Method for enabling and disabling group of AIOT devices and related apparatus

The method for controlling AIoT devices using group identifiers and stop codes addresses the limitations of existing technologies by enhancing network efficiency and security through efficient group-level RF transmission management.

WO2026128190A1PCT designated stage Publication Date: 2026-06-18INNOPEAK TECHNOLOGY INC

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
INNOPEAK TECHNOLOGY INC
Filing Date
2025-11-19
Publication Date
2026-06-18

AI Technical Summary

Technical Problem

Conventional mechanisms for disabling Ambient Internet of Things (AIoT) devices, such as remote kill switches and backoff timers, either erase valuable data or require continuous state and energy resources, which are unsuitable for AIoT devices with limited power and resources.

Method used

A method for enabling and disabling a group of AIoT devices using group identifiers, group keys, and stop codes to control radio frequency transmission capability, allowing temporary or permanent disablement based on coded instructions.

Benefits of technology

Improves network efficiency and security by enabling group-level control of RF transmission, temporarily disabling devices to alleviate congestion and permanently removing malfunctioning or compromised devices, while preserving data and minimizing energy consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025056192_18062026_PF_FP_ABST
    Figure US2025056192_18062026_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by a network device for enabling and disabling a group of Ambient Internet of Things (AIoT) devices in a communication network includes provisioning the group of AIoT devices with a group identifier (ID), a group key, and a first stop code, transmitting, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and determining whether to disable the RF transmission capability of the group of AIoT devices based on the second stop code and the third stop code.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD FOR ENABLING AND DISABLING GROUP OF AIOT DEVICES AND RELATED APPARATUSCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to U.S. Provisional Application No. 63 / 733,363, entitled “METHOD AND APPARATUS FOR ENABLING AND DISABLING AMBIENT IOT DEVICES,” filed on December 12, 2024, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication systems, and more particularly, to a method for enabling and disabling a group of Ambient Internet of Things (AIoT) devices and a related apparatus.BACKGROUND

[0003] Conventional mechanisms, such as remote kill switches or remote wipe functions, have been applied to user equipments (UEs) for theft deterrence and data protection. However, these approaches are not suitable for Ambient loT (AIoT) devices. Remote wipe eliminates valuable collected data, while a kill switch permanently disables the device until reconfiguration. Existing backoff timer schemes likewise require continuous state and energy resources that conflict with the ultra-low power and limited capabilities of AIoT devices. Therefore, a mechanism is needed to temporarily enable or disable RF transmission for a group of AIoT devices while preserving stored data and minimizing energy and state burdens.

[0004] Therefore, there is a need for a method for enabling and disabling a group of Ambient Internet of Things (AIoT) devices and a related apparatus.SUMMARY

[0005] An object of the present disclosure is to propose a method for enabling and disabling a group of Ambient Internet of Things (AIoT) devices and a related apparatus, which can improve network efficiency and enhance the security of AIoT communications by allowing group-level control of RF transmission capability.

[0006] In a first aspect of the present disclosure, a method performed by a network device for enabling and disabling a group of Ambient Internet of Things (AIoT) devices in a communication network includes provisioning the group of AIoT devices with a group identifier (ID), a group key, and a first stop code, transmitting, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and determining whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code.

[0007] In a second aspect of the present disclosure, a network device includes a transmitter configured to: provision a group of Ambient Internet of Things (AIoT) devices with a group identifier (ID), a group key, and a first stop code and transmit, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and a determiner configured to determine whetherto disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code.

[0008] In a third aspect of the present disclosure, a network device includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The network device is configured to perform the above method.

[0009] In a fourth aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.

[0010] In a fifth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.

[0011] In a sixth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.

[0012] In a seventh aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.

[0013] In an eighth aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS

[0014] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.

[0015] FIG. 1 is a block diagram of a network device and one or more Ambient Internet of Things (AIoT) devices of communication in a communication system according to an embodiment of the present disclosure.

[0016] FIG. 2 is a block diagram of a network device according to an embodiment of the present disclosure.

[0017] FIG. 3 is a block diagram of a network device according to an embodiment of the present disclosure.

[0018] FIG. 4 is a flowchart illustrating a method performed by a network device for enabling and disabling a group of Ambient Internet of Things (AIoT) devices according to an embodiment of the present disclosure.

[0019] FIG. 5 is a flowchart illustrating processing logic for disabling and enabling RF transmission capability mechanism for a group of AIoT devices in an AIoT communication system according to an embodiment of the present disclosure.

[0020] FIG. 6 is a flowchart illustrating alternative processing logic for disabling and enabling RF transmission capability mechanism for a group of AIoT devices in an AIoT communication system according to an embodiment of the present disclosure.

[0021] FIG. 7 is a flowchart illustrating temporarily disabling RF transmission of a group of AIoT devices in an AIoT communication system according to an embodiment of the present disclosure.

[0022] FIG. 8 is a flowchart illustrating enabling RF transmission capability for a group of AIoT devices in a AIoT communication system according to an embodiment of the present disclosure.

[0023] FIG. 9 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.

