Upcycling temporary identifier

WO2026206223A1PCT designated stage Publication Date: 2026-10-01TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2026/050202
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-03-26
Publication Date
2026-10-01

Smart Images

  • Figure SE2026050202_01102026_PF_FP_ABST
    Figure SE2026050202_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A method is performed by a wireless device (712) for facilitating upcycling of a temporary identifier, ID, for the wireless device (712) The method comprises agreeing with a network device (708) of a telecommunications network (702), during an attachment procedure for the wireless device to the telecommunications network, on a root ID for the wireless device, and on a parameter to generate the temporary ID; generating the temporary ID as a function of the root ID and the parameter; and communicating with the network device using the temporary ID. A network device, a wireless device, and a method performed by a network device are also disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] UPCYCLING TEMPORARY IDENTIFIER

[0002] TECHNICAL FIELD

[0003] The present disclosure relates to a method performed by a wireless device for facilitating upcycling of a temporary identifier for the wireless device. A wireless device, a network device, and a method performed by a network device are also disclosed.

[0004] BACKGROUND

[0005] In Third Generation Partnership Program (3 GPP), a study on Zero Energy (ZE) Internet of Things (IOT) (ZE-IoT) was started in Release 18, and is referred to as ‘Ambient IoT’ (A-IoT) (RP -222685) in 3GPP. The resulting 3GPP study item technical report can be found in 3GPP Technical Report (TR) 38.848 vl 8.0.0 “Study on Ambient IoT (Internet of Things) in RAN” (2023-09-29). In Release 19, the work continued with a study in Radio Access Network (RAN) working groups (RP -240826) for which the outcome can be found in technical report 3 GPP TR 38.769 vl9.0.0 “Study on solutions for Ambient IoT (Internet of Things) in NR” (2025-01-15). It was agreed to continue in the last part of Release 19 with normative work (RP -243326) to specify a limited solution:

[0006] • Indoor inventory, indoor command only,

[0007] • Backscattering Device Type 1 only,

[0008] • Deployment Scenario 1 (D1T1-B) (micro BS indoor; device indoor) only,

[0009] o Carrier Wave (CW) outside topology,

[0010] • Reader to Device (R2D) in Downlink (DL) spectrum; Device to Reader (D2R) and CW in Uplink (UL) spectrum

[0011] That is, the only services supported in Release 19 are ‘inventory’ (reporting of device identified to the network) and ‘command’ (transmitting a small payload to the device). Further, the deployment scenario supported are indoor devices which receive CW transmissions for network nodes and the reflected signals are received by indoor micro basestations (in Frequency Division Duplex (FDD) uplink spectrum). For downlink, direct transmission from the indoor micro basestation to the device is supported in FDD downlink spectrum.

[0012] Functional and Protocol Simplifications for Ambient IoT

[0013] For Ambient IoT (A-IoT), 3GPP will target an IoT segment well below the existing cellular IoT technologies (e.g. Narrow Band IOT - NB-IoT), with significantly lower energy consumption and device complexity / cost. An illustration of an A-IoT environment is depicted in Figure 1. This requires simplifications in physical layer design, and the higher layer Layer 2 or Layer 3 (L2 / L3)design will also be much more lightweight with a minimal set of functionalities. For Random Access and multiple access devices the Release 19 scope is limited to the following:

[0014] • A-IoT Random access, including re-access for failure handling. Contention-based and contention-free cases are supported. For the contention-based random access, only Solution 1 (3 -step only) is included (unless RAN2 decides to use Solution 3 (unified solution) by RAN2#129).

[0015] For 2-step Contention Based Random Access (CBRA):

[0016] • 2 messages / steps sequence,

[0017] • Message 2 can be optional (at least for study), and

[0018] • Device transmit collision resolution (CR ID, e.g., RN16) along with data in 1st message. For 3 -step CBRA:

[0019] • 4 messages / steps sequence,

[0020] • Message 4 can be optional (at least for study), and

[0021] • Device transmit collision resolution (CR ID, e.g., RN16) in 1st message and data in subsequent message only if the 1st message is acknowledged.

[0022] Contention Free Random Access (CFRA):

[0023] • Using 3-step CBRA for single device but without Msgl / 2,

[0024] • The paging message trigger CBRA targets single device,

[0025] • Other methods can be based on ID to address resource utilization locally, e.g.,

[0026] • AS ID (For Further Studies, FFS), and

[0027] • Other ID (FFS).

[0028] Figure 2 shows a 2-step CBRA while Figure 3 shows a 3-step and 4-step CBRA.

[0029] TEMP ID Agreements in SA3

[0030] 3GPP Technical Specification (TS) 22.369 V19.3.0 (2024-09-27) in clause 5.2.6 outlines the need for privacy mechanisms to protect A-IoT identities from unauthorised exposure, it specifies the potential use of a Temp ID in the A-IoT NAS (Non-Access stratum) layer to address the privacy protection requirements. In the 3GPP TSG-SA3 Meeting #120, SA2 has considered the potential use of Temp ID to address privacy protection in A-IoT. Further, it is noted that identity protection mechanisms in mobile networks defined in TS 33.501, e.g. V19.2.0, often rely on encryption and pseudonymization techniques managed within SA3 scope. Therefore, SA3 is needed to ensure alignment with existing 3GPP security frameworks while meeting A-IoT-specific privacy requirements.Bloom Filter

[0031] A Bloom Filter (BF) as illustrated in Figure 4 is an m bits long bit string that is initialized to all zeros. Each item from a data set is added to the filter by hashing the inserted data item with k different hash functions. The selection of hash functions depends on the implementation, but once the hash functions have been selected, the same set of functions is used during the lifetime of the filter.

[0032] Each of these hash operations results in an integer value between zero and m-1. The resulting k different values are used as indexes to the Bloom filter bit string. The corresponding bits in the Bloom filter are set to 1 (see Figure 4, inserting items Data 1 and Data 2). If an indexed bit in the filter is already 1 due to some previously added data item, it is left unmodified. Once all the items of a set have been inserted in the filter, it can be used to verify if an arbitrary data item has been inserted in it or not.

[0033] The verification process starts with calculating the k different index values using the hash functions. The corresponding k values are verified from the filter and if all of them are set to 1 (see Figure 4, Data X verification) the verification process returns a positive answer. In this case, it can be assumed that the data item belongs to the set. However, if any of the verified bits is 0, the verification returns a negative answer, and the data item is not a member of the set.

[0034] The verification could result in a positive answer even though the data item has not been inserted in the filter. This means that all the bit locations are 1 but those were generated by inserting two or more different data items in the filter. This is called a false positive answer. False negative, is not possible with Bloom Filters, so a negative answer is always correct.

