Security of artificial intellection of things application protocol
AKMA and AIoTF enhance 5G network security by deriving and managing security keys, addressing the lack of defined protocols for UE-AIoT associations, ensuring reliable AIoT services through existing 5G infrastructure.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2024-11-15
- Publication Date
- 2026-05-21
AI Technical Summary
The existing wireless communication systems lack a defined security protocol for establishing secure associations between user equipment (UE) and artificial intelligence of things (AIoT) functions, particularly in the context of 5G networks, which are crucial for supporting diverse access requirements and emerging business needs.
Implementing authentication and key management for applications (AKMA) to derive and manage security keys, such as KAKMA and KAIOTF, using existing 5G primary authentication procedures, and introducing a new core network function (AIoTF) to manage device-related information and facilitate secure communication between UE and AIoT devices.
Establishes secure communication channels between UE and AIoT devices, ensuring reliable and efficient AIoT services by leveraging existing 5G infrastructure and enhancing security associations without additional authentication steps.
Smart Images

Figure CN2024132148_21052026_PF_FP_ABST
Abstract
Description
SECURITY OF ARTIFICIAL INTELLECTION OF THINGS APPLICATION PROTOCOLTECHNICAL FIELD
[0001] This document is directed generally to digital wireless communications.BACKGROUND
[0002] Mobile telecommunication technologies are moving the world toward an increasingly connected and networked society. In comparison with the existing wireless networks, next generation systems and wireless communication techniques will need to support a much wider range of use-case characteristics and provide a more complex and sophisticated range of access requirements and flexibilities.
[0003] Long-Term Evolution (LTE) is a standard for wireless communication for mobile devices and data terminals developed by 3rd Generation Partnership Project (3GPP) . LTE Advanced (LTE-A) is a wireless communication standard that enhances the LTE standard. The 5th generation of wireless system, known as 5G, advances the LTE and LTE-A wireless standards and is committed to supporting higher data-rates, large number of connections, ultra-low latency, high reliability and other emerging business needs.SUMMARY
[0004] Techniques are disclosed for providing security of artificial intelligence of things (AIoT) using, for example, authentication and key management for applications (AKMA) .
[0005] A first wireless communication method includes receiving, by a unified data management (UDM) , one or more device identifiers of one or more first type of wireless devices and one or more identifiers of one or more second type of wireless devices, where each device from the first type of wireless devices and the second type of wireless devices has a single identifier; and storing, by the UDM, a mapping of the one or more device identifiers and the one or more identifiers.
[0006] In some embodiments, the one or more device identifiers includes a device identifier that identifies a first device of the one or more first type of wireless devices, and the device identifier is used to register the first device with a second device of the one or more second type of wireless devices. In some embodiments, the mapping between the one or more device identifiers and the one or more identifiers is changed in response to a change associated with a second device from the one or more second type of wireless devices. In some embodiments, the change includes a movement of the second device. In some embodiments, the one or more first type of wireless devices includes at least one artificial intelligence of things (AIoT) device, and the one or more second type of wireless devices includes one or more user equipment (UE) .
[0007] A second wireless communication method includes transmitting, by a first network function to a second network function, a first message that includes one or more device identifiers of one or more first type of wireless devices, where the first message triggers the second network function to provide one or more identifiers that identifies one or more second type of wireless devices and that corresponds to the one or more device identifiers; and receiving, by the first network function from the second network function, a list comprising the one or more identifiers mapped to the one or more device identifiers.
[0008] In some embodiments, the method further comprises transmitting, by the first network function to an authentication and key management for applications anchor function (AAnF) , a second message that includes an identifier of a second device, wherein the second message requests a key of the first network function; and receiving, by the first network function from the AAnF, the key of the first network function and an authentication and key management for applications key identifier (A-KID) . In some embodiments, the key of the first network function is a derived from an authentication and key management for applications (AKMA) key. In some embodiments, the key of the first network function is a derived using: a string of fixed digits, an identifier of the first network function, a length of the identifier of the first network function, a parameter of the second device, and a length of the parameter of the second device.
