Network system to obtain a network-encrypted data item and wireless device
The network system uses fully homomorphic encryption to securely transmit and process data items from wireless devices, addressing resource constraints in ambient IoT systems by allowing third-party systems to decrypt data using their secret keys, ensuring secure and efficient communication.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- KONINK KPN NV
- Filing Date
- 2025-09-15
- Publication Date
- 2026-05-07
AI Technical Summary
Existing wireless communication systems face challenges in securely transmitting sensitive data, such as long-term secret keys, to intended recipients while minimizing energy, processing, and memory resource consumption, particularly in ambient Internet-of-Things (IoT) devices with limited resources, and existing key establishment methods like Diffie-Hellman are resource-intensive and require public key infrastructure.
A network system employs fully homomorphic encryption to receive and process data items from wireless devices, using a network system encryption key to maintain data security, allowing third-party systems to decrypt the data using their respective secret keys without exposing them to the network system, enabling secure and resource-efficient transmission and key establishment.
This approach allows secure transmission and processing of encrypted data items with minimal resource consumption, enabling secure communication between the wireless device and the network without exposing secret keys, suitable for ambient IoT devices.
Smart Images

Figure EP2025076169_07052026_PF_FP_ABST
Abstract
Description
[0001] Network system to obtain a network-encrypted data item and wireless device
[0002] TECHNICAL FIELD
[0003] The present disclosure relates to a network system to obtain a network-encrypted data item and a wireless device. Particularly, the disclosure relates to a network system configured to obtain a network- encrypted data item and a wireless device configured to provide a wireless transmission comprising the data item to the network system. More particularly, the wireless device may comprise an ambient Internet-of-Things, loT, device.
[0004] BACKGROUND
[0005] One concern in the transmission of data has always been the vulnerability of the data in terms of unallowed access or interception before (or after) the data arrives at the destination. This concern has increased with wireless transmission of data since such transmissions can be received by virtually any receiver in the neighbourhood in general. Data encryption has played an important role to reduce the risk that, even if data is intercepted, the interceptor has access to the data in plain form.
[0006] Still some data types are never transmitted over the wireless part of a wireless network in the daily practical use of communication systems, even not in encrypted form. An example of such a data type comprises long-term secret keys, K, typically stored securely in devices and networks which are the basis for encryption, integrity protection, and / or authentication. If such a long-term key becomes exposed, communications between the device and network are no longer secure, so that a new shared long-term key needs to be established.
[0007] Diffie-Hellman is a well-known means for key establishment and is embedded in protocols like Transport Layer Security, TLS, as defined in RFC 8446. 3GPP TR 33.935 provides a study on detailed long-term key update processes describing a solution comprising a Diffie-Hellman based key agreement protocol as well. Key establishment according to these protocols involves at least one handshake (i.e. sending a message and receiving another one). In addition, a public key infrastructure is needed to enable authentication of the peers, which may involve the transfer of considerable amounts (up to several kilobytes) of certificate data as part of the handshake, as well as the pre-installation of (root) certificates in the device. This involves consumption of energy resources, processing resources and memory resources. It is generally desirable to reduce consumption of one or more of such resources and particularly desirable in use cases like ambient Internet-of-Things, loT systems.
[0008] 3GPP Technical Recommendations TR 22.840 and TS 22.369, contain requirements on ambient power-enabled loT. The documents disclose use cases and requirements for ambient loT devices being battery-less devices with limited energy storage capability (a capacitor may be included) wherein the energy is provided through the harvesting of radio waves, light, motion, heat or any other power source that could be suitable. Ambient Internet-of-Things, loT, devices are generally low complexity devices. The ambient loT devices may be embodied as a sticker, for example, and attached to a product of interest for inventory or product monitoring purposes. Using ambient loT, products may for example be monitored in a (global) logistic chain, from the source, e.g. a factory, wholesale market, or central logistics center, to their destination(s), e.g. a local distribution center, reseller warehouse(s), business customer(s), or end-users. Ambient loT may also be used, for example, to collect sensor data from large amounts of low cost devices, where replacement of batteries to keep the devices powered is not an option.
[0009] SUMMARY
[0010] The inventors have considered that it is generally desirable to enable wireless transmission of data items, such as data items enabling key generation, from a wireless device to a network in an efficient, but secure, manner. One use case that benefits from such efficient transmission involves an ambient Internet-of-Things, loT, system wherein an ambient loT device faces considerable restrictions in terms of energy, processing and memory resources, yet requires secure transmission of the data items so that only the intended recipient may access the data item. Moreover, the network system for which the wireless transmission is intended may not yet have a long-term shared key for securing the communication between the wireless device and the network such as addressing confidentiality protection, integrity protection and / or authentication.
[0011] One aspect of the disclosure pertains to a network system configured to obtain a network- encrypted data item from a data item transmitted from a wireless device. The wireless device may contain at least a first secret key shared with a first third-party system and a second secret key shared with a second third-party system. The network system may be configured to receive a wireless transmission from the wireless device, wherein the wireless transmission contains a data item encrypted with both the first secret key and the second secret key, i.e. a device encrypted data item. The network system may further be configured to perform a fully homomorphic encryption operation to encrypt the encrypted data item using a network system encryption key. The network system may be configured to interact with the first third-party system and second third-party system to obtain the data item encrypted with the network system encryption key.
[0012] One example of the interaction is that the network system may be configured to have the network- encrypted data item decrypted by the first third-party system and the second third-party system, while being fully homomorphically encrypted with the network system encryption key.
[0013] It is noted that the first system and second system are considered third-party systems as they should not possess each other’s secret keys and neither should the network system. Each of the third- party systems may have a separate association with the wireless device through the respective secret keys. The wireless device does not need to have an association yet with the network system. The third- party systems may be connected to the network system in wired fashion.
[0014] It should further be appreciated that fully homomorphic encryption, FHE, is known as such in the art and, briefly, allows for a variety of operations on encrypted data items. An operation on an encrypted data item is equivalent as that same operation on the unencrypted data item. Examples of such operations include decryption operations with other keys than with a network system decryption key, associated with a network system encryption key, and a key generation function applied on the fully homomorphically encrypted content, or part thereof. It should be appreciated that the network system may comprise a wireless network system, such as a public land mobile network, PLMN, or be a system contained in such a PLMN or other wireless network.
[0015] The disclosed network system and wireless device enable wireless transmission and processing of a device-encrypted data item, such as a data item used for key generation, in a resource usage efficient, yet secure, manner. For example, a single wireless transmission with a device-encrypted data item from the wireless device may be received by the network system and be decrypted with the aid of the third-party systems using their respective secret keys, without exposing these secret keys to the network system. To that end, the network system applies fully homomorphic encryption to one or more of its transmissions to one or more of the third-party systems. The fully homomorphic encryption allows the third-party systems to decrypt an encrypted data item using their respective secret keys while the encryption, with at least the network system encryption key, is maintained, so that the data item is not exposed to the third-party systems.
