Devices and methods for security mechanism management
The communication method for Ambient IoT devices negotiates and manages security capabilities, providing secure network access by determining appropriate security levels, overcoming the limitations of existing subscription models for low-complexity devices.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2026-04-02
AI Technical Summary
Ambient IoT devices, powered by ambient energy sources, require efficient and secure communication mechanisms to manage their security capabilities and operations, as existing subscription models are not suitable for these low-complexity, power-efficient devices.
A communication method involving multiple communication devices that negotiate and manage security capabilities and operations through request-response signaling to determine and authorize the security levels of Ambient IoT devices, allowing them to access the network securely.
Enables secure and efficient negotiation of security mechanisms for Ambient IoT devices, ensuring appropriate security levels are met during network access, addressing the limitations of existing subscription models.
Smart Images

Figure CN2024121250_02042026_PF_FP_ABST
Abstract
Description
DEVICES AND METHODS FOR SECURITY MECHANISM MANAGEMENTFIELD
[0001] Example embodiments of the present disclosure generally relate to the field of communication techniques and in particular, to devices and methods for security mechanism management.BACKGROUND
[0002] The Ambient Internet of Things (IoT) refers to a new class of IoT devices primarily powered by harvesting ambient energy from radio waves, light, motion, heat, or any other viable ambient energy source. The Ambient IoT (AIoT) is an extension of the existing IoT. Ambient IoT devices carry out many of the same functions as IoT devices and target many of the same use cases but require additional design choices to meet solution demands. By relying on energy harvested from ambient sources, the Ambient IoT makes it possible to develop lower-cost, smaller, and maintenance-free devices, allowing the IoT to become more scalable in existing use cases and in use cases still to be developed. Harvesting energy from ambient sources generates only minimal amounts of power. This creates the inherent requirement for Ambient IoT devices to be less complex and more power efficient.SUMMARY
[0003] In a first aspect, there is provided a first communication device comprising: a processor configured to cause the first communication device to: transmit, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an AIoT operation; and receive, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0004] In a second aspect, there is provided a second communication device comprising: a processor configured to cause the second communication device to: in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an AIoT operation, transmit, to a third communication device, a second request indicating the first security capability of the first communication device; and in response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0005] In a third aspect, there is provided a third communication device comprising: a processor configured to cause the third communication device to: in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an AIoT operation, transmit, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device; and in response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0006] In a fourth aspect, there is provided a fourth communication device comprising: a processor configured to cause the fourth communication device to: receive, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an AIoT operation, the security level being associated with a first security capability of the first communication device; and transmit, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0007] In a fifth aspect, there is provided a fifth communication device comprising: a processor configured to cause the fifth communication device to: receive, from a third communication device, a fourth request for subscription information of a first communication device; and transmit, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an AIoT operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device.
[0008] In a sixth aspect, there is provided a sixth communication device comprising: a processor configured to cause the sixth communication device to: transmit, to a seventh communication device, a sixth request for a security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0009] In a seventh aspect, there is provided a seventh communication device comprising: a processor configured to cause the seventh communication device to: receive, from a sixth communication device, a sixth request for security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device; and transmit, to the eighth communication device, a seventh request for the security mechanism switching.
[0010] In an eighth aspect, there is provided an eighth communication device comprising: a processor configured to cause the eighth communication device to: receive, from a seventh communication device, a seventh request for a security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in the eighth communication device; and transmit, to the seventh communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device.
[0011] In a ninth aspect, there is provided a ninth communication device comprising: a processor configured to cause the ninth communication device to: receive, from a sixth communication device, a report comprising an indication of a security operation status of an eighth communication device, wherein the security operation status is updated in response to a security mechanism switching associated with an AIoT operation.
[0012] In a tenth aspect, there is provided a tenth communication device comprising: a processor configured to cause the tenth communication device to: transmit, to a sixth communication device, information for a security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0013] In an eleventh aspect, there is provided a communication method performed by a first communication device. The method comprises: transmitting, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an AIoT operation; and receiving, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0014] In a twelfth aspect, there is provided a communication method performed by a second communication device. The method comprises: in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an AIoT operation, transmitting, to a third communication device, a second request indicating the first security capability of the first communication device; and in response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmitting, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0015] In a thirteenth aspect, there is provided a communication method performed by a third communication device. The method comprises: in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an AIoT operation, transmitting, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device; and in response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmitting, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0016] In a fourteenth aspect, there is provided a communication method performed by a fourth communication device. The method comprises: receiving, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an AIoT operation, the security level being associated with a first security capability of the first communication device; and transmitting, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0017] In a fifteenth aspect, there is provided a communication method performed by a fifth communication device. The method comprises: receiving, from a third communication device, a fourth request for subscription information of a first communication device; and transmitting, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an AIoT operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device.
[0018] In a sixteenth aspect, there is provided a communication method performed by a sixth communication device. The method comprises: transmitting, to a seventh communication device, a sixth request for a security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0019] In a seventeenth aspect, there is provided a communication method performed by a seventh communication device. The method comprises: receiving, from a sixth communication device, a sixth request for security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device; and transmitting, to the eighth communication device, a seventh request for the security mechanism switching.
[0020] In an eighteenth aspect, there is provided a communication method performed by an eighth communication device. The method comprises: receiving, from a seventh communication device, a seventh request for a security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in the eighth communication device; and transmitting, to the seventh communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device.
[0021] In a nineteenth aspect, there is provided a communication method performed by a ninth communication device. The method comprises: receiving, from a sixth communication device, a report comprising an indication of a security operation status of an eighth communication device, wherein the security operation status is updated in response to a security mechanism switching associated with an AIoT operation.
[0022] In a twentieth aspect, there is provided a communication method performed by a tenth communication device. The method comprises: transmitting, to a sixth communication device, information for a security mechanism switching associated with an AIoT operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0023] In a twenty-first aspect, there is provided a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to carry out the method according to the eleventh, twelfth, thirteenth, fourteenth, fifteenth, sixteenth, seventeenth, eighteenth, nineteenth, or twentieth aspect.
[0024] Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Through the more detailed description of some example embodiments of the present disclosure in the accompanying drawings, the above and other objects, features and advantages of the present disclosure will become more apparent, wherein:
[0026] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0027] FIG. 2A illustrates an example connectivity topology of an AIoT device;
[0028] FIG. 2B illustrates another example connectivity topology of an AIoT device;
[0029] FIG. 3 illustrates a signaling flow of a process of security mechanism management in accordance with some embodiments of the present disclosure;
[0030] FIG. 4 illustrates a signaling flow of an example process of security mechanism management in accordance with some embodiments of the present disclosure;
[0031] FIG. 5 illustrates a signaling flow of a process of security mechanism management in accordance with some embodiments of the present disclosure;
[0032] FIG. 6 illustrates a signaling flow of an example process of security mechanism management in accordance with some embodiments of the present disclosure;
[0033] FIG. 7 illustrates a signaling flow of an example process of security mechanism management in accordance with some embodiments of the present disclosure;
[0034] FIG. 8 illustrates a signaling flow of an example process of security mechanism management in accordance with some embodiments of the present disclosure;
[0035] FIG. 9 illustrates a signaling flow of an example process of security mechanism management in accordance with some embodiments of the present disclosure;
[0036] FIG. 10 illustrates a signaling flow of an example process of security mechanism management in accordance with some embodiments of the present disclosure;
[0037] FIG. 11 illustrates a flowchart of a method implemented at a first communication device according to some example embodiments of the present disclosure;
[0038] FIG. 12 illustrates a flowchart of a method implemented at a second communication device according to some example embodiments of the present disclosure;
[0039] FIG. 13 illustrates a flowchart of a method implemented at a third communication device according to some example embodiments of the present disclosure;
[0040] FIG. 14 illustrates a flowchart of a method implemented at a fourth communication device according to some example embodiments of the present disclosure;
[0041] FIG. 15 illustrates a flowchart of a method implemented at a fifth communication device according to some example embodiments of the present disclosure;
[0042] FIG. 16 illustrates a flowchart of a method implemented at a sixth communication device according to some example embodiments of the present disclosure;
[0043] FIG. 17 illustrates a flowchart of a method implemented at a seventh communication device according to some example embodiments of the present disclosure;
[0044] FIG. 18 illustrates a flowchart of a method implemented at an eighth communication device according to some example embodiments of the present disclosure;
[0045] FIG. 19 illustrates a flowchart of a method implemented at a ninth communication device according to some example embodiments of the present disclosure;
[0046] FIG. 20 illustrates a flowchart of a method implemented at a tenth communication device according to some example embodiments of the present disclosure; and
[0047] FIG. 21 illustrates a simplified block diagram of an apparatus that is suitable for implementing example embodiments of the present disclosure.
[0048] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0049] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0050] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0051] As used herein, the term ‘terminal device’ refers to any device having wireless or wired communication capabilities. Examples of the terminal device include, but not limited to, user equipment (UE) , personal computers, desktops, mobile phones, cellular phones, smart phones, personal digital assistants (PDAs) , portable computers, tablets, wearable devices, internet of things (IoT) devices, Ultra-reliable and Low Latency Communications (URLLC) devices, Internet of Everything (IoE) devices, machine type communication (MTC) devices, devices on vehicle for V2X communication where X means pedestrian, vehicle, or infrastructure / network, devices for Integrated Access and Backhaul (IAB) , Space borne vehicles or Air borne vehicles in Non-terrestrial networks (NTN) including Satellites and High Altitude Platforms (HAPs) encompassing Unmanned Aircraft Systems (UAS) , eXtended Reality (XR) devices including different types of realities such as Augmented Reality (AR) , Mixed Reality (MR) and Virtual Reality (VR) , the unmanned aerial vehicle (UAV) commonly known as a drone which is an aircraft without any human pilot, devices on high speed train (HST) , or image capture devices such as digital cameras, sensors, gaming devices, music storage and playback appliances, or Internet appliances enabling wireless or wired Internet access and browsing and the like. The ‘terminal device’ can further has ‘multicast / broadcast’ feature, to support public safety and mission critical, V2X applications, transparent IPv4 / IPv6 multicast delivery, IPTV, smart TV, radio services, software delivery over wireless, group communications and IoT applications. It may also incorporate one or multiple Subscriber Identity Module (SIM) as known as Multi-SIM. The term “terminal device” can be used interchangeably with a UE, a mobile station, a subscriber station, a mobile terminal, a user terminal or a wireless device.
[0052] The term “network device” refers to a device which is capable of providing or hosting a cell or coverage where terminal devices can communicate. Examples of a network device include, but not limited to, a Node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a next generation NodeB (gNB) , a transmission reception point (TRP) , a remote radio unit (RRU) , a radio head (RH) , a remote radio head (RRH) , an IAB node, a low power node such as a femto node, a pico node, a reconfigurable intelligent surface (RIS) , and the like.
[0053] The terminal device or the network device may have Artificial intelligence (AI) or Machine learning capability. It generally includes a model which has been trained from numerous collected data for a specific function, and may be used to predict some information.
[0054] The terminal or the network device may work on several frequency ranges, e.g., FR1 (e.g., 450 MHz to 6000 MHz) , FR2 (e.g., 24.25GHz to 52.6GHz) , frequency band larger than 100 GHz as well as Tera Hertz (THz) . It can further work on licensed / unlicensed / shared spectrum. The terminal device may have more than one connection with the network devices under Multi-Radio Dual Connectivity (MR-DC) application scenario. The terminal device or the network device can work on full duplex, flexible duplex and cross division duplex modes.
