Providing security credentials to drones
By providing secure credentials and keys for the UE of the UAV system in the terrestrial cellular network, the problem of denial-of-service attacks caused by forged remote identifiers is solved, ensuring secure communication and efficient operation of UAVs.
Patent Information
- Application Number
- CN202180033547.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-12
- Filing Date
- 2021-05-06
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2041-05-06
AI Technical Summary
In drone systems, forged remote identifiers can lead to denial-of-service attacks, affecting the operational efficiency of UAVs and causing property damage. Existing technologies are unable to effectively address this security vulnerability.
By establishing secure communication between the UE and the UDM entity or service provider in the terrestrial cellular network, and protecting the remote identifier of the UAV with security credentials and keys, the security and legitimacy of the communication are ensured.
It effectively prevents denial-of-service attacks, improves the operational efficiency of UAVs, and reduces property losses and security risks caused by forged identifiers.
Smart Images

Figure CN115516820B_ABST
Abstract
Description
[0001] Cross-references
[0002] This patent application claims the benefit of Greek Provisional Patent Application No. 20200100241 filed by FACCIN et al. on May 12, 2020, entitled “PROVIDING SECURITY CREDENTIALS TO AN UNMANNED AERIAL VEHICLE,” which application is assigned to its assignee and is expressly incorporated herein by reference in its entirety. Technical Field
[0003] The following relates generally to wireless communications and, more particularly, to techniques for providing security credentials to unmanned aerial vehicles (UAVs). Background Art
[0004] Wireless communication systems are widely deployed to provide various types of communication content, such as voice, video, packet data, messaging, broadcast, and the like. These systems may be able to support communication with multiple users by sharing available system resources (e.g., time, frequency, and power). Examples of such multiple access systems include fourth generation (4G) systems, such as long term evolution (LTE) systems, advanced LTE (LTE-A) systems, or LTE-A Pro systems, and fifth generation (5G) systems, which may be referred to as new radio (NR) systems. These systems may employ techniques such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), or discrete Fourier transform spread orthogonal frequency division multiplexing (DFT-S-OFDM). A wireless multiple access communication system may include one or more base stations or one or more network access nodes, each base station or network access node simultaneously supporting communication with multiple communication devices, which may be referred to as user equipment (UE). Summary of the Invention
[0005] The described technology relates to improved methods, systems, devices, and apparatuses that support techniques for providing security credentials to user equipment (UE) associated with an unmanned aerial vehicle (UAV) in an unmanned aerial system (UAS). Generally, the described technology implements secure communications for a UAV via signaling provided over a terrestrial cellular network. For example, a UE associated with a UAV may establish a connection with one or more network entities (such as a unified data management (UDM) entity and an access and mobility management function (AMF)) and receive a security configuration from the UDM entity (e.g., via the AMF). In some cases, the security configuration may include one or more security credentials that may enable communication between the UE and a service provider (e.g., a UAV flight service provider (UFSS), a UAS service provider (USS), or both). In some examples, the UDM entity may generate the security configuration after the UE (e.g., and the UAV) establishes a connection with a network entity (AMF, core network, UDM, etc.). Additionally or alternatively, the service provider (UFSS, USS, etc.) may generate a security configuration (e.g., after receiving a Registration Request message from the UE or UAV) and may signal the security configuration to the UDM, which then forwards the security configuration to the UE (e.g., via the AMF).
[0006] A method of wireless communication at a UE associated with a UAV in a terrestrial cellular network is described. The method may include: performing a registration procedure with one or more network functions for communicating with an unmanned aerial vehicle (UAV) service provider, the one or more network functions including an AMF; receiving, via the AMF, an indication of a security configuration from a UDM entity in a non-access stratum (NAS) transport message, the security configuration including one or more security credentials for enabling communication between the UE and the UAV service provider; and communicating with the UAV service provider based on the one or more security credentials of the security configuration.
[0007] An apparatus for wireless communication at a user equipment (UE) associated with a UAV in a terrestrial cellular network is described. The apparatus may include a processor, a memory coupled to the processor, and instructions stored in the memory. The instructions are executable by the processor to cause the apparatus to: perform a registration procedure with one or more network functions for communicating with an unmanned aerial vehicle (UAS) service provider, the one or more network functions including an Active Mobile Device (AMF); receive, via the AMF, an indication of a security configuration from a UDM entity in a NAS transport message, the security configuration including one or more security credentials for enabling communication between the UE and the UAS service provider; and communicate with the UAS service provider based on the one or more security credentials of the security configuration.
[0008] Another apparatus for wireless communication at a UE associated with a UAV in a terrestrial cellular network is described. The apparatus may include means for performing the following operations: performing a registration procedure with one or more network functions for communicating with an unmanned aerial vehicle system service provider, the one or more network functions including an AMF; receiving, via the AMF, an indication of a security configuration from a UDM entity in a non-access stratum (NAS) transport message, the security configuration including one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider; and communicating with the unmanned aerial vehicle system service provider based on the one or more security credentials of the security configuration.
[0009] A non-transitory computer-readable medium is described that stores code for wireless communication at a UE associated with a UAV in a terrestrial cellular network. The code may include instructions executable by a processor to: perform a registration procedure with one or more network functions for communication with an unmanned aerial vehicle system (UAS) service provider, the one or more network functions including an AMF; receive, via the AMF, an indication of a security configuration from a UDM entity in a non-access stratum (NAS) transport message, the security configuration including one or more security credentials for enabling communication between the UE and the UAS service provider; and communicate with the UAS service provider based on the one or more security credentials of the security configuration.
[0010] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for performing the following: sending a confirmation message to the UDM entity indicating that the UE successfully received the indication of the security configuration, wherein communicating with the UAV system service provider may be based on the confirmation message.
[0011] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for performing the following: sending a registration request for communication between the UE and the drone system service provider to the drone system service provider, the registration request including registration information corresponding to the UE.
[0012] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for determining to send the registration request to the drone system service provider based on an identity of the drone system service provider received in the indication of the security configuration.
[0013] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for performing the following: receiving a registration response message from the drone system service provider in response to the registration request, the registration response message including an identifier for the UE, wherein communicating with the drone system service provider may be based on the identifier for the UE in combination with the security configuration.
[0014] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the registration request can be secured based on one or more security credentials received from the UDM entity.
[0015] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, an indication of the security configuration can be received based on sending the registration request.
[0016] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the registration request includes a Universal Public Subscription Identifier (GPSI) of the UE, and wherein the indication of the security configuration can be received based on the GPSI of the UE.
[0017] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for determining to remove security credentials previously used by the UE for previous communications.
[0018] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the security configuration includes: a UE identity for identifying the UE in communications between the UE and the drone system service provider, credentials for communications between the UE and the drone system service provider, private and public security keys for enabling communications between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof.
[0019] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, an indication of the security configuration may be received at a hardware component of the UE.
[0020] A method for wireless communication performed at a UDM entity is described. The method may include: sending an indication of a security configuration to an AMF, the security configuration including one or more security credentials for enabling communication between a UE associated with a UAV and a UAV service provider; receiving an acknowledgment message from the AMF indicating that the UE successfully received the indication of the security configuration; and sending a message to the UAV service provider based on receiving the acknowledgment message, the message indicating the one or more security credentials to be used by the UE for communication with the UAV service provider.
[0021] An apparatus for wireless communication at a UDM entity is described. The apparatus may include a processor, a memory coupled to the processor, and instructions stored in the memory. The instructions may be executed by the processor to cause the apparatus to: send an indication of a security configuration to an AMF, the security configuration including one or more security credentials for enabling communication between a UE associated with a UAV and a UAV service provider; receive an acknowledgment message from the AMF indicating that the UE successfully received the indication of the security configuration; and, based on receiving the acknowledgment message, send a message to the UAV service provider indicating the one or more security credentials to be used by the UE for communication with the UAV service provider.
[0022] Another apparatus for wireless communication at a UDM entity is described. The apparatus may include means for: sending an indication of a security configuration to an AMF, the security configuration including one or more security credentials for enabling communication between a UE associated with a UAV and an unmanned aerial system service provider; receiving an acknowledgment message from the AMF indicating that the UE successfully received the indication of the security configuration; and sending a message to the unmanned aerial system service provider based on receiving the acknowledgment message, the message indicating the one or more security credentials to be used by the UE for communication with the unmanned aerial system service provider.
[0023] A non-transitory computer-readable medium storing code for wireless communication at a UDM entity is described. The code may include instructions executable by a processor to: send an indication of a security configuration to an AMF, the security configuration including one or more security credentials for enabling communication between a UE associated with a UAV and a UAV service provider; receive an acknowledgment message from the AMF indicating that the UE successfully received the indication of the security configuration; and, based on receiving the acknowledgment message, send a message to the UAV service provider indicating the one or more security credentials to be used by the UE for communication with the UAV service provider.
[0024] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, sending the message to the drone system service provider may also include operations, features, components, or instructions for performing the following: generating a security configuration for communication between the UE and the drone system service provider; and sending an indication of the security configuration to the drone system service provider to enable communication between the UE and the drone system service provider.
[0025] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the security configuration may be generated based on: the UE registering with the network including the UDM entity and the AMF, no security configuration previously delivered to the UE, a security refresh for the UE, a trigger received from the UAV system service provider, or a combination thereof.
[0026] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for performing each of the following: receiving an indication of the security configuration from the drone system service provider, wherein sending the indication of the security configuration to the AMF may be based on receiving the indication of the security configuration from the drone system service provider.
[0027] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, sending the message to the drone system service provider may include operations, features, components, or instructions for performing the following: sending a parameter provision information message to the drone system service provider, the parameter provision information message including a confirmation message indicating that the UE successfully received the indication of the security configuration.
[0028] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, receiving an indication of a security configuration may include operations, features, components, or instructions for performing the following: receiving an indication of the security configuration from the drone system service provider via a UDM service message, a network open function update message, or a combination thereof.
[0029] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, sending an indication of a security configuration may include operations, features, components, or instructions for performing the following: sending a UDM configuration update message for parameters for the UE to the AMF, wherein the UDM configuration update message includes an indication of the security configuration.
[0030] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the security configuration includes: a UE identity for identifying the UE in communications between the UE and the drone system service provider, credentials for communications between the UE and the drone system service provider, private and public security keys for enabling communications between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof.
[0031] A method for wireless communication at an unmanned aerial vehicle system service provider is described. The method may include: receiving a registration request from a UE associated with a UAV, including registration information corresponding to the UE; determining one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider based on the registration request; and communicating with the UE based on the one or more security credentials.
[0032] An apparatus for wireless communication at an unmanned aerial vehicle system service provider is described. The apparatus may include a processor, a memory coupled to the processor, and instructions stored in the memory. The instructions are executable by the processor to cause the apparatus to: receive a registration request from a UE associated with a UAV, including registration information corresponding to the UE; determine, based on the registration request, one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider; and communicate with the UE based on the one or more security credentials.
[0033] Another apparatus for wireless communication at an unmanned aerial vehicle system service provider is described. The apparatus may include means for: receiving a registration request including registration information corresponding to a UE associated with a UAV from the UE; determining, based on the registration request, one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider; and communicating with the UE based on the one or more security credentials.
[0034] A non-transitory computer-readable medium storing code for wireless communication at an unmanned aerial vehicle system service provider is described. The code may include instructions executable by a processor to: receive a registration request including registration information corresponding to a UE associated with a UAV from the UE; determine one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider based on the registration request; and communicate with the UE based on the one or more security credentials.
[0035] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, determining the one or more security credentials may include operations, features, components, or instructions for performing the following: receiving an indication of a security configuration from a UDM entity, the security configuration including one or more security credentials for enabling communications between the UE and the drone system service provider.
[0036] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the UDM entity may generate the security configuration based on: the UE registering with a network including the UDM entity, no security configuration previously delivered to the UE, a security refresh for the UE, a trigger received from the UAV system service provider, or a combination thereof.
[0037] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, determining the one or more security credentials may include operations, features, components, or instructions for generating a security configuration for communications between the UE and the drone system service provider based on registration information corresponding to the UE received in the registration request, the security configuration including the one or more security credentials.
[0038] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may also include operations, features, components, or instructions for performing the following: sending an indication of the security configuration to a UDM entity; and receiving a parameter provision information message from the UDM entity, the parameter provision information message including a confirmation message indicating that the UE successfully received the indication of the security configuration, wherein communication with the UE may be based on the confirmation message.
[0039] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, sending an indication of a security configuration may include operations, features, components, or instructions for performing the following: sending an indication of the security configuration to the UDM entity via a UDM service message, a network exposure function update message, or a combination thereof.
[0040] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the registration request includes a GPSI of the UE, and wherein the one or more security credentials may be generated based on the GPSI.
[0041] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the one or more security credentials include: a UE identity for identifying the UE in communications between the UE and the drone system service provider, credentials for communications between the UE and the drone system service provider, private and public security keys for enabling communications between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 An example of a wireless communication system that supports provisioning security credentials to an unmanned aerial vehicle (UAV) in accordance with aspects of the present disclosure is shown.
[0043] Figure 2 An example of a wireless communication system supporting techniques for providing security credentials to a UAV in accordance with aspects of the present disclosure is shown.
[0044] Figure 3 、 Figure 4 and 5 An example of a process flow in a system supporting techniques for provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown.
[0045] Figure 6 and Figure 7 A block diagram of a device that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown.
[0046] Figure 8 A block diagram of a user equipment (UE) communications manager that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown.
[0047] Figure 9 Diagrams of systems including devices that support provisioning security credentials to a UAV are shown in accordance with aspects of the present disclosure.
[0048] Figure 10 and Figure 11 A block diagram of a device that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown.
[0049] Figure 12 A block diagram of a communications manager that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown.
[0050] Figure 13 Diagrams of systems including devices that support provisioning security credentials to a UAV are shown in accordance with aspects of the present disclosure.
[0051] Figures 14 to 19 A flow chart illustrating a method for supporting provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown. DETAILED DESCRIPTION
[0052] Unmanned aerial vehicles (UAVs) (which may also be referred to as drones) may include the ability to send or receive wireless signals, including sending various messages to other devices (e.g., to other UAVs or ground-based equipment). For example, in the United States, the Federal Aviation Administration (FAA) has implemented remote identification of unmanned aerial vehicle systems (UAS) to enable public and civilian identification of UAS for safety, security, and compliance purposes. Specifically, remote identification enables UASs to broadcast information that, in addition to various parameters related to the UAV's movement (including position, direction vector, latitude, longitude, speed, direction, altitude, etc.), also includes one or more assigned remote identifiers (IDs) corresponding to the UAV's identity (e.g., aircraft ID). Thus, remote IDs can provide a way to receive information about UAVs for tracking and collision avoidance. However, remote IDs assigned to UAVs may be forged, resulting in security oversights. For example, a fraudulent remote ID for a UAV may affect the UAV's operation. In some cases, a fraudulent remote ID may cause one or more UAVs to stop, reverse, land, or maneuver based on the corresponding fraudulent location information in the ID. Such a security breach may be referred to as a denial of service (DoS) attack and may result in inefficient operation of the UAV and loss or damage to property.
[0053] As described herein, a user equipment (UE) associated with a UAV may receive security credentials from a network entity (e.g., from a unified data management (UDM) entity via an access and mobility management function (AMF)) to enable secure communications with a service provider (e.g., a UAV flight service provider (UFSS), a UAS service provider (USS), or both). For example, the UDM entity may generate security credentials corresponding to a security configuration and assign them to the UAV. In some cases, the UDM entity may deliver the security configuration to the UE associated with the UAV (e.g., via the AMF) using a parameter update message (e.g., a non-access stratum (NAS) transport message). The UDM entity may update the UAV with parameters by delivering protected UDM update data via national airspace system signaling (e.g., via a NAS transport message based on service provider policy). In some cases, the UAV may perform security checks on the received UDM update data. The UDM entity may send the generated security credentials to the service provider to enable communications between the service provider and the UE and UAV.
[0054] Additionally or alternatively, the service provider (e.g., UFSS, USS, or both) may generate security credentials. For example, a UE associated with a UAV may first issue a registration request to the service provider. Using the Universal Public Subscription Identifier (GPSI) provided by the UE in the registration request, the service provider may determine that the UE associated with the UAV may not have a security configuration and may (e.g., via the AMF) provide a security configuration to the UDM entity to push to the UE. In some cases, the UE associated with the UAV may receive one or more IDs (e.g., remote IDs) for operation on the carrier. In some cases, the one or more IDs may correspond to a broadcast remote ID (BRID), a network remote ID (NRID), or both for communication between the carrier and the service provider. The one or more IDs may be protected by a security configuration.