[0016] The disclosed network system can only have access to the data item if both third-party systems cooperate with the network system. The third-party systems, on the other hand, cannot access the data item by virtue of encryption of the data item with the network system encryption key. The network system can access the data item after interaction with both third-party systems using a network system decryption key. The network system decryption key is associated with the network system encryption key. The network system encryption key and network system decryption key may constitute a matching key pair.
[0017] It should be noted that WO 2019 / 055088 discloses a cyber ownership asset transfer system to transfer ownership of the asset to a second entity using an escrow entity for secure transfer of the asset. The transfer system requires extensive communications with a device and transmission of components of cryptographic keys over the air.
[0018] In one embodiment, the network system is configured to obtain a network-encrypted data item from a data item transmitted from a wireless device. The wireless device may contain at least a first secret key shared with a first third-party system and a second secret key shared with a second third- party system for encryption of data items of the wireless transmission.
[0019] The network system may be configured to receive a wireless transmission from the wireless device, wherein the wireless transmission contains a first encrypted data item, wherein the first encrypted data item comprises a data item encrypted using the second secret key representing a second encrypted data item, wherein the second encrypted data item is encrypted using the first encryption key to constitute the first encrypted data item comprised in the wireless transmission.
[0020] The network system may further be configured to perform a fully homomorphic encryption operation on the first encrypted data item using a network system encryption key to obtain a third encrypted data item and provide the third encrypted data item to the first third-party system. The network system may further be configured to receive the second encrypted data item encrypted under the network system encryption key from the first third-party system and provide the received second encrypted data item encrypted under the network system encryption key to the second third-party system. The network system may also be configured to receive the data item encrypted under the network system encryption key from the second third-party system to obtain the network-encrypted data item.
[0021] Another aspect of the disclosure relates to a wireless device configured for use with the network system as disclosed herein. In one embodiment, the wireless device is configured to establish a shared secret key with the network system. The wireless device is configured to store at least the first secret key shared with the first third-party system and the second secret key shared with the second third-party system. The wireless device may further be configured to transmit the wireless transmission, wherein the wireless transmission comprises a first encrypted data item, wherein the first encrypted data item comprises the data item encrypted using the second secret key representing a second encrypted data item, wherein the second encrypted data item is encrypted using the first encryption key to constitute the first encrypted data item comprised in the wireless transmission.
[0022] The wireless device may comprise an ambient Internet-of-Things, loT, device. Moreover, the wireless device may, by including the two keys from different third-party system into a single transmission, establish a secret key with the network system in a resource efficient manner.
[0023] In one embodiment, the network system may be further configured to decrypt the network- encrypted data item using a network system decryption key to obtain the data item. The network system decryption key is associated with the network system encryption key. The network system encryption key and network system decryption key may constitute a matching key pair. The embodiment enables the network system to obtain access to a data item without having access to the secret key(s) used by the wireless device to encrypt the data item for the wireless transmission.
[0024] In one embodiment, the network system may be further configured to forward the network- encrypted data item to a third-party system, such as the first third-party system. The embodiment enables the network system to further process and / or securely store the data item elsewhere. For example, the embodiment allows the network system to establish a new secret key, shared with the wireless device, with the aid of a third-party system using the network-encrypted data item forwarded to it. The secret key may be shared only by the wireless device and the network system.
[0025] In one embodiment, the wireless device comprises a key generation function to establish a third secret key shared with the network system. In this embodiment, the network system may be further configured to derive the third secret key shared with the wireless device based on at least the data item from the wireless transmission. The data item may comprise, for example, a random number, RAND, which can be used as input for a shared key generation function.
[0026] In one embodiment, the wireless device is configured to generate a random number, RAND, as the data item to establish a third secret key in the network system based on the wireless transmission. The wireless device further comprises a key generation function to generate the third secret key based on the first secret key and the random number, RAND.
[0027] The embodiment enables the network system to obtain a secret key for further secure communication with the wireless device. It is noted that the random number, RAND, as disclosed herein includes a pseudo-random number. The third secret key may be a key shared only between the wireless device and the network system. More data items may be included in the wireless transmission. In one embodiment, further data, separated from the random number, RAND, may be included in the wireless transmission. This allows for the transmission of data in addition to the random number, RAND.
[0028] In one embodiment, the first third-party system has access to the key generation function, i.e. the same key generation function as is available to the wireless device. The network system may be further configured to forward the network-encrypted random number, RAND, to the first third-party system. The network system may further be configured to receive a function result from the key generation function from the first third-party system, wherein the function result is based on at least the random number, RAND, and the first secret key possessed by the first third-party system, wherein the function result is encrypted under the network system encryption key. The network system may further be configured to obtain the third secret key from the received function result by applying a decryption with a network system decryption key associated with the network system encryption key.
[0029] The embodiment enables the network system to acquire the third secret key without needing access to the first and second secret keys and without exposing the random number, RAND, to the third-party systems and may thereby obtain a secure association with the wireless device. The random number, RAND, remains protected by the network system encryption key, but can, as a result of the fully homomorphic encryption, be used by the first third-party system for applying the key generation function. This interaction also provides control to the first third-party system to allow the network system to derive the third secret key. The first third-party system may, if it has allowed the operation, decide to discard the first secret key. The third secret key can be established with a single wireless transmission from the wireless device, which may be particularly beneficial for ambient loT devices.
[0030] It is noted that the network system does not need to acquire or have the key generation function to obtain the secret key. However, if the secure association of the wireless device needs to be transferred again, the network system may act as the first third-party system and then use a key generation function shared with the wireless device.
[0031] In one embodiment, the network system is configured to receive further data from the wireless device encrypted under the third secret key or transmit further data to the wireless device encrypted under the third secret key. The embodiment enables secure communication under the third secret key after having established the shared secret key in both the network system and wireless device in the manner disclosed herein. A message transmitted to the wireless device may inform the wireless device that the association with a new network has succeeded, for example. The message may include the identity of the new network that can be used when a next new network comes into play. Also, it may include an identifier assigned to the wireless device by the network system, a key that is derived from the third secret key and meant for use in further communications (i.e., enabling key cycling), and / or application payload.
[0032] It is noted that the shared secret key can also be used for integrity protection and / or authentication of the wireless device.
[0033] In one embodiment, the network system may be configured to interface with a computer system of a first mobile network operator as the first third-party system. The wireless device is associated with the first mobile network operator through the first secret key shared between the wireless device and the first mobile network operator. This association may exist prior to transmitting the wireless transmission from the wireless device, enabling the wireless device to exchange information securely with a network of the first mobile network operator by applying the first secret key. The network system may be associated with the wireless device after the third secret key is available to both the network system and the wireless device. The association with the first third-party system may then be released, for example by discarding the first secret key in the first third-party system or wireless device, or both. In this manner, ownership is granted to the network system. One example includes that the wireless device is transferred from one network operator to another. It is noted that an association of the network system and the wireless device through the third secret key does not already need to exist at the moment when the wireless device performs the wireless transmission, possibly a single wireless transmission, with the data item encrypted with the first and second secret keys.