[0024] FIG. 10 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS

[0025] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.

[0026] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.

[0027] Optionally, a user equipment (UE) mentioned in the embodiments of the present application may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem, an in-vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.

[0028] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.

[0029] A number of UE vendors offer solutions for “remote kill switch” or “remote wipe” that can be used to wipe clean a stolen UE. Current 3GPP standards also support features such as backoff timer that is used when a UE stops requesting network access temporarily until a certain amount of time has passed. For a group of devices, broadcast has been used to send information to the devices, but not for requesting the devices for the purpose of turning off RF transmit capability. Currently, only individual UE vendors provide remote wipe functions, 3GPP standards support mechanisms like backoff timers, but they do not yet support using broadcast to disable RF transmission capability for a group of devices.

[0030] One drawback of using the “remote kill switch” or “remote wipe” is that it wipes clean any data that is kept in the UE. While this is useful for a stolen UE, it may not be useful for an AIoT device whose usefulness is the data within the device. A remote wipe is helpful for stolen UEs but impractical for AIoT devices where the stored data is the main value.

[0031] Another drawback is the “remote kill switch” renders the UE completely disabled until the UE is reconfigured again (e.g., factory reset) while the reasons for disabling an AIoT device can be to stop it from transmitting to the network temporarily until a time when the network is available (e.g., less congested). In the case of AIoT devices, if the command is to temporarily disable the RF transmit capability, the group of AIoT devices are still expected to continue “listen” or receive to commands from the network so that the temporary disabling of RF transmit capabilities can be restored or re-enabled. Unlike a full kill switch, AIoT devices may only need temporary RF transmit disabling while still listening to network commands for re-enablement.

[0032] Y et another drawback of using a backoff timer on an AIoT device is that the AIoT device keeps a timer or a counter active which requires the AIoT device to maintain a state or maintain a clock which goes against the characteristics of the AIoT device (i.e., AIoT devices are characterized by not having a conventional battery (or with limited battery) and is powered by energy harvesting, limited storage, and limited computing capabilities.) Using a backoff timer is unsuitable for AIoT devices since it requires maintaining state or a clock, conflicting with their limited power and resources.

[0033] FIG. 1 illustrates that, in some embodiments, a network device 10 and one or more AIoT devices 20 of communication in a communication system 40. The communication system 40 includes the network device10 and the one or more AIoT devices 20. The network device 10 may include a memory 12, a transceiver 13, and a processor 11 coupled to the memory 12 and the transceiver 13. The one or more AIoT devices 20 may include a memory 22, a transceiver 23, and a processor 21 coupled to the memory 22 and the transceiver 23. The processor 11 or 21 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 11 or 21. The memory 12 or 22 is operatively coupled with the processor 11 or 21 and stores a variety of information to operate the processor 11 or 21. The transceiver 13 or 23 is operatively coupled with the processor 11 or 21, and the transceiver 13 or 23 transmits and / or receives a radio signal.

[0034] The processor 11 or 21 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 12 or 22 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 13 or 23 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 12 or 22 and executed by the processor 11 or 21. The memory 12 or 22 can be implemented within the processor11 or 21 or external to the processor 11 or 21 in which case those can be communicatively coupled to the processor 11 or 21 via various means as is known in the art.

[0035] In some embodiments, the transceiver 13 is configured to provision the group of AIoT devices 20 with a group identifier (ID), a group key, and a first stop code and transmit, to the group of AIoT devices 20, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and theprocessor 11 is configured to determine whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices 20 based on the second stop code and the third stop code. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve network efficiency and enhance the security of AIoT communications by allowing group-level control of RF transmission capability.

[0036] FIG. 2 illustrates a network device 200 according to an embodiment of the present disclosure. The network device 200 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the network device 200 using any suitably configured hardware and / or software. The network device 200 includes a transmitter 201 and a determiner 202. The transmitter 201 is configured to provision a group of AIoT devices with a group identifier (ID), a group key, and a first stop code and transmit, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and the determiner 202 is configured to determine whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve network efficiency and enhance the security of AIoT communications by allowing group-level control of RF transmission capability.

[0037] In some embodiments, the determiner 202 is further configured to determine whether the second stop code and the third stop code are identical or different. In some embodiments, when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently enabled and the second stop code matches the first stop code, the determiner 202 temporarily disables the RF transmission capability of the group of AIoT devices and updates the first stop code with the third stop code. In some embodiments, when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently disabled and the second stop code matches the first stop code, the determiner 202 enables the RF transmission capability of the group of AIoT devices and updates the first stop code with the third stop code. In some embodiments, when the second stop code and the third stop code are identical, the determiner 202 permanently disables the RF transmission capability of the group of AIoT devices. In some embodiments, the second stop code and the third stop code are transmitted via an intermediate user equipment (UE), a UE relay, or a base station (BS). The determiner 202 controls AIoT devices’ RF transmission by comparing stop codes, temporarily disabling, enabling, or permanently disabling transmission and updating codes accordingly, with codes delivered via UE, relay, or BS.