[0055] The embodiments of the present disclosure may be performed in test equipment, e.g., signal generator, signal analyzer, spectrum analyzer, network analyzer, test terminal device, test network device, channel emulator. In some embodiments, the terminal device may be connected with a first network device and a second network device. One of the first network device and the second network device may be a master node and the other one may be a secondary node. The first network device and the second network device may use different radio access technologies (RATs) . In some embodiments, the first network device may be a first RAT device and the second network device may be a second RAT device. In some embodiments, the first RAT device is eNB and the second RAT device is gNB. Information related with different RATs may be transmitted to the terminal device from at least one of the first network device or the second network device. In some embodiments, first information may be transmitted to the terminal device from the first network device and second information may be transmitted to the terminal device from the second network device directly or via the first network device. In some embodiments, information related with configuration for the terminal device configured by the second network device may be transmitted from the second network device via the first network device. Information related with reconfiguration for the terminal device configured by the second network device may be transmitted to the terminal device from the second network device directly or via the first network device.
[0056] As used herein, the singular forms ‘a’ , ‘an’ and ‘the’ are intended to include the plural forms as well, unless the context clearly indicates otherwise. The term ‘includes’ and its variants are to be read as open terms that mean ‘includes, but is not limited to. ’ The term ‘based on’is to be read as ‘at least in part based on. ’ The term ‘one embodiment’ and ‘an embodiment’ are to be read as ‘at least one embodiment. ’ The term ‘another embodiment’ is to be read as ‘at least one other embodiment. ’ The terms ‘first, ’ ‘second, ’ and the like may refer to different or same objects. Other definitions, explicit and implicit, may be included below.
[0057] In some examples, values, procedures, or apparatus are referred to as ‘best, ’ ‘lowest, ’ ‘highest, ’ ‘minimum, ’ ‘maximum, ’ or the like. It will be appreciated that such descriptions are intended to indicate that a selection among many used functional alternatives can be made, and such selections need not be better, smaller, higher, or otherwise preferable to other selections.
[0058] As used herein, the term “resource, ” “transmission resource, ” “uplink resource, ” or “downlink resource” may refer to any resource for performing a communication, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0059] Principles and implementations of the present disclosure will be described in detail below with reference to the figures.
[0060] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. As shown in the example architecture 100 of FIG. 1, there are a plurality of devices including an AIoT controller 110, a device implementing an Application Function (AF) 120 (also referred to as AF 120 for purpose of discussion) , a device implementing an AIoT device management function 130 (also referred to as AIoT device management function 130 or AIoT device management 130 for purpose of discussion) , an AIoT reader 140, and an AIoT device 150.
[0061] The AIoT controller 110 may be a core network entity that enables AIoT scenarios. It may be a network function implemented in the core netwrok. In some embodiments, the AIoT controller 110 may be implemented at an existing core network entity or as a part of an existing netwrok function. Alternatively, it may be implemented as a new network function. It is to be understood that the above are discussed for purpose of illustration, rather than suggesting any limitations.
[0062] The AIoT controller 110 may work alongside core network functions, such as Application Function (AF) 120, AIoT device management function 130, AIoT reader 140 and / or the like.
[0063] The Application Function (AF) 120 may be a network service provider. For example, the AF 120 may be a functional device immediate response to changing conditions or requirements, such as adjusting irrigation schedules based on real time data.
[0064] The AIoT device management function 130 may be a combination of devices and functionalities implemented within the AIoT system for overseeing and controlling AIoT devices. For example, the AIoT device management function 130 may be a security enhancement module or an efficiency improvement module of a AIoT system.
[0065] The AIoT reader 140 may be a device that reads and interprets data gathered from the AIoT device 150. The AIoT reader 140 may extract meaningful information from the vast amount of data produced by the ambient environment, making it useful for various applications.
[0066] The AIoT device 150 may refer to an IoT device which is much smaller and cheaper compared to previous generations of IoT. The ultimate ambient IoT energy source is that from radio waves. Both Ambient IoT and Ambient computing rely upon energy harvesting as one of the key mechanisms for powering and enabling the technology. Energy harvesting, as it applies to Ambient IoT and Ambient Computing, is the harnessing of the power in ambient radio waves to power tiny computers. An ambient IoT device may have a new radio / air interface to a reader / node. The new radio interface may be frame based or non-frame based. Deploying ambient IoT service on existing system could reduce the operation cost and quickly commercialize the new service.
[0067] It is to be understood that the number of devices and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of devices configured to implementing example embodiments of the present disclosure. Although not shown, it would be appreciated that one or more additional devices may be located in the communication environment 100.
[0068] The communications in the communication environment 100 may conform to any suitable standards including, but not limited to, Global System for Mobile Communications (GSM) , Long Term Evolution (LTE) , LTE-Evolution, LTE-Advanced (LTE-A) , New Radio (NR) , Wideband Code Division Multiple Access (WCDMA) , Code Division Multiple Access (CDMA) , GSM EDGE Radio Access Network (GERAN) , Machine Type Communication (MTC) and the like. The embodiments of the present disclosure may be performed according to any generation communication protocols either currently known or to be developed in the future. Examples of the communication protocols include, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the fifth generation (5G) communication protocols, 5.5G, 5G-Advanced networks, or the sixth generation (6G) networks.
[0069] FIG. 2A illustrates a schematic diagram of an example connectivity topology of an AIoT device. In the communication environment 200A, a plurality of communication devices, including an AIoT device 150 and a network device 170, can communicate with each other. The AIoT device 150 may be the AIoT device 150 discussed with reference to FIG. 1.
[0070] In the example of FIG. 2A, the ambient IoT device 150 communicates bidirectionally with the network device 120. In the communication environment 100A, the network device 170 may be a base station. For example, the network device 170 may be outdoor, and the ambient IoT device 150 may be indoor.
[0071] The network device 170 may be a NG-RAN device. As used herein, the term "RAN" refers to a radio access network, a critical component of wireless communication systems such as LTE and 5G. The RAN connects devices, such as smartphones and IoT devices, to the core network, facilitating the transmission of data and control signals. “NG-RAN” , also known as the next generation RAN, is an important part of the 5G network architecture. In some embodiments of the present disclosure, the netwrok device 170 is sometimes referred to as a NG-RAN device.
[0072] FIG. 2B illustrates a schematic diagram of another example connectivity topology of an AIoT device. In the communication environment 200B, a plurality of communication devices, including the AIoT device 150 discussed with reference to FIG. 1, a network device 170 and an intermediate node 160, can communicate with each other.
[0073] In the example of FIG. 2B, the AIoT device 150 communicates bidirectionally with an intermediate node 160 between the ambient IoT device 150 and the network device 170. In the communication environment 200B, the network device 170 may be a base station serving an intermediate node 160. The intermediate node 160 may be a UE, a relay, an IAB node, a repeater, and the like which is capable of Ambient IoT. The intermediate node 160 may transfer Ambient IoT data and / or signaling between the ambient IoT device 150 and the network device 170, and a UE may act as an intermediate node 160 which is under the control of the network device 170. For example, the network device 170 may be outdoor, and the ambient IoT device 150 may be indoor.
[0074] It is to be understood that although illustrated as a network device, the network device 170 may be another device than a network device. Although illustrated as a terminal device, the intermediate node 160 may be a device other than a terminal device.
[0075] It is to be understood that the number of devices and their connections shown in FIG. 2A or 2B are only for the purpose of illustration without suggesting any limitation. The communication environment 200A or 200B may include any suitable number of devices configured to implementing example embodiments of the present disclosure. Although not shown, it would be appreciated that one or more additional devices may be located in the cell, and one or more additional cells may be deployed in the communication environment 200A or 200B.
[0076] In the following, for the purpose of illustration, some example embodiments are described with the intermediate node 160 operating as a UE which may be authorized to be an intermediate node, and the network device 170 operating as a base station. However, in some example embodiments, operations described in connection with a terminal device may be implemented at a network device or other device, and operations described in connection with a network device may be implemented at a terminal device or other device.
[0077] In some example embodiments, the AIoT device 150 may be a terminal device (e.g., UE) and the network device 170 may be a base station (e.g., gNB) . In this case, a link from the network device 170 to the AIoT device 150 may be referred to as a downlink (DL) , while a link from the AIoT device 150 to the network device 170 may be referred to as an uplink (UL) . In DL, the network device 170 is a transmitting (TX) device (or a transmitter) and the AIoT device 150 is a receiving (RX) device (or a receiver) . In UL, the AIoT device 150 is a TX device (or a transmitter) and the network device 170 is a RX device (or a receiver) .
[0078] As discussed above, key issues related to a system architecture supporting AIoT devices may focus on the following aspects:
[0079] ● -System architecture identified along with other solutions;
[0080] ● -Authentication and authorization for an AIoT device;
[0081] ● -Validation of an AIoT device identifier;
[0082] ● -Whether and how to secure device operations and services for an AIoT device or a group of AIoT devices.
[0083] Regarding identification, subscription, registration and connection management, some issues pertain to authorization and management of Ambient IoT Devices to support Ambient IoT services.
[0084] Considering that Ambient IoT Devices are a new type of reduced capabilities devices, the existing subscription model may not be suitable. Specifically, there is the need to study the device identification method to support Ambient IoT devices which are under operator control.
[0085] Based on the above consideration, the aspects to be studied in this key issue include:
[0086] - Study whether subscription management, registration management and / or connection management are necessary for an Ambient IoT Device or a group of Ambient IoT Devices, and if so, then identify the necessary state machine (s) , procedures and functionality considering the Ambient IoT Devices capability and characteristics.
[0087] - Study whether and how reachability and paging apply to Ambient IoT Device (s) considering the Ambient IoT devices capability and characteristics, and if so, what are the impacts.
[0088] - Study how to identify Ambient IoT Device or group of devices and how to format the identifier.
[0089] To solve the above and other potential issues, embodiments of the present disclosure propose solutions for security mechanism management. In particular, embodiments of the present disclosure provide solutions related to how to negotiate AIoT security between the AIoT device and the network when the AIoT device accesses the network.
[0090] In this way, for some use cases, e.g. a closed and controllable environment in a warehouse, the security / privacy requirement can be compromised and be acceptable, for example, to the network / operator / 3rd party, the AIoT devices (especially Type 2 device) with security capabilities can access to the network with the no security mechanism based on the negotiation between the network and the AIoT device.
[0091] More details will be discussed below. Reference is made to FIG. 3, which illustrates a signaling flow 300 of a process of security mechanism management in accordance with some embodiments of the present disclosure. As shown in FIG. 3, the signaling flow 300 involves a first communication device 301, a second communication device 302, a third communication device 303, a fourth communication device 304 and a fifth communication device 305.
[0092] By referring to the embodiments of FIG. 1, the first communication device 301 may be implemented as the AIoT device 150. The second communication device 302 may be implemented as the AIoT reader 140. The third communication device 303 may be implemented as the AIoT controller 110, which may be a core network device for example. The fourth communication device 304 may be implemented as the AF 120. Ther fifth communication device 305 may be implemented as the AIoT device management function 130, which may be a management function in the core network.
[0093] In the signaling flow 300, the first communication device 301 transmits (310) a first request to the second communication device 302. The fist request may indicate a first security capability of the first communication device 301 with respect to an AIoT operation. The AIoT operation may be an operation that is related to an inventory procedure, a command procedure, and / or other AIoT-related procedure.
[0094] In some embodiments, the first security capability may indicate one or more security levels supported by the first communication device. That is, the first security capability may be associated with one or more security levels. The security level indicates a level of security at which the AIoT operation is allowed to be performed. For example, a first security level may indicate that the AIoT operation may be performed with no security. Alternatively, a second security level may indicate that the AIoT operation may be performed with security. As a further alternatively, a further security level may indicate that the AIoT operation may be performed with a certain degree or level of security.
[0095] In some embodiments, the one or more security levels may include a first security level indicating that the first communication device supports a no-security AIoT operation, a second security level indicating that the first communication device supports a security AIoT operation, and / or the like. It is to be understood that there may be various security levels indicating different security degrees for performing the AIoT operation, which does not suggest any limitation to the present disclosure.
