School of Specs Ambient IoT — a tag with no batteryIn depth

The system groups · chapter 8 of 14 · 7 minutes

8 SA3, and why a device with no battery is a hard security problem

What the security group set out to study, the specification it produced, and how far the record actually lets you go on this subject.

8.1 Why this is harder than it looks

Security in a mobile network rests on the device being able to do work: hold a secret, run a calculation, remember what happened last time, and answer within a deadline.

A device budgeted at about a millionth of a watt [3] — one run on harvested energy, with only a capacitor's worth of storage [4] — can be assumed to do very little of that.

It may lose power between one message and the next. It may be one of thousands answering at once. It may be somewhere nobody can ever reach it again.

SA3 said as much in its own objective, which names the constraint explicitly rather than treating security as a bolt-on:

8.2 The study

FS_Ambient_IoT_Sec, unique id 1030031, approved as SP-240506 at plenary SP-103 FS_Ambient_IoT_Sec SP-240506. It finished on 2024-12-12 and stands complete, the same day the radio solutions study finished FS_Ambient_IoT_Sec FS_Ambient_IoT_solutions.

It carries 726 documents, and its report, TR 33.713, carries 708 FS_Ambient_IoT_Sec TR 33.713. That report is the single largest security document in the area, and it is where the threat analysis lives.

SA3 as a group filed 1349 documents across 15 meetings, third behind RAN1 and SA2, and sent 38 letters — joint second with RAN2 SA3 RAN1 SA2 RAN2.

8.3 The specification

The normative work is AmbientIoT-SEC, unique id 1070022, revised as SP-251196 at plenary SP-109 AmbientIoT-SEC SP-251196. It carries 434 documents.

Its output is TS 33.369, and the title is the important part: security aspects of Ambient IoT services for isolated private networks TS 33.369.

That phrase matches the architecture boundary exactly. The scope of TS 23.369 says that in this release the Ambient IoT system is an isolated private network that does not interact with a public network [5]. The security specification was written for that world and says so in its own name.

TS 33.369 carries 385 documents and 150 change requests — after TS 23.369, the second most-changed specification in the whole area TS 33.369 TS 23.369.

8.4 Why security work runs alongside, not after

SA3 did not wait for the architecture to be finished. Its study opened at plenary SP-103 in March 2024 SP-240506 while SA2's architecture study was still running, and finished a few months after it FS_AmbientIoT FS_Ambient_IoT_Sec.

That overlap is deliberate and it shows in the coordination. SA2's own work item description names SA3 as responsible for the security aspects, and SA3's names SA2 as responsible for the architecture — each defers to the other rather than waiting AmbientIoT-ARC AmbientIoT-SEC.

The letters follow the same pattern. SA3 sent 38 of the area's 351 letters between groups [6], joint second, which is what a group does when it has to keep pace with a design it does not control SA3.

8.5 What the record will and will not tell you

This is the chapter where the honest answer matters most, because security is the subject readers most want detail on.

What the data holds is paperwork: which study ran, which work item followed, which specification came out, how many documents and change requests each took, and the objective sentences quoted above. That is all cited on this page.

What the data does not hold is any of the following, and no amount of reading the register will produce it:

  • N1. Which threats were found. The threat analysis is inside TR 33.713 and this school does not carry its text TR 33.713.

  • N2. Which mechanisms were chosen. Those are inside TS 33.369 TS 33.369.

  • N3. Why any group decided anything. The data records a document's outcome word — approved, agreed, revised, noted, merged, withdrawn — and nothing about the reasoning SP-240506.

The fix, in every case, is the same: the register carries each document's own address on 3gpp.org, and the answer is in the document.

8.6 The size of the security effort

It is worth stating plainly how much work this was, because "security aspects" sounds like an appendix and was not one.

