Method for device authorization in integrated sensing and communication and related apparatus

The method and apparatus for device authorization in ISAC improve sensing accuracy and security by authorizing AIoT devices through RAN node proximity checks and device eligibility verification, addressing the challenge of unauthorized AIoT participation in sensing tasks.

WO2026096242A1PCT designated stage Publication Date: 2026-05-07INNOPEAK TECHNOLOGY INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
INNOPEAK TECHNOLOGY INC
Filing Date
2025-10-21
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing integrated sensing and communication (ISAC) systems face challenges in authorizing ambient internet-of-things (AIoT) devices, which are not bound to traditional user subscriptions, necessitating new methods to ensure privacy and security while leveraging these devices for sensing tasks.

Method used

A method and apparatus for device authorization in ISAC, where a radio access network (RAN) node determines the proximity and authorization of AIoT devices, and the devices themselves verify their eligibility to participate in sensing sessions based on pre-provisioned or network-verified authorization information.

Benefits of technology

Enhances sensing accuracy, preserves security and privacy, and reduces the risk of storing sensitive information by ensuring only authorized AIoT devices contribute to sensing operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025051859_07052026_PF_FP_ABST
    Figure US2025051859_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by a radio access network (RAN) node for device authorization in integrated sensing and communication (ISAC) includes determining, by the RAN node, that at least one ambient intemet-of-things (AIoT) device is within a vicinity of a remote object and determining whether the at least one AIoT device is authorized to participate in a sensing session.
Need to check novelty before this filing date? Find Prior Art

Description

Atty. Dkt. No. 10085-01-0177-PCTMETHOD FOR DEVICE AUTHORIZATION IN INTEGRATED SENSINGAND COMMUNICATION AND REUATED APPARATUSCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to U.S. Provisional Application No. 63 / 715,377, entitled “METHOD AND APPARATUS FOR DEVICE AUTHORIZATION IN INTEGRATED SENSING AND COMMUNICATION,” filed on November 1, 2024, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication systems, and more particularly, to a method for device authorization in integrated sensing and communication (ISAC) and a related apparatus.BACKGROUND

[0003] Integrated sensing and communication (ISAC) enables both communication and sensing functions. While authorization of conventional relay UEs can be achieved through user subscription verification, ambient internet-of-things (AIoT) devices are not necessarily bound to subscriptions and may simultaneously participate in sensing, which raises new challenges in authorization and privacy protection.

[0004] Therefore, there is a need for a method for device authorization in integrated sensing and communication (ISAC) and a related apparatus.SUMMARY

[0005] An object of the present disclosure is to propose a method for device authorization in integrated sensing and communication (ISAC) and a related apparatus and a related apparatus, which can improve sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device.

[0006] In a first aspect of the present disclosure, a method performed by a radio access network (RAN) node for device authorization in integrated sensing and communication (ISAC) includes determining, by the RAN node, that at least one ambient internet-of-things (AIoT) device is within a vicinity of a remote object and determining whether the at least one AIoT device is authorized to participate in a sensing session.

[0007] In a second aspect of the present disclosure, a method performed by an ambient internet- of-things (AIoT) device for device authorization in integrated sensing and communication (ISAC) includes receiving, by the AIoT device, an indication from a radio access network (RAN) nodeAtty. Dkt. No. 10085-01-0177-PCT that the AIoT device is located within a vicinity of a remote object and is a candidate to participate in a sensing session and determining, by the AIoT device, whether the AIoT device is authorized to participate in the sensing session based on an authorization information.

[0008] In a third aspect of the present disclosure, a radio access network (RAN) node includes a determiner configured to determine that at least one ambient intemet-of-things (AIoT) device is within a vicinity of a remote object and determine whether the at least one AIoT device is authorized to participate in a sensing session.

[0009] In a fourth aspect of the present disclosure, an ambient intemet-of-things (AIoT) device includes a receiver configured to receive an indication from a radio access network (RAN) node that the AIoT device is located within a vicinity of a remote object and is a candidate to participate in a sensing session and a determiner configured to determine whether the AIoT device is authorized to participate in the sensing session based on an authorization information.

[0010] In a fifth aspect of the present disclosure, a radio access network (RAN) node includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The RAN node is configured to perform the above method.

[0011] In a sixth aspect of the present disclosure, an ambient internet-of-things (AIoT) device includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The AIoT device is configured to perform the above method.

[0012] In a seventh aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.

[0013] In an eighth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.

[0014] In a ninth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.

[0015] In a tenth aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.

[0016] In an eleventh aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obviousAtty. Dkt. No. 10085-01-0177-PCT that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.

[0018] FIG. l is a block diagram of a radio access network (RAN) node and one or more Ambient Internet of Things (AIoT) devices of communication in a communication system according to an embodiment of the present disclosure.

[0019] FIG. 2 is a block diagram of a RAN node according to an embodiment of the present disclosure.