[0038] In some embodiments, the second stop code and the third stop code are ciphered, integrity protected, or both ciphered and integrity-protected, using the group key. In some embodiments, the second stop code and the third stop code are transmitted individually to each AIoT device using security keys derived during an authentication procedure between the network device and each AIoT device. In some embodiments, the determiner 202 is further configured to enable the group of AIoT devices to continue transmitting RF transmissions to the group of AIoT devices while the RF transmission capability of the group of AIoT devices is temporarily disabled. In some embodiments, the determiner 202 is further configured to permanently disable the RF transmission capability of the group of AIoT devices by rendering the group of AIoT devices out of service and preventing re-enablement of the RF transmission capability of the group of AIoT devices. The stopcodes may be secured with keys and sent individually or by group, allowing temporary disablement while still receiving transmissions, or permanent disablement by rendering the devices out of service.

[0039] In some embodiments, the transmitter 202 is configured to receive a disable request confirmation message from the group of AIoT devices prior to a temporary disablement of the RF transmission capability of the group of AIoT devices. In some embodiments, a temporary disablement of the RF transmission capability of the group of AIoT devices is initiated by the determiner 202 in response to a network congestion. In some embodiments, a permanent disablement of the RF transmission capability of the group of AIoT devices is initiated by the determiner 202 in response to a detection of a malfunction, a misbehavior, or a security attack of the group of AIoT devices. In some embodiments, the determiner 202 is further configured to update the first stop code by storing a triplet of an updated group ID, an updated group key, and an updated stop code for subsequent verification of the second stop code and the third stop code. The determiner 202 may confirm disable requests, temporarily disable RF due to congestion, permanently disable RF for malfunctions or attacks, and update stop codes with new group IDs, keys, and codes for verification.

[0040] FIG. 3 illustrates a network device 300 according to an embodiment of the present disclosure. The network device 300 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the network device 300 using any suitably configured hardware and / or software. The network device 300 may include a memory 301, a transceiver 302, and a processor 303 coupled to the memory 301 and the transceiver 302. The processor 303 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 303. The memory 301 is operatively coupled with the processor 303 and stores a variety of information to operate the processor 303. The transceiver 302 is operatively coupled with the processor 303, and the transceiver 302 transmits and / or receives a radio signal. The processor 303 may include applicationspecific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 301 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 302 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 301 and executed by the processor 303. The memory 301 can be implemented within the processor 303 or external to the processor 303 in which case those can be communicatively coupled to the processor 303 via various means as is known in the art.

[0041] In some embodiments, the transceiver 302 is configured to provision a group of AIoT devices with a group identifier (ID), a group key, and a first stop code and transmit, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and the processor 303 is configured to determine whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve network efficiency and enhance the security of AIoT communications by allowing group-level control of RF transmission capability.

[0042] FIG. 4 illustrates a method 400 performed by a network device for enabling and disabling a group of Ambient Internet of Things (AIoT) devices in a communication network according to an embodiment of thepresent disclosure. The method 400 performed by the network device is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 400 performed by the network device using any suitably configured hardware and / or software. In some embodiments, the method 400 performed by the network device includes: an operation 402, provisioning the group of AIoT devices with a group identifier (ID), a group key, and a first stop code, an operation 404, transmitting, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key, and an operation 406, determining whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can improve network efficiency and enhance the security of AIoT communications by allowing group-level control of RF transmission capability.

[0043] In some embodiments, the method further includes determining whether the second stop code and the third stop code are identical or different. In some embodiments, when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently enabled and the second stop code matches the first stop code, temporarily disabling the RF transmission capability of the group of AIoT devices and updating the first stop code with the third stop code. In some embodiments, when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently disabled and the second stop code matches the first stop code, enabling the RF transmission capability of the group of AIoT devices and updating the first stop code with the third stop code. In some embodiments, when the second stop code and the third stop code are identical, permanently disabling the RF transmission capability of the group of AIoT devices. In some embodiments, the second stop code and the third stop code are transmitted via an intermediate user equipment (UE), a UE relay, or a base station (BS). The method manages AIoT devices’ RF transmission by comparing stop codes, temporarily disabling, enabling, or permanently disabling based on code matches, with codes delivered via UE, relay, or BS.

[0044] In some embodiments, the second stop code and the third stop code are ciphered, integrity protected, or both ciphered and integrity-protected, using the group key. In some embodiments, the second stop code and the third stop code are transmitted individually to each AIoT device using security keys derived during an authentication procedure between the network device and each AIoT device. In some embodiments, the method further includes enabling the group of AIoT devices to continue transmitting RF transmissions to the group of AIoT devices while the RF transmission capability of the group of AIoT devices is temporarily disabled. In some embodiments, permanently disabling the RF transmission capability of the group of AIoT devices includes rendering the group of AIoT devices out of service and preventing re-enablement of the RF transmission capability of the group of AIoT devices. The method secures stop codes with keys, allows per-device transmission during temporary RF disablement, and can permanently disable devices by rendering them out of service.

