Method and apparatus for verifying mobile device communications
By dividing the certificate into multiple segments and embedding them in frames for transmission, combined with certificate verification, the problem of message authenticity and integrity verification in wireless communication networks is solved, achieving more efficient communication security.
Patent Information
- Application Number
- CN202180022682.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-03-30
- Filing Date
- 2021-03-31
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2041-03-31
AI Technical Summary
In wireless communication networks, as the number of mobile devices increases, it becomes difficult for receivers to verify the authenticity and integrity of sent communication messages.
The certificate is divided into multiple certificate segments and embedded into multiple frames to be sent in a periodic sequence. The certificate is used for verification in combination with the receiver verifying the authenticity of the broadcast remote identity.
The efficiency of authenticity and integrity verification of communication messages is improved, ensuring the reliability and security of communications.
Smart Images

Figure CN115315981B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to and the benefit of U.S. Provisional Application No. 63 / 008,440, filed on April 10, 2020, entitled “Methods and Apparatus for Verifying UAV Communications,” and U.S. Patent Application No. 17 / 217,386, filed on March 30, 2021, entitled “Method and Apparatus for Verifying Mobile Device Communications,” and the entire contents of both applications are incorporated herein by reference. Technical Field
[0003] Generally speaking, aspects of the present disclosure relate to wireless communications, and more particularly, aspects of the present disclosure relate to apparatus and methods for verifying communication messages sent by a mobile device, such as an unmanned aerial vehicle (UAV) or other mobile device. Background Art
[0004] Wireless communication networks are widely deployed to provide various types of communication content, such as voice, video, packet data, messaging, broadcast, and so on. These systems may be multiple-access systems capable of supporting communication with multiple users by sharing available system resources (e.g., time, frequency, and power). Examples of such multiple-access systems include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, and single-carrier frequency division multiple access (SC-FDMA) systems.
[0005] These multiple access technologies have been adopted in various telecommunication standards to provide a common protocol that enables different wireless devices to communicate on a city-wide, national-wide, regional-wide, and even global scale. For example, the fifth generation (5G) wireless communication technology, which may be referred to as New Radio (NR), is envisioned to be used to extend and support various usage scenarios and applications for the current mobile network generation. In one aspect, 5G communication technologies may include: enhanced mobile broadband to address people-centric use cases for accessing multimedia content, services, and data; ultra-reliable low-latency communications (URLLC) with specifications for latency and reliability; and massive machine-type communications, which may allow a very large number of connected devices to transmit relatively small amounts of non-latency sensitive information. However, as the demand for mobile broadband access continues to increase, further improvements in NR communication technology and other technologies may be needed.
[0006] In a wireless communication network, a mobile device (e.g., a UAV) can send messages to receivers (e.g., other UAVs, UAV controllers, base stations, ground controllers, etc.), base stations, and / or the network. However, as the number of mobile devices in an area increases, it may become difficult for the receiver to verify the authenticity and integrity of the sent communication messages. Summary of the Invention
[0007] To provide a basic understanding of one or more aspects of the present invention, a brief summary of these aspects is provided below. This summary is not an exhaustive overview of all contemplated aspects, nor is it intended to identify key or critical elements of all aspects, or to describe the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the detailed description that follows.
[0008] Aspects of the present disclosure include methods for: obtaining at least one certificate; segmenting the at least one certificate into a plurality of certificate segments; embedding the plurality of certificate portions into corresponding frames in a plurality of frames; and sequentially transmitting the plurality of frames in a cycle.
[0009] Other aspects of the present disclosure include a mobile device having a memory containing instructions, a transceiver, and one or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to execute the instructions in the memory to: obtain at least one certificate; segment the at least one certificate into a plurality of certificate segments; embed the plurality of certificate portions into corresponding frames in a plurality of frames; and transmit the plurality of frames sequentially in a cycle.
[0010] One aspect of the present disclosure includes a mobile device comprising: a unit for obtaining at least one certificate; a unit for segmenting the at least one certificate into a plurality of certificate segments; a unit for embedding the plurality of certificate portions into corresponding frames in a plurality of frames; and a unit for sequentially sending the plurality of frames in a cycle.
[0011] Some aspects of the present disclosure include a non-transitory computer-readable medium having instructions stored therein that, when executed by one or more processors of a mobile device, cause the one or more processors to: obtain at least one certificate; segment the at least one certificate into a plurality of certificate segments; embed the plurality of certificate portions into corresponding frames in a plurality of frames; and sequentially transmit the plurality of frames in a cycle.
[0012] Aspects of the present disclosure include a method for a receiver to: receive a broadcast remote identification from a mobile device having a mobile device identification; receive a certificate associated with the mobile device identification; and verify the authenticity of the broadcast remote identification using the certificate.
[0013] Other aspects of the present disclosure include a receiver having a memory containing instructions, a transceiver, and one or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to execute the instructions in the memory for: receiving a broadcast remote identification from a mobile device having a mobile device identification; receiving a certificate associated with the mobile device identification; and using the certificate to verify the authenticity of the broadcast remote identification.
[0014] One aspect of the present disclosure includes a receiver comprising: means for receiving a broadcast remote identification from a mobile device having a mobile device identification; means for receiving a certificate associated with the mobile device identification; and means for verifying the authenticity of the broadcast remote identification using the certificate.
[0015] Some aspects of the present disclosure include a non-transitory computer-readable medium having instructions stored therein, which, when executed by one or more processors of a receiver, cause the one or more processors to perform the following operations: receiving a broadcast remote identification from a mobile device having a mobile device identification; receiving a certificate associated with the mobile device identification; and using the certificate to verify the authenticity of the broadcast remote identification.
[0016] Aspects of the present disclosure include methods for a base station (BS) to: receive a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and send the certificate.
[0017] Other aspects of the present disclosure include a base station (BS) having a memory containing instructions, a transceiver, and one or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to execute the instructions in the memory for: receiving a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and sending the certificate.
[0018] One aspect of the present disclosure includes a base station (BS) comprising: means for receiving a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and means for sending the certificate.
[0019] Some aspects of the present disclosure include a non-transitory computer-readable medium having instructions stored therein, which, when executed by one or more processors of a base station (BS), cause the one or more processors to perform the following operations: receive a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and send the certificate.
[0020] To accomplish the foregoing and related ends, one or more aspects comprise the features fully described below and particularly pointed out in the claims. The following description and the accompanying drawings describe in detail certain exemplary features of one or more aspects. However, these features are merely illustrative of the various ways in which the principles of these various aspects may be employed, and this description is intended to include all such aspects and their equivalents. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The disclosed aspects of the present invention are described below in conjunction with the accompanying drawings, which are provided to illustrate and not to limit the disclosed aspects, wherein like reference numerals represent like elements, and wherein:
[0022] Figure 1 is a diagram illustrating an example of a wireless communication system and an access network;
[0023] Figure 2 is a schematic diagram of an example of a user device such as a mobile device or a UAV;
[0024] Figure 3 is a schematic diagram of an example of a base station;
[0025] Figure 4 is a schematic diagram of an example of an environment for managing a UAV;
[0026] Figure 5 is a sequence diagram of an example of a process for a UAV to distribute certificates;
[0027] Figure 6A is a sequence diagram of an example of the initialization process of a UAV to a network;
[0028] Figure 6B is a sequence diagram of a first example of a process in which a base station distributes certificates;
[0029] Figure 6C is a sequence diagram of a second example of a process for a base station to distribute certificates;
[0030] Figure 6D is a sequence diagram of an example of a process for a receiver to obtain a certificate;
[0031] Figure 6E is a sequence diagram of an example of a process in which a base station broadcasts a certificate;
[0032] Figure 7 is a process flow diagram of an example of a method for sending credentials by a mobile device;
[0033] Figure 8 is a process flow diagram of an example of a method for a receiver to perform authentication; and
[0034] Figure 9 is a process flow diagram of an example of a method for distributing certificates by a base station. DETAILED DESCRIPTION
[0035] The detailed description below, in conjunction with the accompanying drawings, is intended only to illustrate various configurations and is not intended to represent that the concepts described herein can be implemented only in these configurations. The detailed description includes specific details to provide a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts can be implemented without these specific details. In some instances, to avoid obscuring these concepts, well-known structures and components are shown in block diagram form.
[0036] Some aspects of telecommunications systems will now be presented with reference to various apparatuses and methods. These apparatuses and methods will be described in the following detailed description and depicted in the accompanying drawings by various blocks, components, circuits, processes, algorithms, and the like (collectively, "elements"). Such elements may be implemented using electronic hardware, computer software, or any combination thereof. Whether these elements are implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system.
[0037] For example, an element or any part of an element or any combination of elements can be implemented as a "processing system" including one or more processors. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, systems on chip (SoCs), baseband processors, field programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gate logic, discrete hardware circuits, and other suitable hardware configured to perform the various functions described throughout this disclosure. One or more processors in a processing system can execute software. Software should be broadly interpreted to mean instructions, instruction sets, codes, code segments, program codes, programs, subroutines, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, processes, functions, etc., regardless of whether they are referred to as software, firmware, middleware, microcode, hardware description languages, or other terms.
[0038] Therefore, in one or more exemplary embodiments, the functions described herein can be implemented with hardware, software or any combination thereof. When implemented using software, these functions can be stored or encoded into one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media. The storage medium can be any available medium that a computer can access. By way of example and not limitation, such computer-readable media can include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage or other magnetic storage device, a combination of the aforementioned types of computer-readable media, or any other medium that can be used to store computer executable code in the form of instructions or data structures and can be accessed by a computer.
[0039] In one implementation, the UAV may divide the certificate into multiple parts. The UAV may embed each part of the certificate into a frame. The UAV may sequentially transmit frames containing the divided parts. The UAV may transmit a broadcast remote identifier. A recipient of the broadcast remote identifier and / or the certificate parts may append the certificate parts to the certificate for authenticating the broadcast remote identifier.
[0040] In one implementation, the broadcast remote identity may be a mobile identity (associated with a mobile device or UAV) declared during the broadcast process. In other cases, the broadcast remote identity may be a certificate associated with or containing the mobile identity. The mobile identity may be a serial number, a government-issued identifier, a universally unique identifier, and the like.
[0041] Figure 1 1 is a schematic diagram illustrating an example of a wireless communication system and access network 100. The wireless communication system (also referred to as a wireless wide area network (WWAN)) includes at least one base station (BS) 105, a user equipment (UE) 110, an evolved packet core (EPC) 160, and a 5G core (5GC) 190. The BS 105 may include a macro cell (a high-power cellular base station) and / or a small cell (a low-power cellular base station). A macro cell includes a base station. A small cell includes a femto cell, a pico cell, and a micro cell. In one implementation, the UE 110 may include a communication component 222. The communication component 222 and / or the modem 220 of the UE 110 may be configured to communicate with the BS 105 or other UEs 110 via a cellular network, a Wi-Fi network, or other wireless and wired networks. The UE 110 may include a certificate component 224 that retrieves a certificate, segments the certificate, and / or embeds the certificate segments into a frame. In some implementations, the BS 105 may include a communication component 322 configured to communicate with the UE 110.
[0042] The BS 105 configured for 4G LTE (collectively referred to as the Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN)) can be connected to the EPC 160 via a backhaul link interface 132 (e.g., S1, X2, Internet Protocol (IP), or flex interface). The BS 105 configured for 5G NR (collectively referred to as the Next Generation RAN (NG-RAN)) can interface with the 5GC 190 via a backhaul link interface 134 (e.g., S1, X2, Internet Protocol (IP), or flex interface). Among other functions, the BS 105 may also perform one or more of the following functions: transmission of user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, distribution of non-access stratum (NAS) messages, NAS node selection, synchronization, radio access network (RAN) sharing, multimedia broadcast multicast service (MBMS), user and device tracking, RAN information management (RIM), paging, positioning, and transmission of warning messages. The BSs 105 may communicate with each other directly or indirectly (e.g., through the EPC 160 or 5GC 190) via a backhaul link interface 134. The backhaul links 132, 134 may be wired or wireless.
