WO2024257073A1 - Confidentiality and privacy protection of messages from restricted devices - Google Patents
Confidentiality and privacy protection of messages from restricted devices Download PDFInfo
- Publication number
- WO2024257073A1 WO2024257073A1 PCT/IB2024/058470 IB2024058470W WO2024257073A1 WO 2024257073 A1 WO2024257073 A1 WO 2024257073A1 IB 2024058470 W IB2024058470 W IB 2024058470W WO 2024257073 A1 WO2024257073 A1 WO 2024257073A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- temporary identifier
- network entity
- processor
- nonce
- lot
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/75—Temporary identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
- H04W60/04—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0869—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/02—Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/047—Key management, e.g. using generic bootstrapping architecture [GBA] without using a trusted network node as an anchor
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/71—Hardware identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/18—Self-organising networks, e.g. ad-hoc networks or sensor networks
Definitions
- Some implementations of the methods and apparatuses described herein may further include a processor for wireless communication, comprising at least one controller coupled with at least one memory and configured to cause the processor to receive a registration request from a network server that includes a nonce and a temporary identifier, compare the temporary identifier received via the registration request and the generated temporary identifier, and, when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmit a response message to the network server that indicates the match of the temporary identifier and the generated temporary identifier.
- a processor for wireless communication comprising at least one controller coupled with at least one memory and configured to cause the processor to receive a registration request from a network server that includes a nonce and a temporary identifier, compare the temporary identifier received via the registration request and the generated temporary identifier, and, when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmit a response message to the network server that indicates the match of the temporary
- the at least one controller is further configured to cause the processor to generate an output hash using a device identifier associated with the processor and the nonce from the registration request and generate a temporary identifier using the output hash of the device identifier associated with the processor and the nonce from the registration request.
- Some implementations of the methods and apparatuses described herein may further include a method performed by an loT device, the method comprising receiving a registration request from a network server that includes a nonce and a temporary identifier, generating an output hash using a device identifier for the loT device and the nonce from the registration request, generating a temporary identifier using the device identifier for the loT device and the nonce from the registration request, comparing the temporary identifier received via the registration request and the generated temporary identifier, and, when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmitting a response message to the network server that indicates the match of the temporary identifier and the generated temporary identifier.
- Figure 2 illustrates an example of messaging between an loT server and an ambient-powered loT device in accordance with aspects of the present disclosure.
- Figure 8 illustrates an example of a network equipment (NE) in accordance with aspects of the present disclosure.
- Figure 9 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present disclosure.
- Figure 11 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present disclosure.
- loT devices Lacking a USIM or other similar component, these loT devices cannot employ typical confidentiality or privacy protection to its communications, because such techniques are computationally intense and may utilize all or much of any harvested energy just to perform the protection. Thus, ambient power-enabled loT devices should employ other techniques that balance the resources for performing computations with a desired level of security.
- the loT devices and/or loT servers can perform key generation using secret parameters that are only known to the devices/servers as input into a hash function.
- the loT server and loT device can utilize a device identifier as a secret parameter, which is input, along with a nonce, into hash operations or functions to generate security keys (e.g., a key K).
- key generation can include time information or other similar information to ensure freshness of the security K during generation.
- Such operations have a low complexity, but a suitable level of protection, and thus can be useful for loT devices and other ambient power-enabled devices when sending confidentiality and/or privacy protected messages, such as during registration procedures.
- Aspects of the present disclosure are described in the context of a wireless communications system.
- the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20.
- IEEE Institute of Electrical and Electronics Engineers
- Wi-Fi Wi-Fi
- WiMAX IEEE 802.16
- IEEE 802.20 The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
- TDMA time division multiple access
- FDMA frequency division multiple access
- CDMA code division multiple access
- the one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100.
- One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology.
- An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection.
- an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
- An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area.
- an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies.
- an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN).
- NTN non-terrestrial network
- different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
- the one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100.