[0034] In one embodiment, the wireless transmission may further comprise at least one identifier of the wireless device. The network system may be configured to provide the at least one identifier to at least one of the first third-party system and the second third-party system. The identifier may be a globally unique identifier, GUID, which may be applied by both the first third-party system and the second third- party system. The wireless transmission may also comprise more identifiers, such as a first identifier (e.g. an IMSI) for the first third-party system and a second identifier (e.g. an IMEI) for the second third- party system.
[0035] In one embodiment, the wireless device may be further configured to include at least one identifier of the wireless device in the wireless transmission.
[0036] The embodiment allows to distinguish between wireless devices. For example, the network system providing an identifier to the first third-party system enables the first third-party system to find the first secret key, or set of first secret keys, associated with the wireless device. For example, the network system providing an identifier to the second third-party system enables the second third-party system to find the second secret key, or set of second secret keys, associated with the wireless device. An example of an identifier for the wireless device comprises a globally unique identifier, GUID. Use of a GUID as an identifier for the wireless device allows the wireless device to associate with various network systems when moving, wherein the identifier may not be known originally in the network system under consideration. The device identifier may also be applied by the network system to identify the first third-party system and / or second third-party system applicable to the wireless device from which the transmission is received.
[0037] In one embodiment, the wireless transmission may further comprise at least one of an identifier of the first secret key and the second secret key. The network system may further be configured to provide the at least one identifier to at least one of the first third-party system and the second third-party system.
[0038] In one embodiment, the wireless device may be further configured to include at least one of an identifier of the first secret key and the second secret key in the wireless transmission.
[0039] The embodiment allows to identify a secret key in a set of secret keys associated with the wireless device in at least one of the first third-party system and the second third-party system. For example, the network system providing an identifier to the first third-party system enables the first third-party system to find a first secret key within a set of first secret keys, associated with the device. For example, the network system providing an identifier to the second third-party system enables the second third-party system to find the second secret key within a set of second secret keys, associated to the device. The identifier may also be used to compute a subsequent key for a set of keys.
[0040] In one embodiment, the wireless transmission may comprise at least one tracing identifier. The network system may be configured to trace at least one of the first third-party system and second third- party system based on the tracing identifier.
[0041] Optionally, the network system may be configured to obtain information from a tracing system using the tracing identifier. The tracing server may act as a well-known DNS server, resolving the tracing identifier into an address of the third-party system.
[0042] In one embodiment, the wireless device may be configured to include at least one tracing identifier in the wireless transmission. The tracing identifier may point to at least one of the first third-party system, the second third-party system and a tracing system.
[0043] The embodiment enables the network system to identify at least one of the first third-party system and second third-party system based on the wireless transmission so that the network system is aware of the address / location of the third-party systems required for the interaction. In one embodiment, an identifier of the wireless device may be used as a tracing identifier, for example if a GUID is used as a wireless device identifier and at least a part of the GUID identifies the second third-party system, for example.
[0044] As disclosed herein, one use case that benefits from such transmission involves an ambient loT system wherein an ambient loT device faces considerable restrictions in terms of energy, processing, and memory resources, yet requiring secure transmission of the data items so that only the intended recipient may access the data item.
[0045] Therefore, in one embodiment, the wireless device may be an ambient Internet-of-Things, loT, device. The network system may be configured to receive the wireless transmission from the ambient loT device to obtain the network-encrypted data item to establish a third secret key shared with the network system through a single wireless transmission.
[0046] In one embodiment, the network system may further be configured to trigger transmission of an energy pulse for the ambient loT device to enable the wireless transmission.
[0047] In one embodiment, the ambient loT device is configured to receive an energy pulse from the network system to enable the wireless transmission.
[0048] The embodiment may assist in triggering the wireless transmission. For example, the network system may provide energy to the ambient loT device to establish a shared third secret key.
[0049] One more aspect of the disclosure relates to a system comprising at least one network system and at least one wireless device as disclosed herein. The system may comprise an ambient loT system. The system may also include at least one of the first third-party system and the second third-party system as disclosed herein.
[0050] A further aspect of the disclosure pertains to a method in a network system to obtain a network- encrypted data item from a data item transmitted from a wireless device. One step of the method involves receiving a wireless transmission from the wireless device wherein the wireless transmission contains a data item encrypted with both a first secret key and a second secret key. The wireless device may contain at least a first secret key shared with a first third-party system and a second secret key shared with a second third-party system. The method may further include a step of performing a fully homomorphic encryption operation to encrypt the encrypted data item using a network system encryption key. The method may further involve a step of interacting with a first third-party system and a second third-party system to obtain the data item encrypted with the network system encryption key. In one example, the step of interacting may involve decrypting the network-encrypted data item by the first third-party system and the second third-party system, while being fully homomorphically encrypted with the network system encryption key.
[0051] Yet another aspect of the disclosure involves a computer program comprising software code portions configured to execute, when run by the network system, the steps of the above method.
[0052] A still further aspect of the disclosure relates to a method for a wireless device, such as an ambient loT device, to establish a secret key with the network system. One step of the method involves storing at least a first secret key shared with the first third-party system and a second secret key shared with the second third-party system. The method further comprises the step of transmitting a wireless transmission comprising a first encrypted data item, wherein the first encrypted data item comprises the data item encrypted using the second secret key representing a second encrypted data item, wherein the second encrypted data item is encrypted using the first encryption key to constitute the first encrypted data item comprised in the wireless transmission. The method may be performed using a single transmission including the two keys from different third-party system to establish a secret key with the network system in a resource efficient manner.
[0053] Another aspect of the disclosure involves a computer program comprising software code portions configured to execute, when run by the wireless device, the steps of the above method.
[0054] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as a system, a method or a computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a "circuit," "module" or "system." Functions described in this disclosure may be implemented as an algorithm executed by a processor / microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied, e.g., stored, thereon.
[0055] Any combination of one or more computer readable medium(s) may be utilized. The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer readable storage medium may include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present invention, a computer readable storage medium may be any tangible medium that can contain, or store, a program for use by or in connection with an instruction execution system, apparatus, or device.
[0056] A computer readable signal medium may include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium may be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
[0057] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber, cable, RF, etc., or any suitable combination of the foregoing. Computer program code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code may execute entirely on the person's computer, partly on the person's computer, as a stand-alone software package, partly on the person's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the person's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0058] Aspects of the present invention are described below with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor, in particular a microprocessor or a central processing unit (CPU), of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer, other programmable data processing apparatus, or other devices create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0059] These computer program instructions may also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.
[0060] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0061] The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.
[0062] Moreover, a computer program for carrying out the methods described herein, as well as a non- transitory computer readable storage-medium storing the computer program are provided.
