Method, apparatus and system for authentication of a device
The use of a PUF-based authentication system addresses IoT device authentication challenges by ensuring secure and efficient network access through dynamic challenge-response pairs and service management, mitigating signaling congestion and physical attacks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2026-04-02
AI Technical Summary
Existing IoT device authentication methods face challenges such as signaling congestion during mass access to 5G networks, vulnerability to physical attacks, and inadequate security mechanisms, particularly for narrowband IoT devices, leading to potential decryption and impersonation risks.
A system and method utilizing a physical unclonable function (PUF) for device authentication, involving challenge-response pairs and a service provisioning management node to manage authentication and key generation, ensuring secure and efficient network access for IoT devices.
Enhances security by providing dynamic and robust authentication, reducing signaling congestion, and protecting against physical attacks, while maintaining efficient network access for IoT devices.
Smart Images

Figure CN2025088816_02042026_PF_FP_ABST
Abstract
Description
METHOD, APPARATUS AND SYSTEM FOR AUTHENTICATION OF A DEVICECROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of U.S. provisional patent application number 63 / 699, 325 filed on September 26, 2024, the contents of which are incorporated herein by reference in their entirety.TECHNICAL FIELD
[0002] The present disclosure relates generally to device authentication in a wireless communication system and in particular to methods, apparatus and systems for multiple device authentication using identification management and key management.BACKGROUND
[0003] Security issues regarding internet of things (IoT) devices require significant attention when these types of devices access a network. Currently, narrow band IoT devices (NB-IoT) reuse the existing normal user equipment (UE) ’s security mechanisms. Thus, IoT devices inherit security abilities of a normal UE. These security abilities associated with normal UEs have been deemed inconvenient for massive IoT devices (IoTDs) to initiate access requests at the same time. When massive IoTDs activate in order to connect to a fifth generation (5G) core network (5GC) at the same time, each IoT device individually needs to implement the 5G authentication and key-agreement (5G AKA) or the evolved packet system authentication and key agreement (EPS AKA) protocol with successful authentication. However, due to the large number of IoTs involved, the full access authentication process will lead to signaling congestion and, thus, cause negative experiences when providing respective IoT application services.
[0004] In addition, it is also necessary to consider the physical security of the IoT devices in different IoT scenarios. Especially when considering IoTs, these devices are typically easily accessible outdoors, for example in smart metering applications, and are thus are more vulnerable to side-channel attacks or physical attacks. Such attacks can cause secrets stored in hardware, which can include a preconfigured symmetrical key or private key, to be more easily compromised by an adversary. For example, an adversary can decrypt history encrypted information and imitate a target device in order to cause undesired consequences.
[0005] Therefore, there is a need for a method, apparatus and system for device authentication that obviates or mitigates one or more limitations of the prior art.
[0006] This background information is provided to reveal information believed by the applicant to be of possible relevance to the present disclosure. No admission is necessarily intended, nor should be construed, that any of the preceding information constitutes prior art against the present disclosure.SUMMARY
[0007] An object of embodiments of the present disclosure is to provide a system and method for device authentication based on a physical unclonable function. According to embodiments, a method is provided for authentication of a first device. The method may be performed by an identification management (IDM) node. The method includes receiving an authentication request, wherein the authentication request includes an identification information related to the first device, a first code and a second response of a second challenge-response pair related to the first device. In some embodiments, the first code is based on a first information associated with the first device, and the first information includes a first response of a first challenge-response pair related to the first device and the identification information related to the first device. The method further includes verifying the first device by comparing the identification information related to the first device with existing identification information related to the first device. In some embodiments, the comparing further includes comparing the received first code and a value calculated based on the first response related to the first device and the identification information related to the first device. The method further includes generating a first authentication information based on a second information associated with the first device. In some embodiments, the second information includes a second challenge of the second-challenge response pair related to the first device. The method further includes transmitting an authentication response message, wherein the authentication response message comprises the first authentication information.
[0008] In some embodiments, the identification information related to the first device includes at least one of a subscriber identification information of a customer related to the first device and an identifier of the first device. In some embodiments, the second response is computed at the first device by applying a physical unclonable function (PUF) to the second challenge of the second-challenge response pair related to the first device.
[0009] In some embodiments, the first code is computed at the first device by applying a function on input parameters, the input parameters including the first response related to the first device and the identification information related to the first device. In some embodiments, the input parameters further include one or more of a nonce, or the identifier of the first device.
[0010] In some embodiments, receiving the authentication request includes receiving the authentication request from a service provisioning management (SPM) node, along with information associated with the SPM node. In some embodiments, generating the first authentication information comprises generating the first authentication information based on the second information associated with the first device and the information associated with the SPM node. In some embodiments, the information associated with the SPM node comprises an identifier of the SPM node.
[0011] In some embodiments, the method further includes generating a root key parameter. In some embodiments, the method further includes transmitting the authentication response message including the root key parameter to the SPM node.
[0012] In some embodiments, the method further includes receiving an indication of successful verification of a second code. In some embodiments, the method further includes generating a root key based on the root key parameter and a third information.
[0013] In some embodiments, the third information includes at least one of a first challenge of the first challenge-response pair related to the first device, and the identifier of the first device.
[0014] In some embodiments, the method further includes generating a first credential for the first device, wherein the first credential is associated with the second response and the identification information related to the first device. In some embodiments, the first credential is used for a subsequent authentication of the first device when the first device accesses the network.
[0015] In some embodiments, the method further includes generating a second credential for a second device, wherein the second credential is associated with a first response of a first challenge-response pair related to the second device and identification information related to the second device. In some embodiments, the method further includes transmitting a message, wherein the message includes the first credential for the first device, the second credential for the second device, the identification information related to the first device and the identification information related to the second device, and a second challenge of a second challenge-response pair related to the second device.
[0016] According to embodiments, a method is provided for authentication of a first device. The method may be performed by an SPM node. The method includes receiving an authentication request from the first device, wherein the authentication request includes an identification information related to the first device, a first code and a second response of a second challenge-response pair related to the first device. In some embodiments, the first code is based on first information associated with the first device, and the first information includes a first response of a first challenge-response pair related to the first device and the identification information related to the first device. The method further includes transmitting, to an IDM node, the authentication request and information associated with the SPM node. The method further includes receiving, from the IDM node, an authentication response message. In some embodiments, the authentication response message includes a first authentication information, wherein the IDM node generates the first authentication information based on a second information associated with the first device and the information associated with the SPM node. In some embodiments, the second information includes a second challenge of the second-challenge response pair related to the first device.
[0017] In some embodiments, the identification information related to the first device includes at least one of a subscriber identification information of a customer related to the first device and an identifier of the first device. In some embodiments, the information associated with the SPM node comprises an identifier of the SPM node.
[0018] In some embodiments, the method further includes receiving a third challenge of a third challenge-response pair related to the first device and a root key parameter. In some embodiments, the method further includes generating a second authentication information with the information associated with the SPM node. In some embodiments, the method further includes transmitting a response message to the first device, wherein the response message includes the third challenge, the second authentication information, the root key parameter, and the information associated with the SPM node.
[0019] In some embodiments, the method further includes receiving a second code. In some embodiments, the method further includes verifying the second code. In some embodiments, the method further includes transmitting an indication of successful verification of the second code to the IDM node. In some embodiments, the first device generates the second code using the identification information related to the first device and the second authentication information.
[0020] In some embodiments, the method further includes receiving a message from the IDM node, wherein the message includes a first credential for the first device, a second credential for a second device, the identification information related the first device and identification information related to the second device, a root key associated with the root key parameter, and a second challenge of a second challenge-response pair related to the second device. In some embodiments, the method further includes storing at a local cache one or more of: the first credential for the first device, the second credential for the second device, the identification information related to the first device and the identification information related to the second device, the root key, the second challenge of the second challenge-response pair related to the second device, and the third challenge of the third challenge-response pair related to the first device
[0021] In some embodiments, the method further includes generating a first device key parameter for a first device key associated with the first device. In some embodiments, the method further includes transmitting the first device key parameter to the first device. In some embodiments, the first device key parameter comprises at least one of the identifier of the first device, the identifier of the SPM node and a session identifier. In some embodiments, the first device generates a root key using the received root key parameter and generates a first device key based on the first device key parameter. In some embodiments, the SPM node and the first device communicate with each other through the C / M-GW.
[0022] According to embodiments, a method is provided for authentication of a second device. The method may be performed by an SPM node. The method includes receiving an authentication request from the second device. In some embodiments, the authentication request includes an identification information related to the second device (e.g., PSRID, &ID of device) , a first code and a second response of a second challenge-response pair related to the second device. In some embodiments, the first code is based on a first information associated with the second device. In some embodiments, the first information includes a first response of a first challenge-response pair related to the second device and the identification information related to the second device (e.g., PSRID) . The method further includes verifying the second device by comparing the received first code and a value calculated based on the first response related to the second device and the identification information related to the second device. The method further includes generating a first authentication information based on a second information associated with the second device. In some embodiments, the second information includes a second challenge of the second challenge-response pair related to the second device and information associated with the SPM node. The method further includes transmitting an authentication response to the second device. In some embodiments, the authentication response includes the first authentication information and the information associated with the SPM node.
[0023] In some embodiments, the identification information related to the second device includes a subscriber identification information of a customer related to the second device and an identifier of the second device. In some embodiments, the information associated with the SPM node includes an identifier of the SPM node.
[0024] In some embodiments, the method further includes generating a third challenge of a third challenge-response pair related to the second device. In some embodiments, transmitting the authentication response includes transmitting the authentication response including the third challenge related to the second device.
[0025] In some embodiments, the second device computes the second response by applying a PUF to the second challenge of the second-challenge response pair related to the second device. In some embodiments, the second device computes the first code by applying a function on input parameters, wherein the input parameters include the first response related to the second device and the identification information related to the second device. In some embodiments, the input parameters further include one or more of a nonce, or an identifier of the second device.
[0026] In some embodiments, the method further includes receiving an indication of successful verification from the second device. In some embodiments, the method further includes generating a device key parameter for a device key, wherein the device key parameter includes at least one of the identifier of the second device, the identifier of the SPM node, or a session identifier.
[0027] In some embodiments, the method further includes generating a credential for the second device, wherein the credential is associated with the second response related to the second device and an existing credential of the second device. In some embodiments, the method further includes transmitting the device key parameter to the second device. In some embodiments, the second device generates the device key based on an existing root key and the received device key parameter.
[0028] In some embodiments, the SPM node and the second device communicate with each other through the C / M-GW.
[0029] According to embodiments, a method is provided for authenticating (or dynamically authenticating) a first device. The method may be performed by an SPM node. The method includes receiving a message, wherein the message includes an identification information associated with the first device, a code, and a third response of a third challenge-response pair related to the first device. In some embodiments, the code is based on first information associated with the first device, wherein the first information includes a second response of a second challenge-response pair related to the first device, identification information associated with the first device (e.g., PSRID) and information associated with the SPM node. The method further includes verifying the first device by comparing the received code and a value calculated based on the second response related to the first device, the identification information associated with the first device and the information associated with the SPM node. The method further includes generating a credential for the first device, wherein the credential is associated with the third response of the third challenge-response pair related to the first device and an existing credential for the first device. The method further includes generating a fourth challenge of a fourth challenge-response pair related to the first device. The method further includes transmitting to the first device the fourth challenge related to the first device.
[0030] In some embodiments, the identification information associated with the first device includes at least one of a subscriber identification information of a customer related to the first device and an identifier of the first device. In some embodiments, the information associated with the SPM node includes an identifier of the SPM node.
[0031] In some embodiments, the method further includes generating a device key parameter for a device key of the first device. In some embodiments, the method further includes transmitting to the first device the device key parameter.
[0032] In some embodiments, the first device computes the third response by applying a PUF to a third challenge of the third challenge-response pair related to the first device. In some embodiments, the first device computes the code by applying a function to the identification information associated with the first device (e.g., PSRID) , the second response related to the first device and the information associated with the SPM node. In some embodiments, the first device generates a new device key for the first device based on an existing root key.
[0033] In some embodiments, the first device and the SPM node communicate with each other through the C / M-GW.
[0034] According to another aspect, a (e.g. non-transitory) computer readable medium, computer program, or computer program product, comprising stored thereon statements and instructions which, when executed by a computer processor perform one or more methods described herein.
[0035] According to another aspect, an apparatus or system is provided, where the apparatus includes modules configured to perform one or more methods described herein. According to another aspect, another apparatus or system is provided that includes computing electronics and is configured to perform the methods described herein. According to another aspect, another apparatus is provided that includes processing and wireless communication electronics and is configured to operate as described herein.
[0036] According to another aspect, a method is provided for execution by processing and wireless communication electronics. The method includes performing operations as described herein. In some embodiments a computer program product is provided. The computer program product includes a non-transitory computer readable medium having recorded thereon statements and instructions which, when executed by a computer, cause the computer to perform one or more methods described herein.
[0037] According to another aspect, a chip is provided, where the chip includes a processor and a data interface, and the processor reads, by using the data interface, an instruction stored in a memory, to perform the different aspects described herein.
[0038] Other aspects of the application provide for apparatus, and systems configured to implement the methods according to the different aspects disclosed herein. For example, wireless stations and access points can be configured with machine readable memory containing instructions, which when executed by the processors of these devices, configures the device to perform the methods disclosed herein.
[0039] Embodiments have been described above in conjunctions with aspects of the present disclosure upon which they can be implemented. Those skilled in the art will appreciate that embodiments may be implemented in conjunction with the aspect with which they are described, but may also be implemented with other embodiments of that aspect. When embodiments are mutually exclusive, or are otherwise incompatible with each other, it will be apparent to those skilled in the art. Some embodiments may be described in relation to one aspect, but may also be applicable to other aspects, as will be apparent to those of skill in the art.BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Further features and advantages of the present disclosure will become apparent from the following detailed description, taken in combination with the appended drawings, in which:
[0041] FIG. 1 is a call flow diagram for customer registration, according to embodiments of this disclosure.
[0042] FIG. 2 is a flow diagram for full initial and mutual authentication with a master device, according to embodiments of this disclosure.
[0043] FIG. 3 is a call flow diagram for a full initial and mutual authentication based on a master device, according to embodiments of this disclosure.
[0044] FIG. 4 is a call flow diagram for provisioning of a root key to a group of devices by a master device, according to embodiments of this disclosure.
[0045] FIG. 5 is a flow diagram for partial initial and mutual authentication based on a master device, according to embodiments of this disclosure.
[0046] FIG. 6 is a call flow diagram for partial initial and mutual authentication based on a master device, according to embodiments of this disclosure.
[0047] FIG. 7 is a flow diagram for mutual authentication without a master device, according to embodiments of this disclosure.
[0048] FIG. 8 is a call flow diagram for full initial and mutual authentication without a master device, according to embodiments of this disclosure.
[0049] FIG. 9 is a flow diagram for partial initial and mutual authentication without a master device, according to embodiments of this disclosure.
