METHODS AND APPARATUS FOR SECURITY AND PRIVACY OF WTRU-TO-WTRU RETRANSMISSION DISCOVERY
The UE-to-UE relay system with security keys and timer-based DDS updates addresses security and privacy issues in ProSe communications, ensuring authorized UEs share information securely.
Patent Information
- Authority / Receiving Office
- BR · BR
- Patent Type
- Applications
- Current Assignee / Owner
- INTERDIGITAL PATENT HOLDINGS INC
- Filing Date
- 2024-03-06
- Publication Date
- 2026-07-14
AI Technical Summary
Existing proximity-based services (ProSe) lack effective security measures to protect discovery messages and maintain user privacy during UE-to-UE relay communications, particularly in scenarios requiring restricted ProSe codes and authorization.
Implementing a UE-to-UE relay system that uses security keys and restricted ProSe codes to protect discovery messages, ensuring only authorized end UEs can share IP address/prefix information, and employing a timer-based mechanism for updating protected Direct Discovery Sets (DDS) to enhance security and privacy.
Ensures secure and private UE-to-UE relay communications by authorizing only authorized UEs and protecting discovery messages, thereby maintaining user privacy and integrity in proximity-based services.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
1 / 44 “METHODS AND APPARATUS FOR SECURITY AND PRIVACY OF WTRU-TO-WTRU RETRANSMISSION DISCOVERY” CROSS-REFERENCE TO RELATED ORDERS
[001] This application claims the benefit of U.S. Provisional Application No. 63 / 489,273, filed March 9, 2023, the content of which is incorporated herein by reference. BACKGROUND
[002] Proximity-based services (ProSe) can be provided to UEs that are close to each other. A UE can support ProSe direct discovery procedures, which can be used to discover other nearby UEs. A UE can also support direct communication with another UE, for example, direct data transmission to another UE without traversing the infrastructure network.
[003] The discovery procedure can also be considered open or restricted. In the case of open discovery, no explicit permission would be required from the UE being discovered. In the case of restricted discovery, there may be a requirement for explicit permission granted to the discovering UE, authorizing it to discover a discovered UE. This permission may be associated, for example, with a restricted ProSe code. The restricted ProSe code can be provisioned or configured on UEs authorized to use, provide, or discover other UEs that are using the same restricted ProSe code. SUMMARY
[004] Proximity-based services (ProSe) can be provided to UEs that are close to each other. A UE can support ProSe direct discovery procedures, which can be used to discover other nearby UEs. A UE can also support direct communication with another UE. A UE-to-UE relay may be able to relay traffic to and from UEs. Petition 870250084263, dated 09 / 18 / 2025, page 6 / 63 2 / 44 finals. A UE-to-UE relay broadcasts discovery messages, including its associated relay service code (RSC), to facilitate the relay discovery process for end UEs. The discovery message may include a Direct Discovery Set (DDS). The DDS may contain information associated with one or more end UEs that are near the UE-to-UE relay. This may include user information identification (user information ID) and a ProSe restricted code. Each RSC may have one or more ProSe restricted codes associated with it. The IP address / prefix information of an end UE is associated with a unique pair of ProSe restricted code and user information ID.
[005] Potential security requirements for EU-to-EU relay: EU-to-EU relay may include protecting discovery messages and confidential privacy information of EUs during an EU-to-EU relay discovery procedure. Security keys may be used to protect messages during transmission. Both the relay and the end EU may be provisioned with the security material associated with the RSC to properly exchange and process relay message security. Only authorized end EUs may be provisioned with the security material associated with a given ProSe restricted code. The EU-to-EU relay may only share the IP address / prefix information of a first end EU with a second end EU if the second end EU is authorized for restricted discovery with the same ProSe restricted code associated with the first end EU.
[006] The final UE sends a protected DDS to the UE-to-EU relay, and the UE-to-EU relay includes the protected DDS in the discovery message. In one example, the final UE might run a timer to trigger the sending of an updated protected DDS to the UE-to-EU relay when the timer expires. In another example, the UE-to-EU relay might provide information Petition 870250084263, dated 09 / 18 / 2025, page 7 / 63 3 / 44 regarding an upcoming announcement opportunity, and the final EU can then send an updated protected DDS to the EU-to-EU relay during the next announcement opportunity. BRIEF DESCRIPTION OF THE DRAWINGS
[007] A more detailed understanding can be obtained from the following description, given by way of example in conjunction with the accompanying drawings, where similar reference numbers in the figures indicate similar elements, and where:
[008] Figure 1A is a system diagram that illustrates an exemplary communications system in which one or more disclosed modalities can be implemented;
[009] Figure 1B is a system diagram illustrating an exemplary wireless transmit / receive unit (WTRU) that can be used within the communications system illustrated in Figure 1A according to one embodiment;
[010] Figure 1C is a system diagram illustrating an exemplary radio access network (RAN) and an exemplary central network (CN) that can be used within the communications system illustrated in Figure 1A according to one embodiment;
[011] Figure 1D is a system diagram that illustrates an additional exemplary RAN and an additional exemplary CN that can be used within the communications system illustrated in Figure 1A according to a modality;
[012] Figure 2 illustrates an example of end UE connectivity using UE-to-UE relay connectivity over the PC5 interface;
[013] Figure 3 illustrates the UE-to-UE relay discovery procedure with Model A;
[014] Figure 4 shows an example of a relay message where a single set of keys associated with an RSC is used to protect the Petition 870250084263, dated 09 / 18 / 2025, page 8 / 63 4 / 44 message;
[015] Figure 5 shows an example of a relay message where multiple sets of keys associated with an RSC are used to protect the message;
[016] Figure 6 shows an example of a call flow for a U2U relay direct link establishment procedure with support for discovery of the Model A U2U relay using multiple key sets and IP sharing privacy;
[017] Figure 7 shows an example of a call flow for a U2U relay direct link modification procedure to enable support for U2U Model A relay discovery using multiple key sets and IP sharing privacy;
[018] Figure 8 shows an example of a call flow for a U2U relay DNS query with IP sharing privacy;
[019] Figure 9 shows an example of a call flow for a U2U Model A relay discovery procedure initiated by a U2U relay using multiple sets of keys;
[020] Figure 10 shows an example of a call flow for a U2U Model A relay discovery procedure initiated by final UE using multiple sets of keys; and
[021] Figure 11 shows an example of a call flow for a U2U Model A relay discovery procedure initiated by final UE with deferred announcement of discovered final UE. DETAILED DESCRIPTION
[022] Figure 1A is a diagram illustrating an exemplary communications system 100 in which one or more disclosed modalities can be implemented. The communications system 100 can be a multiple access system that Petition 870250084263, dated 09 / 18 / 2025, page 9 / 63 5 / 44 provides content, such as voice, data, video, messages, broadcast, etc., to multiple wireless users. The 100 communications system can allow multiple wireless users to access this content by sharing system resources, including wireless bandwidth. For example, 100 communications systems may employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single carrier FDMA (SC-FDMA), zero-tailed single-word discrete Fourier transform spreading OFDM (ZT-UW-DFT-S-OFDM), single-word OFDM (UWOFDM), resource block filtered OFDM, filter bank multicarrier (FBMC), and the like.
[023] As shown in Figure 1A, the communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104, a central network (CN) 106, a public switched telephone network (PSTN) 108, the Internet 110 and other networks 112, although it is important to note that the disclosed embodiments contemplate any number of WTRUs, base stations, networks and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment.By way of example, WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a station (STA), may be configured to transmit and / or receive wireless signals and may include a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a mobile phone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things (IoT) device, a watch or other wearable device, a head-mounted display (HMD), a vehicle, a drone, a medical device, and applications. Petition 870250084263, dated 09 / 18 / 2025, page 10 / 63 6 / 44 (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in industrial and / or automated process chain contexts), a consumer electronic device, a device operating in commercial and / or industrial wireless networks, and the like. Any of the WTRUs 102a, 102b, 102c, and 102d may be referred to alternatively as UE.
[024] Communication systems 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a and 114b may be any type of device configured to wirelessly interact with at least one of the WTRUs 102a, 102b, 102c, and 102d to facilitate access to one or more communication networks, such as CN 106, Internet 110, and / or the other networks 112. As an example, base stations 114a and 114b may be a base transceiver station (BTS), a NodeB, an eNode B (eNB), a Home Node B, a next-generation NodeB such as a gNode B (gNB), a new radio NodeB (NR), a site controller, an access point (AP), a wireless router, and the like. Although base stations 114a and 114b are represented as a single element, it is important to note that base stations 114a and 114b can include any number of interconnected base stations and / or network elements.
