Security improvements in SL unicast
By performing SL counter checking, PDCP entity reconstruction and main SL RLC entity configuration in side link unicast communication, security issues in side link unicast communication are solved, achieving higher security and reliability.
Patent Information
- Application Number
- CN202080099508.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2040-04-08
AI Technical Summary
There are security-related issues in side link (SL) unicast communications, including the possibility of a ‘man-in-the-middle’ attack, incorrect key updates, and complexity of security algorithm inputs.
By performing an SL counter check request and response mechanism in user equipment (UE), the data transmission count mismatch is detected to identify potential 'man-in-the-middle' attacks; after the upper key is updated, the PDCP entity is reset, a new encryption and integrity protection algorithm is applied, and the updated PDCP data PDU is generated; when PDCP replication is used, the main SL RLC entity is configured to determine the correct logical channel ID for security algorithm input.
Effectively prevent ‘man-in-the-middle’ attacks, ensure the correctness of the key update process, simplify the input process of security algorithms, and improve the security and reliability of SL unicast communication.
Smart Images

Figure CN115398967B_ABST
Abstract
Description
Background Art
[0001] A user equipment (UE) may be configured with multiple communication links. For example, a UE may receive a signal from a cell of a corresponding network via a downlink, and may transmit a signal to a cell of a corresponding network via an uplink. A UE may also be configured to communicate with another UE via a side link (SL). The term "side link" refers to a communication link that may be used for device-to-device (D2D) communication. Thus, a SL may facilitate communication between a UE and another UE without using a cell. Various security-related issues may arise in SL communications. Summary of the invention
[0002] In some exemplary embodiments, a computer-readable storage medium includes an instruction set that, when executed by a processor, causes the processor to perform an operation. The computer-readable storage medium may be embodied in a first user equipment (UE), the first UE being configured with a sidelink (SL) connection with a second UE. The operation includes generating an SL counter check request, the SL counter check request including at least a first count for data transmission from the first UE to the second UE as determined by the first UE. The operation also includes transmitting the request to the second UE, and receiving a counter check response to the request, the response including at least a second count for data transmission from the first UE to the second UE as determined by the second UE. The operation also includes determining a first difference between the first count and the second count, and releasing the SL connection with the second UE when the first difference exceeds a threshold.
[0003] In another exemplary embodiment, a computer-readable storage medium includes an instruction set that, when executed by a processor, causes the processor to perform operations. The computer-readable storage medium may be embodied in a first user equipment (UE), which is configured with a sidelink (SL) connection with a second UE. The operation includes initiating an upper layer key update. The operation also includes resetting the header compression protocol of the SL connection for the data radio bearer (DRB) used in the SL connection, and discarding all stored packet data convergence protocol (PDCP) protocol data units (PDUs) and service data units (SDUs). The operation also includes: applying a new encryption algorithm and a new integrity protection algorithm to the DRB, using the new encryption and integrity protection algorithm to generate an updated PDCP PDU, and submitting the updated PDCP PDU to the lower layer.
[0004] In yet other exemplary embodiments, a computer-readable storage medium includes an instruction set that, when executed by a processor, causes the processor to perform operations. The computer-readable storage medium may be embodied in a first user equipment (UE), the first UE being configured with a sidelink (SL) connection with a second UE and operating by using a packet data convergence protocol (PDCP) replication of multiple logical channels, determining a primary SL RLC entity corresponding to a primary logical channel, the primary SL RLC entity having a primary SL RLC identifier (ID) and the primary logical channel having a primary logical channel ID. The operation includes transmitting an indication of using PDCP replication and the primary SL RLC ID to the second UE, wherein the second UE uses the primary logical channel ID corresponding to the primary SL RLC ID to decrypt a transmission from the first UE. BRIEF DESCRIPTION OF THE DRAWINGS
[0005] Figure 1 Exemplary network arrangements are shown according to various exemplary embodiments.
[0006] Figure 2 An exemplary UE according to various exemplary embodiments is shown.
[0007] Figure 3 A method for implementing a count check procedure in a SL unicast communication between a first UE and a second UE according to various exemplary embodiments is shown.
[0008] Figure 4 Methods for PDCP re-establishment at a first transmitting UE in SL communication with a second receiving UE according to various exemplary embodiments are shown.
[0009] Figure 5 According to various exemplary embodiments, a method for Figure 4 A method for performing PDCP reestablishment at a second UE.