[0045] In some embodiments, the method further includes receiving a disable request confirmation message from the group of AIoT devices prior to a temporary disablement of the RF transmission capability of the group of AIoT devices. In some embodiments, a temporary disablement of the RF transmission capability of the group of AIoT devices is initiated by the network device in response to a network congestion. In some embodiments, a permanent disablement of the RF transmission capability of the group of AIoT devices is initiated by thenetwork device in response to a detection of a malfunction, a misbehavior, or a security attack of the group of AIoT devices. In some embodiments, updating the first stop code includes storing a triplet of an updated group ID, an updated group key, and an updated stop code for subsequent verification of the second stop code and the third stop code. The method includes confirming disable requests, temporarily disabling RF due to congestion, permanently disabling for malfunctions or attacks, and updating stop codes with new group IDs, keys, and codes for verification.

[0046] Examples:

[0047] 5G Ambient loT (AIoT) service is a new 5G service that can be used to support various use cases such as, automated warehousing, inventory management, smart grid, non-public logistics, industrial manufacturing, loT sensors and smart home. AIoT devices operate in both licensed and unlicensed spectrum. AIoT devices collect information related to the use case and report back to the 3 GPP network or application server via the 3 GPP network when requested. AIoT enables diverse use cases by having devices gather data and report it to the 3GPP network or application servers over licensed and unlicensed spectrum.

[0048] It is important in terms of network performance and network reliability that an AIoT device or a group of AIoT devices only communicate when requested. Otherwise, the vast number of AIoT devices (expected to be numbered in the millions) communicating or sending information to the network at the same time can overwhelm the network’s bandwidth and cause undesirable side effects such as denying access to other devices such as UEs trying to gain access to the network. To avoid network overload, AIoT devices should only communicate when requested, since millions of simultaneous transmissions could overwhelm bandwidth and block other devices.

[0049] 5G network controls when AIoT devices can communicate and when they cannot communicate, i.e., enable or disable an AIoT device. Some embodiments of the present disclosure provides a mechanism for disabling a group of AIoT devices and enabling a group of temporarily disabled AIoT devices in a communication network. The 5G network controls AIoT communication, with embodiments providing mechanisms to disable or re-enable groups of devices as needed.

[0050] In some examples, a group of AIoT devices are provisioned with a group identifier, group key, and a stop RF transmission code (i.e., Group ID, Group Key, Stop Code). Two (2) group stop RF transmission codes (e.g., Stop Code) associated with a group of AIoT devices are sent from the network (e.g., via intermediate UE, UE relay, or via BS) to an AIoT device. The two group stop RF transmission codes are sent to the group using the Group ID and are protected using the Group Key. AIoT devices are provisioned with a Group ID, Group Key, and Stop Code, and the network sends two protected stop codes via UE, relay, or BS for group control.

[0051] In some examples, the two stop RF transmission codes may be the same or may be different. The RF transmission capability may have been temporarily disabled previously. The two stop codes may be identical or different, with RF transmission possibly already temporarily disabled.

[0052] In case the group of AIoT devices’ RF transmission capability has not been disabled (i.e., the group of AIoT devices can actively send RF transmission when instructed by the network or when certain local conditions are met) and the two stop transmission codes are different, the instruction is interpreted by the group of AIoT devices to temporarily disable RF transmission capability. Upon receiving the two stop RF transmission codes and after verifying that the codes are sent securely (i.e., using the Group Key to recover the secured transmission),the group of AIoT devices verifies the first received code against a previously stored stop transmission code (i.e., the Group ID, Group Key, and Stop Code triplet). If the first received code is identical to that of the stored code in the Group ID, Group Key, Stop Code triplet, the group of AIoT devices temporarily stop RF transmission (i.e., turn off Rf transmission capability) and replaces the stored RF transmission code with the second received code. The newly stored RF transmission code triplet (i.e., Group ID, Group Key, Second Received Code) is to be used to verify next time when further stop transmission codes are received. When AIoT devices are active and receive two different secured stop codes, they verify the first against the stored code; if it matches, they temporarily disable RF transmission and update the stored code with the second one for future verification.

[0053] Since only RF transmission capability is temporarily disabled in the group of AIoT devices, the group of AIoT devices can still receive RF transmission from the network in case the network decides to (re)enable the group of temporarily disabled AIoT device (i.e., only RF transmission capability is disabled), for example when network congestion subsided. When RF transmission is temporarily disabled, AIoT devices can still receive network signals, allowing re-enablement once conditions like congestion improve.

[0054] In case the group of AIoT devices’ RF transmission capability has been disabled (i.e., AIoT device can no longer actively send RF transmission even if instructed by the network or when certain local conditions are met) and the two stop transmission codes are different, The group of AIoT devices verifies the first received code against a previously stored stop transmission code in the Group ID, Group Key, Stop Code triplet. If the first received code is identical to that of the stored code in the triplet, the group of AIoT devices enables the previously disabled RF transmission capability. The group of AIoT devices replaces the stored RF transmission code with the second received code. The newly stored RF transmission code (i.e., Group ID, Group Key, Second Received Code) is to be used to verify next time when further stop transmission codes are received. If AIoT devices are already disabled and receive two different secured stop codes, they verify the first against the stored code; if it matches, they re-enable RF transmission and update the stored code with the second one for future use.