[0096] Optionally, in some example embodiments, before transmitting (310) the first security capability, the first communication device 301 may receive, from the second communication device 302, information about a second security capability of the second communication device 302 with respect to the AIoT operation. Then, the first communication device 301 may transmit (310) the first security capability to the second communication device 302. The first security capability is associated with the same security level as the second security capability. That is, the security level indicated by the first security capability may be the same as the security level indicated by the second security capability.
[0097] For example, in some cases where the second communication device 302 transmits the second security capability indicating that a no-security AIoT operation is supported, the first communication device 301 may know that the no-security AIoT operation is supported by the second communication device 302 and if the first communication device 301 also supports the no-security AIoT operation, it may transmit the first security capability indicates the same.
[0098] Alternatively, or in addition, in some cases where the second communication device 302 transmits the second security capability indicating that a security AIoT operation is supported, the first communication device 301 may know that the security AIoT operation is supported by the second communication device 302 and if the first communication device 301 also supports the security AIoT operation, it may transmit the first security capability indicates the same.
[0099] In some example embodiments, the information about the security capability of the second communication device may be received via a broadcasting signal. For example, the broadcasting signal may be an AIoT paging signal, a system information block (SIB) , or other situatable broadcasting signal (s) .
[0100] The second communication device 302, in response to receiving (312) the first request from the first communication device 301, transmits (314) , to a third communication device 303, a second request indicating the first security capability of the first communication device.
[0101] In some embodiments, upon receiving (316) the second request, the third communication device 303 may obtain subscription information of the first communication device, and transmit the third request to the fourth communication device 304 based on the subscription information. The third request may indicate that a security level associated with the first security capability is request for the first communication device 301.
[0102] In some embodiments, the third request may include, for example, but not limited to, an indication indicating the security level is requested, location information indicating an area in which the security level is requested, and / or reader information indicating at least one reader connecting to the first communication device.
[0103] For example, the third communication device 303 may transmit (318) , to the fifth communication device 305, a fourth request for subscription information of the first communication device. The fifth communication device 305 receives (320) the fourth request from the third communication device 303, and then transmits (322) a fourth response comprising the subscription information to the third communication device 303.
[0104] The subscription information may indicate a security level at which an ambient internet of things (AIoT) operation is allowed to be performed by the first communication device. In some embodiments, the subscription information may include, alone or in combination, for example, an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, reader information indicating at least one reader connecting to the first communication device, and / or information about a fourth communication device for authorization.
[0105] Accordingly, the third communication device 303 may receive (324) the fourth response from the fifth communication device 305, and thus have the knowledge of the subscription information.
[0106] After receiving (324) the subscription information, or just after receiving (316) the second request from the second communication device 302, The third communication device 303 transmits (326) , to the fourth communication device 304, the third request indicating that a security level associated with the first security capability is request for the first communication device.
[0107] The fourth communication device 304, upon receiving (328) the third request from the third communication device 303, may determine whether the AIoT operation is allowed to be performed by the first communication device 301. If yes, the fourth communication device 304 transmits (330) , to the third communication device 303, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0108] In some embodiments, the third response may include, for example, but not limited to, an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, and / or reader information indicating at least one reader connecting to the first communication device.
[0109] In some example embodiments, the security level is, for example, a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response may include an indication indicating that the AIoT operation is allowed to be performed without security. Alternatively, or in addition, if the security level is a second security level indicating that the first communication device supports a security AIoT operation, the third response may include an indication indicating that the AIoT operation is allowed to be performed with security.
[0110] In response to receiving (332) the third response from the fourth communication device 304, the third communication device transmits (334) , to the second communication device 302, a second response to the second request. The second response may indicate the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0111] In some example embodiments, the security level is, for example, a first security level indicating that the first communication device supports a no-security AIoT operation, and the second response may include an indication indicating that the AIoT operation is allowed to be performed without security. Alternatively, or in addition, if the security level is a second security level indicating that the first communication device supports a security AIoT operation, the second response may include an indication indicating that the AIoT operation is allowed to be performed with security.
[0112] The second communication device 302 receives (336) the second response from the third communication device 303, and thus know the security level at which the AIoT operation is allowed to be performed by the first communication device. In response, the second communication device 302 transmits (338) , to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0113] The first communication device 301 receives (340) the first response from the second communication device 302.
[0114] In some example embodiments, the security level is, for example, a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response may include an indication indicating that the AIoT operation is allowed to be performed without security. Alternatively, or in addition, if the security level is a second security level indicating that the first communication device supports a security AIoT operation, the first response may include an indication indicating that the AIoT operation is allowed to be performed with security.
[0115] In this way, the AIoT security may be negotiated between the AIoT device and the network when the AIoT device accesses the network.
[0116] FIG. 4 illustrates a signaling flow 400 of an example process of security mechanism management in accordance with some embodiments of the present disclosure. For purpose of discussion, the embodiments of FIG. 4 will be discussed with respect to FIG. 1. As shown in FIG. 4, the signaling flow 400 involves the AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, and the AIoT device 150.
[0117] The AIoT controller 110 may be considered as an implementation of the third communication device 303 of FIG. 3. The AF 120 may be considered as an implementation of the fourth communication device 304 of FIG. 3. The AIoT device management function 130 may be considered as an implementation of the fifth communication device 305 of FIG. 3. The AIoT reader 140 may be considered as an implementation of the second communication device 302 of FIG. 3. The AIoT device 150 may be considered as an implementation of the first communication device 301 of FIG. 3.
[0118] In the embodiments of FIG. 4, AIoT security operation negotiation is, for example, carried out during an AIoT device registration procedure. Specifically, the AIoT reader 140, also referred to as a reader or a RAN reader, may broadcast its capability to the AIoT device 150 with supporting no security AIoT operation. The AIoT device 150 may report its security capability of supporting no security AIoT operation to the AIoT controller 110. The AIoT controller 110 may retrieve the device subscription from AIoT device management function 130 of “allowed no security AIoT operation” in certain area and / or connecting to certain reader (s) .
[0119] The AIoT controller 110 may request the authorization from the AF 120 for no security AIoT operation of the AIoT device 150. Then, the AIoT controller 110 may authorize the no security AIoT operation, and send the result to the AIoT device 150.
[0120] It is to be understood that, the AIoT Controller 110 may be named in other ways, for example, named as an AIoT Function or an AIoT Management Function. The AIoT device Management function may be collocated with User Data Management (UDM) , for example.
[0121] More details of the signaling flow 400 of FIG. 4 will be discussed below. At 410, the, the reader 140 may send the network capability to the AIoT device 150 with supporting no security AIoT operation indication, which can be in an AIoT paging, a system information block, e.g., SIB1, or other broadcast message. For example, the network capability may be included in a message named “network capability notification (Supporting No security operation indication) ” . In the following discussion, the network capability may be transmitted at 410 via the SIB1 for example. It is to be understood, this step may be optional and suggest no limitations to embodiments of the present disclosure.
[0122] The AIoT device 150 may receive the SIB1 and know a cell related to the reader 140 supporting no security AIoT operation. At 411, the AIoT device 150 may send a registration request to the reader 140, which may include the AIoT device 150’s identification (ID) and its security capability of supporting no security AIoT operation. In some embodiments, at 411, the AIoT device 150 may send the registration request in the form of “registration request (Device ID, No security operation capability indication) ” .
[0123] At 412, the reader 140 may send a registration request to the AIoT controller 110, which may include the AIoT device 150’s ID and its security capability of supporting no security AIoT operation. In some embodiments, at 412, the registration request may be in the form of “Registration Request (Device ID, No security operation capability indication) ” .
[0124] At 413, the AIoT controller 110 may send a device subscription request to the AIoT device 150 management, which includes the device ID received at 412. In some embodiments, at 413, the device subscription request may be in the form of “Device Subscription Request (Device ID) ” .
[0125] At 414, the AIoT device management function 130 may send the device subscription to the AIoT controller 110 which includes ‘No security AIoT operation allowed indication’ in certain area (e.g., location information) and / or connecting to certain reader (s) (e.g., reader ID (s) ) , and the AF 120 information (e.g. the AF 120 IP address) . In some embodiments, at 414, the AIoT device management function 130 may send a “Device Subscription Response (Device ID, No security operation allowed indication, AF information) ” .
[0126] At 415, the AIoT controller 110 may send a device operation request to the AF 120, which includes Device ID and Request No security operation indication to request no security operation for the device, additionally it can include Device Location and / or Reader ID to indicate the device location and connecting reader (s) . In some embodiments, at 415, the AIoT controller 110 may send a “Device operation Request(Device ID, Reader ID, Device Location, Request No security operation indication) ” .
[0127] At 416, the AF 120 may send a device operation response to the AIoT controller 110, which may include a device ID, and a no security operation allowed indication. Additionally, it may include the device location (s) , that is, the location of the AIoT device 150 and a connecting reader list for the AIoT device 150, and where and which the AIoT device 150 connecting the No security operation is allowed. The connecting reader list may indicate a list of readers connected to the AIoT device 150. In some embodiments, at 415, the AIoT controller 110 may send a “Device operation Response (Device ID, No security operation allowed indication) ” .
[0128] At 417, the AIoT controller 110 may authorize the No security operation for the device, and sends a registration response to the reader 140, which includes the device ID and No security operation indication. If the reader 140 does not interpret the content of registration response (e.g. Non-Access Stratum (NAS) ) , an additional No security operation indication can also be sent in the same message (e.g. NG-AP) to the reader 140 which convey the NAS Registration Response. The reader 140 will operate without security for the AIoT device 150, e.g. inventory. In some embodiments, at 417, the AIoT controller 110 may send a “Registration Response (Device ID, No security operation indication) ” to the reader 140.
[0129] At 418, the reader 140 may send a registration response to the AIoT device 150, which includes No security operation indication. The AIoT device 150 will operate without security for the following operation, e.g., inventory. The following security operation status switch shall be secured between the AIoT device 150 and the AIoT controller 110, e.g. by NAS security mechanism. In some embodiments, at 418, the reader 140 may send a “Registration Response (No security operation indication) ” to the AIoT device 150.
[0130] In this way, an AIoT security operation negotiation is conducted during an AIoT device registration procedure. It is to be understood that the AIoT device registration procedure is just illustrated for purpose of discussion, embodiments of the present disclosure are also applicable for other procedures involving negotiation of AIoT security operations.
[0131] Reference is made to FIG. 5, which illustrates a signaling flow 500 of a process of security mechanism management in accordance with some embodiments of the present disclosure. As shown in FIG. 5, the signaling flow 500 involves a sixth communication device 501, a seventh communication device 502, an eighth communication device 503, a ninth communication device 504 and a tenth communication device 505.
[0132] By referring to the embodiments of FIG. 1, the sixth communication device 501 may be implemented as the AIoT controller 110. The seventh communication device 502 may be implemented as the AIoT reader 140. The eighth communication device 503 may be implemented as the AIoT device 150. The ninth communication device 504 may be implemented as the AF 120. The tenth communication device 505 may be implemented as the AIoT device management function 130.
[0133] In the signaling flow 500, the sixth communication device 501 transmits (510) , to the seventh communication device 502, a sixth request for a security mechanism switching associated with an AIoT operation. The security mechanism switching may be switching on or switching off a security mechanism in the eighth communication device 503. The AIoT operation may be an operation that is related to an inventory procedure, a command procedure, and / or other AIoT-related procedure.
[0134] The sixth request may be transmitted based on a determination made by the sixth communication device, or may be triggered by at least one of: the seventh communication device 502, the eighth communication device 503, the ninth communication device 504, or the tenth communication device 505.