[0050] FIG. 10 is a call flow diagram for partial initial and mutual authentication without a master device, according to embodiments of this disclosure.
[0051] FIG. 11 is a flow diagram for dynamic partial authentication, according to embodiments of this disclosure.
[0052] FIG. 12 is a call flow diagram for dynamic partial mutual authentication, according to embodiments of this disclosure.
[0053] FIG. 13A is a method for authenticating a first device, according to embodiments of this disclosure.
[0054] FIG. 13B illustrates another method for authenticating a first device, according to embodiments of this disclosure.
[0055] FIG. 13C illustrates a method for authenticating a second device, according to embodiments of this disclosure.
[0056] FIG. 13D illustrates a method for dynamically authenticating a first device, according to embodiments of this disclosure.
[0057] FIG. 14 illustrates an example communication system, according to embodiments of this disclosure.
[0058] FIG. 15 illustrates an example apparatus, according to embodiments of this disclosure.
[0059] FIG. 16A illustrates another example apparatus, according to embodiments of this disclosure.
[0060] FIG. 16B illustrates another example apparatus, according to an embodiments of this disclosure.
[0061] It will be noted that throughout the appended drawings, like features are identified by like reference numerals.DETAILED DESCRIPTION
[0062] Embodiments of the present disclosure provide for systems, methods and apparatus for device authentication based on a physical unclonable function (PUF) . According to embodiments, a method is provided for authenticating a first device. The method may be carried out by an identification management (IDM) node. The method includes receiving an authentication request that contains identification information related to the first device, a first code, and a second response from a second challenge-response pair associated with the first device. In certain embodiments, the first code is derived from first information linked to the first device. This first information includes both the first response of a first challenge-response pair and the identification information of the first device. The method then verifies the first device by comparing its identification information with existing identification records. In some embodiments, this comparison also involves checking the received first code against a computed value based on the first response and the identification information of the first device. Next, the method includes generating first authentication information using second information related to the first device. In some cases, this second information includes the second challenge of the second challenge-response pair. Further, the method includes transmitting an authentication response message containing the first authentication information.
[0063] According to some embodiments, another method is provided for authenticating a first device. The method may be carried out by a service provisioning management (SPM) node. The method includes receiving an authentication request from the first device. The authentication request includes identification information associated with the first device, a first code, and a second response corresponding to a second challenge-response pair related to the first device. In certain embodiments, the first code is generated based on first information linked to the first device. This first information includes a first response from a first challenge-response pair related to the first device and the device’s identification information. The method further includes transmitting the authentication request, along with information related to the SPM node, to an IDM node. The SPM node then receives an authentication response message from the IDM node. In some embodiments, the authentication response message contains first authentication information. The IDM node generates this first authentication information based on second information associated with the first device and the information related to the SPM node. The second information may include a second challenge from the second challenge-response pair related to the first device.
[0064] According to some embodiments, a method is provided for authenticating a second device. The method may be performed by an SPM node. The method includes receiving an authentication request from the second device. The authentication request includes identification information related to the second device (e.g., PSRID, device ID) , a first code, and a second response corresponding to a second challenge-response pair associated with the second device. In certain embodiments, the first code is generated based on first information linked to the second device. This first information includes a first response from a first challenge-response pair related to the second device and its identification information (e.g., PSRID) . The method further includes verifying the second device by comparing the received first code with a calculated value. This value may be determined using the first response related to the second device and its identification information. The method may further involve generating first authentication information based on second information associated with the second device. In some embodiments, this second information includes a second challenge from the second challenge-response pair related to the second device, along with information associated with the SPM node. The method may further include transmitting an authentication response to the second device. In some embodiments, this response contains the first authentication information and the information associated with the SPM node.
[0065] According to some embodiments, a method is provided for authenticating (or dynamically authenticating) a first device. The method may be performed by an SPM node. The method includes receiving a message from the first device. This message may contain identification information associated with the first device, a code, and a third response corresponding to a third challenge-response pair related to the first device. In certain embodiments, the code is generated based on first information linked to the first device. This first information includes a second response from a second challenge-response pair associated with the first device, the device’s identification information (e.g., PSRID) , and information related to the SPM node. The method may further include verifying the first device by comparing the received code with a calculated value. This value may be determined using the second response related to the first device, its identification information, and the information associated with the SPM node. The method may further involve generating a credential for the first device. This credential may be linked to both the third response of the third challenge-response pair and an existing credential associated with the first device. The method may also include generating a fourth challenge as part of a fourth challenge-response pair related to the first device. Finally, the method includes transmitting this fourth challenge to the first device.
[0066] Considering the connection of massive internet of things (IoT) devices (IoTDs) in wireless networks, including new radio (NR) and sixth generation (6G) networks, access to the network may be managed via one or more control / management (C / M) gateways (C / M-GWs) . In some embodiments, a function, termed service provisioning management (SPM) , is responsible for authentication and key management for wireless network access. In some embodiments, a trust function, termed identifier management or identification management (IDM) , is responsible for identifier (ID) management and user identification.
[0067] A device-level technology approach for safeguarding data involves the use of a physical unclonable function (PUF) . While silicon production processes are precise, for example with respect to the production of integrated circuits (IC) , PUF technology exploits the fact that there are still tiny variations in each circuit produced. PUF is a lightweight security solution that uses these tiny differences in IC production to generate a unique digital value that can be used as a secret key. PUF can be used to improve security associated with IoT systems, wherein device authentication is an important task. PUF operates using one or more challenge-response pair (s) (CRPs) , where a challenge “C” is applied to the PUF system. This challenge reacts with the components of the PUF system in a way that produces an unpredictable and random response “R” .
[0068] At present, some PUF-based secure authentication and communication methods have been proposed for IoT. Currently, a PUF-based communication architecture is presented, where all IoT nodes are integrated with a PUF instance, and the protocol, with the help of PUF, enables authentication and public key exchange among different data nodes and server nodes. In addition, the scheme introduces a modified identity-based encryption (IBE) scheme against repudiation attacks in which the response of the PUF is regarded as the public identity to solve secure communication between two data nodes. Another PUF, called radio frequency (RF) -PUF, uses the effects of inherent process variations on RF properties of the wireless transmitters (Tx) . This allows real-time authentication of wireless nodes detected through in-situ machine learning at the receiver (Rx) end. It is noted that the method can be employed for enhanced physical layer security for IoT.
[0069] It has been realized that existing solutions usually support 5GAKA or EAP-TLS. These solutions are usually static authentication which means that certificates or credentials are not changed. However, it has been realized that these static authentication methods may not be suitable for devices, in particular when considering IoT devices.
[0070] Additionally, it has also been realized that existing solutions based on PUF also provide static authentication because both the device and the trust authority (TA) keep only one CRP pair. It has been realized that this configuration is not safe for devices, in particular when considering IoT devices.
[0071] In some embodiments, there are provided methods wherein devices, for example IoT devices, can be formed into a group, wherein one of the devices of the group can be selected as a master device or group leader for authentication of the devices with a wireless network. In some embodiments, there are provided methods wherein there is no group leader or master device and each of the devices is considered equal during an authentication procedure.
[0072] According to embodiments, the instant disclosure focuses on multiple device authentication based on PUF. According to embodiments, this disclosure provides methods about a full mutual authentication for a master device (e.g. a group leader) and a partial mutual authentication for other devices (e.g. group members) . In some embodiments, after a successful authentication, all devices have the same root key, but each device has its own device key derived from the same root key. According to embodiments, this disclosure also provides methods about a full mutual authentication without a master device and a partial mutual authentication for other devices. In some embodiments, after successful authentication, each device has its own root key and its own device key, which is derived from the root key. In addition, in some embodiments, the present disclosure provides dynamic authentication for devices to dynamically access a network.
[0073] According to embodiments, device authentication involves a customer or a user registering with the network on behalf of one or more devices. In some embodiments, the customer manages the one or more devices. In some embodiments, a first device implements a full initial and mutual authentication. In such embodiments, when the device initially accesses a network or system, a mutual authentication is implemented or performed between the device and the network or system, wherein the mutual authentication involves a trust function termed IDM. In some embodiments, a following device implements a partial initial and mutual authentication. In such embodiments, when the device initially accesses the network or system, mutual authentication is implemented or performed between the device and the network or system without involving a trust function termed IDM. In some embodiments, a dynamic credential is used for dynamical and mutual authentication between the device and the network or system.
[0074] According to embodiments, one or more devices may be authenticated by the network based on PUF. One or more embodiments may include or relate to customer registration, authentication based on master device or group leader, authentication without master device, and dynamic authentication. Customer Registration
[0075] According to embodiments, in this customer registration procedure, a customer registers with the network via Wi-Fi or another access point. In some embodiments, IDM generates a list of IDs for devices and obtains a CRP pair, e.g., (C, R) , for each device. In some embodiments, the customer obtains a list of IDs of the devices, a basic profile, and assigns them to the devices.
[0076] According to embodiments, a pre-condition regarding this customer registration method is that the customer has multiple devices, and these devices support PUF functionality. In some embodiments, the customer obtains an ID from the IDM, which may be termed a preservation subscriber real identifier (PSRID) , and a basic profile from the network. In some embodiments, the basic profile includes basic information of the customer (e.g., device information, main applications (which may be optional (not mandatory) ) , and a geographic area where the customer’s devices are mobile. In some embodiments, each device keeps or stores one or more of: a current response R, a next challenge C, the PSRID, the ID of the device, and the basic profile. In some embodiments, the IDM keeps a list of current responses R associated with the devices, a list of next challenges C associated with the devices, a list of IDs of the device, the PSRID, and the basic profile.
[0077] FIG. 1 is a call flow diagram for customer registration, according to embodiments of this disclosure. As illustrated, the call flow or method 100 for customer registration involves actions performed and communication between a group of devices 130, a customer 132 and an IDM 133, for example, a CONsortium of NETworks-IDM (CONET-IDM) .
[0078] According to embodiments, customer registration according to method 100 commences when a customer 132 sends a request 101 to an IDM 133 for registration. The request may include identification information (e.g., passport) and an indication of a number of devices belonging to the customer for registration. This request may indicate the services required from the network. In some embodiments, at 102, the method includes the IDM 133 verifying the identification information with the involvement of the government’s database. In some embodiments, at 103, the method includes the IDM 133 generating an ID for the customer, e.g., PSRID. The PSRID may not disclose the real ID of the customer 132 and could be used by the network to identify the customer 132. In some embodiments, at 103, the IDM 133 further generates a list of IDs for the devices. These IDs for devices could be random numbers or sequences. In some embodiments, at 103, the IDM 133 further generates a list of first challenges C (i, j) corresponding to a list of first CRPs, where j = 1, …, n. Here, “i” indexes times of implementing authentication (or indicative of time) , “j” indexes name of a device (or indicative of a particular device) . The value “n” could be the number of the devices 130 belonging to the customer 132. In some embodiments, at 104, the method further includes the IDM 133 obtaining a basic profile based on the request from the network. In some embodiments, the IDM 133 sends a response 105 to the customer. The response may include one or more of the list of first challenges C (i, j) , j=1, …, n, the list of IDs of the devices, the PSRID, and the basic profile.
[0079] According to embodiments, at 106, the customer 132 assigns each device, for example, a first device, device j, of the group of devices 130 a first challenge C (i, j) of a first CRP, an ID of device j, the PSRID and the basic profile. The first device, device j, may serve as the master device or group leader of the group of devices 130. In some embodiments, at 107, each device, for example, the first device, device j, generates a first response R (i, j) by applying a PUF to the first challenge C (i, j) , such that R (i, j) = PUF (C (i, j) ) . In some embodiments, each device, for example, the first device, device j, sends a message 108 to the customer. This message may include the first response R (i, j) .
[0080] According to embodiments, upon receiving a list of first responses R (i, j) , j=1, …, n, the customer 132 sends a message 109 including the list of first responses R (i, j) , where j = 1 , …, n to the IDM 133. In some embodiments, at 110, the IDM 133 store, maintains or keeps the list of first responses R (i, j) , j=1, …, n and generates a list of second challenges C (i+1, j) corresponding to a list of second CRPs, j=1, …, n. The IDM 133 sends a message 111 including the list of second challenges C (i+1, j) , where j = 1, …, n to the customer 132.
[0081] According to embodiments, the customer 132 sends a message 112 including a respective second challenge C (i+1, j) to each device, for example, the first device, device j. In some embodiments, at 113, each device, for example, the first device, device j, keeps the second challenge C (i+1, j) and the first response R (i, j) . Mutual Authentication Based on a Master Device
[0082] According to some embodiments, mutual authentication is based on a master device or group leader. In some embodiments, a mater device (or a first device) performs a full initial and mutual authentication with the network, where the mutual authentication is performed between the first device and the network and involves a trust function termed IDM. In some embodiments, a following or a second device performs a partial initial and mutual authentication, where mutual authentication is performed between the second device and the network without involving the IDM. In some embodiments, in the full initial and mutual authentication, a master device or group leader initially accesses the network, and an SPM triggers the full mutual authentication with involvement of the IDM. In some embodiments, both the master device and the SPM have a root key. In some embodiments, the SPM downloads processed credentials from the IDM, where the credentials are related to the devices and the SPM. In some embodiments, the master device sends the root key to the other devices that belong to the customer, for example, the other devices of the group. In some embodiments, in the partial initial and mutual authentication, another or a second device initially accesses the network, wherein the SPM triggers a mutual authentication without the involvement of the IDM. In some embodiments, the device generates a device key that is derived from the root key.
[0083] According to embodiments, a master device is selected or determined. This master device may initially access the network, and the network may trigger a mutual authentication procedure. According to embodiments, the mutual authentication procedure includes using one or more CRPs including a current or a first CRP pair and a next or a second CRP pair. In some embodiments, the current or first response R (i, j) of the current CRP is used for authenticating a device j of a group of devices. In some embodiments, the next or second challenge C (i+1, j) of the second CRP is used for authenticating the SPM, wherein i is the time index, and j is the device index. In some embodiments, a credential for a device can be associated with the current CRP pair and the PSRID. In some embodiments, the credentials for all devices can be aggregated or batched. In some embodiments, after successful authentication, one or more next credentials for one or more devices of the group of devices can be generated. These next credentials may be used to authenticate the one or more devices when the SPM triggers a new authentication procedure. In some embodiments, all devices have the same root key, wherein the root key is associated with the master device. In some embodiment, a device key for each device can be derived from the root key. In some embodiments, a device may have its own root key and its own device key that is derived from the root key.
[0084] FIG. 2 is a flow diagram illustrating a method for a full initial and mutual authentication with a master device, according to embodiments of this disclosure. The method 200 includes, at 201, the SPM triggering a full initial and mutual authentication between the master device (afirst device or device j) and an IDM. In some embodiments, the IDM verifies a first code associated with a first information associated with the master or first device. The first information includes a first response, R (i, j) of a first CRP related to the first device and identification information related to the first devices. In some embodiment. In some embodiments, the first device, device j, verifies the SPM with a second challenge C (i+1, j) of a second CRP.
