the transformed biometric templates are compared at the secure enclave 108 of the network 104. More specifically, in Option 2, Key agreement happens (or has already happened) between the network 104 and the authentication service 102 (step 214.8). The key agreement may utilize any type of key agreement protocol. The authentication service 102 sends the transform parameter t_id for UE_id to the ISAC system 106 (step 214.9). The authentication service 102 also transforms the reference biometric template for the subscriber P (i.e., corresponding to the UE ID) with transform parameter t id and sends the resulting transformed reference biometric template (BioT_t_id) for the subscriber P to the secure enclave 108 of the network 104 (step 214.10). Note that the authentication service 102 is preferably hosted by an external node (i.e., an external computing system) that is external to the network 104.
[0052] The ISAC system 106 captures the raw biometric data for the subscriber P associated with the UE having the identity UE_id, creates a collected biometric template from the collected biometric data, and transforms the collected biometric template using the transform parameter t_id received from the authentication service 102 (step 214.11). The resulting transformed collected biometric template is referred to as JBioT_t_id. The ISAC system 106 sends the transformed collected biometric template (JBioT_t_id) to the secure enclave 108 (step 214.12).
[0053] The secure enclave 108 of the network 104 compares the transformed collected biometric template to the transformed reference biometric template for the subscriber P (step 214.13). If there is a match (e.g., if the two transformed biometric templates match at least to a predefined threshold degree or a hamming distance between the two transformed biometric templates is less than a predefined threshold hamming distance), then the 2F authentication of the prover 100 is a success; otherwise, 2F authentication of the prover 100 fails. The secure enclave 108 of the network 104 sends a verification (i.e., authentication) result (e.g., success or fail) to the network 104 (step 214.14), and the network 104 sends the verification result to the authentication service 102 (step 214.15).
[0054] In Option 3, the reference biometric template is stored at the authentication service 102 (which is external to the 3GPP system) and the verification also occurs at the authentication service 102. The ISAC system 106 works as bit-pipe in providing the collected biometric data to the authentication service 102. More specifically, key agreement happens (or has previously happened) between the network 104 and the authentication service 102 (step 214.16). Any key agreement protocol may be used. The authentication service 102 sends the transform parameter t_id for UE_id to the ISAC system 106 (step 214.17). The authentication service 102 also transforms the reference biometric template corresponding to UE_id with the transform parameter t_id and saves the resulting transformed reference biometric template (BioT_t_id) or sends it to its own secure enclave (step 214.18).
[0055] The ISAC system 106 captures the raw biometric data for the subscriber with identity UE_id, creates a collected biometric template using the collected biometric data, and transforms the collected biometric template using the transform parameter t_id received from the authentication service 102 (step 214.19). This transformed template is referred to as JBioT_t_id. The ISAC system 106 sends the transformed collected biometric template (JBioT_t_id) to the authentication service 102 (or a secure enclave of the authentication service 102) over the secure channel using the agreed key(s) (step 214.20). The authentication service 102 (or its secure enclave) performs verification by comparing the transformed collected biometric template to the transformed reference biometric template for the subscriber P (step 214.21). If there is a match (e.g., if the two transformed biometric templates match at least to a predefined threshold degree or a hamming distance between the two transformed biometric templates is less than a predefined threshold hamming distance or similar metric), then the 2F authentication of the prover 100 is a success; otherwise, 2F authentication of the prover 100 fails.
[0056] Once authentication has completed, the ISAC system 106 deletes the collected ISAC- based biometric data and any associated information (step 216a). Optionally, the ISAC system106 or the network 104 may store information needed for traceability as defined by existing or future defined regulatory compliance (step 216b).
[0057] The authentication service 102 sends the authentication result (success or fail) to the pro ver 100 (step 218).
[0058] Figure 3 shows an example of a communication system 300 in accordance with some embodiments, in which aspects of the prover 100, authentication service 102, network 104, IS AC system 106, and secure enclave 108 can be applied. The communication system 300 is one example of the network 104 described above. The functionality described herein with respect to the network 104 may be performed by core network node 308, network node 310 in access network 304, or a combination of core network node(s) and / or a combination (access) network nodes (which are also sometimes referred to herein as RAN nodes).