[0135] In some embodiments, the ninth communication device 504 transmits, to the sixth communication device, information for the security mechanism switching, which may be considered as a trigger for the security mechanism switching. The sixth communication device 501 may, in response to receiving information for the security mechanism switching from the ninth communication device 504, transmit (510) the sixth request to the seventh communication device 502. In some implementations, the information may be included in an AIoT operation request.
[0136] In some embodiments, the tenth communication device 505 transmits, to the sixth communication device 501, information for the security mechanism switching, which may be considered as a trigger for the security mechanism switching. The sixth communication device 501 may, in response to receiving the information for the security mechanism switching from the tenth communication device 505, transmit (510) the sixth request to the seventh communication device 502. In this case, the information may be included in a subscription change notification related to the eighth communication device 503.
[0137] In some embodiments, the tenth communication device 505 may receive, from the sixth communication device 501, an acknowledgement to the information.
[0138] In some embodiments, either the seventh communication device 502 or the eighth communication device 503 may transmit to the sixth communication device 501, a trigger for the security mechanism switching. The sixth communication device 501 may, in response to receiving a trigger for the security mechanism switching from the seventh communication device 502 or from the eighth communication device 503, transmit (510) the sixth request to the seventh communication device 502. In this case, the trigger may include at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0139] In some embodiments, the sixth communication device 501 may transmit an acknowledgement to the trigger to the seventh communication device 502 or the eighth communication device 503.
[0140] The sixth request may indicate switching on or switching off the security mechanism in the eighth communication device 503. In some embodiments, the sixth request may include a cause for the security mechanism switching.
[0141] The seventh communication device 502, upon receiving (512) the sixth request from the sixth communication device 501, transmits (514) , to the eighth communication device 503, a seventh request for the security mechanism switching. In some embodiments, the seventh request may include the cause for the security mechanism switching.
[0142] The eighth communication device 503 receives (516) , from a seventh communication device, a seventh request for the security mechanism switching associated with an AIoT operation. Thus, the eighth communication device 503 may know whether the security mechanism in the eighth communication device 503 is to be switched on or switched off. Then, the eighth communication device 503 may perform the switching accordingly and thus may update its security operation status accordingly.
[0143] The eighth communication device 503 then transmits (518) , to the seventh communication device 502, a seventh response to the seventh request. The seventh response may include an indication of a security operation status of the eighth communication device.
[0144] The seventh communication device 502 receives (520) , from the eighth communication device 503, the seventh response to the seventh request. Thus, the seventh communication device 502 may have information about the security operation status of the eighth communication device 503. Then, the seventh communication device 502 may transmit (522) , to the sixth communication device 501, a sixth response to the sixth request. The sixth response may include information indicating the security operation status of the eighth communication device.
[0145] The sixth communication device 501 may receive (524) , from the seventh communication device 502, the sixth response to the sixth request and may then transmit (526) , to a ninth communication device 504, a report including at least one of an indication indicating the security operation status of the eighth communication device, or a cause for the security mechanism switching.
[0146] The ninth communication device 504, upon receiving (528) the report from the sixth communication device 501, may transmit an acknowledgement to the report to the sixth communication device 501.
[0147] In view of the above, the AIoT security operation status can be switched in flexible ways. The security operation status switch may be initiated by an AF, an AIoT device management function, by an AIoT Controller, by an AIoT RAN Reader, by an AIoT device and / or other suitable devices / nodes.
[0148] It is to be understood that although the embodiments of the present disclosure are discussed with respect to switching on / off the security mechanism of operations in an inventory procedure, which is discussed just illustrated for purpose of discussion. Embodiments of the present disclosure are also applicable to a command procedure or other suitable procedures.
[0149] FIG. 6 illustrates a signaling flow 600 of an example process of security mechanism management in accordance with some embodiments of the present disclosure. For purpose of discussion, the embodiments of FIG. 6 will be discussed with respect to FIG. 1. As shown in FIG. 6, the signaling flow 600 involves the AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, and the AIoT device 150.
[0150] The AIoT controller 110 may be considered as an implementation of the sixth communication device 501 of FIG. 5. The AF 120 may be considered as an implementation of the ninth communication device 504 of FIG. 5. The AIoT device management function 130 may be considered as an implementation of the tenth communication device 505 of FIG. 5. The AIoT reader 140 may be considered as an implementation of the seventh communication device 502 of FIG. 5. The AIoT device 150 may be considered as an implementation of the eighth communication device 501 of FIG. 5.
[0151] Embodiments of FIG. 6 are related to AIoT security operation status switch initiated by the AF 120. Based on a requirement from a 3rd party or application, the AF 120 may initiate switching of the security operation status of the AIoT device 150 from no security to having security, or from having security to no security, i.e. switch on or off the security in the AIoT device 150 (also referred to as “the device” for discussion) . The security operation status switch may be secured between the AIoT device 150 and the AIoT controller 110, e.g. by NAS security mechanism.
[0152] In the signaling flow 600, at 611, the AF 120 may send an AIoT Operation Request (Device ID, switch on or switch off security in the device) to the AIoT controller 110 to request switch on or switch off the security mechanism in the AIoT device 150.
[0153] At 612, the AIoT controller 110 may send an AIoT Operation Request to the reader 140, which includes Device ID, switch on or switch off security in the device, and NAS message (Device configuration update) to the AIoT device. The “Device configuration update” may be secured by a NAS security mechanism between the AIoT controller 110 and the AIoT device 150. For example, the AIoT Operation Request sent at 612 may be in the form of “AIoT Operation Request (Device ID, switch on or switch off security in the device, NAS (Device configuration update) ) ” .
[0154] At 613, the reader 140 may send the NAS message, e.g., in the form of “Device configuration update (switch on or switch off security in the device) ” to the AIoT device 150. The reader 140 may switch on or switch off the following AIoT operation, e.g., inventory for the AIoT device 150 as requested at 612.
[0155] At 614, the AIoT device150 may update its security configuration as requested in Device configuration update to switch on or switch off security. The AIoT device sends a Device configuration update response to the reader 140 with Security operation status indication to indicate the security operation status with no security or having security. For example, the Device configuration update response (Security operation status indication) may be sent at 614 from the AIoT device150 to the reader 140.
[0156] At 615, the reader 140 may send an AIoT Operation Response (Device ID, Device configuration update response) to the AIoT controller 110. The Device configuration update response may be a NAS message which is received at 614.
[0157] At 616, the AIoT controller 110 may send an AIoT Operation Response (Device ID, Security operation status indication) to the AF 120, which indicates the AIoT device security operation status with no security or having security.
[0158] FIG. 7 illustrates a signaling flow 700 of an example process of security mechanism management in accordance with some embodiments of the present disclosure. For purpose of discussion, the embodiments of FIG. 7 will be discussed with respect to FIG. 1. As shown in FIG. 7, the signaling flow 700 involves the AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, and the AIoT device 150.
[0159] The AIoT controller 110 may be considered as an implementation of the sixth communication device 501 of FIG. 5. The AF 120 may be considered as an implementation of the ninth communication device 504 of FIG. 5. The AIoT device management function 130 may be considered as an implementation of the tenth communication device 505 of FIG. 5. The AIoT reader 140 may be considered as an implementation of the seventh communication device 502 of FIG. 5. The AIoT device 150 may be considered as an implementation of the eighth communication device 501 of FIG. 5.
[0160] Embodiments of FIG. 7 are related to AIoT security operation status switch initiated by AIoT device management function 130. In this case, the AIoT device subscription in the AIoT device management 130 may be changed for switch on or switch off security in the device.
[0161] In the signaling flow 700, at 710, the AIoT device management function 130 may send an AIoT device subscription change notification (Device ID, switch on or switch off security in the device) to the AIoT controller 110.
[0162] At 711, the AIoT controller 110 may send an AIoT device subscription change notification Response (e.g., AIoT device subscription change notification Response (Device ID) ) to the AIoT device management function 130 to ack receiving the notification.
[0163] Steps 712 to 715 are similar as the step 612 to 615. In particular, at 712, the AIoT controller 110 may send an AIoT Operation Request to the reader 140, which includes Device ID, switch on or switch off security in the device, and NAS message (Device configuration update) to the AIoT device. The “Device configuration update” may be secured by a NAS security mechanism between the AIoT controller 110 and the AIoT device 150. For example, the AIoT Operation Request sent at 612 may be in the form of “AIoT Operation Request (Device ID, switch on or switch off security in the device, NAS (Device configuration update) ) ” .
[0164] At 713, the reader 140 may send the NAS message, e.g., in the form of “Device configuration update (switch on or switch off security in the device) ” to the AIoT device 150. The reader 140 may switch on or switch off the following AIoT operation, e.g., inventory for the AIoT device 150 as requested at 712.
[0165] At 714, the AIoT device150 may update its security configuration as requested in Device configuration update to switch on or switch off security. The AIoT device sends a Device configuration update response to the reader 140 with Security operation status indication to indicate the security operation status with no security or having security. For example, the Device configuration update response (Security operation status indication) may be sent at 714 from the AIoT device150 to the reader 140.
[0166] At 715, the reader 140 may send an AIoT Operation Response (Device ID, Device configuration update response) to the AIoT controller 110. The Device configuration update response may be a NAS message which is received at 714.
[0167] In some embodiments, the messages sent at steps 712, 713 and / or 716 may include a cause value, which may indicate the cause for the switching, for example, due to change of subscription.
[0168] At 716, the AIoT controller 110 may send an AIoT Operation change notification (Device ID, Security operation status indication) to the AF 120 to notify the AF 120 about the security operation status of the AIoT device 150.
[0169] At 717, the AF 120 may send an AIoT Operation change notification response to ack receiving the notification.
[0170] FIG. 8 illustrates a signaling flow 800 of an example process of security mechanism management in accordance with some embodiments of the present disclosure. For purpose of discussion, the embodiments of FIG. 8 will be discussed with respect to FIG. 1. As shown in FIG. 8, the signaling flow 800 involves the AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, and the AIoT device 150.
[0171] The AIoT controller 110 may be considered as an implementation of the sixth communication device 501 of FIG. 5. The AF 120 may be considered as an implementation of the ninth communication device 504 of FIG. 5. The AIoT device management function 130 may be considered as an implementation of the tenth communication device 505 of FIG. 5. The AIoT reader 140 may be considered as an implementation of the seventh communication device 502 of FIG. 5. The AIoT device 150 may be considered as an implementation of the eighth communication device 501 of FIG. 5.
[0172] Embodiments of FIG. 8 are related to AIoT security operation status switch initiated by the AIoT controller 110. In this case, based on the internal or external trigger, the AIoT controller 110 decides to change the security operation status for switching on or switching off security between the AIoT device 150 and the reader 140. The switch-on-security trigger may be based on the operation security risk evaluation to the environment, e.g. the warehouse has some out-of-control device or Reader. For example, if the AIoT controller detects a device which is unknown, it may determine that a security risk is detected and may initiate the AIoT security operation status switch.
[0173] The signaling flow 800 starts at 812. At 812, the AIoT controller 110 may send an AIoT Operation Request to the reader 140, which includes Device ID, switch on or switch off security in the device, and NAS message (Device configuration update) to the AIoT device. The “Device configuration update” may be secured by a NAS security mechanism between the AIoT controller 110 and the AIoT device 150. For example, the AIoT Operation Request sent at 612 may be in the form of “AIoT Operation Request (Device ID, switch on or switch off security in the device, NAS (Device configuration update) ) ” .
[0174] At 813, the reader 140 may send the NAS message, e.g., in the form of “Device configuration update (switch on or switch off security in the device) ” to the AIoT device 150. The reader 140 may switch on or switch off the following AIoT operation, e.g., inventory for the AIoT device 150 as requested at 812.