[0085] In some embodiments, after successful authentication, at 202, method 200 includes the master device and the SPM obtaining or negotiating a root key. In some embodiments, at 203, method further includes the master device generating a device key that is derived from the root key. In some embodiments, at 204, the method further includes the other devices obtaining the root key, where the master device sends the root key to the other devices belonging to the customer.
[0086] In some embodiments, when a second or another device, device j+1, initially accesses the network, at 205, the method further includes the SPM triggering a partial initial and mutual authentication between the second device, device j+1, and the SPM. In some embodiments, the SPM verifies a code that is based on information associated with the second device. The information may include a first response, R (i, j+1) , of a first CRP related to the second device, device j+1. In some embodiments, the second device verifies the SPM with a second challenge C (i+1, j+1) of a second CRP associated with the second device. In some embodiments, after successful authentication, at 206, the second device, device j+1, generates a device key that is derived from the root key.
[0087] According to some embodiments, one or more preconditions may be needed for full initial and mutual authentication involving a master device. In some embodiments, a precondition may be that the customer is registered with the network and has a PSRID. In some embodiments, a precondition may be that a master device or a group leader is selected or determined. In some embodiments, a precondition may be that the master device or group leader initially accesses the network before the other devices in the group of devices. As such, other devices access the network after the master device or group leader. In some embodiments, the first device that initially accesses the network is a master device or a group leader. For example, device j may be designated as the master device, where j=1.
[0088] According to some embodiments, device j stores, maintains or keeps one or more of: CRPs associated with device j, a third challenge C (i+2, j) of a third CRP associated with device j, a second response, R (i+1, j) of a second CRP associated with device j, a root key, a device key for the device j, an ID of device j, a basic profile, a PSRID, a Subscriber Temporary Identifier (STID) , and an SPM ID, where i =1. According to some embodiments, the SPM stores, maintains or keeps one or more of: the third challenge C (i+2, j) of a third CRP associated with the device j, credentials, the PSRID, the ID of device j, the root key, the device key for the device j, and a list of second challenges C (i+1, j+1) corresponding to a list of CRPs, where j=1, …, n-1.
[0089] FIG. 3 is a call flow diagram for a full initial and mutual authentication based on a master device, according to embodiments of this disclosure. The call flow illustrating a method 300 is defined using a first device, device j 330, a C / M-GW 331, an SPM node or SPM 332 and a trust IDM function (IDM 133) .
[0090] According to embodiments, method 300 includes, at 301, computing at a first device, device j 330, a second response R (i+1, j) of a second CRP related to the first device. In some embodiments, the second response is obtained by applying a PUF to a second challenge of the second CRP related to the first device, such that R (i+1, j) = PUF (C (i+1, j) . In some embodiments, the first device further computes a first code by applying a function on input parameters. The input parameters may include a first response R (i, j) of a first CRP related to the first device and identification information related to the first device, such as a PSRID or an ID of the first device. The input parameters may further include a nonce, or an ID of the first device (an ID of device j) . For example, the first code may be computed as follows: first code = H (R (i, j) ||PSRID) , where H is a hash function. In some embodiments, the first code is based on a first information associated with the first device, wherein the first information includes the first response of the first CRP related to the first device and the identification information related to the first device. The identification information related to the first device comprises at least one of a subscriber identification information of a customer related to the first device (PSRID) and an identifier of the first device.
[0091] In some embodiments, the first device, device j 330, sends an authentication request message 302 to the C / M-GW 331. The authentication request message includes the identification information related to the first device including the PSRID and the ID of the first device. The authentication request message may further include the first code and the second response. In some embodiments, the C / M-GW 331 selects an SPM 332 and forwards the authentication request 302 to the SPM 332, wherein the authentication request message 302 includes one or more of: the PSRID, the ID of device j, the first code, and the second response R (i+1, j) . In some embodiments, the SPM 332 sends a second authentication request message 303 to the IDM 133. This second authentication request message 303 may include one or more information elements in the authentication request 302 including one or more of: the PSRID, the ID of device j, the first code, the second response R (i+1, j) . The second authentication request message 303 may further include information associated with the SPM node, e.g., SPM ID.
[0092] According to embodiments, at 304, the method 300 further includes the IDM 133 verifying the first device by comparing the identification information related to the first device, e.g., the PSRID, with an existing identification information related to the first device, e.g., a “PSRID” in the IDM’s storage. In some embodiments, the IDM 133 further verifies the first device, device j, by comparing the received first code and a value calculated based on the first response, R (i, j) , related to the first device and the identification information related to the first device, PSRID. For example, the calculated value may be based on its input (termed as R (i, j) ||PSRID) . In some embodiments, at 304, the IDM obtains a second challenge C (i+1, j) of a second CRP that is mapped to or associated with the first device, device j.
[0093] In some embodiments, at 304, the IDM further generates a first authentication (auth) information that may be used for validating the SPM. In some embodiments, the first authentication information is generated based on a second information associated with the first device, wherein the second information includes a second challenge C (i+1, j) of a second CRP related to the first device. In some embodiments, the first authentication information is further generated based on information associated with the SPM node, SPM ID. In some embodiments, the first authentication information is an output of a function. The input to this function may include the second challenge C (i+1, j) and the SPM ID. For example, the first authentication information may be computed as: first authentication = H (C (i+1, j) ||SPM ID) , wherein H is a hash function. As used herein, the terms 'authentication' and 'auth' are used interchangeably to refer to the same concept.
[0094] In some embodiments, at 304, the IDM generates a parameter for a root key or a root key parameter. In some embodiments, the root key parameter may include one or more of: a nonce, time value i, and other information (e.g., the SPM ID, the PSRID, or the ID of the device (or device ID) ) . In some embodiments, the IDM further generates a third challenge C (i+2, j) of a third CRP related to the first device.
[0095] In some embodiments, the IDM 133 sends an authentication response message 305 to the SPM 332. The authentication response message may include one or more of: the third challenge C (i+2, j) , the first authentication information, and the parameter for the root key.
[0096] According to embodiments, at 306, the method further includes the SPM 332 generating a second authentication information based on one or more of: the information associated with the SPM node and the received first authentication information. For example, the second authentication information may be computed as: second authentication information =H (first auth||SPM ID) , where H is a hash function.
[0097] In some embodiments, the SPM 332 sends a response message 307 to the first device, device j 330, via the C / M-GW 331. This response message may include one or more of: the third challenge C (i+2, j) , the second authentication information, the information associated with the SPM node (e.g., SPM ID) , and the parameter for the root key.
[0098] In some embodiments, at 308, the method includes the first device, device j 330, verifying the second authentication information based on one or more of: the SPM ID, and the second challenge C (i+1, j) . In some embodiments, the first device verifies the SPM via verifying the second authentication information. In some embodiments, at 308, the first device, device j 330, may generate a second code using the identification information related to the first device (the ID of the device j) and the second authentication information. For example, the second code may be computed as follows: second code = H (ID of the device||second auth) , where H is a hash function. In some embodiments, if the verification or validation fails, the first device, device j, sends a failure notification to the IDM. In some embodiments, upon verification or validation, the first device, device j 330, sends the second code 309 to the SPM 332 via C / M-GW 331.
[0099] According to embodiments, at 310, the method includes the SPM 332 verifying the second code. In some embodiments, if the validation fails, the SPM sends a failure notification to the IDM. In some embodiments, upon verification, the SPM 332 sends an indication of successful verification or validation of the second code 311 to the IDM 133.
[0100] In some embodiments, after a successful authentication, at 312, the method includes the IDM 133 generating a root key based on the root key parameter and a third information. In some embodiments, the third information includes at least one of the first challenge C (i, j) of the first CRP related to the first device, and the identifier of the first device.
[0101] In some embodiments, at 313, the method includes the IDM 133 generating a first credential for the first device, device j. The first credential may be associated with the second response R (i+1, j) and the identification information related to the first device, e.g., PSRID. In some embodiments, the first credential is used for a next or subsequent authentication of the first device, device j, when the device j accesses the network again.
[0102] In some embodiments, at 313, the IDM further generates one or more credentials for one or more other devices in the group of devices. Each credential of the one or more credentials may be associated with a respective first response R (i, j+1) of a first CRP related to a respective device of the one or more other devices, wherein j=1, …, n-1. Each credential of the one or more credentials may further be associated with an identification information (e.g., PSRID) related to a respective device of the one or more other devices. For example, IDM may generate a second credential for a second device, wherein the second credential is associated with a first response of a first CRP related to the second device and identification information related to the second device.
[0103] In some embodiments, the IDM may process and aggregate all credentials to obtain aggregated credentials. In some embodiments, the IDM 133 then sends to SPM 332 a message 314 comprising one or more of: the first credential for the first device, the one or more credentials for the one or more other devices (e.g., the second credential for the second device) , the aggregated credentials, the identification information related to the first device and identification information related to the second device (e.g., PSRID) , the root key, and a list of second challenges C (i+1, j+1) corresponding to a list of second CRPs related to the one or more other devices, where j=1, …, n-1 (e.g., a second challenge of a second CRP related to the second device) .
[0104] According to embodiments, at 315, the SPM 332 stores, maintains or keeps, at a local cache, information including one or more of: the generated credentials (the first credential for the first device, the one or more credentials for the one or more other devices (e.g., the second credential for the second device) , the identification information related to the first device and the identification information related to second device, aggregated credentials) , the list of second challenges C (i+1, j+1) , j=1, …, n-1, the PSRID, ID of the first device (device j) , the root key and the third challenge C (i+2, j) related to the first device. In some embodiments, at 316, the method includes the SPM 332 subsequently generating a first device key parameter for a first device key associated with the first device. In some embodiments, the first device key parameter comprises at least one of ID of the first device (device j) , the SPM ID, or a session ID, for example. In some embodiments, the SPM 332 sends the first device key parameter 317 to the C / M-GW 331.
[0105] According to embodiments, at 318, the C / M-GW 331 generates a temporary ID (termed as a STID) for the first device, device j. This temporary ID may be used for communications with the network. In some embodiments, the C / M-GW 331 sends a response message 319 to the first device. The response message may include one or more of: the temporary ID (e.g., STID) and the first device key parameter. In some embodiments, at 320, the method includes the first device, device j 330, generating 320 a root key based on one or more of: the first challenge C (i, j) and the received first device key parameter. In some embodiments, the root key generated by the first device may be the same as or similar to the root key generated by the IDM at 312. In some embodiments, the root key is used for device key derivation. In some embodiments, at 320, the first device, device j, generates the first device key based on one or more of: the root key and the received first device key parameter. As may be appreciated, both the device side and the network side use the same device key for communication between the device and the network during a session. In some embodiments, each device may have its own root key and its own device key generated from the root key, and the network may keep all different root keys of various devices. In some embodiments, after a successful mutual authentication by the first device, device j, the other devices of the group of devices can obtain the root key from device j. Each device may subsequently keep the root key for subsequent use for accessing the network.
[0106] In some embodiments, in method 300, the communication between the first device, device j 330, and the SPM 332 may be performed directly or indirectly via, for example, the C / M-GW 331.
[0107] FIG. 4 is a call flow diagram illustrating a method for provisioning a root key to a group of devices by a master device, according to embodiments of this disclosure. As illustrated, the method 400 includes, a first device, device j 330, which has been determined or selected to be a master device for a group of devices, has performed a full initial and mutual authentication and subsequently sends the root key 401 to each of the other devices in the group of devices, e.g., device j+1, device j+2, etc. Each device of the other devices being associated with the group of devices (e.g., as a member of the group of devices) and the device j being the master device of the group of devices. In some embodiments, at 402, each of the other devices in the group of devices (e.g., device j+1, device j+2, etc. ) keeps or maintains the root key. In some embodiments, each of the other devices transmit and acknowledgement (ACK) 403 to the master device, device j 330. This ACK may indicate a successful receipt of the root key from the master node.
[0108] FIG. 5 is a flow diagram illustrating a method for partial initial and mutual authentication based on a master device, according to embodiments of this disclosure. The partial initial and mutual authentication relates to devices associated with a group of devices other than a master device of the group of devices, where the master device associated with the group has been authenticated. In this procedure or method 500, the SPM maintains credentials for the devices. Other devices in the group, except the master device, are authenticated by the SPM without the involvement of the IDM.
[0109] According to embodiments, a precondition relating to partial initial and mutual authentication based on a master device is a customer associated with the group of devices has already registered with the network and has a PSRID. Another precondition may be that a master device or a group leader has already been authenticated by the network. As such, the SPM may already maintain credentials for the devices associated with the master device. For example, device j (where j=1) may serve as the master device.
[0110] According to embodiments, after a mutual authentication, a second device, device j+1, keeps or maintains one or more of: a third challenge C (i+2, j+1) of a third CRP associated with the second device, a second response R (i+1, j+1) of a second CRP associated with the second device, a root key, a device key for the second device, an ID of the second device, a basic profile, a PSRID, an STID, and an SPM ID. This may apply, for example, where i=1 and j=1. In some embodiments, after all devices j+1 (where j = 1, …, n-1) have been authenticated, the SPM stores, keeps or maintains one or more of: a list of third challenges C (i+2, j+1) corresponding to a list of third CRPs, (where j=1, …, n) , one or more credential for one or more devices of the group other than the master device (e.g., a credential for the second device) , the PSRID, an ID of the second device (e.g., device j+1) , a root key, and a device key for the second device (e.g., device j+1) .
[0111] Having regard to FIG. 5, at 501, method 500 includes a second device, device j+1, computing a second response R (i+1, j+1) of a second CRP related to the second device. In some embodiments, the second device further computes a first code based on a first information associated with the second device, where the first information includes a first response R (i, j+1) of a first CRP related to the second device.
[0112] In some embodiments, at 502, the method further includes, the SPM verifying the second device, device j+1 with the first code. In some embodiments, at 502, the SPM further obtains a second challenge C (i+1, j+1) of the second CRP related to the second device. In some embodiments, at 502, the SPM further generates a first authentication information for verifying the SPM. In some embodiments, the first authentication information is generated based on the second challenge C (i+1, j+1) of the second CRP related to the second device and information associated with the SPM, e.g., the SPM’s ID.
[0113] In some embodiments, at 503, the method further includes the second device, device j+1, subsequently verifying the SPM based on the first authentication information. In some embodiments, at 504, the method further includes the SPM generating a credential for the second device, wherein the credential is associated with the second response R (i+1, j+1) related to the second device and an existing credential of the second device. In some embodiments, the SPM generates and stores, keeps or maintains a third challenge C (i+2, j+1) of a third CRP related to the second device.
[0114] In some embodiments, at 505, the method further includes the second device, device j+1, subsequently generating a device key and keeping or maintaining the third challenge C (i+2, j+1) related to the second device. In some embodiments, the second device, device j+1, has or maintains one or more of: a device key (e.g. key materials) and an STID. In some embodiments, the device key is derived from the root key, which was previously distributed to the devices (including the second device e.g. device j+1 etc. ) by the first device, master device j, after the master device completed authentication.
