Protection for discovery messasge

By identifying and protecting discovery messages based on network identity presence, the method addresses inefficiencies and power consumption issues in communication networks, enhancing decryption accuracy and reducing unnecessary processing.

WO2025236291A1PCT designated stage Publication Date: 2025-11-20ALCATEL LUCENT SHANGHAI BELL CO LTD +2
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/094019
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-17
Publication Date
2025-11-20

AI Technical Summary

Technical Problem

Existing communication networks face inefficiencies and high power consumption due to the need for multiple attempts to decrypt discovery messages with incorrect keys when the network identity is scrambled and encrypted, as per current security solutions in SA3 technical specifications.

Method used

A method for protecting discovery messages by determining the presence of a network identity within the message, allowing for targeted encryption and scrambling operations, thereby reducing unnecessary decryption attempts and enhancing communication efficiency.

Benefits of technology

This approach improves communication efficiency and reduces power consumption by ensuring correct decryption and scrambling processes, optimizing network operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024094019_20112025_PF_FP_ABST
    Figure CN2024094019_20112025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to protection for a discovery message. In one aspect, a first terminal device receives a discovery message from a second terminal device, and the discovery message comprises an indication of whether a network identity is comprised in the discovery message. Based on determining that the indication indicates that the network identity is comprised in the discovery message, the first terminal device obtains the network identity. In this way, the first terminal device will not try to decrypt the discovery message with multiple "assumed" but "wrong" keys which most likely would be failed finally and would be very time and energy consuming. Therefore, the communication efficiency of the discovery message can be improved and the power consumption of the first terminal device can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

PROTECTION FOR DISCOVERY MESSASGEFIELD

[0001] Various example embodiments relate to the field of communication and in particular, to devices, methods, apparatuses and a computer readable storage medium for a protection for a discovery message.BACKGROUND

[0002] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network.

[0003] Such communication networks operate in accordance with standards, such as those promulgated by Third Generation Partnership Project (3GPP) or European Telecommunications Standards Institute (ETSI) . Examples of such standards include the so-called 5th generation (5G) standard or other standards promulgated by 3GPP.SUMMARY

[0004] In general, example embodiments of the present disclosure provide a solution for protection for a discovery message, especially for supporting selective protection for a PC5 discovery message.

[0005] In a first aspect, there is provided a first terminal device. The first terminal device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first terminal device at least to: receive a discovery message from a second terminal device, and the discovery message comprises an indication of whether a network identity is comprised in the discovery message; and obtain the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.

[0006] In a second aspect, there is provided a second terminal device. The second terminal device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second terminal device at least to: perform a protection operation for a discovery message based on whether the discovery  message comprises a network identity; and transmit the discovery message to a first terminal device, and the discovery message comprises an indication of whether the network identity is comprised in the discovery message.

[0007] In a third aspect, there is provided a method at a first terminal device. The method comprises receiving a discovery message from a second terminal device, and the discovery message comprises an indication of whether a network identity is comprised in the discovery message; and obtaining the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.

[0008] In a fourth aspect, there is provided a method at a second terminal device. The method comprises performing a protection operation for a discovery message based on whether the discovery message comprises a network identity; and transmitting the discovery message to a first terminal device, and the discovery message comprises an indication of whether the network identity is comprised in the discovery message.

[0009] In a fifth aspect, there is provided an apparatus of first terminal device. The apparatus comprises means for receiving a discovery message from a second terminal device, and the discovery message comprises an indication of whether a network identity is comprised in the discovery message; and means for obtaining the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.

[0010] In a sixth aspect, there is provided an apparatus of second terminal device. The apparatus comprises means for performing a protection operation for a discovery message based on whether the discovery message comprises a network identity; and means for transmitting the discovery message to a first terminal device, and the discovery message comprises an indication of whether the network identity is comprised in the discovery message.

[0011] In a seventh aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the method according to any one of the above third to fourth aspect.

[0012] In an eighth aspect, there is provided a computer program comprising instructions, which, when executed by an apparatus, cause the apparatus at least to perform at least the method according to any one of the above third to fourth aspect.

[0013] In a ninth aspect, there is provided a first terminal device. The first terminal device  comprises receiving circuitry configured to receive a discovery message from a second terminal device, and the discovery message comprises an indication of whether a network identity is comprised in the discovery message; and obtaining circuitry configured to obtain the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.

[0014] In a tenth aspect, there is provided a second terminal device. The second terminal device comprises performing circuitry configured to perform a protection operation for a discovery message based on whether the discovery message comprises a network identity; and transmitting circuitry configured to transmit the discovery message to a first terminal device, and the discovery message comprises an indication of whether the network identity is comprised in the discovery message.

[0015] It is to be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of example embodiments of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Some example embodiments will now be described with reference to the accompanying drawings, in which:

[0017] Fig. 1A illustrates an example network environment in which example embodiments of the present disclosure may be implemented;

[0018] Fig. 1B illustrates an example of encrypted and scrambled IEs in ProSe U2N relay discovery announcing message;

[0019] Fig. 1C illustrates an example of encrypted and scrambled IEs in ProSe U2N relay discovery announcing message comprising the HPLMN ID;

[0020] Fig. 2 illustrates an example signaling chart illustrating an example process according to some embodiments of the present disclosure;

[0021] Fig. 3 illustrates a flowchart of a method implemented at a first terminal device according to some example embodiments of the present disclosure;

[0022] Fig. 4 illustrates a flowchart of a method implemented at a second terminal device according to some example embodiments of the present disclosure;

[0023] Fig. 5 illustrates a simplified block diagram of an apparatus that is suitable for implementing embodiments of the present disclosure; and

[0024] Fig. 6 illustrates a block diagram of an example computer readable medium in accordance with some embodiments of the present disclosure.

[0025] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION

[0026] Principles of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement example embodiments of the present disclosure, without suggesting any limitation as to the scope of the disclosure. The example embodiments of the present disclosure described herein can be implemented in various manners other than the ones described below.

[0027] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.

[0028] References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0029] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0030] The terminology used herein is for the purpose of describing particular embodiments  only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof. As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0031] As used in this application, the term “circuitry” may refer to one or more or all of the following:

[0032] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0033] (b) combinations of hardware circuits and software, such as (as applicable) :

[0034] (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and

[0035] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0036] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0037] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0038] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as long term evolution (LTE) , LTE-advanced (LTE-A) , wideband code division multiple access (WCDMA) , high-speed packet access (HSPA) , narrow band internet of things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the future fifth generation (5G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which example embodiments of the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.

[0039] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP) , for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a new radio (NR) NB (also referred to as a gNB) , a remote radio unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, a low power node such as a femto, a pico, and so forth, depending on the applied terminology and technology.

[0040] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a subscriber station (SS) , a portable subscriber station, a mobile station (MS) , or an access terminal (AT) . The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an internet of things (loT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone,  a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. In the following description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.

[0041] Fig. 1A illustrates an example network environment 100 in which example embodiments of the present disclosure may be implemented. The environment 100, which may be a part of a communication network, comprises terminal devices and network devices.

[0042] As illustrated in Fig. 1A, the communication network 100 may comprise a first terminal device 110 (hereinafter may also be referred to as user equipment 110 or a receiving UE 110) , and a second terminal device 120 (hereinafter may also be referred to as user equipment 120 or a sending UE 120) . The communication network 100 may further comprise a network device 130. The network device 130 can manage a cell 101. One or two of the first terminal device 110 and the second terminal device 120 may located in the coverage of the cell 101. In addition, one or two of the first terminal device 110 and the second terminal device 120 may located outside the coverage of the cell 101. The first terminal device 110 and the second terminal device 120 can communicate with each other via sidelinks without the help of the network device 130. The first terminal device 110 may communicate with the network device 130 indirectly through the second terminal device 120. For example, the second terminal device 120 is connected to network device 130, and the first terminal device 110 may communicate with network device 130 through the second terminal device 120 after discovered related U2N with match discovery message sending by the second terminal device 120. An interface between the first terminal device 110 and the second terminal device 120 is referred to as PC5 interface, and an interface between the first terminal device 110 and the network device 130 is referred to as Uu interface.