[025] Base station 114a may be part of RAN 104, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, and the like. Base station 114a and / or base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in the licensed spectrum, the unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide coverage for a wireless service for a specific geographic area that may be Petition 870250084263, dated 09 / 18 / 2025, p. 11 / 63 7 / 44 relatively fixed or that may change over time. The cell may be further divided into cell sectors. For example, the cell associated with base station 114a may be divided into three sectors. Thus, in one embodiment, base station 114a may include three transceivers, i.e., one for each cell sector. In another embodiment, base station 114a may employ multiple-input multiple-output (MIMO) technology and may utilize multiple transceivers for each cell sector. For example, beamforming may be used to transmit and / or receive signals in the desired spatial directions.
[026] Base stations 114a and 114b can communicate with one or more of WTRUs 102a, 102b, 102c and 102d via an air interface 116, which can be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter waves, micrometer waves, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 can be established using any suitable radio access technology (RAT).
[027] More specifically, as noted above, communications system 100 may be a multiple access system and may employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA and the like. For example, base station 114a in RAN 104 and WTRUs 102a, 102b and 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 116 using wideband CDMA (WCDMA). WCDMA may include communication protocols such as High-Speed Packet Access (HSPA) and / or HSPA Enhanced (HSPA+). HSPA may include High-Speed Downlink Packet Access (HSDPA) and / or High-Speed Uplink Packet Access (HSUPA).
[028] In one embodiment, base station 114a and WTRUs 102a, 102b and 102c can implement a radio technology such as Terrestrial Radio Access. Petition 870250084263, dated 09 / 18 / 2025, page 12 / 63 8 / 44 Evolved UMTS (E-UTRA), which can establish the 116 air interface using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).
[029] In one embodiment, base station 114a and WTRUs 102a, 102b and 102c can implement a radio technology, such as NR Radio Access, which can establish the 116 air interface using NR.
[030] In one embodiment, base station 114a and WTRUs 102a, 102b, and 102c may implement multiple radio access technologies. For example, base station 114a and WTRUs 102a, 102b, and 102c may implement LTE radio access and NR radio access together, for example, using dual connectivity (DC) principles. Thus, the air interface used by WTRUs 102a, 102b, and 102c may be CHARACTERIZED by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., an eNB and a gNB).
[031] In other embodiments, base station 114a and WTRUs 102a, 102b, 102c may implement radio technologies such as IEEE 802.11 (i.e., Wireless Fidelity (WiFi)), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 1X, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile Communications (GSM), Enhanced Data Rates for GSM Evolution (EDGE), GSM EDGE (GERAN) and the like.
[032] Base station 114b in Figure 1A can be a wireless router, a Home B Node, a Home eNode B, or an access point, for example, and can utilize any suitable RAT to facilitate wireless connectivity in a localized area, such as a workplace, a residence, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a highway, and the like. In one embodiment, base station 114b and WTRUs 102c and Petition 870250084263, dated 09 / 18 / 2025, p. 13 / 63 9 / 44 102d can implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In one embodiment, base station 114b and WTRUs 102c and 102d can implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In yet another embodiment, base station 114b and WTRUs 102c and 102d can utilize a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR, etc.) to establish a picocell or femtocell. As shown in Figure 1A, base station 114b can have a direct connection to the Internet 110. Thus, base station 114b may not need to access the Internet 110 via CN 106.
[033] RAN 104 may be in communication with CN 106, which may be any type of network configured to provide voice, data, application, and / or voice over internet protocol (VoIP) services to one or more of WTRUs 102a, 102b, 102c, and 102d. The data may have varying quality of service (QoS) requirements, such as different requirements for throughput, latency, error tolerance, reliability, data throughput, mobility, and the like. CN 106 may provide call control, billing services, location-based mobile services, prepaid calls, internet connectivity, video distribution, etc., and / or perform high-level security functions such as user authentication. Although not shown in Figure 1A, it is important to note that RAN 104 and / or CN 106 may be in direct or indirect communication with other RANs that use the same RAT as RAN 104 or a different RAT.For example, in addition to being connected to RAN 104, which may use NR radio technology, CN 106 may also be communicating with another RAN (not shown) that uses GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or WiFi radio technology.
[034] CN 106 can also serve as a gateway for WTRUs 102a, 102b, 102c, 102d to access PSTN 108, the Internet 110 and / or other networks 112. PSTN 108 may include circuit-switched telephone networks that provide service Petition 870250084263, dated 09 / 18 / 2025, p. 14 / 63 10 / 44 simple telephone line (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the Transmission Control Protocol (TCP), the User Datagram Protocol (UDP), and / or the Internet Protocol (IP) in the TCP / IP Internet protocol suite. Networks 112 may include wired and / or wireless communication networks owned and / or operated by other service providers. For example, networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as RAN 104 or a different RAT.
[035] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multimode capabilities (for example, WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communication with different wireless networks via different wireless links). For example, WTRU 102c shown in Figure 1A may be configured to communicate with base station 114a, which may employ cellular-based radio technology, and with base station 114b, which may employ IEEE 802 radio technology.
[036] Figure 1B is a system diagram illustrating an exemplary WTRU 102. As shown in Figure 1B, the WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a numeric keypad 126, a touch-sensitive display / keyboard 128, non-removable memory 130, removable memory 132, a power supply 134, a global positioning system (GPS) chipset 136 and / or other peripherals 138, among others. It should be noted that the WTRU 102 may include any subcombination of the above elements, while remaining consistent with an embodiment.
[037] Processor 118 can be a general-purpose processor, a special-purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Circuits Petition 870250084263, dated 09 / 18 / 2025, page 15 / 63 11 / 44 Application-Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), any other type of integrated circuit (IC), a state machine, and the like. Processor 118 can perform signal encoding, data processing, power control, input / output processing, and / or any other functionality that allows the WTRU 102 to operate in a wireless environment. Processor 118 can be coupled to transceiver 120, which can be coupled to transmit / receive element 122. Although Figure 1B represents processor 118 and transceiver 120 as separate components, it is important to note that processor 118 and transceiver 120 can be integrated into a single electronic package or chip.
[038] The transmit / receive element 122 can be configured to transmit or receive signals from a base station (e.g., base station 114a) via the air interface 116. For example, in one embodiment, the transmit / receive element 122 can be an antenna configured to transmit and / or receive RF signals. In another embodiment, the transmit / receive element 122 can be a transmitter / detector configured to transmit and / or receive infrared, UV, or visible light signals, for example. In yet another embodiment, the transmit / receive element 122 can be configured to transmit and / or receive RF and light signals. It should be noted that the transmit / receive element 122 can be configured to transmit and / or receive any combination of wireless signals.
[039] Although the transmit / receive element 122 is represented in Figure 1B as a single element, the WTRU 102 can include any number of transmit / receive elements 122. More specifically, the WTRU 102 can employ MIMO technology. Thus, in one embodiment, the WTRU 102 can include two or more transmit / receive elements 122 (e.g., multiple antennas) to transmit and receive wireless signals over the air interface 116.
[040] The 120 transceiver can be configured to modulate the signals to be Petition 870250084263, dated 09 / 18 / 2025, p. 16 / 63 12 / 44 transmitted by the transmit / receive element 122 and to demodulate the signals received by the transmit / receive element 122. As noted above, the WTRU 102 may have multimode capabilities. Thus, the transceiver 120 may include multiple transceivers to allow the WTRU 102 to communicate via multiple RATs, such as NR and IEEE 802.11, for example.
[041] The WTRU 102 processor 118 can be coupled with and receive user input data from the speaker / microphone 124, the numeric keypad 126, and / or the touch-sensitive display / keyboard 128 (e.g., a liquid crystal display (LCD) unit or an organic light-emitting diode (OLED) display unit). The processor 118 can also send user data to the speaker / microphone 124, the numeric keypad 126, and / or the touch-sensitive display / keyboard 128. In addition, the processor 118 can access information and store data in any suitable type of memory, such as non-removable memory 130 and / or removable memory 132. Non-removable memory 130 can include random access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device.Removable memory 132 may include a Subscriber Identity Module (SIM) card, a memory card, a Secure Digital (SD) memory card, and the like. In other embodiments, processor 118 may access information and store data in memory that is not physically located in WTRU 102, such as on a server or home computer (not shown).