[0043] BS 105 can communicate wirelessly with UE 110. Each of BS 105 can provide communication coverage for a respective geographic coverage area 130. There can be overlapping geographic coverage areas 130. For example, a small cell 105′ can have a coverage area 130′ that overlaps with the coverage area 130 of one or more macro BSs 105. A network that includes both small cells and macro cells can be referred to as a heterogeneous network. A heterogeneous network can also include a home evolved Node B (eNB) (HeNB), which can provide service to a restricted group called a closed subscriber group (CSG). The communication link 120 between BS 105 and UE 110 can include uplink (UL) (also known as reverse link) transmissions from UE 110 to BS 105 and / or downlink (DL) (also known as forward link) transmissions from BS 105 to UE 110. The communication link 120 can use multiple-input multiple-output (MIMO) antenna technology including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be through one or more carriers. BS 105 / UE 110 may use up to a total of Y xIn one embodiment, a carrier aggregation of up to Y MHz (e.g., 5, 10, 15, 20, 100, 400, etc. MHz) of spectrum bandwidth is assigned per carrier in a carrier aggregation of 100 MHz (x component carriers). These carriers may be adjacent to each other or non-adjacent to each other. The assignment of carriers may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be assigned for DL compared to UL). These component carriers may include a primary component carrier and one or more secondary component carriers. The primary component carrier may be referred to as a primary cell (PCell), and the secondary component carrier may be referred to as a secondary cell (SCell).
[0044] Some UEs 110 may communicate with each other using device-to-device (D2D) communication links 158. D2D communication links 158 may use DL / UL WWAN spectrum. D2D communication links 158 may use one or more sidelink channels, such as a physical sidelink broadcast channel (PSBCH), a physical sidelink discovery channel (PSDCH), a physical sidelink shared channel (PSSCH), and a physical sidelink control channel (PSCCH). D2D communication may be accomplished through various wireless D2D communication systems, such as FlashLinQ, WiMedia, Bluetooth, ZigBee, Wi-Fi based on IEEE 802.11 standards, LTE, or NR.
[0045] The wireless communication system may also include a Wi-Fi access point (AP) 150 that communicates with a Wi-Fi station (STA) 152 via a communication link 154 in the 5 GHz unlicensed spectrum. When communicating in the unlicensed spectrum, the STA 152 / AP 150 may perform a clear channel assessment (CCA) prior to communication to determine whether the channel is available.
[0046] The small cell 105' can operate in licensed and / or unlicensed spectrum. When operating in the unlicensed spectrum, the small cell 105' can adopt NR and use the same 5 GHz unlicensed spectrum used by the Wi-Fi AP 150. The small cell 105' adopting NR in the unlicensed spectrum can improve the coverage and / or increase the capacity of the access network.
[0047] BS 105 (whether a small cell 105′ or a large cell (e.g., a macro base station)) may include an eNB, gNodeB (gNB), or other type of base station. Some base stations, such as gNB 180, may operate in conventional sub-6 GHz (sub-6 GHz) spectrum, millimeter wave (mmW) frequencies, and / or near-mmW frequencies to communicate with UE 110. When gNB 180 operates at mmW or near-mmW frequencies, gNB 180 may be referred to as a mmW base station. Extremely high frequency (EHF) is a portion of the radio frequency (RF) band within the electromagnetic spectrum. EHF has frequencies ranging from 30 GHz to 300 GHz, with wavelengths ranging from 1 mm to 10 mm. Radio waves in this band may be referred to as millimeter waves. Near-mmW frequencies extend down to frequencies of 3 GHz, with wavelengths of 100 mm. Super high frequency (SHF) bands are between 3 GHz and 30 GHz, also known as centimeter waves. Communications using mmW / near-mmW radio frequency bands suffer from significantly higher path loss and shorter communication ranges. The mmW base station 180 may utilize beamforming 182 with the UE 110 to compensate for this path loss and short range.
[0048] EPC 160 may include a Mobility Management Entity (MME) 162, other MMEs 164, a Serving Gateway 166, a Multimedia Broadcast Multicast Service (MBMS) Gateway 168, a Broadcast Multicast Service Center (BM-SC) 170, and a Packet Data Network (PDN) Gateway 172. MME 162 may communicate with a Home Subscriber Server (HSS) 174. MME 162 is a control node that handles signaling between UE 110 and EPC 160. Generally, MME 162 provides bearer and connection management. All user Internet Protocol (IP) packets are transmitted through Serving Gateway 166, which itself is connected to PDN Gateway 172. PDN Gateway 172 provides UE IP address assignment and other functions. PDN Gateway 172 and BM-SC 170 are connected to IP Services 176. IP Services 176 may include the Internet, an intranet, an IP Multimedia Subsystem (IMS), PS streaming services, and / or other IP services. The BM-SC 170 may provide functionality for MBMS user service provisioning and delivery. The BM-SC 170 may serve as the entry point for content providers' MBMS transmissions, may be used to authorize and initiate MBMS bearer services within a public land mobile network (PLMN), and may be used to schedule MBMS transmissions. The MBMS Gateway 168 may be used to distribute MBMS services to BSs 105 belonging to a Multicast Broadcast Single Frequency Network (MBSFN) area broadcasting a specific service, and may be responsible for session management (start / stop) and collecting eMBMS-related billing information.
[0049] 5GC 190 may include an access and mobility management function (AMF) 192, other AMFs 193, a session management function (SMF) 194, and a user plane function (UPF) 195. AMF 192 may communicate with a unified data management (UDM) 196. AMF 192 is a control node that handles signaling between UE 110 and 5GC 190. Typically, AMF 192 provides QoS flow and session management. All user Internet Protocol (IP) packets are transmitted through UPF 195. UPF 195 provides UE IP address assignment, as well as other functions. UPF 195 is connected to IP services 197. IP services 197 may include the Internet, an intranet, an IP multimedia subsystem (IMS), PS streaming services, and / or other IP services.
[0050] The BS 105 may also be referred to as a gNB, a Node B, an evolved Node B (eNB), an access point, a base transceiver station, a radio base station, an access point, an access node, a radio transceiver, a Node B, an eNodeB (eNB), a gNB, a Home Node B, a Home eNodeB, a repeater, a transceiver function, a basic service set (BSS), an extended service set (ESS), a transmit reception point (TRP), or some other appropriate terminology. The BS 105 provides an access point to the EPC 160 or the 5GC 190 for the UE 110. Examples of the UE 110 include a cellular phone, a smartphone, a Session Initiation Protocol (SIP) phone, a laptop, a personal digital assistant (PDA), a satellite radio unit, a global positioning system, a multimedia device, a video device, a digital audio player (e.g., an MP3 player), a camera, a game console, a tablet device, a smart device, a wearable device, a vehicle, an electric meter, a gas pump, a large or small kitchen appliance, a healthcare device, an implant, a sensor / actuator, a display, or any other similarly functional device. Some UEs 110 may be referred to as IoT devices (e.g., parking meters, gas pumps, toasters, vehicles, heart monitors, etc.) UE 110 may also be referred to as a station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other appropriate terminology.
[0051] In some examples, UE 110 may include, be a part of, or be the same as a mobile device, UAV, UAS, etc.
[0052] refer to Figure 2, one example of an implementation of UE 110 may include a modem 220 having a communication component 222. The communication component 220 and / or the modem 220 of UE 110 may be configured to communicate with BS 105 via a cellular network, a Wi-Fi network, or other wireless and wired networks. A certificate component 224 may retrieve the certificate, segment the certificate, and / or embed the certificate segments into a frame.
[0053] In some implementations, the UE 110 may include various components, including components such as one or more processors 212 and memory 216 communicating via one or more buses 244, and a transceiver 202, which may operate in conjunction with a modem 220 and a communication component 222 to implement one or more of the functions described herein in connection with communicating with the BS 105. Furthermore, the one or more processors 212, the modem 220, the memory 216, the transceiver 202, the RF front end 288, and the one or more antennas 265 may be configured to support voice and / or data calls (simultaneously or non-simultaneously) in one or more radio access technologies. The one or more antennas 265 may include one or more antennas, antenna elements, and / or antenna arrays.
[0054] In one aspect, the one or more processors 212 may include a modem 220 that utilizes one or more modem processors. Thus, various functions associated with the communication component 222 and / or the credential component 224 may be included in the modem 220 and / or the processor 212, and in one aspect, may be performed by a single processor, while in other aspects, different ones of these functions may be performed by a combination of two or more different processors. For example, in one aspect, the one or more processors 212 may include any one or any combination of the following: a modem processor, a baseband processor, a digital signal processor, a transmit processor, a receive device processor, or a transceiver processor associated with the transceiver 202. Additionally, the modem 220 may configure the UE 110 as well as the processor 212. In other aspects, some of the features of the one or more processors 212 and / or the modem 220 associated with the communication component 222 and / or the credential component 224 may be performed by the transceiver 202.
[0055] In addition, the memory 216 can be configured to store data used herein and / or local versions of the applications 275 executed by the at least one processor 212 or the communication component 222, the certificate component 224, and / or one or more subcomponents of the communication component 222 and / or the certificate component 224. The memory 216 can include any type of computer-readable medium usable by a computer or the at least one processor 212, such as random access memory (RAM), read-only memory (ROM), tape, magnetic disk, optical disk, volatile memory, non-volatile memory, and any combination thereof. For example, in one aspect, when the UE 110 is operating the at least one processor 212 to execute one or more of the communication component 222, the certificate component 224, and / or the subcomponents, the memory 216 can be a non-transitory computer-readable storage medium storing one or more computer-executable codes and / or data associated therewith for defining the communication component 222, the certificate component 224, and / or the subcomponents thereof.
[0056] The transceiver 202 may include at least one receiver 206 and at least one transmitter 208. The receiver 206 may include hardware, firmware, and / or software code (executable by a processor) for receiving data, the code including instructions and stored in a memory (e.g., a computer-readable medium). For example, the receiver 206 may be an RF receiving device. In one aspect, the receiver 206 may receive signals transmitted by at least one BS 105. The transmitter 208 may include hardware, firmware, and / or software code (executable by a processor) for transmitting data, the code including instructions and stored in a memory (e.g., a computer-readable medium). Suitable examples of the transmitter 208 may include, but are not limited to, an RF transmitter.
[0057] In addition, in an aspect, the UE 110 may include an RF front end 288 that may communicate with one or more antennas 265 and the transceiver 202 to receive and transmit radio transmissions (e.g., wireless communications transmitted by at least one BS 105 or wireless transmissions transmitted by the UE 110). The RF front end 288 may be coupled to the one or more antennas 265 and may include one or more low noise amplifiers (LNAs) 290, one or more switches 292, one or more power amplifiers (PAs) 298, and one or more filters 296 to transmit and receive RF signals.
[0058] In one aspect, the LNAs 290 can amplify the received signal at a desired output level. In one aspect, each LNA 290 can have specified minimum and maximum gain values. In one aspect, the RF front end 288 can use one or more switches 292 to select a particular LNA 290 and its specified gain value based on the desired gain value for a particular application.
[0059] Furthermore, for example, the RF front end 288 can utilize one or more PAs 298 to amplify the signal for RF output at a desired output power level. In one aspect, each PA 298 can have a specified minimum and maximum gain value. In one aspect, the RF front end 288 can utilize one or more switches 292 to select a particular PA 298 and a specified gain value based on the desired gain value for a particular application.
[0060] In addition, for example, the RF front end 288 can use one or more filters 296 to filter a received signal to obtain an input RF signal. Similarly, in one aspect, for example, a corresponding filter 296 can be used to filter the output from a corresponding PA 298 to produce an output signal for transmission. In one aspect, each filter 296 can be coupled to a specific LNA 290 and / or PA 298. In one aspect, the RF front end 288 can use one or more switches 292 to select a transmit path or a receive path using a specific filter 296, LNA 290, and / or PA 298 based on a configuration specified by the transceiver 202 and / or processor 212.