[0043] It is to be understood that the number of devices is only for the purpose of illustration without suggesting any limitations. The system 100 may include any suitable number of terminal devices or network devices adapted for implementing embodiments of the present disclosure. Although not shown, it would be appreciated that one or more terminal devices or network devices may be located in the environment 100.

[0044] Communications in the communication system 100 may be implemented according  to any proper communication protocol (s) , comprising, but not limited to, cellular communication protocols of the first generation (1G) , the second generation (2G) , the third generation (3G) , the fourth generation (4G) and the fifth generation (5G) and on the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: code division multiple access (CDMA) , frequency division multiple access (FDMA) , time division multiple access (TDMA) , frequency division duplex (FDD) , time division duplex (TDD) , multiple-input multiple-output (MIMO) , orthogonal frequency division multiple (OFDM) , discrete Fourier transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.

[0045] According to new stage 2 requirements in system aspect 3 (SA3) technical specification (TS) 33.503, a new information element, e.g., a PLMN ID of potential ProSe UE to network (U2N) relay UE, is required to be included in a discovery message (e.g., PROSE PC5 DISCOVERY message) for UE-to-network relay discovery announcement. Fig. 1B illustrates an example of encrypted and scrambled IEs in ProSe U2N relay discovery announcing message. As shown in Fig. 1B, the IEs after UTC-based counter LSB are scrambled and the IEs after MIC (i.e., the payload) are encrypted.

[0046] According to the requirement, the PLMN ID should be in “plain text” , i.e. without encryption and scrambling since the receiver of the discovery message uses this PLMN ID information element (IE) to obtain the proper security material in order to unscramble and decrypt the discovery message. However, the PLMN ID or HPLMN ID is currently not excluded from both the encryption and scrambling operations. Based on security solutions in SA3, as part of announcement information, the PLMN ID or HPLMN ID will be scrambled and probably encrypted as shown in the Fig. 1C, which is not expected because if the PLMN ID or HPLMN ID is scrambled and / or encrypted, the monitoring UE (or a ProSe remote UE) cannot decide which security material / key should be used to un-scramble or decrypt the message. The monitoring UE have to try multiple times, which consumes time and energy.

[0047] According to some embodiments of the present disclosure, a solution is provided for a protection operation for a discovery message. In one aspect of this solution, a first terminal device receives a discovery message from a second terminal device, and the discovery message comprises an indication of whether a network identity is comprised in the discovery  message. Based on determining that the indication indicates that the network identity is comprised in the discovery message, the first terminal device obtains the network identity. In this way, the first terminal device will not try to decrypt the discovery message with multiple “assumed” but “wrong” keys which most likely would be failed finally and would be very time and energy consuming. Therefore, the communication efficiency of the discovery message can be improved and the power consumption of the first terminal device can be reduced. Principles and implementations of embodiments of the present disclosure will be described in detail below with reference to Figs. 2-6.

[0048] Fig. 2 illustrates a signaling chart illustrating an example process 200 according to some embodiments of the present disclosure. For the purpose of discussion, the process 200 will be described with reference to Fig. 1A. The process 200 may involve the first terminal device 110 and the second terminal device 120. It would be appreciated that although the process 200 has been described in the communication environment 100 of Fig. 1A, this process may be likewise applied to other communication scenarios with similar issues.

[0049] In the process 200, the second terminal device 120 performs 210 a protection operation for a discovery message based on whether the discovery message comprises a network identity. In some embodiments, the first terminal device 110 may comprise a monitoring UE, and the first terminal device 110 may also be referred to as a remote UE or a receiving device. The second terminal device 120 may comprise an announcing UE, and the second terminal device 120 may also be referred to as a relay device or a sending device. Additionally, the network identity may comprise a PLMN ID or a HPLMN ID. The protection operation may be associated with three types of security that are used to protect the discovery message (e.g., restricted 5G ProSe direct discovery messages over the PC5 interface) : an integrity protection, a scrambling protection, and message-specific confidentiality.

[0050] In some embodiments, in order to perform the protection operation, the second terminal device 120 may determine a position of the network identity in the discovery message if the discovery message comprises the network identity. Based on the position of the network identity, the second terminal device 120 may encrypt and scramble the discovery message. Due to encryption and scrambling are impacted with each other, the encryption and scrambling need to be considered together.

[0051] The second terminal device 120 receives code-sending security parameters from the direct discovery name management function (DDNMF)  / ProSe key management function  (PKMF) to indicate how to protect the message. The code-sending security parameters may contain a discovery user scrambling key (DUSK) and may contain a discovery user integrity key (DUIK) . The code-sending security parameters may contain both a discovery user confidentiality key (DUCK) and the Encrypted_bits_mask.

[0052] Alternatively or additionally, the position of the network identity may comprise: a first position between a message integrity code (MIC) field and an announcer information field, and the network identity is a mandatory information element (IE) of the payload of the discovery message, a second position as the last IE of the payload of the discovery message, and the network identity is an optional IE of the payload of the discovery message, which is represented as Type, Length and Value (TLV) or Type and Value (TV) while the Type indicates the IE is for PLMN ID or HPLMN ID, a third position between a universal time coordinated (UTC) -based counter field and the MIC field, and the network identity is a mandatory IE of the header of the discovery message, or any combination of two or more of the above-mentioned items. The term header refers to the first three mandatory IEs in discovery message for UE-to-network relay discovery announcement, i.e. (the message type + UTC based counter LSB + MIC) .

[0053] In a first example, if the position of the network identity is the first position, the network identity may be un-encrypted and un-scrambled. Alternatively or additionally, in order to encrypt and scramble the discovery message, the second terminal device 120 may set bits corresponding to the network identity in a mask (e.g., Encrypted_bits_mask) to a first value, perform a first logical operation (e.g., an AND operation) between a keystream and the mask, perform a second logical operation (e.g., an exclusive or operation) between the keystream and the payload of discovery message, set bits corresponding to the network identity in a bit sequence (e.g., time-hash-bitsequence) to the first value , and perform a second logical operation between the bit sequence and the payload of discovery message. Additionally, the first value may comprise 0.

[0054] For instance, the PLMN ID may be put after message headers as a first mandatory IE of the payload (i.e., after MIC and before Announcer Info) , as shown in table 1. The scrambling algorithm may then be enhanced to allow un-scrambled PLMN ID, and the Encrypted_bits_mask may be enhanced to allow un-encrypted PLMN ID.

[0055] Table 1. Put plain text PLMN ID as first mandatory IE

[0056] The “un-E” in table 1 means “un-encrypted” , and “un-S” in table 1 means “un-scrambled” . “E” means “encrypted” , and “S” means “scrambled” . “M” means “mandatory” , and “O” means “optional” .

[0057] The second terminal device 120 may form the discovery message comprising the PLMN ID, and calculate MIC if a DUIK was provided, otherwise set MIC to a 32-bit random string. Then, the second terminal device 120 may set the MIC IE to the MIC. After that, the second terminal device 120 may add message-specific confidentiality to the discovery message if DUCK was received, and add scrambling based on the discovery message with added message-specific confidentiality if the DUSK was received.

[0058] The Encrypted_bits_mask is applicable to the mandatory IEs of payload of the discovery message. The corresponding bits of PLMN ID in the Encrypted_bits_mask may be set to 0, and other bits in the Encrypted_bits_mask may be set to 1. In some example, some bits of the other bits in the Encrypted_bits_mask may also be set to 0.