- a UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology.
- the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples.
- the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.
- LoT Internet-of-Things
- LoE Internet-of-Everything
- MTC machine-type communication
- An NE 102 may support communications with the CN 106, or with another NE 102, or both.
- an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface).
- the NE 102 may communicate with each other directly.
- the NE 102 may communicate with each other or indirectly (e.g., via the CN 106.
- one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC).
- An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).
- TRPs transmission-reception points
- the CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions.
- the CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)).
- EPC evolved packet core
- 5GC 5G core
- MME mobility management entity
- AMF access and mobility management functions
- S-GW serving gateway
- PDN gateway Packet Data Network gateway
- UPF user plane function
- control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
- NAS non-access stratum
- the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures).
- the NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
- a time interval of a resource may be organized according to frames (also referred to as radio frames).
- Each frame may have a duration, for example, a 10 millisecond (ms) duration.
- each frame may include multiple subframes.
- each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration.
- each frame may have the same duration.
- each subframe of a frame may have the same duration.
- a time interval of a resource may be organized according to slots.
- a subframe may include a number (e.g., quantity) of slots.
- the number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100.
- Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols).
- the number (e.g., quantity) of slots for a subframe may depend on a numerology.
- an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc.
- the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz).
- FR1 410 MHz - 7.125 GHz
- FR2 24.25 GHz - 52.6 GHz
- FR3 7.125 GHz - 24.25 GHz
- FR4 (52.6 GHz - 114.25 GHz
- FR4a or FR4-1 52.6 GHz - 71 GHz
- FR5 114.25 GHz - 300 GHz
- the loT device 220 may include other security algorithms for security protection of messages, while utilizing the technology described herein for privacy/confidentiality protection of messages, such as during registration procedures.
- Figure 3 illustrates an example server-initiated messaging flow 300 between the loT server 210 and the loT device 220 in accordance with aspects of the present disclosure.
- loT server 210 and the loT device 220 are shown performing the operations of the messaging flow 300, some aspects of some operations may also be performed by other entities of the messaging flow 300 or by entities that are not shown in the messaging flow 300, or any combination thereof.
- FIG. 4 illustrates an example representation of an output hash 400 in accordance with aspects of the present disclosure.
- the output hash 400 is concatenated, with a first portion 410, the most significant bits, representing the temporary identifier, and a second portion 420, the least significant bits, representing the encryption key K.
- the output hash 400 is truncated with the least significant bits representing the key K.
- step 2 The loT server 210 encrypts the device ID with the encryption key K as a temporary identifier and the configured encryption algorithm.
- the loT device 220 uses the temporary ID corresponding to a remaining part of the output hash of the encryption key K.
- the loT server 210 transmits an initial registration request message to the loT device 220.
- the request includes or contains the nonce and the temporary ID.
- the device profile in the loT server 210 may store initial temporary device IDs for one time use at a time of initial registration for all devices as device profile information and/or may broadcast the request to a subset of loT devices, as described herein.
- the loT device 220 receives the initial registration request from the loT server 210.
- the loT device 220 computes or otherwise determines the encryption key K and temporary ID as described herein, such as via a hash of the device ID and the nonce (and, optionally, the length of the nonce and/or a root key).
- the loT device 220 computes or otherwise determines the temporary ID. For example, the loT device 220 encrypts the device ID with the key K or uses the temporary identifier when the key K is a truncated hash. The loT device 220 compares the determined temporary ID with the received temporary ID, and when the compared temporary IDs match, the loT device 220 confirms determines it was successfully targeted by the loT server 210 and can send a result of the comparison to the loT server 210.
- the loT server 210 may broadcast the initial registration request to multiple devices, such as when there is no direct addressing of the loT device 220.