[0061] As such, the transceiver 202 can be configured to transmit and receive wireless signals via the RF front end 288 through the one or more antennas 265. In an aspect, the transceiver can be tuned to operate at a specified frequency so that the UE 110 can communicate, for example, with one or more BSs 105 or one or more cells associated with the one or more BSs 105. In an aspect, the modem 220 can configure the transceiver 202 to operate at a specified frequency and power level based on, for example, the UE configuration of the UE 110 and the communication protocol used by the modem 220.
[0062] In one aspect, the modem 220 can be a multi-band multi-mode modem that can process digital data and communicate with the transceiver 202 so that the digital data is sent and received using the transceiver 202. In one aspect, the modem 220 can be multi-band and configured to support multiple frequency bands with a specific communication protocol. In one aspect, the modem 220 can be multi-mode and configured to support multiple operating networks and communication protocols. In one aspect, the modem 220 can control one or more components of the UE 110 (e.g., the RF front end 288, the transceiver 202) to enable the transmission and / or reception of signals from the network based on a specified modem configuration. In one aspect, the modem configuration can be based on the mode of the modem and the frequency band in use. In another aspect, the modem configuration can be based on UE configuration information associated with the UE 110, such as provided by the network.
[0063] refer to Figure 3 One example of an implementation of the BS 105 may include a modem 320 having a communication component 322, wherein the communication component 322 is configured to transmit data. The communication component 322 and / or the modem 320 of the BS 105 may be configured to communicate with the UE 110 via a cellular network, a Wi-Fi network, or other wireless and wired networks.
[0064] In some implementations, the BS 105 may include various components, including components such as one or more processors 312 and memory 316, and a transceiver 302, communicating via one or more buses 344, which may operate in conjunction with a modem 320 and a communication component 322 to implement one or more of the functions described herein related to communicating with the UE 110. Furthermore, the one or more processors 312, modem 320, memory 316, transceiver 302, RF front end 388, and one or more antennas 365 may be configured to support voice and / or data calls (simultaneously or non-simultaneously) in one or more radio access technologies.
[0065] In one aspect, the one or more processors 312 may include a modem 320 that utilizes one or more modem processors. Various functions associated with the communication component 322 may be included in the modem 320 and / or the processor 312, and in one aspect, they may be performed by a single processor, while in other aspects, different ones of these functions may be performed by a combination of two or more different processors. For example, in one aspect, the one or more processors 312 may include any one or any combination of the following: a modem processor, a baseband processor, a digital signal processor, a transmit processor, a receiving device processor, or a transceiver processor associated with the transceiver 302. Additionally, the modem 320 may configure the BS 105 as well as the processor 212. In other aspects, some of the features of the one or more processors 312 and / or the modem 320 associated with the communication component 322 may be performed by the transceiver 302.
[0066] In addition, the memory 316 can be configured to store data used herein and / or local versions of the applications 375 executed by the at least one processor 312 or the communication component 322, the determination component, and / or one or more subcomponents of the communication component 322 or the determination component. The memory 316 can include any type of computer-readable medium usable by a computer or the at least one processor 312, such as random access memory (RAM), read-only memory (ROM), tape, magnetic disk, optical disk, volatile memory, non-volatile memory, and any combination thereof. For example, in one aspect, when the BS 105 operates the at least one processor 312 to execute one or more of the communication component 322, the determination component, and / or the subcomponents, the memory 316 can be a non-transitory computer-readable storage medium storing one or more computer-executable codes and / or data associated therewith for defining the communication component 322, the determination component, and / or the subcomponents thereof.
[0067] The transceiver 302 may include at least one receiver 306 and at least one transmitter 308. The at least one receiver 306 may include hardware, firmware, and / or software code (executable by a processor), including instructions, stored in a memory (e.g., a computer-readable medium) for receiving data. For example, the receiver 306 may be an RF receiving device. In one aspect, the receiver 306 may receive signals transmitted by the UE 110. The transmitter 308 may include hardware, firmware, and / or software code (executable by a processor), including instructions, stored in a memory (e.g., a computer-readable medium) for transmitting data. Suitable examples of the transmitter 308 may include, but are not limited to, an RF transmitter.
[0068] In addition, in an aspect, the BS 105 may include an RF front end 388 that may communicate with one or more antennas 365 and the transceiver 302 to receive and transmit radio transmissions (e.g., wireless communications transmitted by other BSs 105 or wireless transmissions transmitted by the UE 110). The RF front end 388 may be coupled to the one or more antennas 365 and may include one or more low noise amplifiers (LNAs) 390, one or more switches 392, one or more power amplifiers (PAs) 398, and one or more filters 396 to transmit and receive RF signals.
[0069] In one aspect, the LNAs 390 can amplify the received signal at a desired output level. In one aspect, each LNA 390 can have a specified minimum and maximum gain value. In one aspect, the RF front end 388 can use one or more switches 392 to select a particular LNA 390 and its specified gain value based on the desired gain value for a particular application.
[0070] Furthermore, for example, the RF front end 388 can utilize one or more PAs 398 to amplify the signal for RF output at a desired output power level. In one aspect, each PA 398 can have a specified minimum and maximum gain value. In one aspect, the RF front end 388 can utilize one or more switches 392 to select a particular PA 398 and a specified gain value based on the desired gain value for a particular application.
[0071] In addition, for example, the RF front end 388 can use one or more filters 396 to filter the received signal to obtain an input RF signal. Similarly, in one aspect, for example, a corresponding filter 396 can be used to filter the output from a corresponding PA 398 to produce an output signal for transmission. In one aspect, each filter 396 can be coupled to a specific LNA 390 and / or PA 398. In one aspect, the RF front end 388 can use one or more switches 392 to select a transmit path or a receive path using a specific filter 396, LNA 390, and / or PA 398 based on a configuration specified by the transceiver 302 and / or processor 312.
[0072] As such, the transceiver 302 can be configured to transmit and receive wireless signals via the RF front end 388 through one or more antennas 365. In an aspect, the transceiver can be tuned to operate at a specified frequency so that the BS 105 can communicate, for example, with the UE 110 or one or more cells associated with one or more BSs 105. In an aspect, the modem 320 can configure the transceiver 302 to operate at a specified frequency and power level based on, for example, the base station configuration of the BS 105 and the communication protocol used by the modem 320.
[0073] In one aspect, modem 320 can be a multi-band multi-mode modem that can process digital data and communicate with transceiver 302 so that digital data is sent and received using transceiver 302. In one aspect, modem 320 can be multi-band and configured to support multiple frequency bands with a specific communication protocol. In one aspect, modem 320 can be multi-mode and configured to support multiple operating networks and communication protocols. In one aspect, modem 320 can control one or more components (e.g., RF front end 388, transceiver 302) of BS 105 to enable transmission and / or reception of signals from the network based on a specified modem configuration. In one aspect, the modem configuration can be based on the mode of the modem and the frequency band in use. In another aspect, the modem configuration can be based on the base station configuration associated with BS 105.
[0074] Go to Figure 4In one implementation, an example of an environment 400 for managing UAVs may include a mobile device 402. The mobile device 402 may include, be part of, or be the same as the UE 110. The mobile device 402 may be a UAV, an unmanned aerial vehicle system (UAS), a drone, or other device that can be controlled by a remote operator. The mobile device 402 may be operated by an operator 404 (e.g., a human operator, a machine operator, or an artificial intelligence operator). The environment 400 may include a first receiver 410a, a second receiver 410b, and a third receiver 410c. The first receiver 410a may be a third-party authorized entity (TPAE, such as a police detector, a civil / government detector, a regulatory agency, etc.). The second receiver 410b and the third receiver 410c may be mobile devices such as UAVs. Other types of receivers are also possible. The mobile device 402 may communicate with the first receiver 410a via a wireless communication link 412 such as Bluetooth, Wi-Fi, a cellular device-to-device link, or other wireless communication link. The mobile device 402 can communicate with the second receiver 410b via a D2D communication link 158 such as Bluetooth, Wi-Fi, a cellular device-to-device link, or other wireless communication link. The mobile device 402 can communicate with the third receiver 410c via a communication link 154 such as Bluetooth, Wi-Fi, a cellular device-to-device link, or other wireless communication link. Other communication links can also be used for communication.
[0075] In some implementations, the environment 400 may include a first BS 105a having a first coverage area 130a and a second BS 105b having a second coverage area 130b. The environment 400 may include a core network 430, such as Figure 1 160 or 5GC 190 in the core network. The environment 400 may include a UAV service provider (USS) 420. The USS 420 may optionally include a UAV flight management system (UFMS) 422. In some optional implementations, the UFMS 422 may be implemented in the core network 430. In other optional implementations, the UFMS 422 may be implemented in a standalone server separate from the UFMS 422. The USS 420 and / or the UFMS 422 may communicate with the first receiver 410a via a communication link 414 (e.g., WiFi, a long-range radio, a cellular link, optical fiber, etc.) or via the core network 430. The USS 420 and / or the UFMS 422 may communicate with the core network 430 via a communication interface 416 (e.g., a 5GC 190 network exposure function, an EPC 160 service capability exposure function, a 3GPP Rx interface, etc.).
[0076] In an implementation of the present disclosure, the mobile device 402 may include a remote identification (ID). The remote ID may include one or more information such as the following: UAV ID (e.g., serial number, registration number, or UAV service management unique ID), UAV type, timestamp, timestamp accuracy, operational status, operational description, latitude, longitude, geodetic altitude, takeoff altitude, position pressure altitude, vertical accuracy, horizontal accuracy, speed (north / south), speed (east / west), vertical speed, operator latitude, operator longitude, etc. The remote ID may be dynamically updated during operation of the mobile device 402. The mobile device 402 may obtain some or all of the remote ID information (e.g., UAV ID) from the USS 420 and / or the UFMS 422 via a cellular network (e.g., the first BS 105a, the second BS 105b, etc.).
[0077] In some implementations, the remote ID may include a network remote ID (NRID) and a broadcast remote ID (BRID). The NRID and / or BRID may include some or all of the remote ID information. In one example, the BRID may include the UAV ID and location information.
[0078] In one implementation, the cryptographic hash / digest of the BRID is the same as the UAV ID or the index of the UAV ID.
[0079] In one aspect of the present disclosure, the mobile device 402 may broadcast a BRID to one or more of the first receiver 410a, the second receiver 410b, and / or the third receiver 410c. To enable the first receiver 410a, the second receiver 410b, and / or the third receiver 410c to authenticate the BRID, the mobile device 402 may send (e.g., unicast, multicast, or broadcast) a certificate. The certificate may be a certificate of the mobile device 402, a certificate from a certificate authority that assigned the certificate of the mobile device 402, or a trust chain file indicating one or more levels of certificates, each level up to a root certificate or other designated authority. The mobile device 402 may split the certificate into n parts and may send the n parts of the certificate in n frames. For example, the mobile device 402 may split the certificate into 20 parts (n=20). The mobile device 402 may embed the 20 certificate partitions / segments into 20 frames and sequentially transmit the 20 frames to one or more of the first receiver 410a, the second receiver 410b, and / or the third receiver 410c. For example, frame 1 may include the first portion of the certificate, frame 2 may include the second portion of the certificate, and so on. Once the receivers (e.g., the first receiver, the second receiver, and / or the third receiver) have received all frames (e.g., 20 frames), the receivers (e.g., ...) may concatenate the various portions of the certificate (e.g., the 20 portions of the 20 frames) to generate or form a certificate (e.g., the certificate 402 of the mobile device).
[0080] In one example, using a certificate to authenticate the BRID can allow the receiver 410 to simultaneously verify the authenticity of the mobile device 402 .
[0081] In some aspects, the mobile device 402 can indicate the number of parts (or frames) of the certificate to the receivers 410a-c. For example, the mobile device 402 can split the certificate into 50 parts and embed the 50 parts into 50 frames. The mobile device 402 can indicate in the first frame (containing the first part of the certificate) that the 50 parts of the certificate will be sent. In response, the receivers 410a-c can assemble the certificate after receiving the 50 parts in the 50 frames.