[0059] For the Message-specific confidentiality protection, the use and mode of operation of the ciphering algorithms are specified. Input parameters to the ciphering algorithms are listed below:

[0060] - KEY: 128 least significant bits of the output of the KDF (DUCK, UTC-based counter, MIC)

[0061] - COUNT is UTC-based counter, BEARER is 0x00

[0062] - DIRECTION: 0x00

[0063] - LENGTH: LEN (discovery message) - (LEN (Message Type) + LEN (UTC-based counter LSB) + LEN (MIC) ) , where LEN (x) is the length of x in number of bits

[0064] KEY is set to as such to generate message-specific keystream. The output keystream of the ciphering algorithm (i.e., output_keystream) is then masked with the Encrytped_bits_mask to produce the final keystream for the message-specific confidentiality protection (i.e., KEYSTREAM) as below:

[0065] KEYSTREAM = output_keystream AND (Encrypted_bits_mask || 0xFF.. FF)

[0066] The KEYSTREAM is XORed with the payload of discovery message (which excludes message type filed, UTC-based counter filed and MIC filed) for message-specific confidentiality protection.

[0067] For the scrambling protection, the second terminal device 120 may set 4 least significant bits (LSBs) of the UTC-based counter equal to zero for the purpose of scrambling calculation. The second terminal device 120 then may compute the time-hash-bitsequence from DUSK and the modified UTC-based counter passed through a keyed hash function (KDF) . The time-hash-bitsequence keystream is set to L least significant bits of the output of the KDF, where L is the bit length of the discovery message to be scrambled and set to Min (the length of discovery message-16, 256) . Min (the length of discovery message-16, 256) is the function used to retrieve the smaller value of the length of discovery message-16 and 256. 16 in the function is the size of message type and UTC-based counter LSB in bit length. The maximum length of the discovery message to be scrambled is limited to 256 bits.

[0068] After that, the second terminal device 120 may update the time-hash-bitsequence to exclude PLMN ID, and perform the exclusive OR (XOR) operation between the updated time-hash-bitsequence with the discovery message excluding message type field, UTC-based counter field and PLMN ID field as below:

[0069] XOR (0xFFFF || (time-hash-bitsequence AND (0xFFFFFFFF || 0x000000 || 0xFF.. FF) with the least significant (L + 16) bits of discovery message

[0070] The PLMN ID may be excluded from scrambling with set corresponding bits of time-hash-bitsequence to “0” . For the second input of AND operation, the first 0xFFFFFFFF represents MIC filed, the following 0x000000 represents PLMN ID filed, the last 0xFF.. FF represents other IEs of the payload.

[0071] In a second example, if the position of the network identity is the first position, the network identity may be un-encrypted and scrambled. Alternatively or additionally, in order to encrypt and scramble the discovery message, the second terminal device 120 may set bits corresponding to the network identity in a mask to a first value, perform a first logical  operation between a keystream and the mask, perform a second logical operation between the keystream and the payload of discovery message and scramble the MIC field and the payload of discovery message comprising the network identity.

[0072] For instance, the PLMN ID may be put after message headers as a first mandatory IE of the payload (i.e., after MIC and before Announcer Info) , as shown in table 2. The Encrypted_bits_mask may be enhanced to allow un-encrypted PLMN ID, and the PLMN ID may be scrambled since less computing process is required to try multiple times of unscrambling.

[0073] Table 2. Put scrabbled but unencrypted HPLMN ID as first mandatory IE

[0074] Some enhancements of Encrypted_bits_mask is the same as in the first example and will not be described again here. The scrambling of the discovery message comprising the PLMN ID is the same as the scrambling of the discovery message which does not comprise the PLMN ID.

[0075] In a third example, if the position of the network identity is the second position, the network identity may be un-encrypted and un-scrambled. Alternatively or additionally, in order to encrypt and scramble the discovery message, the second terminal device 120 may set bits corresponding to the network identity in a keystream to a first value, perform a first logical operation between the keystream and the payload of discovery message, set bits corresponding to the network identity in a bit sequence to a first value, and perform a second logical operation between the bit sequence and the payload of discovery message.

[0076] For instance, the PLMN ID may be put as the last IE of the discovery message which is optional, as shown in table 3. The scrambling algorithm may then be enhanced to allow un-scrambled PLMN ID, and the Encrypted_bits_mask may be enhanced to allow un- encrypted PLMN ID.

[0077] Table 3. Put plain text PLMN ID as the first optional IE

[0078] The form the discovery message and include the PLMN ID as the last IE of the message, which is optional. Then, the second terminal device 120 may calculate MIC if a DUIK was provided, otherwise set MIC to a 32-bit random string. Then, the second terminal device 120 may set the MIC IE to the MIC. After that, the second terminal device 120 may add message-specific confidentiality to the discovery message if DUCK was received, and the PLMN ID is not encrypted. The second terminal device 120 may add scrambling based on the discovery message with added message-specific confidentiality if the DUSK was received, and the PLMN ID is not scrambled.

[0079] For the Message-specific confidentiality protection, the use and mode of operation of the ciphering algorithms are specified. Input parameters to the ciphering algorithms are listed below:

[0080] - KEY: 128 least significant bits of the output of the KDF (DUCK, UTC-based counter, MIC)

[0081] - COUNT is UTC-based counter, BEARER is 0x00

[0082] - DIRECTION: 0x00

[0083] - LENGTH: LEN (discovery message) - (LEN (Message Type) + LEN (UTC-based counter LSB) + LEN (MIC) ) , where LEN (x) is the length of x in number of bits

[0084] KEY is set to as such to generate message-specific keystream. The output keystream of the ciphering algorithm (i.e., output_keystream) is then masked with the Encrytped_bits_mask to produce the final keystream for the message-specific confidentiality  protection (i.e., KEYSTREAM) as below:

[0085] KEYSTREAM = output_keystream AND (Encrypted_bits_mask || 0xFF.. FF||0x00.. 00)

[0086] The KEYSTREAM is XORed with the payload of discovery message excluding PLMN ID filed as the last IE for message-specific confidentiality protection.

[0087] For the scrambling protection, the second terminal device 120 may set 4 LSBs of the UTC-based counter equal to zero for the purpose of scrambling calculation. The second terminal device 120 then may compute the time-hash-bitsequence from DUSK and the modified UTC-based counter passed through a KDF. The time-hash-bitsequence keystream is set to L least significant bits of the output of the KDF, where L is the bit length of the discovery message to be scrambled and set to Min (the length of discovery message-16, 256) . 16 in the function is the size of message type and UTC-based counter LSB in bit length. The maximum length of the discovery message to be scrambled is limited to 256 bits.

[0088] After that, the second terminal device 120 may update the time-hash-bitsequence to exclude PLMN ID, and perform the XOR operation between the updated time-hash-bitsequence with the discovery message excluding message type field, UTC-based counter field and PLMN ID field as below:

[0089] XOR (0xFFFF || (time-hash-bitsequence AND (0xFF.. FF || 0x00.. 00) with the least significant (L + 16) bits of discovery message

[0090] The PLMN ID may be excluded from scrambling with set corresponding bits of time-hash-bitsequence to “0” . For the second input of AND operation, the first 0xFF.. FF represents MIC filed and other IEs of payload which including both mandatory and optional IEs, the following 0x000000 represents PLMN ID filed.

[0091] In a fourth example, the position of the network identity is the third position, and the network identity may be un-encrypted and un-scrambled. Alternatively or additionally, in order to encrypt and scramble the discovery message, the second terminal device 120 may exclude a bit length of the network identity from the bit length of the discovery message to be scrambled, exclude a bit length of the network identity from the bit length of the discovery message to be encrypted, perform a logical operation between a keystream and the discovery message except message type field, UTC-based counter field, MIC field and the network identity of the header.