[0010] Figure 6 Methods for configuring a primary SL RLC entity for use as a security algorithm in the PDCP layer when PDCP duplication is used according to various exemplary embodiments are shown. DETAILED DESCRIPTION
[0011] The exemplary embodiments may be further understood with reference to the following description and associated drawings, wherein similar elements have the same reference numerals. The exemplary embodiments relate to mechanisms performed at one or more user equipments (UEs) for addressing security-related issues in sidelink (SL) unicast communications. As will be described in detail below, various issues may arise in current SL unicast communications, including the possibility of "man-in-the-middle" attacks, the inability to properly rekey, and difficulty determining the correct inputs to security algorithms.
[0012] The exemplary embodiments are described with respect to UE. However, the use of UE is provided for illustration purposes only. The exemplary embodiments may be used with any electronic component configured with hardware, software and / or firmware for exchanging information (e.g., control information) and / or data with a network. Therefore, the UE described herein is used to represent any suitable electronic device.
[0013] Exemplary embodiments are also described with reference to a side link (SL). The term "side link" generally refers to a communication link between a UE and another UE. SL provides direct device-to-device (D2D) communication, wherein information and / or data exchanged between a UE and another UE via a side link does not pass through a cell. In some configurations, a single side link provides bidirectional data communication between a UE and another UE. In other configurations, a single side link provides unidirectional data communication between a UE and another UE, but signaling may be transmitted in both directions. The term "unicast" refers to one-to-one (i.e., D2D) device communication and may generally refer to bidirectional communication or unidirectional communication. Various embodiments may be applied to one or both forms of communication as indicated below.
[0014] Both the Long Term Evolution (LTE) and 5G New Radio (NR) standards support SL communications. In some configurations, the network may provide information to the UE indicating how to establish, maintain and / or utilize the SL. Therefore, when the information and / or data exchanged through the SL does not pass through the cell, the UE and the network may exchange information associated with the SL. In other configurations, the SL is not controlled by the network. In either configuration, the first UE and the second UE may still perform a synchronization process, a discovery process and exchange control information corresponding to the SL.
[0015] The first problem that can occur in SL unicast communications is the possibility of packet insertion attacks, especially in vehicle-to-everything (V2X) transmissions. When SL unicast security is disabled, a "man-in-the-middle" type attack can occur, where the attacking device records, relays and / or alters communications between communicating devices.
[0016] According to a first aspect of an exemplary embodiment, a SL counter check procedure is implemented, in particular as a backup security procedure for situations such as when SL unicast security is disabled. As will be described in further detail below, a first UE may send a SL counter check request indicating a count of data transmissions sent to and / or received from UE2. UE2 may respond with a corresponding count for data transmissions sent to and / or received from UE1. When a mismatch between corresponding counts exceeding a threshold is determined, it is indicated that a potential "man in the middle" has damaged the SL connection between the UEs, and the connection is released, and the security issue is reported to the network.
[0017] A second problem that may occur in SL unicast communications is that the current SL Packet Data Convergence Protocol (PDCP) does not support PDCP re-establishment. PDCP re-establishment is a process when upper layers perform a key update, for example, generating a new set of keys for decrypting encrypted messages.
[0018] According to a second aspect of the exemplary embodiment, a function for a UE to perform a reestablishment procedure after an upper layer key update is defined. As will be described in further detail below, an updated encryption and integrity protection algorithm is provided to a PDCP entity, the algorithm is applied to the relevant radio bearer, and an updated PDCP data PDU is generated for the SL communication link.
[0019] A third issue that may arise in SL unicast transmission is that the logical channel ID is used as input for the key stream calculation instead of the bearer ID, causing complications when PDCP duplication is used. PDCP duplication is a mechanism where multiple (i.e., at least two) logical channels are mapped to a single SL radio bearer. When SL PDCP duplication is used, it is unclear which of the multiple logical channel IDs is to be used for the SL RB. Although PDCP duplication is not supported in 3GPP Rel-16, PDCP duplication may be enabled in future releases and mechanisms are needed to support the scheme.
[0020] According to a third aspect of the exemplary embodiment, when SL PDCP duplication is used, a primary SL RLC entity (equal to a logical channel) is configured and the ID of the primary RLC entity will be used as an input to the security algorithm in the PDCP layer.
[0021] Figure 1 An exemplary network arrangement 100 according to various exemplary embodiments is shown. The exemplary network arrangement 100 includes UEs 110, 112. Those skilled in the art will appreciate that the UEs 110, 112 may be any type of electronic component configured to communicate via a network, such as a component of a connected car, a mobile phone, a tablet, a smartphone, a phablet, an embedded device, a wearable device, an Internet of Things (IoT) device, etc.