- Each of the devices e.g., a subset of devices
- step 5 the loT device 220 transmits an initial registration response message, which includes or contains a result of the comparison and the determined temporary ID, to the loT server 210. However, when the temporary identifiers do not match, the loT device 220 may not send a response message. At this point, the loT device 220 is registered with the loT server 210 and may refrain from performing additional comparisons for a certain time period (e.g., tracked by a registration timer).
- the loT device 220 may transmit other or additional information to the loT server 210 via the response message, such as device capabilities, security capabilities, and so on.
- the loT device 220 may encrypt the additional information with the key K.
- the messaging flow 500 may include the loT server 210 and the loT device 220, which may be examples of loT servers and loT devices, as described herein.
- the operations between theloT server 210 and the loT device 220 may be performed in different orders or at different times. Some operations may also be omited, or other operations may be added.
- the loT server 210 and the loT device 220 are shown performing the operations of the messaging flow 500, some aspects of some operations may also be performed by other entities of the messaging flow 500 or by entities that are not shown in the messaging flow 500, or any combination thereof.
- Messaging flow 500 may be similar in aspects to messaging flow 300.
- the loT server 210 stores or is aware of all associated loT devices, including the loT device 220, via stored device identifiers.
- the loT device 220, to perform operations, may harvest energy, as described herein.
- step 1 the loT device 220 initiates setup procedure to establish a security association with the loT server 210.
- the loT device 220 generates a nonce, as described herein.
- the loT server 210 receives the initial registration request from the loT server 210.
- the loT device 220 computes or otherwise determines the encryption key K and temporary ID as described herein, such as via a hash of the device ID and the nonce (and, optionally, the length of the nonce and/or a root key).
- the loT server 210 selects a corresponding profile to the temporary device ID (when available), selects all unregistered devices belonging to an indicated category (e.g., one by one), or selects all unregistered devices.
- the loT device 220 computes or otherwise determines the temporary ID. For example, the loT device 220 encrypts the device ID with the key K or uses the temporary identifier when the key K is a truncated hash. The loT device 220 compares the determined temporary ID with the received temporary ID, and when the compared temporary IDs match, the loT device 220 confirms determines it was successfully targeted by the loT server 210 and can send a result of the comparison to the loT server 210.
- the loT server 210 repeats the computation until the computed temporary ID corresponds to the received temporary ID.
- the loT device associated with a match of temporary IDs is then registered to the loT server 210.
- step 5 the loT server 210 transmits an initial registration response message with a result of the comparison of the temporary IDs, as well as the temporary ID. Based on information received via the request message, the loT server 210 may transmits additional information to set up a security association (e.g., use of a stronger key) to exchange information using confidentiality protection.
- a security association e.g., use of a stronger key
- a sender may initiate a key refresh at any time, such as by computing a new nonce, a new temporary ID2, and a new encryption key K2.
- the sender transmits the new nonce to the receiver (e.g., the other of the loT device 220 or the loT server 210), encrypted with the old encryption Key K, using the old temporary ID to address the receiver.
- the receiver decrypts the nonce2 and computes the new temporary ID2 and encryption key K2, using the decrypted nonce2.
- the receiver then sends the response message using the new temporary ID2 and potential message encryption with the new encryption key K2.
- the sender and/or the receiver may use additional input parameters, and, optionally, lengths of the parameters, as input to the hash function or the KDF.
- These parameters may include timers, counters, additional nonces, random numbers, device specific parameters, and so on.
- FIG. 6 illustrates an example of a UE 600 in accordance with aspects of the present disclosure.
- the UE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608.
- the processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
- the processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations or components thereof may be implemented in hardware (e.g., circuitry).
- the hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
- DSP digital signal processor
- ASIC application-specific integrated circuit
- the processor 602 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 602 may be configured to operate the memory 604. In some other implementations, the memory 604 may be integrated into the processor 602. The processor 602 may be configured to execute computer-readable instructions stored in the memory 604 to cause the UE 600 to perform various functions of the present disclosure.
- an intelligent hardware device e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof.