[0055] Various aspects of the present disclosure are first described in the context of a wireless communication system. Additional examples are then provided regarding program flow. Various aspects of the present disclosure are further illustrated and described with reference to device diagrams, system diagrams, and flow charts related to techniques for providing security credentials to a UAV.
[0056] Figure 1 An example of a wireless communication system 100 that supports techniques for providing security credentials to a UAV in accordance with aspects of the present disclosure is shown. The wireless communication system 100 may include one or more base stations 105, one or more UEs 115, and a core network 130. In some examples, the wireless communication system 100 may be a Long Term Evolution (LTE) network, an Advanced LTE (LTE-A) network, an LTE-A Pro network, or a New Radio (NR) network. In some examples, the wireless communication system 100 may support enhanced broadband communications, ultra-reliable (e.g., mission-critical) communications, low-latency communications, communications with low-cost and low-complexity devices, or any combination thereof, among others.
[0057] Base stations 105 may be dispersed throughout a geographic area to form wireless communication system 100 and may be devices of different forms or capabilities. Base stations 105 and UEs 115 may communicate wirelessly via one or more communication links 125. Each base station 105 may provide a coverage area 110 over which UEs 115 and base stations 105 may establish one or more communication links 125. Coverage area 110 may be an example of a geographic area over which base stations 105 and UEs 115 may support communication of signals according to one or more radio access technologies.
[0058] The UEs 115 may be dispersed throughout the coverage area 110 of the wireless communication system 100, and each UE 115 may be fixed or mobile, or fixed or mobile at different times. The UEs 115 may be devices of different forms or with different capabilities. Figure 1 Some exemplary UEs 115 are shown in FIG. The UEs 115 described herein are capable of communicating with various types of devices, such as other UEs 115, base stations 105, or network devices (e.g., core network nodes, relays, integrated access and backhaul (IAB) nodes, or other network devices). Figure 1 shown.
[0059] The wireless communication system 100 may include one or more repeating devices (e.g., wireless repeaters). The wireless repeaters may include functionality to forward, extend, and redirect wireless signals transmitted within the wireless communication system. In some cases, wireless repeaters may be used in line-of-sight (LOS) or non-line-of-sight (NLOS) scenarios. In LOS scenarios, directional (e.g., beamforming) transmissions (such as mmW transmissions) may be limited by path loss through the air. In NLOS scenarios (such as in urban areas or indoors), mmW transmissions may be limited by signal blocking or signal-interfering physical objects. In either scenario, the wireless repeater may be used to receive signals from the base station 105 and transmit the signals to the UE 115, or to receive signals from the UE 115 and transmit the signals to the base station 105. The wireless repeater may utilize beamforming, filtering, gain control, and phase correction techniques to improve signal quality and avoid radio frequency interference with the transmitted signal.
[0060] Base stations 105 can communicate with core network 130, or with each other, or both. For example, base stations 105 can interface with core network 130 via one or more backhaul links 120 (e.g., via S1, N2, N3, or other interfaces). Base stations 105 can communicate with each other via backhaul links 120 (e.g., via X2, Xn, or other interfaces) directly (e.g., directly between base stations 105) or indirectly (e.g., via core network 130), or both. In some examples, backhaul links 120 can be or include one or more wireless links.
[0061] One or more of the base stations 105 described herein may include or may be referred to by one of ordinary skill in the art as a base station transceiver, a radio base station, an access point, a radio transceiver, a NodeB, an eNodeB (eNB), a next generation NodeB or a giga-NodeB (any of which may be referred to as a gNB), a Home NodeB, a Home eNodeB, or other suitable terminology.
[0062] UE 115 may also include or be referred to as a mobile device, a wireless device, a remote device, a handheld device, or a subscriber device, or some other suitable terminology, where a "device" may also be referred to as a unit, a station, a terminal, or a client, etc. UE 115 may also include or be referred to as a personal electronic device, such as a cellular phone, a personal digital assistant (PDA), a tablet computer, a laptop computer, or a personal computer. In some examples, UE 115 may include or be referred to as a wireless local loop (WLL) station, an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a machine type communication (MTC) device, etc., which may be implemented in various objects such as household appliances or vehicles, meters, etc. In some examples, UE 115 may be an example of a drone or UAV.
[0063] The UE 115 described herein may be capable of communicating with various types of devices, such as other UEs 115, which may sometimes act as relays, as well as base stations 105 and network devices (including macro eNBs or gNBs, small cell eNBs or gNBs, or relay base stations, etc., such as Figure 1 shown).
[0064] The UE 115 and the base station 105 can wirelessly communicate with each other via one or more communication links 125 on one or more carriers. The term "carrier" can refer to a set of radio spectrum resources having a defined physical layer structure for supporting the communication link 125. For example, a carrier used for the communication link 125 can include a portion of a radio frequency spectrum band (e.g., a bandwidth part (BWP) that operates according to one or more physical layer channels for a given radio access technology (e.g., LTE, LTE-A, LTE-A Pro, NR)). Each physical layer channel can carry acquisition signaling (e.g., synchronization signals, system information), control signaling to coordinate operations for the carrier, user data, or other signaling. The wireless communication system 100 can use carrier aggregation or multi-carrier operation to support communication with the UE 115. Depending on the carrier aggregation configuration, the UE 115 can be configured with multiple downlink component carriers and one or more uplink component carriers. Carrier aggregation can be used with frequency division duplex (FDD) and time division duplex (TDD) component carriers.
[0065] In some examples (e.g., in a carrier aggregation configuration), a carrier may also have acquisition signaling or control signaling that coordinates the operation of other carriers. A carrier may be associated with a frequency channel (e.g., an Evolved Universal Mobile Telecommunications System Terrestrial Radio Access (E-UTRA) Absolute Radio Frequency Channel Number (EARFCN)) and may be located according to a channel raster for discovery by a UE 115. A carrier may operate in a standalone mode, where initial acquisition and connection may be performed by a UE 115 via the carrier, or in a non-standalone mode, where a different carrier (e.g., of the same or different radio access technology) is used to anchor the connection.
[0066] The communication link 125 shown in the wireless communication system 100 may include uplink transmissions from the UE 115 to the base station 105, or downlink transmissions from the base station 105 to the UE 115. A carrier may carry downlink or uplink communications (e.g., in FDD mode) or may be configured to carry both downlink and uplink communications (e.g., in TDD mode).
[0067] A carrier may be associated with a particular bandwidth of a radio frequency spectrum, and in some examples, the carrier bandwidth may be referred to as the "system bandwidth" of the carrier or wireless communication system 100. For example, the carrier bandwidth may be one of a plurality of determined bandwidths of a carrier for a particular radio access technology (e.g., 1.4, 3, 5, 10, 15, 20, 40, or 80 megahertz (MHz)). The devices of the wireless communication system 100 (e.g., base station 105, UE 115, or both) may have a hardware configuration that supports communication on a particular carrier bandwidth, or may be configured to support communication on one carrier bandwidth in a set of carrier bandwidths. In some examples, the wireless communication system 100 may include a base station 105 and a UE 115 that support simultaneous communication via carriers associated with multiple carrier bandwidths. In some examples, each served UE 115 may be configured to operate on a portion (e.g., a subband, a BWP) or all of the carrier bandwidth.
[0068] The signal waveform transmitted via the carrier may be composed of multiple subcarriers (e.g., using a multicarrier modulation (MCM) technique, such as orthogonal frequency division multiplexing (OFDM) or discrete Fourier transform spread OFDM (DFT-S-OFDM)). In a system employing MCM technology, a resource element may be composed of one symbol period (e.g., the duration of one modulation symbol) and one subcarrier, where the symbol period is inversely proportional to the subcarrier spacing. The number of bits carried by each resource element may depend on the modulation scheme (e.g., the order of the modulation scheme, the coding rate of the modulation scheme, or both). Therefore, the more resource elements received by the UE 115 and the higher the order of the modulation scheme, the higher the data rate of the UE 115. Wireless communication resources may refer to a combination of radio frequency spectrum resources, time resources, and spatial resources (e.g., spatial layers or beams), and the use of multiple spatial layers may further improve the data rate or data integrity of communications with the UE 115.
[0069] One or more digital parameters for a carrier may be supported, where the digital parameters may indicate subcarrier spacing (Δf) and a cyclic prefix. A carrier may be divided into one or more BWPs with the same or different digital parameters. In some examples, a UE 115 may be configured with multiple BWPs. In some examples, a single BWP for a carrier may be valid at a given time, and communications for a UE 115 may be limited to one or more valid BWPs.
[0070] The time interval of the base station 105 or the UE 115 may be expressed as a multiple of a basic time unit, for example, the basic time unit may be referred to as T s =1 / (Δf max ·N f ) seconds sampling period, where Δf max It can represent the maximum supported subcarrier spacing, and N f The maximum supported Discrete Fourier Transform (DFT) size may be indicated. Time intervals of communication resources may be organized according to radio frames, each having a specified duration (e.g., 10 milliseconds (ms)). Each radio frame may be identified by a System Frame Number (SFN) (e.g., in the range 0 to 1023).
[0071] Each frame can include multiple consecutively numbered subframes or time slots, and each subframe or time slot can have the same duration. In some examples, the frame can be divided (e.g., in the time domain) into subframes, and each subframe can be further divided into multiple time slots. Alternatively, each frame can include a variable number of time slots, and the number of time slots can depend on the subcarrier spacing. Each time slot can include multiple symbol periods (e.g., depending on the length of the cyclic prefix that precedes each symbol period). In some wireless communication systems 100, the time slot can be further divided into multiple micro-time slots containing one or more symbols. In addition to the cyclic prefix, each symbol period can contain one or more (e.g., N f ) sampling period. The duration of a symbol period may depend on the subcarrier spacing or frequency band of operation.
[0072] A subframe, slot, mini-slot, or symbol may be the smallest scheduling unit (e.g., in the time domain) of the wireless communication system 100 and may be referred to as a Transmit Time Interval (TTI). In some examples, the TTI duration (e.g., the number of symbol periods in a TTI) may be variable. Additionally or alternatively, the smallest scheduling unit of the wireless communication system 100 may be dynamically selected (e.g., in bursts of shortened TTIs (sTTIs)).
[0073] Physical channels can be multiplexed on a carrier according to various techniques. Physical control channels and physical data channels can be multiplexed on a downlink carrier, for example, using one or more of time division multiplexing (TDM), frequency division multiplexing (FDM), or hybrid TDM-FDM techniques. A control region (e.g., a control resource set (CORESET)) for physical control channels can be defined by a number of symbol periods and can extend across the system bandwidth of a carrier or a subset of the system bandwidth. One or more control regions (e.g., CORESETs) can be configured for a group of UEs 115. For example, one or more UEs 115 can monitor or search the control region for control information according to one or more search space sets, and each search space set can include one or more control channel candidates at one or more aggregation levels arranged in a cascaded manner. The aggregation level for a control channel candidate can refer to the number of control channel resources (e.g., control channel elements (CCEs)) associated with the coded information for a control information format having a given payload size. A search space set can include a common search space set configured for sending control information to multiple UEs 115 and a UE-specific search space set for sending control information to a specific UE 115.
[0074] Each base station 105 can provide communication coverage via one or more cells (e.g., macro cells, small cells, hot spots, or other types of cells, or any combination thereof). The term "cell" can refer to a logical communication entity used for communication with a base station 105 (e.g., via a carrier) and can be associated with an identifier (e.g., a physical cell identifier (PCID), a virtual cell identifier (VCID), or other) used to distinguish adjacent cells. In some examples, a cell can also refer to a geographic coverage area 110 or a portion of a geographic coverage area 110 (e.g., a sector) on which a logical communication entity operates. Depending on various factors such as the capabilities of the base station 105, such cells can range from a smaller area (e.g., a structure, a subset of a structure) to a larger area. For example, a cell can be or include a building, a subset of a building, or an external space between or overlapping a geographic coverage area 110, etc.
[0075] A macro cell typically covers a relatively large geographic area (e.g., a radius of several kilometers) and can allow unrestricted access to UEs 115 that have a service subscription with a network provider that supports the macro cell. Small cells can be associated with base stations 105 with lower power than macro cells, and small cells can operate in the same or different frequency bands (e.g., licensed, unlicensed) as the macro cell. Small cells can provide unrestricted access to UEs 115 that have a service subscription with the network provider, or can provide restricted access to UEs 115 associated with the small cell (e.g., UEs 115 in a closed subscriber group (CSG), UEs 115 associated with users at home or in the office). A base station 105 can support one or more cells and can also support communication on one or more cells using one or more component carriers. In some examples, a carrier can support multiple cells, and different cells can be configured according to different protocol types (e.g., MTC, narrowband IoT (NB-IoT), enhanced mobile broadband (eMBB)) that can provide access to different types of devices.
[0076] In some examples, base stations 105 can be mobile and, therefore, provide communication coverage for mobile geographic coverage areas 110. In some examples, different geographic coverage areas 110 associated with different technologies can overlap, but the different geographic coverage areas 110 can be supported by the same base station 105. In other examples, overlapping geographic coverage areas 110 associated with different technologies can be supported by different base stations 105. The wireless communication system 100 can include, for example, a heterogeneous network in which different types of base stations 105 provide coverage for various geographic coverage areas 110 using the same or different radio access technologies.
[0077] The wireless communication system 100 can support synchronous or asynchronous operation. For synchronous operation, the base stations 105 can have similar frame timing, and transmissions from different base stations 105 are approximately aligned in time. For asynchronous operation, the base stations 105 can have different frame timing, and in some examples, transmissions from different base stations 105 may not be aligned in time. The techniques described herein can be used for either synchronous or asynchronous operation.
[0078] Some UEs 115, such as MTC or IoT devices, may be low-cost or low-complexity devices and may provide automated communication between machines (e.g., via machine-to-machine (M2M) communication). M2M communication or MTC may refer to data communication technology that allows devices to communicate with each other or with a base station 105 without human intervention. In some examples, M2M communication or MTC may include communications from devices that incorporate sensors or meters to measure or capture information and relay this information to a central server or application that utilizes the information or presents the information to a human interacting with the application. Some UEs 115 may be designed to collect information or implement automated behavior of machines or other equipment. Examples of applications for MTC devices include smart metering, inventory monitoring, water level monitoring, equipment monitoring, healthcare monitoring, wildlife monitoring, weather and geological event monitoring, fleet management and tracking, remote security sensing, physical access control, and transaction-based billing for services.
[0079] Some UEs 115 may be configured to employ a mode of operation that reduces power consumption, such as half-duplex communication (e.g., a mode that supports one-way communication via transmission or reception, but not simultaneous transmission and reception). In some examples, half-duplex communication may be performed at a reduced peak rate. Other power saving techniques for the UE 115 include entering a power-saving "deep sleep" mode when not engaged in active communication, operating over a limited bandwidth (e.g., according to narrowband communication), or a combination of these techniques. For example, some UEs 115 may be configured to operate using a narrowband protocol type associated with a defined portion or range (e.g., a set of subcarriers or resource blocks (RBs)) within a carrier, within a guard band of a carrier, or outside of a carrier.
[0080] The wireless communication system 100 can be configured to support ultra-reliable communication or low-latency communication or various combinations thereof. For example, the wireless communication system 100 can be configured to support ultra-reliable low-latency communication (URLLC) or mission-critical communication. UE 115 can be designed to support ultra-reliable low-latency or critical functions (e.g., mission-critical functions). Ultra-reliable communication can include private communication or group communication and can be supported by one or more mission-critical services such as mission-critical push-to-talk (MCPTT), mission-critical video (MCVideo), or mission-critical data (MCData). Support for mission-critical functions may include prioritization of services, and mission-critical services can be used for public safety or general commercial applications. The terms ultra-reliable, low-latency, mission-critical, and ultra-reliable low-latency can be used interchangeably in this article.
[0081] In some examples, UE 115 can also communicate directly with other UEs 115 via device-to-device (D2D) communication links 135 (e.g., using a peer-to-peer (P2P) or D2D protocol). One or more UEs 115 utilizing D2D communication may be within the geographic coverage area 110 of base station 105. Other UEs 115 in the group may be outside the geographic coverage area 110 of base station 105 or unable to receive transmissions from base station 105. In some examples, multiple groups of UEs 115 communicating via D2D communication may utilize a one-to-many (1:M) system, in which each UE 115 transmits to each other UE 115 in the group. In some examples, base station 105 facilitates the scheduling of resources for D2D communication. In other cases, D2D communication is performed between UEs 115 without the involvement of base station 105.