[0022] Throughout the specification, the terms "UE 110", "UE" and "transmitting device" can be used interchangeably. In addition, the terms "UE 112", "additional UE" and "receiving device" can also be used interchangeably. It should also be understood that an actual network arrangement may include any number of UEs used by any number of users. Therefore, the example with two UEs 110, 112 is provided for illustration purposes only.
[0023] UE 110, 112 can communicate directly with one or more networks. In the example of network configuration 100, the networks with which UE 110, 112 can wirelessly communicate are 5G NR radio access network (5G NR-RAN) 120, LTE radio access network (LTE-RAN) 122, and wireless local area network (WLAN) 124. These types of networks support vehicle-to-everything (V2X) and / or sidelink communications. However, UE 110 can also communicate with other types of networks, and UE 110 can also communicate with the network via a wired connection. Therefore, UE 110, 112 may include a 5G NR chipset that communicates with 5G NR-RAN 120, an LTE chipset that communicates with LTE-RAN 122, and an ISM chipset that communicates with WLAN 124.
[0024] 5G NR-RAN 120 and LTE-RAN 122 may be part of cellular networks that may be deployed by cellular providers (e.g., Verizon, AT&T, Sprint, T-Mobile, etc.). These networks 120, 122 may include, for example, cells or base stations (NodeB, eNodeB, HeNB, eNBS, gNB, gNodeB, macrocell base stations, microcell base stations, small cell base stations, femtocell base stations, etc.) configured to send and receive traffic from UEs equipped with appropriate cellular chipsets. WLAN 124 may include any type of wireless local area network (WiFi, hotspot, IEEE 802.11x network, etc.).
[0025] The UEs 110, 112 may be connected to the 5G NR-RAN via a gNB 120A. The gNB 120A may be configured with the necessary hardware (e.g., antenna array), software, and / or firmware to perform massive multiple-input multiple-output (MIMO) functionality. Massive MIMO may refer to a base station configured to generate multiple beams for multiple UEs. Reference to a single gNB 120A is for illustrative purposes only. The exemplary embodiments may apply to any appropriate number of gNBs. The UEs 110, 112 may also be connected to the LTE-RAN 122 via an eNB 122A.
[0026] Those skilled in the art will appreciate that any associated process may be performed for the UE 110, 112 to connect to the 5G NR-RAN 120 and the LTE-RAN 122. For example, as discussed above, the 5G NR-RAN 120 and the LTE-RAN 122 may be associated with a particular cellular provider at which the UE 110, 112 and / or its user has a contract and credential information (e.g., stored on a SIM card). Upon detecting the presence of the 5G NR-RAN 120, the UE 110, 112 may transmit the corresponding credential information in order to associate with the 5G NR-RAN 120. More specifically, the UE 110, 112 may be associated with a particular base station (e.g., gNB 120A of the 5G NR-RAN 120, eNB 122A of the LTE-RAN 122).
[0027] UE 110, 112 may also communicate directly with each other using a side link. The side link is a direct D2D communication link. Therefore, information and / or data transmitted directly to another endpoint (e.g., UE 110 or UE 112) does not pass through a cell (e.g., gNB 120A, eNB 122A). In some embodiments, UE 110, 112 may receive information from the cell about how to establish, maintain and / or utilize the side link. Therefore, the network (e.g., 5G NR-RAN 120, LTE-RAN 122) may control the side link. In other embodiments, UE 110, 112 may control the side link. Regardless of how the side link is controlled, UE 110, 112 may simultaneously maintain a downlink / uplink to the currently occupied cell (e.g., gNB 120A, eNB 122A) and a side link to another UE.
[0028] In addition to the networks 120, 122, and 124, the network arrangement 100 includes a cellular core network 130, the Internet 140, an IP multimedia subsystem (IMS) 150, and a network service backbone 160. The cellular core network 130 can be viewed as an interconnected collection of components that manage the operation and traffic of the cellular network. The cellular core network 130 also manages the traffic flowing between the cellular network and the Internet 140. The IMS 150 can be generally described as an architecture for delivering multimedia services to the UE 110 using the IP protocol. The IMS 150 can communicate with the cellular core network 130 and the Internet 140 to provide multimedia services to the UE 110. The network service backbone 160 communicates directly or indirectly with the Internet 140 and the cellular core network 130. The network service backbone 160 can be generally described as a set of components (e.g., servers, network storage arrangements, etc.) that implement a set of services that can be used to extend the functionality of the UE 110 to communicate with various networks.