- the processor 602 may be configured to operate the memory 604. In some other implementations, the memory 604 may be integrated into the processor 602.
- the processor 602 may be configured to execute computer-readable instructions stored in the memory 604 to cause the UE 600 to perform various functions of the present disclosure.
- the memory 604 may include volatile or non-volatile memory.
- the memory 604 may store computer-readable, computer-executable code including instructions when executed by the processor 602 cause the UE 600 to perform various functions described herein.
- the code may be stored in a non-transitory computer-readable medium such the memory 604 or another type of memory.
- Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
- a non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
- the processor 602 and the memory 604 coupled with the processor 602 may be configured to cause the UE 600 to perform one or more of the functions described herein (e.g., executing, by the processor 602, instructions stored in the memory 604).
- the processor 602 may support wireless communication at the UE 600 in accordance with examples as disclosed herein.
- the UE 600 may be configured to support a means for generating a temporary identifier that is based on a nonce and a device identifier for the UE and transmitting a registration request message that includes the nonce and the temporary identifier to a network entity.
- the UE 600 may include at least one transceiver 608. In some other implementations, the UE 600 may have more than one transceiver 608.
- the transceiver 608 may represent a wireless transceiver.
- the transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.
- a receiver chain 610 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium.
- the receiver chain 610 may include one or more antennas for receive the signal over the air or wireless medium.
- the receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal.
- the receiver chain 610 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal.
- the receiver chain 610 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
- a transmitter chain 612 may be configured to generate and transmit signals (e.g., control information, data, packets).
- the transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium.
- the at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM).
- the transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium.
- the transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
- FIG. 7 illustrates an example of a processor 700 in accordance with aspects of the present disclosure.
- the processor 700 may be an example of a processor configured to perform various operations in accordance with examples as described herein.
- the processor 700 may include a controller 702 configured to perform various operations in accordance with examples as described herein.
- the processor 700 may optionally include at least one memory 704, which may be, for example, an L1/L2/L3 cache. Additionally, or alternatively, the processor 700 may optionally include one or more arithmetic-logic units (ALUs) 706.
- ALUs arithmetic-logic units
- One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
- the processor 700 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein.
- a protocol stack e.g., a software stack
- operations e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading
- the processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 700) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
- RAM random access memory
- ROM read-only memory
- DRAM dynamic RAM
- SDRAM synchronous dynamic RAM
- SRAM static RAM
- FeRAM ferroelectric RAM
- MRAM magnetic RAM
- RRAM resistive RAM
- flash memory phase change memory
- PCM phase change memory
- the controller 702 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein.
- the controller 702 may operate as a control unit of the processor 700, generating control signals that manage the operation of various components of the processor 700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
- the controller 702 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 704 and determine subsequent instruction(s) to be executed to cause the processor 700 to support various operations in accordance with examples as described herein.
- the controller 702 may be configured to track memory address of instructions associated with the memory 704.
- the controller 702 may be configured to decode instructions to determine the operation to be performed and the operands involved.
- the controller 702 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein.
- the controller 702 may be configured to manage flow of data within the processor 700.
- the controller 702 may be configured to control transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 700.
- ALUs arithmetic logic units
- the memory 704 may include one or more caches (e.g., memory local to or included in the processor 700 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 704 may reside within or on a processor chipset (e.g., local to the processor 700). In some other implementations, the memory 704 may reside external to the processor chipset (e.g., remote to the processor 700).
- caches e.g., memory local to or included in the processor 700 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc.
- the memory 704 may reside within or on a processor chipset (e.g., local to the processor 700). In some other implementations, the memory 704 may reside external to the processor chipset (e.g., remote to the processor 700).
- the memory 704 may store computer-readable, computer-executable code including instructions that, when executed by the processor 700, cause the processor 700 to perform various functions described herein.
- the code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory.