[0020] FIG. 3 is a block diagram of an AIoT device according to an embodiment of the present disclosure.

[0021] FIG. 4 is a flowchart illustrating a method performed by a radio access network (RAN) node for device authorization in integrated sensing and communication (ISAC) according to an embodiment of the present disclosure.

[0022] FIG. 5 is a flowchart illustrating a method performed by an ambient internet-of-things (AIoT) device for device authorization in integrated sensing and communication (ISAC) according to an embodiment of the present disclosure.

[0023] FIG. 6A is a block diagram illustrating ISAC with a base station (BS) and a user equipment (UE) according to an embodiment of the present disclosure.

[0024] FIG. 6B is a block diagram illustrating ISAC with BS, UE, and AIoT device according to an embodiment of the present disclosure.

[0025] FIG. 7 is a flowchart illustrating ISAC using sensing UE and AIoT device with network authorization according to an embodiment of the present disclosure.

[0026] FIG. 8 is a flowchart illustrating sensing authorization based on AIoT device configuration according to an embodiment of the present disclosure.

[0027] FIG. 9 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.

[0028] FIG. 10 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS

[0029] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.

[0030] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system,Atty. Dkt. No. 10085-01-0177-PCT a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.

[0031] Optionally, a user equipment (UE) mentioned in the embodiments of the present application may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem, an in- vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.

[0032] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.

[0033] Integrated sensing and communication (ISAC) is a new technology. Authorization of devices surrounding a sensing object has not been considered. In communication with relay UE (e.g., UE-to-UE relay or UE-to-Network relay), each relay UE is bound to a subscriber or user and the authorization is achieved by verifying that the user has subscribed to relay service. In contrast to relay UEs that are authorized through user subscriptions, device authorization for ISAC has not yet been addressed.

[0034] When the surrounding devices are ambient internet-of-things (loT) devices, unlike relay UEs, these devices may or may not be bound to a traditional subscription of a normal user. In this case, authorization of a user subscription may not be applicable. Furthermore, there may be multiple ambient loT devices that are used to assist the sensing of a remote object and all of the ambient loT devices need to be authorized. This is also different from relay UE case where onlyAtty. Dkt. No. 10085-01-0177-PCT one relay UE is used at any time for a communication session. Unlike relay UEs, ambient loT devices may not be bound to user subscriptions, and since multiple such devices can simultaneously assist in sensing, all of them must be individually authorized.

[0035] When one or more AIoT devices are used, how to authorize these devices to assist with sensing of a remote object without compromising the privacy of the remote object (e.g., a human) is being addressed. In ISAC, unlike relay UEs that are authorized through user subscriptions, ambient loT devices may not be subscription-bound and multiple such devices may simultaneously assist in sensing, creating a need for proper authorization mechanisms that also preserve the privacy of the sensing object.

[0036] FIG. 1 illustrates that, in some embodiments, a RAN node 10 and one or more AIoT devices 20 of communication in a communication system 40. The communication system 40 includes the RAN node 10 and the one or more AIoT devices 20. The RAN node 10 may include a memory 12, a transceiver 13, and a processor 11 coupled to the memory 12 and the transceiver 13. The one or more AIoT devices 20 may include a memory 22, a transceiver 23, and a processor 21 coupled to the memory 22 and the transceiver 23. The processor 11 or 21 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 11 or 21. The memory 12 or 22 is operatively coupled with the processor 11 or 21 and stores a variety of information to operate the processor 11 or 21. The transceiver 13 or 23 is operatively coupled with the processor 11 or 21, and the transceiver 13 or 23 transmits and / or receives a radio signal.

[0037] The processor 11 or 21 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 12 or 22 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 13 or 23 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 12 or 22 and executed by the processor 11 or 21. The memory 12 or 22 can be implemented within the processor 11 or 21 or external to the processor 11 or 21 in which case those can be communicatively coupled to the processor 11 or 21 via various means as is known in the art.

[0038] In some embodiments, the processor 11 is configured to determine that at least one ambient intemet-of-things (AIoT) device 20 is within a vicinity of a remote object and determine whether the at least one AIoT device 20 is authorized to participate in a sensing session. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improveAtty. Dkt. No. 10085-01-0177-PCT sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device.

[0039] In some embodiments, the processor 11 initiates the sensing session in response to a sensing service request from a sensing function. In some embodiments, the processor 11 is configured to select a user equipment (UE) to perform sensing of the remote object. In some embodiments, the processor 11 is configured to request a network entity or a third-party application function associated with the at least one AIoT device 20 to verify whether the at least one AIoT device 20 is authorized to participate in the sensing session. In some embodiments, the transceiver 13 is configured to receive an authorization result of the at least one AIoT device 20, and the authorization result is determined by the network entity or the third-party application function. In some embodiments, the processor 11 is configured to trigger at least one authorized AIoT device to provide sensing information. In some embodiments, the processor 11 is configured to collect a sensing measurement data from the UE and from at least one authorized AIoT device 20.