[0055] Regardless of whether the current RF transmission capability of the group of AIoT devices is enabled or disabled, if both received stop transmission codes are the same, the group of AIoT devices permanently disables RF transmission capability and is rendered out of service. In this case, AIoT device can no longer enabled the previously disabled RF transmission capability. If both received stop codes are identical, the AIoT devices permanently disable RF transmission and are rendered out of service with no re-enablement possible.

[0056] FIG. 5 below illustrates processing logic for disabling and enabling RF transmission capability mechanism in an AIoT communication system for a group of AIoT devices. Upon receiving Stop Code 1 and Stop Code 2 from the network, the group of AIoT devices checks if the Stop Code 1 and Stop Code 2 are identical.

[0057] If Stop Code 1 and Stop Code 2 are different, each AIoT device in the group of AIoT devices checks if its RF transmission capability is disabled or enabled. If the AIoT device’s RF transmission capability is disabled temporarily, and the received Stop Code 1 and the AIoT device’s stored Stop Code are identical, the AIoT device enables its RF transmission capability. The AIoT device overwrites its Stop Code in the (Group ID, Group Key, Stop Code) triplet with Stop Code 2. If the two stop codes differ and an AIoT device is temporarily disabled, it re-enables RF transmission when Stop Code 1 matches the stored code and updates the stored code with Stop Code 2.

[0058] If Stop Code 1 and Stop Code 2 are different, each AIoT device in the AIoT device group checks if its RF transmission capability is disabled or enabled. If the AIoT device’s RF transmission capability is enabled, and the received Stop Code 1 and the AIoT device’s stored code are identical, the AIoT device disables its RF transmission capability temporarily. The AIoT device overwrites its Stop Code in the (Group ID, Group Key, Stop Code) triplet with Stop Code 2. If the two stop codes differ and an AIoT device is enabled, it temporarily disables RF transmission when Stop Code 1 matches the stored code and updates the stored code with Stop Code 2. If Stop Code 1 and Stop Code 2 are identical, each AIoT device in the AIoT device group permanently disables its RF transmission capability. If the two stop codes differ and the device is enabled, it temporarily disables RF transmission when Stop Code 1 matches the stored code and updates it with Stop Code 2, and if the two stop codes are identical, the device permanently disables RF transmission.

[0059] FIG. 6 below illustrates alternative processing logic for disabling and enabling RF transmission capability mechanism in an AIoT communication system for a group of AIoT devices. The processing logic defines how AIoT devices handle two received stop codes: if different, a temporarily disabled device re-enables transmission and an enabled device temporarily disables transmission (both updating the stored code with Stop Code 2), and if identical, all devices permanently disable RF transmission, while FIG. 6 shows an alternative version of this mechanism.

[0060] FIG. 7 illustrates an example call flow for temporarily disabling a group of AIoT devices’ RF transmission capability in a AIoT communication system. Not shown in FIG. 7 is the potential that the Temporary Disable Request is protected using previously established security keys that is unique between the network and each individual AIoT device in the group.

[0061] FIG. 7 illustrates a call flow for temporarily disabling AIoT devices’ RF transmission, with the disable request potentially secured using per-device network keys. FIG. 7 illustrates at least one of the following steps:

[0062] Step 1 : the group of AIoT devices and the network are pre-provisioned with Group ID, Group Key, and Stop Code triplets. Each individual AIoT device in the group of AIoT devices and network go through authorization and authentication process individually, after which each AIoT device in the group is authorized and authenticated. At this stage, each AIoT device in the group and network may share a set of shared keys such that communication between an AIoT device and network may be protected individually between each AIoT device and the network. The network can use single message to each of the AIoT device for group instructions, but this would not be efficient. Instead, group operation is performed in Step 2. Step 1 provisions AIoT devices and the network with Group ID, Group Key, and Stop Code triplets, completes individual authentication with shared keys, and notes that while single-device messaging is possible, group operations are more efficient.

[0063] Step 2: The network decides to temporarily disable the group of AIoT devices’ RF transmission capability. The network sends Stop Code 1 (Stop Code 1 is set to the AIoT device’s pre-provisioned RF transmission stop code) and Stop Code 2 (Stop Code 2 can be set to any randomly generated number with same size as Stop Code 1) to the group of AIoT devices in a Temporary Disable Request message (i.e., part of the current Inventory and Command Procedure as in 3GPP TR 38.769. Since the group AIoT device and the network may have go through authentication and established shared keys. Shared keys then can be used to protect the Temporary Disable Request message if the Temporary Disable Request message is sent individually to each of the AIoT devices in the group, otherwise, the Group Key in the (Group ID, Group Key, Stop Code) triplet isused to protect the message being sent to the entire membership if the group. Protection of the Temporary Disable Request message may include ciphering, integrity protection or both ciphering and integrity protection. In Step 2, the network sends a Temporary Disable Request with Stop Code 1 and a new random Stop Code 2 to the AIoT group, protecting the message using either shared keys for individual devices or the Group Key for the whole group.