[0029] Figure 2 An exemplary UE 110 is shown according to various exemplary embodiments. Figure 1 100 is used to describe the UE 110. The UE 110 may include a processor 205, a memory arrangement 210, a display device 215, an input / output (I / O) device 220, a transceiver 225, and other components 230. The other components 230 may include, for example, a SIM card, an embedded SIM (eSIM), an audio input device, an audio output device, a power source, a data acquisition device, a port for electrically connecting the UE 110 to other electronic devices, etc. Figure 2 The UE 110 shown in FIG. 1 may also represent the UE 112 .
[0030] The processor 205 may be configured to execute multiple engines of the UE 110. For example, the engines may include a counter check engine 235, a PDCP reconstruction engine 240, and a security algorithm input determination engine 245. As will be described below, the counter check engine 235 may be operable to initiate and / or respond to a counter check request for comparing data transmission counts between two UEs in SL communication. The PDCP reconstruction engine 240 may initiate PDCP reconstruction and / or refresh PDCP PDU / SDU with an updated encryption and / or integrity protection algorithm. The security algorithm input determination engine 245 may identify one of the multiple SL RLC entities as a primary entity and indicate the primary entity to the second UE and / or use a primary SL logical channel ID (corresponding to the primary SL RLC entity) to decrypt the transmission.
[0031] The above engines are each an application (e.g., a program) executed by the processor 205 for exemplary purposes only. The functions associated with the engine may also be represented as an independently integrated component of the UE 110, or may be a modular component coupled to the UE 110, such as an integrated circuit with or without firmware. For example, an integrated circuit may include an input circuit for receiving a signal and a processing circuit for processing the signal and other information. The engine may also be embodied as an application or multiple separate applications. In addition, in some UEs, the functionality described for the processor 205 is shared between two or more processors such as a baseband processor and an application processor. The exemplary embodiments may be implemented in any of these or other configurations of the UE.
[0032] The memory arrangement 210 may be a hardware component configured to store data related to operations performed by the UE 110. The display device 215 may be a hardware component configured to display data to a user, and the I / O device 220 may be a hardware component that enables user input. The display device 215 and the I / O device 220 may be separate components or may be integrated together (such as a touch screen). The transceiver 225 may be a hardware component configured to establish a connection with the 5G NR-RAN 120, the WLAN 122, etc. Thus, the transceiver 225 may operate on multiple different frequencies or channels (e.g., a continuous frequency group).
[0033] As described above, the first exemplary embodiment relates to detecting a "man-in-the-middle" (i.e., an attacking device) between two UEs communicating via a SL. The exemplary counter checking mechanism described below (where data transmissions between two UEs are counted) may indicate the presence of an attacking device when a mismatch between corresponding counts is determined.
[0034] Figure 3 A method 300 for implementing a count check procedure in a SL unicast communication between a first UE (e.g., UE 110) and a second UE (e.g., UE 112) is shown. As described below, the exemplary process can be used in a one-way communication or a two-way communication. The count check process as described herein can be performed at various intervals. For example, the count check can be performed for each message exchange, the count check can be performed periodically (e.g., every X seconds), the count check can be performed based on an event (e.g., every Y communications), etc.
[0035] In 305, either the first UE or the second UE initiates a counter check procedure by generating a SL counter check request. The counter check request includes an information element (IE) including a first count indicating a count of data transmissions in a first direction (e.g., from the first UE to the second UE) of two directions, and a second count indicating a count of data transmissions in a second direction (e.g., from the second UE to the first UE) of two directions. In some exemplary embodiments, the IE may also include one or both of a radio bearer (RB) identifier (RB ID) and / or a logical channel ID of the data transmission. In some exemplary embodiments, a separate counter may be used for each RB or logical channel, so when multiple RBs and / or logical channels are used, a counter for the above transmission direction may be listed for each of the RB IDs and / or logical channel IDs. For example, if it is considered that two RBs (e.g., RB1 and RB2) are established between the first UE and the second UE, the request IE may include a list of RBs and corresponding counters (e.g., RB1 [Tx-RB1 counter, Rx-RB1 counter], RB2 [Tx-RB2 counter, Rx-RB2 counter]). In 310, the first UE transmits (ie, signals) a counter check request to the second UE.