[042] Processor 118 can receive power from power source 134 and can be configured to distribute and / or control power to the other components of WTRU 102. Power source 134 can be any device suitable for powering WTRU 102. For example, power source 134 can include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel-metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, cells of Petition 870250084263, dated 09 / 18 / 2025, page 17 / 63 13 / 44 fuel and similar.
[043] Processor 118 can also be coupled to GPS chipset 136, which can be configured to provide location information (e.g., longitude and latitude) pertaining to the current location of WTRU 102. In addition to, or replacing, GPS chipset 136 information, WTRU 102 can receive location information via air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of signals received from two or more nearby base stations. Importantly, WTRU 102 can acquire location information by any suitable location determination method, remaining consistent with a modality.
[044] The processor 118 may be additionally coupled with other peripherals 138, which may include one or more software and / or hardware modules that provide additional wired or wireless features, functionality and / or connectivity. For example, peripherals 138 may include an accelerometer, an electronic compass, a satellite transceiver, a digital camera (for stills and / or video), a Universal Serial Bus (USB) port, a vibration device, a television transceiver, a hands-free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an internet browser, a Virtual Reality and / or Augmented Reality (VR / AR) device, an activity tracker and the like. Peripherals 138 may include one or more sensors.The sensors may be one or more of the following: a gyroscope, an accelerometer, a Hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor, an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, a humidity sensor, and the like. Petition 870250084263, dated 09 / 18 / 2025, page 18 / 63 14 / 44
[045] The WTRU 102 may include a full-duplex radio for which the transmission and reception of some or all signals (e.g., associated with specific subframes for UL (e.g., for transmission) and DL (e.g., for reception) may be concurrent and / or simultaneous. The full-duplex radio may include an interference management unit to substantially reduce and / or eliminate self-interference by means of hardware (e.g., an inductor) or signal processing by means of a processor (e.g., a separate processor (not shown) or by means of processor 118). In one embodiment, the WTRU 102 may include a half-duplex radio for which the transmission and reception of some or all signals (e.g., associated with specific subframes for UL (e.g., for transmission) or DL (e.g., for reception) may be concurrent and / or simultaneous.
[046] Figure 1C is a system diagram illustrating RAN 104 and CN 106 according to one mode. As noted above, RAN 104 can employ E-UTRA radio technology to communicate with WTRUs 102a, 102b, and 102c via air interface 116. RAN 104 can also be in communication with CN 106.
[047] RAN 104 may include eNode-Bs 160a, 160b, and 160c, although it is important to note that RAN 104 may include any number of eNode-Bs while remaining consistent with one embodiment. eNode-Bs 160a, 160b, and 160c may each include one or more transceivers for communication with WTRUs 102a, 102b, and 102c via air interface 116. In one embodiment, eNode-Bs 160a, 160b, and 160c may implement MIMO technology. Thus, eNode-B 160a, for example, may use multiple antennas to transmit wireless signals to and / or receive wireless signals from WTRU 102a.
[048] Each of the eNode-Bs 160a, 160b, and 160c can be associated with a specific cell (not shown) and can be configured to handle radio resource management decisions, handover decisions, and user scheduling. Petition 870250084263, dated 09 / 18 / 2025, page 19 / 63 15 / 44 in UL and / or DL and similar. As shown in Figure 1C, the eNode-Bs 160a, 160b, and 160c can communicate with each other via an X2 interface.
[049] The CN 106 shown in Figure 1C may include a mobility management entity (MME) 162, a service gateway (SGW) 164, and a packet data network gateway (PDN) (PGW) 166. Although the above elements are represented as part of CN 106, it is important to note that any of these elements may be owned and / or operated by an entity other than the CN operator.
[050] MME 162 can be connected to each of the eNode-Bs 162a, 162b, 162c in RAN 104 via an S1 interface and can serve as a control node. For example, MME 162 can be responsible for authenticating users of WTRUs 102a, 102b, 102c, carrier activation / deactivation, selection of a specific service gateway during an initial connection of WTRUs 102a, 102b, 102c, and similar functions. MME 162 can provide a control plane function to switch between RAN 104 and other RANs (not shown) that employ other radio technologies such as GSM and / or WCDMA.
[051] SGW 164 can be connected to each of the B eNodes 160a, 160b, and 160c in RAN 104 via the S1 interface. SGW 164 can generally route and forward user data packets to / from WTRUs 102a, 102b, and 102c. SGW 164 can perform other functions such as anchoring user planes during handovers between B eNodes, triggering paging when DL data is available to WTRUs 102a, 102b, and 102c, managing and storing contexts of WTRUs 102a, 102b, and 102c, and similar functions.
[052] SGW 164 can be connected to PGW 166, which can provide WTRUs 102a, 102b and 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between WTRUs 102a, 102b and 102c and IP-enabled devices. Petition 870250084263, dated 09 / 18 / 2025, p. 20 / 63 16 / 44
[053] CN 106 can facilitate communications with other networks. For example, CN 106 can provide WTRUs 102a, 102b, and 102c with access to circuit-switched networks, such as PSTN 108, to facilitate communications between WTRUs 102a, 102b, and 102c and traditional fixed-line communication devices. For example, CN 106 can include, or communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between CN 106 and PSTN 108. Additionally, CN 106 can provide WTRUs 102a, 102b, and 102c with access to other 112 networks, which may include other wired and / or wireless networks that are owned and / or operated by other service providers.
[054] Although the WTRU is described in Figures 1A-1D as a wireless terminal, it is foreseen that, in certain representative embodiments, such a terminal may use (e.g., temporarily or permanently) wired communication interfaces with the communication network.
[055] In representative modalities, the other 112 network may be a WLAN.
[056] A WLAN in Basic Services Infrastructure Set (BSS) mode can have an Access Point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP may have access to or an interface with a Distribution System (DS) or another type of wired / wireless network that carries inbound and / or outbound traffic from the BSS. Traffic to the STAs originating outside the BSS can arrive through the AP and be delivered to the STAs. Traffic originating from the STAs to destinations outside the BSS can be sent to the AP to be delivered to the respective destinations. Traffic between STAs within the BSS can be sent through the AP, for example, where the originating STA can send traffic to the AP and the AP can deliver the traffic to the destination STA. Traffic between STAs within a BSS can be considered and / or referred to as point-to-point traffic.Point-to-point traffic can be sent between (e.g., directly between) the source and destination STAs with a Direct Link System (DLS) configuration. In certain representative modes, DLS... Petition 870250084263, dated 09 / 18 / 2025, p. 21 / 63 17 / 44 can use an 802.11e DLS or a tunneled 802.11z DLS (TDLS). A WLAN using the Independent BSS (IBSS) mode may not have an AP, and the STAs (e.g., all STAs) within or using the IBSS can communicate directly with each other. The IBSS communication mode may sometimes be referred to in the present invention as an “ad-hoc” communication mode.
[057] When using the 802.11ac infrastructure operating mode or a similar operating mode, the AP can transmit a beacon on a fixed channel, such as a primary channel. The primary channel can have a fixed width (e.g., 20 MHz bandwidth) or a dynamically defined width. The primary channel can be the BSS's operating channel and can be used by STAs to establish a connection with the AP. In certain representative embodiments, Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA) can be implemented, for example, in 802.11 systems. For CSMA / CA, STAs (e.g., each STA), including the AP, can sense the primary channel. If the primary channel is sensed / detected and / or determined to be occupied by a specific STA, that specific STA can back off. An STA (e.g., only one station) can transmit at any time on a given BSS.
[058] High Throughput (HT) STAs can utilize a 40 MHz wide channel for communication, for example, by combining the 20 MHz primary channel with an adjacent or non-adjacent 20 MHz channel to form a 40 MHz wide channel.
[059] Very High Throughput (VHT) STAs can support 20 MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels. 40 MHz and / or 80 MHz channels can be formed by combining contiguous 20 MHz channels. A 160 MHz channel can be formed by combining 8 contiguous 20 MHz channels or by combining two non-contiguous 80 MHz channels, which can be called an 80+80 configuration. For the 80+80 configuration, the data, after encoding Petition 870250084263, dated 09 / 18 / 2025, page 22 / 63 The 18 / 44 channel data can be passed through a segment analyzer that can split the data into two streams. Inverse Fast Fourier Transform (IFFT) processing and time-domain processing can be performed on each stream separately. The streams can be mapped to the two 80 MHz channels, and the data can be transmitted by a transmitting STA. At the receiver of the receiving STA, the operation described above for the 80+80 configuration can be reversed, and the combined data can be sent to the Medium Access Control (MAC).