- the controller 702 and/or the processor 700 may be configured to execute computer-readable instructions stored in the memory 704 to cause the processor 700 to perform various functions.
- the processor 700 and/or the controller 702 may be coupled with or to the memory 704, the processor 700, the controller 702, and the memory 704 may be configured to perform various functions described herein.
- the processor 700 may include multiple processors and the memory 704 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
- the one or more ALUs 706 may be configured to support various operations in accordance with examples as described herein.
- the one or more ALUs 706 may reside within or on a processor chipset (e.g., the processor 700).
- the one or more ALUs 706 may reside external to the processor chipset (e.g., the processor 700).
- One or more ALUs 706 may perform one or more computations such as addition, subtraction, multiplication, and division on data.
- one or more ALUs 706 may receive input operands and an operation code, which determines an operation to be executed.
- One or more ALUs 706 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 706 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not- AND (NAND), enabling the one or more ALUs 706 to handle conditional operations, comparisons, and bitwise operations.
- logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not- AND (NAND)
- the processor 700 may support wireless communication in accordance with examples as disclosed herein.
- the processor 700 may be configured to or operable to support a means for generating an output hash based on a nonce and a device identifier for a UE, generating a temporary identifier that is based on the nonce and the device identifier, and transmitting a registration request message that includes the nonce and the temporary identifier to a network entity.
- the processor 700 may be also configured to support a means for receiving a registration request from a network server that includes a nonce and a temporary identifier, comparing the temporary identifier received via the registration request and the generated temporary identifier, and when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmitting a response message to the network server that indicates the match of the temporary identifier and the generated temporary identifier
- Figure 8 illustrates an example of a NE 800 in accordance with aspects of the present disclosure.
- the NE 800 may include a processor 802, a memory 804, a controller 806, and a transceiver 808.
- the processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
- the processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations or components thereof may be implemented in hardware (e.g., circuitry).
- the hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
- DSP digital signal processor
- ASIC application-specific integrated circuit
- the processor 802 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 802 may be configured to operate the memory 804. In some other implementations, the memory 804 may be integrated into the processor 802. The processor 802 may be configured to execute computer-readable instructions stored in the memory 804 to cause the NE 800 to perform various functions of the present disclosure.
- an intelligent hardware device e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof.
- the processor 802 may be configured to operate the memory 804. In some other implementations, the memory 804 may be integrated into the processor 802.
- the processor 802 may be configured to execute computer-readable instructions stored in the memory 804 to cause the NE 800 to perform various functions of the present disclosure.
- the memory 804 may include volatile or non-volatile memory.
- the memory 804 may store computer-readable, computer-executable code including instructions when executed by the processor 802 cause the NE 800 to perform various functions described herein.
- the code may be stored in a non-transitory computer-readable medium such the memory 804 or another type of memory.
- Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
- a non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
- the processor 802 and the memory 804 coupled with the processor 802 may be configured to cause the NE 800 to perform one or more of the functions described herein (e.g., executing, by the processor 802, instructions stored in the memory 804).
- the processor 802 may support wireless communication at the NE 800 in accordance with examples as disclosed herein.
- the NE 800 may be configured to support a means for selecting a UE that is unregistered with the network entity, generating a nonce based on a device identifier for the selected UE and also generate a temporary identifier that is based the nonce and the device identifier, and transmitting a registration request message that includes the nonce and the temporary identifier to the selected UE for registering with the network entity.
- the controller 806 may manage input and output signals for the NE 800.
- the controller 806 may also manage peripherals not integrated into the NE 800.
- the controller 806 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems.
- the controller 806 may be implemented as part of the processor 802.
- the NE 800 may include at least one transceiver 808. In some other implementations, the NE 800 may have more than one transceiver 808.
- the transceiver 808 may represent a wireless transceiver.
- the transceiver 808 may include one or more receiver chains 810, one or more transmitter chains 812, or a combination thereof.
- a receiver chain 810 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium.