[0082] In another aspect, mobile device 402 can indicate to receivers 410a-c the last frame that carries the last portion of the certificate. For example, mobile device 402 can segment the certificate into 15 portions and embed the 15 portions into 15 frames. Mobile device 402 can indicate in the 15th frame that it is the last frame carrying portions of the certificate. In response, receivers 410a-c can assemble the certificate after receiving the 15th frame (having the 15th or final portion).
[0083] In some aspects, frames carrying portions of credentials may be marked as credential frames.
[0084] In certain aspects, the number of frames used to send portions (ie, segments) of the credential may be dynamically determined based on factors such as weather conditions, traffic, regulatory requirements, the technology used for transmission, and so forth.
[0085] In some implementations, after the receivers 410a - c assemble the certificate from its parts, the receivers 410a - c can use the certificate to authenticate the BRID and / or other messages sent by the mobile device 402 .
[0086] In certain aspects, the mobile device 402 may transmit frames carrying portions of the credential at a certain periodicity. Examples of periodicity may include 50 milliseconds (ms), 100 ms, 500 ms, 1 second (s), 5 s, 10 s, 50 s, 100 s, or other durations. The periodicity may be determined by various methods described below.
[0087] In one aspect of the present disclosure, the mobile device 402 may receive a security profile (e.g., an IEEE 1609.2 security profile). The mobile device 402 may receive the security profile during installation, programming, setup, initialization, or registration of the mobile device 402. The security profile may indicate a periodicity for sending frames carrying portions of the credentials.
[0088] In another aspect of the present disclosure, the mobile device 402 may receive the periodicity value when connected to the first BS 105 a, the second BS 105 b, the UFMS 422, and / or the USS 420. For example, when the USS 420 and / or the UFMS 422 provide the UAV ID to the mobile device 402, the USS 420 and / or the UFMS 422 may send the periodicity to the mobile device 402. In other examples, when the USS 420 and / or the UFMS 422 provide the UAV ID to the mobile device 402, the periodicity may be embedded in the UAV ID.
[0089] In a different aspect, the first BS 105a serving the mobile device 402 can send the periodicity to the mobile device 402 via a radio resource configuration (RRC) message or a system information broadcast (SIB) message. The sent periodicity can be a value (e.g., 1 s, 2 s, 5 s, 10 s, 20 s, 50 s, 100 s, etc.) or an index from a set of predefined indices (e.g., 0 - never, 1 - 5 s, 2 - 10 s, 3 - 20 s, etc.).
[0090] In some aspects of the present disclosure, the first BS 105a serving the mobile device 402 can dynamically update the periodicity of the mobile device 402 via RRC messages. The first BS 105a can send an RRC message to the mobile device 402 to change the periodicity of frames used to send portions of the certificate (e.g., from 10s to 15s).
[0091] In one implementation, the periodicity may depend on the flight plan of the mobile device 402 , the geographic area along the flight plan, local / regional / national policies, traffic density, terrain interference, or other factors related to the operation of the mobile device 402 .
[0092] In some implementations, the periodicity may be adaptively based on detected environmental factors, such as RF interference from other UAV traffic, weather-related attenuation, excessive requests for credentials, etc. In certain implementations, the periodicity may be determined based on received signal strength indication (RSSI), radio frequency, one or more network or link quality of service (QoS) parameters, or other factors related to the quality of the communication channel.
[0093] In one aspect of the present disclosure, receivers 410a-c can obtain credentials from sources other than mobile device 402. In a first example, USS 420 and / or UFMS 422 can provide the credentials to core network 430. Core network 430 can determine the geographic location of mobile device 402 based on location information (e.g., latitude, longitude, altitude, etc.) in a remote ID, BRID, or NRID. Core network 430 can determine one or more coverage areas and corresponding base stations associated with the geographic location, such as first BS 105a and first coverage area 130a. After determining that mobile device 402 is within first coverage area 130a, core network 430 can provide the credentials to first BS 105a. Mobile device 402 can broadcast a BRID. After mobile device 402 broadcasts the BRID, second receiver 410b can receive the BRID from mobile device 402. Second receiver 410b can obtain information (e.g., the UAV ID of mobile device 402) from the BRID. The second receiver 410b may send a certificate request including the UAV ID to the first BS 105a (the serving base station for the second receiver 410b). In response, the first BS 105a may send a certificate response including the certificate (received earlier from the core network 430) to the second receiver 410b. The second receiver 410b may use the certificate to authenticate the BRID from the mobile device 402.
[0094] In a second example, mobile device 402 may broadcast a BRID. After mobile device 402 broadcasts the BRID, second receiver 410b may receive the BRID from mobile device 402. Second receiver 410b may obtain information from the BRID (e.g., the UAV ID of mobile device 402). Second receiver 410b may send a certificate request including the UAV ID to first BS 105a (a serving base station for second receiver 410b). In response, first BS 105a may send a certificate retrieval message (including the UAV ID of mobile device 402) to USS 420 and / or UFMS 422 (e.g., via core network 430) to request a certificate. USS 420 and / or UFMS 422 may send a certificate associated with the UAV ID of mobile device 402 to first BS 105a in a certificate transfer message. Upon receiving the certificate transfer message, first BS 105a may send a certificate response including the certificate to second receiver 410b in response to the certificate request for second receiver 410b. The second receiver 410b can use the certificate to authenticate the BRID from the mobile device 402.
[0095] In a third example, the mobile device 402 may broadcast a BRID. After the mobile device 402 broadcasts the BRID, the second receiver 410b may receive the BRID from the mobile device 402. The second receiver 410b may obtain information from the BRID, such as the UAV ID of the mobile device 402. The second receiver 410b may identify the USS 420 and / or UFMS 422 by using the UAV ID (e.g., the UAV ID may be in the format of an FQDN, and the receiver 410b may use DNS to retrieve the address of the USS and / or UFMS), and send a certificate request including the UAV ID to the USS 420 and / or UFMS 422 (e.g., via the first BS 105a and / or the core network 430). In response to receiving the certificate request, the USS 420 and / or the UFMS 422 may send a certificate response including a certificate associated with the UAV ID to the second receiver 410b (e.g., via the core network 430 and / or the first BS 105a). The second receiver 410b may use the certificate to authenticate the BRID from the mobile device 402 .
[0096] In a fourth example, USS 420 and / or UFMS 422 can provide a certificate to core network 430. Core network 430 can determine the geographic location of mobile device 402 based on location information (e.g., latitude, longitude, altitude, etc.) in the remote ID, BRID, and / or NRID. Core network 430 can determine one or more coverage areas and corresponding base stations associated with the geographic location, such as first base station 105a and first coverage area 130a. After determining that mobile device 402 is within first coverage area 130a, core network 430 can provide the certificate to first base station 105a. Upon receiving the certificate, first base station 105a can broadcast the certificate within first coverage area 130a. Second receiver 410b can receive the broadcasted certificate. Mobile device 402 can broadcast a BRID. After mobile device 402 broadcasts the BRID, second receiver 410b can receive the BRID from mobile device 402. Second receiver 410b can use the certificate to authenticate the BRID from mobile device 402. The first BS 105a and the second BS 105b can broadcast the received certificate using a cellular broadcast system with an indication of the BRID certificate, a Commercial Mobile Alert System (CMAS) with an indication of the BRID certificate, or using a multimedia broadcast / multicast system, using a public or dedicated channel for the BRID certificate (where all receivers subscribe to the channel to receive the BRID certificate).
[0097] In a fifth example, the first BS 105a can receive a certificate from the mobile device 402, the core network 430, the UFMS 422, and / or the USS 420. The first BS 105a can receive a flight / travel plan for the mobile device 402 from the core network 430, the UFMS 422, and / or the USS 420. Based on the flight plan, the first BS 105a can determine the geographic area that the mobile device 402 will enter. The first BS 105a can identify a coverage area associated with the geographic area that the mobile device 402 will enter, such as the second coverage area 130b of the second BS 105b. In response, the first BS 105a can identify the second BS 105b associated with the second coverage area 130b and send the certificate to the second BS 105b (for broadcasting to receivers in the second coverage area 130b) before the mobile device 402 enters the second coverage area 130b.
[0098] In some aspects of the present disclosure, receiver 410 can use a certificate to authenticate any message sent by mobile device 402. Once authenticated, receiver 410 can verify the authenticity and / or integrity of any message from mobile device 402. In another example, mobile device 402 can use any message as a BRID.
[0099] Go to Figure 5 In some implementations, the example sequence diagram 500 may include a UAV 502, a first receiver 504, a second receiver 506, a radio access network (RAN) 508, a core network 430, a UFMS 422, and a USS 420. The first receiver 504 and / or the second receiver 506 may be a UAV, a mobile device, a UE, a TPAE, a base station, a controller, or other devices. At 520, the UAV 502 may be configured by obtaining a UAV ID and performing credential bootstrapping (e.g., security certificates). At 522, the UAV 502 may send an RRC connection request to the RAN 508. At 524, the RAN 508 may send an RRC connection response to the UAV 502 with parameters for establishing a wireless communication link between the RAN 508 and the UAV 502. At 526, the UAV 502 may send an RRC connection complete message to the RAN 508. At 528, the RAN 508 may optionally send an RRC connection reconfiguration message to the UAV 502. The reconfiguration may change the connection and / or operating parameters of the UAV 502, such as the periodicity of sending portions of the certificate, for example. At 530, in response to completing the reconfiguration, the UAV 502 may optionally send an RRC connection reconfiguration complete message to the RAN 508.
[0100] In some implementations, at 532, the UAV 502 may broadcast a BRID received by the first receiver 504. The UAV 502 may segment the certificate into n segments (e.g., 25 segments). The UAV 502 may embed the n segments into n frames. In an alternative implementation, the UAV 502 may mark the n frames to indicate that the n frames carry the segments of the certificate. At 534-1, the UAV 502 may transmit the first frame carrying the first segment of the certificate. At 534-2, the UAV 502 may transmit the second frame carrying the second segment of the certificate, and so on. At 534-n, the UAV 502 may transmit the nth frame carrying the last segment of the certificate. The UAV 502 may transmit each of the n frames carrying the segments of the certificate at a predetermined period. For example, the USS 420 and / or the UFMS 422 may signal the periodicity at step 520 during the bootstrapping process. Alternatively, the RAN 508 signals the periodicity using an RRC configuration / reconfiguration message at steps 524 or 528. The periodicity may also be stored internally in the UAV 502 (eg, in memory, hard-coded, etc.) prior to step 520.
[0101] In an alternative implementation, the first frame may include a segment indicator indicating that the certificate includes n segments. The segment indicator may indicate to a receiving device, such as the first receiver 504, that the UAV 502 is to send n frames (and n segments of the certificate).
[0102] In another optional implementation, the nth frame may include a termination indicator indicating that the nth frame is carrying the last segment of the UAV 502's credentials.
[0103] In an alternative implementation, the UAV 502 may assign sequence numbers to the n frames corresponding to the order of the segments of the certificate. The frame carrying the first segment of the certificate may be assigned "1." The frame carrying the second segment of the certificate may be assigned "2," and so on.
[0104] In one aspect of the present disclosure, the UAV 502 may segment the certificate into a number of segment groups. The UAV 502 may sequentially embed each segment group (equal or unequal in number) into a corresponding frame for transmission. For example, the UAV 502 may segment the certificate into 50 segments. The UAV 502 may group the 50 segments of the certificate into 5 segments groups of 10 each (e.g., group 1 - segments #1-10, group 2 - segments #11-20, etc.). The UAV 502 may embed the first segment group into the first frame, the second segment group into the second frame, and so on. The UAV 502 may sequentially transmit five frames carrying the five segment groups. In some implementations, the groups may have the same number of segments or different numbers of segments.
[0105] At 536, the first receiver 504 may verify the BRID by authenticating the BRID using the concatenated certificates (as described above).