[0059] In the example, the communication system 300 includes a telecommunication network 302 that includes an access network 304, such as a Radio Access Network (RAN), and a core network 306, which includes one or more core network nodes 308. The access network 304 includes one or more access network nodes, such as network nodes 310A and 310B (one or more of which may be generally referred to as network nodes 310), or any other similar Third Generation Partnership Project (3GPP) access nodes or non-3GPP Access Points (APs). Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 302 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 302 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 302, including one or more network nodes 310 and / or core network nodes 308.
[0060] Examples of an ORAN network node include an Open Radio Unit (O-RU), an Open Distributed Unit (O-DU), an Open Central Unit (O-CU), including an O-CU Control Plane (O- CU-CP) or an O-CU User Plane (O-CU-UP), a RAN intelligent controller (near-real time or non- real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such asan Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the O-RAN Alliance or comparable technologies. The network nodes 310 facilitate direct or indirect connection of User Equipment (UE), such as by connecting UEs 312A, 312B, 312C, and 312D (one or more of which may be generally referred to as UEs 312) to the core network 306 over one or more wireless connections.
[0061] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 300 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 300 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.
[0062] The UEs 312 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 310 and other communication devices. Similarly, the network nodes 310 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 312 and / or with other network nodes or equipment in the telecommunication network 302 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 302.
[0063] In the depicted example, the core network 306 connects the network nodes 310 to one or more hosts, such as host 316. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 306 includes one or more core network nodes (e.g., core network node 308) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 308. Example core network nodes include functions of one or more ofa Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-Concealing Function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).
[0064] The host 316 may be under the ownership or control of a service provider other than an operator or provider of the access network 304 and / or the telecommunication network 302 and may be operated by the service provider or on behalf of the service provider. The host 316 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0065] As a whole, the communication system 300 of Figure 3 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system 300 may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable Second, Third, Fourth, or Fifth Generation (2G, 3G, 4G, or 5G) standards, or any applicable future generation standard (e.g., Sixth Generation (6G)); Wireless Local Area Network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any Low Power Wide Area Network (LPWAN) standards such as LoRa and Sigfox.
[0066] In some examples, the telecommunication network 302 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunication network 302 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 302. For example, the telecommunication network 302 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing enhanced Mobile Broadband (eMBB) services to other UEs, and / or massive Machine Type Communication (mMTC) / massive Internet of Things (loT) services to yet further UEs.
[0067] In some examples, the UEs 312 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 304 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 304. Additionally, a UE may be configured for operating in single- or multi-Radio Access Technology (RAT) or multi-standard mode. For example, a UE may operate with any one or combination of WiFi, New Radio (NR), and LTE, i.e. being configured for Multi-Radio Dual Connectivity (MR-DC), such as Evolved UMTS Terrestrial RAN (E-UTRAN) NR - Dual Connectivity (EN-DC).
[0068] In the example, a hub 314 communicates with the access network 304 to facilitate indirect communication between one or more UEs (e.g., UE 312C and / or 312D) and network nodes (e.g., network node 310B). In some examples, the hub 314 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 314 may be a broadband router enabling access to the core network 306 for the UEs. As another example, the hub 314 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 310, or by executable code, script, process, or other instructions in the hub 314. As another example, the hub 314 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 314 may be a content source. For example, for a UE that is a Virtual Reality (VR) headset, display, loudspeaker or other media delivery device, the hub 314 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 314 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 314 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.
[0069] The hub 314 may have a constant / persistent or intermittent connection to the network node 310B. The hub 314 may also allow for a different communication scheme and / or schedule between the hub 314 and UEs (e.g., UE 312C and / or 312D), and between the hub 314 and the core network 306. In other examples, the hub 314 is connected to the core network 306 and / or one or more UEs via a wired connection. Moreover, the hub 314 may be configured to connect to a Machine-to-Machine (M2M) service provider over the access network 304 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 310 while still connected via the hub 314 via a wired or wireless connection. In some embodiments, the hub 314 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 310B. In otherembodiments, the hub 314 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and the network node 310B, but which is additionally capable of operating as a communication start and / or end point for certain data channels.