[0082] In some systems, the D2D communication link 135 can be an example of a communication channel between vehicles (e.g., UE 115), such as a sidelink communication channel. In some examples, vehicles can communicate using vehicle-to-everything (V2X) communication, vehicle-to-vehicle (V2V) communication, or some combination of these. Vehicles can signal information related to traffic conditions, signal scheduling, weather, safety, emergency situations, or any other information related to the V2X system. In some examples, vehicles in a V2X system can communicate with roadside infrastructure (such as roadside units) or communicate with a network using vehicle-to-network (V2N) communication via one or more network nodes (e.g., base station 105), or both.
[0083] The core network 130 may provide user authentication, access authorization, tracking, Internet Protocol (IP) connectivity, and other access, routing, or mobility functions. The core network 130 may be an evolved packet core (EPC) or a 5G core (5GC), which may include at least one control plane entity (e.g., a mobility management entity (MME), an access and mobility management function (AMF)) that manages access and mobility and at least one user plane entity (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)) that routes packets or interconnections to external networks. The control plane entities may manage NAS functions such as mobility, authentication, and bearer management for the UE 115 served by the base station 105 associated with the core network 130. User IP packets may be delivered through the user plane entities, which may provide IP address allocation and other functions. The user plane entities may be connected to the network operator IP service 150. The operator IP service 150 may include access to the Internet, an intranet, an IP multimedia subsystem (IMS), or a packet-switched streaming service.
[0084] Some network devices, such as base stations 105, may include subcomponents such as access network entities 140, which may be examples of access node controllers (ANCs). Each access network entity 140 may communicate with a UE 115 via one or more other access network transmit entities 145, which may be referred to as radio heads, smart radio heads, or transmit / receive points (TRPs). Each access network transmit entity 145 may include one or more antenna panels. In some configurations, the various functions of each access network entity 140 or base station 105 may be distributed across various network devices (e.g., radio heads and ANCs) or consolidated into a single network device (e.g., base station 105).
[0085] The wireless communication system 100 can operate using one or more frequency bands, for example, in the range of 300 megahertz (MHz) to 300 gigahertz (GHz). Typically, the region from 300 MHz to 3 GHz is referred to as the ultra-high frequency (UHF) region or decimeter band, because the lengths of wavelengths range from approximately 1 decimeter to 1 meter. UHF waves can be blocked or redirected by buildings and environmental features, but the waves can penetrate structures sufficiently for a macrocell to provide service to a UE 115 located indoors. Transmission of UHF waves can be associated with smaller antennas and a shorter range (e.g., less than 100 kilometers) than transmission using the lower frequencies and longer waves of the high frequency (HF) or very high frequency (VHF) portions of the spectrum below 300 MHz.
[0086] The wireless communication system 100 may also operate in a super high frequency (SHF) region using a frequency band from 3 GHz to 30 GHz (also known as the centimeter band) or in an extremely high frequency (EHF) region of the spectrum (e.g., from 30 GHz to 300 GHz) (also known as the millimeter band). In some examples, the wireless communication system 100 may support millimeter wave (mmW) communications between the UE 115 and the base station 105, and the EHF antennas of the respective devices may be smaller and more closely spaced than the UHF antennas. In some examples, this may facilitate the use of antenna arrays within the device. However, the propagation of EHF transmissions may be affected by greater atmospheric attenuation and shorter distances than SHF or UHF transmissions. The techniques disclosed herein may be employed across transmissions using one or more different frequency regions, and the designated use of bands across these frequency regions may vary by country or regulatory body.
[0087] The wireless communication system 100 can utilize both licensed radio frequency spectrum bands and unlicensed radio frequency spectrum bands. For example, the wireless communication system 100 can employ license assisted access (LAA), unlicensed LTE (LTE-U) radio access technology, or NR technology in an unlicensed band such as the 5 GHz industrial, scientific, and medical (ISM) band. When operating in an unlicensed radio frequency spectrum band, devices such as the base station 105 and the UE 115 can employ carrier sensing for conflict detection and fallback. In some examples, operations in the unlicensed frequency band can be based on a carrier aggregation configuration, in combination with component carriers operating in a licensed band (e.g., LAA). Operations in the unlicensed spectrum can include downlink transmissions, uplink transmissions, P2P transmissions, or D2D transmissions, among others.
[0088] The base station 105 or UE 115 may be equipped with multiple antennas that can be used to employ techniques such as transmit diversity, receive diversity, multiple-input multiple-output (MIMO) communications, or beamforming. The antennas of the base station 105 or UE 115 may be located within one or more antenna arrays or antenna panels that can support MIMO operations or transmit or receive beamforming. For example, one or more base station antennas or antenna arrays may be co-located in an antenna assembly such as an antenna tower. In some examples, the antennas or antenna arrays associated with the base station 105 may be located in different geographical locations. The base station 105 may have an antenna array with rows and columns of multiple antenna ports that the base station 105 may use to support beamforming for communications with the UE 115. Similarly, the UE 115 may have one or more antenna arrays that can support various MIMO or beamforming operations. Additionally or alternatively, the antenna panel may support radio frequency beamforming for signals transmitted via the antenna ports.
[0089] The base station 105 or the UE 115 can use MIMO communication to take advantage of multipath signal propagation and improve spectral efficiency by sending or receiving multiple signals via different spatial layers. Such technology can be referred to as spatial multiplexing. Multiple signals can be sent, for example, by a transmitting device via different antennas or different combinations of antennas. Similarly, multiple signals can be received by a receiving device via different antennas or different combinations of antennas. Each of the multiple signals can be referred to as a separate spatial stream and can carry bits associated with the same data stream (e.g., the same codeword) or different data streams (e.g., different codewords). Different spatial layers can be associated with different antenna ports for channel measurement and reporting. MIMO technology includes single-user MIMO (SU-MIMO) that sends multiple spatial layers to the same receiving device and multi-user MIMO (MU-MIMO) that sends multiple spatial layers to multiple devices.
[0090] Beamforming (which may also be referred to as spatial filtering, directional transmission, or directional reception) is a signal processing technique that can be used in a transmitting device or a receiving device (e.g., a base station 105, a UE 115) to shape or steer an antenna beam (e.g., a transmit beam, a receive beam) along a spatial path between the transmitting device and the receiving device. Beamforming can be achieved by combining signals conveyed via antenna elements of an antenna array so that some signals propagating in a particular orientation relative to the antenna array experience constructive interference, while other signals experience destructive interference. Adjustments to signals transmitted via antenna elements can include the transmitting device or the receiving device applying an amplitude offset, a phase offset, or both to the signals carried via the antenna elements associated with the device. The adjustments associated with each of the antenna elements can be defined by a set of beamforming weights associated with a particular orientation (e.g., relative to the antenna array of the transmitting device or the receiving device, or relative to some other orientation).
[0091] The base station 105 or the UE 115 can use beam sweeping techniques as part of a beamforming operation. For example, the base station 105 can use multiple antennas or antenna arrays (e.g., antenna panels) to perform beamforming operations for directional communication with the UE 115. The base station 105 can transmit some signals (e.g., synchronization signals, reference signals, beam selection signals, or other control signals) multiple times in different directions. For example, the base station 105 can transmit signals according to different sets of beamforming weights associated with different transmit directions. The transmissions in different beam directions can be used to identify (e.g., by a transmitting device such as the base station 105, or by a receiving device such as the UE 115) the beam direction for later transmission or reception by the base station 105.
[0092] Base station 105 may transmit some signals, such as data signals associated with a particular receiving device, in a single beam direction (e.g., a direction associated with a receiving device such as UE 115). In some examples, the beam direction associated with transmission along the single beam direction may be determined based on signals transmitted in one or more beam directions. For example, UE 115 may receive one or more signals transmitted by base station 105 in different directions and may report to base station 105 an indication of the signal received by UE 115 with the highest signal quality or other acceptable signal quality.
[0093] In some examples, transmission by a device (e.g., by a base station 105 or a UE 115) may be performed using multiple beam directions, and the device may use a combination of digital precoding or radio frequency beamforming to generate a combined beam for transmission (e.g., from the base station 105 to the UE 115). The UE 115 may report feedback indicating precoding weights for one or more beam directions, and the feedback may correspond to a configured number of beams across the system bandwidth or across one or more subbands. The base station 105 may transmit a reference signal (e.g., a cell-specific reference signal (CRS), a channel state information reference signal (CSI-RS)), which may be precoded or unprecoded. The UE 115 may provide feedback for beam selection, which may be a precoding matrix indicator (PMI) or feedback based on a codebook (e.g., a multi-panel codebook, a linear combination codebook, a port selection codebook). Although these techniques are described with reference to signals sent by base station 105 in one or more directions, UE 115 may employ similar techniques to send signals multiple times in different directions (e.g., to identify a beam direction for subsequent transmission or reception by UE 115) or to send signals in a single direction (e.g., to send data to a receiving device).
[0094] When receiving various signals (such as synchronization signals, reference signals, beam selection signals, or other control signals) from base station 105, a receiving device (e.g., UE 115) may attempt multiple reception configurations (e.g., directional listening). For example, the receiving device may attempt multiple reception directions by receiving via different antenna subarrays, by processing received signals according to different antenna subarrays, by receiving according to different receive beamforming weight sets applied to signals received at multiple antenna elements of an antenna array (e.g., different directional listening weight sets), or by processing received signals according to different receive beamforming weight sets applied to signals received at multiple antenna elements of an antenna array, any of which may be referred to as "listening" according to different reception configurations or reception directions. In some examples, the receiving device may use a single receive beam to receive along a single configuration direction (e.g., when receiving data signals). The single receive configuration may be aligned in a beam direction determined based on listening according to different reception configuration directions (e.g., a beam direction determined to have the highest signal strength, the highest signal-to-noise ratio (SNR), or another acceptable signal quality based on listening according to multiple beam directions).
[0095] The wireless communication system 100 can be a packet-based network that operates according to a layered protocol stack. In the user plane, communications on the bearer or packet data convergence protocol (PDCP) layer can be IP-based. The radio link control (RLC) layer can perform packet segmentation and reassembly to communicate over logical channels. The medium access control (MAC) layer can perform priority processing and multiplex logical channels into transport channels. The MAC layer can also use error detection technology, error correction technology, or both to support retransmission of the MAC layer to improve link efficiency. In the control plane, the radio resource control (RRC) protocol layer can provide the establishment, configuration, and maintenance of an RRC connection between the UE 115 and the base station 105 or the core network 130 that supports radio bearers for user plane data. In the physical layer, transport channels can be mapped to physical channels.
[0096] UE 115 and base station 105 can support retransmission of data to increase the likelihood that the data is successfully received. Hybrid automatic repeat request (HARQ) feedback is a technique for increasing the likelihood of correctly receiving data over communication link 125. HARQ can include a combination of error detection (e.g., using a cyclic redundancy check (CRC)), forward error correction (FEC), and retransmission (e.g., automatic repeat request (ARQ)). Under poor radio conditions (e.g., low signal-to-noise ratio conditions), HARQ may improve throughput in the MAC layer. In some examples, a device can support HARQ feedback for the same time slot, wherein the device can provide HARQ feedback in a particular time slot for data received in a previous symbol in the time slot. In other cases, the device can provide HARQ feedback in a subsequent time slot or according to some other time interval.
[0097] When one or more UEs 115 in the wireless communication system 100 are drones or UAVs, various requirements for UAV traffic management may exist. Specifically, drones or UAVs may fundamentally change aviation, and regulatory agencies (such as the FAA, the European Union Aviation Safety Agency (EASA)), etc.) may require that drones or UAVs be fully integrated into the national airspace system. Here, safety and security may be high priorities for such systems, and the use of technologies such as FAA and EASA's U-Space Remote Identification may impact integration efforts. In some examples, UAS Remote Identification includes the ability for a UAS in flight to provide identification information that can be received by other parties. Remote Identification can help facilitate advanced operations for UASs and provide a foundation for UAS Traffic Management (UTM). Furthermore, when a UAS appears to be flying in an unsafe manner or in situations where a drone is not permitted to fly, remote identification can assist regulatory agencies, flight control agencies, law enforcement (e.g., where the ground control system is the Federal Bureau of Investigation (FBI) or a police terminal), and federal security agencies. Furthermore, remote identification can expand the operational environment of drones in one or more areas (e.g., in critical areas).
[0098] As UAV operations become increasingly common (e.g., for commercial and private operations), various countries and regions may begin implementing various aspects of providing a structure for UAV safety management. For example, in the United States, service providers (such as USS or UFSS) may be certified by the FAA. Each service provider may be responsible for exchanging data with other service providers and coordinating. Therefore, the wireless communication system 100 can support the coexistence of UAVs and service providers through signaling provided by the terrestrial cellular network. For example, one or more IDs (e.g., remote IDs) may be assigned to a UAV or drone (which may be an example of a UE 115) for communicating with a service provider or broadcasting information to surrounding devices (e.g., in a BRID message). The BRID message may include various parameters or instructions associated with the UAV and used by other devices to detect and learn information about the UAV (e.g., including the UAV's location, ID, flight information, etc.). However, the ID assigned to the UAV may be forged, resulting in security oversights. For example, information in a fraudulent ID for the UAV (such as location information) may affect the operation of the UAV. In some cases, a fraudulent ID could cause one or more UAVs to stop, reverse, land, or maneuver based on the corresponding fraudulent location information in the ID. This security vulnerability can be referred to as a denial of service (DoS) attack and could result in inefficient operation of the UAVs and loss or damage to property.
[0099] In such cases, a network entity in the wireless communication system 100 (such as a UDM entity associated with the core network 130) may coordinate with a UE 115 associated with a UAV or USS to deliver security configurations for communications with a service provider to the UAV. For example, the UE 115 associated with the UAV may receive security credentials from a network entity associated with the core network 130 (e.g., from the UDM entity via the AMF) to enable secure communications with a service provider (e.g., a UFSS, a USS, or both). For example, the UDM entity may generate security credentials corresponding to the security configurations and assign them to the UAV. In some cases, the UDM entity may deliver the security configurations to the UE 115 associated with the UAV (e.g., via the AMF) using a parameter update message (e.g., a NAS transport message). The UDM entity may update the UAV with parameters by delivering protected UDM update data via national airspace system signaling (e.g., via a NAS transport message based on service provider policy). In some cases, the UAV may perform security checks on the received UDM update data. The UDM entity may send the generated security credentials to the service provider to enable communication between the service provider and the UE 115 and the UAV.
[0100] Additionally or alternatively, a service provider (e.g., UFSS, USS, or both) may generate security credentials. For example, a UE 115 associated with a UAV may issue a registration request to a service provider. Using the GPSI (e.g., or a different type of identifier for a UE or UAV) provided by the UE in the registration request, the service provider may determine that the UE associated with the UAV may not have a security configuration and may (e.g., via the AMF) provide a security configuration to the UDM entity to push to the UE 115. In some cases, the UE 115 associated with the UAV may receive one or more IDs (e.g., remote IDs) for operation on the carrier. In some cases, the one or more IDs may correspond to a BRID, NRID, or both used for communication between the carrier and the service provider. The one or more IDs may be protected by a security configuration.
[0101] It should be noted that although some aspects of the present disclosure are described with respect to remote identification and USS implementations (which may be associated with aspects implemented by the FAA in the United States), the same or similar techniques may also be applicable to other flight management systems used in other regions or countries. That is, the techniques described herein should not be considered limited to remote identification or the FAA, and such techniques may be applicable to other systems and functions that provide UAS flight management. For example, the described techniques may be utilized in the European U-space system and other examples.
[0102] Figure 2 An example of a wireless communication system 200 that supports techniques for providing security credentials to a UAV according to aspects of the present disclosure is shown. In some examples, the wireless communication system 200 can implement aspects of the wireless communication system 100. For example, the wireless communication system 200 can include a base station 105-a having a coverage area 110-a, a UE 115-a, and a core network 130-a, which can be as described in reference to FIG. Figure 1 The wireless communication system 100 may include one or more UAVs 205 (e.g., drones). In some cases, the UAVs 205 may be as described in reference to Figure 1 1. The base station 105-a and the UE 115-a may communicate via a communication link 125-a, the base station 105-a and the UAV 205 may communicate via a communication link 125-b, and the UAV 205 and the UE 115-a may communicate via a communication link 125-c, which may be as described with reference to FIG. Figure 1An example of a communication link 125 is depicted. Although a base station 105 is shown for illustrative purposes, a UE 115-a may communicate with various wireless devices, such as another UE 115, a repeater device, or other wireless devices.
[0103] Although one UAV 205 is shown, the wireless communication system 200 may include any number of UAVs 205. In some cases, the UE 115 may be an example of an alternative communication device, such as a cellular device. For example, the UE 115-a may be an example of a cellular device. The base station 105-a, the UE 115-a, and the UAV 205 may exchange information (e.g., via the communication link 125, sidelink communication, or both).