[0064] Steps 3: The group of AIoT devices receives the Temporary Disable Request Message from the network with Stop Code 1 and Stop Code 2. If the Temporary Disable Request is protected using the Group Key in the (Group ID, Group Key, Stop Code) triple, each AIoT device uses its own Group Key to verify the message. If the Temporary Disable Request message is sent individually to each AIoT device protected using the keys derived as a process of authentication previously performed, each AIoT device verifies the message (e.g., decipher and / or verify integrity of the message. In Step 3, AIoT devices receive the Temporary Disable Request and verify it using either the Group Key for group messages or individual authentication-derived keys for perdevice messages.

[0065] Steps 4: Each AIoT device in the group of AIoT devices with Group ID that matches Group ID in the (Group ID, Group Key, Stop Code) triple verifies that Stop Code 1 is the same as the pre-provisioned Stop Code in the (Group ID, Group Key, Stop Code) triple. In Step 4, each AIoT device checks that its Group ID matches and verifies whether Stop Code 1 equals the pre-provisioned Stop Code in its stored triplet.

[0066] Steps 5 : If the Stop Code 1 is verified successfully, each AIoT device in the group of AIoT devices temporarily disables its RF transmission capability. Each AIoT device in the group of AIoT devices replaces its stored Stop Code in the (Group ID, Group Key, Stop Code) triplet with the received Stop Code 2. In Step 5, after verifying Stop Code 1, each AIoT device temporarily disables RF transmission and updates its stored Stop Code with Stop Code 2.

[0067] Similarly, if the request from the network is to permanently disable the group of AIoT devices’ RF transmission capability, the Disable Request message will contain two identical Stop Codes (i.e., Stop Code 1 is equal to Stop Code 2). If both Stop Code 1 and Stop Code 2 are identical, the AIoT devices permanently disable RF transmission and are rendered out of service.

[0068] FIG. 7 illustrates the call flow for disabling RF transmission in a group of AIoT devices. First, devices and the network are provisioned with a Group ID, Group Key, and Stop Code triplet, and each device completes individual authentication, allowing either per-device secure messaging or efficient group operations. The network then issues a Temporary Disable Request containing Stop Code 1 (the pre-provisioned code) and a new Stop Code 2, secured with either shared per-device keys or the Group Key. Upon receiving the request, devices verify it using the appropriate key, check that their Group ID matches, and confirm Stop Code 1 against the stored code. If verified, they temporarily disable RF transmission and update their stored code with Stop Code 2. Alternatively, if the network sends two identical stop codes, the devices permanently disable RF transmission and are rendered out of service.

[0069] FIG. 8 illustrates an example call flow for enabling RF transmission capability for a group of AIoT devices in a AIoT communication system. Call flow of an example to enable a AIoT whose RF transmission capability has been temporarily disabled is illustrated in FIG. 8. Not shown in FIG. 8 is the potential that theEnable Request can be sent individually to each of the AIoT device in the group and can be protected individually using previously established security keys in a less efficiently manner.

[0070] FIG. 8 illustrates the call flow for re-enabling RF transmission in AIoT devices that were temporarily disabled, with the enable request optionally sent per device using individual security keys, though less efficiently. Also not shown in either FIG. 7 or FIG. 8 is the option that the group of AIoT devices can send a disable request confirm message before disabling the RF transmission capability. An explicit confirmation can be used to ensure that the request has been processed and that the replacement Stop Code has been correctly updated in the group of AIoT devices. FIG. 8 illustrates the call flow for re-enabling RF transmission in temporarily disabled AIoT devices. The Enable Request can be sent individually to each device with per-device security keys, though less efficient. Additionally, the system may allow AIoT devices to send a disable request confirmation before disabling, ensuring the request is processed and the Stop Code updated correctly.

[0071] Mechanism for disabling and enabling RF transmission capability of a group of AIoT devices benefits the security of AIoT communications in many ways.

[0072] First, the mechanism(s) of the present disclosure allows the network to temporarily disable the RF transmission capability of a group of AIoT devices rather than each device individually, for example when the network experiences network congestion due to a large number of AIoT devices communicating with the network. By providing a mechanism for temporarily disabling a group of AIoT devices’ RF transmission capability in a single message can relieve the network of its congestion, addressing one of the reasons to disable the AIoT device’s RF transmission capability in an efficient manner. Network congestion may cause other higher-priority devices, such as UE to be unable to access the network. Temporarily disabling AIoT devices can alleviate network congestion until a time when network resources are more suitable to lower priority devices such as AIoT devices. The disclosed mechanism lets the network temporarily disable RF transmission for a group of AIoT devices with a single message, efficiently reducing congestion and ensuring higher-priority UEs can access the network until resources are available again.