[0070] Figure 4 shows a UE 400 in accordance with some embodiments, which may provide for the UE 312 and the prover 100. As used herein, a UE refers to a device capable, configured, arranged, and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, Voice over Internet Protocol (VoIP) phone, wireless local loop phone, desktop computer, Personal Digital Assistant (PDA), wireless camera, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, Laptop Embedded Equipment (LEE), Laptop Mounted Equipment (LME), smart device, wireless Customer Premise Equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3GPP, including a Narrowband Internet of Things (NB-loT) UE, a Machine Type Communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.
[0071] A UE 400 may support Device-to-Device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), Vehicle-to-Vehicle (V2V), Vehicle-to-Infrastructure (V2I), or Vehicle- to-Everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).
[0072] The UE 400 includes processing circuitry 402 that is operatively coupled via a bus 404 to an input / output interface 406, a power source 408, memory 410, a communication interface 412, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 4. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0073] The processing circuitry 402 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored asmachine-readable computer programs in the memory 410. The processing circuitry 402 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general purpose processors, such as a microprocessor or Digital Signal Processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 402 may include multiple Central Processing Units (CPUs).
[0074] In the example, the input / output interface 406 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 400. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.
[0075] In some embodiments, the power source 408 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 408 may further include power circuitry for delivering power from the power source 408 itself, and / or an external power source, to the various parts of the UE 400 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 408. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 408 to make the power suitable for the respective components of the UE 400 to which power is supplied.
[0076] The memory 410 may be or be configured to include memory such as Random Access Memory (RAM), Read Only Memory (ROM), Programmable ROM (PROM), Erasable PROM (EPROM), Electrically EPROM (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 410 includes one or more application programs 414, such as an operating system, web browser application, a widget, gadgetengine, or other application, and corresponding data 416. The memory 410 may store, for use by the UE 400, any of a variety of various operating systems or combinations of operating systems.
[0077] The memory 410 may be configured to include a number of physical drive units, such as Redundant Array of Independent Disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, High Density Digital Versatile Disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, Holographic Digital Data Storage (HDDS) optical disc drive, external mini Dual In-line Memory Module (DIMM), Synchronous Dynamic RAM (SDRAM), external micro-DIMM SDRAM, smartcard memory such as a tamper resistant module in the form of a Universal Integrated Circuit Card (UICC) including one or more Subscriber Identity Modules (SIMs), such as a Universal SIM (USIM) and / or Internet Protocol Multimedia Services Identity Module (ISIM), other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as a ‘SIM card.’ The memory 410 may allow the UE 400 to access instructions, application programs, and the like stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system, may be tangibly embodied as or in the memory 410, which may be or comprise a device-readable storage medium.
[0078] The processing circuitry 402 may be configured to communicate with an access network or other network using the communication interface 412. The communication interface 412 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 422. The communication interface 412 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 418 and / or a receiver 420 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 418 and receiver 420 may be coupled to one or more antennas (e.g., the antenna 422) and may share circuit components, software, or firmware, or alternatively be implemented separately.
[0079] In the illustrated embodiment, communication functions of the communication interface 412 may include cellular communication, WiFi communication, LPWAN communication, data communication, voice communication, multimedia communication, short- range communications such as Bluetooth, NFC, location-based communication such as the use of the Global Positioning System (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented according to one ormore communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband CDMA (WCDMA), GSM, LTE, NR, UMTS, WiMax, Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP), Synchronous Optical Networking (SONET), Asynchronous Transfer Mode (ATM), Quick User Datagram Protocol Internet Connection (QUIC), Hypertext Transfer Protocol (HTTP), and so forth.
[0080] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 412, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected, an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).
[0081] As another example, a UE comprises an actuator, a motor, or a switch related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.
[0082] A UE, when in the form of an loT device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application, and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a television, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or VR, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE 400 shown in Figure 4.
[0083] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship, an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0084] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator and handle communication of data for both the speed sensor and the actuators.