[0035] Due to the possible false positives, a data item belongs to a set with some probability if the verification returns a positive answer. This probability depends on many parameters, such as size of the filter m, the number of hash operations k per item, and the number of items that has been added to the filter. Roughly, the more bits that are set to 1 in the filter, the greater the probability for false positives.

[0036] SUMMARY

[0037] An object of the invention is to enable a more energy efficient and / or privacy -improving handling of a device identifier for communication between a telecommunications network and a wireless device.

[0038] A first aspect of the invention relates to a method performed by a wireless device for facilitating upcycling of a temporary identifier, ID, for the wireless device. The method comprises: agreeing with a network device of a telecommunications network, during anattachment procedure for the wireless device to the telecommunications network, on a root ID for the wireless device, and on a parameter to generate the temporary ID; generating the temporary ID as a function of the root ID and the parameter; and communicating with the network device using the temporary ID. Hereby is achieved, inter alia, that the wireless device and communications network / network device only need to agree on the initial root ID and a parameter for the generation of the temporary ID, after which there is no need for explicit signaling when changing temporary ID, or optionally just need for a minimal trigger indicating that ID has been / will be changed, thereby reducing amount of signaling needed for temporary ID handling, while enabling that a permanent device ID is not used as a temporary ID.

[0039] A second aspect of the invention relates to a wireless device for facilitating upcycling of a temporary identifier, ID, for the wireless device. The wireless device is configured to: agree with a network device of a telecommunications network, during an attachment procedure for the wireless device to the telecommunications network, on a root ID for the wireless device, and on a parameter to generate the temporary ID; generate the temporary ID as a function of the root ID and the parameter; and communicate with the network device using the temporary ID.

[0040] A third aspect of the invention relates to a method for facilitating upcycling of a temporary identifier, ID, for a wireless device, where the method is performed by a network device of a telecommunications network. The method comprises: agreeing with the wireless device, during an attachment procedure of the wireless device to the telecommunications network, on a root ID and on a parameter to generate the temporary ID; generating the temporary ID as a function of the root ID and the parameter; and communicating with the wireless device using the temporary ID.

[0041] In an embodiment of the method according to the third aspect, the method further comprises generating a bloom filter based on root IDs associated with the wireless device and other wireless devices. The method may in that case further comprise receiving an unknown temporary ID; generating a bloom filter value from the unknown temporary ID; checking if the bloom filter value is present in any bloom filters generated; for each matching bloom filter value, generating temporary IDs associated with respective wireless devices based on their root IDs; and determining that a respective wireless device is associated with the unknown temporary ID in response to a generated temporary ID matching the unknown temporary ID.

[0042] A fourth aspect relates to a network device for facilitating upcycling of a temporary identifier, ID, for a wireless device, wherein the network device, when being a part a telecommunications network, is configured to: agree with the wireless device during an attachment procedure of the wireless device to the telecommunications network, on a root ID and on aparameter to generate the temporary ID; generate the temporary ID as a function of the root ID and the parameter; and communicate with a network device using the temporary ID.

[0043] In an embodiment of the network device according to the fourth aspect, the network device is configured according to the above embodiment of the third aspect.

[0044] The function is in an embodiment (of any one of the four aspects) a one-way hash function. The wireless device is in an embodiment (of any one of the four aspects) an ambient internet of things, A-IoT, device, a low-power wide-area device, a slave node, an IOT device, or low power User Equipment.

[0045] The root ID is in an embodiment (of any one of the four aspects) one of: an A-IoT device ID, a Subscription Permanent Identifier, a Subscription Concealed Identifier, or an Electronic Product Code.

[0046] The temporary ID is in an embodiment (of any one of the four aspects) an n-th iterated temporary ID derived using an input in the form of F(ID_{n-l}, the parameter) = ID_{n} where n>l and ID O is the root ID.

[0047] In an embodiment of any one of the four aspects, the parameter is an ID-chain identifier related to the temporary ID.

[0048] In an embodiment of any one of the four aspects, the method further comprises agreeing to a next iteration of the temporary ID based on an implicit trigger or an explicit trigger. Such an implicit trigger may be based on one or more of: a number of messages sent, a timer, or occurrence of an event. The explicit trigger may be based on signaling between the wireless device and the network device to generate a new iteration of a temporary ID or to indicate which iteration of a temporary ID chain to use. The explicit trigger may alternatively be based on occurrence of a security event. The explicit trigger may comprise an indication that an over the air update has been performed at the wireless device.

[0049] In an embodiment of any one of the four aspects, a paging trigger comprises a mask of a root ID and the network node responds with either an n-th iterated ID or a first iterated ID.

[0050] In an embodiment of any one of the four aspects, the temporary ID is transmitted by a reader device over a contention free random access message 1 or a contention based random access message 3.

[0051] BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.Figure 1 shows an exemplary Ambient Internet of Things (lot) (A-IoT) environment in accordance with some embodiments of the present disclosure;

[0053] Figure 2 shows an example of a 2-step Contention Based Random Access (CBRA) procedure in accordance with some embodiments of the present disclosure;

[0054] Figure 3 shows an example of a 3-step and a 4-step CBRA procedure in accordance with some embodiments of the present disclosure;

[0055] Figure 4 shows an example of a bloom filter in accordance with some embodiments of the present disclosure;

[0056] Figure 5 shows a flow chart of a method for facilitating upcycling ofa device ID in accordance with some embodiments of the present disclosure;

[0057] Figure 6 shows a flow chart of another method for recovery of temporary IDs in accordance with some embodiments of the present disclosure;

[0058] Figure 7 shows an example of a communication system in accordance with some embodiments of the present disclosure;

[0059] Figure 8 shows a wireless device, which may be configured to operate in the communication system of Figure 7; and

[0060] Figure 9 shows a network node in accordance with some embodiments of the present disclosure.

[0061] DETAILED DESCRIPTION

[0062] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein.

[0063] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0064] There currently exist certain challenge(s). Especially for very power and computing constrained devices, it might be beneficial to have sessions with very long lifetime so as to not have to re-establish a full session / context with the network too frequently as it can be costly with respect to computation and energy. When having a long-lived session, it is important from a privacy point of view that a client device cannot be identified and tracked, which is why typically a temporary ID is used instead of the permanent ID. However, also the temporary ID needs to berefreshed since using the same identifier (even if temporary) for a long time also is a privacy concern. Re-negotiating the temporary ID also consumes resources, but somehow the network and device need to be synchronized, which is typically handled by explicit signaling for renegotiating the temporary ID. Since radio communication is expensive from a power constrained device’s point of view, a more efficient approach is needed.

[0065] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. Proposed in the disclosure is a hash-chain based temporary ID generation mechanism that can be run independently at device and network to generate unlinkable temporary IDs to be used for identifying the device. Furthermore, proposed is a solution for how the network can try to recover from a synchronization of such hash-chain based temporary ID. The disclosure presents techniques for how the hash chains can be used for generating temporary IDs and how a Bloom filter based approach can be used to recover from a desynchronization.