[060] Operating modes below 1 GHz are supported by 802.11af and 802.11ah. The operating channel bandwidths and carriers are reduced in 802.11af and 802.11ah compared to those used in 802.11n and 802.11ac. 802.11af supports bandwidths of 5 MHz, 10 MHz, and 20 MHz in the TV White Space (TVWS) spectrum, and 802.11ah supports bandwidths of 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz using non-TVWS spectrum. According to a representative embodiment, 802.11ah can support Meter Type Control / Machine Type Communications (MTC), such as MTC devices in a macro coverage area. MTC devices may have certain features, for example, limited features, including support for (e.g., support only for) certain and / or limited bandwidths. MTC devices may include a battery with a lifespan exceeding a certain limit (e.g., to maintain a very long lifespan).
[061] WLAN systems, which can support multiple channels and channel bandwidths, such as 802.11n, 802.11ac, 802.11af, and 802.11ah, include a channel that can be designated as the primary channel. The primary channel can have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel can be defined and / or limited by an STA, among all STAs operating in a BSS, that supports the operating mode with the lowest bandwidth. In the 802.11ah example, the primary channel can have a bandwidth of 1 MHz for STAs (e.g., MTC-type devices) that Petition 870250084263, dated 09 / 18 / 2025, page 23 / 63 19 / 44 supports (for example, only supports) the 1 MHz mode, even if the AP and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier Sense and / or Network Allocation Vector (NAV) settings may depend on the primary channel status. If the primary channel is busy, for example, due to an STA (that only supports the 1 MHz operating mode) transmitting to the AP, all available frequency bands may be considered busy, even if most of them remain idle.
[062] In the United States, the available frequency bands that can be used by 802.11ah range from 902 MHz to 928 MHz. In Korea, the available frequency bands range from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands range from 916.5 MHz to 927.5 MHz. The total bandwidth available for 802.11ah ranges from 6 MHz to 26 MHz, depending on the country code.
[063] Figure 1D is a system diagram illustrating RAN 104 and CN 106 according to a modality. As noted above, RAN 104 can employ NR radio technology to communicate with WTRUs 102a, 102b, and 102c via air interface 116. RAN 104 can also be in communication with CN 106.
[064] RAN 104 may include gNBs 180a, 180b, 180c, although it is possible to observe that RAN 104 may include any number of gNBs, remaining consistent with a modality. gNBs 180a, 180b, 180c may each include one or more transceivers for communication with WTRUs 102a, 102b, 102c via air interface 116. In a modality, gNBs 180a, 180b, 180c may implement MIMO technology. For example, gNBs 180a, 108b may use beamforming to transmit and / or receive signals from gNBs 180a, 180b, 180c. Thus, the gNB 180a, for example, can use multiple antennas to transmit wireless signals to and / or receive wireless signals from the WTRU 102a. In one embodiment, the gNBs 180a, Petition 870250084263, dated 09 / 18 / 2025, p. 24 / 63 20 / 44 180b and 180c can implement carrier aggregation technology. For example, gNB 180a can transmit multiple component carriers to WTRU 102a (not shown). A subset of these component carriers may be in unlicensed spectrum, while the remaining component carriers may be in licensed spectrum. In one embodiment, gNBs 180a, 180b, and 180c can implement Coordinated Multipoint (CoMP) technology. For example, WTRU 102a can receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).
[065] WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c using transmissions associated with scalable numerology. For example, the OFDM symbol spacing and / or the OFDM subcarrier spacing can vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c using subframes or transmission time intervals (TTIs) of varying lengths or scalable lengths (e.g., containing a variable number of OFDM symbols and / or lasting various absolute time lengths).
[066] gNBs 180a, 180b, 180c can be configured to communicate with WTRUs 102a, 102b, 102c in a standalone configuration and / or in a non-standalone configuration. In the standalone configuration, WTRUs 102a, 102b, 102c can communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., eNode-Bs 160a, 160b, 160c). In the standalone configuration, WTRUs 102a, 102b, 102c can use one or more of gNBs 180a, 180b, 180c as a mobility docking point. In a standalone configuration, WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c using signals in an unlicensed band. In a non-standalone configuration, WTRUs 102a, 102b, and 102c can communicate / connect to gNBs 180a, 180b, and 180c. Petition 870250084263, dated 09 / 18 / 2025, page 25 / 63 21 / 44 while also communicating / connecting to another RAN, such as eNode-Bs 160a, 160b, and 160c. For example, WTRUs 102a, 102b, and 102c can implement CC principles to communicate with one or more gNBs 180a, 180b, and 180c and one or more eNode-Bs 160a, 160b, and 160c substantially simultaneously. In the non-standalone configuration, eNode-Bs 160a, 160b, and 160c can serve as a mobility anchor for WTRUs 102a, 102b, and 102c, and gNBs 180a, 180b, and 180c can provide additional coverage and / or throughput to serve WTRUs 102a, 102b, and 102c.
[067] Each of the gNBs 180a, 180b, 180c can be associated with a specific cell (not shown) and can be configured to handle radio resource management decisions, handover decisions, user scheduling in the UL and / or DL, network slicing support, DC, interoperability between NR and E-UTRA, routing of user plane data to the User Plane Function (UPF) 184a, 184b, routing of control plane information to the Access and Mobility Management Function (AMF) 182a, 182b, and the like. As shown in Figure 1D, the gNBs 180a, 180b, 180c can communicate with each other via an Xn interface.
[068] The CN 106 shown in Figure 1D may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b and possibly a Data Network (DN) 185a, 185b. Although the above elements are represented as part of CN 106, it is important to note that any of these elements may be owned and / or operated by an entity other than the CN operator.
[069] AMF 182a, 182b can be connected to one or more gNBs 180a, 180b, 180c in RAN 104 via an N2 interface and can serve as a control node. For example, AMF 182a, 182b can be responsible for authenticating users of WTRUs 102a, 102b, 102c, support for network slicing (e.g., Petition 870250084263, dated 09 / 18 / 2025, page 26 / 63 22 / 44 handling different Protocol Data Unit (PDU) sessions with different requirements), selection of a specific SMF 183a, 183b, log area management, termination of non-access stratum signaling (NAS), mobility management and the like. Network slicing can be used by AMF 182a and 182b to customize CN support for WTRUs 102a, 102b and 102c based on the types of services used. For example, different network slices can be established for different use cases, such as services that rely on ultra-reliable low-latency access (URLLC), services that rely on enhanced massive mobile broadband (eMBB) access, services for MTC access and the like. The AMF 182a and 182b can provide a control plane function to switch between RAN 104 and other RANs (not shown) that employ other radio technologies such as LTE, LTE-A, LTE-A Pro and / or non-3GPP access technologies such as WiFi.
[070] SMF 183a, 183b can be connected to AMF 182a, 182b on CN 106 via an N11 interface. SMF 183a, 183b can also be connected to UPF 184a, 184b on CN 106 via an N4 interface. SMF 183a, 183b can select and control UPF 184a, 184b and configure traffic routing through UPF 184a, 184b. SMF 183a, 183b can perform other functions such as managing and allocating UE IP addresses, managing PDU sessions, controlling policy and QoS enforcement, providing DL data notifications, and the like. A PDU session type can be IP-based, non-IP-based, Ethernet-based, and the like.
[071] UPF 184a, 184b can be connected to one or more of the gNBs 180a, 180b, 180c in RAN 104 via an N3 interface, which can provide WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between WTRUs 102a, 102b, 102c and IP-enabled devices. UPF 184, 184b can perform other functions, such as routing and Petition 870250084263, dated 09 / 18 / 2025, page 27 / 63 23 / 44 packet forwarding, user plane policy enforcement, multihomed PDU session support, user plane QoS handling, DL packet buffering, mobility tethering provision, and similar.
[072] CN 106 can facilitate communications with other networks. For example, CN 106 can include, or communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between CN 106 and PSTN 108. In addition, CN 106 can provide WTRUs 102a, 102b, and 102c with access to other 112 networks, which may include other wired and / or wireless networks owned and / or operated by other service providers. In one embodiment, WTRUs 102a, 102b, and 102c can be connected to a local DN 185a and 185b via UPF 184a and 184b, via the N3 interface to UPF 184a and 184b, and via an N6 interface between UPF 184a and 184b and DN 185a and 185b.