[0104] The UAV 205 may be part of a UAS. The UAS may include a UAV controller and one or more UAVs 205, wherein each of the one or more UAVs 205 may be connected or communicate with each other using wireless communication technology. In some cases, the UAV controller may be configured to issue functions and commands (e.g., navigation, generating geo-fences, detection, monitoring, identification, flight planning) to the UAV 205, and receive data (e.g., telemetry) from the UAV 205. Additionally or alternatively, the UAV controller may be coupled to a communication device (e.g., UE 115-a) that may be used to communicate with the UAV 205 as described in reference to FIG. Figure 1 The wireless network described herein (e.g., such as via base station 105-a and core network 130-a) communicates to relay information to and from the UAV 205. In some cases, a communication device (e.g., UE 115-a) can also be used to control or operate the UAV 205. In other examples, the UAV controller can be connected to a wireless network (e.g., a Third Generation Partnership Project (3GPP) mobile network), to the Internet, or both. Additionally or alternatively, the UAV controller can be unconnected to a mobile network and can utilize, for example, a command and control (C2) interface.
[0105] In some cases, the UAV 205 may send or receive information from the core network 130-a via the core network link 210-a. The base station 105-a may send or receive information between the core network 130-a and the UAV 205, the UE 115-a, or both via the core network link 210-b. The core network 130-a may include a UFSS 215, a USS 220, or both, which may communicate with each other via the link 230. For example, the UFSS 215 and the USS 220 may exchange information about the UAV 205. Additionally or alternatively, the UFSS 215, the USS 220, or both may communicate with the UDM entity 225 via the link 235 and the link 240, respectively. In some examples, the UDM entity 225 may exchange additional information about the UAV 205. In some cases, each UAV 205 of the UAS may exchange application data traffic with the USS 220. The core network 130-a may also include an AMF 245, which may act as an intermediary between the UDM entity 225 and the base station 105-a, the UAV 205, the UE 115-a, or a combination thereof. For example, the AMF 245 and the UDM entity 225 may communicate over a link 250 to send messages between the UDM entity 225 and the base station 105-a, the UAV 205, the UE 115-a, or a combination thereof.
[0106] The UAV 205 may be assigned one or more IDs, such as a BRID or NRID, both of which are examples of remote IDs. Remote IDs may enable public and civilian identification of UASs for safety, security, and compliance purposes. For example, remote IDs may increase the accountability of UAV operations by generating UAV identification information while preserving operational and personal privacy for UAV operators and associated personnel (e.g., a company implementing the UAV 205 and its customers). The remote ID may include multiple information parameters related to the movement of the UAV 205 (position, direction vector, latitude, longitude, speed, direction, altitude, etc.), information about the accuracy of the movement parameters, or both.
[0107] For example, the remote ID may include various data fields corresponding to information associated with the UAV 205. In some examples, the identification information may include a UAS ID (e.g., or UAV ID), which may also include a serial number (e.g., which may be represented in the ANSI / CTA-2063 entity serial number format when a registration ID is not present), a registration number (e.g., a number provided by the Civil Aviation Authority (CAA) or its authorized representative), or a UAV Traffic Management (UTM) assigned ID (UUID) (e.g., a unique ID provided by the UTM that is traceable to the registration ID and can serve as a “session ID” to protect exposure of operationally sensitive information). In some cases, parameters associated with the UAV 205 may include the UAV type (such as fixed wing, quad rotor, etc., which may distinguish between different aircraft types), a timestamp (e.g., the applicable time of the dynamic message (which may be based on a time source, such as via a global positioning system (GPS)), or the time at which the message was calculated), a timestamp accuracy (e.g., a statement of timestamp accuracy over a time period), the operating state of the UAV 205 (e.g., on the ground or in the air), an operational description (e.g., an explanation of the reason for the presence of the UAV 205), or any combination thereof. Additionally, the parameters may include fields that provide location, orientation, and movement information for the UAV 205. Various parameters may also include operator information (e.g., operator location, operator identity), group information (e.g., in the case where multiple UAVs 205 are operating in a group or formation), and security or authentication token information.
[0108] In some examples, one or more IDs assigned to a UAV 205 may enable the UAV 205 to communicate with the core network 130-a. However, the ID assigned to a UAV 205 may be forged, resulting in a security oversight. For example, a fraudulent ID for a UAV 205 in a UAS may affect the operation of the UAV 205. In some cases, a fraudulent ID may cause one or more UAVs 205 in the UAS to stop, reverse, land, or maneuver based on the corresponding fraudulent location information in the ID. Such a security vulnerability may be referred to as a denial of service (DoS) attack and may result in inefficient operation of the UAV 205 and loss or damage to property.
[0109] As described herein, the UAV 205 may receive security credentials (e.g., indirectly from the UDM entity 225 via a NAS transport message sent by the AMF 245) to enable secure communications with the UFSS 215, the USS 220, other network devices, or a combination thereof. For example, the UDM entity 225 may generate security credentials corresponding to a security configuration and assign them to the UAV 205. In some cases, the UDM entity 225 may deliver the security configuration (e.g., via the AMF 245) to a mobile entity (ME) in the UAV 205 (e.g., hardware of the UAV) using a parameter update message via a UDM control plane procedure. For example, the UDM entity 225 may generate and store one or more parameters associated with the UAV 205. In some cases, the parameters may include updated default configured network slice assistance information (NSSAI), updated routing indicator data, updated ME security configuration, or a combination thereof. The UDM entity 225 may update the UAV 205 with parameters by delivering protected UDM update data to the AMF 245 via a notification message, and the AMF 245 may send a NAS transport message to the UAV 205 carrying a security configuration generated by the UDM entity 225 (e.g., based on operator policy). In some examples, the UDM update data may include one or more parameters, a confirmation request indication, a re-registration request indication, or a combination thereof. In some cases, the UAV 205 may perform a security check on the received UDM update data. If the UDM update data passes the security check, the UAV 205 may update the routing indicator data, the default configured NSSAI data, the ME security configuration, or a combination thereof based on the UDM update data. The UDM entity 225 may send the generated security credentials to the service provider (e.g., the UFSS 215, the USS 220, or both) to enable communication between the service provider and the UAV 205.
[0110] Additionally or alternatively, a service provider (e.g., UFSS 215, USS 220, or both) may generate security credentials for communication with UAV 205. In some examples, UAV 205 may issue a registration request to UFSS 215 or USS 220. Consequently, UFSS 215 or USS 220 may determine that UAV 205 may not have a security configuration and may (e.g., via AMF 245) provide a security configuration (e.g., based on the GPSI provided by UAV 205 in the registration request) to UDM entity 225 for push to the ME. In some cases, wireless communication system 200 (which may be a wireless communication system operating according to a 3GPP mobile network standard) may provide UAV 205 with one or more IDs (e.g., remote IDs) for operation on a carrier. In some cases, one or more IDs may be used for BRID, NRID, communication between the carrier and USS 220. The one or more IDs may be protected by a security configuration. After receiving the security credentials, the UAV 205 can replace the stored security configuration (e.g., the previously used security credentials) with the security configuration corresponding to the received security credentials.
[0111] In some cases, the security configuration may include UAV credentials, security keys (e.g., private keys, public keys, or both), the ID or address of the UFSS 215, or a combination thereof. The UAV credentials may be used for communication between the UAV 205 and the UFSS 215, the USS 220, or both. The security keys may be used to protect ID information sent by the UAV 205. Additionally or alternatively, the keys may be used to verify BRID information received by the UAV 205 from other UAVs 205.
[0112] After receiving the security credentials (e.g., as assigned by the UDM entity 225 or by the UFSS 215 or USS 220, as described herein), the UAV 205 may determine whether the security credentials were successfully received. For example, if the UAV 205 determines that the security credentials were successfully received and decoded, the UAV 205 may send a positive acknowledgement message to the UDM entity 225 (e.g., via the AMF 245), and the UDM entity 225 may forward the positive acknowledgement to the UFSS 215 or USS 220, where the security credentials are then applied to subsequent communications between the UAV 205 and the UFSS 215, USS 220, or both.
[0113] In some cases, the UAV 205 may send the positive acknowledgement message in an uplink NAS transport message (e.g., in a payload container information element (e.g., a payload type information element for a UE parameter update transparent container)). After receiving a downlink NAS transport message for updating parameters of the UAV 205 (e.g., the downlink NAS transport message includes a UE parameter update list, the UE parameter update list also includes a UE parameter update data set having a UE parameter update data set type, the UE parameter update data set type indicating a security configuration for the ME of the UAV 205), the UAV 205 may determine whether to send an acknowledgement message. For example, the UAV 205 may send the positive acknowledgement message based on an acknowledgement bit received with the security credentials (e.g., an acknowledgement bit of a UE parameter update header in a UE parameter update transparent container) indicating that the UAV 205 sends acknowledgement feedback (e.g., requesting acknowledgement) and based on the fact that the information included in the downlink NAS transport message is not indicated for data to update the routing indicator. The ME of the UAV 205 replaces any stored security configuration with the security configuration included in the downlink NAS transport message. Subsequently, after sending the positive acknowledgement message, the UAV 205 and the UFSS 215, USS 220, or both may communicate securely.
[0114] Figure 3 An example of a process flow 300 in a system supporting techniques for providing security credentials to a UAV in accordance with aspects of the present disclosure is shown. In some examples, the process flow 300 may implement aspects of the wireless communication system 100 and the wireless communication system 200. The process flow 300 may include a UAV or UE 115-b, an AMF 245-a, and a UDM entity 225-a, which may be as described in reference Figure 1 and Figure 2 Examples of corresponding devices described. In some cases, such as reference Figure 2 As described, a UAV or UE 115 (such as UAV / UE 115-b) may attempt to communicate with a service provider (such as a UFSS, a USS, or both), wherein the UDM entity 225-a or the UFSS or USS generates a security configuration for communication between the UAV / UE 115-b and the UFSS or USS. Subsequently, the UDM entity 225-a may send an indication of the security configuration to the UAV / UE 115-b via the AMF 245-a.
[0115] At 305, the UDM entity 225-a may notify the affected AMF 245-a of the change in information related to the UAV / UE 115-b using a service-based interface for the UDM entity 225-a via a User Data Management (SDM) message, where the service-based interface for the UDM entity 225-a is indicated by Nudm (e.g., Nudm_SDM_Notification service operation). The Nudm notification (e.g., Nudm_SDM_Notification service operation) may include updated data for the UAV / UE 115-b, such as a generated security configuration. For example, the Nudm notification may indicate a UDM update data operation ("Routing Indicator Update Data", "Default Configuration NSSAI Update Data", "ME Security Configuration", etc.) that may be transparently delivered to the UAV / UE 115-b over the NAS within the access and mobility subscription data (e.g., via the AMF 245-a). The UDM update data may include updated parameters to be delivered to the UAV / UE 115-b (updated routing indicator data, default configured NSSAI, ME security configuration, etc.), whether the UAV / UE 115-b sends a confirmation message to the UDM entity 225-a, whether the UAV / UE 115-b re-registers after the update data, or a combination thereof.
[0116] At 310, the AMF 245-a may issue a downlink NAS transport message to the UAV / UE 115-b (e.g., the served UE). The AMF 245-a may include the transparent container received from the UDM entity 225-a in the downlink NAS transport message. In some cases, the UAV / UE 115-b may verify that the UDM update data is provided by the local public land mobile network (HPLMN). If the security check on the UDM update data is successful (e.g., the information is verified), the UAV / UE 115-b may store the information and use the parameters from then on, or may forward the information to a subscriber identity module (SIM) (e.g., a universal mobile telecommunications system SIM (USIM)). Alternatively, if the security check on the UDM update data fails, the UAV / UE 115-b may discard the contents of the UDM update data.
[0117] At 315, if the UAV / UE 115-b has verified that the UDM update data is provided by the HPLMN, and the UDM entity 225-a has requested the UAV / UE 115-b to send a confirmation message to the UDM entity 225-a (e.g., as described in reference Figure 2described), the UAV / UE 115-b may issue an uplink NAS transport message with a transparent container including an acknowledgment of the UAV / UE 115-b to the AMF 245-a (e.g., the serving AMF 245).
[0118] At 320, if the AMF 245-a receives an uplink NAS transport message with a transparent container carrying a UE acknowledgment from the UAV / UE 115-b, the AMF 245-a may issue a Nudm information message (e.g., a Nudm_SDM_Info request message) to the UDM entity 225-a including a transparent container carrying the UE acknowledgment from the UAV / UE 115-b.
[0119] At 325 , if the UDM entity 225 - a has requested the UAV / UE 115 - b to re-register, the UAV / UE 115 - b may wait until returning to the RRC idle state and may initiate a registration procedure.
[0120] Figure 4 An example of a process flow 400 in a system supporting techniques for providing security credentials to a UAV in accordance with aspects of the present disclosure is shown. In some examples, the process flow 400 may implement aspects of the wireless communication system 100, the wireless communication system 200, and the process flow 300. The process flow 400 may illustrate an example of a communication procedure between a UAV or UE 115 (such as a UAV / UE 115-c) and a service provider (such as a UFSS 215-b or a USS 220-b) using a security configuration signaled by an AMF 245-b from a UDM entity 225-b. The following alternative examples may be implemented in which some of the processes are performed in a different order than described or not performed at all. In some cases, the processes may include additional features not mentioned below, or additional processes may be added. In some cases, the UAV / UE 115-c may be a UE 115 associated with a UAV in a terrestrial cellular network (e.g., as described in reference to FIG. 2 ). Figure 1 description).
[0121] At 405, the UAV / UE 115-c may perform a registration procedure with one or more network functions, including the AMF 245-b, for communication with the unmanned aerial system service provider. For example, the UAV / UE 115-c may perform a registration procedure to establish a connection for communication with the UFSS 215-b, the USS 220-b, or both.
[0122] At 410, the UDM entity 225-b may generate a security configuration for the UAV / UE 115-c. The security configuration may include one or more security credentials for enabling communication between the UAV / UE 115-c and the UFSS 215-b, the USS 220-b, or both. In some cases, the security configuration may include: credentials for communication between the UAV / UE 115-c and the UFSS 215-b, the USS 220-b, or both, private and public security keys for enabling such communication, one or more security keys that the UAV / UE 115-c may use to broadcast a remote ID and verify a received remote ID, an ID of the UFSS 215-b, the USS 220-b, or both, or a combination thereof. For example, a security configuration (e.g., an ME security configuration) may include security credentials (credentials, associated keys, etc.) to be used by the ME of the UAV / UE 115-c (i.e., the UAV rather than the USIM of the UAV / UE 115-c).
[0123] At 415, the UDM entity 225-b may send a security configuration to the UAV / UE 115-c (e.g., via the AMF 245-b). In some cases, the UDM entity 225-b may send the security configuration with one or more security credentials in a NAS transport message. In some examples, the UAV / UE 115-c may receive the security configuration based on the GPSI of the UAV / UE 115-c. Additionally or alternatively, the UAV / UE 115-c may receive the security configuration based on sending a registration request to the UFSS 215-b, the USS 220-b, or both. In some cases, the UAV / UE 115-c may remove the security credentials used for previous communications. The UAV / UE 115-c may receive the security configuration at a hardware component of the UAV / UE 115-c, such as an ME. In some cases, the UDM entity 225-b may send a UDM configuration update message including parameters for the UAV / UE 115-c to the AMF 245-b. The UDM configuration update message may indicate a security configuration.
[0124] In some cases, at 420, the UAV / UE 115-c may issue a confirmation message to the UDM entity 225-b (e.g., via the AMF 245-b) to confirm that the UAV / UE 115-c received the security configuration.
[0125] In some cases, at 425, the UDM entity 225-b may send a message including security credentials for the UAV / UE 115-c to the UFSS 215-b, the USS 220-b, or both based on receipt of the confirmation message at 420. The message may include an indication of a security configuration for enabling communications between the UAV / UE 115-c and the UFSS 215-b, the USS 220-b, or both.
[0126] In some examples, at 430, the UAV / UE 115-c may send a registration request to the UFSS 215-b, the USS 220-b, or both. The registration request may include registration information corresponding to the UAV / UE 115-c. For example, the registration request may include the GPSI of the UAV / UE 115-c. In some cases, the UAV / UE 115-c may send the registration request based on an identity of the UFSS 215-b, the USS 220-b, or both, which the UAV / UE 115-c may receive in the security configuration at 415. The registration request may be protected by one or more security credentials in the security configuration from the UDM entity 225-b. In some cases, the UFSS 215-b, the USS 220-b, or both may determine the one or more security credentials based on the registration request.