[0066] Certain embodiments may provide one or more of the following technical advantage(s). Since the device and network only need to agree on the initial root temporary ID, after which there is no need from explicit signaling when changing temporary ID, or optionally just need for a minimal trigger indicating that ID has been / will be changed, thereby reducing amount of signaling needed for temporary ID handling. Additionally, the recovery process disclosed herein for temporary-ID desynchronization situations, can be done solely at the network side, thereby not costing resources at a potentially resource constrained client device.

[0067] In a scenario where a client device (e.g., a User Equipment - UE) connects to a network (e.g., a core network (CN) via a Radio Access Network (RAN)). The communication between the UE and RAN / Core should be privacy preserving for the device. This means that the device should be identified by a temporary identifier towards the network, which (temporary identifier) can be changed when needed to further enhance privacy. The network and device agree on a temporary ID to be used for future communication. Aspects of this disclosure apply to power constrained devices, but the same temporary ID mechanisms and solutions could be applied to other scenarios.

[0068] In embodiments used here, RAN nodes can be gNB, UE, readers, intermediate UEs, master nodes, etc. Core network nodes (described herein as “network devices”) can be for example Ambient Internet of Things (loT) Functions (A-IoTFs), Access & Mobility Management Functions (AMFs) etc. The wireless devices could be UEs, A-IoT devices, low-power wide-area (LWPA) devices, a slave node, an IOT device (.e. a wireless loT device), or low power UEs. The polling messages can be termed as a paging message, a control message, a broadcast message, a groupcast message, and a registration request message, etc.Figure 5 shows a flow chart of a method for facilitating upcycling of device IDs in accordance with some embodiments of the present disclosure.

[0069] In a main embodiment in Figure 5, a network device 708 and a wireless device 712 agree on a temporary ID during an attachment procedure / registration procedure at step 502. The temporary ID is here from now on called a root temporary ID or just root ID, to be used for the wireless device 712 instead of a permanent ID of the wireless device / subscription. The network device 708 and the wireless device 712 might also agree, and exchange other information related to the use and generation of the temporary ID as explained in later steps.

[0070] The network device 708 communicates at step 508 with wireless device 712 using a temp ID which is obtained after an n-th iteration (generated at step 504 for the wireless device 712 and generated at step 506 for the network device 708) from the root ID where the backward derivation of root ID from n-th iterated temp ID is not possible. The iteration of IDs can be done using a oneway hash function. Examples of the one-way hash function are SHA-256 and SHA-3. Alternatively to the one-way hash-function, an encryption algorithm known to be useful in 3 GPP networks can be used, but output from such encryption algorithms / / encryption functions may have a length that might not be fixed, and might be longer than for hash functions. Also, the computational effort to perform encryption instead of hashing might be bigger. The example of the root ID can be e.g. an A-IOT device ID, a Subscription Permanent Identifier (SUPI), a Subscription Concealed Identifier (SUCI), an Electronic Product Code (EPC), an original device ID (International Mobile Equipment Identity, IMEI), and ID which is burnt in a device memory.

[0071] In the embodiment, the n-th iterated temp ID is derived using a function using input in the form of n-l-th iterated ID where for n = 1, the ID O is the root ID, i.e.,

[0072] F(ID_{n-l}) = ID_{n}

[0073] where

[0074] n >l,

[0075] ID O = ROOT ID.

[0076] In addition to using the ID_{n-l} as input to the function, also some additional parameter (id chain identifier) agreed between network and device could be used for initializing the chain of IDs, such that ID_1 = F(ROOT ID, <id_chain_identifier>), and for other IDs, ID{n} = F(ID_{n-1 }). This way, an attacker aware of the ROOT ID is not able to generate the chain of IDs.

[0077] To further improve on the solution, it is possible that the id chain identifier would be used for each generation round. This would prevent an attacker knowing a previous ID (e.g. ID N) to try to map a new ID (e.g. ID N-l) to the previous ID (e.g. ID N). Without using the id chain identifier, an attacker could do F(new_ID) to get to know the next ID in the chain, whichis what the wireless device 712 has used as ID previously. This approach would be relevant in scenarios where the temporary ID is sent in plain-text and one wants to prevent an attacker from being able to map different temporary IDs to the same device.

[0078] In one embodiment, at steps 510 and 512, the network device 708 and the wireless device 712, optionally based on policy exchanged during initial attach / regi strati on procedure in step 502, selects at step 512 a next temp ID for communication between the network device and the wireless device based on either implicit triggering or an explicit trigger at step 514. The explicit trigger can be a dedicated message telling the other party that the ID is about to be changed.

[0079] In one embodiment, the implicit triggering allows the network device and the wireless device to select the same next iterate temp ID for communication without the need to indicate via explicit signaling between the nodes. For example:

[0080] • In one option, the wireless device 712 can maintain a timer, and after a certain time window, the wireless device 712 always selects next temp ID.

[0081] • In another option, the wireless device 712 selects next temp ID if a new event has started.

[0082] The event can be referred to as a new paging / access event / round or new command event or new inventory event or new inventory plus command event / trigger.

[0083] • A third exemplary option is to change the temp ID after it has been used for a certain amount of messages.

[0084] In one embodiment, the explicit triggering allows the network device 708 and the wireless device 712 to exchange signaling and agree on utilizing next iterated temp ID.

[0085] This can include indicating what iteration (n) of the ID chain to use. This way the network device 708 and / or the wireless device 712 do not need to store the full chain of IDs, but can instead derive a suitable ID by doing the indicated (n) amount of iterations from the root ID.

[0086] In one embodiment, if a wireless device 712 has chosen a next temp ID, the wireless device can provide feedback or an indication to the network device 708 about selection of the next temp ID.

[0087] In one option, the wireless device 712 can indicate to the network device 708 that an over-the-air (OTA) update is received which can act as a trigger for selecting the next temp ID.

[0088] In one embodiment, the network device 708 can broadcast a request to the wireless devices to select the next temp ID in case a security event is detected.

[0089] In one embodiment, the wireless device 712 can indicate iteration of ID, instead of indicating the temp ID. In order to identify the transmission, the wireless device 712 can use other IDs, suchcollision resolution ID, say RN16, which is associated with the wireless device 712 for a particular Contention Based Random Access (CBRA) or Contention Free Random Access (CFRA) occasion.

[0090] In one option, the wireless device 712 can send a simple request without indicating the iteration or the temp ID to trigger calculation of the next temp ID, as the last iteration of ID is known by the network device.