[0063] Elements and aspects discussed for or in relation with a particular embodiment may be suitably combined with elements and aspects of other embodiments, unless explicitly stated otherwise. Embodiments of the present invention will be further illustrated with reference to the attached drawings, which schematically will show embodiments according to the invention. It will be understood that the present invention is not in any way restricted to these specific embodiments.
[0064] BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Aspects of the invention will be explained in greater detail by reference to exemplary embodiments shown in the drawings, in which:
[0066] FIG. 1 is a schematic illustration of an embodiment of a system comprising a network system and a wireless device;
[0067] FIG. 2 is a schematic illustration of an embodiment of a network system and an embodiment of a wireless device in combination with a first third-party system and a second third-party system;
[0068] FIG. 3 is a time diagram showing some steps to be performed by the network system and wireless device according to a first operation embodiment;
[0069] FIG. 4 is a time diagram showing some steps to be performed by the network system and wireless device according to a second operation embodiment;
[0070] FIG. 5 is a time diagram showing some steps to be performed by the network system and wireless device according to a third operation embodiment; and
[0071] FIG. 6 is a block diagram of a processing system for a network system or a part thereof. DETAILED DESCRIPTION OF THE DRAWINGS
[0072] FIG. 1 is a schematic illustration of an embodiment of a system 1 comprising a network system
[0073] 10 and a wireless device 20. The network system 10 may be integrated in a telecommunications network, PLMN, such as in a core network CN or in a local network, such as local area network LAN as shown in FIG. 1. Network system 10 may also be integrated in a base station BS or access point AP. Network system 10 may also comprise several components distributed over functions or components in a telecommunications network, local area network and / or back-end system.
[0074] Wireless device 20 may be an ambient Internet-of-Things, loT, device. The wireless device 20 may be a technically simple and inexpensive device and may be embodied as a sticker, for example. Energy, process power and storage space are typically scarce resources for such devices. The wireless devices may be operated over a network NW using a server computer SC as shown in FIG. 1 . The operator of server computer SC may be logistics operator, for example. Communication with the wireless device 20 can be accomplished via the base stations BS of telecommunications networks and via access points AP of local area networks, for example.
[0075] The wireless device 20 may be a mobile device. In FIG. 1 it may be assumed that wireless device 20 is served initially via a telecommunications network comprising core network CN-A and the associated base stations BS. Core network CN-A contains a computer system COMP (e.g. a Home Subscriber Server, HSS and / or Authentication Centre AuC of a 4G 3GPP-standard compliant network or a Unified Data Management, UDM function and / or Authentication Server function, AUSF, of a 5G 3GPP-standard compliant network) containing a secure key shared with wireless device 20. Wireless device 20 may use the secure key for secure transfer, including authentication, integrity protection and confidentiality protection of data items over the air interface with base stations BS associated with core network CN-A.
[0076] The wireless device 20 may move under the coverage of base stations BS associated with another core network, such as core network CN-B, or other network, such a local area network LAN enabling wireless communications via access points AP. Furthermore, the wireless device may need to obtain a secure association with another network. Network system 10 implemented in core network CN- B and / or in local area network LAN, for example, may be used to obtain a data item from wireless device 20 without having a security association with the CN-B at that point in time. The data item may be used to establish a secure key in CN-B as will be described in further detail below. Establishing the secure key associates the wireless device 20 with CN-B, i.e. the device is subscribed to the operator of CN-B. It is noted that, preferably, this can be arranged from a single transmission from wireless device 20 to save resources in wireless device 20. This may be important when wireless device 20 comprises an ambient loT device. Wireless device 20 may obtain energy for the single transmission from an energy transmission, such as an energy pulse, via the base stations BS associated with core network CN-B. In one embodiment, the network system 10 triggers transmission of the energy transmission. Another embodiment may be a mobile device (UE) that acts a reader for the wireless device 20 and that has a connection with the base station, so that it acts as a hop in between wireless device and the base station. FIG. 2 is a schematic illustration of an embodiment of a network system 10 and an embodiment of a wireless device 20 in combination with a first third-party system TP-1 and a second third-party system TP-2.
[0077] Network system 10 comprises interfaces 11 , 12 to the first third-party system TP-1 and second third-party system TP-2 respectively. In addition, network system 10 comprises an interface 13 over which information obtained from a wireless transmission from wireless device 20 can be received. Network system 10 further comprises a processing system 14 configured to perform various functions of network system 10 as disclosed herein and a storage system 15 configured to store computer code and / or data items and other information for executing the functions of the network system 10. Storage system 15 may comprise a network system encryption key ENw and may also comprise a corresponding network system decryption key DNW. The processing system 14 is configured to perform fully homomorphic encryption, FHE, using network system encryption key ENW
[0078] Network system 10 is connected to the first third-party system TP-1 via interface 11 and corresponding interface 11 at the first third-party system TP-1 . The first third-party system TP-1 may be implemented in a wireless telecommunications network PLMN. For example, the first third-party system TP-1 may be integrated in core network CN-A in FIG. 1 .
[0079] The first third-party system TP-1 further comprises a processing system P1 and a storage system SS1 . The first third-party system TP-1 may, for example, be contained in a telecommunications network PLMN of a current operator to which wireless device 20 is securely associated. To that end, storage system SS1 may contain a first secret key K1 that is shared with wireless device 20, i.e. wireless device 20 currently uses a corresponding active secret key K1 as known in SS1.
[0080] Network system 10 may also be connected to the second third-party system TP-2 via interface 12 and corresponding interface I2. The second third-party system TP-2 further comprises a processing system P2 and a storage system SS2. The second third-party system TP-2 may comprise another secret key K2 in storage system SS2. In one embodiment, the second third-party system TP-2 may comprise a system from a manufacturer and / or vendor of the wireless device 20.
[0081] It is noted that secret keys K1 , K2 do not leave the respective third-party systems TP-1 and TP- 2. Also network system decryption key DNW cannot be accessed from third-party systems TP-1 and TP- 2. In other words, each of network system 10, first third-party system TP-1 and second third-party system TP-2 only possess their own key for a particular wireless device 20. Network system encryption key ENW and network system decryption key DNW may be a public / private key pair.
[0082] FIG. 2 also depicts a schematic illustration of an embodiment of a wireless device 20, more specifically an ambient loT device 20. The ambient loT device 20 comprises a processor part 21 , a storage / memory part 22 and a transmitter part and receiver part, collectively indicated as transceiver part 23 for wirelessly receiving and transmitting radiofrequency, RF, signals. The ambient loT device 20 may further comprise an activation part 24 configured to harvest energy from one or more external energy sources, such as RF energy pulses triggered by network system 10. The ambient loT device 20 may further comprise a sensor 25, or connector therefore. It should be appreciated that the ambient loT device 20 may comprise a plurality of sensors 25 or connectors therefore. Examples of sensors include a location sensor, a temperature sensor, a humidity sensor, a light sensor, a pressure sensor, a motion sensor etc.