[0115] FIG. 6 is a call flow diagram illustrating a method for partial initial and mutual authentication based on a master device, according to embodiments of this disclosure. The call flow or method 600 is defined using a second device, device j+1 630, a C / M-GW 331 and an SPM node or SPM 332. The method 600 may be based on a group of devices including the second device, where the first device, device j, of the group serves as a master device and has completed authentication.
[0116] According to embodiments, at 601, method 600 includes the second device, device j+1 630, computing a second response R (i+1, j+1) of a second CRP related to the second device by applying a PUF to a second challenge of the second CRP related to the second device, such that the second response R (i+1, j+1) = PUF (C (i+1, j+1) . In some embodiments, the second device further computes a first code by applying a function on input parameters. The first code may be an output of the function, where the input parameters include a first response R (i, j+1) of a first CRP related to the second device and identification information related to the second device, e.g., PSRID. The input parameters may further include a nonce, or ID of the second device, device j+1. For example, the first code may be computed as follows: first code = H (R (i, j+1) ||PSRID) , where H is a hash function.
[0117] In some embodiments, the second device, device j+1 630, subsequently sends an authentication request 602 to the C / M-GW 331. In some embodiments, the C / M-GW 331 selects the SPM 332 and forwards the authentication request 602 to the SPM 332. In some embodiments, the authentication request includes one or more of an identification information related to the second device, the first code and the second response R (i+1, j+1) . In some embodiments, the identification information related to the second device comprises a subscriber identification information of a customer related to the second device, e.g., PSRID, and an identifier of the second device, e.g., ID of device j+1.
[0118] In some embodiments, at 603, the method further includes, the SPM 332 verifying the second device, device j+1, by comparing the received first code and a value calculated based on the first response related to the second device and the identification information related to the second device. In some embodiments, the SPM obtains or finds a second challenge C (i+1, j+1) of the second CRP that is mapped to the credential. The credential may refer to a credential from the IDM that is linked with the second challenge of the second CRP associated with the second device. Each device may be associated with such credential information and such credential information, which are obtained from IDM, are kept in the SPM.
[0119] In some embodiments, at 604, the method further includes the SPM 332 generating a first authentication (auth) information that may be used for validating the SPM 332. In some embodiments, the first authentication information is generated based on the second information associated with the second device, wherein the second information includes the second challenge C (i+1, j+1) of the second CRP related to the second device and information associated with the SPM node, e.g., an ID of the SPM or SPM ID. In some the first authentication information is an output of a function. The input to this function may include the second challenge C (i+1, j+1) and the SPM ID. For example, the first authentication information may be computed as follows: first authentication = H (C (i+1, j+1) ||SPM ID) , wherein H is a hash function.
[0120] In some embodiments, at 604, the SPM 332 subsequently generates a third challenge C (i+2, j+1) of a third CRP related to the second device. In some embodiments, the SPM 332 sends an authentication response 605 to the second device, device j+1 630, via the C / M-GW 331. In some embodiments, the authentication response includes one or more of: the third challenge C (i+2, j+1) related to the second device, the first authentication information, and the information associated with the SPM, e.g., SPM ID.
[0121] According to embodiments, at 606, the second device, device j+1 630, verifies the SPM by verifying the first authentication based on the SPM ID, and the second challenge C (i+1, j+1) . In some embodiments, if the verification or validation fails, the second device, device j+1, sends a failure notification to the IDM.
[0122] In some embodiments, the second device, device j+1 630, sends the result of authentication (e.g. an indication of successful verification) 607 to the SPM 332 via C / M-GW 331. In some embodiments, after a successful authentication, at 608, the SPM 332 generates a device key parameter for a device key. The device key parameter may include at least one of the ID of the second device (ID of device j+1) , an ID of the SPM node (SPM ID) , or a session ID. In some embodiments, at 608, the SPM 332 further generates a credential for the second device, device j+1. In some embodiments, the credential is associated with the second response R (i+1, j+1) related to the second device and an existing credential of the second device (e.g., a received credential from IDM) . In some embodiments, the existing credential of the second device may refer to a credential received in message 314 from IDM in method 300. The SPM may further store, keep or maintain the second response R (i+1, j+1) and the third challenge C (i+2, j+1) . In some embodiments, the SPM 332 sends the device key parameter for the device key 609 to the second device via the C / M-GW 331.
[0123] According to embodiments, at 610, the method further includes the C / M-GW 331 generating a temporary ID (termed as an STID) for the second device, device j+1. This temporary ID may be used for communications with the network. The C / M-GW 331 may send a message 611 including one or more of the STID and the device key parameter to the second device, device j+1 630. In some embodiments, at 612, the second device, device j+1 630, subsequently generates a device key based on an existing root key and the received device key parameter. The existing root key may refer to a root key obtained from a first device, device j 330, being a master device of a group of devices associated with the second device. The existing root key may refer to the root key generated at 320 of method 300 by the first device and shared with the second device. The second device, device j+1 630, may further keep or maintain the third challenge C (i+2, j+1) .
[0124] Accordingly, in some embodiments, in method 600, the communication between the second device, device j+1 630, and the SPM 332 may be performed directly or indirectly via, for example, the C / M-GW 331. Mutual Authentication Without a Master Device
[0125] According to embodiments, there is provided a method for a full initial and mutual authentication without a master device. This method may be similar to the method for full initial and mutual authentication with a master device, however each device has its own root key. According to an embodiment, in method for full initial and mutual authentication without a master device, the SPM maintains all of the root keys of the respective devices. In some embodiments, a first device is authenticated with the involvement of IDM. The first device can be defined as a device belonging to the customer. In some embodiments, this first device accesses the network prior to the other devices that belong to the customer. In some embodiments, the other devices (e.g., subsequent devices after the first device) can be authenticated without the involvement of the IDM.
[0126] According to embodiments, the method for full initial and mutual authentication without a master device involves using a current or a first CRP pair and the next or second CRP pair for a mutual authentication. In some embodiments, a first or a current response R (i, j) of the first CRP is used for authenticating the first device, device j, and the second or next challenge C (i+1, j) of the second CRP is used for authenticating the SPM, wherein i is a time index, and j is a device index. According to embodiments, the credentials for a device can be associated with the current CRP pair and the PSRID. In some embodiments, the credentials for all devices can be aggregated, or patched. After successful authentication, the next credentials or set of credentials for the devices can be generated. These next credentials may be used to authenticate devices when the SPM triggers a new authentication procedure. In addition, each device may have its own root key and its own device key, wherein the device key is derived from the root key.
[0127] According to embodiments, a precondition for full initial and mutual authentication without a master device may be that a customer has already registered to the network and has a PSRID. In some embodiments, a first device (e.g., device j=1) initially accesses the network and other devices (e.g. devices j+1, etc. ) access the network after the first device. According to embodiments, the first device, device j, keeps or maintains one or more of: a third challenge C (i+2, j) of a third CRP related to the first device, a second response R (i+1, j) of a second CRP related to the first device, a root key for the first device (device j) , a device key for the first device (device j) , an ID of the first device (device j) , a basic profile, a PSRID, an STID, and an SPM ID. According to embodiments, the SPM stores, keeps or maintains one or more of: the third challenge C (i+2, j) , a list of second challenges C (i+1, j+1) where j = 1, …, n-1, credentials, the PSRID, the ID of the first device (device j) , the root key for the first device (device j) , and the device key for the first device (device j) .
[0128] FIG. 7 is a flow diagram illustrating a method for mutual authentication without a master device, according to embodiments of this disclosure. The method 700 includes, at 701, the IDM verifying the PSRID by comparing a received first code and a value computed based on information related to a first device, device j. In some embodiments, the IDM verifies the PSRID to verify the first device. In some embodiments, at 701, the IDM further generates a first authentication (auth) information and a parameter for a root key (or a root key parameter) . In some embodiments, the first code is generated by the first device, device j. In some embodiments, the method further includes, at 702, the first device, device j subsequently verifying the SPM through a second authentication information that is generated by the SPM according to at least the first authentication information. In some embodiments, the method further includes, at 703, the SPM verifying a second code that is generated by the first device, device j. In some embodiments, the method further includes, at 704, the IDM generating one or more new credentials for one or more other devices. In some embodiments, the IDM further generates a root key. In some embodiments, the one or more new credentials for the one or more other devices are sent to the SPM. In some embodiments, at 705, the first device, device j, subsequently generates a root key and a device key.
[0129] FIG. 8 is a call flow diagram for full initial and mutual authentication without a master device, according to embodiments of this disclosure. The call flow, illustrating a method 800, is defined using a first device, device j 830, a C / M-GW 331, an SPM node or SPM 332 and a trust function termed IDM 333.
[0130] According to embodiments, method 800 includes, at 801, computing at a first device, device j 830, a second response R (i+1, j) of a second CRP related to the first device. In some embodiments, the second response is obtained by applying a PUF to a second challenge of the second CRP related to the first device, such that R (i+1, j) =PUF (C (i+1, j) . In some embodiments, the first device further computes a first code by applying a function on input parameters. The first code may be an output of a function. The input parameters to the function may include a first response R (i, j) of a first CRP related to the first device and identification information associated with the first device, such as PSRID. The input parameters may further include a nonce, or an ID of the first device (ID of device j) . For example, the first code may be computed as follows: first code = H (R (i, j) ||PSRID) , where H is a hash function. In some embodiments, the first code is based on a first information associated with the first device, wherein the first information includes the first response of the first CRP related to the first device and the identification information related to the first device. The identification information related to the first device comprises at least one of a subscriber identification information of a customer related to the first device (PSRID) and an identifier of the first device.
[0131] In some embodiments, the first device, Device j 830, sends an authentication request message 802 to a C / M-GW 331. The C / M-GW 331 may select a SPM 332 and forwards the authentication request 802 to the SPM 332. In some embodiments, the authentication request message includes the identification information related to the first device including the PSRID, and the ID of the first device (ID of device j) . The authentication request message may further include the first code, and the second response R (i+1, j) . In some embodiments, the SPM 332 sends a second authentication message 803 to the IDM 333. This second authentication message 803 may include one or more information elements in the authentication request message 802including one or more of: the PSRID, the ID of device j, the first code, and the second response R (i+1, j) . The second authentication request message 803 may further include information associated with the SPM node, e.g., SPM ID.
[0132] According to embodiments, at 804, the IDM 133 verifies the first device by comparing the identification information related to the first device, e.g., the PSRID, with an existing identification information related to the first device, e.g., a “PSRID” in the IDM’s storage. In some embodiments, the IDM 333 further verifies the first device, device j, by comparing the received first code and a value calculated based on the first response, R (i, j) , related to the first device and the identification information related to the first device, PSRID. For example, the calculated value may be based on its input (termed as R (i, j) ||PSRID) . In some embodiments, at 804, the IDM obtains a second challenge C (i+1, j) of a second CRP that is mapped to response R (i, j) .
[0133] In some embodiments, at 804, the IDM further generates a first authentication (auth) information that may be used for validating the SPM. In some embodiments, the first authentication information is generated based on a second information associated with the first device, wherein the second information includes a second challenge C (i+1, j) of a second CRP related to the first device. In some embodiments, the first authentication information is further generated based on information associated with the SPM node, SPM ID. In some embodiments, the first authentication information is an output of a function, wherein the input for this function can include the second challenge C (i+1, j) and the SPM ID. For example, first authentication information may be computed as follows: first authentication =H (C (i+1, j) ||SPM ID) , wherein H is a hash function.
[0134] In some embodiments, at 804, the IDM further generates a parameter for a root key (or a root key parameter) . In some embodiments, the root key parameter includes one or more of: a nonce, a time value i, and other information (e.g., the SPM ID, the PSRID, the device ID) . In some embodiments, the IDM further generates a third challenge C (i+2, j) of a third CRP related to the first device.
[0135] In some embodiments, the IDM 333 sends an authentication response message 805 to the SPM 332. The authentication response message may include one or more of: the third challenge C (i+2, j) , the first authentication information, and the parameter for the root key.
[0136] According to embodiments, at 806, the method further includes the SPM 332 generating a second authentication information based on one or more of: the received first authentication information and the information associated with the SPM. For example, the second authentication information may be computed as follows: second authentication information =H(first auth||SPM ID) , where H is a hash function.
[0137] In some embodiments, the SPM 332 sends an authentication response message 807 to the first device, device j 830 via the C / M-GW 331. The authentication response message may include one or more of: the third challenge C (i+2, j) , the second authentication information, the SPM ID, and the parameter for the root key.
[0138] In some embodiments, at 808, the first device, device j 830, verifies the second authentication information based on one or more of: the SPM ID, and the second challenge C (i+1, j) . In some embodiments, the first device verifies the SPM by verifying the second authentication information. In some embodiments, at 808, the first device, device j 830, may generate a second code using the identification information related to the first device (the ID of the device j) and the second authentication information. For example, the second code may be computed as follows: second code = H (ID of the device||second auth) , where H is a hash function. In some embodiments, if the verification or validation fails, the first device, device j, sends a failure notification to the IDM. In some embodiments, upon verification or validation, the first device, device j 830, sends the second code 809 to the SPM 332 via the C / M-GW 331.
[0139] According to embodiments, at 810, the SPM 332 verifies 810 the second code. In some embodiments, if the validation fails, the SPM sends a failure notification to the IDM. In some embodiments, upon verification, the SPM 332 sends an indication of successful verification or validation 811 to the IDM.
[0140] In some embodiments, after a successful authentication, at 812, the IDM 333 generates a root key based on one or more of: the parameter for the root key and a third information. In some embodiments, the third information includes at least one of the first challenge C (i, j) of the first CRP related to the first device, and the ID of the first device (e.g., ID of device j) .
[0141] In some embodiments, at 813, the IDM 333 generates a first credential for the first device, device j. The first credential may be associated with the second response R (i+1, j) and the identification information related to the first device, e.g., PSRID. In some embodiments, the first credential is used for a next authentication of the first device, device j, when the device j accesses to the network.
[0142] In some embodiments, the IDM generates one or more credentials for one or more other devices in the group of devices. Each credential of the one or more credentials may be associated with a respective first response R (i, j+1) of a first CRP related to a respective device of the one or more devices, wherein j=1, …, n-1. Each credential of the one or more credentials may further be associated with an identification information (e.g., PSRID) related to a respective device of the one or more devices. For example, IDM may generate a second credential for a second device, wherein the second credential is associated with a first response of a first CRP related to the second device and identification information related to the second device.
[0143] In some embodiments, the IDM may process and aggregate all credentials to obtain aggregated credentials. In some embodiments, the IDM 333 then sends to the SPM 332 a message 814 including one or more of: first credential for the first device, the one or more credentials for the one or more other devices (e.g., the second credential for the second device) , the aggregated credentials, respective identification information related to the first device and the second device (e.g., PSRID) , and a list of second challenges C (i+1, j+1) , corresponding to a list of second CRPs related to the one or more other devices, where j=1, …, n-1 (e.g., a second challenge of a second CRP related to the second device) .