[0106] In an alternative implementation, each segment of the certificate can be associated with an identifier. For example, the UAV 502 can split the certificate into 30 segments. The UAV 502 can mark the first segment with "1", the second segment with "2", ..., and the thirtieth segment with "30". If the first receiver 504 fails to receive some of the segments (e.g., the seventeenth segment marked with the identifier "17"), the first receiver 504 can send a request to the UAV 502 to retransmit the seventeenth segment using the identifier.
[0107] At 538, the UAV 502 may wait until the broadcast timer expires. The broadcast timer may indicate the interval that the UAV 502 waits between broadcasting two BRIDs. The broadcast timer may last for 1 second, 5 seconds, 10 seconds, 50 seconds, or other suitable interval (e.g., depending on the operation of the UAV 502, the remaining battery power in the UAV 502, the operating environment, regulations, etc.).
[0108] In some implementations, at 542, the UAV 502 may broadcast a BRID received by the second receiver 506. The UAV 502 may segment the certificate into m segments (e.g., 15 segments). The UAV 502 may embed the m segments into m frames. In an alternative implementation, the UAV 502 may mark the m frames to indicate that the m frames carry segments of the certificate. At 544-1, the UAV 502 may send a first frame carrying the first segment of the certificate. At 544-2, the UAV 502 may send a second frame carrying the second segment of the certificate, and so on. At 544-m, the UAV 502 may send an mth frame carrying the last segment of the certificate. At 546, the second receiver 506 may verify the BRID by authenticating the BRID using the concatenated certificates (as described above).
[0109] In some cases, the number of segments into which the UAV 502 divides the certificate may depend on the communication link technology, the operation of the UAV 502, the battery power remaining in the UAV 502, the operating environment, regulations, etc.
[0110] Go to Figure 6A -E, in one implementation, the example of sequence diagram 600 may include a UAV 602, a first receiver 604, a second receiver 606, a first BS 105a, a second BS 105b, a core network 430, a UFMS 422, and a USS 420. The first receiver 604 and / or the second receiver 606 may be a UAV, a mobile device, a UE, a TPAE, a base station, a controller, or other device. At 620, the UAV 602 may be configured by obtaining a UAV ID and performing credential bootstrapping (e.g., a security certificate). At 622, the UAV 602 may register and / or connect to a mobile network including the first BS 105a and the second BS 105b. At 624, the UAV 602 may register with the USS 420 and / or the UFMS 422.
[0111] refer to Figure 6A and Figure 6BIn some implementations, at 630, the USS 420 may send a location subscription to the core network 430 to obtain an updated location of the UAV 602. At 632, the core network 430 may send a location report including the last known location of the UAV 602 (based on the received remote ID, NRID, or BRID). In an alternative implementation, the USS 420 may subscribe to the UFMS 422 to obtain location information from the UFMS 422. In another example, the USS 420 may obtain location information from a location service (LCS) of the communication network 100. At 634, the USS 420 and / or the UFMS 422 may send credentials associated with the UAV 602 (including the UAV ID) to the core network 430. At 636, based on the location information received from the USS 420 and the UFMS 422, the core network 430 may determine the geographic location of the UAV 602 based on the location information (e.g., latitude, longitude, altitude, etc.) in the location report. The core network 430 may determine one or more coverage areas and corresponding base stations associated with the geographic location, such as the first BS 105a and the first coverage area 130a. At 638, the core network 430 may provide a certificate to the first BS 105a and / or the second BS 105b after determining that the UAV 602 is within the first coverage area 130a.
[0112] In some implementations, at 640, the UAV 602 may broadcast a BRID. After the UAV 602 broadcasts the BRID, the first receiver 604 may receive the BRID from the UAV 602. The first receiver 604 may obtain information from the BRID, such as the UAVID of the UAV 602. At 642, the first receiver 604 may send a certificate request including the UAVID to the first BS 105a (the serving base station of the first receiver 604). In response, the first BS 105a may identify the certificate associated with the UAV ID. At 644, the first BS 105a may send a certificate response including the certificate (previously received at 638 from the core network 430) to the first receiver 604. At 646, the first receiver 604 may use the certificate to authenticate the BRID from the UAV 602.
[0113] Go to Figure 6A and Figure 6CIn some implementations, at 650, the UAV 602 may broadcast a BRID. After the UAV 602 broadcasts the BRID, the second receiver 606 may receive the BRID from the UAV 602. The second receiver 606 may obtain information from the BRID, such as the UAV ID of the UAV 602. At 652, the second receiver 606 may send a certificate request including the UAV ID to a second BS 105b (e.g., a serving base station for the second receiver 606). In response, at 654, the second BS 105b may send a certificate retrieval message (including the UAV ID of the UAV 602) to the UFMS 422 (e.g., via the core network 430) to request a certificate. Alternatively, the BS 105b may send a certificate retrieval message to the USS 420 via the UFMS to request a certificate. At 656, the USS 420 and / or the UFMS 422 may send the certificate associated with the UAV ID of the UAV 602 to the second BS 105b in a certificate transfer message. At 658, the second BS 105b, upon receiving the certificate transfer message, may send a certificate response including the certificate to the second receiver 606 in response to the certificate request for the second receiver 606. At 660, the second receiver 606 may use the certificate to verify the BRID from the UAV 602.
[0114] Go to Figure 6A and Figure 6D In some implementations, at 662, the UAV 602 may broadcast a BRID. After the UAV 602 broadcasts the BRID, the second receiver 606 may receive the BRID from the UAV 602. The second receiver 606 may obtain information from the BRID, such as the UAV ID of the UAV 602. At 664, the second receiver 606 may send a certificate request including the UAV ID to the USS 420 and / or the UFMS 422 (e.g., via the first BS 105a, the second BS 105b, and / or the core network 430). At 666, in response to receiving the certificate request, the USS 420 and / or the UFMS 422 may send a certificate response including a certificate associated with the UAV ID to the second receiver 606 (e.g., via the core network 430, the first BS 105a, and / or the second BS 105b). At 668 , the second receiver 606 may use the certificate to authenticate the BRID from the UAV 602 .
[0115] refer to Figure 6A and 6EIn one implementation, at 630, the core network 430 may send a location subscription to the USS 420 and / or the UFMS 422 to obtain an updated location of the UAV 602. At 632, the USS 420 and / or the UFMS 422 may send a location report including the last known location of the UAV 602 (based on the received remote ID, NRID, or BRID). At 634, the USS 420 and / or the UFMS 422 may send a certificate associated with the UAV 602 (including the UAV ID) to the core network 430. At 636, the core network 430 may determine the geographic location of the UAV 602 based on the location information (e.g., latitude, longitude, altitude, etc.) in the remote ID, BRID, and / or NRID. The core network 430 may determine one or more coverage areas and corresponding base stations associated with the geographic location, such as the first BS 105a and the first coverage area 130a. At 638, the core network 430 may provide the certificate to the first BS 105a via a certificate transfer message after determining that the UAV 602 is within the first coverage area 130a. At 670, the UAV 602 may broadcast a BRID. After the UAV 602 broadcasts the BRID, the first receiver 604 may receive the BRID from the UAV 602. At 672, the first BS 105a may broadcast the certificate (the certificate received from the core network 430 at 638) in the first coverage area 130a. The first receiver 604 may receive the broadcasted certificate. At 674, the first receiver 604 may use the certificate to authenticate the BRID from the UAV 602.
[0116] In one aspect of the present disclosure, a receiver requesting a certificate may store maps, directions, and / or coordinates indicating geographic locations where there is no or substantially no network signal. Before approaching these locations, the receiver may request a certificate before losing the ability to wirelessly obtain a certificate.
[0117] refer to Figure 7 , an example of method 700 for sending a certificate can be performed by one or more of the following: a processor 212, a memory 216, an application 275, a modem 220, a transceiver 202 and / or subcomponents thereof, an RF front end 288 and / or subcomponents thereof, a communication component 222, and / or a certificate component 224 of a UE 110 (e.g., a mobile device 402, a UAV 502, or a UAV 602) in a wireless communication network 100.
[0118] At block 705, method 700 may obtain at least one certificate. For example, certificate component 224 of UE 110 may obtain at least one certificate, as described above with respect to Figure 4 -6 described.
[0119] In certain implementations, the processor 212, the modem 220, the processor 212, the memory 216, the application 275, the modem 220, and / or the credential component 224 may be configured to obtain at least one credential and / or may define means for obtaining at least one credential.
[0120] At block 710, method 700 may segment the at least one certificate into a plurality of certificate segments.For example, certificate component 224 of UE 110 may segment the at least one certificate into a plurality of certificate segments, as described above.
[0121] In some implementations, the processor 212, the modem 220, the processor 212, the memory 216, the application 275, the modem 220, and / or the certificate component 224 may be configured to split the at least one certificate into a plurality of certificate segments and / or may define a unit for splitting the at least one certificate into a plurality of certificate segments.
[0122] At block 715, method 700 may embed the plurality of credential portions into corresponding frames in the plurality of frames. For example, communication component 224 of UE 110 may embed the plurality of credential portions into corresponding frames in the plurality of frames. The first credential segment may be embedded into the first frame, the second credential segment may be embedded into the second frame, and so on.
[0123] In some implementations, the processor 212, the modem 220, the processor 212, the memory 216, the application 275, the modem 220, and / or the communication component 224 may be configured to embed the plurality of credential portions into corresponding frames in the plurality of frames and / or may define means for embedding the plurality of credential portions into corresponding frames in the plurality of frames.
[0124] At block 720, method 700 may sequentially transmit the plurality of frames in a periodic manner. For example, communication component 224 of UE 110 may periodically sequentially transmit the plurality of frames. Communication component 222 may transmit the plurality of frames to transceiver 202 or transmitter 208. Transceiver 202 or transmitter 208 may convert the plurality of frames into electrical signals and transmit them to RF front end 288. RF front end 288 may filter and / or amplify the electrical signals. RF front end 288 may transmit the electrical signals as electromagnetic signals via one or more antennas 265.
[0125] In some implementations, the processor 212, the modem 220, the communication component 222, the transceiver 202, the receiver 206, the transmitter 208, the RF front end 288 and / or subcomponents of the RF front end 288 may be configured to sequentially transmit the multiple frames in a cycle and / or may define a unit for sequentially transmitting the multiple frames in a cycle.
[0126] Alternatively or additionally, method 700 may also include any of the above methods, further comprising: assigning sequence numbers to corresponding frames in the multiple frames, wherein sending the multiple frames includes: sending the multiple frames based on the sequence numbers of the multiple frames.
[0127] Alternatively or additionally, method 700 may also include any of the above methods, wherein the multiple frames include at least one of the following: the first frame of the multiple frames including the number of the multiple frames, or the last frame including an indicator indicating the end of transmission of the multiple frames (for example, the last frame containing the last certificate segmentation).
[0128] Alternatively or additionally, the method 700 may further include any of the above methods, and further include receiving the periodic value.
[0129] Alternatively or additionally, the method 700 may further include any one of the above methods, wherein receiving the value comprises: obtaining a security profile associated with the mobile device; and obtaining the value of the periodicity from the security profile.
[0130] Alternatively or additionally, method 700 may further include any one of the above methods, wherein receiving the value comprises: receiving a mobile device identification and a mobile device identification configuration parameter from a network; and obtaining the value of the periodicity from the mobile device identification configuration parameter.
[0131] Alternatively or additionally, method 700 may also include any one of the above methods, wherein receiving the value includes: dynamically receiving the value from the network via a system information broadcast message or a radio resource configuration message, wherein receiving the value includes: dynamically receiving an updated value from the network via a radio resource reconfiguration message.
[0132] Alternatively or additionally, method 700 may further comprise any of the above methods, wherein: the periodicity is determined based on received signal strength indication (RSSI), radio frequency, or one or more network or link quality of service (QoS) parameters.
[0133] Alternatively or additionally, method 700 may further include any of the above methods, wherein the mobile device is an unmanned aerial vehicle. Other examples of mobile devices include ground vehicles, fixed or mobile robotic platforms, control actuators, fixed or mobile sensing electronic devices, smart devices, and the like.