[0175] At 814, the AIoT device150 may update its security configuration as requested in Device configuration update to switch on or switch off security. The AIoT device sends a Device configuration update response to the reader 140 with Security operation status indication to indicate the security operation status with no security or having security. For example, the Device configuration update response (Security operation status indication) may be sent at 814 from the AIoT device150 to the reader 140.
[0176] At 815, the reader 140 may send an AIoT Operation Response (Device ID, Device configuration update response) to the AIoT controller 110. The Device configuration update response may be a NAS message which is received at 814.
[0177] In some embodiments, the messages sent at steps 812, 813 and / or 816 may include a cause value, which may indicate the cause for the switching, for example, why this security operation change happens, e.g. security risk detected for switch-on-security
[0178] At 816, the AIoT controller 110 may send an AIoT Operation change notification (Device ID, Security operation status indication) to the AF 120 to notify the AF 120 about the security operation status of the AIoT device 150.
[0179] At 817, the AF 120 may send an AIoT Operation change notification response to ack receiving the notification.
[0180] FIG. 9 illustrates a signaling flow 900 of an example process of security mechanism management in accordance with some embodiments of the present disclosure. For purpose of discussion, the embodiments of FIG. 9 will be discussed with respect to FIG. 1. As shown in FIG. 9, the signaling flow 900 involves the AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, and the AIoT device 150.
[0181] The AIoT controller 110 may be considered as an implementation of the sixth communication device 501 of FIG. 5. The AF 120 may be considered as an implementation of the ninth communication device 504 of FIG. 5. The AIoT device management function 130 may be considered as an implementation of the tenth communication device 505 of FIG. 5. The AIoT reader 140 may be considered as an implementation of the seventh communication device 502 of FIG. 5. The AIoT device 150 may be considered as an implementation of the eighth communication device 501 of FIG. 5.
[0182] Embodiments of FIG. 9 are related to AIoT security operation status switch initiated by the AIoT reader 140. In this case, based on the internal or external trigger, the AIoT reader 140 may decide to change the security operation status for switching on or switching off security between the AIoT device 150 and the Reader 140. The switch-on-security trigger may be based on the operation security risk evaluation to the environment, e.g. the warehouse has some out-of-control device or Reader.
[0183] In the signaling flow 900, at 910, the reader 140 may sends a message, such as “AIoT Operation change request (switch on or switch off security in the device, Cause) ” to the AIoT controller 110. The cause may be the evaluation result based on the AIoT operation security risk in the environment.
[0184] Optionally, at 911, the AIoT controller 110 may send an AIoT Operation change response to ack receiving at 910.
[0185] Steps 912 to 917 are similar as steps 812 to 817. In particular, at 912, the AIoT controller 110 may send an AIoT Operation Request to the reader 140, which includes Device ID, switch on or switch off security in the device, and NAS message (Device configuration update) to the AIoT device. The “Device configuration update” may be secured by a NAS security mechanism between the AIoT controller 110 and the AIoT device 150. For example, the AIoT Operation Request sent at 612 may be in the form of “AIoT Operation Request (Device ID, switch on or switch off security in the device, NAS(Device configuration update) ) ” .
[0186] At 913, the reader 140 may send the NAS message, e.g., in the form of “Device configuration update (switch on or switch off security in the device) ” to the AIoT device 150. The reader 140 may switch on or switch off the following AIoT operation, e.g., inventory for the AIoT device 150 as requested at 912.
[0187] At 914, the AIoT device150 may update its security configuration as requested in Device configuration update to switch on or switch off security. The AIoT device sends a Device configuration update response to the reader 140 with Security operation status indication to indicate the security operation status with no security or having security. For example, the Device configuration update response (Security operation status indication) may be sent at 914 from the AIoT device150 to the reader 140.
[0188] At 915, the reader 140 may send an AIoT Operation Response (Device ID, Device configuration update response) to the AIoT controller 110. The Device configuration update response may be a NAS message which is received at 914.
[0189] In some embodiments, the messages sent at steps 912, 913 and / or 916 may include a cause value, where the cause value may indicate why this security operation change happens, e.g., security risk detected for switch-on-security.
[0190] At 916, the AIoT controller 110 may send an AIoT Operation change notification (Device ID, Security operation status indication) to the AF 120 to notify the AF 120 about the security operation status of the AIoT device 150.
[0191] At 917, the AF 120 may send an AIoT Operation change notification response to ack receiving the notification.
[0192] FIG. 10 illustrates a signaling flow 1000 of an example process of security mechanism management in accordance with some embodiments of the present disclosure. For purpose of discussion, the embodiments of FIG. 10 will be discussed with respect to FIG. 1. As shown in FIG. 10, the signaling flow 1000 involves the AIoT controller 110, the AF 120, the AIoT device management function 130, the AIoT reader 140, and the AIoT device 150.
[0193] The AIoT controller 110 may be considered as an implementation of the sixth communication device 501 of FIG. 5. The AF 120 may be considered as an implementation of the ninth communication device 504 of FIG. 5. The AIoT device management function 130 may be considered as an implementation of the tenth communication device 505 of FIG. 5. The AIoT reader 140 may be considered as an implementation of the seventh communication device 502 of FIG. 5. The AIoT device 150 may be considered as an implementation of the eighth communication device 501 of FIG. 5.
[0194] Embodiments of FIG. 10 are related to AIoT security operation status switch initiated by the AIoT device 150. In this case, based on the internal or external trigger, the AIoT device 150 may decide to change the security operation status for switching on or switching off security between the AIoT device 150 and the reader 140. The switch- on-security trigger may be based on the operation configuration by the warehouse administrator.
[0195] In the signaling flow 1000, at 1011, the AIoT device 150 may send a Device configuration update request (switch on or switch off security in the device, Cause) to the AIoT controller 110, the cause may be configured by the warehouse administrator.
[0196] Steps 1012 to 1017 are similar as steps 912 to 917. In particular, at 1012, the AIoT controller 110 may send an AIoT Operation Request to the reader 140, which includes Device ID, switch on or switch off security in the device, and NAS message (Device configuration update) to the AIoT device. The “Device configuration update” may be secured by a NAS security mechanism between the AIoT controller 110 and the AIoT device 150. For example, the AIoT Operation Request sent at 612 may be in the form of “AIoT Operation Request (Device ID, switch on or switch off security in the device, NAS (Device configuration update) ) ” .
[0197] At 1013, the reader 140 may send the NAS message, e.g., in the form of “Device configuration update (switch on or switch off security in the device) ” to the AIoT device 150. The reader 140 may switch on or switch off the following AIoT operation, e.g., inventory for the AIoT device 150 as requested at 1012.
[0198] At 1014, the AIoT device150 may update its security configuration as requested in Device configuration update to switch on or switch off security. The AIoT device sends a Device configuration update response to the reader 140 with Security operation status indication to indicate the security operation status with no security or having security. For example, the Device configuration update response (Security operation status indication) may be sent at 1014 from the AIoT device 150 to the reader 140. At 1014, if the reader 140 fails to receive a response from an AIoT device, it may consider this round of updating fails and may try later.
[0199] At 1015, the reader 140 may send an AIoT Operation Response (Device ID, Device configuration update response) to the AIoT controller 110. The Device configuration update response may be a NAS message which is received at 1014.
[0200] In some embodiments, the messages sent at steps 1012, 1013 and / or 1016 may include a cause value, where the cause value may indicate why this security operation change happens, e.g., security risk detected for switch-on-security.
[0201] At 1016, the AIoT controller 110 may send an AIoT Operation change notification (Device ID, Security operation status indication) to the AF 120 to notify the AF 120 about the security operation status of the AIoT device 150.
[0202] At 1017, the AF 120 may send an AIoT Operation change notification response to ack receiving the notification.
[0203] Optionally, in some embodiments, if the AIoT controller 110 determines that the security risk is under control, the security mechanism may be not changed or switched. Instead, the AIoT controller 110may ignore the security risk or just response no action to the AIoT device 150.
[0204] In the above embodiments and other possible embodiments of the present disclosure, the cause value may indicate different levels of risks, for example, a high level, a medium level, or a low level.
[0205] FIG. 11 illustrates a flowchart of a communication method 1100 implemented at a first communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1100 will be described from the perspective of the first communication device 301 in FIG. 3.
[0206] At block 1110, the first communication device 301 transmits, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation.
[0207] At block 1120, the first communication device 301 receives, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0208] In some example embodiments, the first communication device is further caused to:receive, from the second communication device, information about a second security capability of the second communication device with respect to the AIoT operation; and transmit the first security capability of the first communication device to the second communication device, wherein the first security capability is associated with the same security level as the second security capability.
[0209] In some example embodiments, the information about the security capability of the second communication device is received via a broadcasting signal, and / or wherein the broadcasting signal comprising at least one of an AIoT paging signal or a system information block (SIB) .
[0210] In some example embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the first response comprises an indication indicating that the AIoT operation is allowed to be performed with security.
[0211] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0212] In some example embodiments, the first communication device comprises an AIoT device, and the second communication device comprises a reader.
[0213] FIG. 12 illustrates a flowchart of a communication method 1200 implemented at a second communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1200 will be described from the perspective of the second communication device 302 in FIG. 3.
[0214] At block 1210, the second communication device 302 in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a third communication device, a second request indicating the first security capability of the first communication device.
[0215] At block 1220, the second communication device 302 in response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0216] In some example embodiments, the second communication device is further caused to: transmit, to the first communication device, information about a second security capability of the second communication device with respect to the AIoT operation, wherein the first security capability is associated with the same security level as the second security capability.
[0217] In some example embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response and the second response each comprise an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the first response and the second response each comprise an indication indicating that the AIoT operation is allowed to be performed with security.
[0218] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0219] In some example embodiments, the first communication device comprises an AIoT device, the second communication device comprises a reader, and the third communication device comprises an AIoT controller.
[0220] FIG. 13 illustrates a flowchart of a communication method 1300 implemented at a third communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1300 will be described from the perspective of the third communication device 303 in FIG. 3.
[0221] At block 1310, the third communication device 303 in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device.
[0222] At block 1320, the third communication device 303 in response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0223] In some example embodiments, the third communication device may further obtain subscription information of the first communication device; and transmit the third request to the fourth communication device based on the subscription information.
[0224] In some example embodiments, the third communication device may further transmit, to a fifth communication device, a fourth request for subscription information of the first communication device; and receive, from the fifth communication device, a fourth response comprising the subscription information.
[0225] In some example embodiments, the subscription information comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, reader information indicating at least one reader connecting to the first communication device, or information about the fourth communication device.
[0226] In some example embodiments, the third request comprises at least one of: an indication indicating the security level is requested, location information indicating an area in which the security level is requested, or reader information indicating at least one reader connecting to the first communication device.
[0227] In some example embodiments, the third response comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, or reader information indicating at least one reader connecting to the first communication device.
[0228] In some example embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the second response and the third response each comprise an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the second response and the third response each comprise an indication indicating that the AIoT operation is allowed to be performed with security.
[0229] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0230] In some example embodiments, the first communication device comprises an AIoT device, the second communication device comprises a reader, the third communication device comprises an AIoT controller, the fourth communication device comprises a device implementing an Application Function (AF) , and the fifth communication device comprises a device implementing an AIoT device management function.
[0231] FIG. 14 illustrates a flowchart of a communication method 1400 implemented at a fourth communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1400 will be described from the perspective of the fourth communication device 304 in FIG. 3.
[0232] At block 1410, the fourth communication device 304 receives, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an ambient internet of things (AIoT) operation, the security level being associated with a first security capability of the first communication device.
[0233] At block 1420, the fourth communication device 304 transmits, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0234] In some example embodiments, the third request comprises at least one of: an indication indicating the security level is requested, location information indicating an area in which the security level is requested, or reader information indicating at least one reader connecting to the first communication device.