[0085] Figure 5 shows a network node 500 in accordance with some embodiments, such as may provide aspects of the network 104. Other embodiments may provide aspects implementations of the authentication service 102, the ISAC system 106, and / or the secure enclave 108. As used herein, network node refers to equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment in a telecommunication network. Examples of network nodes include, but are not limited to, APs (e.g., radio APs), Base Stations (BSs) (e.g., radio BSs, Node Bs, evolved Node Bs (eNBs), NR Node Bs (gNBs)), and O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).
[0086] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node), and / or Remote Radio Units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such RRUs may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a Distributed Antenna System (DAS).
[0087] Other examples of network nodes include multiple Transmission Point (multi-TRP) 5G access nodes, Multi-Standard Radio (MSR) equipment such as MSR BSs, network controllers such as Radio Network Controllers (RNCs) or BS Controllers (BSCs), Base Transceiver Stations (BTSs), transmission points, transmission nodes, Multi-Cell / Multicast Coordination Entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).
[0088] The network node 500 includes processing circuitry 502, memory 504, a communication interface 506, and a power source 508. The network node 500 may be composed of multiple physically separate components (e.g., a NodeB component and an RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 500 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair may in some instances be considered a single separate network node. In some embodiments, the network node 500 may be configured to support multiple RATs. In such embodiments, some components may be duplicated (e.g., separate memory 504 for different RATs) and some components may be reused (e.g., a same antenna 510 may be shared by different RATs). The network node 500 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 500, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, Long Range Wide Area Network (LoRaWAN), Radio Frequency Identification (RFID), or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within the network node 500.
[0089] The processing circuitry 502 may comprise a combination of one or more of a microprocessor, controller, microcontroller, CPU, DSP, ASIC, FPGA, or any other suitable computing device, resource, or combination of hardware, software, and / or encoded logic operable to provide, either alone or in conjunction with other network node 500 components, such as the memory 504, to provide network node 500 functionality.
[0090] In some embodiments, the processing circuitry 502 includes a System on a Chip (SOC). In some embodiments, the processing circuitry 502 includes one or more of Radio Frequency (RF) transceiver circuitry 512 and baseband processing circuitry 514. In some embodiments, the RF transceiver circuitry 512 and the baseband processing circuitry 514 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. Inalternative embodiments, part or all of the RF transceiver circuitry 512 and the baseband processing circuitry 514 may be on the same chip or set of chips, boards, or units.
[0091] The memory 504 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid state memory, remotely mounted memory, magnetic media, optical media, RAM, ROM, mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD), or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable, and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 502. The memory 504 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 502 and utilized by the network node 500. The memory 504 may be used to store any calculations made by the processing circuitry 502 and / or any data received via the communication interface 506. In some embodiments, the processing circuitry 502 and the memory 504 are integrated.
[0092] The communication interface 506 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 506 comprises port(s) / terminal(s) 516 to send and receive data, for example to and from a network over a wired connection. The communication interface 506 also includes radio front-end circuitry 518 that may be coupled to, or in certain embodiments a part of, the antenna 510. The radio front-end circuitry 518 comprises filters 520 and amplifiers 522. The radio front-end circuitry 518 may be connected to the antenna 510 and the processing circuitry 502. The radio front-end circuitry 518 may be configured to condition signals communicated between the antenna 510 and the processing circuitry 502. The radio front-end circuitry 518 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 518 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of the filters 520 and / or the amplifiers 522. The radio signal may then be transmitted via the antenna 510. Similarly, when receiving data, the antenna 510 may collect radio signals which are then converted into digital data by the radio front-end circuitry 518. The digital data may be passed to the processing circuitry 502. In other embodiments, the communication interface 506 may comprise different components and / or different combinations of components.
[0093] In certain alternative embodiments, the network node 500 does not include separate radio front-end circuitry 518; instead, the processing circuitry 502 includes radio front-endcircuitry and is connected to the antenna 510. Similarly, in some embodiments, all or some of the RF transceiver circuitry 512 is part of the communication interface 506. In still other embodiments, the communication interface 506 includes the one or more ports or terminals 516, the radio front-end circuitry 518, and the RF transceiver circuitry 512 as part of a radio unit (not shown), and the communication interface 506 communicates with the baseband processing circuitry 514, which is part of a digital unit (not shown).