[0040] In some embodiments, the transceiver 13 is configured to send the sensing measurement data to a sensing function to complete the sensing session. In some embodiments, the authorization result indicates whether the at least one AIoT device 20 is pre-configured to participate in the sensing session. In some embodiments, the processor 11 is configured to exclude the at least one AIoT device 20 from the sensing session when the authorization result indicates that the at least one AIoT device 20 is not authorized. In some embodiments, the processor 11 is configured to determine based on a pre-provisioned authorization information of the at least one AIoT device 20, whether the at least one AIoT device 20 is authorized to participate in the sensing session. In some embodiments, when the pre-provisioned authorization indicates that the at least one AIoT device 20 is authorized, the processor 11 triggers the at least one AIoT device 20 to participate in sensing and collects a sensing measurement data of the at least one AIoT device 20. In some embodiments, when the pre-provisioned authorization indicates that the at least one AIoT device 20 is not authorized, the processor 11 excludes the at least one AIoT device 20 from the sensing session.

[0041] In some embodiments, the transceiver 23 is configured to receive an indication from the RAN node 10 that the AIoT device 20 is located within a vicinity of a remote object and is a candidate to participate in a sensing session and the processor 21 is configured to determine whether the AIoT device 20 is authorized to participate in the sensing session based on an authorization information. This can solve issues in the prior art and other issues. Further, theAtty. Dkt. No. 10085-01-0177-PCT proposed some embodiments can improve sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device.

[0042] In some embodiments, the authorization information includes a pre-provisioned authorization configuration or a result received from a network entity or a third-party application function. In some embodiments, when the AIoT device 20 is authorized, the processor 21 activates sensing functionality and transmits a sensing measurement data to the RAN node 10. In some embodiments, when the AIoT device 20 is not authorized, the processor 21 refrains from participating in the sensing session. In some embodiments, the transceiver 23 receives an activation command from the RAN node 10 to initiate sensing. In some embodiments, the transceiver 23 receives the authorization result as part of a signaling message from a network entity or from a third-party application function associated with the AIoT device 20. In some embodiments, the pre-provisioned authorization configuration is stored locally in the AIoT device 20 and indicates whether the AIoT device 20 is permitted to participate in the sensing session.

[0043] FIG. 2 illustrates a RAN node 200 according to an embodiment of the present disclosure. The RAN node 200 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the RAN node 200 using any suitably configured hardware and / or software. The RAN node 200 includes a determiner 201. The determiner 201 is configured to determine that at least one ambient intemet-of-things (AIoT) device is within a vicinity of a remote object and determine whether the at least one AIoT device is authorized to participate in a sensing session. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device.

[0044] In some embodiments, the determiner 202 initiates the sensing session in response to a sensing service request from a sensing function. In some embodiments, the determiner 202 is configured to select a user equipment (UE) to perform sensing of the remote object. In some embodiments, the determiner 202 is configured to request a network entity or a third-party application function associated with the at least one AIoT device to verify whether the at least one AIoT device is authorized to participate in the sensing session. In some embodiments, the determiner 202 is configured to receive an authorization result of the at least one AIoT device, and the authorization result is determined by the network entity or the third-party application function. In some embodiments, the determiner 202 is configured to trigger at least one authorized AIoT device to provide sensing information. In some embodiments, the determiner 202 is configured to collect a sensing measurement data from the UE and from at least one authorized AIoT device.Atty. Dkt. No. 10085-01-0177-PCT

[0045] In some embodiments, the determiner 202 is configured to send the sensing measurement data to a sensing function to complete the sensing session. In some embodiments, the authorization result indicates whether the at least one AIoT device is pre-configured to participate in the sensing session. In some embodiments, the determiner 202 is configured to exclude the at least one AIoT device from the sensing session when the authorization result indicates that the at least one AIoT device is not authorized. In some embodiments, the determiner 202 is configured to determine based on a pre-provisioned authorization information of the at least one AIoT device, whether the at least one AIoT device is authorized to participate in the sensing session. In some embodiments, when the pre-provisioned authorization indicates that the at least one AIoT device is authorized, the determiner 202 triggers the at least one AIoT device to participate in sensing and collects a sensing measurement data of the at least one AIoT device. In some embodiments, when the preprovisioned authorization indicates that the at least one AIoT device is not authorized, the determiner 202 excludes the at least one AIoT device from the sensing session.