[073] In view of Figures 1A-1D and the corresponding description of Figures 1A-1D, one or more, or all, of the functions described in the present invention in relation to one or more of: WTRU 102a-d, Base Station 114a-b, eNode-B 160a-c, MME 162, SGW 164, PGW 166, gNB 180a-c, AMF 182a-b, UPF 184a-b, SMF 183a-b, DN 185a-b and / or any other device(s) described in this invention, may be performed by one or more emulation devices (not shown). The emulation devices may be one or more devices configured to emulate one or more, or all, of the functions described in this invention. For example, emulation devices can be used to test other devices and / or simulate network and / or WTRU functions.
[074] Emulation devices can be designed to implement one or more tests of other devices in a laboratory environment and / or in a carrier network environment. For example, one or more emulation devices can perform one or more, or all, of the functions while fully or fully Petition 870250084263, dated 09 / 18 / 2025, page 28 / 63 24 / 44 partially implemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. One or more emulation devices may perform one or more, or all, of the functions while temporarily implemented / deployed as part of a wired and / or wireless communication network. The emulation device may be directly coupled to another device for testing and / or performance testing purposes using wireless communications.
[075] One or more emulation devices may perform one or more, including all, of the functions while not implemented / deployed as part of a wired and / or wireless communication network. For example, emulation devices may be used in a test scenario in a test laboratory and / or in an undeployed (e.g., under test) wired and / or wireless communication network to implement tests of one or more components. The emulation device(s) may be test equipment. Direct RF coupling and / or wireless communications via an RF circuit array (e.g., which may include one or more antennas) may be used by the emulation devices to transmit and / or receive data.
[076] The following abbreviations and acronyms may be referred to as: 5GS System DCA Direct Connection Acceptance DCR Direct Connection Request DDS Direct Discovery Set DNMF Direct Discovery Name Management Function LMA Link Modification Acceptance LMR Link Modification Request MIC Message Integrity Code PCF Policy Control Function Petition 870250084263, dated 09 / 18 / 2025, page 29 / 63 25 / 44 PKMF ProSe Key Management Function ProSe Proximity-Based Services RSC Relay Service Code EU to EU U2U UTC Coordinated Universal Time
[077] Proximity-based services (ProSe) can be provided to UEs that are close to each other. A UE can support ProSe direct discovery procedures, which can be used to discover other UEs in its vicinity. A UE can also support direct communication with another UE, for example, direct data transmission to another UE without traversing the infrastructure network.
[078] For ProSe direct discovery, two models can be considered, depending on the roles the UEs perform. In Model A, UEs can be classified as advertising or monitoring UEs, based on their roles: an advertising UE can advertise / broadcast information that can be used by monitoring UEs to discover the advertising UE. In Model B, UEs can be classified as discovering or discovered UEs, based on their roles: a discovering UE can transmit a request containing information about what it is interested in discovering, and a discovered UE that receives the request can respond with some information related to the discovering UE's request. The discovered UE can be called the advertising UE. The discovering UE can be called the monitoring UE.
[079] The discovery procedure can also be considered open or restricted. In the case of open discovery, no explicit permission would be required from the UE being discovered. In the case of restricted discovery, there may be a requirement for explicit permission granted to the discovering UE, authorizing it to discover a discovered UE. This permission may be associated, for example, with Petition 870250084263, dated 09 / 18 / 2025, page 30 / 63 26 / 44 a ProSe restricted code. The ProSe restricted code can be provisioned or configured on UEs authorized to use, provide, or discover other UEs that are using the same ProSe restricted code. A ProSe restricted code can be, for example, associated with a ProSe service or a ProSe application identity (e.g., ProSe application ID). The ProSe restricted code can be sent by the announcing UE over the air to announce its authorization for discovery purposes, facilitating the discovery process.
[080] A UE-to-UE (U2U) relay is a UE capable of relaying traffic to and from end UEs. Figure 2 illustrates an example of end UE connectivity using a UE-to-UE relay connectivity via the PC5 interface.
[081] Figure 3 illustrates the U2U relay discovery procedure with Model A. In (1), the U2U relay discovered other nearby UEs. In (2), the U2U relay broadcasts a discovery announcement message. A relay service code (RSC) can be used to identify the connectivity service provided by the U2U relay. An RSC can be pre-configured or provisioned on the U2U relay and authorized end UEs. An RSC can have associated policies or security information, for example, necessary for authentication and authorization between the end UE and the U2U relay. A U2U relay can broadcast discovery / announcement messages in which it announces its relay service capability, including an associated RSC in the message.
[082] There may be cases where an end UE is interested in discovering another end UE authorized to use or provide a specific ProSe service, but the end UEs are not located near each other. If the end UEs are located near a U2U relay, the U2U relay can facilitate the discovery process. The U2U relay can, for example, advertise information associated with nearby end UEs. The discovery message from the U2U relay can, for example, Petition 870250084263, dated 09 / 18 / 2025, page 31 / 63 27 / 44 example, include information associated with nearby end UEs and the services they are authorized to use / provide, such as the ProSe restricted codes they are advertising. At the same time, the U2U relay may also include its own information, such as the RSC, to support U2U relay discovery. Information to support U2U relay discovery may include, for example, the U2U relay information ID and the relay service code (RSC). Information associated with end UEs is referred to as the Direct Discovery Set (DDS).
[083] The DDS may contain information associated with end UEs that are in the vicinity of the U2U relay and with which the U2U relay may communicate. The DDS may include the user information identification (user information ID) and a ProSe restricted code associated with the end UE. The user information ID may be assigned to end UEs per service. It may be unique for each end UE using the service and may be used to differentiate end UEs using the same service.
[084] Potential security requirements for U2U relays may include protecting discovery messages and the privacy of sensitive information of end UEs during a U2U relay discovery procedure. Security keys may be used to protect messages during transmission. Both the U2U relay and the end UEs may be provided with the security material associated with the RSC to properly exchange and process relay messages. However, only authorized end UEs may be provided with the security material associated with a specific ProSe restricted code.
[085] The terms security material, security key and security key set are used interchangeably in the present invention to represent one or more parameters used to protect or secure a message or Petition 870250084263, dated 09 / 18 / 2025, page 32 / 63 28 / 44 parts of a message. The terms protected message and secure message are used interchangeably in the present invention to represent a message that is protected / secured with specific security material. The security material for different messages may be different and, consequently, they are represented in the present invention using an association of security material with some or all of the information that is being protected, for example, security material associated with CSR.
[086] Figure 4 shows an example of a relay message where a single key set associated with an RSC is used to protect the message. The message integrity code (MIC) 401 can be computed for message integrity protection using an integrity key. The portion of the message with the UE-to-UE relay information ID 402 and the final UE-to-UE information element 403 can be encrypted using a confidentiality key. (In the present invention, the term UE-to-UE relay information ID refers to the UE-to-UE relay user information ID.) The UTC-based counter can be used in both integrity and confidentiality calculations to ensure protection updates and protect against replay attacks. The UTC-based counter used internally by UEs can be encoded, for example, as the 32 most significant bits of the UTC time.The parameter sent in the message by the advertising UE can contain the four least significant bits (LSB) of the UTC 404-based counter; this can be used by the monitoring UE when setting the UTC-based counter value to ensure that both UEs use the same value.
[087] In one example, a single key set can be used to protect the relay message. When a single key set is associated with an RSC, an UE authorized to use an RSC can decrypt, tamper with, or replay any DDS transmitted with that RSC. For example, a first UE Petition 870250084263, dated 09 / 18 / 2025, page 33 / 63 A 29 / 44 authorized user of a first ProSe service may be able to eavesdrop on the contents of a relay message, including information from a second UE using a different ProSe service. Mitigating this security issue may be possible by applying security isolation between ProSe services (i.e., preventing multiple ProSe services from sharing common RSC keys). However, this may require configuring a dedicated RSC for a given ProSe service. This can be set up as part of the service deployment.
[088] In another example, multiple sets of keys can be used to protect the relay message. For example, each ProSe service has a ProSe restricted code and associated security material. In this case, each individual Direct Discovery Set (DDS) can be protected using its own individual security material, for example, the security material associated with the ProSe restricted code. The security material associated with the RSC can be used to encrypt the U2U relay discovery message.