[0127] At 435, the UFSS 215-b, the USS 220-b, or both may issue a registration response to the UAV / UE 115-c based on receiving the registration request. In some cases, the registration response may include an identifier for the UAV / UE 115-c.
[0128] At 440, the UAV / UE 115-c may communicate with the UFSS 215-b, the USS 220-b, or both based on the one or more security credentials in the security configuration. In some cases, the communication may be based on the UAV / UE 115-c sending a confirmation message at 420. Additionally or alternatively, the communication may be based on the identifier received in the registration response at 435 in combination with the security configuration.
[0129] Figure 5An example of a process flow 500 in a system supporting techniques for providing security credentials to a UAV in accordance with aspects of the present disclosure is shown. In some examples, the process flow 500 may implement aspects of the wireless communication system 100 or the wireless communication system 200. The process flow 500 may include aspects of the process flow 300 and the process flow 400. For example, the process flow 500 may illustrate an example of a communication procedure between a UAV or UE 115 (such as a UAV / UE 115-d) and a service provider (such as a UFSS 215-c or a USS 220-c) using a security configuration signaled by an AMF 245-c from a UDM entity 225-c. The following alternative examples may be implemented in which some of the processes are performed in a different order than described or not performed at all. In some cases, the processes may include additional features not mentioned below, or additional processes may be added. In some cases, the UAV / UE 115-d may be a UE 115 associated with the UAV in a terrestrial cellular network (e.g., as described in reference to FIG. Figure 1 description).
[0130] At 505, the UAV / UE 115-d may perform a registration procedure with one or more network functions, including the AMF 245-c, for communication with a service provider, such as the UFSS 215 or the USS 220. For example, the UAV / UE 115-d may perform a registration procedure to establish a connection for communication with the UFSS 215-c, the USS 220-c, or both.
[0131] In some examples, at 510, the UAV / UE 115-d may send a registration request to the UFSS 215-c, the USS 220-c, or both. The registration request may include registration information corresponding to the UAV / UE 115-d. For example, the registration request may include the GPSI of the UAV / UE 115-c. In some cases, the UFSS 215-c, the USS 220-c, or both may determine one or more security credentials based on the registration request.
[0132] At 515, the UFSS 215-c, the USS 220-c, or both may generate a security configuration for the UAV / UE 115-d. The security configuration may include one or more security credentials for enabling communication between the UAV / UE 115-d and the UFSS 215-c, the USS 220-c, or both. In some cases, the security configuration may include: credentials for communication between the UAV / UE 115-d and the UFSS 215-c, the USS 220-c, or both, private and public security keys for enabling communication, one or more security keys that the UAV / UE 115-d may use to broadcast a remote ID and verify a received remote ID, an ID of the UFSS 215-c, the USS 220-c, or both, or a combination thereof. In some cases, the UFSS 215-c, the USS 220-c, or both may generate a security configuration based on the UAV / UE 115-d registering with a network including the UDM entity 225-c and the AMF 245-b or the UAV / UE 115-d. In some other cases, the UFSS 215-c, the USS 220-c, or both may generate a security configuration based on: no previous delivery of a security configuration to the UAV / UE 115-d; a security refresh for the UAV / UE 115-d; a trigger received from the UFSS 215-c, the USS 220-c, or both; or a combination thereof.
[0133] At 520, the UFSS 215-c, the USS 220-c, or both may send a security configuration to the UDM entity 225-c. For example, the UFSS 215-c, the USS 220-c, or both may send an indication of the security configuration to the UDM entity 225-c via a UDM service message, a network open function update message, or both. At 525, the UDM entity 225-c may send the security configuration to the UAV / UE 115-d (e.g., via the AMF 245-c) based on receiving the security configuration at 520. In some cases, the UDM entity 225-b may send the security configuration with one or more security credentials in a national airspace system message. In some examples, the UAV / UE 115-d may receive the security configuration based on the GPSI of the UAV / UE 115-d. Additionally or alternatively, the UAV / UE 115-d may receive a security configuration based on sending a registration request to the UFSS 215-c, the USS 220-c, or both. In some cases, the UAV / UE 115-d may remove security credentials used for previous communications. The UAV / UE 115-d may receive the security configuration at a hardware component of the UAV / UE 115-d, such as the ME. In some cases, the UDM entity 225-c may send a UDM configuration update message including parameters for the UAV / UE 115-d to the AMF 245-b. The UDM configuration update message may indicate the security configuration.
[0134] In some cases, at 530, the UAV / UE 115-d may issue a confirmation message to the UDM entity 225-c (e.g., via the AMF 245-c) to confirm that the UAV / UE 115-d received the security configuration. At 535, the UDM entity 225-c may issue a confirmation message to the UFSS 215-c, the USS 220-c, or both to confirm that the UAV / UE 115-d received the security configuration. For example, the UDM entity 225-c may send a parameter provisioning information message including the confirmation message.
[0135] At 540, the UFSS 215-c, the USS 220-c, or both may issue a registration response to the UAV / UE 115-d based on receiving the confirmation message. In some cases, the registration response may include an identifier for the UAV / UE 115-d.
[0136] At 545, the UAV / UE 115-d may communicate with the UFSS 215-c, the USS 220-c, or both based on the one or more security credentials in the security configuration. In some cases, the communication may be based on the UAV / UE 115-d sending a confirmation message at 530. Additionally or alternatively, the communication may be based on the identifier received in the registration response at 540 in combination with the security configuration.
[0137] Figure 6 A block diagram 600 of a device 605 that supports provisioning security credentials to a UAV according to aspects of the present disclosure is shown. The device 605 can be an example of aspects of the UE 115 as described herein. The device 605 can include a receiver 610, a UE communication manager 615, and a transmitter 620. The device 605 can also include a processor. Each of these components can communicate with each other (e.g., via one or more buses).
[0138] The receiver 610 may receive information such as packets, user data, or control information associated with various information channels (e.g., control channels, data channels, and information related to providing security credentials to the UAV). The information may be passed to other components of the device 605. The receiver 610 may be a reference Figure 9 Examples of various aspects of the transceiver 920 are described. The receiver 610 may utilize a single antenna or a group of antennas.
[0139] The UE communication manager 615 can perform registration procedures with one or more network functions, including an AMF, for communication with a UAS service provider. In some cases, the UE communication manager 615 can receive an indication of a security configuration from a UDM entity in a non-access stratum transport message via the AMF. The security configuration includes one or more security credentials for enabling communication between the UE and the UAS service provider. The UE communication manager 615 can then communicate with the UAS service provider based on the one or more security credentials in the security configuration. The UE communication manager 615 can be an example of aspects of the UE communication manager 910 described herein.
[0140] The actions performed by the UE communication manager 615 as described herein can be implemented to achieve one or more potential advantages. One embodiment can enable a UDM entity or a UFSS, USS, or both to send a security configuration to a UE associated with a UAV. Such a configuration can implement techniques for secure communication between the UE and the UFSS, USS, or both based on security credentials, which can result in reduced DoS attacks or imposter attacks, among other advantages.
[0141] The UE communication manager 615 or its subcomponents may be implemented in hardware, in code (e.g., software or firmware) executed by a processor, or in any combination thereof. If implemented in code executed by a processor, the functions of the UE communication manager 615 or its subcomponents may be controlled by a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device designed to perform the functions described in this disclosure, discrete gate or transistor logic, discrete hardware components, or any combination thereof.
[0142] The UE communications manager 615 or its subcomponents can be physically located in various locations, including being distributed so that portions of the functionality are implemented by one or more physical components at different physical locations. In some examples, according to various aspects of the present disclosure, the UE communications manager 615 or its subcomponents can be separate and distinct components. In some examples, according to various aspects of the present disclosure, the UE communications manager 615 or its subcomponents can be combined with one or more other hardware components, including but not limited to input / output (I / O) components, transceivers, network servers, another computing device, one or more other components described in accordance with the present disclosure, or a combination thereof.
[0143] The transmitter 620 can transmit signals generated by other components of the device 605. In some examples, the transmitter 620 can be collocated with the receiver 610 in the transceiver module. For example, the transmitter 620 can be a reference Figure 9 Examples of various aspects of the transceiver 920 are described. The transmitter 620 may utilize a single antenna or a group of antennas.
[0144] Figure 7 A block diagram 700 of a device 705 that supports provisioning security credentials to a UAV according to aspects of the present disclosure is shown. The device 705 can be an example of aspects of the device 605 or UE 115 as described herein. The device 705 can include a receiver 710, a UE communication manager 715, and a transmitter 735. The device 705 can also include a processor. Each of these components can communicate with each other (e.g., via one or more buses).
[0145] The receiver 710 may receive information such as packets, user data, or control information associated with various information channels (e.g., control channels, data channels, and information related to providing security credentials to the UAV). The information may be passed to other components of the device 705. The receiver 710 may be a reference Figure 9 Examples of aspects of the transceiver 920 are described. The receiver 710 may utilize a single antenna or a group of antennas.
[0146] UE communications manager 715 may be an example of aspects of UE communications manager 615 as described herein. UE communications manager 715 may include registration component 720, security configuration component 725, and secure communications component 730. UE communications manager 715 may be an example of aspects of UE communications manager 910 as described herein.
[0147] The registration component 720 can perform a registration procedure with one or more network functions for communicating with the UAS service provider, the one or more network functions including the AMF.
[0148] The security configuration component 725 may receive an indication of a security configuration from a UDM entity in a non-access stratum transport message via the AMF, the security configuration including one or more security credentials for enabling communication between the UE and the UAV system service provider.
[0149] The secure communication component 730 can communicate with the drone system service provider based on the one or more security credentials of the security configuration.
[0150] Based on the configuration described herein, the processor of the UE (eg, controls the receiver 710, the UE communication manager 715, the transmitter 735, the reference Figure 9 The transceiver 920 described herein, or a processor thereof, can reduce the impact or likelihood of property loss or damage associated with a UAV while ensuring relatively efficient communications. For example, the configuration techniques described herein can utilize a UDM entity and a UFSS, USS, or both to produce a secure configuration, which can achieve efficient operation, among other benefits.
[0151] The transmitter 735 can transmit signals generated by other components of the device 705. In some examples, the transmitter 735 can be collocated with the receiver 710 in the transceiver module. For example, the transmitter 735 can be a reference Figure 9 Examples of various aspects of the transceiver 920 are described. The transmitter 735 can utilize a single antenna or a group of antennas.
[0152] Figure 8 A block diagram 800 is shown of a UE communication manager 805 that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure. The UE communication manager 805 can be an example of aspects of the UE communication manager 615, the UE communication manager 715, or the UE communication manager 910 described herein. The UE communication manager 805 can include a registration component 810, a security configuration component 815, a secure communication component 820, a confirmation message component 825, and a registration request component 830. Each of these modules can communicate with each other directly or indirectly (e.g., via one or more buses).
[0153] The registration component 810 can perform a registration procedure with one or more network functions for communicating with an unmanned aerial vehicle system service provider, the one or more network functions including the AMF.
[0154] The security configuration component 815 may receive an indication of a security configuration from a UDM entity via the AMF in a non-access stratum transport message, the security configuration including one or more security credentials for enabling communications between the UE and the drone system service provider. In some cases, the indication of the security configuration may be received at a hardware component of the UE. In addition, the security configuration may include: a UE identity for identifying the UE in communications between the UE and the drone system service provider, credentials for communications between the UE and the drone system service provider, private and public security keys for enabling communications between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof. In some examples, the security configuration component 815 may determine to remove security credentials previously used by the UE for previous communications.
[0155] The secure communication component 820 can communicate with the drone system service provider based on the one or more security credentials of the security configuration.
[0156] The confirmation message component 825 can send a confirmation message to the UDM entity indicating that the UE successfully received the indication of the security configuration, wherein the communication with the unmanned aerial vehicle system service provider is based on the confirmation message.
[0157] Registration request component 830 can send a registration request for communications between the UE and the UAS service provider to the UAS service provider, the registration request including registration information corresponding to the UE. In some examples, registration request component 830 can determine to send the registration request to the UAS service provider based on the identity of the UAS service provider received in the indication of the security configuration. Additionally, registration request component 830 can receive a registration response message from the UAS service provider in response to the registration request, the registration response message including an identifier for the UE, wherein communication with the UAS service provider is based on the identifier for the UE in combination with the security configuration. In some cases, the registration request can be secured based on one or more security credentials received from the UDM entity. Additionally, an indication of the security configuration can be received based on sending the registration request. In some cases, the registration request can include the UE's GPSI, wherein the indication of the security configuration is received based on the UE's GPSI.
[0158] Figure 9 A diagram of a system 900 including a device 905 that supports provisioning security credentials to a UAV according to aspects of the present disclosure is shown. The device 905 can be an example of or include components of the device 605, device 705, or UE 115 described herein. The device 905 can include components for two-way voice and data communications, including components for sending and receiving communications, including a UE communication manager 910, an I / O controller 915, a transceiver 920, an antenna 925, a memory 930, and a processor 940. These components can communicate electronically via one or more buses (e.g., bus 945).
[0159] The UE communication manager 910 may perform a registration procedure with one or more network functions, including an AMF, for communication with a UAS service provider. In some cases, the UE communication manager 910 may receive an indication of a security configuration from a UDM entity in a non-access stratum transport message via the AMF. The security configuration includes one or more security credentials for enabling communication between the UE and the UAS service provider. The UE communication manager 910 may then communicate with the UAS service provider based on the one or more security credentials in the security configuration.
[0160] I / O controller 915 can manage input and output signals for device 905. I / O controller 915 can also manage peripheral devices that are not integrated into device 905. In some cases, I / O controller 915 can represent a physical connection or port to an external peripheral device. In some cases, I / O controller 915 can utilize a controller such as MS- MS- OS / , or another known operating system. In other cases, I / O controller 915 may represent or interact with a modem, keyboard, mouse, touch screen, or similar device. In some cases, I / O controller 915 may be implemented as part of a processor. In some cases, a user may interact with device 905 via I / O controller 915 or via hardware components controlled by I / O controller 915.
[0161] As described above, transceiver 920 can communicate bidirectionally via one or more antennas, wired or wireless links. For example, transceiver 920 can represent a wireless transceiver and can communicate bidirectionally with another wireless transceiver. Transceiver 920 can also include a modem to modulate packets and provide the modulated packets to an antenna for transmission, as well as demodulate packets received from the antenna.
[0162] In some cases, a wireless device may include a single antenna 925. However, in some cases, the device may have more than one antenna 925, which may be capable of transmitting or receiving multiple wireless transmissions simultaneously.
[0163] The memory 930 may include random access memory (RAM) and read-only memory (ROM). The memory 930 may store computer-readable, computer-executable code 935 including instructions that, when executed, cause the processor to perform the various functions described herein. In some cases, the memory 930 may include, among other things, an I / O system (BIOS), which may control basic hardware or software operations, such as interacting with peripheral components or devices.
[0164] The processor 940 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a central processing unit (CPU), a microcontroller, an ASIC, an FPGA, a programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some cases, the processor 940 may be configured to operate a memory array using a memory controller. In other cases, the memory controller may be integrated into the processor 940. The processor 940 may be configured to execute computer-readable instructions stored in a memory (e.g., memory 930) to cause the device 905 to perform various functions (e.g., functions or tasks that support providing security credentials to the UAV).
[0165] The code 935 may include instructions for implementing various aspects of the present disclosure, including instructions for supporting wireless communications. The code 935 may be stored in a non-transitory computer-readable medium (such as system memory or other types of memory). In some cases, the code 935 may not be directly executable by the processor 940, but may cause a computer (e.g., when compiled and executed) to perform the functions described herein.
[0166] Figure 10 A block diagram 1000 of a device 1005 that supports provisioning security credentials to a UAV according to aspects of the present disclosure is shown. The device 1005 can be an example of aspects of a network entity as described herein. The device 1005 can include a receiver 1010, a communication manager 1015, and a transmitter 1020. The device 1005 can also include a processor. Each of these components can communicate with each other (e.g., via one or more buses).
[0167] The receiver 1010 may receive information such as packets, user data, or control information associated with various information channels (e.g., control channels, data channels, and information related to providing security credentials to the UAV). The information may be passed to other components of the device 1005. The receiver 1010 may be a reference Figure 13 Examples of various aspects of the transceiver 1320 are described. The receiver 1010 can utilize a single antenna or a group of antennas.
[0168] The communication manager 1015 may send an indication of a security configuration to the AMF, the security configuration including one or more security credentials for enabling communications between the UE associated with the UAV and the unmanned aerial system service provider. In addition, the communication manager 1015 may receive an acknowledgment message from the AMF indicating that the UE successfully received the indication of the security configuration. In some cases, the communication manager 1015 may, based on receiving the acknowledgment message, send a message to the unmanned aerial system service provider indicating one or more security credentials to be used by the UE for communications with the unmanned aerial system service provider.