[0046] FIG. 3 illustrates an AIoT device 300 according to an embodiment of the present disclosure. The AIoT device 300 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the AIoT device 300 using any suitably configured hardware and / or software. The AIoT device 300 includes a receiver 301 and a determiner 302. The receiver 301 is configured to receive an indication from a radio access network (RAN) node that the AIoT device 300 is located within a vicinity of a remote object and is a candidate to participate in a sensing session, and the determiner 302 is configured to determine whether the AIoT device 300 is authorized to participate in the sensing session based on an authorization information. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device. In some embodiments,

[0047] In some embodiments, the authorization information includes a pre-provisioned authorization configuration or a result received from a network entity or a third-party application function. In some embodiments, when the AIoT device 300 is authorized, the determiner 302 activates sensing functionality and transmits a sensing measurement data to the RAN node. In some embodiments, when the AIoT device 300 is not authorized, the determiner 302 refrains from participating in the sensing session. In some embodiments, the receiver 301 receives an activation command from the RAN node to initiate sensing. In some embodiments, the receiver 301 receives the authorization result as part of a signaling message from a network entity or from a third-party application function associated with the AIoT device 300. In some embodiments, the pre-Atty. Dkt. No. 10085-01-0177-PCT provisioned authorization configuration is stored locally in the AIoT device 300 and indicates whether the AIoT device 300 is permitted to participate in the sensing session.

[0048] FIG. 4 illustrates a method 400 performed by a radio access network (RAN) node for device authorization in integrated sensing and communication (ISAC) according to an embodiment of the present disclosure. The method 400 performed by the RAN node is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 400 performed by the RAN node using any suitably configured hardware and / or software. In some embodiments, the method 400 performed by the RAN node includes: an operation 402, determining, by the RAN node, that at least one ambient internet-of- things (AIoT) device is within a vicinity of a remote object, and an operation 404, determining whether the at least one AIoT device is authorized to participate in a sensing session. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device.

[0049] In some embodiments, initiating the sensing session is performed by the RAN node in response to a sensing service request from a sensing function. In some embodiments, the method further includes selecting, by the RAN node, a user equipment (UE) to perform sensing of the remote object. In some embodiments, determining whether the at least one AIoT device is authorized to participate in the sensing session includes requesting, by the RAN node, a network entity or a third-party application function associated with the at least one AIoT device to verify whether the at least one AIoT device is authorized to participate in the sensing session. In some embodiments, the method further includes receiving, by the RAN node, an authorization result of the at least one AIoT device, wherein the authorization result is determined by the network entity or the third-party application function. In some embodiments, the method further includes triggering, by the RAN node, at least one authorized AIoT device to provide sensing information. In some embodiments, the method further includes collecting, by the RAN node, a sensing measurement data from the UE and from at least one authorized AIoT device.

[0050] In some embodiments, the method further includes sending, by the RAN node, the sensing measurement data to a sensing function to complete the sensing session. In some embodiments, the authorization result indicates whether the at least one AIoT device is pre-configured to participate in the sensing session. In some embodiments, the method further includes excluding the at least one AIoT device from the sensing session when the authorization result indicates that the at least one AIoT device is not authorized. In some embodiments, determining whether the at least one AIoT device is authorized to participate in the sensing session includes determining,Atty. Dkt. No. 10085-01-0177-PCT based on a pre-provisioned authorization information of the at least one AIoT device, whether the at least one AIoT device is authorized to participate in the sensing session. In some embodiments, when the pre-provisioned authorization indicates that the at least one AIoT device is authorized, the RAN node triggers the at least one AIoT device to participate in sensing and collects a sensing measurement data of the at least one AIoT device. In some embodiments, when the preprovisioned authorization indicates that the at least one AIoT device is not authorized, the RAN node excludes the at least one AIoT device from the sensing session.

[0051] Some embodiments describe a method for managing participation of Ambient loT (AIoT) devices in an integrated sensing and communication (ISAC) session. A sensing RAN node may initiate the session in response to a sensing service request and optionally select a UE to perform sensing of a remote object. The RAN node determines whether at least one AIoT device is authorized to participate, either by requesting verification from a network entity or third-party function, or by referencing pre-provisioned authorization information. Based on the authorization result, the RAN node triggers authorized AIoT devices to provide sensing information while excluding unauthorized devices. During the session, the RAN node collects sensing measurement data from both the UE and the authorized AIoT devices, and ultimately sends the aggregated data to a sensing function to complete the sensing session.

[0052] FIG. 5 illustrates a method 500 performed by an ambient internet-of-things (AIoT) device for device authorization in integrated sensing and communication (ISAC) according to an embodiment of the present disclosure. The method 500 performed by the AIoT device is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 500 performed by the AIoT device using any suitably configured hardware and / or software. In some embodiments, the method 500 performed by the AIoT device includes: an operation 502, receiving, by the AIoT device, an indication from a radio access network (RAN) node that the AIoT device is located within a vicinity of a remote object and is a candidate to participate in a sensing session, and an operation 504, determining, by the AIoT device, whether the AIoT device is authorized to participate in the sensing session based on an authorization information. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve sensing accuracy, preserve security and privacy of a sensing object, and / or reduce a risk of storing sensitive information in at least one AIoT device.