[0009] In some embodiments, the method further comprises transmitting, by the first network function to the second device, a third message comprising the A-KID and an AIoT service request; and receiving, by the first network function from the second device, a response message that includes a device identifier of a first device from the one or more first type of wireless devices, where the response message comprising the device identifier indicates that a security association between the second device and the first network function has been established. In some embodiments, the first network function includes an artificial intelligence of things function (AIoTF) , the second network function includes a unified data management (UDM) , the one or more first type of wireless devices includes at least one artificial intelligence of things (AIoT) device, and the one or more second type of wireless devices includes one or more user equipment (UE) .
[0010] In yet another exemplary aspect, the above-described methods are embodied in the form of processor-executable code and stored in a non-transitory computer-readable storage medium. The code included in the computer readable storage medium when executed by a processor, causes the processor to implement the methods described in this patent document.
[0011] In yet another exemplary embodiment, a device that is configured or operable to perform the above-described methods is disclosed.
[0012] The above and other aspects and their implementations are described in greater detail in the drawings, the descriptions, and the claims.
[0013] BRIEF DESCRIPTION OF THE DRAWING
[0014] FIG. 1 shows the procedure to derive authentication and key management for applications (AKMA) key (KAKMA) after a successful primary authentication.
[0015] FIG. 2A shows an example user-plane architecture for Topology 2.
[0016] FIG. 2B shows an example protocol stack for the user-plane architecture for Topology 2.
[0017] FIG. 3 shows an example process for deriving KAKMA after primary authentication.
[0018] FIG. 4 shows an example process for establishing Security association between UE (reader) and AF (AIOTF) .
[0019] FIG. 5 shows an exemplary block diagram of a hardware platform that may be a part of a network device or a communication device.
[0020] FIG. 6 shows an example of wireless communication including a base station (BS) and user equipment (UE) based on some implementations of the disclosed technology.
[0021] FIG. 7 shows an exemplary flowchart for storing a mapping of device identifier (s) of one or more first type of wireless device and identifier (s) of one or more second type of wireless devices.
[0022] FIG. 8 shows an exemplary flowchart for receiving a list of one or more identifiers of one or more second type of wireless devices and one or more device identifiers of one or more first type of wireless devices.DETAILED DESCRIPTION
[0023] In the user-plane architecture for Topology 2 (e. g., user equipment (UE) as reader) to support artificial intelligence of things (AIoT) services, the security of artificial intelligence of things application protocol (AIoT-AP) interface is not defined yet. The terms “UE as reader” or “UE (reader) ” can include scenarios where the UE operates as a relay to receive and forward message (s) and / or where the UE reads a message from an AIoT device to determine whether it is an inventory message or a command that instructs the UE to perform an operation. In an example embodiment, this patent document describes using authentication and key management for applications (AKMA) to establish security association between UE (reader) and AIoT function (AF) (also known as AIOTF) . Before start AIoT service, AIOTF may push an Naanf_AKMA_ApplicationKey_Get request to AKMA anchor function (AAnF) to get key KAIOTF which is the AIOTF key. KAIOTF can be used for the security between UE (reader) and AF (AIOTF) . And, the AIoT Service Request can be piggybacked in (or included in) application session establishment request message from AF (AIOTF) to UE (reader) .
[0024] The example headings for the various sections below are used to facilitate the understanding of the disclosed subject matter and do not limit the scope of the claimed subject matter in any way. Accordingly, one or more features of one example section can be combined with one or more features of another example section. Furthermore, 5G terminology is used for the sake of clarity of explanation, but the techniques disclosed in the present document are not limited to 5G technology only, and may be used in wireless systems that implemented other protocols.