[0092] For instance, the PLMN ID may be put as a header between UTC-based counter filed and MIC filed, which is neither scrambled nor encrypted, as shown in table 4. Encryption algorithm is enhanced to support U2N specific discovery message.

[0093] Table 4. Put plain text PLMN ID as a header IE

[0094] For the Message-specific confidentiality protection, the use and mode of operation of the ciphering algorithms are specified. Input parameters to the ciphering algorithms are listed below:

[0095] - KEY: 128 least significant bits of the output of the KDF (DUCK, UTC-based counter, MIC)

[0096] - COUNT is UTC-based counter, BEARER is 0x00

[0097] - DIRECTION: 0x00

[0098] - LENGTH: LEN (discovery message) - (LEN (Message Type) + LEN (UTC-based counter LSB) + LEN (MIC) ) , where LEN (x) is the length of x in number of bits

[0099] If the discovery message is for UE-to-network relay discovery announcement or UE-to-network relay discovery response, the LENGTH may further exclude the length of PLMN ID. Optionally, the PLMN ID may be included as an input of KDF.

[0100] KEY is set to as such to generate message-specific keystream. The output keystream of the ciphering algorithm (i.e., output_keystream) is then masked with the Encrytped_bits_mask to produce the final keystream for the message-specific confidentiality protection (i.e., KEYSTREAM) as below:

[0101] KEYSTREAM = output_keystream AND (Encrypted_bits_mask || 0xFF.. FF)

[0102] The KEYSTREAM is XORed with the payload of discovery message (which exclude message type filed, UTC-based counter filed, MIC filed and PLMN ID filed) for message-specific confidentiality protection.

[0103] For the scrambling protection, the second terminal device 120 may set 4 LSBs of the UTC-based counter equal to zero for the purpose of scrambling calculation. The second terminal device 120 then may compute the time-hash-bitsequence from DUSK and the modified UTC-based counter passed through a KDF. The time-hash-bitsequence keystream is set to L least significant bits of the output of the KDF, where L is the bit length of the discovery message to be scrambled and set to Min (the length of discovery message-16 / 40, 256) . 16 in the function is the size of message type and UTC-based counter LSB in bit length. It is 40 in the case of ProSe U2N relay discovery which includes additional length of PLMN ID.The maximum length of the discovery message to be scrambled is limited to 256 bits.

[0104] After that, the second terminal device 120 may perform the XOR operation between the time-hash-bitsequence with the discovery message excluding message type field, UTC-based counter field as below:

[0105] XOR (0xFFFFFFFFFF || time-hash-bitsequence) with the least most significant (L+ 16 / 40) bits of discovery message

[0106] In some embodiments, in order to perform the protection operation, the second terminal device 120 may encrypt and scramble the discovery message based on determining that the discovery message does not comprise the network identity. For example, if the discovery message does not comprise the PLMN ID, the second terminal device 120 may encrypt and scramble the discovery message in the same manner as it previously encrypted and scrambled the discovery message that did not comprise the PLMN ID.

[0107] Continuing with reference to Fig. 2, the second terminal device 120 transmits 215 the discovery message 220 to the first terminal device 110. The discovery message 220 comprises an indication of whether the network identity is comprised in the discovery message 220.

[0108] Backward compatibility issue was raised and discussed. Due to the introduction of the new IE (i.e., PLMN ID) in the discovery messages which may not be supported by the opposite UE, which will result into a decoding error even after trying multiple times of undo scrambling and decryption. For example, since the reliable server connection (RSC) is encrypted, and remote UE (e.g., the first terminal device 110) has no idea whether the PLMN  ID included in the discovery message. The remote UE may proceed every message announced in the proximity area, and try to decrypt each message with multiple “assumed” but “wrong” keys which most likely will be failed finally. It's very time and energy consuming. To support both a common message without PLMN ID and a new message including PLMN ID, an indication (e.g., a new message type) may be proposed to extend for remote / monitor UE to identify whether it support the PLMN ID in the discovery message. The ProSe U2N relay UE (e.g., the second terminal device 120) may use the indication to announce the discovery message if PLMN ID is included in the ProSe discovery announcement / response message. The remote UE may retrieve the PLMN ID from the discovery announcement / response message if the indication indicates that the discovery message is the new message including PLMN ID, and get key based on PLMN ID to undo scrambling and decryption. In this way, it will avoid the remote UE to trying undo scrambling and decryption on each message announced in the area with “wrong” supposed keys, and fail finally. It will be time and energy consuming.

[0109] In some embodiments, the indication may be provided via a message type of the discovery message 220, and the message type is configured for indicating that the network identity is comprised in the discovery message 220.

[0110] In some embodiments, the indication may be provided via a type of an optional information element of the discovery message 220, and the optional information element is configured for indicating the network identity in the discovery message 220. For example, PLMN ID may be included as an optional IE at the end of the discovery message 220, which type is tag length value (TLV) or type value (TV) , as shown in table 5.

[0111] Table 5. Put plain text PLMN ID as the optional IE

[0112] Both a sending UE with a capability of handling the discovery message comprising the network identity (hereinafter referred to as first sender) and a receiving UE with a capability of handling the discovery message comprising the network identity (hereinafter referred to as first receiver) may know that the location of the PLMN ID and handle it at that location. The first receiver may decode the TV IE which receives at that location and find that the type of the IE refers to PLMN ID, hence the first receiver may use it.

[0113] For a sending UE without a capability of handling the discovery message comprising the network identity (hereinafter referred to as second sender) and a first receiver, the PLMN ID IE was not added in the discovery message by the second sender, and old security mechanism (i.e. it uses the keys associated with its PLMN ID as usual) is used. The first receiver goes and reads the TV IE which receives at the expected location and doesn’ t find the PLMN ID IE. Hence the first receiver can assume that the discovery message is encrypted using the keys associated with its own PLMN ID. If both the second sender and first receiver are in the same PLMN, then the processing of the discovery message will work successfully. In this scenario, the value of other IEs (e.g. RRC container) in the same location may happen to have the same value as the PLMN ID Type, but that should be “small incident” which can be accepted.

[0114] For first sender and a receiving UE without a capability of handling the discovery message comprising the network identity (hereinafter referred to as second receiver) , the PLMN ID may be added in the discovery message by the first sender, and the second receiver doesn't know it. Then the processing of the discovery message will fail as the second receiver expects the whole discovery message to be encrypted and scrambled in the old way.

[0115] In some embodiments, the indication may be provided via a message version / release of the discovery message. For example, the message version / release is configured for indicating that the network identity is comprised in the discovery message.

[0116] Alternatively or additionally, the indication may be determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device. In some embodiments, the indication may be determined by a network device based on a network configuration. For example, the message type may be decided by the network and a UE during a discovery key request procedure based on the capability of UEs and network configuration.

[0117] On the other side of the communication, the first terminal device 110 receives 225 the discovery message 220 from the second terminal device 120. The first terminal device 110 obtains 230 the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message 220.

[0118] In some embodiments, the first terminal device 110 may un-scramble and decrypt the discovery message 220 considering the position of the network identity in the discovery message 220.

[0119] The first terminal device 110 receives code-sending security parameters from the DDNMF / PKMF to indicate a UE how a received discovery message is protected. The code-sending security parameters may contain a DUSK and may contain either a DUIK or an indication whether to use match reports for MIC checking. The match reports option is not allowed for ProSe Query Codes. The code-sending security parameters may also contain both a DUCK and a corresponding Encrypted_bits_mask.

[0120] In a first example, if the position of the network identity is the first position, and the network identity is un-encrypted and un-scrambled, the first terminal device 110 may set bits corresponding to the network identity in a mask (e.g., Encrypted_bits_mask) to a first value, perform a first logical operation (e.g., an AND operation) between a keystream and the mask, perform a second logical operation (e.g., an exclusive or operation) between the keystream  and the payload of discovery message 220, set bits corresponding to the network identity in a bit sequence (e.g., time-hash-bitsequence) to the first value, and perform a second logical operation between the bit sequence and the payload of discovery message 220. Additionally, the first value may comprise 0.