[0083] The ambient loT device 20 may not have an internal energy source (a capacitor may be included though) and may be required to harvest external power through activation part 24 as mentioned above for its activation. The ambient loT device 20 is configured to harvest energy to activate at least one of the processor part 21 , the storage / memory part 22, the transceiver part 23 and sensor 25 to execute an action. Power supply lines to these parts are indicated by the dashed-dotted lines in device 20. Signaling lines are indicated by the solid lines in device 20.
[0084] In operation, network system 10 is configured to obtain a device-encrypted data item over interface 13 from wireless device 20 transmitting the data item. The wireless device 20 may contain at least a first secret key K1 shared with a first third-party system TP-1 and a second secret key K2 shared with a second third-party system TP-2. The wireless transmission contains a data item encrypted with both the first secret key K 1 and the second secret key K2. The network system 10 is further configured to perform a fully homomorphic encryption, FHE, operation to encrypt the encrypted data item received from the wireless device 20 using a network system encryption key ENW. The network system may be configured to interact with the first third-party system TP-1 over interfaces 11 , 11 and second third-party system TP-2 over interface 12, I2 to obtain the data item encrypted with the network system encryption key ENW. This will be explained in more detail with reference to FIG. 3. One example of the interaction is that the network system 10 is configured to have the network-encrypted data item decrypted by the first third-party system TP-1 using secret key K1 and the second third-party system TP-2 using secret key K2, while being fully homomorphically encrypted with the network system encryption key ENW.
[0085] The network system 10 and wireless device 20 enable wireless transmission and processing of a data item, such as a data item used for key generation, in a resource usage efficient, yet secure, manner. For example, a single wireless transmission SWT with an encrypted data item from the wireless device may be received by the network system 10 and be decrypted with the aid of the third-party systems TP- 1 , TP-2 using their respective secret keys K1 , K2, without exposing these secret keys K1 , K2 to the network system 10. To that end, the network system 10 applies fully homomorphic encryption to one or more of its transmissions to one or more of the third-party systems TP-1 , TP-2. The fully homomorphic encryption allows the third-party systems TP-1 , TP-2 to decrypt an encrypted data item using their respective secret keys K1 , K2 wherein the encryption, with at least the network system encryption key ENW is maintained to obtain the network-encrypted data item.
[0086] The network system 10 can only have access to the data item if both third-party systems TP-1 and TP-2 cooperate with the network system 10. The third-party systems TP-1 , TP-2 , on the other hand, cannot access the data item by virtue of encryption of the data item with the network system encryption key ENW. The network system can access the data item after interaction with both third-party systems using a network system decryption key DNW. The network system decryption key DNW is associated with the network system encryption key ENW. The network system encryption key ENW and network system decryption key DNW may constitute a matching (public / private) key pair.
[0087] In operation, the wireless device 20 is configured for use with the network system 10 to establish a secret key K3 with the network system 10 as will be shown in further detail with reference to FIGS. 3- 5. The wireless device 20 is configured to store at least the first secret key K1 shared with the first third- party system TP-1 and the second secret key K2 shared with the second third-party system TP-2. The wireless device 20 may further be configured to transmit the wireless transmission. The wireless transmission may consist of a single wireless transmission. The wireless transmission comprises a data item encrypted using the second secret key K2 representing a second encrypted data item, wherein the second encrypted data item is encrypted using the first encryption key K1 to constitute the first encrypted data item comprised in the wireless transmission. As explained with reference to FIG. 1 , the wireless device 20 may comprise an ambient Internet-of-Things, loT, device.
[0088] FIG. 3 is a time diagram showing some steps to be performed by the network system 10 and wireless device 20 according to a first operation embodiment.
[0089] In a first step S1 , wireless device 20 performs a single wireless transmission of data item DAT. Data item DAT is encrypted by the second secret key K2 representing second encrypted data item K2(DAT). The second encrypted data item K2(DAT) is encrypted using the first secret key K1 to constitute the first encrypted data item K1 (K2(DAT)) for the single wireless transmission. The data item DAT, encrypted under K2 and K1 , is then received by network system 10. It is noted that prior to step S1 , the wireless device 20 may have been energized, for example an RF energy pulse triggered by network system 10 (not shown).
[0090] In step S2, network system 10 performs a fully homomorphic encryption FHE operation using network system encryption key ENW and transmits the result to the first third-party system TP-1 possessing key K1. As a result of the fully homomorphic encryption, the first third-party system TP-1 may apply the first secret key K1 to decrypt the first encrypted data item K1 (K2(DAT)) to obtain the second encrypted data item K2(DAT) encrypted under the network system encryption key ENW.
[0091] The result of the decryption operation at the first third-party system TP-1 is returned to network system 10 in step S3. The first third-party system TP-1 may discard the first secret key K1 after the decryption operation. The first secret key K1 may also be discarded at a later stage or be maintained for later use. Examples of later use include a further interaction with the network system or other system, wherein a data item is to be decrypted and / or for key derivation, such as following step S7 in FIG. 3 or FIG. 4.
[0092] Upon receiving the result of the decryption operation in the first third-party system TP-1 in step
[0093] 53, network system 10 may decide to forward the result to the second third-party system TP-2 in step
[0094] 54. It is noted that first third-party system TP-1 may alternatively transmit the result of the decryption operation directly to the second third-party system TP-2 (not shown). It is also noted that the network system 10 may decrypt the result using network system decryption key DNW to obtain the second encrypted data item K2(DAT). The network system 10 may perform a further fully homomorphic encryption FHE operation on K2(DAT), similar to the previous FHE operation prior to step S2, and forward the result in step S4. The two FHE encryptions may be different and may require multiple network system encryption / decryption key pairs.
[0095] The second third-party system TP-2 may apply the second secret key K2 to decrypt the second encrypted data item K2(DAT) to obtain the network-encrypted data item DAT, i.e. the data item DAT encrypted under the network system encryption key ENW applied at the network system 10. In step S5, the result of the decryption operation at the second third-party system TP-2, i.e. the network-encrypted data item, FHE-ENW[DAT], is obtained by the network system 10.
[0096] The network system 10 may perform further processing on the network-encrypted data item FHE- ENW[DAT].
[0097] For example, in step S6, the network system 10 may further decrypt the network-encrypted data item using a network system decryption key DNW to obtain the data item DAT. Step S6 enables the network system 10 to obtain access to the data item, DAT, of an encrypted data item K1 (K2(DAT) without having access to the secret key(s) K1 , K2 used by the wireless device 20 to encrypt the data item for the wireless transmission and without needing a prior key establishment with the wireless device 20.
[0098] Alternatively, as shown by step S7, the network system 10 may forward the network-encrypted data item to the first third-party system TP-1 once more. This may be useful if network system 10 needs to obtain a secret key K3 and needs further input from the first third-party system TP-1 to which the wireless device 20 is currently associated through a shared secret key K1 as will be explained in further detail with reference to FIG. 4.