[0134] Go to Figure 8, an example of method 800 for verifying the authenticity of a BRID may be performed by a receiver. Examples of a receiver may include UE 110, UAV 502, UAV 602, or other devices.
[0135] At block 805, method 800 may receive a broadcast remote identification (BRID) from a mobile device having a mobile device identification. For example, communication component 222 of UE 110 may receive a broadcast remote identification (BRID) from a mobile device having a mobile device identification, as described above with respect to Figure 4 -6. One or more antennas 265 can receive electromagnetic signals carrying the BRID. The RF front end 288 can receive electrical signals generated from the electromagnetic signals. The RF front end 288 can filter and / or amplify these electrical signals. The transceiver 202 or the receiver 206 can receive the electrical signals from the RF front end 288, convert the electrical signals into a BRID, and transmit the BRID to the communication component 222.
[0136] In some implementations, the processor 212, the modem 220, the communication component 222, the transceiver 202, the receiver 206, the transmitter 208, the RF front end 288, and / or subcomponents of the RF front end 288 may be configured to receive a broadcast remote identification (BRID) from a mobile device having a mobile device identification and / or may define means for receiving a broadcast remote identification (BRID) from a mobile device having a mobile device identification.
[0137] At block 810, method 800 can receive a certificate associated with the mobile device identity. For example, communication component 222 of UE 110 can receive a certificate associated with the mobile device identity, as described above with respect to Figure 4 -6. One or more antennas 265 can receive electromagnetic signals carrying credentials. RF front end 288 can receive electrical signals generated from the electromagnetic signals. RF front end 288 can filter and / or amplify these electrical signals. Transceiver 202 or receiver 206 can receive the electrical signals from RF front end 288, convert these electrical signals into credentials, and transmit the credentials to communication component 222.
[0138] In some implementations, the processor 212, the modem 220, the communication component 222, the transceiver 202, the receiver 206, the transmitter 208, the RF front end 288, and / or subcomponents of the RF front end 288 may be configured to receive a certificate associated with the mobile device identity and / or may define a unit for receiving a certificate associated with the mobile device identity.
[0139] At block 815, method 800 can use the certificate to verify the authenticity of the BRID. For example, certificate component 224 of UE 110 can use the certificate to verify the authenticity of the BRID, as described above.
[0140] In some implementations, the processor 212, the modem 220, the processor 212, the memory 216, the application 275, the modem 220, and / or the certificate component 224 may be configured to verify the authenticity of the BRID using the certificate and / or may define means for verifying the authenticity of the BRID using the certificate.
[0141] In an alternative implementation, a receiver can receive authenticated messages (e.g., signed broadcast messages) instead of a BRID. The receiver can use the certificate to verify the authenticity of the authenticated message. The receiver can perform this verification without receiving the BRID. For example, the authenticated message can be a collision avoidance message. The receiver can verify the authenticity of the authenticated message without knowing the broadcaster's BRID.
[0142] Alternatively or additionally, method 800 may also include any one of the above methods, wherein receiving the certificate includes: receiving multiple frames sequentially in a cycle from the mobile device, each frame including one certificate segment of multiple certificate segments; obtaining the multiple certificate segments from the multiple frames; and connecting the multiple certificate segments based on the order of the multiple frames to generate the certificate.
[0143] Alternatively or additionally, the method 800 may further include any one of the above methods, wherein receiving the certificate includes receiving the certificate associated with the mobile device identity, wherein the certificate is broadcast by a network.
[0144] Alternatively or additionally, method 800 may also include any one of the above methods, wherein receiving the certificate includes: obtaining the mobile device identifier from the broadcast remote identifier; sending a request message including the mobile device identifier to the network to request the certificate associated with the mobile device identifier; and receiving the certificate associated with the mobile device identifier from the network.
[0145] Alternatively or additionally, the method 800 may further include any one of the above methods, wherein obtaining the mobile device identification includes calculating a cryptographic hash of the certificate.
[0146] Alternatively or additionally, the method 800 may further comprise any of the above methods, wherein a cryptographic hash of the certificate or a component of the cryptographic hash constitutes the broadcast remote identification and serves as the mobile device identification or an index to the mobile device identification.
[0147] Alternatively or additionally, the method 800 may further include any one of the above methods, further comprising: generating the mobile device identification by calculating the encrypted hash of the certificate.
[0148] Go to Figure 9 In some implementations, the method 900 for distributing certificates may be performed by one or more of: a processor 312, a memory 316, an application 375, a modem 320, a transceiver 302 and / or subcomponents thereof, an RF front end 388 and / or subcomponents thereof, and / or a communication component 322 of a BS 105 (e.g., a first BS 105a or a second BS 105b) in the wireless communication network 100.
[0149] At block 905, method 900 can receive a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network. For example, communication component 322 of UE 110 can receive a certificate associated with a mobile device having a mobile device identification (ID) from a core network, as described above with respect to Figure 4 6. One or more antennas 365 can receive electromagnetic signals carrying credentials. RF front end 388 can receive electrical signals generated from the electromagnetic signals. RF front end 388 can filter and / or amplify these electrical signals. Transceiver 302 or receiver 306 can receive the electrical signals from RF front end 388, convert the electrical signals into credentials, and transmit the credentials to communication component 322.
[0150] In some implementations, the processor 312, the modem 320, the communication component 322, the transceiver 302, the receiver 306, the transmitter 308, the RF front end 388 and / or subcomponents of the RF front end 388 may be configured to receive a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network and / or may define a unit for receiving a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network.
[0151] At block 910, method 900 may transmit the certificate. For example, communication component 322 of UE 110 may transmit the certificate. Communication component 322 may transmit the plurality of frames to transceiver 302 or transmitter 308. Transceiver 302 or transmitter 308 may convert the certificate into electrical signals and transmit them to RF front end 388. RF front end 388 may filter and / or amplify the electrical signals. RF front end 388 may transmit the electrical signals as electromagnetic signals via one or more antennas 365.
[0152] In some implementations, the processor 312, the modem 320, the communication component 322, the transceiver 302, the receiver 306, the transmitter 308, the RF front end 388, and / or subcomponents of the RF front end 388 may be configured to send the certificate and / or may define a unit for sending the certificate.
[0153] Alternatively or additionally, method 900 may also include any of the above methods, and further include: receiving a request message for the certificate associated with a mobile device identifier from one or more receivers before sending the certificate, wherein the request message includes the mobile device identifier; and wherein sending the certificate includes: sending the certificate to the one or more receivers.
[0154] Alternatively or additionally, the method 900 may further include any one of the above methods, wherein sending the certificate includes broadcasting the certificate and the mobile device identification associated with the certificate.
[0155] Alternatively or additionally, method 900 may also include any of the above methods, and further include: receiving a travel plan indicating that the mobile device is scheduled to enter a geographic area; determining a coverage area associated with the geographic area; determining one or more base stations associated with the coverage area; wherein sending the certificate includes: sending the certificate to the one or more base stations before the mobile device enters the geographic area.
[0156] Other Implementations
[0157] Aspects of the present disclosure include a method for a mobile device to obtain at least one certificate; segment the at least one certificate into a plurality of certificate segments; embed the plurality of certificate segments into corresponding frames in a plurality of frames; and sequentially transmit the plurality of frames in a cycle.
[0158] Aspects of the present disclosure include the method described above, further comprising assigning sequence numbers to corresponding frames of the plurality of frames, wherein sending the plurality of frames comprises sending the plurality of frames based on the sequence numbers of the plurality of frames.
[0159] Aspects of the present disclosure include any of the above methods, wherein the plurality of frames comprises at least one of: a first frame of the plurality of frames comprising the number of the plurality of frames, or a last frame comprising an indicator indicating an end of transmission of the plurality of frames.
[0160] Aspects of the present disclosure include any of the above methods, further comprising: receiving the periodicity value prior to sending the plurality of frames.
[0161] Aspects of the present disclosure include any of the above methods, wherein receiving the value comprises: obtaining a security profile associated with the mobile device; and obtaining the value of the periodicity from the security profile.
[0162] Aspects of the present disclosure include any of the above methods, wherein receiving the value comprises: receiving a mobile device identification and a mobile device identification configuration parameter from a network; and obtaining the value of the periodicity from the mobile device identification configuration parameter.
[0163] Aspects of the present disclosure include any of the methods above, wherein receiving the value comprises dynamically receiving the value from the network via a system information broadcast message or a radio resource configuration message.
[0164] Aspects of the present disclosure include any of the methods described above, wherein receiving the value comprises dynamically receiving an updated value from the network via a radio resource reconfiguration message.
[0165] Aspects of the present disclosure include any of the above methods, wherein the periodicity is determined based on a received signal strength indication (RSSI), radio frequency, or one or more network or link quality of service (QoS) parameters.
[0166] Aspects of the present disclosure include any of the above methods, wherein the mobile device is an unmanned aerial vehicle, a ground vehicle, a fixed or mobile robotic platform, a control actuator, or a sensing electronic device.
[0167] Aspects of the present disclosure include any of the above methods, wherein the at least one certificate includes a trust chain file indicating one or more levels of certificates.
[0168] Other aspects of the present disclosure include a mobile device having a memory containing instructions, a transceiver, and one or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to execute the instructions in the memory for: obtaining at least one certificate; segmenting the at least one certificate into a plurality of certificate segments; embedding the plurality of certificate portions into corresponding frames in a plurality of frames; and transmitting the plurality of frames sequentially in a cycle.
[0169] Aspects of the present disclosure include the mobile device described above, wherein the one or more processors are further configured to assign sequence numbers to corresponding frames of the plurality of frames, wherein sending the plurality of frames comprises sending the plurality of frames based on the sequence numbers of the plurality of frames.
[0170] Aspects of the present disclosure include any of the above mobile devices, wherein the plurality of frames comprises at least one of: a first frame of the plurality of frames comprising the number of the plurality of frames, or a last frame comprising an indicator indicating an end of transmission of the plurality of frames.
[0171] Aspects of the present disclosure include any of the mobile devices above wherein the one or more processors are further configured to receive the periodicity value prior to transmitting the plurality of frames.
[0172] Aspects of the present disclosure include any of the above mobile devices, wherein receiving the value comprises: obtaining a security profile associated with the mobile device; and obtaining the value of the periodicity from the security profile.
[0173] Aspects of the present disclosure include any of the above mobile devices, wherein receiving the value comprises: receiving a mobile device identification and a mobile device identification configuration parameter from a network; and obtaining the value of the periodicity from the mobile device identification configuration parameter.
[0174] Aspects of the present disclosure include any of the mobile devices described above, wherein receiving the value comprises dynamically receiving the value from a network via a system information broadcast message or a radio resource configuration message.
[0175] Aspects of the present disclosure include any of the mobile devices described above, wherein receiving the value comprises dynamically receiving an updated value from the network via a radio resource reconfiguration message.
[0176] Aspects of the present disclosure include any of the mobile devices described above, wherein the periodicity is determined based on a received signal strength indication (RSSI), radio frequency, or one or more network or link quality of service (QoS) parameters.
[0177] Aspects of the present disclosure include any of the above-described mobile devices, wherein the mobile device is an unmanned aerial vehicle, a ground vehicle, a fixed or mobile robotic platform, a control actuator, or a sensing electronic device.
[0178] Aspects of the present disclosure include any of the mobile devices described above, wherein the at least one certificate includes a trust chain file indicating one or more levels of certificates.
[0179] Aspects of the present disclosure include a mobile device comprising: a unit for obtaining at least one certificate; a unit for segmenting the at least one certificate into a plurality of certificate segments; a unit for embedding the plurality of certificate segments into corresponding frames in a plurality of frames; and a unit for sequentially transmitting the plurality of frames in a period.
[0180] Aspects of the present disclosure include the mobile device described above, further comprising means for assigning sequence numbers to corresponding frames of the plurality of frames, wherein sending the plurality of frames comprises sending the plurality of frames based on the sequence numbers of the plurality of frames.