[0235] In some example embodiments, the third response comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, or reader information indicating at least one reader connecting to the first communication device.
[0236] In some example embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed with security.
[0237] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0238] In some example embodiments, the first communication device comprises an AIoT device, the third communication device comprises an AIoT controller, and the fourth communication device comprises a device implementing an Application Function (AF) .
[0239] FIG. 15 illustrates a flowchart of a communication method 1500 implemented at a fifth communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1500 will be described from the perspective of the fifth communication device 305 in FIG. 3.
[0240] At block 1510, the fifth communication device 305 receives, from a third communication device, a fourth request for subscription information of a first communication device.
[0241] At block 1520, the fifth communication device 305 transmits, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an ambient internet of things (AIoT) operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device.
[0242] In some example embodiments, the subscription information comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, reader information indicating at least one reader connecting to the first communication device, or information about a fourth communication device for authorization.
[0243] In some example embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed with security.
[0244] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0245] In some example embodiments, the first communication device comprises an AIoT device, the third communication device comprises an AIoT controller, the fourth communication device comprises a device implementing an Application Function (AF) , and the fifth communication device comprises a device implementing an AIoT device management function.
[0246] FIG. 16 illustrates a flowchart of a communication method 1600 implemented at a sixth communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1600 will be described from the perspective of the sixth communication device 501 in FIG. 5.
[0247] At block 1610, the sixth communication device 501 transmits, to a seventh communication device, a sixth request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0248] In some example embodiments, the sixth communication device 501 may further: receive, from the seventh communication device, a sixth response to the sixth request, wherein the sixth response comprises information indicating a security operation status of the eighth communication device; and transmit, to a ninth communication device, a report comprising at least one of an indication indicating the security operation status of the eighth communication device, or a cause for the security mechanism switching.
[0249] In some example embodiments, the sixth request is transmitted based on a determination made by the sixth communication device, or is triggered by at least one of: the seventh communication device, the eighth communication device, a ninth communication device, or a tenth communication device.
[0250] In some example embodiments, the sixth communication device may in response to receiving information for the security mechanism switching from a ninth communication device implementing an Application Function (AF) , transmit the sixth request to a seventh communication device, wherein the information is comprised in an AIoT operation request.
[0251] In some example embodiments, the sixth communication device may in response to receiving information for the security mechanism switching from a tenth communication device implementing an AIoT device management function, transmit the sixth request to a seventh communication device, wherein the information is comprised in a subscription change notification related to the eighth communication device.
[0252] In some example embodiments, the sixth communication device may in response to receiving a trigger for the security mechanism switching from the seventh communication device or from the eighth communication device, transmit the sixth request to a seventh communication device, wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0253] In some example embodiments, the sixth communication device may transmit an acknowledgement to the trigger to the seventh communication device or the eighth communication device.
[0254] In some example embodiments, the sixth request comprises a cause for the security mechanism switching.
[0255] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0256] In some example embodiments, the sixth communication device comprises an AIoT controller, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
[0257] FIG. 17 illustrates a flowchart of a communication method 1700 implemented at a seventh communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1700 will be described from the perspective of the seventh communication device 502 in FIG. 5.
[0258] At block 1710, the seventh communication device 502 receives, from a sixth communication device, a sixth request for security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0259] At block 1720, the seventh communication device 502 transmits, to the eighth communication device, a seventh request for the security mechanism switching.
[0260] In some example embodiments, the seventh communication device is further caused to: receive, from the eighth communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device; and transmit, to a sixth communication device, a sixth response to the sixth request, wherein the sixth response comprises information indicating the security operation status of the eighth communication device.
[0261] In some example embodiments, seventh communication device is further caused to:transmit, to the sixth communication device, a trigger for the security mechanism switching, wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0262] In some example embodiments, the sixth request or the seventh request comprises a cause for the security mechanism switching.
[0263] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0264] In some example embodiments, the sixth communication device comprises an AIoT controller, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
[0265] FIG. 18 illustrates a flowchart of a communication method 1800 implemented at an eighth communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1800 will be described from the perspective of the eighth communication device 503 in FIG. 1.
[0266] At block 1810, the eighth communication device 503 receives, from a seventh communication device, a seventh request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in the eighth communication device.
[0267] At block 1820, the eighth communication device 503 transmits, to the seventh communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device.
[0268] In some example embodiments, the eighth communication device may transmit, to the sixth communication device, a trigger for the security mechanism switching, wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0269] In some example embodiments, the seventh request comprises a cause for the security mechanism switching.
[0270] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0271] In some example embodiments, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
[0272] FIG. 19 illustrates a flowchart of a communication method 1900 implemented at a ninth communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 1900 will be described from the perspective of the ninth communication device 504 in FIG. 5.
[0273] At block 1910, the ninth communication device 504 receives, from a sixth communication device, a report comprising an indication of a security operation status of an eighth communication device, wherein the security operation status is updated in response to a security mechanism switching associated with an ambient internet of things (AIoT) operation.
[0274] In some example embodiments, the ninth communication device may transmit, to the sixth communication device, a trigger for the security mechanism switching, wherein the trigger comprises at least one of: an indication of switching on or switching off a security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0275] In some example embodiments, the ninth communication device may transmit, to the sixth communication device, an acknowledgement to the report.
[0276] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0277] In some example embodiments, the sixth communication device comprises an AIoT controller, the eighth communication device comprises an AIoT device, and the ninth communication device implements an Application Function (AF) .
[0278] FIG. 20 illustrates a flowchart of a communication method 2000 implemented at a tenth communication device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 2000 will be described from the perspective of the tenth communication device 505 in FIG. 5.
[0279] At block 2010, the tenth communication device 505 transmits, to a sixth communication device, information for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0280] In some example embodiments, the tenth communication device is further caused to: receive, from the sixth communication device, an acknowledgement to the trigger.
[0281] In some example embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0282] In some example embodiments, the sixth communication device comprises an AIoT controller, the eighth communication device comprises an AIoT device, and the tenth communication device implements an AIoT device management function.
[0283] FIG. 21 is a simplified block diagram of a device 2100 that is suitable for implementing embodiments of the present disclosure. The device 2100 may be considered as a further example implementation of any of the devices as shown in FIGS. 1, 3 and 5.
[0284] As shown, the device 2100 includes a processor 2110, a memory 2120 coupled to the processor 2110, a suitable transceiver 2140 coupled to the processor 2110, and a communication interface coupled to the transceiver 2140. The memory 2120 stores at least a part of a program 2130. The transceiver 2140 may be for bidirectional communications or a unidirectional communication based on requirements. The transceiver 2140 may include at least one of a transmitter 2142 and a receiver 2144. The transmitter 2142 and the receiver 2144 may be functional modules or physical entities. The transceiver 2140 has at least one antenna to facilitate communication, though in practice an Access Node mentioned in this application may have several ones. The communication interface may represent any interface that is necessary for communication with other network elements, such as X2 / Xn interface for bidirectional communications between eNBs / gNBs, S1 / NG interface for communication between a Mobility Management Entity (MME) / Access and Mobility Management Function (AMF) / SGW / UPF and the eNB / gNB, Un interface for communication between the eNB / gNB and a relay node (RN) , or Uu interface for communication between the eNB / gNB and a terminal device.
[0285] The program 2130 is assumed to include program instructions that, when executed by the associated processor 2110, enable the device 2100 to operate in accordance with the embodiments of the present disclosure, as discussed herein with reference to FIGS. 1 to 20. The embodiments herein may be implemented by computer software executable by the processor 2110 of the device 2100, or by hardware, or by a combination of software and hardware. The processor 2110 may be configured to implement various embodiments of the present disclosure. Furthermore, a combination of the processor 2110 and memory 2120 may form processing means 2150 adapted to implement various embodiments of the present disclosure.
[0286] The memory 2120 may be of any type suitable to the local technical network and may be implemented using any suitable data storage technology, such as a non-transitory computer readable storage medium, semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory, as non-limiting examples. While only one memory 2120 is shown in the device 2100, there may be several physically distinct memory modules in the device 2100. The processor 2110 may be of any type suitable to the local technical network, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 2100 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0287] According to embodiments of the present disclosure, a first communication device comprising a circuitry is provided. The circuitry is configured to: transmit, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation; and receive, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the first communication device as discussed above.
[0288] According to embodiments of the present disclosure, a second communication device comprising a circuitry is provided. The circuitry is configured to: in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a third communication device, a second request indicating the first security capability of the first communication device; and in response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the second communication device as discussed above.
[0289] According to embodiments of the present disclosure, a third communication device comprising a circuitry is provided. The circuitry is configured to: in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device; and in response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the third communication device as discussed above.
[0290] According to embodiments of the present disclosure, a fourth communication device comprising a circuitry is provided. The circuitry is configured to: receive, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an ambient internet of things (AIoT) operation, the security level being associated with a first security capability of the first communication device; and transmit, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the fourth communication device as discussed above.
[0291] According to embodiments of the present disclosure, a fifth communication device comprising a circuitry is provided. The circuitry is configured to: receive, from a third communication device, a fourth request for subscription information of a first communication device; and transmit, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an ambient internet of things (AIoT) operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the fifth communication device as discussed above.
[0292] According to embodiments of the present disclosure, a sixth communication device comprising a circuitry is provided. The circuitry is configured to: transmit, to a seventh communication device, a sixth request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the sixth communication device as discussed above.
[0293] According to embodiments of the present disclosure, a seventh communication device comprising a circuitry is provided. The circuitry is configured to: receive, from a sixth communication device, a sixth request for security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device; and transmit, to the eighth communication device, a seventh request for the security mechanism switching. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the seventh communication device as discussed above.
[0294] According to embodiments of the present disclosure, an eighth communication device comprising a circuitry is provided. The circuitry is configured to: receive, from a seventh communication device, a seventh request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in the eighth communication device; and transmit, to the seventh communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the an eighth communication device as discussed above.
[0295] According to embodiments of the present disclosure, a ninth communication device comprising a circuitry is provided. The circuitry is configured to: receive, from a sixth communication device, a report comprising an indication of a security operation status of an eighth communication device, wherein the security operation status is updated in response to a security mechanism switching associated with an ambient internet of things (AIoT) operation. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the ninth communication device as discussed above.
[0296] According to embodiments of the present disclosure, a tenth communication device comprising a circuitry is provided. The circuitry is configured to: transmit, to a sixth communication device, information for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device. According to embodiments of the present disclosure, the circuitry may be configured to perform any method implemented by the tenth communication device as discussed above.
[0297] The term “circuitry” used herein may refer to hardware circuits and / or combinations of hardware circuits and software. For example, the circuitry may be a combination of analog and / or digital hardware circuits with software / firmware. As a further example, the circuitry may be any portions of hardware processors with software including digital signal processor (s) , software, and memory (ies) that work together to cause an apparatus, such as a terminal device or a network device, to perform various functions. In a still further example, the circuitry may be hardware circuits and or processors, such as a microprocessor or a portion of a microprocessor, that requires software / firmware for operation, but the software may not be present when it is not needed for operation. As used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (s) or a portion of a hardware circuit or processor (s) and its (or their) accompanying software and / or firmware.