[0094] The antenna 510 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 510 may be coupled to the radio front-end circuitry 518 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 510 is separate from the network node 500 and connectable to the network node 500 through an interface or port.
[0095] The antenna 510, the communication interface 506, and / or the processing circuitry 502 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node 500. Any information, data, and / or signals may be received from a UE, another network node, and / or any other network equipment. Similarly, the antenna 510, the communication interface 506, and / or the processing circuitry 502 may be configured to perform any transmitting operations described herein as being performed by the network node 500. Any information, data, and / or signals may be transmitted to a UE, another network node, and / or any other network equipment.
[0096] The power source 508 provides power to the various components of the network node 500 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 508 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 500 with power for performing the functionality described herein. For example, the network node 500 may be connectable to an external power source (e.g., the power grid or an electricity outlet) via input circuitry or an interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 508. As a further example, the power source 508 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.
[0097] Embodiments of the network node 500 may include additional components beyond those shown in Figure 5 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 500 may include user interfaceequipment to allow input of information into the network node 500 and to allow output of information from the network node 500. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 500. In some embodiments providing a core network node, such as core network node 108 of FIG. 3, some components, such as the radio front-end circuitry 518 and the RF transceiver circuitry 512 may be omitted.
[0098] Figure 6 is a block diagram illustrating a virtualization environment 600 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices, and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more Virtual Machines (VMs) implemented in one or more virtualization environments 600 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, a UE, a core network node, or a host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 600 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface. Virtualization may facilitate distributed implementations of a network node, a UE, a core network node, or a host.
[0099] Applications 602 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 600 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.
[0100] Hardware 604 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, an input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 606 (also referred to as hypervisors or Virtual Machine Monitors (VMMs)), provide VMs 608A and 608B (one or more of which may be generally referred to as VMs 608), and / or perform any of the functions, features, and / or benefits described in relation with some embodiments described herein.The virtualization layer 606 may present a virtual operating platform that appears like networking hardware to the VMs 608.
[0101] The VMs 608 comprise virtual processing, virtual memory, virtual networking, or interface and virtual storage, and may be run by a corresponding virtualization layer 606. Different embodiments of the instance of a virtual appliance 602 may be implemented on one or more of VMs 608, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as Network Function Virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers and customer premise equipment.
[0102] In the context of NFV, a VM 608 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 608, and that part of the hardware 604 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 608 on top of the hardware 604 and corresponds to the application 602.
[0103] The hardware 604 may be implemented in a standalone network node with generic or specific components. The hardware 604 may implement some functions via virtualization. Alternatively, the hardware 604 may be part of a larger cluster of hardware (e.g., such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 610, which, among others, oversees lifecycle management of the applications 602. In some embodiments, the hardware 604 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 612 which may alternatively be used for communication between hardware nodes and radio units.
[0104] Figure 7 is a schematic block diagram of a computing system 700 according to some embodiments of the present disclosure and may provide further details of the host 316 of Figure 3. The computing system 700 may be, for example, a computing system that implements the functionality of the secure enclave 108 described herein or a computing system that implements the functionality of the authentication service 102 described herein. As illustrated, the computingsystem 700 includes one or more processors 702 (e.g., CPUs, ASICs, FPGAs, DSPs, and / or the like), memory 704, and a network interface 706. The one or more processors 304 are also referred to herein as processing circuitry. The one or more processors 702 operate to provide one or more functions of the computing system 700 as described herein (e.g., one or more functions of the secure enclave 108 or one or more functions of the authentication service 102, as described herein). In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 704 and executed by the one or more processors 702.
[0105] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the computing system 700 or a node implementing one or more of the functions of the computing system 700 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0106] Although the computing devices described herein (e.g., UEs, network nodes) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions, and methods disclosed herein. Determining, calculating, obtaining, or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.
[0107] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
[0108] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.
[0109] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).
[0110] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.