[0121] The Encrypted_bits_mask is applicable to the mandatory IEs of payload of the discovery message. The corresponding bits of PLMN ID in the Encrypted_bits_mask may be set to 0, and other bits in the Encrypted_bits_mask may be set to 1. In some example, some bits of the other bits in the Encrypted_bits_mask may also be set to 0.

[0122] When receiving the discovery message, the first terminal device 110 may undo scrambling if a DUSK was received. The first terminal device 110 may then check for match on the bits of the discovery message that are not encrypted using message specific confidentiality. If it does not match, then the first terminal device 110 may abort the processing of the discovery message. In other words, the first terminal device 110 determines if the discovery message is the message it intended. If a DUCK was received, the first terminal device 110 may undo message-specific confidentiality. After that, the first terminal device 110 may check for full match if only a match on non-encrypted bits was found above. If it does not match, then the first terminal device 110 may abort the processing of the discovery message. If a MIC check is required, the first terminal device 110 may check MIC directly (if a DUIK was given in the discovery filter security parameters) or via match reports if indicated in the discovery filter security parameters.

[0123] Both the first terminal device 110 and the second terminal device 120 don't scramble / unscramble the PLMN ID. The embodiments for operations of message-specific confidentiality protection and the un-scrambling protection at the first terminal device 110 side are the same as the embodiments for at the second terminal device 120 side and will not be described again here.

[0124] In a second example, if the position of the network identity is the first position, and the network identity is un-encrypted and scrambled, the first terminal device 110 may set bits corresponding to the network identity in a mask to a first value, perform a first logical operation between a keystream and the mask, perform a second logical operation between the keystream and the payload of discovery message 220 and scramble the MIC field and the payload of discovery message 220 comprising the network identity. The embodiments for operations of message-specific confidentiality protection and the un-scrambling protection at  the first terminal device 110 side are the same as the embodiments for at the second terminal device 120 side and will not be described again here.

[0125] In a third example, if the position of the network identity is the second position, and the network identity is un-encrypted and un-scrambled, the first terminal device 110 may set bits corresponding to the network identity in a keystream to a first value, perform a first logical operation between the keystream and the payload of discovery message 220, set bits corresponding to the network identity in a bit sequence to a first value, and perform a second logical operation between the bit sequence and the payload of discovery message 220.

[0126] For instance, the first terminal device 110 may undo scrambling if a DUSK was received. The first terminal device 110 then may get PLMN ID from the last 3 bytes of the discovery message, and select a DUSK based on the PLMN ID. The first terminal device 110 may check for match on the bits of the message that are not encrypted using message specific confidentiality. If it does not match, then the first terminal device 110 may abort the processing of the discovery message. If a DUCK was received, the first terminal device 110 may undo message-specific confidentiality. After that, the first terminal device 110 may check for full match if only a match on non-encrypted bits was found above. If it does not match, then the first terminal device 110 may abort the processing of the discovery message. If a MIC check is required, the first terminal device 110 may check MIC directly (if a DUIK was given in the discovery filter security parameters) or via match reports if indicated in the discovery filter security parameters.

[0127] The embodiments for operations of message-specific confidentiality protection and the un-scrambling protection at the first terminal device 110 side are the same as the embodiments for at the second terminal device 120 side and will not be described again here.

[0128] In a fourth example, if the position of the network identity is the third position, and the network identity is un-encrypted and un-scrambled, the first terminal device 110 may exclude a bit length of the network identity from the bit length of the discovery message 220 to be scrambled, exclude a bit length of the network identity from the bit length of the discovery message 220 to be encrypted, perform a logical operation between a keystream and the discovery message 220 except message type field, UTC-based counter field, MIC field and the network identity of the header. The embodiments for operations of message-specific confidentiality protection and the un-scrambling protection at the first terminal device 110 side are the same as the embodiments for at the second terminal device 120 side and will not  be described again here.

[0129] In some embodiments, the first terminal device 110 may further determine at least one of a scrambling key or a confidentiality key based on the network identity. For example, the first terminal device 110 may select a DUSK or a DUCK based on the PLMN ID.

[0130] Alternatively or additionally, in order to obtain the network identity, the first terminal device 110 may obtain the network identity based on determining that the first terminal device 110 has a capability of handling the discovery message 220 comprising the network identity.

[0131] In addition, the first terminal device 110 may un-scramble and decrypt the discovery message 220 based on determining that the indication indicates that the network identity does not comprised in the discovery message 220. For example, if the discovery message does not comprise the PLMN ID, the first terminal device 110 may un-scramble and decrypt the discovery message in the same manner as it previously un-scramble and decrypt the discovery message that did not comprise the PLMN ID.

[0132] Fig. 3 shows a flowchart of an example method 300 implemented at a first terminal device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 300 will be described from the perspective of the first terminal device 110 with reference to Fig. 1A.

[0133] At block 310, the first terminal device 110 receives, from a second terminal device, a discovery message comprising an indication of whether a network identity is comprised in the discovery message. At block 320, the first terminal device 110 obtains the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.

[0134] In some embodiments, the first terminal device 110 may further un-scramble and decrypt the discovery message considering the position of the network identity in the discovery message.

[0135] In some embodiments, the position of the network identity may comprise a first position between a message integrity code (MIC) field and an announcer information field. In this case, the network identity may be a mandatory information element (IE) of the payload of the discovery message. Alternatively or additionally, the position of the network identity may comprise a second position as the last IE of the payload of the discovery message. In such a case, the network identity may be an optional IE of the payload of the discovery  message. Alternatively or additionally, the position of the network identity may comprise a third position between a universal time coordinated (UTC) -based counter field and the MIC field. In this situation, the network identity may be a mandatory IE of the header of the discovery message.

[0136] In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and scrambled. In some embodiments, the position of the network identity may be the second position, and the network identity may be un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the third position, and the network identity may be un-encrypted and un-scrambled.

[0137] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and un-scrambled, in order to un-scramble and decrypt the discovery message, the first terminal device 110 may set bits corresponding to the network identity in a mask to a first value, perform a first logical operation between a keystream and the mask, and perform a second logical operation between the keystream and the payload of discovery message, and set bits corresponding to the network identity in a bit sequence to the first value, and perform a second logical operation between the bit sequence and the payload of discovery message.

[0138] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and scrambled, in order to un-scramble and decrypt the discovery message, the first terminal device 110 may set bits corresponding to the network identity in a mask to a first value, perform a first logical operation between a keystream and the mask, and perform a second logical operation between the keystream and the payload of discovery message, and scramble the MIC field and the payload of discovery message comprising the network identity.

[0139] In some embodiments, the position of the network identity may be the second position, in order to un-scramble and decrypt the discovery message, the first terminal device 110 may set bits corresponding to the network identity in a keystream to a first value, and perform a first logical operation between the keystream and the payload of discovery message, and set bits corresponding to the network identity in a bit sequence to a first value, and perform a second logical operation between the bit sequence and the payload of discovery  message.

[0140] In some embodiments, the indication may be provided via a message type of the discovery message, and the message type may be configured for indicating that the network identity is comprised in the discovery message.

[0141] In some embodiments, the indication may be provided via a type of an optional information element of the discovery message, and the optional information element may be configured for indicating the network identity in the discovery message.

[0142] In some embodiments, the indication may be provided via a message version / release of the discovery message, and the message version / release may be configured for indicating that the network identity is comprised in the discovery message.

[0143] In some embodiments, the indication may be determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device. In some embodiments, the indication may be determined by a network device based on a network configuration.