- the receiver chain 810 may include one or more antennas for receive the signal over the air or wireless medium.
- the receiver chain 810 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal.
- the receiver chain 810 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal.
- the receiver chain 810 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
- a transmitter chain 812 may be configured to generate and transmit signals (e.g., control information, data, packets).
- the transmitter chain 812 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium.
- the at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM).
- the transmitter chain 812 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium.
- the transmitter chain 812 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
- Figure 9 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
- the operations of the method may be implemented by a UE as described herein.
- the UE may execute a set of instructions to control the function elements of the UE to perform the described functions.
- the method may include generating a temporary identifier that is based on a nonce and a device identifier of the UE.
- the operations of 902 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 902 may be performed by a UE as described with reference to Figure 6.
- the method may include transmitting a registration request message that includes the nonce and the temporary identifier to a network entity.
- the operations of 904 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 904 may be performed a UE as described with reference to Figure 6.
- Figure 10 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
- the operations of the method may be implemented by a NE as described herein.
- the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
- the method may include selecting a UE that is unregistered with the network entity.
- the operations of 1002 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1002 may be performed by a NE as described with reference to Figure 8.
- the method may include generating a nonce based on a device identifier for the selected UE and also generate a temporary identifier that is based on the nonce and the device identifier.
- the operations of 1004 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1004 may be performed by a NE as described with reference to Figure 8.
- the method may include transmitting a registration request message that includes the nonce and the temporary identifier to the selected UE for registering with the network entity.
- the operations of 1006 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1006 may be performed by a NE as described with reference to Figure 8.
- FIG. 11 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
- the operations of the method may be implemented by a UE as described herein.
- the UE may execute a set of instructions to control the function elements of the UE to perform the described functions.
- the method may include receiving a registration request from a network server that includes a nonce and a temporary identifier.
- the operations of 1102 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1102 may be performed by a UE as described with reference to Figure 6.
- the method may include generating an output hash using a device identifier associated with the processor and the nonce from the registration request.
- the operations of 1104 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1104 may be performed by a UE as described with reference to Figure 6.
- the method may include generating a temporary identifier using the output hash of a device identifier associated with the processor and the nonce from the registration request.
- the operations of 1106 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1106 may be performed by a UE as described with reference to Figure 6.
- the method may include comparing the temporary identifier received via the registration request and the generated temporary identifier.
- the operations of 1108 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1108 may be performed by a UE as described with reference to Figure 6.
- the method may include, when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmitting a response message to the network server that indicates the match of the temporary identifier and the generated temporary identifier.
- the operations of 1110 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1110 may be performed by a UE as described with reference to Figure 6.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US202363580177P | 2023-09-01 | 2023-09-01 | |
| US63/580,177 | 2023-09-01 | ||
| US18/819,763 US20250081140A1 (en) | 2023-09-01 | 2024-08-29 | Confidentiality and privacy protection of messages from restricted devices |
| US18/819,763 | 2024-08-29 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024257073A1 true WO2024257073A1 (en) | 2024-12-19 |
Family
ID=92926308
