Ambient IoT Tag Authentication with Two-Piece Reader Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication networks lack effective methods to protect and secure data stored on or generated by ambient internet-of-things (IoT) tag devices, which are often battery-less and rely on energy harvesting, making them vulnerable to unauthorized access.

Innovation Solution

Implement a two-piece authorization process using authentication information from both the cellular network (Network-Auth-Piece) and the ambient IoT reader device (Reader-Auth-Piece) to verify the authenticity of the reader device before allowing data transmission, ensuring that only authorized devices can access the tag device's information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If ambient IoT tag devices are made battery-less with energy harvesting, then device complexity and power consumption are reduced, but security and data protection capabilities deteriorate

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication mechanism is segmented into two separate components: Network-Auth-Piece (provisioned by mobile network) and Reader-Auth-Piece (held by reader device). Both pieces are required together to access tag data, distributing security responsibilities and enabling battery-less tags to maintain security through cryptographic authentication rather than hardware complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobile communication network acts as an intermediary that provisions the Network-Auth-Piece to tag devices and validates authentication requests. This intermediary role enables centralized security management for distributed battery-less tags, maintaining security without requiring complex local processing in the tags themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If open access to ambient IoT tag devices is allowed, then ease of operation is improved, but data protection and security deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Authentication verification is performed preliminarily before allowing any data access to the tag device. The tag device verifies both Network-Auth-Piece and Reader-Auth-Piece before transmitting data, preventing unauthorized access before it can occur rather than relying on post-access security measures

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

Different authentication capabilities are assigned to different devices: tags receive Network-Auth-Piece from the network, reader devices obtain Reader-Auth-Piece, and both are required for successful access. This differentiated local quality enables selective access control while maintaining ease of operation for authorized users

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4471630B1Method for using an ambient internet-of-things reader device in a mobile communication network in order to communicate with an ambient internet-of-things tag device, ambient internet-of-things reader device, especially user equipment, system or mobile communication network, ambient internet-of-things tag device, program and computer-readable medium
Publication Date: 2025.08.06 DEUTSCHE TELEKOM AG
  • EP4471630B1 patent drawingFigure 1

AI summary

The invention relates to a method for using an ambient internet-of-things reader device in a mobile communication network in order to communicate with an ambient internet-of-things tag device, wherein the communication between the ambient internet-of-things reader device and the ambient internet-of-things tag device involves the ambient internet-of-things reader device requesting a piece of requested information from the ambient internet-of-things tag device, the piece of requested information being stored on or within the ambient internet-of-things tag device and the piece of requested information being able to be transmitted, by the ambient internet-of-things tag device, to the ambient internet-of-things reader device, wherein, in order to use the ambient internet-of-things reader device to communicate with the ambient internet-of-things tag device, the method comprises the following steps: -- in a first step, the ambient internet-of-things tag device comprises a first piece of authentication information - or the ambient internet-of-things tag device receives, from the mobile communication network, the first piece of authentication information - , -- in a second step, the ambient internet-of-things reader device transmits a request message, to the ambient internet-of-things tag device, the request message comprising a second piece of authentication information, -- in a third step, the ambient internet-of-things tag device performs a verification or authentication process, wherein the verification or authentication process involves using both the first piece of authentication information and the second piece of authentication information in order to obtain a verification or authentication result, wherein, dependent on the verification or authentication result, the ambient internet-of-things reader device receives, from the ambient internet-of-things tag device, the piece of requested information or another information or no information at all.