[0099] FIG. 4 is a time diagram showing some steps to be performed by the network system 10 and wireless device 20 according to a second operation embodiment. The data item DAT is generated in the wireless device 20 and comprises a random or pseudo-random number, RAND.
[0100] Steps S1-S5 and S7 correspond to steps S1-S5 and S7 as described with reference to FIG. 3 wherein the data item DAT is the random number RAND.
[0101] In step S7, the first third-party system TP-1 receives the network-encrypted data item FHE- ENW[DAT], The first third-party system TP-1 has access to key-derivation function F, which is also contained in wireless device 20. The random number, RAND, remains protected by the network system encryption key ENW, but can, as a result of the fully homomorphic encryption operation FHE, be used by the first third-party system TP-1 for applying the key generation function F on the random number RAND and on the secret key K1 . For this operation, the first third-party system TP-1 may perform the following steps 1-1 = FHE-ENW[RAND], as received in step S7 and I-2 = FHE-ENW[KI], wherein the first third-party system applies the public network system encryption key ENW. By using fully homomorphic encryption, FHE, the following equality applies: R = F(l-2, 1-1) = F(FHE-ENW(KI), FHE-ENW(RAND)) = FHE-ENW(F(KI, RAND)) which is the result for step S8.
[0102] It is noted that in this embodiment, the first third-party system TP-1 should not discard the secret key K1 after processing the information from step S2, but may discard the key after applying the key derivation function F. However, the first third-party system may also maintain the secret key for later use, such as to decrypt a new data item DAT.
[0103] In step S8, the first third-party system TP-1 returns the result R of applying the key derivation function F to the network system 10 encrypted under the network system encryption key ENW. This is denoted in FIG. 4 as F(K1 , RAND), which effectively corresponds to a new secret key K3 as shown in step S9.
[0104] Likewise, the wireless device 20 may derive the new key K3 at any stage after generation of the random number RAND as shown in step S10. In the embodiment of FIG. 4, the network system 10 acquires the third secret key K3 without needing access to the first and second secret keys K1 , K2 and without exposing the random number, RAND, to the third-party systems TP-1 and TP-2. The mechanism also enables the first third-party system TP-1 to control which network system 10 is allowed to obtain the data item DAT and / or secret key K3. The first third-party system may, if it has allowed the operation, decide to discard or maintain the first secret key K1 as indicated above. The third secret key K3 can be established with a single wireless transmission from the wireless device, which may be particularly beneficial for ambient loT devices.
[0105] It should be noted that the embodiments of FIG. 3 and FIG. 4 can be combined if the single wireless transmission contains both a data item DAT and a random number, RAND, wherein the random number RAND is intended for generation of a secret key. The network system 10 may obtain the data item DAT as shown in step S6 of FIG. 3 and the secret key K3 in step S9 of FIG. 4
[0106] In the embodiments of FIG. 3 and FIG. 4, the network system 10 is aware of the first third-party system TP-1 and the second third-party server TP- 2 to transmit the message in step S2 (and S7 in FIG. 4) and S4, respectively.
[0107] Hence, the transmission in step S1 from the wireless device 20 may need to include information about the first third-party system TP-1 and the second third-party system TP-2 along with an identifier identifying the wireless device 20. Alternatively, the network system 10 may be configured to obtain the identity of the first third-party system TP-1 and / or the second third-party system TP-2 in some other way using the identifier of the wireless device 20.
[0108] For identifying the second third-party system TP-2, in one embodiment, the identity of the wireless device 20 may use a unique identifier within the system 1 of FIG. 1 , such as a globally unique identifier, GUID. The identifier may be established by the party operating the second third-party system TP-2 and may therefore already include a unique identification of the second third-party system TP-2. For example, an authorized body, like the Internet Assigned Numbers Authority, IANA, may issue a prefix to the second third-party system TP-2 and the party operating the second third-party system TP-2 may generate a unique identifier for each wireless device 20 comprising that prefix and a number that is unique among all devices sold / manufactured by the party. In one embodiment the prefix may comprise the address (e.g., a fully qualified domain name, FQDN) of the second third-party system TP-2 used for implementing the disclosed operation in FIGS. 3 and 4. In an alternative embodiment, network system 10 may first contact another, known, server (e.g., operated by abovementioned authorized body) to resolve the prefix into an address (and / or it may have retrieved such address information previously from the authorized body and have it cached at their own servers).
[0109] For identifying the first third-party system TP-1 , several possibilities exist. In case the wireless device 20 is initially assigned to an operator of the first third-party system TP-1 (i.e. subscribed), the wireless device 20 may be pre-provisioned with an identifier of TP-1 (such as a server address, for example) upon manufacture or deployment. Such an embodiment allows the wireless device 20 to be assigned only once to a new network system and not any further. For example, in the scenario of FIG. 1 , wireless device 20 would only be allowed to change the secure association to CN-B but a further change to the LAN would not be allowed without further measures. FIG. 5 shows an embodiment, wherein the network system 10 first needs to identify at least one of the first third-party system TP-1 and the second third-party system TP-2. To that end, the embodiment applies a tracing system TS. The tracing system TS keeps track of the network to which the wireless device 20 is currently associated, i.e. with which network the wireless device 20 shares a secret key. Whereas the below description focuses on tracing a network TP-1 , tracing system TS may also be used for tracing TP-2.
[0110] It should be noted that the tracing system TS and second third-party system TP-2 may coincide in one and the same system in case the network system 10 is aware or can be aware of the identity of the combined TP-2 / TS system as described above.
[0111] In a first step S1 , wireless device 20 performs a single wireless transmission of random number RAND. The random number RAND is encrypted by the second secret key K2 representing second encrypted data item K2(RAND). The second encrypted data item K2(RAND) is encrypted using the first secret key K1 to constitute the first encrypted data item K1 (K2(RAND)) for the single wireless transmission. The data item RAND, encrypted under K2 and K1 , is then received by network system 10. It is noted that prior to step S1 , the wireless device 20 may have been energized, for example an RF energy pulse triggered by network system 10 (not shown).
[0112] In addition, the single wireless transmission in step S1 from the wireless device 20 contains an identifier ‘j’ of the wireless device 20.
[0113] If network system 10 is unaware that the wireless device 20 is currently associated with the first third-party server TP-1 , network system 10 may invoke a tracing procedure with tracing system TS. In the example of FIG. 5, network system 10 transmits a tracing request T1 to tracing system TS for the wireless device identifier ‘j’ and receives a tracing response T2 that wireless device 20 is currently associated with the first third-party system TP-1 .
[0114] In FIG. 5, step T3 informs the tracing system TS of a new association of wireless device 20 with the network associated with network system 10 (for example CN-B in FIG. 1) after the secret key K3 is established. Step T4 confirms that the new association is registered in the tracing system TS. In this manner, in the scenario of FIG. 1 , network system 10 for the network LAN may subsequently find that the wireless device 20 is currently associated with CN-B, so that CN-B corresponds to the first third- party server TP-1 in that event.