[0073] Second, the scheme allows the network to permanently disable the RF transmission capability of a group of AIoT devices for example when the AIoT devices’ service life has reached an end, the service of the group of AIoT devices is no longer used (e.g., inventory that the AIoT device is tracking has reached its destination) or when the network deems that the devices may be experience technical difficulties or may be misbehaving, for example if the devices are being attacked (e.g., hijacked by attackers) to perform illegitimate activities. Permanently disabling the RF transmission capability of a group of AIoT devices helps the operator to remove the impacted devices out of its network to improve network performance. The scheme also enables permanent disabling of AIoT devices’ RF transmission when their service ends, is no longer needed, or if devices malfunction or are compromised, thereby removing them from the network to maintain performance.

[0074] FIG. 8 illustrates the call flow for re-enabling RF transmission in temporarily disabled AIoT devices, where the Enable Request may be sent per device with individual keys, though less efficient, and the system may also allow a confirmation message before disabling to ensure proper processing and code update. Overall, the proposed mechanism enhances AIoT security and network reliability by allowing the network to temporarily disable a group of devices with a single message to ease congestion and ensure higher-priority UEs can connect,as well as permanently disable devices when their service ends, is no longer needed, or if they malfunction or are compromised, thereby removing them from the network and improving performance.

[0075] Alternative to using the mechanisms to disable a group of AIoT devices’ RF transmission capability is to permanently wipe clean the device (e.g, wipe clean memory in the device or a permanent kill command), renders the device permanently inoperable. This, however, may not be desirable for operators as there are business reasons for not permanently wiping clean the device, for example to temporarily relieve network congestion by only limiting the group of AIoT devices’ capability to transmit RF signals. An alternative is permanently wiping the device, but this is undesirable since operators may only need to temporarily stop RF transmissions to relieve network congestion.

[0076] Other alternative is to do a remote factory reset, but this is seen similar to a permanent wiping of the device. This has the undesired effect of having to provision each AIoT device for operation again.

[0077] Yet another alternative is to pre-provision two separate Stop Codes in the group of AIoT devices (one for temporarily disabling the RF transmission capability and one for permanently disabling the RF transmission capability), but this requires further provisioning, further storage and further processing. Another alternative is pre-provisioning separate Stop Codes for temporary and permanent disabling, but this adds extra provisioning, storage, and processing requirements.

[0078] Alternatives to the proposed mechanism include permanently wiping or factory resetting AIoT devices, which render them inoperable and require re-provisioning, or pre-provisioning separate stop codes for temporary and permanent disabling, which increases provisioning, storage, and processing burdens, all less desirable than selectively controlling RF transmission to address issues like network congestion.

[0079] In summary, some embodiments of the disclosure present mechanisms for controlling AIoT devices’ RF transmission by enabling temporary or permanent disablement through secure stop codes, improving network efficiency and reliability. Devices provisioned with a Group ID, Group Key, and Stop Code can be instructed to disable or re-enable transmission based on whether two received stop codes match or differ, with identical codes leading to permanent disablement. Call flows (FIG. 7 and FIG. 8) illustrate how the network can efficiently disable or re-enable groups of devices using group or per-device security, with optional confirmation messages ensuring proper updates. This approach helps alleviate congestion by temporarily disabling devices or permanently removing malfunctioning or compromised ones, thereby preserving network performance. Compared to alternatives like device wiping, factory reset, or pre-provisioning separate codes — which are costly, inefficient, or inflexible — the proposed mechanism provides a more practical and secure solution for managing large-scale AIoT deployments.

[0080] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Improve network efficiency and enhance the security of AIoT communications by allowing group-level control of RF transmission capability. 4. Provide a good communication performance. 5. Provide high reliability. 6. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards tocreate an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.

[0081] FIG. 9 is an example of a computing device 1400 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 9 illustrates an example of the computing device 1400 that can implement apparatuses and methods of the above embodiments of FIGs. 1 to 8, using any suitably configured hardware and / or software. In some embodiments, the computing device 1400 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.

[0082] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer- readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer- readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.

[0083] The computing device 1400 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1400. The computing device 1400 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1400 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input eventsin response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.

[0084] The computing device 1400 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 8. The program code may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.

[0085] The computing device 1400 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1400 can transmit messages as electronic or optical signals via the network interface device 1424.

[0086] FIG. 10 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 10 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (I / O) interface 1580, coupled with each other at least as illustrated.

[0087] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more singlecore or multi-core processors. The processors may include any combination of general-purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 8. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.

[0088] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuitry.

[0089] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, basebandcircuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.

[0090] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1 to 8 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.

[0091] In various embodiments, the I / O interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.

[0092] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.

[0093] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware or combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.

[0094] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative coupling operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.

[0095] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.

[0096] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a readonly memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.

[0097] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.

Claims

What is claimed is:

1. A method performed by a network device for enabling and disabling a group of Ambient Internet of Things (AIoT) devices in a communication network, the method comprising: provisioning the group of AIoT devices with a group identifier (ID), a group key, and a first stop code; transmitting, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key; and determining whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code.

2. The method of claim 1, further comprising determining whether the second stop code and the third stop code are identical or different.

3. The method of claim 2, wherein when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently enabled and the second stop code matches the first stop code, temporarily disabling the RF transmission capability of the group of AIoT devices and updating the first stop code with the third stop code.