[0144] In some embodiments, the first terminal device 110 may further determine at least one of a scrambling key or a confidentiality key based on the network identity.

[0145] In some embodiments, in order to obtain the network identity, the first terminal device 110 may obtain the network identity based on determining that the first terminal device has a capability of handling the discovery message comprising the network identity.

[0146] In some embodiments, the first terminal device 110 may un-scramble and decrypt the discovery message based on determining that the indication indicates that the network identity does not comprised in the discovery message.

[0147] In some embodiments, the first terminal device 110 may comprise a monitoring user equipment (UE) , and the second terminal device may comprise an announcing UE. In some embodiments, the network identity may comprise a public land mobile network (PLMN) identity (PLMN ID) or a home public land mobile network (HPLMN) identity (HPLMN ID) . In some embodiments, the first value may comprise 0.

[0148] Fig. 4 shows a flowchart of an example method 400 implemented at a second terminal device in accordance with some embodiments of the present disclosure. For the purpose of discussion, the method 400 will be described from the perspective of the second terminal device 120 with reference to Fig. 1A.

[0149] At block 410, the second terminal device 120 performs a protection operation for a discovery message based on whether the discovery message comprises a network identity. At block 420, the second terminal device 120 transmits, to a first terminal device, the discovery message. The discovery message comprises an indication of whether the network identity is comprised in the discovery message.

[0150] In some embodiments, in order to perform the protection operation, the second terminal device 120 may determine a position of the network identity in the discovery message based on determining that the discovery message comprises the network identity, and encrypt and scramble the discovery message considering the position of the network identity.

[0151] In some embodiments, the position of the network identity may comprise a first position between a message integrity code (MIC) field and an announcer information field. In this case, the network identity may be a mandatory information element (IE) of the payload of the discovery message. Alternatively or additionally, the position of the network identity may comprise a second position as the last IE of the payload of the discovery message. In this case, the network identity may be an optional IE of the payload of the discovery message. Alternatively or additionally, the position of the network identity may comprise a third position between a universal time coordinated (UTC) -based counter field and the MIC field. In this case, the network identity may be a mandatory IE of the header of the discovery message.

[0152] In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and scrambled. In some embodiments, the position of the network identity may be the second position, and the network identity is un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the third position, and the network identity is un-encrypted and un-scrambled.

[0153] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and un-scrambled. In some embodiments, in order to encrypt and scramble the discovery message, the second terminal device 120 may set bits corresponding to the network identity in a mask to a first value, perform a first logical operation between a keystream and the mask, and perform a second logical operation between  the keystream and the payload of discovery message, and set bits corresponding to the network identity in a bit sequence to the first value, and perform a second logical operation between the bit sequence and the payload of discovery message.

[0154] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and scrambled, in order to encrypt and scramble the discovery message, the second terminal device 120 may set bits corresponding to the network identity in a mask to a first value, perform a first logical operation between a keystream and the mask, and perform a second logical operation between the keystream and the payload of discovery message, and scramble the MIC field and the payload of discovery message comprising the network identity.

[0155] In some embodiments, the position of the network identity may be the second position, in order to encrypt and scramble the discovery message, the second terminal device 120 may set bits corresponding to the network identity in a keystream to a first value, perform a first logical operation between the keystream and the payload of discovery message, set bits corresponding to the network identity in a bit sequence to a first value, and perform a second logical operation between the bit sequence and the payload of discovery message.

[0156] In some embodiments, the indication may be provided via a message type of the discovery message, and the message type may be configured for indicating that the network identity is comprised in the discovery message.

[0157] In some embodiments, the indication may be provided via a type of an optional information element of the discovery message, and the optional information element may be configured for indicating the network identity in the discovery message.

[0158] In some embodiments, the indication may be provided via a message version / release of the discovery message, and the message version / release may be configured for indicating that the network identity is comprised in the discovery message.

[0159] In some embodiments, the indication may be determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device. In some embodiments, the indication may be determined by a network device based on a network configuration.

[0160] In some embodiments, in order to perform the protection operation, the second terminal device 120 may encrypt and scramble the discovery message based on determining that the discovery message does not comprise the network identity.

[0161] In some embodiments, the first terminal device may comprise a monitoring user equipment (UE) , and the second terminal device comprises an announcing UE. In some embodiments, the network identity may comprise a public land mobile network (PLMN) identity (PLMN ID) or a home public land mobile network (HPLMN) identity (HPLMN ID) . In some embodiments, the first value may comprise 0.

[0162] In some embodiments, an apparatus capable of performing any of the method 300 (for example, the first terminal device 110) is provided. The apparatus may comprise means for performing the respective steps of the method 300. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.

[0163] In some embodiments, the apparatus comprises means for receiving, from a second terminal device, a discovery message comprising an indication of whether a network identity is comprised in the discovery message, and means for obtaining the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.

[0164] In some embodiments, the apparatus may further comprise means for un-scrambling and decrypting the discovery message considering the position of the network identity in the discovery message.

[0165] In some embodiments, the position of the network identity may comprise a first position between a message integrity code (MIC) field and an announcer information field, wherein the network identity is a mandatory information element (IE) of the payload of the discovery message, a second position as the last IE of the payload of the discovery message, wherein the network identity is an optional IE of the payload of the discovery message, a third position between a universal time coordinated (UTC) -based counter field and the MIC field, wherein the network identity is a mandatory IE of the header of the discovery message, or any combination of two or more of the above-mentioned items.

[0166] In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and scrambled. In some embodiments, the position of the network identity may be the second position, and the network identity may be un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the third position, and the  network identity may be un-encrypted and un-scrambled.

[0167] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and un-scrambled, means for un-scrambling and decrypting the discovery message may comprise means for setting bits corresponding to the network identity in a mask to a first value, means for performing a first logical operation between a keystream and the mask, and means for performing a second logical operation between the keystream and the payload of discovery message, and means for setting bits corresponding to the network identity in a bit sequence to the first value, and means for performing a second logical operation between the bit sequence and the payload of discovery message.

[0168] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and scrambled, means for un-scrambling and decrypting the discovery message may comprise means for setting bits corresponding to the network identity in a mask to a first value, means for performing a first logical operation between a keystream and the mask, and means for performing a second logical operation between the keystream and the payload of discovery message, and means for scrambling the MIC field and the payload of discovery message comprising the network identity.

[0169] In some embodiments, the position of the network identity may be the second position, means for un-scrambling and decrypting the discovery message may comprise means for setting bits corresponding to the network identity in a keystream to a first value, and means for performing a first logical operation between the keystream and the payload of discovery message, and means for setting bits corresponding to the network identity in a bit sequence to a first value, and means for performing a second logical operation between the bit sequence and the payload of discovery message.

[0170] In some embodiments, the indication may be provided via a message type of the discovery message, and the message type may be configured for indicating that the network identity is comprised in the discovery message.

[0171] In some embodiments, the indication may be provided via a type of an optional information element of the discovery message, and the optional information element may be configured for indicating the network identity in the discovery message.

[0172] In some embodiments, the indication may be provided via a message version / release of the discovery message, and the message version / release is configured for indicating that  the network identity is comprised in the discovery message.

[0173] In some embodiments, the indication may be determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device. In some embodiments, the indication may be determined by a network device based on a network configuration.

[0174] In some embodiments, the apparatus may further comprise means for determining at least one of a scrambling key or a confidentiality key based on the network identity. In some embodiments, means for obtaining the network identity may comprise means for obtaining the network identity based on determining that the first terminal device has a capability of handling the discovery message comprising the network identity.

[0175] In some embodiments, the apparatus may further comprise means for un-scrambling and decrypting the discovery message based on determining that the indication indicates that the network identity does not comprised in the discovery message.

[0176] In some embodiments, the first terminal device may comprise a monitoring user equipment (UE) , and the second terminal device may comprise an announcing UE.