[0025] I. Introduction About Authentication and Key Management for Applications (AKMA)
[0026] I. (a) . Deriving AKMA key after primary authentication
[0027] There is no separate authentication of the UE to support AKMA functionality. Instead, AKMA reuses the 5G primary authentication procedure executed, e. g., during the UE registration to authenticate the UE. A successful 5G primary authentication results in KAUSF being stored at the AUSF and the UE. FIG. 1 shows the procedure to derive AKMA key KAKMA after a successful primary authentication. The steps described below are related to the steps identified in FIG. 1
[0028] 1) During the primary authentication procedure, the authentication server function (AUSF) interacts with the unified data management (UDM) in order to fetch authentication information such as subscription credentials (e. g. AKA Authentication vectors) and the authentication method using the Nudm_UEAuthentication_Get Request service operation.
[0029] 2) In the response, the UDM may also indicate to the AUSF whether the AKMA Anchor key needs to be generated for the UE. If the AKMA indication is included, the UDM may also include the RID of the UE.
[0030] 3) If the AUSF receives the AKMA indication from the UDM, the AUSF may store the KAUSF and generate the AKMA Anchor Key (KAKMA) and the A-KID from KAUSF after the primary authentication procedure is successfully completed.
[0031] The UE may generate the AKMA Anchor Key (KAKMA) and the A-KID from the KAUSF before initiating communication with an AKMA Application Function.
[0032] 4) After AKMA key material is generated, the AUSF selects the AKMA anchor function (AAnF) , and may send the generated keys A-KID and KAKMA to the AAnF together with the SUPI of the UE using the Naanf_AKMA_KeyRegistration Request service operation. The AAnF may store the latest information sent by the AUSF.
[0033] The AUSF need not store any AKMA key material after delivery to the AAnF. When re-authentication runs, the AUSF generates a new A-KID, and a new KAKMA and sends the new generated A-KID and KAKMA to the AAnF. After receiving the new generated A-KID and KAKMA, the AAnF deletes the old A-KID and KAKMA and stores the new generated A-KID and KAKMA.
[0034] 5) The AAnF sends the response to the AUSF using the Naanf_AKMA_AnchorKey_Register Response service operation.
[0035] A-KID identifies the KAKMA key of the UE.
[0036] A-KID may be in NAI format, e. g., username@realm. The username part may include the RID and the A-TID (AKMA Temporary UE Identifier) , and the realm part may include Home Network Identifier.
[0037] The A-TID may be derived from KAUSF.
[0038] The AUSF may use the RID received from the UDM as described in step 2 to derive A-KID.
[0039] The chance of A-TID collision is not zero but practically low as the A-TID derivation is based on KDF. The detection of A-TID collision as well as potential handling of collision is not addressed in the present document.
[0040] KAKMA may be derived from KAUSF. Since KAKMA and A-TID in A-KID are both derived from KAUSF based on primary authentication run, the KAKMA and A-KID can only be refreshed by a new successful primary authentication.
[0041] I.(b) . About AIoTF
[0042] A new core network function is introduced to support Ambient IoT (e. g. AIoTF) service for both the topology 1 and topology 2. The AIoTF performs the following functionality:
[0043] · The AIoTF manages the device related information.
[0044] · The AIoTF registers itself in the NRF with its NF profile.
[0045] · The AIoTF receives an AIoT service request from the AF and triggers the BS / UE readers to perform AIoT service operations towards the AIoT Device (s) .
[0046] · The AIoTF aggregates the service operation results (including the removal of the duplicated devices records) from BS Readers and UE Readers and sends to AF.
[0047] I. (c) . Architecture to Support Topology 2 (User-plane option) :
[0048] The following principles may apply:
[0049] As depicted in FIG. 2A, the UE Reader connects to the AIoTF based on the AIoT Application Protocol (AIoT-AP) using an IP PDU Session between the UE and the UPF as transport. The related protocol stack is shown in FIG. 2B. The AIoT AP protocol will support procedures and information to be exchanged. Which transport protocol to use for AIoT-AP can be decided. Security for AIoT-AP is assumed to be defined.