[0091] As long as wireless device 712 and network device 708 are synchronized regarding what iteration of the temporary ID hash chain to use, the network device 708 can always identify the wireless device 712. However, there is the possibility that the network device 708 and wireless device 712 get desynchronized regarding what temporary ID to use, especially if the temporary ID is changed based on an implicit trigger.

[0092] In one embodiment, if a paging trigger contains mask of root ID, i.e., ID_{0}, targeting group of wireless devices, assuming one of targeted devices has valid n-th iterated temp ID, then the wireless device 712 responds during inventory or command or inventory plus command procedure with following policies configured by the network device 708:

[0093] • Option 1 : Respond with n-th iterated ID, i.e., ID_{ 1 } .

[0094] • Option 2: Responds with 1st iterated ID, i.e., ID_{ 1 }, i.e., temp ID iteration starts again, and existing valid n-th iteration ID will become invalid as network inventories the devices using root ID.

[0095] In one option, the temp ID is transmitted by a reader / reader device:

[0096] • Over CFRA Msgl, i.e., R2D MsgO is a paging message which triggers allocation, and in a next D2R message, the wireless device 712 can attempt to transmit a temp ID.

[0097] • Over CBRA Msg3, i.e., R2D MsgO is a paging message which triggers allocation, and in a next D2R message, a device transmits random ID or RN16, then a next R2D message (Msg2) is a contention resolution message, then in a next CBRA Msg3, wireless device 712 can attempt transmitting a temp ID.

[0098] Figure 6 shows a flow chart of an embodiment for recovery of temporary IDs in accordance with some embodiments of the present disclosure.

[0099] When the wireless device 712 and the network device 708 generate / agree on first a root temporary ID, and then do N hash iterations to get the N-long hash-chain of IDs, the network device 708 can also create a bloom filter (BF) that it populates with all the N temporary IDs of the hash-chain. Later, if there is a desynchronization between the wireless device 712 and the network device 708 (e.g. the network receives a message with a temporary ID it does not recognize), the network device 708 can try to identify the wireless device 712 by seeing what BF the “unknown” temporary ID matches. Since a BF never gives false negatives, the network can narrow down thetemporary ID to possibly belonging to a limited set of active UEs / contexts / BFs, i.e. the BFs to which the temporary ID matches. If there are more than 1 possible (i.e. matching) BFs, the network device 708 then has to start to generate the full hash chain up until the last seen ID of each BF to try to identify to which wireless device 712 / BF the “unknown” temporary ID belongs. An unknown temporary ID always has to be closer to the root than the previous ID the network device 708 has associated with a wireless device 712, which is why the network device 708 only has to check up until the last known ID in an ID hash-chain. Thus, the network device 708 has to keep the following data in the context for each wireless device 712:

[0100] • Root temporary ID

[0101] o Secret, agreed between UE and network on registration,

[0102] • Temporary ID chain identifier

[0103] o Secret, a random secret between UE / wireless device and network, also agreed on registration,

[0104] • Hash-chain length, N

[0105] o May be a fixed value for all UEs / wireless device devices, but has to be communicated to a UE / wireless device device since different mobile network operators (MNOs) might use different values for N. Can be communicated together with other info sent to the UE / wireless device when setting up root temporary ID, or in a separate message,

[0106] • Last seen iteration counter

[0107] o When using the first (i.e. Nth) temporary ID of the chain, this is set to N. When moving to the next ID, i.e. N-l in the chain, the value is changed to N-L

[0108] • Last seen temporary ID

[0109] o Whenever temporary ID is switched, this value is changed to the currently used temporary ID

[0110] • Permanent ID / pointer to PDU context (or similar)

[0111] • Bloom filter created based on all the N temporary IDs of the hash-chain.

[0112] With this approach, the network device 708 can try to recover on its own without involving the wireless device 712. So, if the network device 708 receives a temporary ID it does not have marked as a temporary ID currently being used by a served wireless device 712, the network device 708 generates the BF value of the unknown temporary ID. The network device 708 then checks which BFs the BF value matches with. Any BF (i.e. UE context, which includes their own BF) matching the BF value is a potential candidate as owner of the temporary ID. For each matching BF / wireless device 712 context the network device 708 then derives the hash chain up until thelast seen temporary ID, and checks if any of the IDs in the hash chain match the unknown temporary ID. When there is a match it is a verification that the wireless device 712 has been identified, i.e. the wireless device 712 whose context has the BF to which the unknown temporary ID belongs to owns the unknown temporary ID. Hash-calculations, done both for the BF and for the hash-chain, are computationally cheap operations, as is the comparison of the ID and BF values.

[0113] Thus, ain an exemplary embodiment, t step 502, the initial attach / register procedure is performed and based on the temporary ID and root ID. The network device 708 generates, in step 601, a BF based on root temporary ID of newly attached UE / wireless device 712. This also includes what was described above, with the wireless device and the network device agreeing on temp ID related parameters and generating the N:th temporary ID.

[0114] At step 602, the network device 708 receives from the wireless device 712 an unknown temporary ID, i.e. the network cannot identify the wireless device 712 context.

[0115] At step 604, the network device 708 generates a BF value from the unknown temporary ID. At step 606, the network device 708 checks if the BF value is present in any of the BFs of the wireless device contexts it has stored.

[0116] For each UE context with a BF to which the BF value matches, the network device 708 generates the hash-chain at step 608 from the root ID up until the last seen temporary ID, e.g. based on the last seen iteration counter. And, for each value of the hash-chain, the network device 708 checks if the value matches the unknown temporary ID.

[0117] At step 610, when the unknown temporary ID matches a value in a hash chain, this identifies the wireless device 712 context and thus the wireless device 712 that sent the unknown temporary ID.

[0118] At step 612, the network device 708 switches the received unknown temporary ID to be the last seen temporary ID for that context (and updates last seen iteration counter) and starts using that (unknown) temporary ID for the wireless device 712. In other words, the temporary ID is updated from the last seen temporary ID to the unknown temporary ID.

[0119] Figure 7 shows an example of a communication system 700 in accordance with some embodiments.

[0120] In the example, the communication system 700 includes a telecommunications network 702 that includes an access network 704, such as a radio access network (RAN), and a core network 706, which includes one or more core network nodes 708. The access network 704 includes one or more access network nodes or base stations of various types, access network nodes 710A and 710B are depicted (which may be collectively referred to as network nodes 710), or any othersimilar 3rdGeneration Partnership Project (3GPP) access nodes or non-3GPP access points (APs). As used herein, network device could refer to either a core network node, for example an Access & Mobility Management Function (AMF) or an Ambient IOT Function (A-IoTF). Some embodiments of the access network 704 may include more than one access network technology. The network nodes 710 of access network 704 facilitate direct or indirect connection of wireless devices, also referred to as user equipments (UEs), such as by connecting wireless devices 712A, 712B, 712C, and 712D (one or more of which may be generally referred to as wireless devices 712) to the core network 706 over one or more wireless connections. The access network nodes 710 or the core network nodes 708, or the wireless devices 712 can perform the methods described in Figures 5 and 6.