[0169] Additionally or alternatively, the communications manager 1015 may receive a registration request from a UE associated with the UAV, including registration information corresponding to the UE. In some cases, the communications manager 1015 may determine, based on the registration request, one or more security credentials for enabling communications between the UE and the UAV system service provider. Furthermore, the communications manager 1015 may communicate with the UE based on the one or more security credentials. The communications manager 1015 may be an example of aspects of the communications manager 1310 described herein.
[0170] The communication manager 1015 or its subcomponents may be implemented in hardware, in code (e.g., software or firmware) executed by a processor, or in any combination thereof. If implemented in code executed by a processor, the functions of the communication manager 1015 or its subcomponents may be controlled by a general purpose processor, a DSP, an ASIC, an FPGA or other programmable logic device designed to perform the functions described in this disclosure, discrete gate or transistor logic, discrete hardware components, or any combination thereof.
[0171] The communication manager 1015 or its subcomponents can be physically located in various locations, including being distributed such that portions of the functionality are performed by one or more physical components at different physical locations. In some examples, according to various aspects of the present disclosure, the communication manager 1015 or its subcomponents can be separate and distinct components. In some examples, according to various aspects of the present disclosure, the communication manager 1015 or its subcomponents can be combined with one or more other hardware components, including but not limited to I / O components, transceivers, network servers, another computing device, one or more other components described in accordance with the present disclosure, or a combination thereof.
[0172] The transmitter 1020 can transmit signals generated by other components of the device 1005. In some examples, the transmitter 1020 can be collocated with the receiver 1010 in a transceiver module. For example, the transmitter 1020 can be a reference Figure 13 Examples of various aspects of the transceiver 1320 are described. The transmitter 1020 can utilize a single antenna or a group of antennas.
[0173] Figure 11 A block diagram 1100 of a device 1105 that supports provisioning security credentials to a UAV according to aspects of the present disclosure is shown. The device 1105 can be an example of aspects of the device 1005 or a network entity (such as a UE 115) as described herein. The device 1105 can include a receiver 1110, a communication manager 1115, and a transmitter 1150. The device 1105 can also include a processor. Each of these components can communicate with each other (e.g., via one or more buses).
[0174] The receiver 1110 may receive information such as packets, user data, or control information associated with various information channels (e.g., control channels, data channels, and information related to providing security credentials to the UAV). The information may be passed to other components of the device 1105. The receiver 1110 may be a reference Figure 13 Examples of various aspects of the transceiver 1320 are described. The receiver 1110 may utilize a single antenna or a group of antennas.
[0175] The communications manager 1115 can be an example of aspects of the communications manager 1015 as described herein. The communications manager 1115 can include a security configuration indicator 1120, a security confirmation component 1125, a security credential indicator 1130, a registration request receiving component 1135, a security determination component 1140, and a communications component 1145. The communications manager 1115 can be an example of aspects of the communications manager 1310 as described herein.
[0176] The security configuration indicator 1120 may send an indication of a security configuration to the AMF, the security configuration including one or more security credentials for enabling communications between the UE associated with the UAV and the unmanned aerial system service provider.
[0177] The security confirmation component 1125 may receive a confirmation message from the AMF indicating that the UE successfully received the indication of the security configuration.
[0178] The security credential indicator 1130 may send a message to the unmanned aerial vehicle system service provider based on receiving the confirmation message, the message indicating one or more security credentials to be used by the UE for communications with the unmanned aerial vehicle system service provider.
[0179] The registration request receiving component 1135 can receive a registration request from a UE associated with the UAV including registration information corresponding to the UE.
[0180] The security determination component 1140 can determine one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider based on the registration request.
[0181] Communication component 1145 can communicate with the UE based on the one or more security credentials.
[0182] The transmitter 1150 can transmit signals generated by other components of the device 1105. In some examples, the transmitter 1150 can be collocated with the receiver 1110 in the transceiver module. For example, the transmitter 1150 can be a reference Figure 13 Examples of various aspects of the transceiver 1320 are described. The transmitter 1150 may utilize a single antenna or a group of antennas.
[0183] Figure 12 A block diagram 1200 is shown of a communication manager 1205 that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure. The communication manager 1205 can be an example of aspects of the communication manager 1015, the communication manager 1115, or the communication manager 1310 described herein. The communication manager 1205 can include a security configuration indicator 1210, a security confirmation component 1215, a security credential indicator 1220, a security configuration generator 1225, a security configuration indication component 1230, a registration request receiving component 1235, a security determination component 1240, a communication component 1245, a security configuration receiving component 1250, and a security configuration determining component 1255. Each of these modules can communicate with each other directly or indirectly (e.g., via one or more buses).
[0184] The security configuration indicator 1210 may send an indication of a security configuration to the AMF, the security configuration including one or more security credentials for enabling communications between a UE associated with the UAV and a drone system service provider. In some examples, the security configuration indicator 1210 may send a UDM configuration update message of parameters for the UE to the AMF, wherein the UDM configuration update message includes an indication of the security configuration. In some cases, the security configuration may include: a UE identity for identifying the UE in communications between the UE and the drone system service provider, credentials for communications between the UE and the drone system service provider, private and public security keys for enabling communications between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of a wireless device (such as a UE) and to verify a received remote identifier broadcast by an additional UE, an identifier of the drone system service provider, or a combination thereof.
[0185] The security confirmation component 1215 may receive a confirmation message from the AMF indicating that the UE successfully received the indication of the security configuration.
[0186] The security credential indicator 1220 may send a message to the unmanned aerial vehicle system service provider based on receiving the confirmation message, the message indicating one or more security credentials to be used by the UE for communications with the unmanned aerial vehicle system service provider.
[0187] The registration request receiving component 1235 can receive a registration request from a UE associated with the UAV including registration information corresponding to the UE.
[0188] The security determination component 1240 can determine one or more security credentials for enabling communication between the UE and the UAV system service provider based on the registration request. In some cases, the one or more security credentials can include: a UE identity for identifying the UE in communications between the UE and the UAV system service provider, credentials for communication between the UE and the UAV system service provider, private and public security keys for enabling communication between the UE and the UAV system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the UAV system service provider, or a combination thereof.
[0189] Communication component 1245 can communicate with the UE based on the one or more security credentials.
[0190] The security configuration generator 1225 may generate a security configuration for communication between the UE and the UAV system service provider. In some examples, the security configuration generator 1225 may send an indication of the security configuration to the UAV system service provider to enable communication between the UE and the UAV system service provider. In some cases, the security configuration may be generated based on: the UE registering with the network including the UDM entity and the AMF, no security configuration was previously delivered to the UE, a security refresh for the UE, a trigger received from the UAV system service provider, or a combination thereof.
[0191] The security configuration indication component 1230 can receive an indication of the security configuration from the UAV system service provider, wherein sending the indication of the security configuration to the AMF is based on receiving the indication of the security configuration from the UAV system service provider. In some examples, the security configuration indication component 1230 can send a parameter provision information message to the UAV system service provider, the parameter provision information message including a confirmation message indicating that the UE successfully received the indication of the security configuration. In addition, the security configuration indication component 1230 can receive the indication of the security configuration from the UAV system service provider via a UDM service message, a network open function update message, or a combination thereof.
[0192] A security configuration receiving component 1250 can receive an indication of a security configuration from a UDM entity, the security configuration including one or more security credentials for enabling communications between the UE and the UAS service provider. In some cases, the UDM entity can generate the security configuration based on: the UE registering with a network including the UDM entity, no security configuration previously delivered to the UE, a security refresh for the UE, a trigger received from the UAS service provider, or a combination thereof.
[0193] The security configuration determining component 1255 can generate a security configuration for communications between the UE and the UAS service provider based on the registration information corresponding to the UE received in the registration request, the security configuration including the one or more security credentials. In some examples, the security configuration determining component 1255 can send an indication of the security configuration to a UDM entity. Additionally, the security configuration determining component 1255 can receive a parameter provisioning information message from the UDM entity, the parameter provisioning information message including an acknowledgment message indicating that the UE successfully received the indication of the security configuration, wherein communication with the UE is based on the acknowledgment message. In some examples, the security configuration indicating component 1255 can send the indication of the security configuration to the UDM entity via a UDM service message, a network exposure function update message, or a combination thereof. In some cases, the registration request can include the UE's GPSI, wherein the one or more security credentials are generated based on the GPSI.
[0194] Figure 13 A diagram of a system 1300 including a device 1305 that supports provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown. The device 1305 can be an example of or include components of the device 1005, device 1105, or network entity described herein. The device 1305 can include components for two-way voice and data communications, including components for sending and receiving communications, including a communication manager 1310, an I / O controller 1315, a transceiver 1320, an antenna 1325, a memory 1330, and a processor 1335. These components can communicate electronically via one or more buses (e.g., bus 1345).
[0195] The communication manager 1310 may send an indication of a security configuration to the AMF, the security configuration including one or more security credentials for enabling communications between the UE associated with the UAV and the unmanned aerial system service provider. Additionally, the communication manager 1310 may receive an acknowledgment message from the AMF indicating that the UE successfully received the indication of the security configuration. In some cases, the communication manager 1310 may, based on receiving the acknowledgment message, send a message to the unmanned aerial system service provider indicating one or more security credentials to be used by the UE for communications with the unmanned aerial system service provider.
[0196] Additionally or alternatively, the communication manager 1310 may receive a registration request from a UE associated with the UAV, including registration information corresponding to the UE. In some cases, the communication manager 1310 may determine, based on the registration request, one or more security credentials for enabling communication between the UE and the UAV system service provider. Furthermore, the communication manager 1310 may communicate with the UE based on the one or more security credentials.
[0197] I / O controller 1315 can manage input and output signals for device 1305. I / O controller 1315 can also manage peripheral devices that are not integrated into device 1305. In some cases, I / O controller 1315 can represent a physical connection or port to an external peripheral device. In some cases, I / O controller 1315 can utilize a computer such as MS- MS- OS / , or another known operating system. In other cases, I / O controller 1315 may represent or interact with a modem, keyboard, mouse, touch screen, or similar device. In some cases, I / O controller 1315 may be implemented as part of a processor. In some cases, a user may interact with device 1305 via I / O controller 1315 or via hardware components controlled by I / O controller 1315.
[0198] As described above, transceiver 1320 can communicate bidirectionally via one or more antennas, wired or wireless links. For example, transceiver 1320 can represent a wireless transceiver and can communicate bidirectionally with another wireless transceiver. Transceiver 1320 can also include a modem to modulate packets and provide the modulated packets to an antenna for transmission, as well as demodulate packets received from the antenna.
[0199] In some cases, a wireless device may include a single antenna 1325. However, in some cases, the device may have more than one antenna 1325, which may be capable of transmitting or receiving multiple wireless transmissions simultaneously.
[0200] Memory 1330 may include RAM and ROM. Memory 1330 may store computer-readable, computer-executable code 1340 including instructions that, when executed, cause the processor to perform the various functions described herein. In some cases, memory 1330 may include, among other things, BIOS, which may control basic hardware or software operations, such as interacting with peripheral components or devices.
[0201] The processor 1335 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, a microcontroller, an ASIC, an FPGA, a programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some cases, the processor 1335 may be configured to operate a memory array using a memory controller. In other cases, the memory controller may be integrated into the processor 1335. The processor 1335 may be configured to execute computer-readable instructions stored in a memory (e.g., memory 1330) to cause the device 1305 to perform various functions (e.g., functions or tasks that support providing security credentials to the UAV).
[0202] The code 1340 may include instructions for implementing various aspects of the present disclosure, including instructions for supporting wireless communications. The code 1340 may be stored in a non-transitory computer-readable medium (such as system memory or other types of memory). In some cases, the code 1340 may not be directly executable by the processor 1335, but may cause a computer (e.g., when compiled and executed) to perform the functions described herein.
[0203] Figure 14 A flow chart illustrating a method 1400 for supporting provisioning security credentials to a UAV according to aspects of the present disclosure is shown. The operations of the method 1400 may be implemented by a UE 115 or a component thereof as described herein. For example, the operations of the method 1400 may be implemented by a UE 115 or a component thereof as described herein. Figures 6 to 9 In some examples, the UE may execute an instruction set to control the functional elements of the UE to perform the functions described below. Additionally or alternatively, the UE may use dedicated hardware to perform various aspects of the functions described below.
[0204] At 1405, the UE may perform a registration procedure with one or more network functions for communication with the UAV system service provider, the one or more network functions including the AMF. Operation 1405 may be performed according to the methods described herein. In some examples, the UE may be configured as described in reference to Figures 6 to 9 The registration component is described to perform various aspects of operation 1405.
[0205] At 1410, the UE may receive an indication of a security configuration from a UDM entity in a non-access layer transport message via the AMF, the security configuration including one or more security credentials for enabling communication between the UE and the UAV system service provider. Operation 1410 may be performed according to the methods described herein. In some examples, the method may be configured as described in reference to Figures 6 to 9 The security configuration components are described to perform various aspects of operation 1410.
[0206] At 1415, the UE may communicate with the drone system service provider based at least in part on one or more security credentials of the security configuration. Operation 1415 may be performed according to the methods described herein. In some examples, the UE may communicate with the drone system service provider based at least in part on one or more security credentials of the security configuration. Figures 6 to 9 The secure communications components are described to perform aspects of operation 1415 .
[0207] Figure 15 A flow chart illustrating a method 1500 for supporting provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown. The operations of the method 1500 may be implemented by a UE 115 or a component thereof as described herein. For example, the operations of the method 1500 may be implemented by a UE 115 or a component thereof as described herein. Figures 6 to 9 In some examples, the UE may execute an instruction set to control the functional elements of the UE to perform the functions described below. Additionally or alternatively, the UE may use dedicated hardware to perform various aspects of the functions described below.
[0208] At 1505, the UE may perform a registration procedure with one or more network functions for communication with the UAV system service provider, the one or more network functions including the AMF. Operation 1505 may be performed according to the methods described herein. In some examples, the UE may be configured as described in reference to Figures 6 to 9 The registration component is described to perform various aspects of operation 1505.
[0209] At 1510, the UE may receive an indication of a security configuration from a UDM entity in a non-access layer transport message via the AMF, the security configuration including one or more security credentials for enabling communication between the UE and the UAV system service provider. Operation 1510 may be performed according to the methods described herein. In some examples, the method may be configured as described in reference to Figures 6 to 9 The security configuration components are described to perform various aspects of operation 1510.
[0210] At 1515, the UE may send a confirmation message to the UDM entity indicating that the UE successfully received the indication of the security configuration, wherein communicating with the UAV system service provider is based at least in part on the confirmation message. Operation 1515 may be performed according to the methods described herein. In some examples, the UE may be configured as described in reference to Figures 6 to 9 The confirmation message component is described to perform various aspects of operation 1515.
[0211] At 1520, the UE may communicate with the drone system service provider based at least in part on one or more security credentials of the security configuration. Operation 1520 may be performed according to the methods described herein. In some examples, the UE may communicate with the drone system service provider based at least in part on one or more security credentials of the security configuration. Figures 6 to 9 The secure communication components are described to perform various aspects of operation 1520.
[0212] Figure 16 A flow chart illustrating a method 1600 for supporting provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown. The operations of the method 1600 may be implemented by a network entity or a component thereof (e.g., a UDM entity) as described herein. For example, the operations of the method 1600 may be implemented by a network entity or a component thereof (e.g., a UDM entity) as described herein. Figures 10 to 13 In some examples, the network entity may execute an instruction set to control the functional elements of the network entity to perform the functions described below. Additionally or alternatively, the network entity may use dedicated hardware to perform various aspects of the functions described below.
[0213] At 1605, the network entity may send an indication of a security configuration to the AMF, the security configuration including one or more security credentials for enabling communication between the UE associated with the UAV and the UAV system service provider. Operation 1605 may be performed according to the methods described herein. In some examples, the AMF may be configured as described in reference to Figures 10 to 13 The security configuration indicator is described to perform various aspects of operation 1605.
[0214] At 1610, the network entity may receive a confirmation message from the AMF indicating that the UE successfully received the indication of the security configuration. Operation 1610 may be performed according to the methods described herein. In some examples, the UE may receive a confirmation message from the AMF indicating that the UE successfully received the indication of the security configuration. Figures 10 to 13 The security validation component is described to perform various aspects of operation 1610.