Claims
CLAIMS1. A method performed by one or more network nodes (104) of a wireless communications system enabled to perform Integrated Sensing and Communication, ISAC, the method comprising: receiving (206), from an authentication service (102), a request to invoke IS AC -based biometric authentication for a subscriber; determining (208) a location of the subscriber within a coverage area of the wireless communications system; selecting (210) a ISAC system (106) comprising one or more Radio Access Network, RAN, nodes of the wireless communications system, based on the location of the subscriber within the coverage area of the wireless communications system; configuring (212) the ISAC system (106) for collection of biometric data for the subscriber; and requesting (212) the ISAC system (106) to collect biometric data for the subscriber.
2. The method of claim 1 , further comprising: sending (214.1), to the ISAC system (106), a transform parameter for transforming a collected biometric template for the subscriber into a transformed collected biometric template for the subscriber; transforming (214.2) a reference biometric template for the subscriber into a transformed reference biometric template, using the transform parameter; sending (214.2) the transformed reference biometric template for the subscriber to a secure enclave (108) of the wireless communications system; and receiving (214.6) an authentication result from the secure enclave (108) of the wireless communications system, the authentication result being based on a comparison of a transformed reference biometric template for the subscriber and a transformed collected biometric template for the subscriber obtained via the ISAC system (106).
3. The method of claim 1 , further comprising receiving (214. 14) an authentication result from the secure enclave (108) of the wireless communications system, the authentication result being based on a comparison of a transformed reference biometric template for the subscriber and a transformed collected biometric template for the subscriber obtained via the ISAC system (106).
4. A system comprising one or more network nodes (104) of a wireless communications system enabled to perform Integrated Sensing and Communication, ISAC, the one or morenetwork nodes adapted / configured to: receive (206), from an authentication service (102), a request to invoke ISAC -based biometric authentication for a subscriber; determine (208) a location of the subscriber within a coverage area of the wireless communications system; select (210) a ISAC system (106) comprising one or more Radio Access Network, RAN, nodes of the wireless communications system, based on the location of the subscriber within the coverage area of the wireless communications system; configure (212) the ISAC system (106) for collection of biometric data for the subscriber; and request (212) the ISAC system (106) to collect biometric data for the subscriber.
5. The system of claim 4, wherein the one or more network nodes are further adapted to perform the method of any of claims 2 to 3.
6. A method performed by one or more Radio Access Network, RAN, nodes that form an Integrated Sensing and Communication, ISAC, system (106) within a wireless communications system, the method comprising: receiving (212), from a network node (104) of the wireless communications system, information that configures the one or more RAN nodes for collection of biometric data for a subscriber via ISAC; receiving (212), from a network node (104) of the wireless communications system, a request for the ISAC system (106) to collect biometric data for the subscriber; receiving (214.1 ; 214.9; 214.17), from a network node (104) of the wireless communications system or an external node (102), a transform parameter associated to the subscriber; collecting (214.3; 214.11; 214.19) biometric data about the subscriber via ISAC; creating (214.3; 214. 11 ; 214. 19) a collected biometric template for the subscriber based on the collected biometric data; transforming (214.3; 214.11; 214.19) the collected biometric template for the subscriber into a transformed collected biometric template for the subscriber, using the transform parameter associated to the subscriber; and sending (214.4; 214.12; 214.20) the transformed collected biometric template for the subscriber to another node for comparison to a transformed reference biometric template for thesubscriber.
7. The method of claim 6, wherein sending (214.4; 214.12) the transformed collected biometric template for the subscriber to another node comprises sending (214.4; 214.12) the transformed collected biometric template for the subscriber to a secure enclave of the wireless communications system.
8. The method of claim 6, sending (214.20) the transformed collected biometric template for the subscriber to another node comprises sending (214.20) the transformed collected biometric template for the subscriber to a node that is external to the wireless communications system via a secure communication channel.