[0036] In 315, upon receiving the counter check request, the second UE generates a response to the counter check request for each SL data radio bearer (DRB). The following description provides examples of operations related to established DRBs. Exemplary operations for unestablished DRBs will be provided below. For established DRBs, if there is no count for a given transmission direction, for example because the DRB is a unidirectional bearer configured only for another direction, the count value is assumed to be zero for the IE corresponding to the unused direction. For established DRBs that are not included in the request, the second UE may include a counter set for each of the DRBs in the response by including an IE for the SL RB ID, where the counters are set to the values of TX_NEXT-1 and RX_NEXT-1. If the most significant bit of the count is different from the value indicated in the request message for at least one direction of a particular SL RB, the SL RB is included in the response with the SL RB ID and / or SL logical channel ID, where the counters are set to the values of TX_NEXT-1 and RX_NEXT-1.
[0037] For each DRB not established, the second UE includes the not established SL DRB ID in the response with the most significant bit of the counter set set equal to the corresponding value in the request message and the least significant bit set to zero. In 320, the second UE transmits (ie, signals) a counter check request to the first UE.
[0038] In 325, upon receiving the counter check response, the first UE determines whether there is a counter mismatch. The first UE determines the difference between the count of the first UE and the count of the second UE for each of the SL DRBs and compares the difference with a threshold. The threshold may be configured by the NW in RRC signaling (SIB or dedicated signaling), pre-configured between the network provider and the UE provider, or determined by a specific UE implementation (e.g., based on the application executed on the UE, based on the type of UE, etc.). In some exemplary embodiments, the threshold may be constant. In other exemplary embodiments, the threshold may be scaled according to the characteristics of the SL DRB (such as the data rate), for example, a higher data rate will allow a higher threshold.
[0039] In 330, when it is determined that there is a counter mismatch, the counter mismatch is declared and the connection may be released by the first UE. For example, the first UE may send a RRCReaseSidelink or RRCReconfigurationFailureSidelink message to the second UE, indicating that the cause value is "counter mismatch" or "security issue". If either the first UE or the second UE is in an RRC connected state with the network (e.g., 5G RAN 120), the UE may report SLUEinformation to the network, indicating that the release / failure cause is "counter mismatch" or "security issue". In this way, 5G RAN 120 can understand that there may have been an attack on the UE via the side link connection.
[0040] The above mechanism may be employed when unicast security is turned off, or may be used as a backup security measure even when unicast security is turned on. A counter mismatch determination may indicate the presence of an attacking device that intercepts transmissions between two UEs in SL communication or inserts malicious transmissions between two UEs in SL communication. The exemplary counting mechanism allows the UE to be protected against such malicious attacks.
[0041] As described above, the second aspect of the exemplary embodiment relates to the reestablishment of the PDCP entity between two UEs in SL communication. The PDCP layer supports security functions (e.g., integrity, encryption, and header compression) and runs on top of the RLC layer. When the security key is refreshed, the reestablishment of the PDCP is performed. The reestablishment of the PDCP can be a process performed when the upper layer performs a key update.
[0042] Typically, rekeying ensures that a fresh session key (KNPR-sess) is used and may also refresh the KNPR. Either UE in SL communication may rekey the connection at any time before the counter for the PDCP bearer is repeated with the current key.
[0043] Figure 4 A method 400 for performing PDCP reestablishment at a first transmitting UE that is in SL communication with a second receiving UE is shown. As described above, either UE in SL communication may perform a key update on the connection. Thus, the method 400 may be performed by a UE 110 or a UE 112 that has established a SL connection.
[0044] In 405, an upper layer key update is initiated at the first UE. In 410, various aspects of the PDCP entity at the first UE are reset. For example, for both acknowledged (AM) DRBs and unacknowledged (UM) DRBs, the header compression protocol of the SL may be reset so that an initial initialization and refresh (IR) state in unidirectional (U-mode) is established. For all UM DRBs and signaling radio bearers (SRBs), TX_NEXT may be set to an initial value. For SRBs, all stored PDCP service data units (SDUs) and protocol data units (PDUs) may be discarded.
[0045] The new encryption algorithm and the new integrity protection algorithm are applied to the DRB in 415. The new algorithms are provided by upper layers during the PDCP entity key update procedure.
[0046] At 420, a PDCP data PDU is generated using the new ciphering and integrity protection algorithm. Specifically, for the UMDRB, for each PDCP SDU that has been associated with a PDCP sequence number (SN) (but for which the corresponding PDU has not been previously submitted to the lower layers), header compression of the PDCP SDU is performed, integrity protection and ciphering are performed using the count value associated with the PDCP SDU, and the resulting PDCP data PDU is submitted to the lower layers.