[0121] Moreover, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunications network 702 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a network node in the telecommunications network 702 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other network nodes to implement one or more functionalities of any network node in the telecommunications network 702, including one or more access network nodes 710 and / or core network nodes 708.

[0122] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). An ORAN network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN network node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies.The network nodes 710 facilitate direct or indirect connection of one or more UEs 712 to the core network 706 over one or more wireless connections. Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 700 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 700 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0123] The UEs 712 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 710 and other communication devices. Similarly, the network nodes 708, 710 are arranged, capable, configured, and / or operable to communicate directly or indirectly (e.g., via other devices of telecommunications network 702) with the UEs 712 and / or with other network nodes or equipment in the telecommunications network 702 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunications network 702. More specifically, UEs 712 may send messages, data, and / or other signals to network nodes 708, 710 or other elements of the telecommunications network 702 by transmitting such signals to the relevant device directly without the signals passing through any intervening devices or by transmitting such signals to the relevant device indirectly through an intervening device (or multiple intervening devices) that then transmit the signal to the relevant device. Similarly, network nodes 708, 710 may send messages, data, and other signals to UEs 7122, other network nodes 708, 710, and other devices in telecommunications network 702 directly or indirectly. As one specific example, a core network node 108 may transmit a particular message to a wireless device 712 by transmitting the message to an access network node 710 that will then transmit the message to the intended wireless device 712. Similarly, a core network node 108 may receive a particular message from a wireless device 712 by receiving the message from an access network node 710 that itself received the message from the wireless device 712.

[0124] In the depicted example, the core network 706 connects elements of the access network 704 (e.g., one or more of the network nodes 710) to one or more host computing systems, such as host 716. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 706 includes one or more core network nodes (e.g., core network node 708) of various types, one or more ofwhich may be generally referred to as network nodes 708. Network nodes 708 are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, access network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 708. Example core network nodes provide functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0125] The host 716 may be under the ownership or control of a service provider other than an operator or provider of the access network 704 and / or the telecommunications network 702. The host 716 may be operated by the service provider or on behalf of the service provider. The host 716 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0126] As a whole, the communication system 700 of Figure 7 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system 700 may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (Wi-Fi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (Wi-Max), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, Li-Fi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox. Moreover, the communication system 700 may be configured to support multiple different standards, protocols, or other rule sets, with individual components supporting all of the relevant rule sets or with different components or sub-systems within the communication system 700 supporting different standards, protocols, or rule sets.

[0127] As one example, in certain embodiments, access network 704 may contain some access network nodes 710 that support 3 GPP radio access technologies (RAT), such as LTE or NR, whileother access network nodes 710 support (or the same access network nodes 710 additionally support) non-3GPP RATs, such as Wi-Fi or a proprietary RAT. As another example, telecommunications network 702 may support multiple generations of related communication standards (e.g., 4G and 5G 3GPP communication standards) and, as a result, may include an access network 104 and / or a core network 106 that supports multiple different standard generations or may include multiple access networks 104 and / or multiple core networks 106 with individual networks 104, 106 supporting different standard generations.

[0128] Telecommunications network 702 may support network slicing to provide different logical networks to different devices that are connected to the telecommunications network 702. For example, the telecommunications network 702 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0129] In some examples, one or more of the UEs 712 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 704 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 704. Additionally, a UE may be configured for operating in single- or multi -RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0130] In the example, the hub 714 communicates with the access network 704 to facilitate indirect communication between one or more UEs (e.g., wireless device 712C and / or 712D) and network nodes (e.g., network node 710B). In some examples, the hub 714 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 714 may be a broadband router enabling access to the core network 706 for the UEs. As another example, the hub 714 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 710, or by executable code, script, process, or other instructions in the hub 714.

[0131] As another example, the hub 714 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 714 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub 714 may retrieve VR assets, video, audio, orother media or data related to sensory information via a network node, which the hub 714 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 714 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0132] The hub 714 may have a constant / persistent or intermittent connection to the network node 710B. The hub 714 may also allow for a different communication scheme and / or schedule between the hub 714 and UEs (e.g., wireless device 712C and / or 712D), and between the hub 714 and the core network 706. In other examples, the hub 714 is connected to the core network 706 and / or one or more UEs via a wired connection. Moreover, the hub 714 may be configured to connect to an M2M service provider over the access network 704 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 710 while still connected via the hub 714 via a wired or wireless connection. In some embodiments, the hub 714 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 710B. In other embodiments, the hub 714 may be a nondedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 710B, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0133] Figure 8 shows a wireless device 800, which may be configured to operate in communication system 700 of Figure 7. The wireless device 800 may be alternatively referred to as a UE 800, like a wireless device 712 within the context of communication system 700, or as a station (STA) 800 or as a non-access-point station (non-AP STA) 800, in accordance with respective embodiments. As used herein, a wireless device refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Examples of a wireless device include, but are not limited to, an ambient internet of things (A-IoT) device, a low-power wide-area (LWPA) device, a slave node, an IOT device, or low power User Equipment, smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, and wireless terminal. Other examples include any type of UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.The wireless device 800 may support device-to-device (D2D) communication, for example by implementing a 3 GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, the wireless device 800 may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, the wireless device 800 may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, the wireless device 800 may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0134] In particular embodiments, the wireless device 800 includes processing circuitry 802 that is operatively coupled via a bus 804 to an input / output interface 806, a power source 808, a memory 810, a communication interface 812, and / or any other component, or any combination thereof. Certain embodiments of the wireless device 800 may include all or a subset of the components shown in Figure 8. The level of integration between the components may vary from one embodiment of wireless device 800 to another. In general, in a particular embodiment of the wireless device 800, the processing circuitry 802, the input / output interface 806, the power source 808, the memory 810, and the communication interface 812 may, in whole or in part, represent or include physical components common to or shared by one or more of the other elements of the wireless device 800. Further, certain embodiments of the wireless devices 800 may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0135] The processing circuitry 802 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 810. The processing circuitry 802 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 802 may include multiple central processing units (CPUs).

[0136] In the example, the input / output interface 806 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer,an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into wireless device 800. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0137] In some embodiments, the power source 808 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used to supply power to circuitry or to charge an associated battery. The power source 808 may further include power circuitry for delivering power from the power source 808 itself, and / or an external power source, to the various parts of wireless device 800 via input circuitry or an interface such as an electrical power cable. Power source 808 may perform any formatting, converting, or other modification to make accessible power suitable for the respective components of the wireless device 800 to which power is supplied.