[0053] In some embodiments, the authorization information includes a pre-provisioned authorization configuration or a result received from a network entity or a third-party application function. In some embodiments, when the AIoT device is authorized, the AIoT device activates sensing functionality and transmits a sensing measurement data to the RAN node. In someAtty. Dkt. No. 10085-01-0177-PCT embodiments, when the AIoT device is not authorized, the AIoT device refrains from participating in the sensing session. In some embodiments, the AIoT device receives an activation command from the RAN node to initiate sensing. In some embodiments, the AIoT device receives the authorization result as part of a signaling message from a network entity or from a third-party application function associated with the AIoT device. In some embodiments, the pre-provisioned authorization configuration is stored locally in the AIoT device and indicates whether the AIoT device is permitted to participate in the sensing session.

[0054] In some embodiments, authorization information for an AIoT device may be provided either through a pre-provisioned local configuration or as a result received from a network entity or third-party application function. If authorized, the AIoT device activates its sensing functionality and transmits sensing measurement data to the RAN node; if not authorized, it refrains from participating. The AIoT device may receive an activation command from the RAN node to begin sensing, or directly receive the authorization result within a signaling message from the network entity or third-party function. When stored locally, the pre-provisioned authorization configuration specifies whether the AIoT device is permitted to join the sensing session.

[0055] Examples:

[0056] FIG. 6 A illustrates IS AC with a base station (BS) and a user equipment (UE) according to an embodiment of the present disclosure. ISAC in a communication system aims at acquiring information about a remote object or environment and its characteristics without physically contacting it (as illustrated in FIG. 6A). This technology relies on available devices (e.g., base station, UE, etc.) surrounding the remote object providing sensing data that is derived from radio signals impacted (e.g., reflected, refracted, diffracted) by an object or environment of interest for sensing purposes, and optionally processed within the communication system. The sensing data then can be used to derive meaningful information about the object for a variety of use cases such as presence of an object in a home (e.g., intruder), trajectory and position of a drone, e-health such as heart rate monitoring, motion of patient, etc. ISAC enables a communication system to acquire information about remote objects or environments by using radio signals impacted by them, with sensing data collected from surrounding devices such as base stations or UEs. This data can be processed to derive meaningful insights for use cases including intruder detection, drone tracking, patient monitoring, and other e-health applications.

[0057] FIG. 6B illustrates ISAC with BS, UE, and AIoT device according to an embodiment of the present disclosure. With the introduction of Ambient loT (AIoT) services, the accuracy of remote object being sensed can benefit tremendously when the number of Ambient loT devices surrounding the remote object are of great abundance and each Ambient loT device can provideAtty. Dkt. No. 10085-01-0177-PCT incrementally useful sensing data (as in FIG. 6B). However, if the surrounding Ambient loT devices are not properly authorized to provide sensing data, the sensing data can be misused for illegitimate purposes, such as compromising the privacy of the remote object (e.g., a human). Some embodiments of the present disclosure provide a mechanism to authorize one or more surrounding Ambient loT devices to provide sensing information for the remote object. With AIoT services, abundant surrounding devices can greatly improve sensing accuracy, but to prevent misuse and privacy risks, some embodiments of the disclosure provide mechanisms to authorize which AIoT devices may supply sensing data.

[0058] Unlike UEs, AIoT devices are generally stationary, deployed in abundance, and are in the direct communication path of a base station reader. When a remote object is being sensed, the network (i.e., base station) is aware that the remote object is within proximity. Since the base station is also aware of AIoT devices that are also within proximity, it can know which of the AIoT devices can provide assistance to the remote object being sensed. However, before any AIoT devices can be used to provide assistance, the AIoT devices have to be authorized. Unlike mobile UEs, stationary and abundant AIoT devices near a base station can assist in sensing a remote object, but they must first be authorized before providing such assistance.

[0059] Authorization of the AIoT devices to participate in the sensing of a remote object allows the sensing data to be collected by the network. AIoT device authorization is in addition to user consent (if applicable) given by the remote object (e.g., a human) or authorization that is needed from participating UEs and / or base stations.

[0060] AIoT devices are characterized by not having a conventional battery (or with limited battery) and is powered by energy harvesting, limited storage, and limited computing capabilities. Energy harvested by AIoT devices typically rely on wireless radio waves, solar, light, motion / vibration, heat, pressure, or other unconventional power sources. AIoT devices are also generally owned by either the operator or by a third-party application provider. In either case, AIoT devices need to be triggered by the network (either directly by the operator’s network or by an external application function via the network) in order to harvest energy and start functioning.

[0061] Since AIoT devices are generally stationary, the network and the BS reader that serves the AIoT devices are aware of their location due to the fact that AIoT devices need to be triggered to become active. When a remote object in the vicinity of the AIoT devices, the base station reader as instructed by the network determines whether and which AIoT devices are useful in assist with sensing of eh remote object.