4. The method of claim 2, wherein when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently disabled and the second stop code matches the first stop code, enabling the RF transmission capability of the group of AIoT devices and updating the first stop code with the third stop code.

5. The method of claim 2, wherein when the second stop code and the third stop code are identical, permanently disabling the RF transmission capability of the group of AIoT devices.

6. The method of claim 1, wherein the second stop code and the third stop code are transmitted via an intermediate user equipment (UE), a UE relay, or a base station (BS).

7. The method of claim 1, wherein the second stop code and the third stop code are ciphered, integrity protected, or both ciphered and integrity -protected, using the group key.

8. The method of claim 1, wherein the second stop code and the third stop code are transmitted individually to each AIoT device using security keys derived during an authentication procedure between the network device and each AIoT device.

9. The method of claim 1, further comprising enabling the group of AIoT devices to continue transmitting RF transmissions to the group of AIoT devices while the RF transmission capability of the group of AIoT devices is temporarily disabled.

10. The method of claim 1, wherein permanently disabling the RF transmission capability of the group of AIoT devices comprises rendering the group of AIoT devices out of service and preventing re-enablement of the RF transmission capability of the group of AIoT devices.

11. The method of claim 1, further comprising receiving a disable request confirmation message from the group of AIoT devices prior to a temporary disablement of the RF transmission capability of the group of AIoT devices.

12. The method of claim 1, wherein a temporary disablement of the RF transmission capability of the group of AIoT devices is initiated by the network device in response to a network congestion.

13. The method of claim 1, wherein a permanent disablement of the RF transmission capability of the group of AIoT devices is initiated by the network device in response to a detection of a malfunction, a misbehavior, or asecurity attack of the group of AIoT devices.

14. The method of claim 1, wherein updating the first stop code comprises storing a triplet of an updated group ID, an updated group key, and an updated stop code for subsequent verification of the second stop code and the third stop code.

15. A network device, comprising: a transmitter configured to: provision a group of Ambient Internet of Things (AIoT) devices with a group identifier (ID), a group key, and a first stop code; and transmit, to the group of AIoT devices, a second stop code and a third stop code that are associated with the group ID and secured using the group key; and a determiner configured to determine whether to disable a radio frequency (RF) transmission capability of the group of AIoT devices based on the second stop code and the third stop code.

16. The network device of claim 15, wherein the determiner is further configured to determine whether the second stop code and the third stop code are identical or different.

17. The network device of claim 16, wherein when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently enabled and the second stop code matches the first stop code, the determiner temporarily disables the RF transmission capability of the group of AIoT devices and updates the first stop code with the third stop code.

18. The network device of claim 16, wherein when the second stop code and the third stop code are different, and when the RF transmission capability of the group of AIoT devices is currently disabled and the second stop code matches the first stop code, the determiner enables the RF transmission capability of the group of AIoT devices and updates the first stop code with the third stop code.

19. The network device of claim 16, wherein when the second stop code and the third stop code are identical, the determiner permanently disables the RF transmission capability of the group of AIoT devices.

20. The network device of claim 15, wherein the second stop code and the third stop code are transmitted via an intermediate user equipment (UE), a UE relay, or a base station (BS).

21. The network device of claim 15, wherein the second stop code and the third stop code are ciphered, integrity protected, or both ciphered and integrity -protected, using the group key.

22. The network device of claim 15, wherein the second stop code and the third stop code are transmitted individually to each AIoT device using security keys derived during an authentication procedure between the network device and each AIoT device.

23. The network device of claim 15, wherein the determiner is further configured to enable the group of AIoT devices to continue transmitting RF transmissions to the group of AIoT devices while the RF transmission capability of the group of AIoT devices is temporarily disabled.

24. The network device of claim 15, wherein the determiner is further configured to permanently disable the RF transmission capability of the group of AIoT devices by rendering the group of AIoT devices out of service and preventing re-enablement of the RF transmission capability of the group of AIoT devices.

25. The network device of claim 15, wherein the transmitter is configured to receive a disable request confirmation message from the group of AIoT devices prior to a temporary disablement of the RF transmission capability of the group of AIoT devices.

26. The network device of claim 15, wherein a temporary disablement of the RF transmission capability of the group of AIoT devices is initiated by the determiner in response to a network congestion.

27. The network device of claim 15, wherein a permanent disablement of the RF transmission capability of the group of AIoT devices is initiated by the determiner in response to a detection of a malfunction, a misbehavior, or a security attack of the group of AIoT devices.

28. The network device of claim 15, wherein the determiner is further configured to update the first stop code by storing a triplet of an updated group ID, an updated group key, and an updated stop code for subsequent verification of the second stop code and the third stop code.

29. A network device, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the network device is configured to perform the method of any one of claims 1 to 14.

30. A non-transitory machine-readable storage medium having stored thereon instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 14.

31. A chip, comprising: a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the method of any one of claims 1 to 14.

32. A computer readable storage medium, in which a computer program is stored, wherein the computer program causes a computer to execute the method of any one of claims 1 to 14.

33. A computer program product, including a computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 14.

34. A computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 14.