[0138] The memory 810 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 810 includes one or more programs 814, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 816. The memory 810 may store, for use by wireless device 800, any of a variety of various operating systems or combinations of operating systems.

[0139] The memory 810 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or anycombination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 810 may allow wireless device 800 to access instructions, programs, and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 810, which may be or comprise a device-readable storage medium.

[0140] The processing circuitry 802 may be configured to communicate with an access network or other network via or using the communication interface 812. The communication interface 812 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 822. The communication interface 812 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another wireless device or a network node in an access network). Each transceiver may include a transmitter 818 and / or a receiver 820 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 818 and receiver 820 may be coupled to one or more antennas (e.g., antenna 822) and may share circuit components, software, or firmware, or alternatively be implemented separately.

[0141] In the illustrated embodiment, communication functions of the communication interface 812 may include cellular communication, Wi-Fi communication (e.g., according to an IEEE 802.11 family standard), LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0142] In particular embodiments, wireless device 800 may provide an output of data captured via a sensor, through its communication interface 812, via a wireless connection to a network node, and / or in any appropriate manner. Data captured by sensors of a wireless device 800 can be communicated through a wireless connection to a network node via another wireless device 800. In particular embodiments, such output may be periodic (e.g., once every 15 minutes if it reportsthe sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected, an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0143] As another example, the wireless device 800 comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, wireless device 800 may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0144] The wireless device 800, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. In particular embodiments, wireless device 800 represents an loT device that comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the example embodiment of the wireless device 800 shown in Figure 8.

[0145] As yet another specific example, in an loT scenario, the wireless device 800 may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another wireless device and / or a network node. The wireless device 800 may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, wireless device 800 may implement the 3GPP NB-IoT standard. In other scenarios, wireless device 800 may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.In practice, any number of the wireless devices 800 may be used together with respect to a single use case. For example, a first wireless device 800 might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second wireless device 800 that is a remote controller operating the drone. When a user makes changes from the remote controller, the first wireless device 800 may adjust the throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second wireless device 800 can also include more than one of the functionalities described above. For example, the wireless device 800 might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0146] Figure 9 shows a network node 900 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunications network. In accordance with respective embodiments, the network node 900 may be configured to operate in communication system 700 of Figure 7, like the network nodes 708 or 710. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) andNRNodeBs (gNBs)), 0-RAN nodes or components of an 0-RAN node (e.g., 0-RU, 0-DU, O-CU).

[0147] Network nodes 900 may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. Network node 900 may be a relay node or a relay donor node controlling a relay. Network nodes 900 may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an 0-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0148] Other examples of network nodes 900 include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes,Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0149] In particular embodiments, the network node 900 includes a processing circuitry 902, a memory 904, a communication interface 906, and a power source 908. In general, in a particular embodiment of network node 900, processing circuitry 902, memory 904, communication interface 906, and power source 908 may, in whole or in part, represent or include physical components common to or shared by one or more of the other elements of network node 900.

[0150] The network node 900 may be composed of multiple distinct network entities (e.g., a NodeB entity and an RNC entity, or a BTS entity and a BSC entity, etc.), which may each have or utilize their own respective physical components. In certain scenarios in which the network node 900 comprises multiple such entities (e.g., BTS and BSC), one or more of the separate entities may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 900 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memories 904 or portions of the memory 904 for different RATs) and some components may be reused (e.g., a same antenna 910 may be shared by different RATs). The network node 900 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 900, for example GSM, WCDMA, LTE, NR, Wi-Fi (e.g., according to an IEEE 802.11 family standard), Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 900.

[0151] The processing circuitry 902 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other components, such as the memory 904, to provide network node 900 functionality.

[0152] In some embodiments, the processing circuitry 902 includes a system on a chip (SOC). In some embodiments, the processing circuitry 902 includes one or more of radio frequency (RF) transceiver circuitry 912 and baseband processing circuitry 914. In some embodiments, the RF transceiver circuitry 912 and the baseband processing circuitry 914 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments,part or all of RF transceiver circuitry 912 and baseband processing circuitry 914 may be on the same chip or set of chips, boards, or units.

[0153] The memory 904 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 902. The memory 904 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 902 and utilized by the network node 900. The memory 904 may be used to store any calculations made by the processing circuitry 902 and / or any data received via the communication interface 906. In some embodiments, the processing circuitry 902 and memory 904 is integrated.

[0154] The communication interface 906 is used in wired or wireless communication of signaling and / or data with UEs, other network nodes, and / or any other network equipment. In the illustrated embodiment, communication interface 906 comprises port(s) / terminal(s) 916 to send and receive data, for example to and from a network over a wired connection. In particular embodiments, network node 800 may be capable of wireless communication and communication interface 906 may also include radio front-end circuitry 918 that may be coupled to, or in certain embodiments a part of, an antenna 910. Particular embodiments of radio front-end circuitry 918 include filter(s) 920 and amplifier(s) 922. The radio front-end circuitry 918 may be connected to an antenna 910 and processing circuitry 902. The radio front-end circuitry may be configured to condition signals communicated between antenna 910 and processing circuitry 902. The radio front-end circuitry 918 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 918 may convert the digital data into a radio signal(s) having the appropriate channel and bandwidth parameters using a combination of filters 920 and / or amplifiers 922. The radio signal(s) may then be transmitted via the antenna 910. Similarly, when receiving data, the antenna 910 may collect radio signals which are then converted into digital data by the radio front-end circuitry 918. The digital data may be passed to the processing circuitry 902. In other embodiments, the communication interface may comprise different components and / or different combinations of components.In certain alternative embodiments, network node 900 may be capable of wireless communication but does not include separate radio front-end circuitry 918, instead, the processing circuitry 902 includes radio front-end circuitry and is connected to the antenna 910. Similarly, in some embodiments, all or some of the RF transceiver circuitry 912 is part of the communication interface 906. In still other embodiments, the communication interface 906 includes one or more ports or terminals 916, the radio front-end circuitry 918, and the RF transceiver circuitry 912, as part of a radio unit (not shown), and the communication interface 906 communicates with the baseband processing circuitry 914, which is part of a digital unit (not shown).

[0155] The antenna 910 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 910 may be coupled to the radio front-end circuitry 918 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 910 is separate from the network node 900 and connectable to the network node 900 through one or more interfaces or ports.

[0156] The antenna 910, communication interface 906, and / or the processing circuitry 902 may be configured to perform some or all of the receiving operations and / or obtaining operations described herein as being performed by the network node 900. Any information, data, and / or signals may be received from a UE, another network node, and / or any other network equipment. Similarly, the antenna 910, the communication interface 906, and / or the processing circuitry 902 may be configured to perform some or all of the transmitting or sending operations described herein as being performed by the network node 900. Any information, data and / or signals may be transmitted to a UE, another network node, and / or any other network equipment.