[0062] Authorization of AIoT devices enables the network to collect their sensing data, complementing user consent and authorization of UEs or base stations when applicable. TheseAtty. Dkt. No. 10085-01-0177-PCT devices typically lack conventional batteries, relying instead on energy harvesting from sources such as radio waves, solar, or vibration, and thus have limited storage and computing capacity. Owned either by operators or third-party providers, AIoT devices must be triggered by the network or an external application function to activate and operate. Because they are stationary, their locations are known to the network and serving base station, which can then determine which AIoT devices in proximity to a remote object should be authorized and triggered to assist in sensing that object.

[0063] Authorization of the AIoT devices can be done in at least one of following ways:

[0064] 1. AIoT devices are pre-provisioned with indication that they are authorized to participate in sensing activities. The granularity of level of participation can be flexibly set, for example, based on the sensing activity (e.g., trajectory of the object being sensed), based on the object (e.g., only non-human objects being sensed), based on whether the AIoT device participation is primary or secondary (e.g., when there are no UEs available then the AIoT device participation would be considered primary), etc. In case AIoT devices have been pre-provisioned, their authorization indication will be sent to the network when the AIoT devices are triggered. Based on the authorization indication, the network determines whether to include or exclude a AIoT device to participate in sensing. AIoT devices can be pre-provisioned with flexible authorization levels for sensing activities, and when triggered, they report this authorization to the network, which then decides whether to include or exclude them in sensing.

[0065] 2. AIoT devices are triggered by the network, and the network will verify (either within the operator’s network or with the help of a third-party application function) the AIoT devices whether they are authorized to participate in sensing. In case the operator’s network determines the authorization, the authorization may be based on different granularities. When the third-party application provides the authorization, the third-party application function may not need to indicate to the operator details of the authorization. When triggered by the network, AIoT devices undergo authorization verification either by the operator’s network or a third-party application function, with authorization determined at varying levels of granularity.

[0066] Since AIoT devices are also characterized as having limited storage and responds only when triggered, there is very little risk of the AIoT devices retaining any privacy related information, thus reducing the privacy exposure of the object being sensed. Additionally, since AIoT devices only respond when trigger, should they retain any privacy information, it can only be accessible by the network when the network triggers the AIoT device to respond. Because AIoT devices have limited storage and only respond when triggered, they pose minimal risk of retaining or exposing privacy-related information of the sensed object.Atty. Dkt. No. 10085-01-0177-PCT

[0067] FIG. 7 illustrates ISAC using sensing UE and AIoT device with network authorization according to an embodiment of the present disclosure, and includes at least one of the following steps:

[0068] Step 1. A sensing function initiates a sensing service request toward a RAN node such as a sensing RAN node or a RAN sensing node.

[0069] Step 2. The RAN sensing node selects a UE such as a sensing UE to initiate sensing.

[0070] Step 3. The RAN sensing node, being aware of AIoT devices in the vicinity, requests the network to verify whether the AIoT devices are authorized to participate in the sensing session and triggers the authorized AIoT devices to participate.

[0071] Step 4. If an AIoT device belongs to a third-party application function, the authorization is performed by that third-party application function.

[0072] Step 5. The RAN sensing node triggers the AIoT device to participate in sensing.

[0073] Step 6. The RAN sensing node collects sensing measurements from the UE.

[0074] Step 7. The RAN sensing node collects sensing measurements from the AIoT device.

[0075] Step 8. The sensing data is sent to the sensing function, and the sensing session terminates.

[0076] In some embodiments, ISAC involves the sensing function initiating a service request to a sensing RAN node, which then selects a sensing UE and verifies nearby AIoT devices for authorization through the network or a third-party application function. Authorized AIoT devices are triggered to participate alongside the UE, and the RAN node collects sensing measurements from both. The collected sensing data is then forwarded to the sensing function, upon which the sensing session is terminated.

[0077] In another example of a distributed NAS security policy, only the AMF is involved in enforcing the distributed NAS security policy. In this case, the only difference is Step 2 where the distributed NAS security policy is kept within the network (e.g., sent only to AMF) and not shared with the UE. Example is illustrated in FIG. 8. FIG. 8 illustrates sensing authorization based on AIoT device configuration according to an embodiment of the present disclosure, and includes at least one of the following steps:

[0078] Step 1. A sensing function initiates a sensing service request toward a RAN node such as a sensing RAN node or a RAN sensing node.

[0079] Step 2. The RAN sensing node selects a UE such as a sensing UE to initiate sensing.

[0080] Step 3. The RAN sensing node, being aware of an AIoT device in the vicinity, triggers the device to participate in sensing. If the pre-provisioned authorization indicates that the AIoT device is authorized, the sensing session continues; otherwise, the AIoT device is excluded.