[0177] In some embodiments, the network identity may comprise a public land mobile network (PLMN) identity (PLMN ID) or a home public land mobile network (HPLMN) identity (HPLMN ID) . In some embodiments, the first value may comprise 0.

[0178] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of the method 300. In some embodiments, the means comprises at least one processor and at least one memory including computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the performance of the apparatus.

[0179] In some embodiments, an apparatus capable of performing any of the method 400 (for example, the second terminal device 120) is provided. The apparatus may comprise means for performing the respective steps of the method 400. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.

[0180] In some embodiments, the apparatus comprises means for performing a protection operation for a discovery message based on whether the discovery message comprises a network identity, and means for transmitting, to a first terminal device, the discovery message,  wherein the discovery message comprises an indication of whether the network identity is comprised in the discovery message.

[0181] In some embodiments, means for performing the protection operation may comprise means for determining a position of the network identity in the discovery message based on determining that the discovery message comprises the network identity, and means for encrypting and scrambling the discovery message considering the position of the network identity.

[0182] In some embodiments, the position of the network identity may comprise a first position between a message integrity code (MIC) field and an announcer information field, wherein the network identity is a mandatory information element (IE) of the payload of the discovery message, a second position as the last IE of the payload of the discovery message, wherein the network identity is an optional IE of the payload of the discovery message, a third position between a universal time coordinated (UTC) -based counter field and the MIC field, wherein the network identity is a mandatory IE of the header of the discovery message, or any combination of two or more of the above-mentioned items.

[0183] In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the first position, and the network identity is un-encrypted and scrambled. In some embodiments, the position of the network identity may be the second position, and the network identity is un-encrypted and un-scrambled. In some embodiments, the position of the network identity may be the third position, and the network identity is un-encrypted and un-scrambled.

[0184] In some embodiments, the position of the network identity may be the first position, and the network identity may be un-encrypted and un-scrambled, means for encrypting and scrambling the discovery message may comprise means for setting bits corresponding to the network identity in a mask to a first value, means for performing a first logical operation between a keystream and the mask, and means for performing a second logical operation between the keystream and the payload of discovery message, and means for setting bits corresponding to the network identity in a bit sequence to the first value, and means for performing a second logical operation between the bit sequence and the payload of discovery message.

[0185] In some embodiments, the position of the network identity may be the first position,  and the network identity may be un-encrypted and scrambled, means for encrypting and scrambling the discovery message may comprise means for setting bits corresponding to the network identity in a mask to a first value, means for performing a first logical operation between a keystream and the mask, and means for performing a second logical operation between the keystream and the payload of discovery message, and means for scrambling the MIC field and the payload of discovery message comprising the network identity.

[0186] In some embodiments, the position of the network identity may be the second position, means for encrypting and scrambling the discovery message may comprise means for setting bits corresponding to the network identity in a keystream to a first value, means for performing a first logical operation between the keystream and the payload of discovery message, means for setting bits corresponding to the network identity in a bit sequence to a first value, and means for performing a second logical operation between the bit sequence and the payload of discovery message.

[0187] In some embodiments, the indication may be provided via a message type of the discovery message, and the message type may be configured for indicating that the network identity is comprised in the discovery message.

[0188] In some embodiments, the indication may be provided via a type of an optional information element of the discovery message, and the optional information element may be configured for indicating the network identity in the discovery message.

[0189] In some embodiments, the indication may be provided via a message version / release of the discovery message, and the message version / release may be configured for indicating that the network identity is comprised in the discovery message.

[0190] In some embodiments, the indication may be determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device. In some embodiments, the indication may be determined by a network device based on a network configuration.

[0191] In some embodiments, means for performing the protection operation may comprise means for encrypting and scrambling the network identity based on determining that the discovery message does not comprise the network identity. In some embodiments, the first terminal device may comprise a monitoring user equipment (UE) , and the apparatus may comprise means for comprising an announcing UE.

[0192] In some embodiments, the network identity may comprise a public land mobile  network (PLMN) identity (PLMN ID) or a home public land mobile network (HPLMN) identity (HPLMN ID) . In some embodiments, the first value may comprise 0.

[0193] In some embodiments, the device further comprises means for performing other steps in some embodiments of the method 400. In some embodiments, the means comprises at least one processor and at least one memory including computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the performance of the device.

[0194] FIG. 5 is a simplified block diagram of a device 500 that is suitable for implementing embodiments of the present disclosure. The device 500 may be provided to implement the communication device, for example the first terminal device 110 or the second terminal device 120 as shown in Fig. 1A. As shown, the device 500 includes one or more processors 510, one or more memories 520 coupled to the processor 510, and one or more communication modules 540 coupled to the processor 510.

[0195] The communication modules 540 are for bidirectional communications. The communication modules 540 has at least one antenna to facilitate communication. The communication interface may represent any interface that is necessary for communication with other network elements.

[0196] The processor 510 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 500 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.

[0197] The memory 520 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a read only memory (ROM) 524, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random access memory (RAM) 522 and other volatile memories that will not last in the power-down duration.

[0198] A computer program 530 includes computer executable instructions that are executed by the associated processor 510. The program 530 may be stored in the ROM 524.  The processor 510 may perform any suitable actions and processing by loading the program 530 into the RAM 522.

[0199] The embodiments of the present disclosure may be implemented by means of the program 530 so that the device 500 may perform any process of example embodiments of the disclosure as discussed with reference to Figs. 2 to 6. The embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.

[0200] In some embodiments, the program 530 may be tangibly contained in a computer readable medium which may be included in the device 500 (such as in the memory 520) or other storage devices that are accessible by the device 500. The device 500 may load the program 530 from the computer readable medium to the RAM 522 for execution. The computer readable medium may include any types of tangible non-volatile storage, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. Fig. 6 shows an example of the computer readable medium 600 in form of CD or DVD. The computer readable medium has the program 530 stored thereon.

[0201] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0202] Example embodiments of the present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the methods 400, and 500 as described above with reference to Figs. 4-5. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular  abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.

[0203] Program code for carrying out methods of example embodiments of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0204] In the context of the present disclosure, the computer program codes or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.

[0205] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .

[0206] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results.  In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.