[0181] Aspects of the present disclosure include any of the above-described mobile devices, wherein the plurality of frames comprises at least one of: a first frame of the plurality of frames comprising the number of the plurality of frames, or a last frame comprising an indicator indicating an end of transmission of the plurality of frames.
[0182] Aspects of the present disclosure include any of the mobile devices described above, further comprising means for receiving the periodicity value prior to transmitting the plurality of frames.
[0183] Aspects of the present disclosure include any of the above mobile devices, wherein means for receiving the value comprises: means for obtaining a security profile associated with the mobile device; and means for obtaining the value of the periodicity from the security profile.
[0184] Aspects of the present disclosure include any of the above-described mobile devices, wherein the means for receiving the value comprises: a means for receiving a mobile device identification and a mobile device identification configuration parameter from a network; and a means for obtaining the value of the periodicity from the mobile device identification configuration parameter.
[0185] Aspects of the present disclosure include any of the mobile devices described above, wherein means for receiving the value comprises means for dynamically receiving the value from the network via a system information broadcast message or a radio resource configuration message.
[0186] Aspects of the present disclosure include any of the mobile devices described above, wherein means for receiving the value comprises means for dynamically receiving an updated value from the network via a radio resource reconfiguration message.
[0187] Aspects of the present disclosure include any of the mobile devices described above, wherein the periodicity is determined based on a received signal strength indication (RSSI), radio frequency, or one or more network or link quality of service (QoS) parameters.
[0188] Aspects of the present disclosure include any of the above-described mobile devices, wherein the mobile device is an unmanned aerial vehicle, a ground vehicle, a fixed or mobile robotic platform, a control actuator, or a sensing electronic device.
[0189] Aspects of the present disclosure include any of the mobile devices described above, wherein the at least one certificate includes a trust chain file indicating one or more levels of certificates.
[0190] Some aspects of the present disclosure include a non-transitory computer-readable medium having instructions stored therein that, when executed by one or more processors of a mobile device, cause the one or more processors to: obtain at least one certificate; segment the at least one certificate into a plurality of certificate segments; embed the plurality of certificate portions into corresponding frames in a plurality of frames; and sequentially transmit the plurality of frames in a cycle.
[0191] Aspects of the present disclosure include the non-transitory computer-readable medium described above, and further include instructions that, when executed by the one or more processors, cause the one or more processors to perform the following operations: assign sequence numbers to corresponding frames in the plurality of frames, wherein sending the plurality of frames includes: sending the plurality of frames based on the sequence numbers of the plurality of frames.
[0192] Aspects of the present disclosure include any of the above-mentioned non-transitory computer-readable media, wherein the plurality of frames includes at least one of the following: a first frame of the plurality of frames including the number of the plurality of frames, or a last frame including an indicator indicating the end of transmission of the plurality of frames.
[0193] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, further comprising instructions that, when executed by the one or more processors, cause the one or more processors to receive the periodicity value prior to transmitting the plurality of frames.
[0194] Aspects of the present disclosure include any of the above-described non-transitory computer-readable media, wherein the instructions for receiving the value include instructions for: obtaining a security profile associated with the mobile device; and obtaining the value of the periodicity from the security profile.
[0195] Aspects of the present disclosure include any of the above-mentioned non-transitory computer-readable media, wherein the instructions for receiving the value include instructions for the following operations: receiving a mobile device identification and a mobile device identification configuration parameter from a network; and obtaining the periodic value from the mobile device identification configuration parameter.
[0196] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the instructions for receiving the value include instructions for dynamically receiving the value from the network via a system information broadcast message or a radio resource configuration message.
[0197] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the instructions for receiving the value include instructions for dynamically receiving an updated value from the network via a radio resource reconfiguration message.
[0198] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the periodicity is determined based on a received signal strength indication (RSSI), radio frequency, or one or more network or link quality of service (QoS) parameters.
[0199] Aspects of the present disclosure include any of the above-described non-transitory computer-readable media, wherein the mobile device is an unmanned aerial vehicle, a ground vehicle, a fixed or mobile robotic platform, a control actuator, or a sensing electronic device.
[0200] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the at least one certificate includes a trust chain file indicating one or more levels of certificates.
[0201] Aspects of the present disclosure include a method for a receiver to: receive a broadcast remote identification from a mobile device having a mobile device identification; receive a certificate associated with the mobile device identification; and verify the authenticity of the broadcast remote identification using the certificate.
[0202] Aspects of the present disclosure include the method described above, wherein receiving the certificate comprises: periodically and sequentially receiving a plurality of frames from the mobile device, each of the plurality of frames comprising a certificate segment from a plurality of certificate segments; obtaining the plurality of certificate segments from the plurality of frames; and concatenating the plurality of certificate segments based on an order of the plurality of frames to generate the certificate.
[0203] Aspects of the present disclosure include any of the above methods, wherein receiving the certificate comprises receiving the certificate associated with the mobile device identity, wherein the certificate is broadcast by a network.
[0204] Aspects of the present disclosure include any of the above methods, wherein receiving the certificate comprises: obtaining the mobile device identifier from the broadcast remote identifier; sending a request message including the mobile device identifier to a network to request the certificate associated with the mobile device identifier; and receiving the certificate associated with the mobile device identifier from the network.
[0205] Aspects of the present disclosure include any of the above methods, wherein obtaining the mobile device identification comprises computing a cryptographic hash of the certificate.
[0206] Aspects of the present disclosure include any of the above methods, wherein a cryptographic hash of the certificate or a component of the cryptographic hash constitutes the broadcast remote identification and serves as a mobile device identification or an index to the mobile device identification.
[0207] Aspects of the present disclosure include any of the above methods, further comprising generating the mobile device identification by computing the cryptographic hash of the certificate.
[0208] Other aspects of the present disclosure include a receiver having a memory containing instructions, a transceiver, and one or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to execute the instructions in the memory for: receiving a broadcast remote identification from a mobile device having a mobile device identification; receiving a certificate associated with the mobile device identification; and using the certificate to verify the authenticity of the broadcast remote identification.
[0209] Aspects of the present disclosure include the receiver described above, wherein receiving the certificate comprises: periodically and sequentially receiving a plurality of frames from the mobile device, each of the plurality of frames comprising a certificate segment from a plurality of certificate segments; obtaining the plurality of certificate segments from the plurality of frames; and connecting the plurality of certificate segments based on an order of the plurality of frames to generate the certificate.
[0210] Aspects of the present disclosure include any of the above receivers, wherein receiving the certificate comprises receiving the certificate associated with the mobile device identity, wherein the certificate is broadcast by a network.
[0211] Aspects of the present disclosure include any one of the above-mentioned receivers, wherein receiving the certificate includes: obtaining the mobile device identity from the broadcast remote identity; sending a request message including the mobile device identity to a network to request the certificate associated with the mobile device identity; and receiving the certificate associated with the mobile device identity from the network.
[0212] Aspects of the present disclosure include any of the above receivers, wherein obtaining the mobile device identification comprises computing a cryptographic hash of the certificate.
[0213] Aspects of the present disclosure include any of the above receivers, wherein a cryptographic hash of the certificate or a component of the cryptographic hash constitutes the broadcast remote identification and is used as a mobile device identification or an index to the mobile device identification.
[0214] Aspects of the present disclosure include any of the above receivers wherein the one or more processors are further configured to generate the mobile device identification by computing the cryptographic hash of the certificate.
[0215] One aspect of the present disclosure includes a receiver comprising: means for receiving a broadcast remote identification from a mobile device having a mobile device identification; means for receiving a certificate associated with the mobile device identification; and means for verifying the authenticity of the broadcast remote identification using the certificate.
[0216] Aspects of the present disclosure include any of the above-described receivers, wherein the means for receiving the certificate comprises: a means for periodically and sequentially receiving a plurality of frames from the mobile device, each frame comprising one certificate segment from a plurality of certificate segments; a means for obtaining the plurality of certificate segments from the plurality of frames; and a means for concatenating the plurality of certificate segments based on an order of the plurality of frames to generate the certificate.
[0217] Aspects of the present disclosure include the receiver described above, wherein the means for receiving the certificate comprises means for receiving the certificate associated with the mobile device identification, wherein the certificate is broadcast by a network.
[0218] Aspects of the present disclosure include any one of the above-mentioned receivers, wherein the unit for receiving the certificate includes: a unit for obtaining the mobile device identity from the broadcast remote identity; a unit for sending a request message including the mobile device identity to a network to request the certificate associated with the mobile device identity; and a unit for receiving the certificate associated with the mobile device identity from the network.
[0219] Aspects of the present disclosure include any of the above receivers, wherein the means for obtaining the mobile device identification comprises means for computing a cryptographic hash of the certificate.
[0220] Aspects of the present disclosure include any of the above receivers, wherein a cryptographic hash of the certificate or a component of the cryptographic hash constitutes the broadcast remote identification and serves as a mobile device identification or an index to the mobile device identification.
[0221] Aspects of the present disclosure include any of the above receivers, further comprising means for generating the mobile device identification by computing the cryptographic hash of the certificate.
[0222] Some aspects of the present disclosure include a non-transitory computer-readable medium having instructions stored therein, which, when executed by one or more processors of a receiver, cause the one or more processors to perform the following operations: receiving a broadcast remote identification from a mobile device having a mobile device identification; receiving a certificate associated with the mobile device identification; and using the certificate to verify the authenticity of the broadcast remote identification.
[0223] Aspects of the present disclosure include the non-transitory computer-readable medium described above, wherein the instructions for receiving the certificate include instructions for periodically and sequentially receiving a plurality of frames from the mobile device, each frame including one of a plurality of certificate segments; obtaining the plurality of certificate segments from the plurality of frames; and concatenating the plurality of certificate segments based on an order of the plurality of frames to generate the certificate.
[0224] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the instructions for receiving the certificate include instructions for receiving the certificate associated with the mobile device identification, wherein the certificate is broadcast by a network.
[0225] Aspects of the present disclosure include any of the above-mentioned non-transitory computer-readable media, wherein the instructions for receiving the certificate include instructions for the following operations: obtaining the mobile device identity from the broadcast remote identity; sending a request message including the mobile device identity to a network to request the certificate associated with the mobile device identity; and receiving the certificate associated with the mobile device identity from the network.
[0226] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the instructions for obtaining the mobile device identification comprise instructions for computing a cryptographic hash of the certificate.
[0227] Aspects of the present disclosure include any of the above-described non-transitory computer-readable media, wherein a cryptographic hash of the certificate or a component of the cryptographic hash constitutes the broadcast remote identification and serves as a mobile device identification or an index to the mobile device identification.
[0228] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, further comprising instructions that, when executed by the one or more processors, cause the one or more processors to generate the mobile device identification by computing the cryptographic hash of the certificate.
[0229] Aspects of the present disclosure include methods for a base station (BS) to: receive a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and send the certificate.
[0230] Aspects of the present disclosure include the method described above, further comprising: receiving a request message for the certificate associated with a mobile device identifier from one or more receivers before sending the certificate, wherein the request message includes the mobile device identifier; and wherein sending the certificate includes: sending the certificate to the one or more receivers.
[0231] Aspects of the present disclosure include any of the above methods, wherein sending the certificate comprises broadcasting the certificate and the mobile device identification associated with the certificate.
[0232] Aspects of the present disclosure include any of the above methods, further comprising: receiving a travel plan indicating that the mobile device is scheduled to enter a geographic area; determining a coverage area associated with the geographic area; determining one or more base stations associated with the coverage area; and wherein sending the certificate includes: sending the certificate to the one or more base stations before the mobile device enters the geographic area.
[0233] Aspects of the present disclosure include any of the above methods, further comprising: receiving a message; and verifying the authenticity of the mobile device by successfully verifying the authenticity of the message using the certificate.
[0234] Other aspects of the present disclosure include a base station (BS) having a memory containing instructions, a transceiver, and one or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to execute the instructions in the memory for: receiving a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and sending the certificate.
[0235] Aspects of the present disclosure include the BS described above, wherein the one or more processors are further configured to: receive a request message for the certificate associated with a mobile device identifier from one or more receivers before sending the certificate, wherein the request message includes the mobile device identifier; and wherein sending the certificate includes: sending the certificate to the one or more receivers.