[0047] For an AM DRB (the first PDCP SDU for which successful delivery of the corresponding PDCP data PDU is not acknowledged by the lower layers), before reestablishment is initiated, transmission or retransmission is performed for all PDCP SDUs that have been associated with the PDCP SN in ascending order of the COUNT value associated with the PDCP SDU. Similar to the UM DRB discussed above, header compression is performed for each of these PDCP SDUs, integrity protection and ciphering are performed using the COUNT value associated with the PDCP SDU, and the resulting PDCP data PDUs are submitted to the lower layers.
[0048] The aforementioned method 400 reestablishes the lower layer for the SL connection and ends the method for the first UE. Figure 5 A method 500 for PDCP re-establishment at a second UE is shown. At 505, the receiving UE processes the PDCP data PDUs received from the lower layer due to the re-establishment of the lower layer.
[0049] In 510, the stored PDCP SDUs and PDCP PDUs are discarded. In 515, for SRBs and UM DRBs with t-reordering running, t-reordering is stopped and reset. In 520, for UM DRBs, header decompression is performed and all stored PDCP SDUs are delivered to upper layers in ascending order of associated COUNT values. In 525, for AM DRBs, if drb-ContinueROHC is not configured, header decompression is performed for all stored PDCP SDUs.
[0050] In 530, for UM DRB and AM DRB, the header compression protocol of the side link is reset and the NC state in U mode is started. In 535, for UM DRB and SRB, RX_NEXT and RX_DELIV are set to initial values. In 540, the encryption algorithm and the key and integrity protection algorithm and the key provided by the upper layer during the PDCP re-establishment process are applied.
[0051] Therefore, executing methods 400 and 500 will result in a key update procedure being completed between UEs having a sidelink connection.
[0052] As described above, the third aspect of the exemplary embodiments relates to PDCP duplication scenarios where multiple logical RLC entities (and therefore multiple logical channels) are used and it is unclear which logical channel ID is to be used as input to the security algorithm at the PDCP layer.
[0053] Figure 6 A method 600 is shown for configuring a primary SL RLC entity for use as a security algorithm in the PDCP layer when PDCP duplication is used.
[0054] In 605, the first transmitting UE operating through PDCP duplication determines the primary SL RLC entity as the entity carrying the PDCP control PDU. In PDCP duplication, only one of the multiple channels carries the PDCP control PDU. In 610, the first UE indicates to the second receiving UE through an RRCReconfigurationSidelink message that PDCP duplication is used for one SL RB and the identity of the primary SL RLC entity.
[0055] In 615, the second UE decrypts the transmission and IP check using the primary SL logical channel ID corresponding to the primary SL RLC entity.
[0056] Thus, upon completion of method 600, both UEs in the SL connection will understand which logical channel ID will be used for the SL bearer. It should be appreciated that method 600 may be applied to carrier aggregation (CA) based PDCP duplication applicable to intra-RAT PDCP duplication. In addition, method 600 may be applied to dual connectivity (DC) based PDCP duplication applicable to inter-RAT PDCP duplication (e.g., NR SL and LTE SL).
[0057] An example of a first aspect of the exemplary embodiment is provided below.
[0058] A first example includes a method performed by a first user equipment (UE) configured with a sidelink (SL) connection with a second UE. The method includes: generating a SL counter check request, the SL counter check request including at least a first count for data transmission from the first UE to the second UE as determined by the first UE; transmitting the request to the second UE; receiving a counter check response to the request, the response including at least a second count for data transmission from the first UE to the second UE as determined by the second UE; determining a first difference between the first count and the second count; and when the first difference exceeds a threshold, releasing the SL connection with the second UE.
[0059] A second example includes a first user equipment (UE) having a transceiver and a processor. The transceiver is configured to connect to a second UE via a sidelink (SL) connection. The processor is configured to: generate a SL counter check request, the SL counter check request including at least a first count for data transmission from the first UE to the second UE as determined by the first UE; receive a counter check response to the request, the response including at least a second count for data transmission from the first UE to the second UE as determined by the second UE; determine a first difference between the first count and the second count; and when the first difference exceeds a threshold, release the SL connection with the second UE.
[0060] A third example includes a method performed by a first user equipment (UE) configured with a sidelink (SL) connection with a second UE. The method includes: receiving a SL counter check request from the second UE, the request including at least a first count for data transmission from the second UE to the first UE as determined by the second UE; generating a counter check response to the request, the response including at least a second count for data transmission from the second UE to the first UE as determined by the first UE; transmitting the response to the second UE; and receiving a message from the second UE to release the SL connection, wherein the message includes a reason for releasing the SL connection.