[0050] II. Example Techniques
[0051] FIG. 3 shows an example process for deriving KAKMA after primary authentication. The steps described below are related to the steps identified in FIG. 3.
[0052] 1) AIoT device initiates or triggers a registration process by registering into the UE (reader) , and the reader stores AIoT device ID (also known as device ID) . The AIoT device registers into the UE (reader) by sending the UE (reader) the AIoT device ID of the AIoT device.
[0053] 2) The UE (reader) initiates the registration procedure upon receiving the AIoT device ID from the AIoT device. The UE (reader) sends device ID (s) included in the registration request to the AMF. In some embodiments, one or more AIoT devices may send their respective one or more AIoT device IDs (including the AIoT device ID received in step 1) to the UE so that the UE may include the one or more AIoT device IDs in the registration request. In some embodiments, the UE (reader) may include reader ID (e. g., SUCI) of the UE in the registration request.
[0054] 3) Primary authentication procedure. Device ID (s) are also transferred to the UDM. In some embodiments, the UE may send the device ID (s) to the UDM.
[0055] 4) During primary authentication procedure, if the AUSF receives the AKMA indication from the UDM, the AUSF may store the KAUSF and generate the AKMA Anchor Key (KAKMA) and the A-KID from KAUSF after the primary authentication procedure is successfully completed. A-KID can identify the KAKMA key of the UE (reader) .
[0056] The UE may generate the AKMA Anchor Key (KAKMA) and the A-KID from the KAUSF before initiating communication with an AKMA Application Function.
[0057] After the registration, the mapping of device IDs to reader IDs may be stored in the UDM. The UDM may communicate with a plurality of UEs using their respective reader IDs. Each reader ID may be associated with one or more device IDs so that the mapping between the reader IDs and the one or more device IDs can be stored in the UDM. The mapping can be updated by some mechanisms. For example, when the UE (reader) moves, the mapping between the reader ID and the device ID is changed.
[0058] 5) After AKMA key material is generated, the AUSF selects the AAnF, and may send the generated A-KID and KAKMA to the AAnF together with the SUPI of the UE using the Naanf_AKMA_KeyRegistration Request service operation. A-KID identifies the KAKMA key of the UE (reader) .
[0059] 6) The AAnF sends the response to the AUSF using the Naanf_AKMA_AnchorKey_Register Response service operation.
[0060] FIG. 4 shows an example process for establishing Security association between UE (reader) and AF (AIOTF) .
[0061] One of the pre-requisite of FIG. 4 is that a primary authentication may be successfully performed, and KAKMA may be derived and stored in both UE (reader) and AAnF.
[0062] 1) The AF (AIOTF) sends Nudm_AIoT_readerdeviceMAPPing_Get Request to UDM to get the reader ID corresponding to the device ID (s) (also known as AIoT device ID (s) ) . The device ID (s) of the AIoT device (s) may be stored in the AIOTF.
[0063] 2) The UDM responds with Nudm_AIoT_readerdeviceMAPPing_Get Responds including the device ID-reader ID list. The device ID-reader ID list includes a mapping between one or more device IDs and one or more reader IDs, where each reader ID can be associated with one or more device IDs.
[0064] 3) The AF (AIOTF) selects the AAnF, and sends a Naanf_AKMA_ApplicationKey_Get request to AAnF with the AF_ID to request the AIOTF key (KAIOTF) for the UE. The AF also includes the reader ID in the request. The AF can get the reader ID to communicate with the UE (reader) to get or derive the KAIOTF.
[0065] 4) If the reader ID is not SUPI, the AAnF sends an Nudm_SDM_Get Request to UDM. The identifier translation indicates that SUPI of the UE (reader) is requested.