[0236] Aspects of the present disclosure include any of the above BSs, wherein sending the certificate comprises broadcasting the certificate and the mobile device identification associated with the certificate.
[0237] Aspects of the present disclosure include any of the above-mentioned BSs, wherein the one or more processors are further configured to: receive a travel plan indicating that the mobile device is scheduled to enter a geographic area; determine a coverage area associated with the geographic area; determine one or more base stations associated with the coverage area; and wherein sending the certificate includes: sending the certificate to the one or more base stations before the mobile device enters the geographic area.
[0238] Aspects of the present disclosure include any of the above-described BSs, wherein the one or more processors are further configured to: receive a message; and verify the authenticity of the mobile device by successfully verifying the authenticity of the message using the certificate.
[0239] One aspect of the present disclosure includes a base station (BS) comprising: means for receiving a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and means for sending the certificate.
[0240] Aspects of the present disclosure include the BS described above, further comprising: a unit for receiving a request message for the certificate associated with a mobile device identifier from one or more receivers before sending the certificate, wherein the request message includes the mobile device identifier; and wherein sending the certificate includes: sending the certificate to the one or more receivers.
[0241] Aspects of the present disclosure include any of the above BSs, further comprising: means for broadcasting the certificate and the mobile device identification associated with the certificate.
[0242] Aspects of the present disclosure include any of the above-mentioned BSs, and further include: a unit for receiving a travel plan indicating that the mobile device is scheduled to enter a geographic area; a unit for determining a coverage area associated with the geographic area; a unit for determining one or more base stations associated with the coverage area; and wherein sending the certificate includes: sending the certificate to the one or more base stations before the mobile device enters the geographic area.
[0243] Aspects of the present disclosure include any of the above BSs, further comprising: means for receiving a message; and means for verifying the authenticity of the mobile device by successfully verifying the authenticity of the message using the certificate.
[0244] Some aspects of the present disclosure include a non-transitory computer-readable medium having instructions stored therein, which, when executed by one or more processors of a base station (BS), cause the one or more processors to perform the following operations: receive a certificate or a component of a certificate associated with a mobile device having a mobile device identification (ID) from a core network; and send the certificate.
[0245] Aspects of the present disclosure include the non-transitory computer-readable medium described above, and further include instructions that, when executed by the one or more processors, cause the one or more processors to perform the following operations: receiving a request message for the certificate associated with a mobile device identifier from one or more receivers before sending the certificate, wherein the request message includes the mobile device identifier; and wherein sending the certificate includes: sending the certificate to the one or more receivers.
[0246] Aspects of the present disclosure include any of the non-transitory computer-readable media described above, wherein the instructions for transmitting the certificate include instructions for broadcasting the certificate and the mobile device identification associated with the certificate.
[0247] Aspects of the present disclosure include any of the above-mentioned non-transitory computer-readable media, and also include instructions that, when executed by the one or more processors, cause the one or more processors to perform the following operations: receive a travel plan indicating that the mobile device is scheduled to enter a geographic area; determine a coverage area associated with the geographic area; determine one or more base stations associated with the coverage area; and wherein sending the certificate includes: sending the certificate to the one or more base stations before the mobile device enters the geographic area.
[0248] Aspects of the present disclosure include any of the above-mentioned non-transitory computer-readable media, and also include instructions that, when executed by the one or more processors, cause the one or more processors to perform the following operations: receive a message; and verify the authenticity of the mobile device by successfully verifying the authenticity of the message using the certificate.
[0249] The specific embodiments described above in conjunction with the accompanying drawings describe some examples, but they do not represent all examples that can be implemented, nor do they represent all examples that fall within the scope of protection of the claims. As used in this specification, the word "exemplary" means "used as an example, illustration or explanation", but does not mean "more preferred" or "more advantageous" than other examples. The specific embodiments include specific details used to provide a thorough understanding of the described technology. However, these technologies can be implemented without using these specific details. The functions and arrangements of the components discussed can be changed without departing from the scope of protection of the present disclosure. In addition, various examples can omit, replace or add various processes or components as needed. For example, the described method can be performed in an order different from that described, and various steps can be added, omitted or combined. In addition, the features described with respect to certain examples can also be combined in other examples. In some instances, in order to avoid ambiguity in the concepts of the described examples, well-known structures and devices are shown in block diagram form.
[0250] It should be noted that the techniques described herein can be used in various wireless communication networks, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, and other systems. The terms "system" and "network" are often used interchangeably. A CDMA system can implement radio technologies such as CDMA 2000, Universal Terrestrial Radio Access (UTRA), and the like. CDMA 2000 covers IS-2000, IS-95, and IS-856 standards. IS-2000 versions 0 and A are commonly referred to as CDMA 2000 1X, 1X, and the like. IS-856 (TIA-856) is commonly referred to as CDMA 2000 1xEV-DO, High Rate Packet Data (HRPD), and the like. UTRA includes Wideband CDMA (WCDMA) and other variants of CDMA. A TDMA system can implement radio technologies such as Global System for Mobile Communications (GSM). OFDMA systems can implement technologies such as Ultra Mobile Broadband (UMB), Evolved UTRA (E-UTRA), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDM TMRadio technologies such as UTRA and E-UTRA are part of the Universal Mobile Telecommunications System (UMTS). 3GPP LTE and Advanced LTE (LTE-A) are new versions of UMTS that use E-UTRA. UTRA, E-UTRA, UMTS, LTE, LTE-A, and GSM are described in documents from an organization called the "3rd Generation Partnership Project" (3GPP). CDMA2000 and UMB are described in documents from an organization called the "3rd Generation Partnership Project 2" (3GPP2). The techniques described herein can be used for the systems and radio technologies mentioned above as well as other systems and radio technologies (including cellular (e.g., LTE) communications on shared radio spectrum bands). However, the description herein describes an LTE / LTE-A system or a 5G system for example purposes only, and LTE terminology is used in most of the description below, but these techniques may also be applicable to other next generation communication systems.
[0251] Information and signals may be represented using any of a variety of different techniques and methods. For example, data, instructions, commands, information, signals, bits, symbols, and chips mentioned throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, computer-executable code or instructions stored on a computer-readable medium, or any combination thereof.
[0252] The various exemplary blocks and components described in conjunction with the disclosure herein may be implemented or executed using a specially programmed device, such as, but not limited to, a digital signal processor (DSP), an ASIC, an FPGA or other programmable logic device, discrete gate or transistor logic devices, discrete hardware components, or any combination thereof, for performing the functions described herein. A specially programmed processor may be a microprocessor, or the processor may be any conventional processor, controller, microcontroller, or state machine. A specially programmed processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, a combination of one or more microprocessors and a DSP core, or any other such configuration).
[0253] The functions described herein can be implemented using hardware, software (e.g., executed by a processor), firmware, or any combination thereof. When implemented using software executed by a processor, these functions can be stored on a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Other examples and implementations also fall within the scope and spirit of the present disclosure and the claims appended thereto. For example, due to the nature of software, the functions described above can be implemented using software (executed by a specially programmed processor), hardware, firmware, hardware wiring, or any combination thereof. The features used to implement the functions can be physically distributed across multiple locations, including being distributed across different physical locations to implement a portion of the functions. In addition, as used herein (including the claims), "or" (as used in a list item prefixed with "at least one of") indicates a separate list, so that, for example, the list "at least one of A, B, or C" means: A or B or C or AB or AC or BC or ABC (i.e., A and B and C).
[0254] Computer-readable media include computer storage media and communication media, wherein the communication media include any medium that is convenient for transmitting a computer program from one place to another. Storage media can be any available medium that a general or special-purpose computer can access. For example, but not limited to, computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, disk storage or other magnetic storage device, or any other medium that can be used to carry or store the desired program code unit with instruction or data structure form and can be accessed by a general or special-purpose computer, or a general or special-purpose processor. In addition, any connection can be appropriately referred to as a computer-readable medium. For example, if software is transmitted from a website, server or other remote source using a coaxial cable, optical fiber cable, twisted pair, digital subscriber line (DSL) or wireless technologies such as infrared, wireless and microwave, then the coaxial cable, optical fiber cable, twisted pair, DSL or wireless technologies such as infrared, wireless and microwave are included in the definition of the medium. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of protection of computer-readable media.
[0255] To enable any person of ordinary skill in the art to implement or use the present disclosure, the above description is centered around the present disclosure. It is obvious to those of ordinary skill in the art that various modifications to the present disclosure are possible, and the general principles defined herein may also be applied to other variations without departing from the spirit or scope of the present disclosure. In addition, although the elements of the described aspects are described or claimed in the singular, the plural form is contemplated unless expressly stated to be limited to the singular. In addition, unless otherwise stated, all or a portion of any aspect may be used together with all or a portion of any other aspect. Therefore, the present disclosure is not limited to the examples and designs described herein, but is consistent with the broadest scope of the principles and novel features disclosed herein.
Claims
1. A mobile device, comprising: a memory including instructions; transceiver; as well as One or more processors operatively coupled to the memory and the transceiver, and the one or more processors are configured to: Obtain at least one certificate; splitting the at least one certificate into a plurality of certificate segments; embedding the plurality of certificate segments into corresponding frames in the plurality of frames; as well as The plurality of frames are sequentially transmitted in a cycle.
2. The mobile device according to claim 1, wherein The one or more processors are further configured to: Corresponding frames of the plurality of frames are assigned sequence numbers, wherein transmitting the plurality of frames comprises transmitting the plurality of frames based on the sequence numbers of the plurality of frames.
3. The mobile device according to claim 1, wherein: The plurality of frames includes at least one of: a first frame including the number of the plurality of frames, or a last frame including an indicator indicating an end of transmission of the plurality of frames. The mobile device according to claim 1 , wherein: The one or more processors are further configured to: The value of the period is received prior to transmitting the plurality of frames. The mobile device according to claim 4 , wherein: Receiving the value includes: obtaining a security profile associated with the mobile device; and The value of the period is obtained from the security profile. The mobile device according to claim 4 , wherein: Receiving the value includes: receiving a mobile device identification and mobile device identification configuration parameters from a network; and The value of the period is obtained from the mobile device identification configuration parameter.
7. The mobile device according to claim 4, wherein: Receiving the value includes: The value is received dynamically from the network via a system information broadcast message or a radio resource configuration message.
8. The mobile device according to claim 7, wherein: Receiving the value includes: The updated value is dynamically received from the network via a radio resource reconfiguration message.
9. The mobile device of claim 1 , wherein: The period is determined based on a received signal strength indication (RSSI), radio frequency, or one or more network or link quality of service (QoS) parameters.
10. The mobile device of claim 1, wherein: The mobile device is an unmanned aerial vehicle, a ground vehicle, a fixed or mobile robotic platform, a control actuator, or a sensing electronic device.
11. The mobile device of claim 1 , wherein: The at least one certificate includes a trust chain file indicating one or more levels of certificates.
12. A receiver comprising: a memory including instructions; transceiver; as well as One or more processors operatively coupled to the memory and the transceiver, the one or more processors configured to: receiving a broadcast remote identification from a mobile device having a mobile device identification; Receiving a certificate associated with the mobile device identifier, wherein receiving the certificate comprises: sequentially receiving a plurality of frames from the mobile device in a periodic manner, each frame including a credential segment from a plurality of credential segments; obtaining the plurality of credential segments from the plurality of frames; and concatenating the plurality of credential segments based on an order of the plurality of frames to generate the credential; and The certificate is used to verify the authenticity of the broadcast remote identification.
13. The receiver of claim 12, wherein: The encrypted hash of the certificate or a component of the encrypted hash constitutes the broadcast remote identification and serves as the mobile device identification or an index to the mobile device identification.
14. The receiver according to claim 13, wherein The one or more processors are further configured to: The mobile device identification is generated by computing the cryptographic hash of the certificate.
Citation Information
Patent Citations
Network access method, network device, and terminal
US20200077321A1