[0081] Step 4. The RAN sensing node collects sensing measurements from the UE.Atty. Dkt. No. 10085-01-0177-PCT

[0082] Step 5. If the AIoT device is authorized based on its authorization pre-configuration, the RAN sensing node also collects sensing measurements from the AIoT device.

[0083] Step 6. The sensing data is sent to the sensing function, and the sensing session terminates.

[0084] In some embodiments, sensing authorization based on AIoT device configuration involves the sensing function initiating a service request to the sensing RAN node, which selects a sensing UE and triggers nearby AIoT devices to participate. If a pre-provisioned authorization confirms the AIoT device is permitted, the RAN node collects sensing measurements from both the UE and the AIoT device; otherwise, the device is excluded. The collected sensing data is then forwarded to the sensing function, after which the sensing session terminates.

[0085] In some embodiments, the proposed solution of authorizing AIoT devices to participate in sensing enhances accuracy by leveraging the abundance of AIoT devices to provide additional measurements alongside UEs. At the same time, limiting participation to authorized devices preserves the security and privacy of the sensed object, particularly when the object is a human. Furthermore, because AIoT devices have minimal storage, require network triggering to respond, and conserve energy by restricting write-to-memory cycles to critical updates only, the risk of storing or exposing privacy-related information is significantly reduced.

[0086] In some embodiments, the proposed solution of authorizing AIoT devices to participate in the sensing greatly improves sensing accuracy. The more sensing measurements are taken about a sensing object, the more accurate the sensing result. Since AIoT devices are expected to be abundantly available, combining sensing measurement of both AIoT device and UE greatly improves sensing accuracy. Authorizing abundant AIoT devices to participate in sensing, alongside UEs, significantly enhances sensing accuracy by increasing the number of measurements collected for a sensing object.

[0087] Since only authorized AIoT devices are allowed to participate in the sensing session, the security and privacy of the sensing object is preserved, especially if the sensing object is a human. Due to the limited capabilities of AIoT device (e.g., no or little memory storage, need to be triggered in order to respond), each write-to-memory cycle consumes significant amount of energy from which the AIoT device may not have sufficient power to perform other important duties. Because of the constraint of write-cycle, only very critical information or update is written into the AIoT device., the potential to store privacy related information in the AIoT device is reduced. Restricting participation to authorized AIoT devices preserves security and privacy, while their limited storage, trigger-based operation, and energy constraints further reduce the risk of retaining sensitive information.Atty. Dkt. No. 10085-01-0177-PCT

[0088] Alternative to letting AIoT device’s pre-configuration to determine its participation in sensing session is to have the AIoT device reporting its capabilities to the RAN sensing node and let RAN sensing node to decide whether to trigger the AIoT device or not. This has the negative impact that in order to get the AIoT device’ s pre-configuration, the AIoT device has to be triggered first which causes the AIoT device to consume power unnecessarily. As an alternative, AIoT devices may report their capabilities to the RAN sensing node for participation decisions, but this requires triggering them first, leading to unnecessary power consumption.

[0089] In summary, in some embodiments, ISAC can be supported by both sensing UEs and AIoT devices under network authorization. A sensing function may initiate a service request to a sensing RAN node, which then selects a sensing UE and determines whether nearby AIoT devices are authorized to participate, either through verification by the network or based on preprovisioned configuration. Authorized AIoT devices are triggered to provide sensing measurements alongside the UE, while unauthorized devices are excluded. The sensing RAN node collects the sensing data from both the UE and any authorized AIoT devices and forwards the aggregated results to the sensing function, after which the sensing session terminates.

[0090] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Improve sensing accuracy. 4. Preserve security and privacy of a sensing object. 5. Reduce a risk of storing sensitive information in at least one AIoT device. 6. Provide a good communication performance. 7. Provide high reliability. 8. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.Atty. Dkt. No. 10085-01-0177-PCT

[0091] FIG. 9 is an example of a computing device 1400 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 9 illustrates an example of the computing device 1400 that can implement apparatuses and methods of the above embodiments of FIGs. 1 to 8, using any suitably configured hardware and / or software. In some embodiments, the computing device 1400 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.

[0092] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer-readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer-readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.

[0093] The computing device 1400 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1400. The computing device 1400 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1400 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.Atty. Dkt. No. 10085-01-0177-PCT

[0094] The computing device 1400 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 8. The program code may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.

[0095] The computing device 1400 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1400 can transmit messages as electronic or optical signals via the network interface device 1424.

[0096] FIG. 10 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 10 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (VO) interface 1580, coupled with each other at least as illustrated.

[0097] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include any combination of general-purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 8. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.

[0098] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wirelessAtty. Dkt. No. 10085-01-0177-PCT personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multimode baseband circuitry.

[0099] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.

[0100] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1 to 8 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.

[0101] In various embodiments, the VO interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments,Atty. Dkt. No. 10085-01-0177-PCT the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.

[0102] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.

[0103] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware or combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.

[0104] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative coupling operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.