[0061] The third example also includes, when the request does not include a radio bearer (RB) identification (ID), generating a response including a RB ID of a RB established for data transmission on the SL connection.
[0062] The third example also includes reporting the release of the SL connection to the cellular network, including the reason included in the message, when a message to release the SL connection is received and the first UE is in an RRC connected state with the cellular network.
[0063] A fourth example includes a first user equipment (UE) having a transceiver and a processor. The transceiver is configured to connect to a second UE via a sidelink (SL) connection. The processor is configured to: receive a SL counter check request from the second UE, the request including at least a first count for data transmission from the second UE to the first UE as determined by the second UE; generate a counter check response to the request, the response including at least a second count for data transmission from the second UE to the first UE as determined by the first UE; and receive a message from the second UE to release the SL connection, wherein the message includes a reason for releasing the SL connection.
[0064] An example of the second aspect of the exemplary embodiment is provided below.
[0065] A fifth example includes a method performed by a first user equipment (UE) configured with a sidelink (SL) connection with a second UE. The method includes: initiating an upper layer key update; resetting a header compression protocol for a data radio bearer (DRB) used in the SL connection, and discarding all stored packet data convergence protocol (PDCP) protocol data units (PDUs) and service data units (SDUs); applying a new encryption algorithm and a new integrity protection algorithm to the DRB; generating an updated PDCP PDU using the new encryption and integrity protection algorithms; and submitting the updated PDCP PDU to a lower layer.
[0066] A sixth example includes a first user equipment (UE) having a transceiver and a processor. The transceiver is configured to connect to a second UE via a side link (SL) connection. The processor is configured to: initiate an upper layer key update; reset a header compression protocol for a data radio bearer (DRB) used in the SL connection, and discard all stored packet data convergence protocol (PDCP) protocol data units (PDUs) and service data units (SDUs); apply a new encryption algorithm and a new integrity protection algorithm to the DRB; generate an updated PDCP PDU using the new encryption and integrity protection algorithms; and submit the updated PDCP PDU to a lower layer.
[0067] A seventh example includes a method performed by a first user equipment, the first user equipment being configured with a sidelink (SL) connection with a second UE. The method includes: receiving a key update request from the second UE; receiving an updated packet data convergence protocol (PDCP) protocol data unit (PDU) from a lower layer; discarding all stored PDCP PDUs and service data units (SDUs); performing header compression on the updated PDCP PDU; and applying a new encryption algorithm and a new integrity protection algorithm to a data radio bearer (DRB) used in the SL connection.
[0068] An eighth example includes a first user equipment (UE) having a transceiver and a processor. The transceiver is configured to connect to a second UE via a side link (SL) connection. The processor is configured to: receive a key update request from the second UE; receive an updated packet data convergence protocol (PDCP) protocol data unit (PDU) from a lower layer; discard all stored PDCP PDUs and service data units (SDUs); perform header compression on the updated PDCP PDU; and apply a new encryption algorithm and a new integrity protection algorithm to a data radio bearer (DRB) used in the SL connection.
[0069] An example of the third aspect of the exemplary embodiment is provided below.
[0070] A ninth example includes a method performed by a first user equipment (UE) configured with a sidelink (SL) connection with a second UE and operating with a packet data convergence protocol (PDCP) replication in which multiple logical channels are used. The method includes: determining a primary SL RLC entity corresponding to a primary logical channel, the primary SL RLC entity having a primary SL RLC identifier (ID) and the primary logical channel having a primary logical channel ID; and transmitting an indication of using PDCP replication and the primary SL RLC ID to the second UE, wherein the second UE uses the primary logical channel ID corresponding to the primary SL RLC ID to decrypt a transmission from the first UE.
[0071] The tenth example includes a first user equipment (UE) having a transceiver and a processor, the UE being configured to operate via a packet data convergence protocol (PDCP) duplication in which a plurality of logical channels are used. The transceiver is configured to connect to a second UE via a side link (SL) connection. The processor is configured to determine a primary SL RLC entity corresponding to a primary logical channel, the primary SL RLC entity having a primary SL RLC identifier (ID) and the primary logical channel having a primary logical channel ID, wherein the transceiver is further configured to transmit an indication of using PDCP duplication and the primary SL RLC ID to the second UE, wherein the second UE uses the primary logical channel ID corresponding to the primary SL RLC ID to decrypt a transmission from the first UE.