[0144] According to embodiments, at 815, the SPM 332 stores, maintains or keeps one or more of: the generated credentials (including the first credential for the first device, the one or more credentials for the one or more other devices, and / or aggregated credentials) , the list of second challenges C (i+1, j+1) , j = 1, …, n-1, the PSRID, the ID of the first device (device j) , the root key and the third challenge C (i+2, j) related to the first device. In some embodiments, at 816, the SPM 332 subsequently generates a first device key parameter for a device key associated with the first device. In some embodiments, the first device key parameter include at least one of the ID of the first device (device j) , the SPM ID, or a session ID, for example. In some embodiments, the SPM 332 sends the first device key parameter for a device key 817 to the C / M-GW 331.
[0145] According to embodiments, at 818, the C / M-GW 331 generates a temporary ID (termed as a STID) for the first device, device j. This temporary ID may be used for communications with the network. In some embodiments, the C / M-GW 331 sends a response message 819 to the first device 830. The response message may include one or more of: the STID and the first device key parameter for a device key. In some embodiments, at 820, the first device, device j 830, generates a root key based on one or more of: the first challenge C (i, j) and the received first device key parameter for the device key. In some embodiments, the root key generated by the first device may be the same as or similar to the root key generated by the IDM at 812. In some embodiments, the root key is used for device key derivation. In some embodiments, at 820, the first device, device j, further generates the first device key based on one or more of: the root key and the received first device key parameter. As may be appreciated both the device side and the network side use the same device key for communication between the device and the network during a session. In some embodiments, each device may have its own root key and own device key and the network may keep all different root keys of various devices.
[0146] FIG. 9 is a flow diagram illustrating a method for partial initial and mutual authentication without a master device, according to embodiments of this disclosure. The partial initial and mutual authentication relates to devices associated with a group of devices other than a first device of the group of devices, where the first device associated with the group has been authenticated. In this procedure or method 900, the SPM maintains credentials for the devices. Other devices except the first device are authenticated by the SPM without the involvement of the IDM.
[0147] According to embodiments, a second device, device j+1, keeps or maintains one or more of: a third challenge C (i+2, j+1) of a third CRP associated with the second device, a second response R (i+1, j+1) of a second CRP associated with the second device, a root key, a device key for the second device (device j+1) , an ID of the second device (device j+1) , a basic profile, a PSRID, an STID, and an SPM ID, where i=1 and j=1. According to embodiments, after all devices j+1 (where j =1,…, n-1) have accessed the network, the SPM keeps or maintains a list of third challenges C (i+2, j+1) corresponding to a list of third CRPs, where j = 1, …, n. The SPM may further store, keep or maintain one or more of: one or more credentials for one or more devices of the group other than the first device (e.g., a credential for the second device) , the PSRID, a list of IDs of the devices, a list of root keys for the devices, and a list of device keys for the devices.
[0148] Having regard to FIG. 9, at 901, method 900 includes a second device, device j+1 computing a second response R (i+1, j+1) of a second CRP related to the second device. In some embodiments, the second device further computes a first code based on a first information associated with the second device, where ethe first information includes a first response R (i, j+1) of a first CRP related to the second device.
[0149] In some embodiments, at 902, the method further includes the SPM verifying the second devices, device j+1, with the first code. In some embodiments, at 502, the SPM further obtains a second challenge C (i+1, j+1) of the second CRP related to the second device. In some embodiments, at 902, the SPM further generates a first authentication (auth) information for verifying the SPM. In some embodiments, the first authentication information is generated based on the second challenge C (i+1, j+1) of the second CRP related to the second device and information associated with the SPM, e.g., the SPM’s ID.
[0150] In some embodiments, at 903, the second device, device j+1, verifies the SPM based on the first authentication information. In some embodiments, at 904, the SPM further generates a credential associated with the second response R (i+1, j+1) related to the second device and an existing credential of the second device. In some embodiments, at 905, the second device, device j+1, subsequently generates a root key and a device key. The second device may further keep or maintain a third challenge C (i+2, j+1) of a third CRP related to the device.
[0151] FIG. 10 is a call flow diagram illustrating a method for partial initial and mutual authentication without a master device, according to embodiments of this disclosure. The call flow or method 1000 is defined using a second device, device j+1 1030, a C / M-GW 331 and an SPM 332. The method 1000 may be based on a group of devices including the second device, where the first device, device j, of the group has been authenticated.
[0152] According to embodiments, at 1001, method 1000 includes the second device, device j+1 1030, computing a second response, R (i+1, j+1) of a second CRP related to the second device by applying a PUF to a second challenge of the second CRP related to the second device, such that the second response R (i+1, j+1) = PUF (C (i+1, j+1) . In some embodiments, the second device further computes a first code by applying a function on input parameters. The first code may be an output of the function, where the input parameters include a first response R (i, j+1) of a first CRP related to the second device and identification information associated with the second device, e.g.., PSRID. The input parameters may further include a nonce, or ID of the second device, device j+1. For example, the first code may be computed as follows: first code =H(R (i, j+1) ||PSRID) , where H is a hash function.
[0153] In some embodiments, the second device, device j+1 1030, sends an authentication request 1002 to the C / M-GW 331. In some embodiments, the C / M-GW 331 selects the SPM 332 and forwards the authentication request 1002 to the SPM 332. In some embodiments, the authentication request includes one or more of: an identification information related to the second device, the first code and the second response R (i+1, j+1) . In some embodiments, the identification information related to the second device comprises a subscriber identification information of a customer related to the second device, e.g., PSRID, and an ID of the second device, device j+1.
[0154] In some embodiments, at 1003, the SPM 332 verifies the second device, device j+1, by comparing the received first code and a value calculated based on the first response related to the second device and the identification information related to the second device. In some embodiments, the SPM obtains a second challenge C (i+1, j+1) of the second CRP that is mapped to the credential. The credential may refer to a credential from the IDM that is linked with the second challenge of the second CRP associated with the second device. Each device may be associated with such credential information and such credential information, which are obtained from the IDM, are kept in the SPM.
[0155] In some embodiments, at 1004, the SPM 332 generates or computes a first authentication (auth) information that may be used for validating the SPM. In some embodiments, the first auth information is generated based on the second information associated with the second device, wherein the second information includes the second challenge C (i+1, j+1) of the second CRP related to the second device and information associated with the SPM node, e.g., an ID of the SPM or SPM ID.In some embodiment, the first authentication information is an output of a function. The input to this function may include the second challenge C (i+1, j+1) and the SPM ID. For example, the first auth information may be computed as follows: first authentication = H (C (i+1, j+1) ||SPM ID) , wherein H is a hash function.
[0156] In some embodiments, the SPM generates a third challenge C (i+2, j+1) of a third CRP related to the second device. In some embodiments, the SPM generates a parameter for a root key (or a root key parameter) . In some embodiments, the SPM 332 subsequently sends an authentication response 1005 to the second device, device j+1 1030, via the C / M-GW 331. This authentication response may include one or more of: the third challenge C (i+2, j+1) related to the second device, the first auth information, the SPM ID, and the parameter for a root key.
[0157] According to embodiments, at 1006, the second device, device j+1 1030, verifies the SPM by verifying the first auth based on the SPM ID, and the second C (i+1, j+1) . In some embodiments, if the validation fails, the second device, device j+1, sends a failure notification to the IDM. In some embodiments, after validation, the second device, device j+1, generates a root key based on one or more of: the first challenge C (i, j+1) and the received root key parameter.
[0158] In some embodiments, the second device, device j+1 1030, sends the result of authentication, for example an indication of successful authentication, 1007 to the SPM 332 via C / M-GW 331. In some embodiments, after successful authentication, at 1008, the SPM 332 generates a root key for the second device, device j+1. This root key may be the same as or similar to the root key generated by the second device at 1006. The SPM may generate the root key based on one or more of:the first challenge C (i, j+1) and the received root key parameter.
[0159] In some embodiments, at 1009, the SPM 332 generates a device key parameter for a device key for the second device. The device key parameter may include at least one of the ID of the second device (ID of device j+1) , the SPM ID, or a session ID. In some embodiments, the SPM further generates a credential for the second device, device j+1. In some embodiments, the credential is associated with the second response R (i+1, j+1) related to the second device and an existing credential of the second device (e.g., a previously received credential from the IDM) . In some embodiments, the SPM further stores, keeps or maintains the third challenge C (i+2, j+1) and the second response R (i+1, j+1) . In some embodiments, the SPM 332 sends the parameter for the device key or the device key parameter 1010 to the C / M-GW 331.
[0160] According to embodiments, at 1011, the C / M-GW 331 generates a temporary ID (which can be referred to as an STID) for the second device, device j+1. This temporary ID may be used for communications with the network. In some embodiments, the C / M-GW 331 sends a message 1012 including one or more of the STID and the device key parameter to the second device, device j+1 1030. In some embodiments, at 1013, the second device, device j+1 1030, generates a device key based on the root key and the received device key parameter. The root key may refer to the root key generated at 1006. The second device may further keep or store the third challenge, C (i+2, j+1) .
[0161] In some embodiments, each device has its own root key and its own device key. In some embodiments, each device has the same root key and its own device key. Further, the root key in the device side is the same as the network side.
[0162] In some embodiments, in initial and full mutual authentication based on a master device, for example in reference to FIG. 3, IDM may generate a root key, at 312, and further the first device, device j, may generate the same root key at 320. Further, both the SPM and device j may generate a same device key for device j for the device j. For example, device j may generate the device key at 320.
[0163] In some embodiments, in partial initial and mutual authentication based on a master device, for example in reference to FIG. 6, a second device, device j+1, may have the same root key as the first device, device j. Further, both the SPM and the second device, device j+1, may generate a same device key for device j+1. For example, device j+1 630 may generate the device key at 612.
[0164] In some embodiments, in initial and full mutual authentication without a master device, for example in reference to FIG. 8, IDM may generate a root key, at 812, and further the first device, device j, may generate the same root key at 820. Further, both the SPM and device j generates a same device key for device j for the device j. For example, device j may generate the device key at 820.
[0165] In some embodiments, in partial initial and mutual authentication without a master device, for example in reference to FIG. 10, a second device, device j+1, may have the same root key as the first device, device j. Further, both the SPM and the second device, device j+1, may generate a same device key for device j+1. For example, device j+1 may generate the device key at 1013. Dynamic Authentication
[0166] According to some embodiments, there is provided a method for dynamic authentication. Dynamic authentication can provide mutual dynamic authentication and partial dynamic authentication. In dynamic authentication, the SPM already maintains credentials for devices. The SPM may further maintain key profiles for devices. The devices may maintain at least one of an SPM ID and a CRP pair.
[0167] According to embodiments, a first device, device j, accesses the network and may be authenticated due to some conditions (e.g., the C / M-GW cannot identify the STID of the fist device, device j) . According to embodiments, the first device , device j keeps or maintains one or more of: a third challenge C (i+3, j) of a third CRP related to the first device, a third response R (i+2, j) of the third CRP related to the first device, a root key, a device key for the first device (device j) , an ID of the first device (device j) , a basic profile, a PSRID, an STID, and an SPM ID. According to embodiments, after all devices j+1 (j=1, …, n-1) have been authenticated, the SPM stores, keeps or maintains one or more of: one or more new credentials, the PSRID, an ID of all devices, root keys for the devices, device keys for the devices, and a list of third challenges C (i+2, j+1) corresponding to a list of third CRPs, where j = 1, …, n.
[0168] FIG. 11 is a flow diagram illustrating a method for dynamic partial authentication, according to embodiments of this disclosure. According to an embodiment, method 1100 includes, at 1101, a first device, device j, generating or computing a third response R (i+2, j) of a third CRP related to the first device. In some embodiments, the first device generates or computes a code based on a first information associated with the first device, wherein the first information includes a second response R (i+1, j) of a second challenge-response pair related to the first device, identification information related to the first device (e.g., a PSRID) , and information associated with a SPM node, e.g., SPM ID. In some embodiments, at 1102, the SPM verifies the first device by verifying the code received from the first device, device j, based on at least the existing second response R (i+1, j) . In some embodiments, the SPM further generates a device key parameter for a device key of the first device. In some embodiments, at 1103, the first device, device j, subsequently obtains a fourth challenge C (i+3, j) of a fourth CRP related to the first device and the device key parameter for the device key from the SPM. In some embodiments, the first device, device j, generates the device key based on at least the device key parameter.
[0169] FIG. 12 is a call flow diagram for dynamic partial mutual authentication, according to embodiments of this disclosure. The call flow illustrating a method 1250 is defined using a first device, device j 1230, a C / M-GW 331 and an SPM node or SPM 332.
[0170] According to embodiments, method 1250 includes, at 1200, the C / M-GW 331 triggering an authentication procedure due to some conditions (e.g., the C / M-GW cannot identify the first device, device j) . In some embodiment, the C / M-GW 331 sends a request for authentication materials 1201 to the first device, device j 1230.
[0171] In some embodiments, at 1202, the first device, device j 1230, computes a third response R (i+2, j) by applying a PUF to a third challenge of a third CRP related to the first device, such that the third response R (i+2, j) = PUF (C (i+2, j) ) . In some embodiments, the first device further computes or generates a code by applying a function to the identification information associated with the first device (e.g., the PSRID) , the second response related to the first device (e.g., R (i+1, j) , and information associated with the SPM node (e.g., SPM ID) . For example, the code may be computed as follows: code =H(PSRID||R (i+1, j) ||SPM ID) , where H is a hash function. In some embodiments, the code may be defined by a different function (which may be same as the has function, H) , however the code may be at least associated with one or more of the PSRID, second response R (i+1, j) , and the SPM ID. In some embodiments, both the device side and the network side support the same cryptographic algorithms.
[0172] In some embodiments, the code may be based on a first information associated with the first device, wherein the first information includes the second response R (i+1, j) , identification information related to the first device (e.g., a PSRID) , and information associated with a SPM node, e.g., SPM ID. In some embodiments, the first device, device j 1230, sends a message 1203 to the C / M-GW 331, the message including one or more of: an identification information associated with the first device, the code, and the third response R (i+2, j) . In some embodiments, the identification information associated with the first device comprises at least one of a subscriber identification information of a customer related to the first device (e.g., PSRID) and an identifier of the first device (e.g., ID of device j) .
[0173] According to embodiments, the C / M-GW 331 forwards a message 1204 to the SPM 332. In some embodiments, the message 1204 includes one or more information elements in message 1203. In some embodiments, the message 1204 includes one or more of: the identification information associated with the first device (e.g., including the PSRID, and ID of the first device) , the code, and the third response R (i+2, j) .