[0105] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.Atty. Dkt. No. 10085-01-0177-PCT

[0106] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.

[0107] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.

Claims

Atty. Dkt. No. 10085-01-0177-PCTWhat is claimed is:

1. A method performed by a radio access network (RAN) node for device authorization in integrated sensing and communication (ISAC), the method comprising: determining, by the RAN node, that at least one ambient internet-of-things (AIoT) device is within a vicinity of a remote object; and determining whether the at least one AIoT device is authorized to participate in a sensing session.

2. The method of claim 1, wherein initiating the sensing session is performed by the RAN node in response to a sensing service request from a sensing function.

3. The method of claim 1, further comprising selecting, by the RAN node, a user equipment (UE) to perform sensing of the remote object.

4. The method of claim 1, wherein determining whether the at least one AIoT device is authorized to participate in the sensing session comprises requesting, by the RAN node, a network entity or a third-party application function associated with the at least one AIoT device to verify whether the at least one AIoT device is authorized to participate in the sensing session.

5. The method of claim 4, further comprising receiving, by the RAN node, an authorization result of the at least one AIoT device, wherein the authorization result is determined by the network entity or the third-party application function.

6. The method of claim 5, further comprising triggering, by the RAN node, at least one authorized AIoT device to provide sensing information.

7. The method of claim 5, further comprising collecting, by the RAN node, a sensing measurement data from the UE and from at least one authorized AIoT device.

8. The method of claim 7, further comprising sending, by the RAN node, the sensing measurement data to a sensing function to complete the sensing session.

9. The method of claim 5, wherein the authorization result indicates whether the at least one AIoT device is pre-configured to participate in the sensing session.

10. The method of claim 5, further comprising excluding the at least one AIoT device from the sensing session when the authorization result indicates that the at least one AIoT device is not authorized.

11. The method of claim 1 , wherein determining whether the at least one AIoT device is authorized to participate in the sensing session comprises determining, based on a pre-provisioned authorization information of the at least one AIoT device, whether the at least one AIoT device is authorized to participate in the sensing session.

12. The method of claim 11, wherein when the pre-provisioned authorization indicates that the atAtty. Dkt. No. 10085-01-0177-PCT least one AIoT device is authorized, the RAN node triggers the at least one AIoT device to participate in sensing and collects a sensing measurement data of the at least one AIoT device.

13. The method of claim 11, wherein when the pre-provisioned authorization indicates that the at least one AIoT device is not authorized, the RAN node excludes the at least one AIoT device from the sensing session.

14. A method performed by an ambient internet-of-things (AIoT) device for device authorization in integrated sensing and communication (ISAC), the method comprising: receiving, by the AIoT device, an indication from a radio access network (RAN) node that the AIoT device is located within a vicinity of a remote object and is a candidate to participate in a sensing session; and determining, by the AIoT device, whether the AIoT device is authorized to participate in the sensing session based on an authorization information.

15. The method of claim 14, wherein the authorization information comprises a pre-provisioned authorization configuration or a result received from a network entity or a third-party application function.

16. The method of claim 15, wherein when the AIoT device is authorized, the AIoT device activates sensing functionality and transmits a sensing measurement data to the RAN node.

17. The method of claim 15, wherein when the AIoT device is not authorized, the AIoT device refrains from participating in the sensing session.

18. The method of claim 15, wherein the AIoT device receives an activation command from the RAN node to initiate sensing.

19. The method of claim 15, wherein the AIoT device receives the authorization result as part of a signaling message from a network entity or from a third-party application function associated with the AIoT device.

20. The method of claim 15, wherein the pre-provisioned authorization configuration is stored locally in the AIoT device and indicates whether the AIoT device is permitted to participate in the sensing session.

21. A radio access network (RAN) node, comprising: a determiner configured to: determine that at least one ambient internet-of-things (AIoT) device is within a vicinity of a remote object; and determine whether the at least one AIoT device is authorized to participate in a sensing session.

22. An ambient internet-of-things (AIoT) device, comprising: a receiver configured to receive an indication from a radio access network (RAN) node that theAtty. Dkt. No. 10085-01-0177-PCTAIoT device is located within a vicinity of a remote object and is a candidate to participate in a sensing session; and a determiner configured to determine whether the AIoT device is authorized to participate in the sensing session based on an authorization information.

23. A radio access network (RAN) node, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the RAN node is configured to perform the method of any one of claims 1 to 13.

24. An ambient internet-of-things (AIoT) device, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the AIoT device is configured to perform the method of any one of claims 14 to 20.

25. A non-transitory machine-readable storage medium having stored thereon instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 20.

26. A chip, comprising: a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the method of any one of claims 1 to 20.

27. A computer readable storage medium, in which a computer program is stored, wherein the computer program causes a computer to execute the method of any one of claims 1 to 20.

28. A computer program product, including a computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 20.

29. A computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 20.