[0215] At 1615, the network entity may send a message to the UAV system service provider based at least in part on receiving the confirmation message, the message indicating one or more security credentials to be used by the UE for communication with the UAV system service provider. Operation 1615 may be performed according to the methods described herein. In some examples, the UE may be configured to communicate with the UAV system service provider as described in reference to FIG. Figures 10 to 13 The security credential indicator described is used to perform various aspects of operation 1615.
[0216] Figure 17 A flow chart illustrating a method 1700 for supporting provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown. The operations of the method 1700 may be implemented by a network entity or a component thereof (e.g., a UDM entity) as described herein. For example, the operations of the method 1700 may be implemented by a network entity or a component thereof (e.g., a UDM entity) as described herein. Figures 10 to 13 In some examples, the network entity may execute an instruction set to control the functional elements of the network entity to perform the functions described below. Additionally or alternatively, the network entity may use dedicated hardware to perform various aspects of the functions described below.
[0217] At 1705, the network entity may generate a security configuration for communication between the UE and the drone system service provider. Operation 1705 may be performed according to the methods described herein. In some examples, the security configuration may be generated by the user as described in reference to Figures 10 to 13 The security configuration generator is described to perform various aspects of operation 1705.
[0218] At 1710, the network entity may send an indication of a security configuration to the AMF, the security configuration including one or more security credentials for enabling communication between the UE associated with the UAV and the UAV system service provider. Operation 1710 may be performed according to the methods described herein. In some examples, the AMF may be configured as described in reference to Figures 10 to 13 The security configuration indicator is described to perform various aspects of operation 1710.
[0219] At 1715, the network entity may receive a confirmation message from the AMF indicating that the UE successfully received the indication of the security configuration. Operation 1715 may be performed according to the methods described herein. In some examples, the UE may receive a confirmation message from the AMF indicating that the UE successfully received the indication of the security configuration. Figures 10 to 13 The security validation component is described to perform various aspects of operation 1715.
[0220] At 1720, the network entity may send an indication of the security configuration to the UAV system service provider to enable communication between the UE and the UAV system service provider. Operation 1720 may be performed according to the methods described herein. In some examples, the method may be configured as described in reference to Figures 10 to 13 The security configuration generator is described to perform various aspects of operation 1720.
[0221] At 1725, the network entity may send a message to the UAV system service provider based at least in part on receiving the confirmation message, the message indicating one or more security credentials to be used by the UE for communication with the UAV system service provider. Operation 1725 may be performed according to the methods described herein. In some examples, the UE may be configured to communicate with the UAV system service provider as described in reference to FIG. Figures 10 to 13 The security credential indicator described is used to perform various aspects of operation 1725.
[0222] Figure 18 A flow chart illustrating a method 1800 for supporting provisioning security credentials to a UAV in accordance with aspects of the present disclosure is shown. The operations of the method 1800 may be implemented by a network entity or a component thereof as described herein. For example, the operations of the method 1800 may be implemented by a network entity or a component thereof as described herein. Figures 10 to 13 In some examples, the network entity may execute an instruction set to control the functional elements of the network entity to perform the functions described below. Additionally or alternatively, the network entity may use dedicated hardware to perform various aspects of the functions described below.
[0223] At 1805, the network entity may receive a registration request including registration information corresponding to a UE associated with a UAV. Operation 1805 may be performed according to the methods described herein. In some examples, the network entity may receive a registration request including registration information corresponding to the UE from a UE associated with the UAV. Figures 10 to 13 The registration request receiving component is described to perform various aspects of operation 1805.
[0224] At 1810, the network entity may determine one or more security credentials for enabling communication between the UE and the drone system service provider based at least in part on the registration request. Operation 1810 may be performed according to the methods described herein. In some examples, the method may be performed by a user as described in reference to Figures 10 to 13 The security determination components described are used to perform various aspects of operation 1810.
[0225] At 1815, the network entity may communicate with the UE based at least in part on the one or more security credentials. Operation 1815 may be performed according to the methods described herein. In some examples, the UE may be configured as described in reference to Figures 10 to 13 The communication components are described to perform various aspects of operation 1815.
[0226] Figure 19 A flow chart illustrating a method 1900 for supporting provisioning of security credentials to a UAV in accordance with aspects of the present disclosure is shown. The operations of the method 1900 may be implemented by a network entity or a component thereof as described herein. For example, the operations of the method 1900 may be implemented by a network entity or a component thereof as described herein. Figures 10 to 13 In some examples, the network entity may execute an instruction set to control the functional elements of the network entity to perform the functions described below. Additionally or alternatively, the network entity may use dedicated hardware to perform various aspects of the functions described below.
[0227] At 1905, the network entity may receive a registration request from a UE associated with the UAV including registration information corresponding to the UE. Operation 1905 may be performed according to the methods described herein. In some examples, the network entity may receive a registration request from a UE associated with the UAV including registration information corresponding to the UE. Figures 10 to 13 The registration request receiving component is described to perform various aspects of operation 1905.
[0228] At 1910, the network entity may generate a security configuration for communication between the UE and the UAV system service provider based at least in part on the registration information corresponding to the UE received in the registration request, the security configuration including one or more security credentials. Operation 1910 may be performed according to the methods described herein. In some examples, the method may be configured as described in reference to Figures 10 to 13 The secure communications determination components described perform aspects of operation 1910 .
[0229] At 1915, the network entity may determine one or more security credentials for enabling communication between the UE and the drone system service provider based at least in part on the registration request. Operation 1915 may be performed according to the methods described herein. In some examples, the method may be performed by a user as described in reference to Figures 10 to 13 The security determination components described are used to perform various aspects of operation 1915.
[0230] At 1920, the network entity may communicate with the UE based at least in part on the one or more security credentials. Operation 1920 may be performed according to the methods described herein. In some examples, the UE may be configured as described in reference to Figures 10 to 13 The communication components are described to perform various aspects of operation 1920.
[0231] It should be noted that the methods described herein describe possible embodiments, and that the operations and steps may be rearranged or otherwise modified, and other embodiments are possible. Additionally, aspects from two or more methods may be combined.
[0232] The following provides an overview of various aspects of the present disclosure:
[0233] Aspect 1: A method for wireless communication at a UE associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, comprising: performing a registration procedure with one or more network functions for communicating with an unmanned aerial vehicle system service provider, the one or more network functions including an access and mobility management function; receiving an indication of a security configuration from a unified data management entity in a non-access stratum transmission message via the access and mobility management function, the security configuration including one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider; and communicating with the unmanned aerial vehicle system service provider based at least in part on the one or more security credentials of the security configuration.
[0234] Aspect 2: The method of claim 1 further comprising: sending a confirmation message to the unified data management entity via the access and mobility management function indicating that the UE successfully received the indication of the security configuration, wherein communicating with the unmanned aerial vehicle system service provider is based at least in part on the confirmation message.
[0235] Aspect 3: The method according to any one of claims 1 to 2 further comprises: sending a registration request for the communication between the UE and the UAV system service provider to the UAV system service provider, the registration request including registration information corresponding to the UE.
[0236] Aspect 4: The method of claim 3, further comprising: determining to send the registration request to the drone system service provider based at least in part on the identity of the drone system service provider received in the indication of the security configuration.
[0237] Aspect 5: The method according to any one of claims 3 to 4 further comprises: receiving a registration response message from the drone system service provider in response to the registration request, the registration response message including an identifier for the UE, wherein communicating with the drone system service provider is based at least in part on the identifier for the UE in combination with the security configuration.
[0238] Aspect 6: The method of any one of claims 3 to 5, wherein the registration request is secured based at least in part on the one or more security credentials received from the unified data management entity.
[0239] Aspect 7: The method of any one of claims 3 to 6, wherein receiving the indication of the security configuration is based at least in part on sending the registration request.
[0240] Aspect 8: The method according to any one of claims 3 to 7, wherein the registration request includes a universal public subscription identifier of the UE, and the indication of the security configuration is received based at least in part on the universal public subscription identifier of the UE.
[0241] Aspect 9: The method according to any one of aspects 1 to 8, further comprising: determining to remove security credentials previously used by the UE for previous communications.
[0242] Aspect 10: A method according to any one of Aspects 1 to 9, wherein the security configuration includes: a UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify a received remote identifier broadcast by an additional UE, an identifier of the drone system service provider, or a combination thereof.
[0243] Aspect 11: The method according to any one of aspects 1 to 10, wherein the indication of the security configuration is received at a hardware component of the UE.
[0244] Aspect 12: A method for wireless communication at a unified data management entity, comprising: sending an indication of a security configuration to an access and mobility management function, the security configuration including one or more security credentials for enabling communication between a UE associated with an unmanned aerial vehicle (UAV) and an unmanned aerial vehicle system service provider; receiving a confirmation message from the access and mobility management function indicating that the UE successfully received the indication of the security configuration; and sending a message to the unmanned aerial vehicle system service provider based at least in part on receiving the confirmation message, the message indicating the one or more security credentials to be used by the UE for the communication with the unmanned aerial vehicle system service provider.
[0245] Aspect 13: The method according to Aspect 12, wherein sending the message to the drone system service provider further includes: generating the security configuration for the communication between the UE and the drone system service provider; and sending the indication of the security configuration to the drone system service provider to enable the communication between the UE and the drone system service provider.
[0246] Aspect 14: The method according to aspect 13, wherein the security configuration is generated at least in part based on: the UE registering with the network including the unified data management entity and the access and mobility management function, no security configuration was previously delivered to the UE, a security refresh for the UE, a trigger received from the unmanned aerial vehicle system service provider, or a combination thereof.
[0247] Aspect 15: The method according to any one of Aspects 12 to 14, further comprising: receiving the indication of the security configuration from the drone system service provider, wherein sending the indication of the security configuration to the access and mobility management function is at least partially based on receiving the indication of the security configuration from the drone system service provider.
[0248] Aspect 16: The method according to Aspect 15, wherein sending the message to the drone system service provider further comprises: sending a parameter provision information message to the drone system service provider, the parameter provision information message including the confirmation message indicating that the UE successfully received the indication of the security configuration.
[0249] Aspect 17: The method according to any one of Aspects 15 to 16, wherein receiving the indication of the security configuration includes: receiving the indication of the security configuration from the drone system service provider via a unified data management service message, a network open function update message, or a combination thereof.
[0250] Aspect 18: A method according to any one of Aspects 12 to 17, wherein sending the indication of the security configuration includes: sending a unified data management configuration update message for the parameters of the UE to the access and mobility management function, wherein the unified data management configuration update message includes the indication of the security configuration.
[0251] Aspect 19: A method according to any one of Aspects 12 to 18, wherein the security configuration includes: a UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of a wireless device and to verify a received remote identifier broadcast by an additional UE, an identifier of the drone system service provider, or a combination thereof.
[0252] Aspect 20: A method for wireless communication at an unmanned aerial vehicle system service provider, comprising: receiving a registration request including registration information corresponding to a UE associated with an unmanned aerial vehicle (UAV); determining one or more security credentials for enabling communication between the UE and the unmanned aerial vehicle system service provider based at least in part on the registration request; and communicating with the UE based at least in part on the one or more security credentials.
[0253] Aspect 21: The method according to Aspect 20, wherein determining the one or more security credentials comprises: receiving an indication of a security configuration from a unified data management entity, the security configuration comprising the one or more security credentials for enabling the communication between the UE and the drone system service provider.
[0254] Aspect 22: The method of aspect 21, wherein the unified data management entity generates the security configuration based at least in part on: the UE registering with a network including the unified data management entity, no previous delivery of a security configuration to the UE, a security refresh for the UE, a trigger received from the drone system service provider, or a combination thereof.
[0255] Aspect 23: A method according to any one of Aspects 20 to 22, wherein determining the one or more security credentials includes: generating a security configuration for the communication between the UE and the drone system service provider based at least in part on the registration information corresponding to the UE received in the registration request, the security configuration including the one or more security credentials.
[0256] Aspect 24: The method according to Aspect 23 further includes: sending an indication of the security configuration to a unified data management entity; and receiving a parameter provision information message from the unified data management entity, the parameter provision information message including a confirmation message indicating that the UE has successfully received the indication of the security configuration, wherein communicating with the UE is at least partially based on the confirmation message.
[0257] Aspect 25: The method according to aspect 24, wherein sending the indication of the security configuration comprises: sending the indication of the security configuration to the unified data management entity via a unified data management service message, a network open function update message, or a combination thereof.
[0258] Aspect 26: The method according to any one of aspects 23 to 25, wherein the registration request includes a universal public subscription identifier of the UE, and the one or more security credentials are generated based at least in part on the universal public subscription identifier.
[0259] Aspect 27: A method according to any one of Aspects 20 to 26, wherein the one or more security credentials include: a UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify a received remote identifier broadcast by an additional UE, an identifier of the drone system service provider, or a combination thereof.
[0260] Aspect 28: An apparatus for wireless communication at a UE associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, comprising: a processor; a memory coupled to the processor; and instructions stored in the memory and executable by the processor to cause the apparatus to perform a method according to any one of Aspects 1 to 11.
[0261] Aspect 29: An apparatus for wireless communication at a UE associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, comprising: at least one component for performing the method according to any one of aspects 1 to 11.
[0262] Aspect 30: A non-transitory computer-readable medium storing code for wireless communication at a UE associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, the code comprising instructions executable by a processor to perform the method of any one of Aspects 1 to 11.
[0263] Aspect 31: An apparatus for wireless communication at a unified data management entity, comprising: a processor; a memory coupled to the processor; and instructions stored in the memory and executable by the processor to cause the apparatus to perform a method according to any one of Aspects 12 to 19.
[0264] Aspect 32: An apparatus for wireless communication at a unified data management entity, comprising at least one component for performing the method according to any one of aspects 12 to 19.
[0265] Aspect 33: A non-transitory computer-readable medium storing code for wireless communication at a unified data management entity, the code comprising instructions executable by a processor to perform the method according to any one of aspects 12 to 19.
[0266] Aspect 34: An apparatus for wireless communication at an unmanned aerial vehicle system service provider, comprising: a processor; a memory coupled to the processor; and instructions stored in the memory and executable by the processor to cause the apparatus to perform a method according to any one of Aspects 20 to 27.
[0267] Aspect 35: An apparatus for wireless communication at a UAV system service provider, comprising at least one component for performing the method according to any one of Aspects 20 to 27.
[0268] Aspect 36: A non-transitory computer-readable medium storing code for wireless communication at a drone system service provider, the code comprising instructions executable by a processor to perform the method according to any one of aspects 20 to 27.
[0269] Although aspects of LTE, LTE-A, LTE-A Pro, or NR systems may be described for example purposes, and the terminology of LTE, LTE-A, LTE-A Pro, or NR may be used in many descriptions, the techniques described herein are applicable beyond LTE, LTE-A, LTE-A Pro, or NR networks. For example, the techniques described may be applicable to various other wireless communication systems, such as Ultra Mobile Broadband (UMB), Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDM, and other systems and radio technologies not explicitly mentioned herein.
[0270] The information and signals described herein may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0271] The various illustrative blocks and components described in conjunction with the disclosure herein may be implemented or performed with a general purpose processor, a DSP, an ASIC, a CPU, an FPGA, or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but in an alternative embodiment, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in combination with a DSP core, or any other such configuration).
[0272] The functions described herein can be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions can be stored on or transmitted via a computer-readable medium as one or more instructions or codes. Other examples and embodiments are within the scope of this disclosure and the appended claims. For example, due to the nature of software, the functions described herein can be implemented using software executed by a processor, hardware, firmware, hardwiring, or any combination thereof. Features that implement the functions can also be physically located in various locations, including being distributed so that parts of the functions are implemented at different physical locations.
[0273] Computer-readable media include non-transitory computer storage media and communication media (including any media that facilitates transferring a computer program from one place to another). Non-transitory storage media can be any available medium that can be accessed by a general or special-purpose computer. For example, and without limitation, non-transitory computer-readable media can include RAM, ROM, electrically erasable programmable ROM (EEPROM), compact disc (CD) ROM, flash memory, or other optical disc storage devices, magnetic disk storage devices or other magnetic storage devices, or can be used to carry or store the required program code method in the form of an instruction or data structure and any other non-transitory medium that can be accessed by a general or special-purpose computer, or a general or special-purpose processor. Moreover, any connection is appropriately referred to as a computer-readable medium. For example, if software is sent from a website, server or other remote source using coaxial cable, optical cable, twisted pair, digital subscriber line (DSL) or wireless technologies such as infrared, radio and microwave, coaxial cable, optical fiber cable, twisted pair, DSL or wireless technologies such as infrared, radio and microwave are included in the definition of computer-readable media. Disk and disc, as used herein, include CDs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above are also included within the scope of computer-readable media.
