IP Library › Patent Application 18819763
Patent Application
App. No. 18/819,763

CONFIDENTIALITY AND PRIVACY PROTECTION OF MESSAGES FROM RESTRICTED DEVICES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/819,763
Abstract

Various aspects of the present disclosure relate to performing confidentiality and/or privacy protection for communications between devices, such as ambient energy-powered devices. In some cases, the IoT devices and/or IoT servers can perform key generation using secret parameters that are only known to the devices/servers as input into a hash function. For example, the IoT server and IoT device can utilize a device identifier as a secret parameter, which is input, along with a nonce, into hash operations or functions to generate security keys (e.g., a key K). In some cases, key generation can include time information or other similar information to ensure freshness of the security K during generation.

Claims (52)

1 . A network entity for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the network entity to:

select a user equipment (UE) that is unregistered with the network entity;

generate a nonce based on a device identifier for the selected UE and also generate a temporary identifier that is based on the nonce and the device identifier; and

transmit a registration request message that includes the nonce and the temporary identifier to the selected UE for registering with the network entity.

2 . The network entity of claim 1 , wherein the at least one processor is further configured to cause the network entity to:

receive, from the selected UE, a response message that includes the temporary identifier and an indication of a match of the temporary identifier as received from the network entity and a corresponding temporary identifier as stored in the selected UE.

3 . The network entity of claim 2 , wherein the at least one processor is further configured to cause the network entity to:

register the selected UE in response to the match of the temporary identifier generated by the network entity and the corresponding temporary identifier stored by the selected UE.

4 . The network entity of claim 1 , wherein the at least one processor is further configured to cause the network entity to:

generate a hash based on the nonce and the device identifier; and

truncate the hash to generate a security key K for encrypting the device identifier to derive the temporary identifier,

wherein the temporary identifier corresponds to remaining bits of the hash.

5 . The network entity of claim 4 , wherein the at least one processor is further configured to cause the network entity to:

receive, from the selected UE, a response message that includes the temporary identifier, an indication of a match of the temporary identifier as received from the network entity and a corresponding temporary identifier as stored in the selected UE, and one or more parameters encrypted by the security key K; and

decrypt the one or more parameters using the security key K.

6 . The network entity of claim 1 , wherein the network entity is an Internet of Things (IoT) server and the UE is an ambient energy powered IoT device.

7 . The network entity of claim 1 , wherein the at least one processor is configured to cause the network entity to generate the hash using the nonce and the device identifier.

8 . The network entity of claim 1 , wherein the at least one processor is configured to cause the network entity to generate the hash using the nonce, the device identifier, a length of the nonce, and a root key.

9 . The network entity of claim 8 , wherein the at least one processor is configured to cause the network entity to generate the hash as an output of a hash function using one or more parameters, including the device identifier, a random number, or time information.

10 . The network entity of claim 9 , wherein the nonce is a truncated output of the hash function.

11 . The network entity of claim 8 , wherein the at least one processor is configured to cause the network entity to generate the hash using based on one or more parameters, including a random number, time information, a timer, a counter, or an additional nonce.

12 . The network entity of claim 1 , wherein the hash includes:

most significant bits that represent the temporary identifier; and

least significant bits that represent a security key K.

13 . The network entity of claim 1 , wherein the hash includes:

least significant bits that represent the temporary identifier; and

most significant bits that represent a security key K.

14 . A user equipment (UE) for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the UE to:

generate a temporary identifier that is based on a nonce and a device identifier of the UE; and

transmit a registration request message that includes the nonce and the temporary identifier to a network entity.

15 . The UE of claim 14 , wherein the at least one processor is further configured to cause the UE to:

receive, from the network entity, a response message that includes the temporary identifier.

16 . The UE of claim 14 , wherein the temporary identifier is a truncated portion of an output hash based on the nonce and the device identifier.

17 . The UE of claim 14 , wherein the at least one processor is configured to cause the UE to generate a security key K for encrypting the device identifier to derive the temporary identifier.

18 . A processor for wireless communication, comprising:

at least one controller coupled with at least one memory and configured to cause the processor to:

receive a registration request from a network server that includes a nonce and a temporary identifier;

compare the temporary identifier received via the registration request and the generated temporary identifier; and

when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmit a response message to the network server that indicates the match of the temporary identifier and the generated temporary identifier.

19 . The processor of claim 18 , wherein the at least one controller is further configured to cause the processor to:

generate an output hash using a device identifier associated with the processor and the nonce from the registration request; and

generate a temporary identifier using the output hash of the device identifier associated with the processor and the nonce from the registration request.

20 . A method performed by an IoT (Internet of Things) device, the method comprising:

receiving a registration request from a network server that includes a nonce and a temporary identifier;

generating an output hash using a device identifier for the IoT device and the nonce from the registration request;

generating a temporary identifier using the device identifier for the IoT device and the nonce from the registration request;

comparing the temporary identifier received via the registration request and the generated temporary identifier; and

when the comparison indicates a match of the temporary identifier received via the registration request and the generated temporary identifier, transmitting a response message to the network server that indicates the match of the temporary identifier and the generated temporary identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2024
From: KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (SINGAPORE) PTE LIMITED
Reel/Frame 068454/0319 →