[0157] The power source 908 provides power to the various components of network node 900 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 908 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 900 with power for performing the functionality described herein. For example, the network node 900 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 908. As a further example, the power source 908 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0158] Embodiments of the network node 900 may include additional components beyond those shown in Figure 9 for providing certain aspects of the network node’s functionality, including anyof the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 900 may include user interface equipment to allow input of information into the network node 900 and to allow output of information from the network node 900. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 900.

[0159] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions, and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0160] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to othercomponents of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0161] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.Exemplary embodiments

[0162] 1. A method by a wireless device (712) for facilitating upcycling of a device identifier, ID, the method comprising:

[0163] facilitating (502) an attachment of the wireless device (712) to a network, resulting in agreement on a root ID, and sharing of information to generate a temporary ID from the root ID;

[0164] generating (504) the temporary ID as a function of the root ID; and

[0165] communicating (508) with a network device (708) using the temporary ID.

[0166] 2. The method of embodiment 1, wherein the function of the root ID is a one-way hash function.

[0167] 3. The method of any of embodiments 1 to 2, wherein the wireless device (712) is an ambient internet of things, A-IoT, device, a low-power wide-area, LWPA, device, a slave node, an IOT device, or low power User Equipment, UE.

[0168] 4. The method of any of embodiments 1 to 3, wherein the root ID is one of:

[0169] an A-IoT device ID;

[0170] a Subscription Permanent Identifier, SUPI;

[0171] a Subscription Concealed Identifier, SUCI;

[0172] original device ID; or

[0173] other permanent device ID.

[0174] 5. The method of any of embodiments 1 to 4, wherein the temporary ID is an n-th iterated temporary ID derived using an input in the form of F(ID_{n-l }) = ID_{n} where n>l and ID O is the root ID.

[0175] 6. The method of embodiment 5, wherein the function of the root ID is based on a function of the root ID and an additional parameter agreed on between the network device (708) and the wireless device (712).

[0176] 7. The method of any of embodiments 1 to 6, further comprising:

[0177] agreeing (510) to a next iteration of the temporary ID based on an implicit trigger or an explicit trigger.8. The method of embodiment 7, wherein the implicit trigger is based on one or more of: a number of messages sent;

[0178] a timer; or

[0179] occurrence of an event.

[0180] 9 The method of embodiment 7, wherein the explicit trigger is based on signaling between the wireless device (712) and the network device (708) to generate a new iteration of a temporary ID or to indicate which iteration of a temporary ID chain to use.

[0181] 10. The method of embodiment 7, wherein the explicit trigger is based on occurrence of a security event.

[0182] 11. The method of embodiment 7, wherein the explicit trigger comprises an indication that an over the air update has been performed at the wireless device (712).

[0183] 12. The method of any of embodiments 1 to 11, wherein a paging trigger comprises a mask of a root ID and the network node responds with either an n-th iterated ID or a 1stiterated ID.

[0184] 13. The method of any of embodiments 1 to 12, wherein the temporary ID is transmitted by a reader device over a contention free random access msg 1 or a contention based random access msg3.

[0185] 14. A wireless device (712) for facilitating upcycling of a device identifier, ID, wherein the wireless device (712) is configured to:

[0186] facilitate (502) an attachment of the wireless device (712) to a network, resulting in agreement on a root ID, and sharing of information to generate a temporary ID from the root ID;

[0187] generate (504) the temporary ID as a function of the root ID; and

[0188] communicate (508) with a network device (708) using the temporary ID.

[0189] 15. The wireless device (712) of embodiment 14, wherein the wireless device (712) is further configured to perform any of the embodiments of embodiments 2 to 13.

[0190] 16. A method by a network device (708) for facilitating upcy cling of a device identifier, ID,the method comprising:

[0191] facilitating (502) an attachment of a wireless device (712) to a network, resulting in agreement on a root ID, and sharing of information to generate a temporary ID from the root ID;

[0192] generating (506) the temporary ID as a function of the root ID; and

[0193] communicating (508) with the wireless device (712) using the temporary ID.

[0194] 17. The method of embodiment 16, wherein the function of the root ID is a one-way hash function.

[0195] 18. The method of any of embodiments 16 to 17, wherein the wireless device (712) is an ambient internet of things, A-IoT, device, a low-power wide-area, LWPA, device, a slave node, an IOT device, or low power User Equipment, UE.

[0196] 19. The method of any of embodiments 16 to 18, wherein the root ID is one of:

[0197] an A-IoT device ID;

[0198] a Subscription Permanent Identifier, SUPI;

[0199] a Subscription Concealed Identifier, SUCI;

[0200] original device ID; or

[0201] other permanent device ID.

[0202] 20. The method of any of embodiments 16 to 19, wherein the temporary ID is an n-th iterated temporary ID derived using an input in the form of F(ID_{n-l }) = ID_{n} where n>l and ID O is the root ID.

[0203] 21. The method of embodiment 20, wherein the function of the root ID is based on a function of the root ID and an additional parameter agreed on between the network device (708) and the wireless device (712).

[0204] 22. The method of any of embodiments 16 to 21, further comprising:

[0205] agreeing (512) to a next iteration of the temporary ID based on or more of an implicit trigger or an explicit trigger.

[0206] 23. The method of embodiment 22, wherein the implicit trigger is based on one or more of:

[0207] a number of messages sent;a timer; or

[0208] occurrence of an event.

[0209] 24 The method of embodiment 22, wherein the explicit trigger is based on signaling between the wireless device (712) and the network device (708) to generate a new iteration of a temporary ID or to indicate which iteration of a temporary ID chain to use.

[0210] 25. The method of embodiment 22, wherein the explicit trigger is based on occurrence of a security event.

[0211] 26. The method of embodiment 22, wherein the explicit trigger comprises an indication that an over the air update has been performed at the wireless device (712).

[0212] 27. The method of any of embodiments 16 to 26, wherein a paging trigger comprises a mask of a root ID and the network node responds with either an n-th iterated ID or a 1stiterated ID.

[0213] 28. The method of any of embodiments 16 to 27, wherein the temporary ID is transmitted by a reader device over a contention free random access msg 1 or a contention based random access msg3.

[0214] 29. The method of any of embodiments 16 to 28, further comprising:

[0215] generating (601) a bloom filter based on root IDs associated with the wireless device (712) and other wireless devices (712).

[0216] 30. The method of embodiment 29, further comprising:

[0217] receiving (602) an unknown temporary ID;

[0218] generating (604) a bloom filter value from the unknown temporary ID;

[0219] checking (606) if the bloom filter value is present in any bloom filters generated; for each matching bloom filter value, generating (608) temporary IDs associated with respective wireless devices (712) based on their root IDs; and

[0220] determining (610) that a respective wireless device (712) is associated with the unknown temporary ID in response to a generated temporary ID matching the unknown temporary ID.