[0274] Moreover, as used herein (including in the claims), "or" as used in a list of items (e.g., a list of items preceded by a phrase such as "at least one of..." or "one or more") indicates an inclusive list, so that, for example, at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Moreover, as used herein, the phrase "based on" should not be interpreted as a reference to a closed set of conditions. For example, an exemplary step described as "based on condition A" can be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase "based on" should be interpreted in the same manner as the phrase "based at least in part on."
[0275] In the accompanying drawings, similar components or features may have the same reference label. In addition, various components of the same type may be distinguished by following the reference label with a dash and a second label that distinguishes the similar component. If only the first numerical reference label is used in the specification, the description applies to any of the similar components having the same first reference label, regardless of the second or subsequent reference labels.
[0276] The description set forth herein in conjunction with the accompanying drawings describes exemplary configurations and does not represent all possible examples that may be implemented or within the scope of the claims. The term "exemplary" as used herein means "serving as an example, instance, or illustration," rather than "preferred" or "superior to other examples." The detailed description includes specific details to provide an understanding of the described techniques. However, these techniques can be practiced without these specific details. In some examples, known structures and devices are shown in block diagram form to avoid obscuring the concepts of the described examples.
[0277] The description herein is provided to enable one of ordinary skill in the art to make or use the present disclosure. Various modifications to the present disclosure will be readily apparent to one of ordinary skill in the art, and the general principles defined herein may be applied to other variations without departing from the scope of the present disclosure. Therefore, the present disclosure is not limited to the examples and designs described herein, but should be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for wireless communication at a user equipment (UE) associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, comprising: performing a registration procedure with one or more network functions for communicating with a UAS service provider, the one or more network functions including an access and mobility management function; receiving, via the access and mobility management function, an indication of a security configuration from a unified data management entity in a non-access stratum transport message, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial vehicle system service provider, and the non-access stratum transport message comprising an acknowledgement bit indicating a request for acknowledgement of the security configuration; communicating with the drone system service provider based at least in part on the one or more security credentials of the security configuration; as well as Based at least in part on the confirmation bit indicating a request for confirmation of the security configuration, sending, via the access and mobility management function, a confirmation message to the unified data management entity indicating that the UE successfully received the indication of the security configuration, wherein communicating with the unmanned aerial vehicle system service provider is based at least in part on the confirmation message.
2. The method according to claim 1, further comprising: Sending a registration request for the communication between the UE and the UAV system service provider to the UAV system service provider, where the registration request includes registration information corresponding to the UE.
3. The method according to claim 2, further comprising: Sending the registration request to the unmanned aerial vehicle system service provider is determined based at least in part on an identity of the unmanned aerial vehicle system service provider received in the indication of the security configuration.
4. The method according to claim 2, further comprising: Receiving a registration response message from the UAV system service provider in response to the registration request, the registration response message including an identifier for the UE, wherein communicating with the UAV system service provider is based at least in part on the identifier for the UE in combination with the security configuration.
5. The method of claim 2, wherein the registration request is secured based at least in part on the one or more security credentials received from the unified data management entity. The method of claim 2 , wherein receiving the indication of the security configuration is based at least in part on sending the registration request.
7. The method of claim 2, wherein the registration request includes a universal public subscription identifier of the UE, and wherein the indication of the security configuration is received based at least in part on the universal public subscription identifier of the UE.
8. The method according to claim 1, further comprising: Determining to remove security credentials previously used by the UE for a previous communication.
9. The method of claim 1 , wherein the security configuration comprises: A UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof.
10. The method of claim 1, wherein the indication of the security configuration is received at a hardware component of the UE.
11. A method for wireless communication at a unified data management entity, comprising: sending an indication of a security configuration to an access and mobility management function, the security configuration comprising one or more security credentials for enabling communications between a user equipment (UE) associated with an unmanned aerial vehicle (UAV) and a UAV system service provider; receiving, based at least in part on a confirmation bit indicating that confirmation of the security configuration is requested, a confirmation message from the access and mobility management function indicating that the UE successfully received the indication of the security configuration; as well as A message is sent to the drone system service provider based at least in part on receiving the confirmation message, the message indicating the one or more security credentials to be used by the UE for the communication with the drone system service provider.
12. The method of claim 11 , wherein sending the message to the UAV system service provider further comprises: generating the security configuration for the communication between the UE and the UAV system service provider; as well as The indication of the security configuration is sent to the UAV system service provider to enable the communication between the UE and the UAV system service provider.
13. The method of claim 12 , wherein the security configuration is generated based at least in part on: registration of the UE with a network including the unified data management entity and the access and mobility management function, no previous delivery of a security configuration to the UE, a security refresh for the UE, a trigger received from the UAS service provider, or a combination thereof.
14. The method according to claim 11, further comprising: The indication of the security configuration is received from the unmanned aerial vehicle system service provider, wherein sending the indication of the security configuration to the access and mobility management function is based at least in part on receiving the indication of the security configuration from the unmanned aerial vehicle system service provider.
15. The method of claim 14, wherein sending the message to the UAV system service provider further comprises: A parameter provision information message is sent to the UAV system service provider, wherein the parameter provision information message includes the confirmation message indicating that the UE successfully received the indication of the security configuration.
16. The method of claim 14, wherein receiving the indication of the security configuration comprises: The indication of the security configuration is received from the unmanned aerial vehicle system service provider via a unified data management service message, a network open function update message, or a combination thereof.
17. The method of claim 11 , wherein sending the indication of the security configuration comprises: A unified data management configuration update message of parameters for the UE is sent to the access and mobility management function, wherein the unified data management configuration update message includes the indication of the security configuration.
18. The method of claim 11, wherein the security configuration comprises: A UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof.
19. A method for wireless communication at an unmanned aerial vehicle system service provider, comprising: receiving, from a user equipment (UE) associated with an unmanned aerial vehicle (UAV), a registration request including registration information corresponding to the UE; sending, to a unified data management entity or receiving, from a unified data management entity, an indication of a security configuration for communications between the UE and the unmanned aerial system service provider based at least in part on the registration request, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial system service provider; receiving, based at least in part on a confirmation bit indicating a request for confirmation of the security configuration by the UE, a parameter provision information message from the unified data management entity, the parameter provision information message including a confirmation message indicating that the UE successfully received the security configuration; as well as Communicating with the UE is performed based at least in part on the one or more security credentials and at least in part on the confirmation message.
20. The method of claim 19, wherein sending or receiving an indication of a security configuration comprises: The indication of a security configuration is received from the unified data management entity.
21. The method of claim 20, wherein the unified data management entity generates the security configuration based at least in part on: the UE registering with a network including the unified data management entity, no security configuration previously delivered to the UE, a security refresh for the UE, a trigger received from the UAS service provider, or a combination thereof.
22. The method according to claim 19, further comprising: The security configuration for the communication between the UE and the unmanned aerial vehicle system service provider is generated based at least in part on the registration information corresponding to the UE received in the registration request.
23. The method according to claim 22, wherein Sending or receiving instructions for security configuration includes: The indication of the security configuration is sent to the unified data management entity.
24. The method of claim 23, wherein sending the indication of the security configuration comprises: The indication of the security configuration is sent to the unified data management entity via a unified data management service message, a network open function update message, or a combination thereof.
25. The method of claim 22, wherein the registration request includes a universal public subscription identifier of the UE, and wherein the one or more security credentials are generated based at least in part on the universal public subscription identifier.
26. The method of claim 19, wherein the one or more security credentials include: A UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof.
27. An apparatus for wireless communication at a user equipment (UE) associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, comprising: processor, a memory coupled to the processor; as well as instructions stored in the memory and executable by the processor to cause the apparatus to: performing a registration procedure with one or more network functions for communicating with a UAS service provider, the one or more network functions including an access and mobility management function; receiving, via the access and mobility management function, an indication of a security configuration from a unified data management entity in a non-access stratum transport message, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial vehicle system service provider, and the non-access stratum transport message comprising an acknowledgement bit indicating a request for acknowledgement of the security configuration; communicating with the drone system service provider based at least in part on the one or more security credentials of the security configuration; as well as Based at least in part on the confirmation bit indicating a request for confirmation of the security configuration, sending, via the access and mobility management function, a confirmation message to the unified data management entity indicating that the UE successfully received the indication of the security configuration, wherein communicating with the unmanned aerial vehicle system service provider is based at least in part on the confirmation message.
28. The apparatus of claim 27, wherein the instructions are further executable by the processor to cause the apparatus to: Sending a registration request for the communication between the UE and the UAV system service provider to the UAV system service provider, where the registration request includes registration information corresponding to the UE.
29. The apparatus of claim 28, wherein the instructions are further executable by the processor to cause the apparatus to: Sending the registration request to the unmanned aerial vehicle system service provider is determined based at least in part on an identity of the unmanned aerial vehicle system service provider received in the indication of the security configuration.
30. The apparatus of claim 28, wherein the instructions are further executable by the processor to cause the apparatus to: Receiving a registration response message from the UAV system service provider in response to the registration request, the registration response message including an identifier for the UE, wherein communicating with the UAV system service provider is based at least in part on the identifier for the UE in combination with the security configuration.
31. The apparatus of claim 28, wherein the registration request is secured based at least in part on the one or more security credentials received from the unified data management entity.
32. The apparatus of claim 28, wherein receiving the indication of the security configuration is based at least in part on sending the registration request.
33. The apparatus of claim 28, wherein the registration request includes a universal public subscription identifier of the UE, and wherein the indication of the security configuration is received based at least in part on the universal public subscription identifier of the UE.
34. The apparatus of claim 27, wherein the instructions are further executable by the processor to cause the apparatus to: Determining to remove security credentials previously used by the UE for a previous communication.
35. The apparatus of claim 27, wherein the security configuration comprises: A UE identity for identifying the UE in the communication between the UE and the drone system service provider, credentials for the communication between the UE and the drone system service provider, private and public security keys for enabling the communication between the UE and the drone system service provider, one or more security keys to be used by the UE to broadcast a remote identifier of the UE and to verify received remote identifiers broadcast by additional UEs, an identifier of the drone system service provider, or a combination thereof.
36. The apparatus of claim 27, wherein the indication of the security configuration is received at a hardware component of the UE.
37. An apparatus for wireless communication at a unified data management entity, comprising: processor, a memory coupled to the processor; as well as instructions stored in the memory and executable by the processor to cause the apparatus to: sending an indication of a security configuration to an access and mobility management function, the security configuration comprising one or more security credentials for enabling communications between a user equipment (UE) associated with an unmanned aerial vehicle (UAV) and a UAV system service provider; receiving, based at least in part on a confirmation bit indicating that confirmation of the security configuration is requested, a confirmation message from the access and mobility management function indicating that the UE successfully received the indication of the security configuration; as well as A message is sent to the drone system service provider based at least in part on receiving the confirmation message, the message indicating the one or more security credentials to be used by the UE for the communication with the drone system service provider.
38. An apparatus for wireless communication at an unmanned aerial vehicle system service provider, comprising: processor, a memory coupled to the processor; as well as instructions stored in the memory and executable by the processor to cause the apparatus to: receiving, from a user equipment (UE) associated with an unmanned aerial vehicle (UAV), a registration request including registration information corresponding to the UE; sending, to a unified data management entity or receiving, from a unified data management entity, an indication of a security configuration for communications between the UE and the unmanned aerial system service provider based at least in part on the registration request, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial system service provider; receiving, based at least in part on a confirmation bit indicating a request for confirmation of the security configuration by the UE, a parameter provision information message from the unified data management entity, the parameter provision information message including a confirmation message indicating that the UE successfully received the security configuration; as well as Communicating with the UE is performed based at least in part on the one or more security credentials and at least in part on the confirmation message.
39. An apparatus for wireless communication at a user equipment (UE) associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, comprising: means for performing a registration procedure with one or more network functions for communications with an unmanned aerial vehicle system service provider, the one or more network functions including an access and mobility management function; means for receiving, via the access and mobility management function, an indication of a security configuration from a unified data management entity in a non-access stratum transport message, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial vehicle system service provider, and the non-access stratum transport message comprising an acknowledgement bit indicating a request for acknowledgement of the security configuration; means for communicating with the unmanned aerial vehicle system service provider based at least in part on the one or more security credentials of the security configuration; as well as means for sending, based at least in part on the confirmation bit indicating a request for confirmation of the security configuration, to the unified data management entity via the access and mobility management function, a confirmation message indicating that the UE successfully received the indication of the security configuration, wherein communicating with the unmanned aerial vehicle system service provider is based at least in part on the confirmation message.
40. An apparatus for wireless communication at a unified data management entity, comprising: means for sending an indication of a security configuration to an access and mobility management function, the security configuration comprising one or more security credentials for enabling communications between a user equipment (UE) associated with an unmanned aerial vehicle (UAV) and a UAV system service provider; means for receiving, based at least in part on a confirmation bit indicating that confirmation of the security configuration is requested, from the access and mobility management function a confirmation message indicating that the UE successfully received the indication of the security configuration; as well as Means for sending a message to the drone system service provider based at least in part on receiving the confirmation message, the message indicating the one or more security credentials to be used by the UE for the communication with the drone system service provider.
41. An apparatus for wireless communication at an unmanned aerial vehicle system service provider, comprising: means for receiving, from a user equipment (UE) associated with an unmanned aerial vehicle (UAV), a registration request including registration information corresponding to the UE; means for sending to or receiving from a unified data management entity an indication of a security configuration for communications between the UE and the unmanned aerial vehicle system service provider based at least in part on the registration request, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial vehicle system service provider; means for receiving a parameter provision information message from the unified data management entity based at least in part on a confirmation bit indicating a request for confirmation of the security configuration by the UE, the parameter provision information message including a confirmation message indicating that the UE successfully received the security configuration; as well as Means for communicating with the UE based at least in part on the one or more security credentials and at least in part on the confirmation message.
42. A non-transitory computer-readable storage medium storing instructions for wireless communications at a user equipment (UE) associated with an unmanned aerial vehicle (UAV) in a terrestrial cellular network, the instructions causing a processor to: performing a registration procedure with one or more network functions for communicating with a UAS service provider, the one or more network functions including an access and mobility management function; receiving, via the access and mobility management function, an indication of a security configuration from a unified data management entity in a non-access stratum transport message, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial vehicle system service provider, and the non-access stratum transport message comprising an acknowledgement bit indicating a request for acknowledgement of the security configuration; communicating with the drone system service provider based at least in part on the one or more security credentials of the security configuration; as well as Based at least in part on the confirmation bit indicating a request for confirmation of the security configuration, sending, via the access and mobility management function, a confirmation message to the unified data management entity indicating that the UE successfully received the indication of the security configuration, wherein communicating with the unmanned aerial vehicle system service provider is based at least in part on the confirmation message.
43. A non-transitory computer-readable storage medium storing instructions for wireless communication at a unified data management entity, the instructions causing a processor to: sending an indication of a security configuration to an access and mobility management function, the security configuration comprising one or more security credentials for enabling communications between a user equipment (UE) associated with an unmanned aerial vehicle (UAV) and a UAV system service provider; receiving, based at least in part on a confirmation bit indicating that confirmation of the security configuration is requested, a confirmation message from the access and mobility management function indicating that the UE successfully received the indication of the security configuration; and A message is sent to the drone system service provider based at least in part on receiving the confirmation message, the message indicating the one or more security credentials to be used by the UE for the communication with the drone system service provider.
44. A non-transitory computer-readable storage medium storing instructions for wireless communication at an unmanned aerial vehicle system service provider, the instructions causing a processor to: receiving, from a user equipment (UE) associated with an unmanned aerial vehicle (UAV), a registration request including registration information corresponding to the UE; sending, to a unified data management entity or receiving, from a unified data management entity, an indication of a security configuration for communications between the UE and the unmanned aerial system service provider based at least in part on the registration request, the security configuration comprising one or more security credentials for enabling communications between the UE and the unmanned aerial system service provider; receiving, based at least in part on a confirmation bit indicating a request for confirmation of the security configuration by the UE, a parameter provision information message from the unified data management entity, the parameter provision information message including a confirmation message indicating that the UE successfully received the security configuration; as well as Communicating with the UE is performed based at least in part on the one or more security credentials and at least in part on the confirmation message.
45. A computer program product comprising computing instructions for performing the method of any one of claims 1-10 when executed by one or more processors.
46. A computer program product comprising computing instructions for performing the method of any one of claims 11-18 when executed by one or more processors.
47. A computer program product comprising computing instructions for performing the method of any one of claims 19-26 when executed by one or more processors.
Citation Information
Patent Citations
3GPP private lans
WO2020068765A1