[0066] 5) The UE responds with Nudm_SDM_Get Response, and the SUPI of UE (reader) is included in the message.
[0067] 6) The AAnF derives the AIOTF Key (KAIOTF) from KAKMA if it does not already have KAIOTF. The KAIOTF can be the same as KAIOTF used in AKMA. Or key derivation of KAIOTF can be performed as follows.
[0068] KAIOTF derivation function
[0069] When deriving a KAIOTF from KAKMA, the following parameters may be used to form the input S to the KDF:
[0070] · FC = 0xxx, where FC is a string of fixed digits;
[0071] · P0 =AF_ID;
[0072] · L0 = length of AF_ID;
[0073] · P1 = reader parameter (e. g. location of UE (reader) ) ;
[0074] · L1 = length of reader parameter.
[0075] The input key KEY may be KAKMA. The parameter shown above form the input S so that S and KEY can be all the inputs needed for the key derivation function (KDF) .
[0076] 7) The AAnF sends Naanf_AKMA_ApplicationKey_Get response to the AF with SUPI / GPSI, KAIOTF and the KAIOTF expiration time. A-KID is also included in the message.
[0077] 8) The AF (AIOTF) sends Application Session Establishment Request message to the UE (reader) with A-KID. The AIoT Service Request is piggybacked in (or included in) the message. The UE (reader) can use the A-KID to find which KAKMA to use. The UE (reader) can generate the KAIOTF from the KAKMA after receiving the Application Session Establishment Request message.
[0078] 9) UE (reader) sends AIoT Service Request to AIoT device. The AIoT Service Request can be inventory or command.
[0079] 10) The AIoT device sends AIoT Service Response to the UE (reader) with device ID.
[0080] 11) After the KAIOTF is derived on both the UE (reader) and AIOTF, the UE (reader) indicates to the AF that the communication between them is securely protected. The UE (reader) sends the Application Session Establishment Response to the AF (AIOTF) with device ID. It means that the security association between the UE (reader) and the AF (AIOTF) is established.
[0081] FIG. 5 shows an exemplary block diagram of a hardware platform 500 that may be a part of a network device (e. g., base station) or a communication device (e. g., a user equipment (UE) , AIoT device) or a core network device (e. g., access and mobility management function (AMF) , AUSF, UDM, AAnF or AIoTF) . The hardware platform 500 includes at least one processor 510 and a memory 505 having instructions stored thereupon. The instructions upon execution by the processor 510 configure the hardware platform 500 to perform the operations described in FIGS. 1 to 4, 6 to 8, and in the various embodiments described in this patent document. The transmitter 515 transmits or sends information or data to another device. For example, a network device transmitter can send a message to a user equipment. The receiver 520 receives information or data transmitted or sent by another device. For example, a user equipment can receive a message from a network device.
[0082] The implementations as discussed above will apply to a wireless communication. FIG. 6 shows an example of a wireless communication system (e. g., a 5G or NR cellular network) that includes a base station 620 and one or more user equipment (UE) 611, 612 and 613. In some embodiments, the UEs access the BS (e. g., the network) using a communication link to the network (sometimes called uplink direction, as depicted by dashed arrows 631, 632, 633) , which then enables subsequent communication (e. g., shown in the direction from the network to the UEs, sometimes called downlink direction, shown by arrows 641, 642, 643) from the BS to the UEs. In some embodiments, the BS send information to the UEs (sometimes called downlink direction, as depicted by arrows 641, 642, 643) , which then enables subsequent communication (e. g., shown in the direction from the UEs to the BS, sometimes called uplink direction, shown by dashed arrows 631, 632, 633) from the UEs to the BS. The UE may be, for example, a smartphone, a tablet, a mobile computer, a machine to machine (M2M) device, an Internet of Things (IoT) device, and so on.