[0174] In some embodiments, at 1205, the SPM 332 verifies the first device, device j, by comparing the received code and a value calculated based on the second response related to the first device, the identification information associated with the first device and the information associated with the SPM node. In some embodiments, the information associated with the SPM node comprises an identifier of the SPM node (e.g., SPM ID) . In some embodiments, at 1205, the SPM generates a credential (e.g., next credential) for the first device, device j. In some embodiments, the generated credential is associated with the third response R (i+2, j) of the third CRP related to the first device and an existing credential for the first device. In some embodiments, at 1205, the SPM 332 generates a fourth challenge C (i+3, j) of a fourth CRP related to the first device.
[0175] In some embodiments, at 1206, the SPM generates a parameter for a device key (e.g. a device key parameter) of the first device, device j. In some embodiments, the SPM 332 sends a response message 1207 to the C / M-GW 331. In some embodiments, the response message 1207 includes the fourth challenge C (i+3, j) related to the device. In some embodiments, the response message includes the device key parameter if the SPM generates the device key parameter for the device key.
[0176] According to embodiments, at 1208, the C / M-GW 331 generates a temporary ID (which can be termed a STID) for the first device, device j. This temporary ID may be used for communications with the network. In some embodiments, the C / M-GW 331 sends a response message 1209 to the first device, device j 1230. In some embodiments, the response message 1209 includes one or more of: the STID, the fourth challenge C (i+3, j) , and the parameter (e.g. device key parameter) . In some embodiments, at 1210, the first device, device j 1230 keeps or maintains the fourth challenge C (i+3, j) . In some embodiments, at 1210, the first device further generate a new device key for the first device, device j, based on an existing root key and the device key parameter.
[0177] In some embodiments, in method 1250, the communication between the first device, device j 1230, and the SPM 332 may be performed directly or indirectly via, for example, the C / M-GW 331.
[0178] FIG. 13A illustrates a method for authenticating a first device, according to embodiments of this disclosure. The method 1300 may be performed by an IDM node, e.g., IDM 133. The method 1300 includes, at 1305, receiving an authentication request (e.g., authentication request 303) , wherein the authentication request includes an identification information related to the first device, a first code and a second response of a second challenge-response pair related to the first device. In some embodiments, the first code is based on a first information associated with the first device, and the first information includes a first response of a first challenge-response pair related to the first device and the identification information related to the first device. In some embodiments, the method further includes, at 1306, verifying the first device by comparing the identification information related to the first device with an existing identification information related to the first device. In some embodiments, the comparing further includes comparing the received first code and a value calculated based on the first response related to the first device and the identification information related to the first device. In some embodiments, the method further includes, at 1307, generating a first authentication information based on a second information associated with the first device. In some embodiments, the second information includes a second challenge of the second-challenge response pair related to the first device. The one or more operations at 1306 and 1307 may be similar to one or more operations at 304 of method 300. In some embodiments, the method further includes, at 1308, transmitting an authentication response message (e.g., authentication response message 305 of method 300) , wherein the authentication response message comprises the first authentication information.
[0179] FIG. 13B illustrates another method for authenticating a first device, according to embodiments of this disclosure. The method 1301 may be performed by an SPM node. The method includes, at 1310, receiving an authentication request (e.g., authentication request 302 of method 300) from the first device, wherein the authentication request includes an identification information related to the first device, a first code and a second response of a second challenge-response pair related to the first device. In some embodiments, the first code is based on first information associated with the first device, and the first information includes a first response of a first challenge-response pair related to the first device and the identification information related to the first device. In some embodiments, the method further includes, at 1311, transmitting, to an IDM node, the authentication request and information associated with the SPM node (e.g., authentication request 303 of method 300) . In some embodiments, the method further includes, at 1312 receiving, from the IDM node, an authentication response message (e.g., the authentication response message 305 of method 300) . In some embodiments, the authentication response message includes a first authentication information, wherein the IDM node generates the first authentication information based on a second information associated with the first device and the information associated with the SPM node. In some embodiments, the second information includes a second challenge of the second-challenge response pair related to the first device.
[0180] FIG. 13C illustrates a method for authenticating a second device, according to embodiments of the disclosure. The method 1302 may be performed by an SPM node. The method includes, at 1320, receiving an authentication request (e.g., authentication request 602 of method 600) from the second device. In some embodiments, the authentication request includes an identification information related to the second device (e.g., PSRID, and / or ID of device) , a first code and a second response of a second challenge-response pair related to the second device. In some embodiments, the first code is based on a first information associated with the second device. In some embodiments, the first information includes a first response of a first challenge-response pair related to the second device and the identification information related to the second device (e.g., PSRID) . In some embodiments, the method further includes, at 1321, verifying the second device by comparing the received first code and a value calculated based on the first response related to the second device and the identification information related to the second device. One or more operations at 1321 may be similar to one or more operations at 603 of method 600. In some embodiments, the method further includes, at 122, generating a first authentication information based on a second information associated with the second device. In some embodiments, the second information includes a second challenge of the second challenge-response pair related to the second device and information associated with the SPM node. One or more operations at 122 may be similar to one or more operations at 604 of method 600. In some embodiments, the method further includes, at 1323, transmitting an authentication response (e.g., authentication response 605 of method 600) to the second device. In some embodiments, the authentication response includes the first authentication information and the information associated with the SPM node.
[0181] FIG. 13D illustrates a method for dynamically authenticating a first device, according to embodiments of this disclosure. The method 1303 may be performed by an SPM node. The method includes, at 1330, receiving a message (e.g., message 1204 of method 1250) , wherein the message includes an identification information associated with the first device, a code, and a third response of a third challenge-response pair related to the first device. In some embodiments, the code is based on a first information associated with the first device, wherein the first information includes a second response of a second challenge-response pair related to the first device, identification information related to the first device (e.g., PSRID) and information associated with the SPM node. In some embodiments, the method further includes, at 1331, verifying the first device by comparing the received code and a value calculated based on the second response related to the first device, the identification information related to the first device and the information associated with the SPM node. In some embodiments, the method further includes, at 1332, generating a credential for the first device, wherein the credential is associated with the third response of the third challenge-response pair related to the first device and an existing credential for the first device. In some embodiments, the method further includes, at 1333, generating a fourth challenge of a fourth challenge-response pair related to the first device. One or more operations at 1331, 1332, and 1333 may be similar to one or more operations at 1205 of method 1250. In some embodiments, the method further includes, at 1334, transmitting to the first device the fourth challenge related to the first device. The transmission at 1334 may be similar to the transmission of the response message 1207 in method 1250.
[0182] According to an embodiment, a method is provided for customer registration for device authentication. The method includes receiving, by an identifier or identification management (IDM) function from a customer, identification information and an indication of a number of devices for registration. In some embodiments, the method further includes generating by the IDM, a preservation subscriber real identifier (PSRID) , a list of identifiers (IDs) of the devices and a list of first challenges C (i, j) , where i is indicative of time, j is indicative of a particular device, and j = 1 to n. In some embodiments, the method further includes transmitting, by the IDM to the customer, the PSRID, a basic profile, the list of IDs of the devices and the list of first challenges C (i, j) . In some embodiments, the method further includes receiving, by the IDM from the customer, a list of first responses R (i, j) . In some embodiments, one or more of the first challenges and the first responses are used by each of the devices during respective device authentication.
[0183] In some embodiments, a first device, e.g., device j, generates the first response R (i, j) based at least in part on a physical unclonable function (PUF) and the first challenge C (i, j) . In some embodiments, the first device sends the first response R (i, j) to the customer. In some embodiments, the method further includes sending, by the IDM to the customer, a list of second challenges C (i+1, j) , where i is indicative of time, j is indicative of a particular device, and j = 1 to n.
[0184] According to embodiments, a method is provided for device authentication of a first device associated with a group of devices. In some embodiments, device j is the first device. The method includes receiving, by an IDM from the first device via a service provisioning management function (SPM) , a PSRID, an ID of the first device, a first code, a second response R (i+1, j) and an SPM ID. The method further includes generating, by the IDM, an authentication (auth) at least in part based on a second challenge C (i+1, j) and the SPM ID. The method further includes generating, by the IDM, a parameter for a root key. The method further includes sending, by the IDM to the SPM, a third challenge C (i+2, j) , the auth and the parameter for the root key.
[0185] In some embodiments, upon receipt of an indication of a successful verification of the first device, the method further includes generating, by the IDM, the root key based at least in part on a first challenge C (i, j) . In some embodiments, the method further includes generating, by the IDM, credentials at least in part based on the PSRID and a list of first responses R (i, j+1) , where i is indicative of time, j is indicative of a particular device, and j = 1 to n-1. In some embodiments, the method further includes sending, by the IDM to the SPM, the root key, the credentials, the PSRID and a list of second challenges C (i+1, j+1) , where i is indicative of time, j is indicative of a particular device, and j = 1 to n-1.
[0186] In some embodiments, the first device is a master device and the master device sends the root key to each device of the group of devices. In some embodiments, the first device generates the second response R (i+1, j) based on a PUF and the second challenge C (i+1, j) .
[0187] In some embodiments, upon receipt of the root key, the credentials, the PSRID and a list of second challenges C (i+1, j+1) , the SPM generates a parameter indicative of a device key for the first device. In some embodiments, the first device is configured to derive the device key for the first device based at least in part on the root key and the parameter indicative of the device key for the first device.
[0188] According to embodiments, a method is provided for device authentication of a group of devices after authentication of a master device associated with the group of devices, where the master device may refer to device j. The method includes receiving, by an SPM from a second device, (e.g., device j+1) , via a control management gateway (C / M-GW) , a PRSID, an ID of the second device, a first code and a second response R (i+1, j+1) . In some embodiments, upon verification of the first code and finding the second challenge C (i+1, j+1) , the method further includes, generating, by the SPM, an authentication (auth) associated with the second challenge C (i+1, j+1) and an SPM ID. In some embodiments, upon receipt of an indication of a successful verification of the second device, the method further includes, generating, by the SPM, a parameter indicative of a device key for the second device and generating, by the SPM, a credential based at least in part on the second response R (i+1, j+1) . In some embodiments, the method further includes sending, by the SPM towards the second device, the parameter indicative of the device key for the second device.
[0189] In some embodiments, the second device generates the second response R (i+1, j+1) based on a PUF and the second challenge C (i+1, j+1) . In some embodiments, the second device generates the device key for the second device based at least in part on a root key and the parameter indicative of the device key for the second device.
[0190] According to embodiments, a method is provided for device authentication of a group of devices after authentication of a first device associated with the group of devices, wherein device j is the first device. The method includes receiving, by an SPM from a second device, e.g., device j+1, via a C / M-GW, a PRSID, an ID of the second device, a first code and a second response R (i+1, j+1) . In some embodiments, upon verification of the first code and finding the second challenge C (i+1, j+1) , the method further includes generating, by the SPM, an authentication (auth) associated with the second challenge C (i+1, j+1) and an SPM ID. In some embodiments, upon receipt of an indication of a successful verification of the second device, the method further includes generating, by the SPM, a root key and a parameter indicative of a device key for the second device and generating, by the SPM, a credential based at least in part on second response R (i+1, j+1) . In some embodiments, the method further includes sending, by the SPM towards the second device, the parameter indicative of the device key for the second device.
[0191] In some embodiments, the second device generates the second response R (i+1, j+1) based on a PUF and the second challenge C (i+1, j+1) . In some embodiments, the second device generates the device key for the second device based at least in part on the root key and the parameter indicative of the device key for the second device.
[0192] According to embodiments, there is provided a method for physical unclonable function (PUF) -based dynamic partial mutual authentication. There is further provided method for registration and mutual authentication based PUF.
[0193] According to embodiments, for PUF-based dynamic partial mutual authentication, dynamic mutual authentication depends on the current CRP pair (C, R) and the next CRP pair (C, R) , which can reduce storage of a list of C. In addition, for PUF-based dynamic partial mutual authentication, validation of device is dependent on the current CRP pair (C, R) , and validation on the network is dependent on the next CRP pair (C, R) .
[0194] According to embodiments, for registration and mutual authentication based PUF, the parameters based on PUF can be allocated to the devices and the IDM.
[0195] According to embodiments, advantageous effects of the methods of the instant application can relate to improved security protection and decreased use of network overhead. With respect to improved security protection, there is provided a method for mutual authentication on multiple devices, which may protect IoT devices from different attacks. This benefit may be realized because the method makes use of a unique identity (PUF) that is based on physical characteristics of the device. This benefit may be further realized because the method provides mutual authentication between device, service provisioning management (SPM) and identifier or identification management (IDM) . With respect to overhead, for the methods of the instant application, the current CRP pair and the next CRP pair are used to provide dynamic authentication, which may reduce high storage overhead compared to existing solutions (where each of the devices stores a list of CRP pairs) .
[0196] In one or more embodiments described herein, including one or more methods, the communication between a device (e.g., a first device or a second device) and an SPM node may be performed directly or indirectly via, for example, a C / M-GW.
[0197] FIG. 14 illustrates an example communication system, according to embodiments of this disclosure. The communication system 1400 includes a radio access network (RAN) 1420, one or more communication electronic devices (EDs) 1410a, 1410b, 1410c, 1410d, 1410e, 1410f, 1410g, 1410h, 1410i, 1410j (collectively referred to as 1410) , a core network 1430, a public switched telephone network (PSTN) 1440, the Internet 1450, and other networks 1460. The RAN 1420 may include, but is not limited to, a future generation RAN, or a legacy RAN such as, but not limited to, 5th generation (5G) , 4th generation (4G) , 3rd generation (3G) or 2nd generation (2G) radio access network. The one or more communication EDs 1410 (also referred to as “user equipment” ) are configured to connect (e.g., communicatively couple) with each other or to one or more network nodes 1470a, 1470b (collectively referred to as 1470) in the RAN 1420. The core network (CN) 1430 is a part of the communication system 1400 and may include one or more network nodes (e.g., 1470a , 1470b) which provide support for the network features and telecommunication services. The one or more network nodes 1470a and 1470 may refer to a base station or a RAN node being a network element with a RAN responsible for radio transmission and reception in one or more cells to or from ED (s) (such as UE) . In some implementations, the CN 1430 may be dependent on the radio access technology (RAT) used in the communication system 1400. In other implementations, the CN 1430 may be access-agnostic, i.e., the CN 1430 may be independent of the RAT used in the communication system 1400. There are different types of CN 1430, for different 3GPP system generations. For example, the CN 1430 is the Evolved Packet Core (EPC) in 4G, also known as the Evolved Packet System (EPS) . In another example, the CN 1430 is the 5G Core (5GC) which was developed as part of the 5G System (5GS) . The CN 1430 also enables integration of different 3GPP and non-3GPP access types. In some implementations, the CN 1430 also provides the interface towards external networks that may include the PSTN 1440, the Internet 1450, and other networks 1460 in the communication system 1400.
[0198] In general, the communication system 1400 facilitates interaction between multiple wireless or wired elements. The communication system 1400 may transmit different types of content, such as voice, data, video, and / or text, through different transmission methods such as, but not limited to, broadcast, multicast, groupcast, and unicast. Additionally, the communication system 1400 operates by allocating and / or sharing resources, such as carrier spectrum bandwidth, among its constituent elements.