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/IB2024/058470 Pending WO2024257073A1 (en) | 2023-09-01 | 2024-08-30 | Confidentiality and privacy protection of messages from restricted devices |
Country Status (2)
| Country | Link |
|---|---|
| US (1) | US20250081140A1 (en) |
| WO (1) | WO2024257073A1 (en) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013126759A2 (en) * | 2012-02-22 | 2013-08-29 | Qualcomm Incorporated | Preserving security by synchronizing a nonce or counter between systems |
| EP3439344A1 (en) * | 2017-08-03 | 2019-02-06 | Nokia Technologies Oy | Registering user equipment to a visited public land mobile network |
| WO2019112923A1 (en) * | 2017-12-04 | 2019-06-13 | Conviada Wireless, Llc | Improving security via automated sideband communication for m2m/iot |
| WO2020171977A1 (en) * | 2019-02-19 | 2020-08-27 | Microsoft Technology Licensing, Llc | Privacy-enhanced method for linking an esim profile |
| WO2021041279A1 (en) * | 2019-08-23 | 2021-03-04 | Noodle Technology Inc. | Anonymization and randomization of device identities |
-
2024
- 2024-08-29 US US18/819,763 patent/US20250081140A1/en active Pending
- 2024-08-30 WO PCT/IB2024/058470 patent/WO2024257073A1/en active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013126759A2 (en) * | 2012-02-22 | 2013-08-29 | Qualcomm Incorporated | Preserving security by synchronizing a nonce or counter between systems |
| EP3439344A1 (en) * | 2017-08-03 | 2019-02-06 | Nokia Technologies Oy | Registering user equipment to a visited public land mobile network |
| WO2019112923A1 (en) * | 2017-12-04 | 2019-06-13 | Conviada Wireless, Llc | Improving security via automated sideband communication for m2m/iot |
| WO2020171977A1 (en) * | 2019-02-19 | 2020-08-27 | Microsoft Technology Licensing, Llc | Privacy-enhanced method for linking an esim profile |
| WO2021041279A1 (en) * | 2019-08-23 | 2021-03-04 | Noodle Technology Inc. | Anonymization and randomization of device identities |
Also Published As
| Publication number | Publication date |
|---|---|
| US20250081140A1 (en) | 2025-03-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113016202B (en) | Apparatus, method and computer-readable storage medium for base station | |
| CN117544947A (en) | Communication method, device and readable storage medium | |
| US20250225218A1 (en) | Communication method and apparatus | |
| US20250112780A1 (en) | User equipment parameter update header protection | |
| US20250081140A1 (en) | Confidentiality and privacy protection of messages from restricted devices | |
| WO2024245615A1 (en) | Data session establishment in a wireless communication network | |
| EP4723686A1 (en) | Authentication method, and device | |
| US20250350935A1 (en) | Secure transmission of commands to restricted devices | |
| US20250233728A1 (en) | Authenticated encryption with associated data (aead) modes for non-access stratum (nas) and access stratum (as) security | |
| US20250234252A1 (en) | Authenticated encryption with associated data (aead) modes during mobility scenarios | |
| US20260128876A1 (en) | Synchronizing devices based on a sequence number or key mismatch | |
| US20250350939A1 (en) | Authentication and connection establishment for reduced capability devices | |
| US20260129438A1 (en) | Synchronizing devices based on a temporary id mismatch | |
| US20250159581A1 (en) | Ambient internet of things (iot) device integration | |
| US20260032713A1 (en) | Indicating identity type to ambient internet of things (aiot) devices | |
| WO2025229237A1 (en) | Subscription identity concealment in a wireless communication system | |
| US20250365150A1 (en) | Attribute-based credentials for resource access | |
| US20250344265A1 (en) | Apparatus and Method for Establishing a Direct Communication Connection to a Network Via an Access Point of a Different Network Type | |
| US20250344231A1 (en) | Internet of things inventory procedures | |
| US20250365576A1 (en) | Attribute-based credentials for resource access | |
| US20250358869A1 (en) | Selecting subsets of wireless devices | |
| WO2025123706A1 (en) | Methods and apparatuses for supporting multiple accesses of ue to core network | |
| WO2026051374A1 (en) | Method and apparatus of supporting wireless communications based on split radio access network (ran) architecture | |
| WO2025120623A1 (en) | Introduction of enhanced level of security (e.g. 256-bit) to a network and/or various network entities | |
| US20260025242A1 (en) | Group frequency hopping of ambient internet of things (aiot) devices |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24782349 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202617016346 Country of ref document: IN |
|
| REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112026004351 Country of ref document: BR |
|
| WWP | Wipo information: published in national office |
Ref document number: 202617016346 Country of ref document: IN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024782349 Country of ref document: EP |