[0083] FIG. 7 shows an exemplary flowchart for storing a mapping of device identifier (s) of one or more first type of wireless device and identifier (s) of one or more second type of wireless devices. Operation 702 includes receiving, by a unified data management (UDM) , one or more device identifiers of one or more first type of wireless devices and one or more identifiers of one or more second type of wireless devices, where each device from the first type of wireless devices and the second type of wireless devices has a single identifier. Operation 704 includes storing, by the UDM, a mapping of the one or more device identifiers and the one or more identifiers.
[0084] In some embodiments, the one or more device identifiers includes a device identifier that identifies a first device of the one or more first type of wireless devices, and the device identifier is used to register the first device with a second device of the one or more second type of wireless devices. In some embodiments, the mapping between the one or more device identifiers and the one or more identifiers is changed in response to a change associated with a second device from the one or more second type of wireless devices. In some embodiments, the change includes a movement of the second device. In some embodiments, the one or more first type of wireless devices includes at least one artificial intelligence of things (AIoT) device, and the one or more second type of wireless devices includes one or more user equipment (UE) .
[0085] FIG. 8 shows an exemplary flowchart for receiving a list of one or more identifiers of one or more second type of wireless devices and one or more device identifiers of one or more first type of wireless devices. Operation 802 includes transmitting, by a first network function to a second network function, a first message that includes one or more device identifiers of one or more first type of wireless devices, where the first message triggers the second network function to provide one or more identifiers that identifies one or more second type of wireless devices and that corresponds to the one or more device identifiers. Operation 804 includes receiving, by the first network function from the second network function, a list comprising the one or more identifiers mapped to the one or more device identifiers.
[0086] In some embodiments, the method further comprises transmitting, by the first network function to an authentication and key management for applications anchor function (AAnF) , a second message that includes an identifier of a second device, wherein the second message requests a key of the first network function; and receiving, by the first network function from the AAnF, the key of the first network function and an authentication and key management for applications key identifier (A-KID) . In some embodiments, the key of the first network function is a derived from an authentication and key management for applications (AKMA) key. In some embodiments, the key of the first network function is a derived using: a string of fixed digits, an identifier of the first network function, a length of the identifier of the first network function, a parameter of the second device, and a length of the parameter of the second device.
[0087] In some embodiments, the method further comprises transmitting, by the first network function to the second device, a third message comprising the A-KID and an AIoT service request; and receiving, by the first network function from the second device, a response message that includes a device identifier of a first device from the one or more first type of wireless devices, where the response message comprising the device identifier indicates that a security association between the second device and the first network function has been established. In some embodiments, the first network function includes an artificial intelligence of things function (AIoTF) , the second network function includes a unified data management (UDM) , the one or more first type of wireless devices includes at least one artificial intelligence of things (AIoT) device, and the one or more second type of wireless devices includes one or more user equipment (UE) .
[0088] In this document the term “exemplary” is used to mean “an example of” and, unless otherwise stated, does not imply an ideal or a preferred embodiment.
[0089] Some of the embodiments described herein are described in the general context of methods or processes, which may be implemented in one embodiment by a computer program product, embodied in a computer-readable medium, including computer-executable instructions, such as program code, executed by computers in networked environments. A computer-readable medium may include removable and non-removable storage devices including, but not limited to, Read Only Memory (ROM) , Random Access Memory (RAM) , compact discs (CDs) , digital versatile discs (DVD) , etc. Therefore, the computer-readable media can include a non-transitory storage media. Generally, program modules may include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer-or processor-executable instructions, associated data structures, and program modules represent examples of program code for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represents examples of corresponding acts for implementing the functions described in such steps or processes.
