Zero-Power Terminal Authentication with Simplified Key Agreement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is currently no clear specification for how a zero-power terminal, with limited computing capability, should perform authentication and key agreement with a network side in wireless communications systems, particularly in scenarios involving cellular and sidelink communication.

Innovation Solution

An authentication method is provided where a first device, such as a zero-power terminal, generates a second message authentication code based on a key generation algorithm and a parameter, and transmits a response parameter to authenticate with the network side, simplifying the authentication process by requiring support for only one or two key generation algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a zero-power terminal performs traditional authentication and key agreement procedures, then communication security is improved, but device complexity and computing capability requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key generation functionality from the zero-power terminal and concentrates it in the network side (authentication network element). The terminal only needs to support one or two simple key generation algorithms, while the network side performs the complex authentication operations, thereby reducing terminal complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the authentication parameters by introducing a simplified key generation approach where the terminal generates keys based on received parameters from the network. This parameter-driven approach allows the terminal to perform authentication with minimal computational resources while the network maintains full security control.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If a zero-power terminal supports multiple key generation algorithms, then authentication flexibility is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidcomputing capability requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the burden of supporting multiple complex key generation algorithms from the zero-power terminal and relocates it to the network side. The terminal only needs to support one or two simple algorithms, while the network provides the necessary parameters and handles the complex cryptographic operations, achieving flexibility without increasing terminal complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network side acts as an intermediary that provides authentication parameters to the terminal. Instead of the terminal directly implementing multiple complex algorithms, the network mediates the authentication process by supplying pre-computed parameters that the terminal can use with its limited algorithm support, thereby maintaining flexibility while reducing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4718901A1Method and apparatus for authentication
Publication Date: 2026.04.01 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • EP4718901A1 patent drawingFigure 1~2
  • EP4718901A1 patent drawingFigure 3~4
  • EP4718901A1 patent drawingFigure 5~6

AI summary

The present application provides a method and an apparatus for authentication. The method comprises: a first device receiving a first authentication request from an agent node, wherein the first authentication request comprises a first message authentication code, and the first message authentication code is generated by an authentication network element; the first device generating a second message authentication code on the basis of a first key generation algorithm and a first parameter; the first device authenticating the authentication network element on the basis of the first message authentication code and the second message authentication code; the first device generating a response parameter in the condition that the authentication network element is successfully authenticated; and the first device sending a first authentication response to the agent node, wherein the first authentication response comprises the response parameter, and the response parameter is configured for authenticating the first device.