[089] Figure 5 shows an example of a relay message in which multiple sets of keys associated with an RSC are used to protect the message. In this example, each DDS (e.g., Set No. 1 501 and Set No. 2 502) can be protected using its specific set of keys associated with its respective ProSe restricted code.
[090] A single key set approach can allow for simpler deployment options and less impact on existing discovery / provisioning procedures. As such, it may be suitable when a dedicated RSC is used or when no additional protection per ProSe service is required (e.g., used with ProSe services related to public safety). A multi-key set approach can provide additional flexibility in terms of RSC / ProSe service deployment, configuration options, and means to mitigate the potential security / privacy risk mentioned above. This Petition 870250084263, dated 09 / 18 / 2025, page 34 / 63 The 30 / 44 approach may be suitable when an RSC is used by multiple commercial ProSe services. The coexistence of these approaches may be desirable to support different deployment scenarios and varying security requirements.
[091] When employing the multiple key set approach, even if the U2U relay may be relaying traffic associated with a given restricted ProSe code, the key set associated with that restricted ProSe code may not be provisioned on the U2U relay, for example, if the U2U relay is not authorized to use the ProSe service associated with that restricted ProSe code.
[092] The U2U relay that supports protected DDS can support the multi-keyset approach. Support for protected DDS by the U2U relay can be configured in the information associated with the RSC, i.e., it can be per RSC. This allows the coexistence of RSCs that support a single keyset with RSCs that support multiple keysets (e.g., that support protected DDS). The U2U relay can use the configuration information associated with the RSC to determine if protected DDS is supported for the RSC and then use the end UE information to determine if the specific end UE DDS to be advertised requires the supported protection.
[093] End UEs can send a protected DDS to a U2U relay in a discovery message. The U2U relay that supports protected DDS can extract the protected DDS from the message received from the end UE to include in the discovery announcement message that the U2U relay sends. Since multiple end UEs can send discovery messages with protected DDSs to the U2E relay, the relay can transparently extract each received protected DDS and attach / add each extracted protected DDS to the discovery announcement message that the U2U relay sends.
[094] Final UEs that are already connected to the relay may not Petition 870250084263, dated 09 / 18 / 2025, page 35 / 63 31 / 44 Relay discovery messages with protected DDSs to the relay, as they may not be needed after the relay's discovery, and multiple message transmissions may increase overhead and impact UE battery life. The U2U relay can store a received protected DDS to send a later discovery announcement message. However, due to UTC time-based replay protection, the protected DDS may become invalid after a period of time, after which it may be invalidated when received by an end-monitoring UE. The relay may not have access to newly generated protected DDSs and may not be able to properly announce the end-monitor's presence when needed.
[095] In one example, when the U2U relay connected to the end UE decides to advertise previously discovered or currently connected end UEs, the U2U relay can request a protected DDS from those end UEs. The U2U relay can determine that a ProSe service used by an end UE is subject to DDS protection based on the ProSe restricted code stored in the PC5 link context. If a protected DDS received from a previously discovered or connected UE is stored, the U2U relay can verify its validity. If the protected DDS is invalid (for example, based on UTC time), the U2U relay can send a request to obtain an updated protected DDS from the previously discovered or connected UE.
[096] The protected DDS request message can be a newly defined PC5 signaling message (PC5-S), or an existing PC5-S message can be enhanced to include the DDS-related information. The U2U relay can send the PC5-S request message, including the ProSe restricted code, requesting protected DDS from an end UE. The U2U relay can receive, from the end UE, a PC5-S reply message including the protected DDS corresponding to the ProSe restricted code. The U2U relay can then send a Petition 870250084263, dated 09 / 18 / 2025, pp. 36 / 63 32 / 44 U2U relay discovery announcement message, including received protected DDS.
[097] In one example, an end UE can send a protected DDS based on a configured U2U relay discovery time value. The end UE can run a timer and, after the timer expires, the end UE can send a message to the U2U relay, including an updated protected DDS.
[098] In one example, when the U2U relay receives information from an end UE, including a protected DDS, the U2U relay can send the end UE a message including a time value for a next announcement opportunity. The end UE can then send an updated protected DDS to the U2U relay during the next announcement opportunity.
[099] In one example, the U2U relay may include discovery scheduling assistance information in discovery announcement messages. Discovery scheduling assistance information may include information about announcement opportunities. This may be, for example, the time offset (from the current time) until the next announcement. This may include, for example, a setting for recurring announcement opportunities, including start time, end time, and the frequency of these opportunities.
[0100] Each RSC can have more than one ProSe service (e.g., ProSe restricted codes) associated with it. The user information ID assigned to end UEs is unique only for each ProSe service; that is, the same user information ID can be assigned to different end UEs using different services. Different services can be associated with the same RSC. Consequently, more than one IP address can be associated with the same user information ID. Because the relay saves the user information ID and IP address / prefix information in a table to be able to respond to DNS queries, when the relay receives a DNS query message, which includes an ID of Petition 870250084263, dated 09 / 18 / 2025, pp. 37 / 63 33 / 44 user information, it finds the user information ID in the table and sends back a DNS response message, including the corresponding IP address / prefix information. In this case, there may be more than one entry in the table associated with the same user information ID. In order to be able to identify user information IDs received from different end UEs and associated with different end UEs when receiving a DNS Query message, the U2U relay may use the ProSe restricted code associated with the service, in addition to the user information ID. In other words, each unique pair of ProSe restricted code and user information ID may have its own IP address / prefix information.
[0101] An end UE connected to the U2U relay can probe (e.g., using a DNS query) the relay for IP address / prefix information of other end UEs based on an end UE user information ID that it may possess. This can provide the end UE with a malicious means of bypassing restricted discovery authorization and the ability to track whether a specific end UE is connected to the U2U relay. To mitigate this risk, it is desirable to ensure that IP address / prefix information is shared only with authorized end UEs.In other words, the goal is to ensure that the U2U relay shares IP address / prefix information from endpoint A with endpoint B only if endpoint B is authorized for restricted discovery with endpoint A using the same ProSe restricted code as the unique pair of ProSe restricted code and user information ID associated with the IP address / prefix information of interest.
[0102] In one example, during a link establishment procedure, a U2U relay may receive, from a first end UE, a Direct Connection Request (DCR) message including an RSC and a first ProSe restricted code. The U2U relay may store the ProSe restricted code in the context associated with the first end UE (PC5 link, DNS entry). The U2U relay may Petition 870250084263, dated 09 / 18 / 2025, pp. 38 / 63 34 / 44 send a Direct Connection Acceptance (DCA) message to the first UE end, confirming that “IP sharing protection” is enabled for the first UE end. By having “IP sharing protection” enabled, the U2U relay ensures that it will only share the IP address / prefix information of the first UE end with a second UE end if the second UE end is authorized for restricted discovery with the first ProSe restricted code.
[0103] During the DNS resolution procedure, the U2U relay may receive a DNS Query message from the second end UE including the user information ID of the second end UE and a second ProSe restricted code. The U2U relay may verify if the second ProSe restricted code matches the first ProSe restricted code. The U2U relay may send a DNS Reply message to the second end UE including IP address / prefix information of the first end UE only if the second ProSe restricted code is the same as the first ProSe restricted code.
[0104] Figure 6 shows an example of a call flow for a U2U relay direct link establishment procedure with support for discovery of the Model A U2U relay using multiple key sets and IP sharing privacy;
[0105] End UEs can be provisioned by a DDNMF, PCF, or PKMF with an RSC-associated security material and a DDS-associated security material 601, 602. The DDS security material can include a ProSe restricted code and the associated key material. A U2U relay can be provisioned by a PCF or PKMF with an RSC-associated security material 603. The U2U relay and end UEs can be configured with an RSC-associated flag indicating whether the RSC supports protected DDS. The flag can also indicate whether the use of protected DDS is mandatory for the RSC, for example, whether the RSC can operate without protected DDS. Petition 870250084263, dated 09 / 18 / 2025, pp. 39 / 63 35 / 44
[0106] The end UE can send a Direct Connection Request (DCR) message to the U2U relay, including an RSC, the end UE user information ID, and the ProSe 604 restricted code. The end UE can provide an indication for DDS protection. The end UE can provide a validity time value for the ProSe restricted code (e.g., based on the corresponding validity time value configured by PCF / DDNMF on the end UE). The ProSe restricted code can be used by the U2U relay to determine if a specific end UE is subject to IP sharing privacy protection and / or to allow disambiguation of the end UE user information ID (when there are multiple entries).