[0090] Some of the disclosed embodiments can be implemented as devices or modules using hardware circuits, software, or combinations thereof. For example, a hardware circuit implementation can include discrete analog and / or digital components that are, for example, integrated as part of a printed circuit board. Alternatively, or additionally, the disclosed components or modules can be implemented as an Application Specific Integrated Circuit (ASIC) and / or as a Field Programmable Gate Array (FPGA) device. Some implementations may additionally or alternatively include a digital signal processor (DSP) that is a specialized microprocessor with an architecture optimized for the operational needs of digital signal processing associated with the disclosed functionalities of this application. Similarly, the various components or sub-components within each module may be implemented in software, hardware or firmware. The connectivity between the modules and / or components within the modules may be provided using any one of the connectivity methods and media that is known in the art, including, but not limited to, communications over the Internet, wired, or wireless networks using the appropriate protocols.
[0091] While this document contains many specifics, these should not be construed as limitations on the scope of an invention that is claimed or of what may be claimed, but rather as descriptions of features specific to particular embodiments. Certain features that are described in this document in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or a variation of a sub-combination. Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results.
[0092] Only a few implementations and examples are described and other implementations, enhancements and variations can be made based on what is described and illustrated in this disclosure.
Claims
1.A wireless communication method, comprising:receiving, by a unified data management (UDM) , one or more device identifiers of one or more first type of wireless devices and one or more identifiers of one or more second type of wireless devices,wherein each device from the first type of wireless devices and the second type of wireless devices has a single identifier; andstoring, by the UDM, a mapping of the one or more device identifiers and the one or more identifiers.2.The method of claim 1,wherein the one or more device identifiers includes a device identifier that identifies a first device of the one or more first type of wireless devices, andwherein the device identifier is used to register the first device with a second device of the one or more second type of wireless devices.3.The method of claim 1, wherein the mapping between the one or more device identifiers and the one or more identifiers is changed in response to a change associated with a second device from the one or more second type of wireless devices.4.The method of claim 3, wherein the change includes a movement of the second device.5.The method of any one of claims 1 to 4,wherein the one or more first type of wireless devices includes at least one artificial intelligence of things (AIoT) device, andwherein the one or more second type of wireless devices includes one or more user equipment (UE) .6.A wireless communication method, comprising:transmitting, by a first network function to a second network function, a first message that includes one or more device identifiers of one or more first type of wireless devices,wherein the first message triggers the second network function to provide one or more identifiers that identifies one or more second type of wireless devices and that corresponds to the one or more device identifiers; andreceiving, by the first network function from the second network function, a list comprising the one or more identifiers mapped to the one or more device identifiers.7.The method of claim 6, further comprising:transmitting, by the first network function to an authentication and key management for applications anchor function (AAnF) , a second message that includes an identifier of a second device, wherein the second message requests a key of the first network function; andreceiving, by the first network function from the AAnF, the key of the first network function and an authentication and key management for applications key identifier (A-KID) .8.The method of claim 7, wherein the key of the first network function is a derived from an authentication and key management for applications (AKMA) key.9.The method of claim 7, wherein the key of the first network function is a derived using:a string of fixed digits,an identifier of the first network function,a length of the identifier of the first network function,a parameter of the second device, anda length of the parameter of the second device.10.The method of claim 7, further comprising:transmitting, by the first network function to the second device, a third message comprising the A-KID and an AIoT service request; andreceiving, by the first network function from the second device, a response message that includes a device identifier of a first device from the one or more first type of wireless devices,wherein the response message comprising the device identifier indicates that a security association between the second device and the first network function has been established.11.The method of any one of claims 6 to 10,wherein the first network function includes an artificial intelligence of things function (AIoTF) ,wherein the second network function includes a unified data management (UDM) ,wherein the one or more first type of wireless devices includes at least one artificial intelligence of things (AIoT) device, andwherein the one or more second type of wireless devices includes one or more user equipment (UE) .12.An apparatus for wireless communication comprising one or more processors configured to cause the apparatus to implement a method recited in one or more of claims 1 to 11.13.A non-transitory computer readable program storage medium having code stored thereon, the code, when executed by one or more processors, causing an apparatus to implement a method recited in one or more of claims 1 to 11.