[0115] Optionally, tracing system TS checks the validity of the association transfer by contacting TP-1 after step T3 and before step T4. This is shown in FIG.5 by dashed arrows T3A and T3B. Other options for informing the tracing system TS of a new association are also possible, e.g. TP-1 informing the tracing system TS.
[0116] The inventors have considered various further embodiments that could be applied to any one of the above embodiments.
[0117] One further embodiment considers identifiers of wireless devices 20, such as a globally unique identifier, GUID, for example an international mobile subscription identifier, IMSI, subscription permanent identifier, SUPI, and / or international mobile equipment identifier, IMEI, or permanent equipment identifier, PEI. A typical implementation of system 1 as shown in FIG. 1 may manage a plurality of wireless devices 20. Accordingly, the first third-party system TP-1 may maintain a plurality of first secret keys K1 , j (one for each wireless device j) and the second third-party system TP-2 may also maintain a plurality of secret keys K2, j. Both TP-1 and TP-2 need to apply the correct secret key K1 resp. K2. This may be assisted by using an identifier that is unique relative to the first third-party system TP-1 (e.g., I MS I) and relative to the second third-party system TP-2 (e.g., I MEI). In FIG. 5, it is shown for step S1 that the single wireless transmission includes an identifier ‘j’ of the wireless device 20. The identifier ‘j’ may also be included in the messages corresponding to subsequent steps S2, S4 and / or S7 and possibly also in S3, S5 and S8. The first third-party server TP-1 stores a plurality of first secret keys K1 and may identify the secret key K1 , j associated with wireless device 20 having identifier j. Likewise, second third-party server TP-2 stores a plurality of second secret keys K2 and may identify the secret key K2, j associated with wireless device 20 having identifier j.
[0118] Furthermore, it is noted that a new network (e.g. CN-B) may not have a pre-established identifier ‘j’ for the wireless device 20 and that establishing such an identifier would at least involve sending a message back to the wireless device 20 after establishing the shared key (i.e., key K3). Such an additional transmission may be disadvantageous in certain cases, such as when the wireless device 20 is an ambient loT device. Therefore, it would be advantageous to re-use an already established identifier, for example the identifier established with the first third-party system TP-1 or the identifier established with the second third-party system TP-2.
[0119] Considering that, as outlined above, the wireless device 20 may move in between wireless networks any number of times, it may be beneficial to maintain the unique identifier originally assigned by the second third-party system TP-2 throughout the lifetime of the wireless device 20 as the only unique identifier for the purpose(s) disclosed herein, such as a GUID, for example an IMEI.
[0120] One further embodiment includes a limitation of using the secret key K2 associated with TP-2 only once to enhance security. To enable multiple, successive changes of ownership (i.e. changes of secure key associations with the wireless device), the wireless device 20 may share a set of indexed keys K2, i instead of only a single key K2. For such an embodiment, the wireless device 20 may transmit the index i in plain text (along with the encrypted DAT in FIG. 3 or RAND in FIGS. 4 and 5) to the network system as part of step S1 and which index i is later forwarded to the second third-party system TP-2 such that the same key K2 is for decryption at TP-2 that wireless device 20 has used for encryption. One embodiment may involve the wireless device 20 and TP-2 sharing a finite list (e.g., an array) of precomputed keys K2. As an alternative, wireless device 20 and TP-2 may be configured to compute successive keys K2 using a one-way function G: K2J+1 = G(K2, i) and by establishing an initial key K2, 0. The latter embodiment may be beneficial to allow for a large variety of association changes. Also, the wireless device 20 may not be able to store many keys K2, if resources are limited, such as for ambient loT devices.
[0121] The first third-party system TP-1 may enhance security by enforcing key rotation of the secret keys K1 , i from a set of keys K1 rather than using only a single key K1 . In this case K1 will become a set of keys K1 , i. For example, this could involve generating key K1 , i by iterative steps from some K1 , 0 i.e., by using a one way function: K1 , i+1 = G(K1 , i). When the wireless device 20 changes association from TP-1 to the network system, also a set of keys K3,i may be used. One embodiment involves generating the K3, i by iterative steps from some K3,0 i.e., by using a one way function K3,i+1 = G(K3, i). Another involves generating each K3,i from the corresponding K1 ,i as K3,i = F(K1 , i, RAND).
[0122] It should be noted that the messages in FIGS. 3-5 may apply multiple indices for wireless device identification and key identification.
[0123] FIG. 6 depicts a block diagram illustrating an exemplary processing system according to a disclosed embodiment, e.g. a (part of) a network system, third-party system and / or tracing system as described above. As shown in FIG. 6, the processing system 60 may include at least one processor 61 coupled to memory elements 62 through a system bus 63. As such, the processing system may store program code within memory elements 62. Further, the processor 61 may execute the program code accessed from the memory elements 62 via a system bus 63. In one aspect, the processing system may be implemented as a computer system that is suitable for storing and / or executing program code. It should be appreciated, however, that the processing system 60 may be implemented in the form of any system including a processor and a memory that is capable of performing the functions described within this specification.
[0124] The memory elements 62 may include one or more physical memory devices such as, for example, local memory 64 and one or more bulk storage devices 65. The local memory may refer to random access memory or other non-persistent memory device(s) generally used during actual execution of the program code. A bulk storage device may be implemented as a hard drive or other persistent data storage device. The processing system 60 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the number of times program code must be retrieved from the bulk storage device 65 during execution.
[0125] Input / output (I / O) devices depicted as an input device 66 and an output device 67 optionally can be coupled to the processing system. Examples of input devices may include, but are not limited to, a space access keyboard, a pointing device such as a mouse, or the like. Examples of output devices may include, but are not limited to, a monitor or a display, speakers, or the like. Input and / or output devices may be coupled to the processing system either directly or through intervening I / O controllers.
[0126] In an embodiment, the input and the output devices may be implemented as a combined input / output device (illustrated in FIG. 6 with a dashed line surrounding the input device 66 and the output device 67). An example of such a combined device is a touch sensitive display, also sometimes referred to as a “touch screen display” or simply “touch screen” that may be provided with the UE. In such an embodiment, input to the device may be provided by a movement of a physical object, such as e.g. a stylus or a finger of a person, on or near the touch screen display.
[0127] A network adapter 68 may also be coupled to the processing system to enable it to become coupled to other systems, computer systems, remote network devices, and / or remote storage devices through intervening private or public networks. The network adapter may comprise a data receiver for receiving data that is transmitted by said systems, devices and / or networks to the processing system 60, and a data transmitter for transmitting data from the processing system 60 to said systems, devices and / or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapter that may be used with the processing system 60. As pictured in FIG. 6, the memory elements 62 may store an application 69. In various embodiments, the application 69 may be stored in the local memory 64, the one or more bulk storage devices 65, or apart from the local memory and the bulk storage devices. It should be appreciated that the processing system 60 may further execute an operating system (not shown in FIG. 6) that can facilitate execution of the application 69. The application 69, being implemented in the form of executable program code, can be executed by the processing system 60, e.g., by the processor 61. Responsive to executing the application, the processing system 60 may be configured to perform one or more operations or method steps described herein.