[0298] According to embodiments of the present disclosure, a first communication apparatus is provided. The first communication apparatus comprises means for transmitting, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation; and means for receiving, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability. In some embodiments, the first apparatus may comprise means for performing the respective operations of the method 1100. In some example embodiments, the first apparatus may further comprise means for performing other operations in some example embodiments of the method 1100. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0299] According to embodiments of the present disclosure, a second communication apparatus is provided. The second communication apparatus comprises means for in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation, transmitting, to a third communication device, a second request indicating the first security capability of the first communication device; and means for in response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmitting, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability. In some embodiments, the second apparatus may comprise means for performing the respective operations of the method 1200. In some example embodiments, the second apparatus may further comprise means for performing other operations in some example embodiments of the method 1200. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0300] According to embodiments of the present disclosure, a third communication apparatus is provided. The third communication apparatus comprises means for in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an ambient internet of things (AIoT) operation, transmitting, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device; and means for in response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmitting, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device. In some embodiments, the third apparatus may comprise means for performing the respective operations of the method 1300. In some example embodiments, the third apparatus may further comprise means for performing other operations in some example embodiments of the method 1300. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0301] According to embodiments of the present disclosure, a fourth communication apparatus is provided. The fourth communication apparatus comprises means for receiving, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an ambient internet of things (AIoT) operation, the security level being associated with a first security capability of the first communication device; and means for transmitting, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device. In some embodiments, the fourth apparatus may comprise means for performing the respective operations of the method 1400. In some example embodiments, the fourth apparatus may further comprise means for performing other operations in some example embodiments of the method 1400. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0302] According to embodiments of the present disclosure, a fifth communication apparatus is provided. The fifth communication apparatus comprises means for receiving, from a third communication device, a fourth request for subscription information of a first communication device; and means for transmitting, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an ambient internet of things (AIoT) operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device. In some embodiments, the fifth apparatus may comprise means for performing the respective operations of the method 1500. In some example embodiments, the fifth apparatus may further comprise means for performing other operations in some example embodiments of the method 1500. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0303] According to embodiments of the present disclosure, a sixth communication apparatus is provided. The sixth communication apparatus comprises means for transmitting, to a seventh communication device, a sixth request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device. In some embodiments, the sixth apparatus may comprise means for performing the respective operations of the method 1600. In some example embodiments, the sixth apparatus may further comprise means for performing other operations in some example embodiments of the method 1600. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0304] According to embodiments of the present disclosure, a seventh communication apparatus is provided. The seventh communication apparatus comprises means for receiving, from a sixth communication device, a sixth request for security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device; and means for transmitting, to the eighth communication device, a seventh request for the security mechanism switching. In some embodiments, the seventh apparatus may comprise means for performing the respective operations of the method 1700. In some example embodiments, the seventh apparatus may further comprise means for performing other operations in some example embodiments of the method 1700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0305] According to embodiments of the present disclosure, an eighth communication apparatus is provided. The eighth communication apparatus comprises means for receiving, from a seventh communication device, a seventh request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in the eighth communication device; and means for transmitting, to the seventh communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device. In some embodiments, the eighth apparatus may comprise means for performing the respective operations of the method 1800. In some example embodiments, the eighth apparatus may further comprise means for performing other operations in some example embodiments of the method 1800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0306] According to embodiments of the present disclosure, a ninth communication apparatus is provided. The ninth communication apparatus comprises means for receiving, from a sixth communication device, a report comprising an indication of a security operation status of an eighth communication device, wherein the security operation status is updated in response to a security mechanism switching associated with an ambient internet of things (AIoT) operation. In some embodiments, the ninth apparatus may comprise means for performing the respective operations of the method 1900. In some example embodiments, the ninth apparatus may further comprise means for performing other operations in some example embodiments of the method 1900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0307] According to embodiments of the present disclosure, a tenth communication apparatus is provided. The tenth communication apparatus comprises means for transmitting, to a sixth communication device, information for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device. In some embodiments, the tenth apparatus may comprise means for performing the respective operations of the method 2000. In some example embodiments, the tenth apparatus may further comprise means for performing other operations in some example embodiments of the method 2000. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0308] In summary, embodiments of the present disclosure provide the following aspects.
[0309] In an aspect, it is proposed a first communication device comprising: a processor configured to cause the first communication device to: transmit, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation; and receive, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0310] In some embodiments, the first communication device is further caused to: receive, from the second communication device, information about a second security capability of the second communication device with respect to the AIoT operation; and transmit the first security capability of the first communication device to the second communication device, wherein the first security capability is associated with the same security level as the second security capability.
[0311] In some embodiments, the information about the security capability of the second communication device is received via a broadcasting signal, and / or wherein the broadcasting signal comprising at least one of an AIoT paging signal or a system information block (SIB) .
[0312] In some embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the first response comprises an indication indicating that the AIoT operation is allowed to be performed with security.
[0313] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0314] In some embodiments, the first communication device comprises an AIoT device, and the second communication device comprises a reader.
[0315] In an aspect, it is proposed a second communication device comprising: a processor configured to cause the second communication device to: in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a third communication device, a second request indicating the first security capability of the first communication device; and in response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.
[0316] In some embodiments, the second communication device is further caused to: transmit, to the first communication device, information about a second security capability of the second communication device with respect to the AIoT operation, wherein the first security capability is associated with the same security level as the second security capability.
[0317] In some embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response and the second response each comprise an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the first response and the second response each comprise an indication indicating that the AIoT operation is allowed to be performed with security.
[0318] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0319] In some embodiments, the first communication device comprises an AIoT device, the second communication device comprises a reader, and the third communication device comprises an AIoT controller.
[0320] In an aspect, it is proposed a third communication device comprising: a processor configured to cause the third communication device to: in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device; and in response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0321] In some embodiments, the third communication device is further caused to: obtain subscription information of the first communication device; and transmit the third request to the fourth communication device based on the subscription information.
[0322] In some embodiments, the third communication device is further caused to: transmit, to a fifth communication device, a fourth request for subscription information of the first communication device; and receive, from the fifth communication device, a fourth response comprising the subscription information.
[0323] In some embodiments, the subscription information comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, reader information indicating at least one reader connecting to the first communication device, or information about the fourth communication device.
[0324] In some embodiments, the third request comprises at least one of: an indication indicating the security level is requested, location information indicating an area in which the security level is requested, or reader information indicating at least one reader connecting to the first communication device.
[0325] In some embodiments, the third response comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, or reader information indicating at least one reader connecting to the first communication device.
[0326] In some embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the second response and the third response each comprise an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the second response and the third response each comprise an indication indicating that the AIoT operation is allowed to be performed with security.
[0327] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0328] In some embodiments, the first communication device comprises an AIoT device, the second communication device comprises a reader, the third communication device comprises an AIoT controller, the fourth communication device comprises a device implementing an Application Function (AF) , and the fifth communication device comprises a device implementing an AIoT device management function.
[0329] In an aspect, it is proposed a fourth communication device comprising: a processor configured to cause the fourth communication device to: receive, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an ambient internet of things (AIoT) operation, the security level being associated with a first security capability of the first communication device; and transmit, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.
[0330] In some embodiments, the third request comprises at least one of: an indication indicating the security level is requested, location information indicating an area in which the security level is requested, or reader information indicating at least one reader connecting to the first communication device.
[0331] In some embodiments, the third response comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, or reader information indicating at least one reader connecting to the first communication device.
[0332] In some embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed with security.
[0333] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0334] In some embodiments, the first communication device comprises an AIoT device, the third communication device comprises an AIoT controller, and the fourth communication device comprises a device implementing an Application Function (AF) .
[0335] In an aspect, it is proposed a fifth communication device comprising: a processor configured to cause the fifth communication device to: receive, from a third communication device, a fourth request for subscription information of a first communication device; and transmit, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an ambient internet of things (AIoT) operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device.
[0336] In some embodiments, the subscription information comprises at least one of: an indication indicating that the AIoT operation is allowed to be performed at the security level, location information indicating an area in which the AIoT operation is allowed to be performed at the security level, reader information indicating at least one reader connecting to the first communication device, or information about a fourth communication device for authorization.
[0337] In some embodiments, the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / or wherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed with security.
[0338] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0339] In some embodiments, the first communication device comprises an AIoT device, the third communication device comprises an AIoT controller, the fourth communication device comprises a device implementing an Application Function (AF) , and the fifth communication device comprises a device implementing an AIoT device management function.
[0340] In an aspect, it is proposed a sixth communication device comprising: a processor configured to cause the sixth communication device to: transmit, to a seventh communication device, a sixth request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0341] In some embodiments, the sixth communication device is further caused to: receive, from the seventh communication device, a sixth response to the sixth request, wherein the sixth response comprises information indicating a security operation status of the eighth communication device; and transmit, to a ninth communication device, a report comprising at least one of an indication indicating the security operation status of the eighth communication device, or a cause for the security mechanism switching.
[0342] In some embodiments, the sixth request is transmitted based on a determination made by the sixth communication device, or is triggered by at least one of: the seventh communication device, the eighth communication device, a ninth communication device, or a tenth communication device.
[0343] In some embodiments, the sixth communication device is further caused to: in response to receiving information for the security mechanism switching from a ninth communication device implementing an Application Function (AF) , transmit the sixth request to a seventh communication device, wherein the information is comprised in an AIoT operation request.
[0344] In some embodiments, the sixth communication device is further caused to: in response to receiving information for the security mechanism switching from a tenth communication device implementing an AIoT device management function, transmit the sixth request to a seventh communication device, wherein the information is comprised in a subscription change notification related to the eighth communication device.
[0345] In some embodiments, the sixth communication device is further caused to: in response to receiving a trigger for the security mechanism switching from the seventh communication device or from the eighth communication device, transmit the sixth request to a seventh communication device, wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0346] In some embodiments, the sixth communication device is further caused to: transmit an acknowledgement to the trigger to the seventh communication device or the eighth communication device.
[0347] In some embodiments, the sixth request comprises a cause for the security mechanism switching.
[0348] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0349] In some embodiments, the sixth communication device comprises an AIoT controller, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
[0350] In an aspect, it is proposed a seventh communication device comprising: a processor configured to cause the seventh communication device to: receive, from a sixth communication device, a sixth request for security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device; and transmit, to the eighth communication device, a seventh request for the security mechanism switching.
[0351] In some embodiments, the seventh communication device is further caused to: receive, from the eighth communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device; and transmit, to a sixth communication device, a sixth response to the sixth request, wherein the sixth response comprises information indicating the security operation status of the eighth communication device.
[0352] In some embodiments, seventh communication device is further caused to: transmit, to the sixth communication device, a trigger for the security mechanism switching, wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0353] In some embodiments, the sixth request or the seventh request comprises a cause for the security mechanism switching.
[0354] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0355] In some embodiments, the sixth communication device comprises an AIoT controller, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
[0356] In an aspect, it is proposed 48. An eighth communication device comprising: a processor configured to cause the eighth communication device to: receive, from a seventh communication device, a seventh request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in the eighth communication device; and transmit, to the seventh communication device, a seventh response to the seventh request, wherein the seventh response comprises an indication of a security operation status of the eighth communication device.
[0357] In some embodiments, the eighth communication device is further caused to: transmit, to the sixth communication device, a trigger for the security mechanism switching, wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0358] In some embodiments, the seventh request comprises a cause for the security mechanism switching.
[0359] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0360] In some embodiments, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
[0361] In an aspect, it is proposed a ninth communication device comprising: a processor configured to cause the ninth communication device to: receive, from a sixth communication device, a report comprising an indication of a security operation status of an eighth communication device, wherein the security operation status is updated in response to a security mechanism switching associated with an ambient internet of things (AIoT) operation.
[0362] In some embodiments, the ninth communication device is further caused to: transmit, to the sixth communication device, a trigger for the security mechanism switching, wherein the trigger comprises at least one of: an indication of switching on or switching off a security mechanism in the eighth communication device, or a cause for the security mechanism switching.
[0363] In some embodiments, the ninth communication device is further caused to: transmit, to the sixth communication device, an acknowledgement to the report.