[0107] Parameters in the DCR message, such as RSC, End UE User Information ID, and ProSe Restricted Code, can be protected (e.g., for confidentiality, integrity, and against replay) using the security material associated with the RSC. An indication of protected DDS support can be provided instead of a ProSe Restricted Code. The indication can be provided to prevent the exposure of a specific ProSe Restricted Code and / or the unauthorized linking of the ProSe Restricted Code with the End UE User Information ID (e.g., if the identifying parameters are not protected for confidentiality in the DCR message). The indication can be used by the U2U relay to determine if the End UE can have at least one protected forward discovery set to be advertised by the U2U relay.
[0108] Upon receiving the DCR message including the ProSe restricted code / DDS protection indication, the U2U relay can verify whether the RSC supports DDS 605 protection based on the indicator described above.
[0109] The U2U relay and the end UE can establish security for the PC5 606 link. The U2U relay can store the ProSe restricted code / indication for DDS protection along with the end UE user information ID. Petition 870250084263, dated 09 / 18 / 2025, pp. 40 / 63 36 / 44 in the context of the PC5 link 607. The U2U relay can send the end UE a Direct Connection Acceptance (DCA) message 608, including a time value for a future opportunity for the end UE U2U relay to announce protected DDS(s).
[0110] Figure 7 shows an example of a call flow for a U2U relay direct link modification procedure to enable support for U2U Model A relay discovery using multiple key sets and IP sharing privacy.
[0111] The end UE may have an established link with the U2U 701 relay. The end UE may send a Link Modification Request (LMR) message to the U2U 702 relay, including a ProSe restricted code (e.g., to add another ProSe service reusing the existing link or to securely provide the ProSe restricted code if it was not sent in the DCR, for example, if an indication was provided during link establishment instead of a ProSe restricted code). The end UE may provide an indication for DDS protection and validity time value, as described above for the DCR case. The provided ProSe restricted code may be used by the U2U relay to determine if a specific end UE is subject to IP sharing privacy protection and / or to allow disambiguation of the end UE user information ID (when there are multiple entries).
[0112] A LMR can be initiated by the end UE to activate DDS protection for the end UE and / or for a specific ProSe service subject to DDS protection (e.g., existing ProSe services on the PC5 link are not subject to DDS protection and the end UE wishes to activate it). The LMR can be initiated by the end UE to revoke a restricted ProSe code after a discovery update procedure, where the DDNMF revokes a previously allocated restricted ProSe code. An indication to revoke a restricted ProSe code can be included in this case. If a new code is Petition 870250084263, dated 09 / 18 / 2025, pp. 41 / 63 37 / 44 allocated by the DDNMF for the final UE to replace the old code, the LMR may include an old and a new restricted ProSe code value, as well as new validity time parameters.
[0113] Upon receiving the DCR message including the restricted ProSe code / indication for DDS protection, the U2U relay can verify, based on the associated indicator, whether the RSC supports protected DDS 703.
[0114] The U2U relay can store the ProSe restriction code / indication for DDS protection along with existing end UE information in the context of the PC5 704 link. Alternatively, the U2U relay can remove or replace the ProSe restriction code if it needs to be revoked or replaced (as indicated above). The U2U relay can decide to release the direct link if all end UE ProSe restriction codes are removed, with no other ProSe service in use.
[0115] The U2U relay can send the end UE a Link Modification Acceptance (LMA) message, including an announcement time value for a future announcement opportunity by the U2U relay of protected DDS(s) from the end UE (e.g., if DDS protection has been enabled for the ProSe service(s) used on this link) 705. If the U2U relay has revoked the last ProSe restriction code for the end UE, the U2U relay can include an indication to cancel any pending protected DDS timer.
[0116] The U2U relay can also invalidate a stored restricted ProSe code when the corresponding validity timer expires. The U2U relay can decide to release the direct link with the final UE if all restricted ProSe codes of the final UE have expired, with no other ProSe service in use.
[0117] Figure 8 shows an example of a call flow for a U2U relay DNS query with IP sharing privacy. Petition 870250084263, dated 09 / 18 / 2025, pp. 42 / 63 38 / 44
[0118] Final UE 1 may perform a direct link establishment procedure with the U2U 801 relay. Final UE 2 may have established a secure connection with the U2U 802 relay (e.g., using a direct link establishment procedure).
[0119] The U2U relay can receive from UE final 2 a DNS query including the user information ID of UE final 1 and the ProSe restricted code used to discover UE final 1 803.
[0120] The U2U relay can check if there is an entry for the user information ID of the end UE 1 and has received the ProSe restricted code 804. There may be multiple entries for the same user information ID. The ProSe restricted code is used to select the specific entry (i.e., retrieve the unique pair of ProSe restricted code and user information ID). The U2U relay can check if the validity timer of the ProSe restricted code has not expired. The U2U relay can send to the end UE 2 a DNS Response including IP address / prefix information of the end UE 1 805, if the previous check is successful.
[0121] Figure 9 shows an example of a call flow for the U2U Model A relay discovery procedure initiated by the U2U relay using multiple sets of keys.
[0122] Final UE 1 can perform a direct link establishment procedure with the U2U 901 relay. The U2U relay can decide to advertise connected or discovered UEs 902.
[0123] For each of the restricted Prose codes stored for the final UE 1, the U2U relay can send a PC5 signaling message request (PC5-S) message, including the previously received restricted Prose code from the final UE 1, to request a corresponding protected DDS 903. A new PC5-S signaling message can be defined or an existing PC5 message can be... Petition 870250084263, dated 09 / 18 / 2025, pp. 43 / 63 Version 39 / 44 has been enhanced to include new necessary information, such as the "keep alive" message, which can be reused for a protected DDS request associated with a restricted ProSe code.
[0124] In one example, the U2U relay can send a PC5-S request message, including an indication to request all applicable protected DDSs for all services (e.g., UE final 1 is using several different ProSe services subject to ProSe service protection). In another example, the U2U relay can send a list of restricted ProSe codes.
[0125] Final UE 1 can generate a secure PC5-S reply message (e.g., keep-alive message) including RSC and a protected DDS using the forward discovery security material 904. Final UE 1 can include one or more DDSs in the reply message (e.g., if the request includes a list of Prose restricted codes). Final UE 1 can protect the PC5-S message using the PC5 link security context and send it to the U2U relay.
[0126] The U2U relay can process the security of the PC5-S reply message and extract the protected DDS(s). The U2U relay can verify if the ProSe restricted code of the received protected DDS is valid (e.g., based on the validity time value, verify if the validity timer has not expired). The U2U relay can send a protected discovery message from the U2U relay, including RSC, U2U relay user information ID, and the received protected DDS(s) from final UE 1 to final UE 2 905. The U2U relay can protect the U2U relay discovery message using the security material associated with the RSC.
[0127] Figure 10 shows an example of a call flow for a U2U Model A relay discovery procedure initiated by the final UE using multiple sets of keys.
[0128] The final EU 1 can perform an establishment procedure Petition 870250084263, dated 09 / 18 / 2025, pp. 44 / 63 40 / 44 direct link with the U2U 1001 relay. The final UE 1 may decide to provide the U2U relay with one or more protected DDSs 1002. This may be triggered based on the time-of-advertisement value provided by the U2U relay, as described above (e.g., in DCA or LMA).
[0129] Final UE 1 can generate a U2U relay discovery announcement message including RSC, U2U relay user information ID, and one or more DDSs, each protected using its respective security material associated with DDS 1003. Final UE 1 can protect the U2U relay discovery message using the security material associated with the RSC and send it to the U2U relay. The destination L2 ID can be set to the L2 ID of the U2U relay discovered by Final UE 1, or using a conventionally configured default L2 ID.
[0130] Alternatively, in 1004, final UE 1 can generate a secure PC5-S request message (unicast) (for example, a keep-alive request message, or a new PC5-S message can be defined) including RSC and one or more DDS(s), each protected using its respective security material associated with the DDS. Final UE 1 can protect the PC5-S message using the security context of the PC5 link and send it to the U2U relay.
[0131] The U2U relay can process the U2U relay discovery message security / PC5-S request and extract the included protected DDS 1005.