[0207] Although example embodiments of the present disclosure have been described in languages specific to structural features and / or methodological acts, it is to be understood that the example embodiments of the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1.A first terminal device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first terminal device at least to:receive, from a second terminal device, a discovery message comprising an indication of whether a network identity is comprised in the discovery message; andobtain the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.2.The first terminal device of claim 1, wherein first terminal device is further caused to:un-scramble and decrypt the discovery message considering the position of the network identity in the discovery message.3.The first terminal device of claim 1 or 2, wherein the position of the network identity comprises one of the following:a first position between a message integrity code (MIC) field and an announcer information field, wherein the network identity is a mandatory information element (IE) of the payload of the discovery message;a second position as the last IE of the payload of the discovery message, wherein the network identity is an optional IE of the payload of the discovery message; ora third position between a universal time coordinated (UTC) -based counter field and the MIC field, wherein the network identity is a mandatory IE of the header of the discovery message.4.The first terminal device of claim 3, wherein one of the following:the position of the network identity is the first position, and the network identity is un-encrypted and un-scrambled;the position of the network identity is the first position, and the network identity is un-encrypted and scrambled;the position of the network identity is the second position, and the network identity is un-encrypted and un-scrambled; orthe position of the network identity is the third position, and the network identity is un-encrypted and un-scrambled.5.The first terminal device of claim 4, wherein the position of the network identity is the first position, and the network identity is un-encrypted and un-scrambled, and the first terminal device is further caused to un-scramble and decrypt the discovery message by:setting bits corresponding to the network identity in a mask to a first value;performing a first logical operation between a keystream and the mask; andperforming a second logical operation between the keystream and the payload of discovery message; andsetting bits corresponding to the network identity in a bit sequence to the first value; andperforming a second logical operation between the bit sequence and the payload of discovery message.6.The first terminal device of claim 4, wherein the position of the network identity is the first position, and the network identity is un-encrypted and scrambled, and the first terminal device is further caused to un-scramble and decrypt the discovery message by:setting bits corresponding to the network identity in a mask to a first value;performing a first logical operation between a keystream and the mask; andperforming a second logical operation between the keystream and the payload of discovery message; andscrambling the MIC field and the payload of discovery message comprising the network identity.7.The first terminal device of claim 4, wherein the position of the network identity is the second position, and the first terminal device is caused to un-scramble and decrypt the discovery message by:setting bits corresponding to the network identity in a keystream to a first value; andperforming a first logical operation between the keystream and the payload of discovery message; andsetting bits corresponding to the network identity in a bit sequence to a first value; andperforming a second logical operation between the bit sequence and the payload of discovery message.8.The first terminal device of any of claims 1-7, wherein the indication is provided via a message type of the discovery message, wherein the message type is configured for indicating that the network identity is comprised in the discovery message.9.The first terminal device of any of claims 1-7, wherein the indication is provided via a type of an optional information element of the discovery message, wherein the optional information element is configured for indicating the network identity in the discovery message.10.The first terminal device of any of claims 1-7, wherein the indication is provided via a message version / release of the discovery message, wherein the message version / release is configured for indicating that the network identity is comprised in the discovery message.11.The first terminal device of any of claims 1-10, wherein one of the following:the indication is determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device; orthe indication is determined by a network device based on a network configuration.12.The first terminal device of any of claims 1-11, wherein the first terminal device is further caused to:determine at least one of a scrambling key or a confidentiality key based on the network identity.13.The first terminal device of any of claims 1-12, wherein the first terminal device is further caused to obtain the network identity by:obtaining the network identity based on determining that the first terminal device has a capability of handling the discovery message comprising the network identity.14.The first terminal device of claim 1, wherein the first terminal device is further caused to:un-scramble and decrypt the discovery message based on determining that the indication indicates that the network identity does not comprised in the discovery message.15.The first terminal device of any of claims 1-14, wherein the first terminal device comprises a monitoring user equipment (UE) , and the second terminal device comprises an announcing UE.16.The first terminal device of any of claims 1-15, wherein the network identity comprises a public land mobile network (PLMN) identity (PLMN ID) or a home public land mobile network (HPLMN) identity (HPLMN ID) .17.The first terminal device of any of claims 5-16, wherein the first value comprises 0.18.A second terminal device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second terminal device at least to:perform a protection operation for a discovery message based on whether the discovery message comprises a network identity; andtransmit, to a first terminal device, the discovery message, wherein the discovery message comprises an indication of whether the network identity is comprised in the discovery message.19.The second terminal device of claim 18, wherein the second terminal device is caused to perform the protection operation by:determining a position of the network identity in the discovery message based on determining that the discovery message comprises the network identity; andencrypting and scrambling the discovery message considering the position of the network identity.20.The second terminal device of claim 18 or 19, wherein the position of the network identity comprises one of the following:a first position between a message integrity code (MIC) field and an announcer information field, wherein the network identity is a mandatory information element (IE) of the payload of the discovery message;a second position as the last IE of the payload of the discovery message, wherein the network identity is an optional IE of the payload of the discovery message; ora third position between a universal time coordinated (UTC) -based counter field and the MIC field, wherein the network identity is a mandatory IE of the header of the discovery message.21.The second terminal device of claim 20, wherein one of the following:the position of the network identity is the first position, and the network identity is un-encrypted and un-scrambled;the position of the network identity is the first position, and the network identity is un-encrypted and scrambled;the position of the network identity is the second position, and the network identity is un-encrypted and un-scrambled; orthe position of the network identity is the third position, and the network identity is un-encrypted and un-scrambled.22.The second terminal device of claim 21, wherein the position of the network identity is the first position, and the network identity is un-encrypted and un-scrambled, and the second terminal device is caused to encrypt and scramble the discovery message by:setting bits corresponding to the network identity in a mask to a first value;performing a first logical operation between a keystream and the mask; andperforming a second logical operation between the keystream and the payload of discovery message; andsetting bits corresponding to the network identity in a bit sequence to the first value; andperforming a second logical operation between the bit sequence and the payload of discovery message.23.The second terminal device of claim 21, wherein the position of the network identity is the first position, and the network identity is un-encrypted and scrambled, and the second terminal device is caused to encrypt and scramble the discovery message by:setting bits corresponding to the network identity in a mask to a first value;performing a first logical operation between a keystream and the mask; andperforming a second logical operation between the keystream and the payload of discovery message; andscrambling the MIC field and the payload of discovery message comprising the network identity.24.The second terminal device of claim 21, wherein the position of the network identity is the second position, and the second terminal device is caused to encrypt and scramble the discovery message by:setting bits corresponding to the network identity in a keystream to a first value;performing a first logical operation between the keystream and the payload of discovery message;setting bits corresponding to the network identity in a bit sequence to a first value; andperforming a second logical operation between the bit sequence and the payload of discovery message.25.The second terminal device of any of claims 18-24, wherein the indication is provided via a message type of the discovery message, wherein the message type is configured for indicating that the network identity is comprised in the discovery message.26.The second terminal device of any of claims 18-24, wherein the indication is provided via a type of an optional information element of the discovery message, wherein the optional information element is configured for indicating the network identity in the discovery message.27.The second terminal device of any of claims 18-24, wherein the indication is provided via a message version / release of the discovery message, wherein the message version / release is configured for indicating that the network identity is comprised in the discovery message.28.The second terminal device of any of claims 18-25, wherein one of the following:the indication is determined by the second terminal device based on a capability of handling the discovery message comprising the network identity of the second terminal device; orthe indication is determined by a network device based on a network configuration.29.The second terminal device of claim 18, wherein the second terminal device is caused to perform the protection operation by:encrypting and scrambling the discovery message based on determining that the discovery message does not comprise the network identity.30.The second terminal device of any of claims 18-29, wherein the first terminal device comprises a monitoring user equipment (UE) , and the second terminal device comprises an announcing UE.31.The second terminal device of any of claims 18-30, wherein the network identity comprises a public land mobile network (PLMN) identity (PLMN ID) or a home public land mobile network (HPLMN) identity (HPLMN ID) .32.The second terminal device of any of claims 22-30, wherein the first value comprises 0.33.A method comprising:receiving, at a first terminal device and from a second terminal device, a discovery message comprising an indication of whether a network identity is comprised in the discovery message; andobtaining the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.34.A method comprising:performing, at a second terminal device, a protection operation for a discovery message based on whether the discovery message comprises a network identity; andtransmitting, to a first terminal device, the discovery message, wherein the discovery message comprises an indication of whether the network identity is comprised in the discovery message.35.An apparatus comprising:means for receiving, at a first terminal device and from a second terminal device, a discovery message comprising an indication of whether a network identity is comprised in the discovery message; andmeans for obtaining the network identity based on determining that the indication indicates that the network identity is comprised in the discovery message.36.An apparatus comprising:means for performing, at a second terminal device, a protection operation for a discovery message based on whether the discovery message comprises a network identity; andmeans for transmitting, to a first terminal device, the discovery message, wherein the discovery message comprises an indication of whether the network identity is comprised in the discovery message.37.A non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method of claim 33 or 34.

Citation Information

Patent Citations

  • Unified header design for discovery messages

    CN105432101A

  • Peer-to-peer relaying of discovery information

    CN106464726A

  • Code encryption

    CN107439028A

  • Data transmission method, device and equipment

    CN117858028A

  • Method and appartus for advertising on basis of area using device-to-device discovery

    US20170372368A1