9. An Integrated Communication and Sensing, ISAC, system (106) comprising one or more Radio Access Network, RAN, nodes of a wireless communications system, the ISAC system (106) adapted / configured to: receive (212), from a network node (104) of the wireless communications system, information that configures the one or more RAN nodes for collection of biometric data for a subscriber via ISAC; receive (212), from a network node (104) of the wireless communications system, a request for the ISAC system (106) to collect biometric data for the subscriber; receive (214.1; 214.9; 214.17), from a network node of the wireless communications system or an external node, a transform parameter associated to the subscriber; collect (214.3; 214.11; 214.19) biometric data about the subscriber via ISAC; create (214.3; 214.11; 214.19) a collected biometric template for the subscriber based on the collected biometric data; transform (214.3; 214.11 ; 214.19) the collected biometric template for the subscriber into a transformed collected biometric template for the subscriber, using the transform parameter associated to the subscriber; and send (214.4; 214.12; 214.20) the transformed collected biometric template for the subscriber to another node for comparison to a transformed reference biometric template for the subscriber.
10. The ISAC system of claim 9, further adapted to perform the method of any of claims 7 to8.
11. A method performed by a secure enclave (108) of a wireless communications system, the method comprising: receiving (214.2; 214.10) a transformed reference biometric template for a subscriber; receiving (214.4; 214.12) a transformed collected biometric template for the subscriber from an Integrated Sensing and Communication, IS AC, system (106) comprising one or more Radio Access Network, RAN, nodes of the wireless communications system, the transformed collected biometric template for the subscriber being based on biometric data collected by the ISAC system (106) about the subscriber; authenticating (214.5; 214.13) the subscriber based on a comparison of the transformed reference biometric template and the transformed collected biometric template; and sending (214.6; 214.14) a result of the authentication to a network node (104) of the wireless communications system.
12. A secure enclave (108) of a wireless communications system, the secure enclave (108) adapted to: receive (214.2; 214.10) a transformed reference biometric template for a subscriber; receive (214.4; 214.12) a transformed collected biometric template for the subscriber from an Integrated Sensing and Communication, ISAC, system (106) comprising one or more Radio Access Network, RAN, nodes of the wireless communications system, the transformed collected biometric template for the subscriber being based on biometric data collected by the ISAC system (106) about the subscriber; authenticate (214.5; 214.13) the subscriber based on a comparison of the transformed reference biometric template and the transformed collected biometric template; and send (214.6; 214.14) a result of the authentication to a network node (104) of the wireless communications system.
13. A method performed by an authentication service (102) for second factor authentication of a user via Integrated Sensing and Communication, ISAC, based biometric data collection provided by a wireless communications system, the method comprising: performing (200) a first factor authentication of a user; sending (206), to a network node (104) of a wireless communications system, a request to invoke ISAC-based collection of biometric data of the user for second factor authentication; sending (214.17) a transform parameter associated to the user to a ISAC system (106) ofthe wireless communications system, the IS AC system (106) comprising one or more Radio Access Network, RAN, nodes of the wireless communications system; generating (214.18) a transformed reference biometric template for the user, using the transform parameter and a reference biometric template for the user; receiving (214.20) a transformed collected biometric template for the user from the ISAC system (106) of the wireless communications system; and authenticating (214.21 ) the user based on a comparison of the transformed reference biometric template and the transformed collected biometric template.
14. The method of claim 13, further comprising sending (218) a result of the authenticating to a device of the user.
15. A computing system for an authentication service (102) for second factor authentication of a user via Integrated Sensing and Communication, ISAC, based biometric data collection provided by a wireless communications system, the computing system adapted to: perform (200) a first factor authentication of a user; send (206), to a network node (104) of a wireless communications system, a request to invoke ISAC-based collection of biometric data of the user for second factor authentication; send (214.17) a transform parameter associated to the user to a ISAC system (106) of the wireless communications system, the ISAC system (106) comprising one or more Radio Access Network, RAN, nodes of the wireless communications system; generate (214.18) a transformed reference biometric template for the user, using the parameter and a reference biometric template for the user; receive (214.20) a transformed collected biometric template for the user from the ISAC system (106) of the wireless communications system; and authenticate (214.21) the user based on a comparison of the transformed reference biometric template and the transformed collected biometric template.
Citation Information
Patent Citations
Privacy-preserving biometric authentication
US20150341349A1
Technologies for end-to-end biometric-based authentication and platform locality assertion
US20170104597A1
Facial recognition tokenization
US20220029987A1
Biometric authenticated biometric enrollment
US20240187223A1
Wireless sensing and communication system with matching function for improved interoperability
WO2024094745A1