SA3 filed 1349 documents — more than RAN2, more than RAN3, more than RAN4 SA3 RAN2 RAN3 RAN4. Its two reports carry 708 and 216 documents, and its one specification 385 TR 33.713 TR 33.714 TS 33.369.

Only two groups in the whole area filed more, and both of them were designing the thing itself rather than securing it RAN1 SA2.

8.7 Phase two

SA3 ran a second study, FS_AIoT_SEC_Ph2, unique id 1090025, opened as SP-251246 at plenary SP-109 FS_AIoT_SEC_Ph2 SP-251246. It finished 2026-06-06, stands complete, and its report is TR 33.714 with 216 documents against it TR 33.714.

Its work tasks name their subject in the documents' own vocabulary:

Three terms in there — "Topology 2", "AIoT device Type 1", "DO-A Capable" — are names, and this course does not explain them, because the register carries the names and not their definitions. Guessing at them would be the exact mistake this school exists to avoid.

The normative phase 2 security work, AmbientIoT_Ph2-SEC, unique id 1120091, opened as SP-260665 at plenary SP-112 and has filed nothing yet AmbientIoT_Ph2-SEC SP-260665.

It declares TS 33.340 impacted. The catalogue on this machine holds no title, no owning group and no status for that number, so this course says nothing about what it is for 33.340.

8.8 What SA3 was still asking in mid-2026

Two letters from SA3 at meeting S3-128, both approved in May 2026, show the questions still open:

  • S3-262519 S3-262519 — a reply on filtering information in the inventory procedure.

  • S3-262517 S3-262517 — a reply on device context invalidity.

Their titles are all this record carries. What either letter said is not held on this machine in any form this register touched, and the fix is to open them from their addresses on 3gpp.org.

8.9 Where to read on

Two documents, in this order, and this school holds the text of neither:

  • TR 33.713 TR 33.713 — the phase 1 security study. Read this first; it is where the threats and the reasoning are.

  • TS 33.369 TS 33.369 — the binding security specification for isolated private networks.

Then TR 33.714 TR 33.714 for where phase 2 went. The architecture these three sit on is SA2 and the specification that did not exist; the protocols that carry them are CT1, CT3, CT4 and CT6 — one work item description, four groups.

Where the numbers in this chapter come from

  1. what the security study set out to do the first two sentences of section 4 of /var/www/whatthespec.net/data/data/wis/1030031/SP-240506 was SP-240237 SID on Ambient IoT Security/SP-240506 was SP-240237 SID on Ambient IoT Security.md, copied word for word, read 2026-08-04
  2. what the phase 2 security study set out to do the first two sentences of section 4 of /var/www/whatthespec.net/data/data/wis/1090025/SP-251246 AIoT Security SID/SP-251246 AIoT Security SID.md, copied word for word, read 2026-08-04
  3. the scope of the RAN solutions study report the first two sentences of clause 1 of the parsed copy of 38.769 version 19.0.0, copied word for word, read 2026-08-04
  4. what an Ambient IoT device is the definition of 'AIoT Device' in clause 3.1 of the parsed copy of 23.369 version 20.0.0, copied word for word, read 2026-08-04
  5. the scope of the architecture specification the first two sentences of clause 1 of the parsed copy of 23.369 version 20.0.0, copied word for word, read 2026-08-04
  6. 351 Ambient IoT documents of type LS out Ambient IoT rows of `tdoc` whose type column is 'LS out', read 2026-08-04

Every source this course is built on

Check yourself

Answers appear when you pick one, with where they come from.

Q8.1 What does SA3's study say it set out to identify?

Q8.2 What is TS 33.369 about, by its own title?

Q8.3 SA3's Rel-19 normative work stands at 95 per cent against a target finish that has passed. What does that mean?

Q8.4 Which two reports hold SA3's thinking?

Q8.5 The phase 2 security work item names TS 33.340 as impacted. What can this course say about that document?

This chapter was built from a source register generated 2026-08-04. A fresher build of the register may hold different numbers.