[0221] 31. A network device (708) for facilitating upcycling of a device identifier, ID, whereinthe network device is configured to:

[0222] facilitate (502) an attachment of the wireless device (712) to a network, resulting in agreement on a root ID, and sharing of information to generate a temporary ID from the root ID;

[0223] generate (506) the temporary ID as a function of the root ID; and

[0224] communicate (508) with a network device (708) using the temporary ID.

[0225] 32. The network device of embodiment 31 wherein the network device (708) is further configured to perform any of the embodiments of embodiments 17 to 30.

Claims

1. CLAIMS1. A method performed by a wireless device (712) for facilitating upcycling of a temporary identifier, ID, for the wireless device (712), the method comprising:agreeing (502) with a network device (708) of a telecommunications network (702), during an attachment procedure for the wireless device (712) to the telecommunications network (702), on a root ID for the wireless device (712), and on a parameter to generate the temporary ID; generating (504) the temporary ID as a function of the root ID and the parameter; and communicating (508) with the network device (708) using the temporary ID.

2. The method of claim 1, wherein the function is a one-way hash function.

3. The method of any one of claims 1 to 2, wherein the wireless device (712) is an ambient internet of things, A-IoT, device, a low-power wide-area device, a slave node, an IOT device, or low power User Equipment.

4. The method of any of embodiments 1 to 3, wherein the root ID is one of:an A-IoT device ID;a Subscription Permanent Identifier;a Subscription Concealed Identifier; oran Electronic Product Code.

5. The method of any one of claims 1 to 4, wherein the temporary ID is an n-th iterated temporary ID derived using an input in the form of F(ID_{n-l}, the parameter) = ID_{n} where n>l and ID O is the root ID.

6. The method of any one of claims 1-5, wherein the parameter is an ID-chain identifier related to the temporary ID.

7. The method of any one of claims 1 to 6, further comprising:agreeing (510) to a next iteration of the temporary ID based on an implicit trigger or an explicit trigger.

8. The method of claim 7, wherein the implicit trigger is based on one or more of:a number of messages sent;a timer; oroccurrence of an event.9 The method of claim 7, wherein the explicit trigger is based on signaling between the wireless device (712) and the network device (708) to generate a new iteration of a temporary ID or to indicate which iteration of a temporary ID chain to use.

10. The method of claim 7, wherein the explicit trigger is based on occurrence of a security event.

11. The method of claim 7, wherein the explicit trigger comprises an indication that an over the air update has been performed at the wireless device (712).

12. The method of any one of claims 1 to 11, wherein a paging trigger comprises a mask of a root ID and the network node responds with either an n-th iterated ID or a first iterated ID.

13. The method of any one of claims 1 to 12, wherein the temporary ID is transmitted by a reader device over a contention free random access message 1 or a contention based random access message 3.

14. A wireless device (712) for facilitating upcycling of a temporary identifier, ID, for the wireless device (712), wherein the wireless device (712) is configured to:agree with a network device (708) of a telecommunications network (702), during an attachment procedure for the wireless device (712) to the telecommunications network (702), on a root ID for the wireless device (712), and on a parameter to generate the temporary ID;generate the temporary ID as a function of the root ID and the parameter; and communicate with the network device (708) using the temporary ID.

15. The wireless device (712) of claim 14, wherein the wireless device (712) is further configured to perform a method according to any one of claims 2 to 13.

16. A method for facilitating upcycling of a temporary identifier, ID, for a wireless device (712), the method performed by a network device (708) of a telecommunications network (702)and comprising:agreeing (502) with the wireless device (712), during an attachment procedure of the wireless device (712) to the telecommunications network (702), on a root ID and on a parameter to generate the temporary ID;generating (506) the temporary ID as a function of the root ID and the parameter; and communicating (508) with the wireless device (712) using the temporary ID.

17. The method of claim 16, wherein the function is a one-way hash function.

18. The method of any one of claims 16 to 17, wherein the wireless device (712) is an ambient internet of things, A-IoT, device, a low-power wide-area device, a slave node, an IOT device, or low power User Equipment.

19. The method of any one of claims 16 to 18, wherein the root ID is one of:an A-IoT device ID;a Subscription Permanent Identifier;a Subscription Concealed Identifier; oran Electronic Product Code.

20. The method of any one of claims 16 to 19, wherein the temporary ID is an n-th iterated temporary ID derived using an input in the form of F(ID_{n-l}, the parameter) = ID_{n} where n>l and ID O is the root ID.

21. The method of any one of claims 16-20, wherein the parameter is an ID-chain identifier related to the temporary ID.

22. The method of any one of claims 16 to 21, further comprising:agreeing (512) to a next iteration of the temporary ID based on or more of an implicit trigger or an explicit trigger.

23. The method of claim 22, wherein the implicit trigger is based on one or more of:a number of messages sent;a timer; oroccurrence of an event.24 The method of claim 22, wherein the explicit trigger is based on signaling between the wireless device (712) and the network device (708) to generate a new iteration of a temporary ID or to indicate which iteration of a temporary ID chain to use.

25. The method of claim 22, wherein the explicit trigger is based on occurrence of a security event.

26. The method of claim 22, wherein the explicit trigger comprises an indication that an over the air update has been performed at the wireless device (712).

27. The method of any one of claims 16 to 26, wherein a paging trigger comprises a mask of a root ID and the network node responds with either an n-th iterated ID or a first iterated ID.

28. The method of any one of claims 16 to 27, wherein the temporary ID is transmitted by a reader device over a contention free random access msg 1 or a contention based random access msg3.

29. The method of any one of claims 16 to 28, further comprising:generating (601) a bloom filter based on root IDs associated with the wireless device (712) and other wireless devices.

30. The method of claim 29, further comprising:receiving (602) an unknown temporary ID;generating (604) a bloom filter value from the unknown temporary ID;checking (606) if the bloom filter value is present in any bloom filters generated; for each matching bloom filter value, generating (608) temporary IDs associated with respective wireless devices (712) based on their root IDs; anddetermining (610) that a respective wireless device is associated with the unknown temporary ID in response to a generated temporary ID matching the unknown temporary ID.

31. A network device (708) for facilitating upcycling of a temporary identifier, ID, for a wireless device (712), wherein the network device, when being a part a telecommunications network (702), is configured to:agree with the wireless device (712) during an attachment procedure of the wireless device (712) to the telecommunications network (702), on a root ID and on a parameter to generate the temporary ID;generate the temporary ID as a function of the root ID and the parameter; and communicate (508) with a network device (708) using the temporary ID.

32. The network device of claim 31 wherein the network device (708) is further configured to perform a method according to any one of claims 17 to 30.