[0132] The U2U relay can check if the RSC supports protected DDS and the validity of the ProSe restricted code(s) of the received protected DDS(s) 1006. The U2U relay can check if each received code corresponds to a stored ProSe restricted code for the final UE 1 and if it is not expired (e.g., based on the validity time value as described above).
[0133] For the alternative case of the PC5 S 1004 message, the relay Petition 870250084263, dated 09 / 18 / 2025, pp. 45 / 63 41 / 44 U2U can send the final UE 1 a secure PC5-S reply message (e.g., keep alive reply message, or a new PC5-S can be set), including a reply status for the announcement (e.g., success or failure) 1007. The reply may include the relevant ProSe restricted code(s).
[0134] The U2U relay can send a protected U2U relay discovery message, including RSC, U2U relay user information ID, and the protected DDS(s) received from final UE 1 to final UE 2 1008. The U2U relay can protect the U2U relay discovery message using the security material associated with the RSC.
[0135] Figure 11 shows an example of a call flow for a U2U Model A relay discovery procedure initiated by the U2U relay with deferred announcement of the discovered final UE.
[0136] Final UE 1 may decide to send a discovery announcement message to U2U relay 1101. The final UE may monitor previous discovery announcement messages sent by U2U relay to determine the next scheduled announcement opportunity for U2U relay. For example, U2U relay may include, in the discovery announcement messages, discovery scheduling assistance information to inform the next final UE(s) about the next announcement opportunity from U2U relay (e.g., expressed as an offset / time window relative to the current time or the time of transmission of the discovery message).The end UE can use this information to schedule / synchronize the transmission of its own discovery messages to the relay in a timely manner, so as to allow the relay to include the end UE's protected DDS in its next relay announcement message (e.g., near real-time, before the relay's next U2U transmission).
[0137] The final UE 1 can generate a discovery announcement message. Petition 870250084263, dated 09 / 18 / 2025, pp. 46 / 63 42 / 44 U2U relay including RSC, U2U relay user information ID and a protected DDS using direct discovery security material and a validity time value of 1102. The validity time value can be set so as not to exceed a maximum range tolerated by time-based replay protection. For example, the validity time value can be set so as not to exceed the maximum time held by the UTC-based LSB counter (e.g., 2, 4, or 16 seconds).
[0138] The U2U relay can process the U2U relay discovery message / PC5-S request and extract the protected DDS and the validity time value 1103. The U2U relay can check if the RSC supports protected DDS.
[0139] The U2U relay can schedule the next announcement for the protected DDS of the final UE according to its own scheduled next announcement opportunity (e.g., based on implementation) and can consider the received validity time value 1104. For example, if the time difference between the next scheduled announcement opportunity is greater than the validity time value (or if no validity time value is provided), the U2U relay can decide to send a protected DDS from final UE 1 immediately (or discard the current discovery message from final UE 1 until a more suitable / aligned relay announcement opportunity is found).
[0140] The U2U relay can send a protected U2U relay discovery message including RSC, U2U relay user information ID, and the protected DDS received from UE ending 1 1105 at the scheduled time. The U2U relay can protect the U2U relay discovery message using the security material associated with the RSC.
[0141] In one example, a U2U relay can be configured with a security material associated with the RSC and end UEs can be configured with a security material associated with the RSC and a security material associated Petition 870250084263, dated 09 / 18 / 2025, pp. 47 / 63 43 / 44 to DDS. The security material associated with DDS can be associated with a ProSe restricted code. The U2U relay and end UEs can be configured with an indicator associated with the RSC, indicating whether the RSC supports protected DDS.
[0142] In one example, a U2U relay can send a request message for a protected DDS to a connected end UE. The request message can include a ProSe restricted code. The U2U relay can receive a reply message from the connected end UE. The reply message can include the requested protected DDS. The message can also include a message type, the ProSe restricted code associated with the DDS, a UTC-based counter, a MIC, and an information ID of the protected end UE. In another example, an end UE can send a discovery message from the U2U relay including a protected DDS. The U2U relay can send a discovery announcement including the received protected DDS.
[0143] Although the resources and elements are described above in specific combinations, a professional with average skill in the art will understand that each resource or element can be used in isolation or in any combination with the other resources and elements. Furthermore, the methods described in the present invention can be implemented in a computer program, software, or firmware embedded in a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted by wired or wireless connections) and computer-readable storage media.Examples of computer-readable storage media include, but are not limited to, read-only memory (ROM), random-access memory (RAM), a register, cache memory, semiconductor memory devices, magnetic media such as internal hard drives and removable disks, magneto-optical media, and optical media such as CD-ROMs and digital versatile discs (DVDs). A processor in association with software may also be... Petition 870250084263, dated 09 / 18 / 2025, pp. 48 / 63 44 / 44 is used to implement a radio frequency transceiver for use in a WTRU, UE, terminal, base station, RNC, or any host computer. Petition 870250084263, dated 09 / 18 / 2025, pp. 49 / 63
Claims
1 / 3 CLAIMS 1. A method implemented by a wireless transmit / receive unit (WTRU) operating as a user equipment (UE) to UE relay, the method CHARACTERIZED in that it comprises: receiving, from a first UE end, a first message, the first message comprising a first protected Direct Discovery Set (DDS), wherein the first DDS includes at least one user information identifier (user information ID) of the first UE end and the first protected DDS is protected using the first security material that is associated with a first Proximity Service (ProSe) service;to receive, from a second end UE, a second message, the second message comprising a second protected Direct Discovery Set (DDS), wherein the second protected DDS includes at least one second user information ID from the second end UE and the second protected DDS is protected using a second security material that is associated with a second Proximity Service (ProSe) service; and to broadcast a third message, wherein: the third message comprises the first protected DDS, the second protected DDS and a relay service code (RSC) associated with a relay connectivity service provided by WTRU; and the third message is protected using a third security material that is associated with the RSC.
2. Method according to claim 1, characterized in that the first end UE is provisioned with the first safety material and the second end UE is provisioned with the second safety material.
3. Method, according to claim 1, CHARACTERIZED in that the WTRU, the first final UE and the second final UE are provisioned with the Petition 870250080958, dated 09 / 09 / 2025, page 16 / 18 2 / 3 third security material.
4. Method, according to claim 1, CHARACTERIZED by the fact that the verification, in the WTRU, based on a configured indication, that the relay connectivity service provided by the WTRU supports relay operation with protected DDS.
5. Method according to claim 4, CHARACTERIZED in that the configured indication is configured by a network and uses RRC signaling.
6. Method according to claim 4, CHARACTERIZED in that the configured indication is pre-provisioned in the WTRU.
7. Wireless transmit / receive unit (WTRU) configured to implement a UE-to-UE relay functionality, the WTRU CHARACTERIZED in that it comprises at least one processor and one transceiver, wherein the at least one processor and one transceiver are configured to: receive, from a first UE end, a first message, the first message comprising a first protected Direct Discovery Set (DDS), wherein the first DDS includes at least one User Information Identification (User Information ID) of the first UE end and the first protected DDS is protected using the first security material that is associated with a first Proximity Service (ProSe) service;to receive, from a second end UE, a second message, the second message comprising a second protected Direct Discovery Set (DDS), wherein the second protected DDS includes at least one second user information ID of the user of the second end UE and the second protected DDS is protected using a second security material that is associated with a second Proximity Service (ProSe) service; and to broadcast a third message, wherein: Petition 870250080958, dated 09 / 09 / 2025, page 17 / 18 3 / 3 the third message comprises the first protected DDS, the second protected DDS and a relay service code (RSC) associated with a relay connectivity service provided by WTRU; and the third message is protected using a third security material associated with the RSC.
8. WTRU, according to claim 7, CHARACTERIZED in that the first end UE is provisioned with the first security material and the second end UE is provisioned with the second security material.
9. WTRU, according to claim 7, CHARACTERIZED in that the first end UE and the second end UE are provisioned with the third safety material.
10. WTRU, according to claim 7, CHARACTERIZED in that at least one processor and transceiver are additionally configured to verify, based on a configured indication, whether the relay connectivity service provided by WTRU supports relay operation with protected DDS.
11. WTRU, according to claim 9, CHARACTERIZED in that the configured indication is configured by a network and uses RRC signaling.
12. WTRU, according to claim 9, CHARACTERIZED by the fact that the configured indication is pre-provisioned in the WTRU. Petition 870250080958, dated 09 / 09 / 2025, p. 18 / 18