[0072] An eleventh example includes a method performed by a first user equipment (UE) configured with a sidelink (SL) connection with a second UE and operating with a packet data convergence protocol (PDCP) duplication in which a plurality of logical channels are used. The method includes receiving an indication of using PDCP duplication and a primary SL RLC ID, and decrypting a transmission from the first UE using a primary logical channel ID corresponding to the primary SL RLC ID.
[0073] The twelfth example includes a first user equipment (UE) having a transceiver and a processor, the UE being configured to operate with a packet data convergence protocol (PDCP) duplication in which a plurality of logical channels are used. The transceiver is configured to connect to a second UE via a sidelink (SL) connection. The processor is configured to receive an indication of using PDCP duplication and a primary SL RLC ID, and to decrypt a transmission from the first UE using a primary logical channel ID corresponding to the primary SL RLC ID.
[0074] Those skilled in the art will appreciate that the exemplary embodiments described above may be implemented with any suitable software configuration or hardware configuration or combination thereof. Exemplary hardware platforms for implementing the exemplary embodiments may include, for example, Intel x86-based platforms with compatible operating systems, Windows OS, Mac platforms and MAC OS, mobile devices with operating systems such as iOS, Android, etc. In other examples, the exemplary embodiments of the above methods may be embodied as a program including lines of code stored on a non-transitory computer-readable storage medium, which, when compiled, may be executed on a processor or microprocessor.
[0075] Although this patent application describes various combinations of various embodiments each having different features, those skilled in the art will understand that any feature of an embodiment may be combined with features of other embodiments in any manner not publicly denied or with features that are not functionally or logically inconsistent with the operation or function of the device of the embodiments disclosed in the present invention.
[0076] It is understood that the use of personally identifiable information should be subject to privacy policies and practices that are generally recognized to meet or exceed industry or government requirements for maintaining user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of the authorized use should be clearly stated to users.
[0077] It will be apparent to those skilled in the art that various modifications may be made to the present disclosure without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure is intended to cover modifications and variations of the present disclosure, provided that these modifications and variations are within the scope of the appended claims and their equivalents.
Claims
1. A computer-readable storage medium comprising an instruction set, wherein the instruction set, when executed by a processor, causes the processor to perform operations comprising: At a first user equipment (UE) configured with a sidelink (SL) connection with a second user equipment (UE): generating a SL counter check request, the SL counter check request comprising at least a first count for data transmission from the first UE to the second UE as determined by the first UE; transmitting the request to the second UE; receiving a counter check response to the request, the response comprising at least a second count for data transmissions from the first UE to the second UE as determined by the second UE; determining a first difference between the first count and the second count; as well as When the first difference exceeds a threshold, releasing the SL connection with the second UE, The threshold is based at least on a data rate on the SL connection.
2. The computer-readable storage medium of claim 1 , wherein the request comprises a third count for data transmissions from the second UE to the first UE as determined by the first UE, and the response comprises a fourth count for data transmissions from the second UE to the first UE as determined by the second UE, the operations further comprising: determining a second difference between the third count and the fourth count; as well as When the second difference exceeds the threshold, the SL connection with the second UE is released.
3. The computer-readable storage medium of claim 1 , wherein the request comprises one of a first radio bearer identifier (RB ID) or a first logical channel ID, and the first count corresponds to data transmission on the one of the first RB ID or the first logical channel ID.
4. The computer-readable storage medium of claim 3, wherein the request comprises one of a second RB ID or a second logical channel ID, wherein the request comprises a fifth count for data transmissions on the one of the second RB ID or the second logical channel ID.
5. The computer-readable storage medium according to claim 1, wherein: The operations also include: When the first UE releases the SL connection with the second UE and is in an RRC connected state with a cellular network, the release of the SL connection is reported to the cellular network.
6. The computer-readable storage medium of claim 1, wherein releasing the SL with the second UE comprises sending a message to the second UE indicating a reason for the release.
7. The computer-readable storage medium of claim 1, wherein the threshold is one of: (i) configured by a cellular network, (ii) preconfigured, or (iii) determined by the first UE based on characteristics of the first UE or an application executed on the first UE. 8 . The computer-readable storage medium of claim 2 , wherein when the SL connection is unidirectional, one of the first count or the third count is set to 0.
9. The computer-readable storage medium of claim 1, wherein the first count and the second count include at least one most significant bit and at least one less significant bit.
Citation Information
Patent Citations
A primary base station device, a secondary base station device, a user device, and a method performed by the same
CN110460589A