[0199] According to embodiments, communication system 1400 facilitates authentication of devices within a network environment according to one or more embodiments described herein. In some embodiments, the communication system includes one or more network entities, including, IDM node, SPM node, C / M-GW, a customer node, that perform authentication procedures using CRP mechanisms and the exchange of authentication information. In some embodiments, the communication system 1400 supports authentication methods performed by a network node, such as receiving authentication requests that include identification information, authentication codes, and CRP information associated with a device. The network node may process these requests by verifying the received information against stored data and generating authentication information based on challenge-response mechanisms. In some embodiments, the communication system 1400 enables interactions between different network entities to support authentication according to one or more embodiments. For example, a network node may transmit authentication requests to another node, receive authentication response messages, and process authentication information to verify device identities. The system may also support dynamic authentication procedures as described herein, where authentication credentials and challenge-response pairs are updated or generated based on received messages.
[0200] Furthermore, communication between different devices / apparatuses in various implementations of this disclosure may refer to direct communication (that is, without the need of forwarding by another device / apparatus) , or may refer to communication (s) between different devices / apparatuses via another device / apparatus (that is, requiring forwarding by another device / apparatus) . Alternatively, such communication (s) may involve one functional unit inside a device / apparatus using another functional unit within the device / apparatus to communicate with another device / apparatus. Phrases such as "sending (or transmitting) information” in this disclosure may be understood as sending / transmitting information directly or indirectly. Similarly, phrases like "receiving information from” may be understood as directly or indirectly receiving information. In the present disclosure, the terms "send" and "transmit" may be used interchangeably in different implementations of this disclosure.
[0201] Future generation EDs 1410 may be referred to by other terms. When an ED 1410 performs (or is configured to perform) a method described herein, it may be interpreted as the ED itself, one or more modules (or units) in the ED, a circuit or chip, or a combination thereof, performing the method. For example, the circuit or chip may include a modem chip, also referred to as a baseband chip, a system on chip (SoC) including a modem core, or system in package (SIP) ) , and the like, and may be responsible for one or more communication functions in the ED.
[0202] FIG. 15 illustrates an example of an apparatus 1510 in a communication system (e.g., the 6G system) , according to embodiments of this disclosure. The apparatus 1510 may represent or be implemented as any node or entity within a communication system involved in one or more embodiments described herein. For example, apparatus 1510 may be an electronic device (e.g., ED 1410) , a network node, a customer node, a device (e.g., a master device, Device J, or a non-master member device of a group) , or a network entity such as a C / M-GW, IDM, SPM, or any other relevant component responsible for facilitating operations described in the claims. a node, or any component (s) within the radio access network (RAN) , core network (CN) , or other network functions or entities implemented in a 6G network or any other suitable network environment. In some embodiments, the apparatus 1510 is configured to perform one or more operations as described herein. The apparatus may operate in various roles across the network, performing tasks that include managing data collection, processing data flows, facilitating secure data exposure, and coordinating interactions between different network components and external entities.
[0203] According to embodiments, apparatus 1510 may execute operations associated with authentication, data management, secure communication, or other network functions as described in one or more embodiments herein. For instance, when apparatus 1510 operates as a customer node or customer device, it may initiate, participate in, or respond to authentication and data transmission processes according to one or more embodiments. As a C / M-GW, IDM, or SPM, apparatus 1510 may manage authentication requests, process data flows, enforce security policies, and facilitate interactions between other network components according to one or more embodiments. In some embodiments, apparatus 1510 may serve as a communication node interacting with one or more of: a member device, a master device and / or non-master devices, coordinating authentication requests, session setup, and data collection according to one or more embodiments. One or more operations performed by apparatus 1510 may encompass generating, processing, transmitting, and verifying authentication-related data, for secure authentication and data exchange in the network environment.
[0204] Apparatus 1510 includes at least one processor 1512. Only one processor 1512 is illustrated to avoid congestion in the drawing. The apparatus 1510 may further include a transmitter 1501 and a receiver 1503 coupled to one or more antennas 1504. Only one antenna 1504 is illustrated to avoid congestion in the drawing. One, some, or all of the antennas 1504 may alternatively be panels. The transmitter 1501 and the receiver 1503 may be integrated, e.g. as a transceiver. The transceiver is configured to modulate data or other content for transmission by at least one antenna 1504 or network interface controller (NIC) . The transceiver is also configured to demodulate data or other content received by the at least one antenna 1504. Each transceiver includes any suitable structure for generating signals for wireless or wired transmission and / or processing signals received wirelessly or by wire. Each antenna 1504 includes any suitable structure for transmitting and / or receiving wireless or wired signals. The apparatus 1510 may include at least one memory 1508. Only the transmitter 1501, receiver 1503, processor 1512, memory 1508, and antenna 1504 is illustrated for simplicity, but the apparatus 1510 may include one or more other components. In some embodiments, the transceiver (or transmitter 1501 and / or receiver 1503) may be viewed as an interface circuit.
[0205] The memory 1508 stores instructions used to perform operations described herein. The memory 1508 may also store data used, generated, or collected by the apparatus 1510. For example, the memory 1508 could store software instructions or modules configured to implement some or all of the functionality and / or embodiments described herein and that are executed by one or more processor 1512.
[0206] The apparatus 1510 may further include one or more input / output devices (not shown) or interfaces. The input / output devices or interfaces permit interaction with a user or other devices in the network. Each input / output device or interface includes any suitable structure for providing information to or receiving information from a user, and / or for network interface communications. Suitable structures include, for example, a speaker, microphone, keypad, keyboard, display, touch screen, etc.
[0207] The processor 1512 may perform (or control the apparatus 1510 to perform) operations (or methods) described herein as being performed by the apparatus 1510. Although not illustrated, the processor 1512 may form part of the transmitter 1501 and / or part of the receiver 1503. Although not illustrated, the memory 1508 may form part of the processor 1512. The processor 1512, the processing components of the transmitter 1501, and the processing components of the receiver 1503 may each be implemented by the same or different one or more processors that are configured to execute instructions stored in a memory (e.g. in the memory 1508) . In some embodiments, the apparatus 1510 may further include scheduler. Although not illustrated, the processor 1512 may implement the scheduler.
[0208] In some implementations, the parts of the apparatus 1510 may be distributed. In some implementations, the term apparatus 1510 may also refer to nodes on the network side that perform processing operations, such as determining the location, resource allocation (scheduling) , message generation, and encoding / decoding.
[0209] The apparatus 1510 may act as network elements involved in specific functions such as a module within a network element, a network interface device, or a processing unit within a larger system architecture. Furthermore, apparatus 1510 can be implemented as an edge device, access point, relay, or any other entity responsible for various communication tasks, processing operations, and network management functions.
[0210] Note that “signaling” , as used herein, may alternatively be called control signaling, control message, control information, or message for simplicity. Signaling may be carried in physical layer signaling (also called as dynamic signaling) , which is transmitted in a physical layer control channel.
[0211] FIG. 16A illustrates an example apparatus 1610, according to embodiments of this disclosure. The apparatus 1610 may be a communication device or an apparatus implemented in a communication device such as apparatus 1510. For example, the apparatus 1610 implemented in an ED may be an integrated circuit, which in some instances may be referred to as a chip, a modem, a modem chip, a baseband chip, or a baseband processor. In some implementations, one or more integrated circuits can be packaged into a system-on-chip, a system-in-package, or a multi-chip module. The apparatus 1610 can include one or more integrated circuits and other discrete components. In some implementations, the apparatus 1610 may be a module within the apparatus 1510.
[0212] In an example, the apparatus 1610 may include one or more processors 1611, and an interface circuit 1612. The apparatus 1610 may further include a memory 1613. The one or more processors 1611 are configured to process signals and execute one or more communication protocols. The memory 1613 is configured to store at least a part of corresponding computer program instructions and / or data. In an example, the one or more processors 1611 execute the computer program instructions stored in the memory 1613 to implement related operations (for example, inputting, outputting, receiving, and transmitting) in one or more embodiments disclosed herein. In some implementations, the memory 1613 being configured to store the corresponding computer program instructions and / or data may mean that the memory 1613 is configured to store all of the corresponding computer program instructions and / or data for execution by the one or more processors 1611. In some implementations, the memory 1613 being configured to store the corresponding computer program instructions and / or data may mean that the memory 1613 is configured to store a part of the corresponding computer program instructions and / or data. For example, the part of the corresponding computer program instructions and / or data may include computer program instructions and / or data that need to be currently executed by the one or more processors 1611. Thus, the memory 1613 may store different parts of computer program instructions and / or data for a plurality times for the one or more processors 1611 to perform related operations in the method embodiments disclosed herein. As a communication interface, the interface circuit 1612 is configured to implement communication with another component. For example, the interface circuit 1612 may communicate a signal with another apparatus or system, such as a radio frequency processing apparatus or another processor. The signal may include or carry information intended as a payload, such as user data, control information, etc. The signal may also include or carry information useful to a receiver, but not necessarily as a payload, such as a pilot signal or reference signal. Communicating the signal may include transmitting the signal to another component or device. Communicating the signal may additionally or alternatively include receiving the signal from another component or device. Transmitting the signal may include outputting the signal to a component or device that is directly or indirectly coupled to the interface circuit 1612. Receiving the signal may include inputting or obtaining the signal from a component or device that is directly or indirectly couped to the interface circuit 1612. Optionally, to reduce a load of the one or more processors, a baseband signal processing circuit 1614 may be also disposed to implement processing of at least a part of baseband signals, including signal demodulation, modulation, encoding, decoding, or the like.
[0213] Apparatus 1610 may be processor 1512 in apparatus 1510, in some scenario, or included in processor 1512 in apparatus 1510 in some scenario. Apparatus 1610 may be or include a baseband chip. In some implementations, the apparatus 1610 may be independently packaged into a chip. In some implementations, the apparatus 1510 includes different types of chips. The apparatus 1610 may be packaged into a processor chip (for example, a SoC chip or an SIP chip) with the different types of chips. In some implementations, the apparatus 1610 may be packaged into a chip with some or all of circuits of a radio frequency processing system that may further included in the apparatus 1510.
[0214] FIG. 16B illustrates another example apparatus 1630 according to embodiments of this disclosure. The apparatus 1630 may include corresponding modules or units configured to implement methods and / or implementations described herein. In some implementations, the apparatus 1630 includes a processing unit 1632 and a communication unit 1633. In some embodiments, the apparatus 1630 may further include a storage unit 1631 configured to store apparatus program code (or instructions) and / or data.
[0215] The apparatus 1630 may be an ED side apparatus, for example, an ED or a module in an ED, or a circuit or a chip responsible for a communication function in an ED. In some implementations, apparatus 1630 may be implemented as apparatus 1510 or 1610. The processing unit 1632 may be the processor 1512. The communication unit 1633 may comprise a receiving unit and / or a transmitting unit. The receiving unit and / or the transmitting unit may be the receiver 1503 and / or transmitter 1501 respectively. The storage unit 1631 may be the memory 1508.
[0216] In some implementations, when the apparatus 1630 is an ED or a module in an ED, a function of the apparatus 1630 may be implemented by one or more processors. The processor may include a modem chip, or a system on chip (SoC) chip or an SIP chip that includes a modem core. A function of the communication unit 1633 may be implemented by a transceiver circuit.
[0217] In some implementations, when the apparatus 1630 is a circuit or a chip that is responsible for a communication function in an ED–such as a modem chip, a system on chip (SoC) chip or an SIP chip that includes a modem core –a function of the processing unit 1632 may be implemented by a circuit system within the chip which includes one or more processors. A function of the communication unit 1633 may be implemented by an interface circuit or a data transceiver circuit on the chip.
[0218] It may be understood that the units in the apparatus 1630 may be logical or functional. Each function may correspond to one functional unit, or two or more functions may be integrated into a single functional unit. In actual implementation, all or some of the units may be integrated into a single physical entity, or may be distributed across different physical entities. In addition, the functional units may be implemented in the form of hardware, software, or a combination of hardware and software. Whether a function is implemented in the form of hardware or software depends on particular applications and design constraint conditions of the technical solutions. A person skilled in the art may use different methods to implement the described functions for specific applications, but it should not be considered that the implementation goes beyond the scope of this disclosure.
[0219] In an example, a functional unit in any one of the apparatuses may be configured as one or more integrated circuits for implementing the methods disclosed herein, for example, as one or more application-specific integrated circuits (application-specific integrated circuits, ASICs) , one or more central processing units (CPUs) , one or more microprocessors or microprocessor units (MPUs) , one or more microcontrollers or microcontroller units (MCUs) , one or more digital signal processors (DSPs) , one or more field programmable gate arrays (FPGAs) , or a combination of these.
[0220] In an example, the storage unit 1631 may include a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, and / or a register.
[0221] A processor may be referred to as a processor system, an application processor, a baseband processor, a processor circuit, or a processor core. The processor may include one or a combination of one or more central processing units (CPUs) , one or more digital signal processors (DSPs) , one or more microprocessors (microprocessor units, MPUs) , one or more microcontrollers (microcontroller units, MCUs) , one or more graphics processing units (GPUs) , one or more field programmable gate arrays (FPGAs) , one or more artificial intelligence processors (AI processors) , or one or more neural network processing units (NPUs) .
[0222] Memory or a storage unit may include one or more of the following storage media: a random access memory (RAM) , a static random access memory (static RAM, SRAM) , a dynamic random access memory (dynamic RAM, DRAM) , a phase-change memory (PCM) , a resistive random access memory (resistive RAM, ReRAM) , a magnetoresistive random access memory (magnetoresistive RAM, MRAM) , a ferroelectric random access memory (ferroelectric RAM, FRAM) , a cache, a register, a read-only memory (ROM) , a flash memory (flash memory) , an erasable programmable read-only memory (erasable programmable ROM, EPROM) , a hard disk, and the like. In an example, computer program instructions used to execute embodiments may be stored in a non-volatile memory, for example, at least a part of a memory or storage unit (for example, one or more of a ROM, a flash memory, an EPROM, or a hard disk) . When a terminal runs, a part or all of corresponding computer program instructions may be loaded to a memory that has a higher transmission speed with the processor, for example, at least a part of a memory or a storage unit (for example, one or more of a RAM, an SRAM, a DRAM, a PCM, a RERAM, an MRAM, a FRAM, a cache, or a register) , so that the processor executes the computer program instructions to perform the steps in the method embodiments disclosed herein.
[0223] A person skilled in the art should understand that embodiments of this application may be provided as a method, an apparatus (or system) , computer-readable storage medium, or a computer program product. Therefore, this application may use a form of a hardware-only embodiment, a software-only embodiment, or an embodiment with a combination of software and hardware. Moreover, this application may use a form of a computer program product that is implemented on one or more computer-usable storage media (including but not limited to a disk memory, an optical memory, and the like) that include computer-usable program code.