[0128] Various embodiments of the invention may be implemented as a program product for use with a computer system, where the program(s) of the program product define functions of the embodiments (including the methods described herein). In one embodiment, the program(s) can be contained on a variety of non-transitory computer-readable storage media, where, as used herein, the expression “non- transitory computer readable storage media” comprises all computer-readable media, with the sole exception being a transitory, propagating signal. In another embodiment, the program(s) can be contained on a variety of transitory computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media (e.g., read-only memory devices within a computer such as CD-ROM disks readable by a CD-ROM drive, ROM chips or any type of solid-state non-volatile semiconductor memory) on which information is permanently stored; and (ii) writable storage media (e.g., flash memory, floppy disks within a diskette drive or hard-disk drive or any type of solid-state random-access semiconductor memory) on which alterable information is stored. The computer program may be run on the processor 61 described herein.
[0129] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0130] The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of embodiments of the present invention has been presented for purposes of illustration but is not intended to be exhaustive or limited to the implementations in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the claims. The embodiments were chosen and described in order to best explain the principles and some practical applications of the present invention, and to enable others of ordinary skill in the art to understand the present invention for various embodiments with various modifications as are suited to the particular use contemplated.
Claims
CLAIMS1. A network system configured to obtain a network-encrypted data item from a data item transmitted from a wireless device, wherein the wireless device contains at least a first secret key shared with a first third-party system and a second secret key shared with a second third- party system, wherein the network system is configured to: receive a wireless transmission from the wireless device, wherein the wireless transmission contains a data item encrypted with both the first secret key and the second secret key; perform a fully homomorphic encryption operation to encrypt the encrypted data item using a network system encryption key; interact with the first third-party system and the second third-party system to obtain the data item encrypted with the network system encryption key.
2. The network system according to claim 1 , wherein the network system is configured to: receive the wireless transmission from the wireless device, wherein the wireless transmission contains a first encrypted data item, wherein the first encrypted data item comprises the data item encrypted using the second secret key representing a second encrypted data item, wherein the second encrypted data item is encrypted using the first encryption key to constitute the first encrypted data item comprised in the wireless transmission; perform the fully homomorphic encryption operation on the first encrypted data item using the network system encryption key to obtain a third encrypted data item and provide the third encrypted data item to the first third-party system; receive the second encrypted data item encrypted under the network system encryption key from the first third-party system and provide the received second encrypted data item encrypted under the network system encryption key to second third-party system; receive the data item encrypted with the network system encryption key from the second third-party system to obtain the network-encrypted data item.
3. The network system according to claim 1 or 2, wherein the network system is further configured to at least one of: decrypt the network-encrypted data item using a network system decryption key associated with the network system encryption key to obtain the data item; forward the network-encrypted data item to a third-party system, such as the first third- party system.
4. The network system according to one or more of the preceding claims, wherein the wireless device comprises a key generation function to establish a third secret key shared with the network system, wherein the network system is further configured to derive the third secret key shared with the wireless device based on at least the data item from the wireless transmission, wherein the data item comprises a random number, RAND, and, optionally, further data separated from the random number, RAND.
5. The network system according to claim 4, wherein the first third-party system has access to the key generation function and the network system is further configured to: forward the network-encrypted random number, RAND, to the first third-party system; receive a function result from the key generation function from the first third-party system, wherein the function result is based on at least the random number, RAND, and the first secret key while being encrypted under the network system encryption key; obtain the third secret key from the received function result by applying a network system decryption key associated with the network system encryption key.
6. The network system according to claim 4 or 5, wherein the network system is configured to at least one of: receive further data from the wireless device encrypted under the third secret key; transmit further data to the wireless device encrypted under the third secret key.
7. The network system according to one or more of the preceding claims, wherein the network system is configured to interface with a computer system of a first mobile network operator as the first third-party system, wherein the wireless device is associated with the first mobile network operator through the first secret key shared between the wireless device and the first mobile network operator prior to transmitting the wireless transmission.
8. The network system according to one or more of the preceding claims, wherein the wireless transmission further comprises at least one of the following: one or more identifiers of the wireless device; and at least one of an identifier of the first secret key and the second secret key, wherein the network system is configured to provide at least one identifier to at least one of the first third-party system and the second third-party system.
9. The network system according to one or more of the preceding claims, wherein the wireless transmission comprises at least one tracing identifier, wherein the network system is configured to trace at least one of the first third-party system and second third-party system based on the tracing identifier and, optionally, the network system is configured to obtain information from a tracing system using the tracing identifier.
10. The network system according to one or more of the preceding claims, wherein the wireless device is an ambient Internet-of-Things, loT, device and the network system is configured to receive the wireless transmission from the ambient loT device to obtain the network-encrypted data item, for example to establish a third secret key shared with the network system, through a single wireless transmission, wherein, optionally, the network system is configured to trigger transmission of an energy pulse for the ambient loT device to enable the wireless transmission.
11. A wireless device configured for use with the network system according to one or more of the preceding claims 1-10, wherein the wireless device is configured to store at least the first secret key of claim 1 shared with the first third-party system of claim 1 and the second secret key of claim 1 shared with the second third-party system of claim 1 , wherein the first third- party system is a different third-party system than the second third-party system, and wherein the wireless device is further configured to transmit the wireless transmission of claim 1 , wherein the wireless transmission comprises a first encrypted data item, wherein the first encrypted data item comprises the data item encrypted using the second secret key representing a second encrypted data item, wherein the second encrypted data item is encrypted using the first encryption key to constitute the first encrypted data item comprised in the wireless transmission.
12. The wireless device according to claim 11 , wherein the wireless device is configured to generate a random number, RAND, as the data item to establish a third secret key in the network system based on the wireless transmission, and, optionally, further data separated from the random number, RAND, wherein the wireless device further comprises a key generation function to generate the third secret key based on the first secret key and the random number, RAND.
13. The wireless device according to claim 11 or 12, wherein the wireless device is further configured to include at least one of the following: one or more identifiers of the wireless device; and at least one of an identifier of the first secret key and the second secret key in the wireless transmission.
14. The wireless device according to one or more of the claims 11-13, wherein the wireless device is configured to include at least one tracing identifier in the wireless transmission, wherein the tracing identifier points to at least one of the first third-party system, the second third-party system and a tracing system.
15. The wireless device according to one or more of the claims 11-14, wherein the wireless device is an ambient Internet-of-Things, loT, device, wherein, optionally, the ambient loT device is configured to receive an energy pulse from the network system to enable the wireless transmission.
Citation Information
Patent Citations
Cyber ownership transfer
WO2019055088A1
System and method for protected data transfer
US20060282901A1
Network system, and methods of encrypting data, decrypting encrypted data in the same
US20180260576A1
Homomorphic encryption offload for lightweight devices
US20220173886A1