[0364] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0365] In some embodiments, the sixth communication device comprises an AIoT controller, the eighth communication device comprises an AIoT device, and the ninth communication device implements an Application Function (AF) .
[0366] In an aspect, it is proposed a tenth communication device comprising: a processor configured to cause the tenth communication device to: transmit, to a sixth communication device, information for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.
[0367] In some embodiments, the tenth communication device is further caused to: receive, from the sixth communication device, an acknowledgement to the trigger.
[0368] In some embodiments, the AIoT operation is related to at least one of an inventory procedure or a command procedure.
[0369] In some embodiments, the sixth communication device comprises an AIoT controller, the eighth communication device comprises an AIoT device, and the tenth communication device implements an AIoT device management function.
[0370] In an aspect, a first communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the first communication device discussed above.
[0371] In an aspect, a second communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the second communication device discussed above.
[0372] In an aspect, a third communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the third communication device discussed above.
[0373] In an aspect, a fourth communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the fourth communication device discussed above.
[0374] In an aspect, a fifth communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the fifth communication device discussed above.
[0375] In an aspect, a sixth communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the sixth communication device discussed above.
[0376] In an aspect, a seventh communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the seventh communication device discussed above.
[0377] In an aspect, a an eighth communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the an eighth communication device discussed above.
[0378] In an aspect, a ninth communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the ninth communication device discussed above.
[0379] In an aspect, a tenth communication device comprises: at least one processor; and at least one memory coupled to the at least one processor and storing instructions thereon, the instructions, when executed by the at least one processor, causing the device to perform the method implemented by the tenth communication device discussed above.
[0380] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the first communication device discussed above.
[0381] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the second communication device discussed above.
[0382] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the third communication device discussed above.
[0383] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fourth communication device discussed above.
[0384] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fifth communication device discussed above.
[0385] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the sixth communication device discussed above.
[0386] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the seventh communication device discussed above.
[0387] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the an eighth communication device discussed above.
[0388] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the ninth communication device discussed above.
[0389] In an aspect, a computer readable medium having instructions stored thereon, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the tenth communication device discussed above.
[0390] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the first communication device discussed above.
[0391] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the second communication device discussed above.
[0392] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the third communication device discussed above.
[0393] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fourth communication device discussed above.
[0394] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the fifth communication device discussed above.
[0395] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the sixth communication device discussed above.
[0396] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the seventh communication device discussed above.
[0397] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the an eighth communication device discussed above.
[0398] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the ninth communication device discussed above.
[0399] In an aspect, a computer program comprising instructions, the instructions, when executed on at least one processor, causing the at least one processor to perform the method implemented by the tenth communication device discussed above.
[0400] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representation, it will be appreciated that the blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0401] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the process or method as described above with reference to FIGS. 1 to 21. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0402] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0403] The above program code may be embodied on a machine readable medium, which may be any tangible medium that may contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine readable medium may be a machine readable signal medium or a machine readable storage medium. A machine readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0404] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0405] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
A first communication device comprising:a processor configured to cause the first communication device to:transmit, to a second communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation; andreceive, from the second communication device, a first response indicating a security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.The device of claim 1, wherein the first communication device is further caused to:receive, from the second communication device, information about a second security capability of the second communication device with respect to the AIoT operation; andtransmit the first security capability of the first communication device to the second communication device, wherein the first security capability is associated with the same security level as the second security capability.The device of claim 2, wherein the information about the security capability of the second communication device is received via a broadcasting signal, and / orwherein the broadcasting signal comprising at least one of an AIoT paging signal or a system information block (SIB) .The device of any of claims 1 to 3, wherein the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / orwherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the first response comprises an indication indicating that the AIoT operation is allowed to be performed with security.The device of any of claims 1 to 4, wherein the AIoT operation is related to at least one of an inventory procedure or a command procedure.The device of any of claims 1 to 5, wherein the first communication device comprises an AIoT device, and the second communication device comprises a reader.A second communication device comprising:a processor configured to cause the second communication device to:in response to receiving, from a first communication device, a first request indicating a first security capability of the first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a third communication device, a second request indicating the first security capability of the first communication device; andin response to receiving, from the third communication device, a second response indicating a security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the first communication device, a first response indicating the security level at which the AIoT operation is allowed to be performed, the security level being associated with the first security capability.The device of claim 7, wherein the second communication device is further caused to:transmit, to the first communication device, information about a second security capability of the second communication device with respect to the AIoT operation, wherein the first security capability is associated with the same security level as the second security capability.The device of claim 7 or 8, wherein the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the first response and the second response each comprise an indication indicating that the AIoT operation is allowed to be performed without security, and / orwherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the first response and the second response each comprise an indication indicating that the AIoT operation is allowed to be performed with security.The device of claim 7 or 8, wherein the AIoT operation is related to at least one of an inventory procedure or a command procedure.The device of any of claims 7 to 10, wherein the first communication device comprises an AIoT device, the second communication device comprises a reader, and the third communication device comprises an AIoT controller.A third communication device comprising:a processor configured to cause the third communication device to:in response to receiving, from a second communication device, a second request indicating a first security capability of a first communication device with respect to an ambient internet of things (AIoT) operation, transmit, to a fourth communication device, a third request indicating that a security level associated with the first security capability is request for the first communication device; andin response to receiving, from the fourth communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device, transmit, to the second communication device, a second response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.The device of claim 12, wherein the third communication device is further caused to:obtain subscription information of the first communication device; andtransmit the third request to the fourth communication device based on the subscription information.The device of claim 13, wherein the third communication device is further caused to:transmit, to a fifth communication device, a fourth request for subscription information of the first communication device; andreceive, from the fifth communication device, a fourth response comprising the subscription information.The device of claim 13 or 14, wherein the subscription information comprises at least one of:an indication indicating that the AIoT operation is allowed to be performed at the security level,location information indicating an area in which the AIoT operation is allowed to be performed at the security level,reader information indicating at least one reader connecting to the first communication device, orinformation about the fourth communication device.The device of any of claims 12 to 15, wherein the third request comprises at least one of:an indication indicating the security level is requested,location information indicating an area in which the security level is requested, orreader information indicating at least one reader connecting to the first communication device.The device of any of claims 12 to 16, wherein the third response comprises at least one of:an indication indicating that the AIoT operation is allowed to be performed at the security level,location information indicating an area in which the AIoT operation is allowed to be performed at the security level, orreader information indicating at least one reader connecting to the first communication device.The device of any claims 12 to 17, wherein the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the second response and the third response each comprise an indication indicating that the AIoT operation is allowed to be performed without security, and / orwherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the second response and the third response each comprise an indication indicating that the AIoT operation is allowed to be performed with security.The device of any of claims 12 to 18, wherein the AIoT operation is related to at least one of an inventory procedure or a command procedure.The device of any of claims 12 to 19, wherein the first communication device comprises an AIoT device, the second communication device comprises a reader, the third communication device comprises an AIoT controller, the fourth communication device comprises a device implementing an Application Function (AF) , and the fifth communication device comprises a device implementing an AIoT device management function.A fourth communication device comprising:a processor configured to cause the fourth communication device to:receive, from a third communication device, a third request indicating a security level is requested for a first communication device to perform an ambient internet of things (AIoT) operation, the security level being associated with a first security capability of the first communication device; andtransmit, to the third communication device, a third response indicating the security level at which the AIoT operation is allowed to be performed by the first communication device.The device of claim 21, wherein the third request comprises at least one of:an indication indicating the security level is requested,location information indicating an area in which the security level is requested, orreader information indicating at least one reader connecting to the first communication device.The device of claim 21 or 22, wherein the third response comprises at least one of:an indication indicating that the AIoT operation is allowed to be performed at the security level,location information indicating an area in which the AIoT operation is allowed to be performed at the security level, orreader information indicating at least one reader connecting to the first communication device.The device of any claims 21 to 23, wherein the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / orwherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed with security.The device of any of claims 21 to 24, wherein the AIoT operation is related to at least one of an inventory procedure or a command procedure.The device of any of claims 21 to 25, wherein the first communication device comprises an AIoT device, the third communication device comprises an AIoT controller, and the fourth communication device comprises a device implementing an Application Function (AF) .A fifth communication device comprising:a processor configured to cause the fifth communication device to:receive, from a third communication device, a fourth request for subscription information of a first communication device; andtransmit, to the third communication device, a fourth response comprising the subscription information, the subscription information indicating a security level at which an ambient internet of things (AIoT) operation is allowed to be performed by the first communication device, the security level being associated with the first security capability of the first communication device.The device of claim 27, wherein the subscription information comprises at least one of:an indication indicating that the AIoT operation is allowed to be performed at the security level,location information indicating an area in which the AIoT operation is allowed to be performed at the security level,reader information indicating at least one reader connecting to the first communication device, orinformation about a fourth communication device for authorization.The device of claim 27 or 28, wherein the security level is a first security level indicating that the first communication device supports a no-security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed without security, and / orwherein the security level is a second security level indicating that the first communication device supports a security AIoT operation, and the third response comprises an indication indicating that the AIoT operation is allowed to be performed with security.The device of any of claims 27 to 29, wherein the AIoT operation is related to at least one of an inventory procedure or a command procedure.The device of any of claims 27 to 30, wherein the first communication device comprises an AIoT device, the third communication device comprises an AIoT controller, the fourth communication device comprises a device implementing an Application Function (AF) , and the fifth communication device comprises a device implementing an AIoT device management function.A sixth communication device comprising:a processor configured to cause the sixth communication device to:transmit, to a seventh communication device, a sixth request for a security mechanism switching associated with an ambient internet of things (AIoT) operation, wherein the security mechanism switching comprises switching on or switching off a security mechanism in an eighth communication device.The device of claim 32, wherein the sixth communication device is further caused to:receive, from the seventh communication device, a sixth response to the sixth request, wherein the sixth response comprises information indicating a security operation status of the eighth communication device; andtransmit, to a ninth communication device, a report comprising at least one of an indication indicating the security operation status of the eighth communication device, or a cause for the security mechanism switching.The device of claim 32 or 33, wherein the sixth request is transmitted based on a determination made by the sixth communication device, or is triggered by at least one of: the seventh communication device, the eighth communication device, a ninth communication device, or a tenth communication device.The device of any of claims 32 to 34, wherein the sixth communication device is further caused to:in response to receiving information for the security mechanism switching from a ninth communication device implementing an Application Function (AF) , transmit the sixth request to a seventh communication device, wherein the information is comprised in an AIoT operation request.The device of any of claims 32 to 34, wherein the sixth communication device is further caused to:in response to receiving information for the security mechanism switching from a tenth communication device implementing an AIoT device management function, transmit the sixth request to a seventh communication device, wherein the information is comprised in a subscription change notification related to the eighth communication device.The device of any of claims 32 to 34, wherein the sixth communication device is further caused to:in response to receiving a trigger for the security mechanism switching from the seventh communication device or from the eighth communication device, transmit the sixth request to a seventh communication device,wherein the trigger comprises at least one of: an indication of switching on or switching off the security mechanism in the eighth communication device, or a cause for the security mechanism switching.The device of claim 37, wherein the sixth communication device is further caused to:transmit an acknowledgement to the trigger to the seventh communication device or the eighth communication device.The device of any of claims 32 to 38, wherein the AIoT operation is related to at least one of an inventory procedure or a command procedure.The device of any of claims 33 to 39, wherein the sixth communication device comprises an AIoT controller, the seventh communication device comprises a reader, and the eighth communication device comprises an AIoT device.
Citation Information
Patent Citations
Wireless communication method and device, and communication equipment
CN117795860A
Authentication security device, terminal, communication system, and communication method
WO2024095485A1
Communication method and related apparatus
WO2024140467A1
Session creation for ambient internet of things communication in a wireless communication system
WO2024161044A1