[0224] Embodiments of the present application can be implemented using electronics hardware, software, or a combination thereof. In some embodiments, the application is implemented by one or multiple computer processors executing program instructions stored in memory. In some embodiments, the application is implemented partially or fully in hardware, for example using one or more field programmable gate arrays (FPGAs) or application specific integrated circuits (ASICs) to rapidly perform processing operations.
[0225] In the present disclosure, the terms “a” or “an” are defined to mean “at least one” , that is, these terms do not exclude a plural number of items, unless stated otherwise.
[0226] In the present disclosure, terms such as “substantially” , “generally” and “about” , which modify a value, condition or characteristic of a feature of an example embodiment, should be understood to mean that the value, condition or characteristic is defined within tolerances that are acceptable for the proper operation of the example embodiment for its intended application.
[0227] In the present disclosure, unless stated otherwise, the terms “connected” and “coupled” , and derivatives and variants thereof, refer herein to any structural or functional connection or coupling, either direct or indirect, between two or more elements. For example, the connection or coupling between the elements can be acoustical, mechanical, optical, electrical, thermal, logical, or any combinations thereof.
[0228] In the present disclosure, the expression “based on” is intended to mean “based at least partly on” , that is, this expression can mean “based solely on” or “based partially on” , and so should not be interpreted in a limited manner. More particularly, the expression “based on” could also be understood as meaning “depending on” , “representative of” , “indicative of”, “associated with” or similar expressions.
[0229] In the present disclosure, the terms "system" and "network" may be used interchangeably in different embodiments of this application. "At least one" means one or more, and "a plurality of" means two or more. The term "and / or" describes an association relationship of associated objects, and indicates that three relationships may exist. For example, A and / or B may indicate the following three cases: Only A exists, both A and B exist, and only B exists, where A and B may be singular or plural. The character " / " indicates an "or" relationship between associated objects. "At least one of the following items (pieces) " or a similar expression thereof indicates any combination of these items, including a single item (piece) or any combination of a plurality of items (pieces) .
[0230] In the present disclosure, "at least one" means one or more, and "a plurality of" means two or more. "and / or" describes an association relationship of associated objects, and indicates that there may be three relationships. For example, A and / or B may indicate cases includes “only A” , “both A and B” , and “only B” , where A and B may be singular or plural. The character " / " generally indicates that the associated objects are in an OR relationship. "At least one of the following items" or a similar expression thereof refers to any combination of these items, including any combination of a single item or a plurality of items. For example, “at least one of a, b, or c” may represent a, b, c, “a and b” , “a and c” , “b and c” , or “a, b and c” , where a, b, and c may be a single or multiple form.
[0231] It will be appreciated that, although specific embodiments of the technology have been described herein for purposes of illustration, various modifications may be made without departing from the scope of the technology. The specification and drawings are, accordingly, to be regarded simply as an illustration of the application as defined by the appended claims, and are contemplated to cover any and all modifications, variations, combinations or equivalents that fall within the scope of the present application. In particular, it is within the scope of the technology to provide a computer program product or program element, or a program storage or memory device such as a magnetic or optical wire, tape or disc, or the like, for storing signals readable by a machine, for controlling the operation of a computer according to the method of the technology and / or to structure some or all of its components in accordance with the system of the technology.
[0232] Acts associated with the method described herein can be implemented as coded instructions in a computer program product. In other words, the computer program product is a computer-readable medium upon which software code is recorded to execute the method when the computer program product is loaded into memory and executed on the microprocessor of the wireless communication device.
[0233] Further, each operation of the method may be executed on any computing device, such as a personal computer, server, PDA, or the like and pursuant to one or more, or a part of one or more, program elements, modules or objects generated from any programming language, such as C++, Java, or the like. In addition, each operation, or a file or object or the like implementing each said operation, may be executed by special purpose hardware or a circuit module designed for that purpose.
[0234] Through the descriptions of the preceding embodiments, the present application may be implemented by using hardware only or by using software and a necessary universal hardware platform. Based on such understandings, the technical solution of the present application may be embodied in the form of a software product. The software product may be stored in a non-volatile or non-transitory storage medium, which can be a compact disc read-only memory (CD-ROM) , USB flash disk, or a removable hard disk. The software product includes a number of instructions that enable a computer device (personal computer, server, or network device) to execute the methods provided in the embodiments of the present application. For example, such an execution may correspond to a simulation of the logical operations as described herein. The software product may additionally or alternatively include a number of instructions that enable a computer device to execute operations for configuring or programming a digital logic apparatus in accordance with embodiments of the present application.
[0235] Although the present application has been described with reference to specific features and embodiments thereof, it is evident that various modifications and combinations can be made thereto without departing from the application. The specification and drawings are, accordingly, to be regarded simply as an illustration of the application as defined by the appended claims, and are contemplated to cover any and all modifications, variations, combinations or equivalents that fall within the scope of the present application.
Claims
1.A method performed by an identification management (IDM) node for authentication of a first device, the method comprising:receiving an authentication request, wherein the authentication request includes an identification information related to the first device, a first code and a second response of a second challenge-response pair related to the first device, wherein the first code is based on a first information associated with the first device, wherein the first information includes a first response of a first challenge-response pair related to the first device and the identification information related to the first device;verifying the first device by comparing the identification information related to the first device with an existing identification information related to the first device, wherein the comparing further comprises comparing the received first code and a value calculated based on the first response related to the first device and the identification information related to the first device;generating a first authentication information based on a second information associated with the first device, wherein the second information includes a second challenge of the second-challenge response pair related to the first device; andtransmitting an authentication response message, wherein the authentication response message comprises the first authentication information.2.The method of claim 1, wherein the identification information related to the first device comprises at least one of a subscriber identification information of a customer related to the first device and an identifier of the first device.3.The method of claim 1 or 2, wherein the second response is computed at the first device by applying a physical unclonable function (PUF) to the second challenge of the second-challenge response pair related to the first device.4.The method of any one of claims 1 to 3, wherein the first code is computed at the first device by applying a function on input parameters, the input parameters including the first response related to the first device and the identification information related to the first device.5.The method of claim 4, wherein the input parameters further include a nonce, or the identifier of the first device.6.The method of any one of claims 1 to 5, wherein receiving the authentication request comprises receiving the authentication request from a service provisioning management (SPM) node, along with information associated with the SPM node.7.The method of claim 6, wherein generating the first authentication information comprises generating the first authentication information based on the second information associated with the first device and the information associated with the SPM node.8.The method of claim 6 or 7, wherein the information associated with the SPM node comprises an identifier of the SPM node.9.The method of any one of claims 4 to 8, further comprising: generating a root key parameter; andtransmitting the authentication response message including the root key parameter to the SPM node.10.The method of claim 9, further comprising:receiving an indication of successful verification of a second code; andgenerating a root key based on the root key parameter and a third information.11.The method of claim 10, wherein the third information includes at least one of a first challenge of the first challenge-response pair related to the first device, and the identifier of the first device.12.The method of any one of claims 1 to 11, further comprising generating a first credential for the first device, wherein the first credential is associated with the second response and the identification information related to the first device, wherein the first credential is used for a subsequent authentication of the first device when the first device accesses a network.13.The method of any one of claims 1 to 12, further comprising generating a second credential for a second device, wherein the second credential is associated with a first response of a first challenge-response pair related to the second device and identification information related to the second device.14.The method of claim 13, further comprising transmitting a message, wherein the message comprises the first credential for the first device, the second credential for the second device, the identification information related to the first device and the identification information related to the second device, and a second challenge of a second challenge-response pair related to the second device.15.A method performed by a service provisioning management (SPM) node for authentication of a first device, the method comprising:receiving an authentication request from the first device, wherein the authentication request includes an identification information related to the first device, a first code and a second response of a second challenge-response pair related to the first device, wherein the first code is based on a first information associated with the first device, wherein the first information includes a first response of a first challenge-response pair related to the first device and the identification information related to the first device;transmitting, to an identification management (IDM) node, the authentication request and information associated with the SPM node; andreceiving, from the IDM node, an authentication response message, wherein the authentication response message comprises a first authentication information, wherein the IDM node generates the first authentication information based on a second information associated with the first device and the information associated with the SPM node, wherein the second information includes a second challenge of the second-challenge response pair related to the first device.16.The method of claim 15, wherein the identification information related to the first device comprises at least one of a subscriber identification information of a customer related to the first device and an identifier of the first device.17.The method of claim 15 or 16, wherein the information associated with the SPM node comprises an identifier of the SPM node.18.The method of any one of claims 15 to 17, further comprising:receiving a third challenge of a third challenge-response pair related to the first device and a root key parameter;generating a second authentication information with the information associated with the SPM node; andtransmitting a response message to the first device, wherein the response message includes the third challenge, the second authentication information , the root key parameter, and the information associated with the SPM node.19.The method of any one of claims 15 to 18, further comprising:receiving a second code;verifying the second code; andtransmitting an indication of successful verification of the second code to the IDM node.20.The method of claim 19, wherein the first device generates the second code using the identification information related to the first device and the second authentication information.21.The method of any one of claims 18 to 20, further comprising:receiving a message from the IDM node, wherein the message comprises a first credential for the first device, a second credential for a second device, the identification information related to the first device and identification information related to the second device, a root key associated with the root key parameter, and a second challenge of a second challenge-response pair related to the second device; andstoring at a local cache one or more of: the first credential for the first device, the second credential for the second device, the identification information related to the first device and the identification information related to the second device, the root key, the second challenge of the second challenge-response pair related to the second device, and the third challenge of the third challenge-response pair related to the first device.22.The method of any one of claims 15 to 21, further comprising:generating a first device key parameter for a first device key associated with the first device; andtransmitting the first device key parameter to the first device.23.The method of claim 22, wherein the first device key parameter comprises at least one of the identifier of the first device, the identifier of the SPM node and a session identifier.24.The method of claim 22 or 23, wherein the first device generates a root key using the received root key parameter and generates a first device key based on the first device key parameter.25.The method of any one of claims 15 to 24, wherein the SPM node and the first device communicate with each other through the control and management (C / M) gateway.26.A method performed by a service provisioning management (SPM) node for authentication of a second device, the method comprising:receiving an authentication request from the second device, wherein the authentication request includes an identification information related to the second device, a first code and a second response of a second challenge-response pair related to the second device, wherein the first code is based on a first information associated with the second device, wherein the first information includes a first response of a first challenge-response pair related to the second device and the identification information related to the second device ;verifying the second device by comparing the received first code and a value calculated based on the first response related to the second device and the identification information related to the second device;generating a first authentication information based on a second information associated with the second device, wherein the second information includes a second challenge of the second challenge-response pair related to the second device and information associated with the SPM node;transmitting an authentication response to the second device, wherein the authentication response includes the first authentication information and the information associated with the SPM node.27.The method of claim 26, wherein the identification information related to the second device comprises a subscriber identification information of a customer related to the second device and an identifier of the second device.28.The method of claim 26 or 27, wherein the information associated with the SPM node comprises an identifier of the SPM node.29.The method of any one of claims 26 to 28, further comprising:generating a third challenge of a third challenge-response pair related to the second device, wherein transmitting the authentication response comprises transmitting the authentication response including the third challenge related to the second device.30.The method of claim any one of claims 26 to 29, wherein the second device computes the second response by applying a physical unclonable function (PUF) to the second challenge of the second-challenge response pair related to the second device.31.The method of any one of claims 26 to 30, wherein the second device computes the first code by applying a function on input parameters, wherein the input parameters include the first response related to the second device and the identification information related to the second device.32.The method of claim 31, wherein the input parameters further include one or more of a nonce, or the identifier of the second device.33.The method of any one of claims 26 to 32, further comprising receiving an indication of successful verification from the second device.34.The method of any one of claims 28 to 33, further comprising generating a device key parameter for a device key, wherein the device key parameter includes at least one of the identifier of the second device, the identifier of the SPM node, or a session identifier.35.The method of any one of claims 26 to 34, further comprising generating a credential for the second device, wherein the credential is associated with the second response related to the second device and an existing credential of the second device.36.The method of claim 34 or claim 35, further comprising transmitting the device key parameter to the second device.37.The method of any one of claims 34 to 36, wherein the second device generates the device key based on an existing root key and the received device key parameter.38.The method of any one of claims 26 to 37, wherein the SPM node and the second device communicate with each other through the control and management (C / M) gateway.39.A method performed by a service provisioning management (SPM) node for authenticating a first device, the method comprising:receiving a message, wherein the message comprises an identification information associated with the first device, a code, and a third response of a third challenge-response pair related to the first device, wherein the code is based on a first information associated with the first device, wherein the first information includes a second response of a second challenge-response pair related to the first device, identification information associated with the first device and information associated with the SPM node;verifying the first device by comparing the received code and a value calculated based on the second response related to the first device, the identification information associated with the first device and the information associated with the SPM node;generating a credential for the first device, wherein the credential is associated with the third response of the third challenge-response pair related to the first device and an existing credential for the first device; andgenerating a fourth challenge of a fourth challenge-response pair related to the first device; andtransmitting to the first device the fourth challenge related to the first device.40.The method of claim 39, wherein the identification information associated with the first device comprises at least one of a subscriber identification information of a customer related to the first device and an identifier of the first device.41.The method of claim 39 or 40, wherein the information associated with the SPM node comprises an identifier of the SPM node.42.The method of any one of claims 39 to 41, further comprising: generating a device key parameter for a device key of the first device; andtransmitting to the first device the device key parameter.43.The method of any one of claims 39 to 42, wherein the first device computes the third response by applying a physical unclonable function (PUF) to a third challenge of the third challenge-response pair related to the first device.44.The method of any one of claims 39 to 43, wherein the first device computes the code by applying a function to the identification information associated with the first device, the second response related to the first device and the information associated with the SPM node.45.The method of any one of claims 39 to 44, wherein the first device generates a new device key for the first device based on an existing root key.46.The method of any one of claims 39 to 45, wherein the first device and the SPM node communicate with each other through the control and management (C / M) gateway.47.A non-transitory computer-readable medium, a computer program, or a program product, each comprising instructions that, when executed by a processor, cause the processor to perform any of claims 1 to 46.48.An apparatus for implementing the method according to any one of claims 1 to 46.49.An apparatus comprising computing electronics and configured to perform the method of any one of claims 1 to 46.50.An apparatus comprising at least one processor and at least one machine-readable medium storing instructions which when executed by the at least one processor configure the apparatus to perform any one of method claims 1 to 46.51.A system for authentication of a first device, the system comprising: an identification management (IDM) node configured to perform the steps of any one of claims 1 to 14; anda service provisioning management (SPM) node configured to perform the steps of any one of claims 15 to 26.
Citation Information
Patent Citations
Method for authentication of a remote station using a secure element
CN103416082A
Picture-response protocol based on physically unclonable function
CN116235466A
Storage device being authenticated to host by utilizing physically unclonable function (PUF) for data encryption / decryption
US20240273243A1
Enhanced authentication for secure communications
US9692757B1
Systems and methods for scalable cryptographic authentication of contactless cards
WO2022271519A1