IP Library Patent Application 18661345
Patent Application
App. No. 18/661,345

AUTHENTICATION AND CONNECTION ESTABLISHMENT FOR REDUCED CAPABILITY DEVICES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/661,345
Abstract

Various aspects of the present disclosure relate to authentication and connection establishment for reduced capability devices. An apparatus, such as an ambient internet of things (AIoT) device, receives a broadcast message from a reader function of a network. The AIoT device performs an authentication procedure with a server function of the network using the reader function and a network function of the network. The authentication procedure utilizes an extensible authentication protocol (EAP) authentication and key agreement prime (EAP-AKA′) authentication method. Based on the authentication procedure, the AIoT device derives an access network security key and uses the access network security key to establish a secure connection with the reader function or the network function. An application function (AF) may subscribe to registration of new AIoT devices. The AF may receive one or more parameters associated with the AIoT device after the AIoT device successfully authenticates and connects to the network.

Claims (51)

1 . A device for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the device to:

receive, from a reader function, a first message comprising a broadcast message;

perform an authentication procedure with a server function using, at least in part, the reader function and a network function, wherein the authentication procedure utilizes an extensible authentication protocol (EAP) authentication and key agreement prime (EAP-AKA′) authentication method based at least in part on the device being associated with an ambient internet of things (AIoT) access type;

derive, as a result of the authentication procedure, an access network security key; and

establish, using the access network security key, a secure connection with the reader function or the network function.

2 . The device of claim 1 , wherein the device comprises an AIoT device that includes a universal subscriber identity module (USIM).

3 . The device of claim 1 , wherein:

the reader function comprises an AIoT reader;

the network function comprises an AIoT function; and

the server function comprises an authentication server function (AUSF).

4 . The device of claim 1 , wherein the first message comprises at least one of an identity request message broadcast by the reader function or an indication of an address of the network function.

5 . The device of claim 1 , wherein to perform the authentication procedure, the at least one processor is configured to cause the device to transmit a second message indicating at least one of a unique AIoT identifier associated with the device or an electronic product code associated with the device.

6 . The device of claim 5 , wherein the second message comprises an Internet key exchange (IKE) message or an EAP identity response message.

7 . The device of claim 5 , wherein the at least one processor is configured to cause the device to receive, from the network function and based at least in part on transmitting the second message, a third message indicating a successful result of the authentication procedure, and wherein the access network security key is derived using one or more of a subscription permanent identifier (SUPI), a global phone subscription identifier (GPSI), or the unique AIoT identifier associated with the device.

8 . The device of claim 5 , wherein the at least one processor is configured to cause the device to receive, from the reader function and based at least in part on transmitting the second message, a third message indicating at least one of a subscription permanent identifier (SUPI) or a global phone subscription identifier (GPSI), and wherein the access network security key is derived using one or more of the SUPI, the GPSI, or the unique AIoT identifier associated with the device.

9 . The device of claim 1 , wherein the secure connection comprises an internet protocol security (IPSec) security association (IPSec SA) between the device and the network function.

10 . The device of claim 1 , wherein:

the network function comprises a trusted wireless local-area network (WLAN) interworking function; and

the secure connection comprises a secure Layer 2 (L2) connection between the device and the network function.

11 . The device of claim 1 , wherein:

the reader function comprises a trusted wireless local-area network (WLAN) interworking function; and

the secure connection comprises a secure Layer 2 (L2) connection between the device and the reader function.

12 . A processor for wireless communication, comprising:

at least one controller coupled with at least one memory and configured to cause the processor to:

receive, from a reader function, a first message comprising a broadcast message;

perform an authentication procedure with a server function using, at least in part, the reader function and a network function, wherein the authentication procedure utilizes an extensible authentication protocol (EAP) authentication and key agreement prime (EAP-AKA′) authentication method based at least in part on an association with an ambient internet of things (AIoT) access type;

derive, as a result of the authentication procedure, an access network security key; and

establish, using the access network security key, a secure connection with the reader function or the network function.

13 . A method performed by a device, the method comprising:

receiving, from a reader function, a first message comprising a broadcast message;

performing an authentication procedure with a server function using, at least in part, the reader function and a network function, wherein the authentication procedure utilizes an extensible authentication protocol (EAP) authentication and key agreement prime (EAP-AKA′) authentication method based at least in part on the device being associated with an ambient internet of things (AIoT) access type;

deriving, as a result of the authentication procedure, an access network security key; and

establishing, using the access network security key, a secure connection with the reader function or the network function.

14 . The method of claim 13 , wherein the device comprises an AIoT device that includes a universal subscriber identity module (USIM).

15 . The method of claim 13 , wherein:

the reader function comprises an AIoT reader;

the network function comprises an AIoT function; and

the server function comprises an authentication server function (AUSF).

16 . The method of claim 13 , wherein the first message comprises at least one of an identity request message broadcast by the reader function or an indication of an address of the network function.

17 . The method of claim 13 , wherein performing the authentication procedure further comprises:

transmitting a second message indicating at least one of a unique AIoT identifier associated with the device or an electronic product code associated with the device.

18 . A device for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the device to:

transmit, to a network exposure function (NEF), a first message indicating an ambient internet of things (AIoT) access network type;

receive, from the NEF and based at least in part on an authentication procedure for an AIoT device associated with the AIoT access network type, a second message indicating one or more parameters associated with the AIoT device; and

perform communications with the AIoT device based at least in part on the one or more parameters.

19 . The device of claim 18 , wherein the first message includes a subscribe request for authenticated AIoT devices including the AIoT device.

20 . The device of claim 18 , wherein the one or more parameters comprise at least one of a global phone subscription identifier (GPSI) associated with the AIoT device, an electronic product code associated with the AIoT device, or a location of the AIoT device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2024
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 069278/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2024
From: KUNZ, ANDREAS; CHOI, HYUNG-NAM; GANESAN, KARTHIKEYAN; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (UNITED STATES) INC.
Reel/Frame 067649/0818 →