Method and apparatus for enhancing security mechanisms in unicast mode sidelink communications

By restricting the update and modification of the direct link identifier of the second user equipment in the wireless communication system, combining IP address configuration and secure information exchange, security risks in unicast mode side link communication are solved, and the security and reliability of the communication system are improved.

CN118945655BActive Publication Date: 2025-08-26ASUS TECH LICENSING INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311829466.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2023-05-11
Filing Date
2023-12-28
Publication Date
2025-08-26
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

The existing wireless communication systems lack effective security mechanisms in unicast mode side link communication, which leads to security risks during the communication process, especially during the direct link key update process, which may lead to security problems.

Method used

By not allowing the second UE to initiate a direct link identifier update program or a direct link modification program when establishing a unicast link with the first UE, it is ensured that encryption measures are adopted during the direct link establishment process, including IP address configuration and security information exchange, and the security of communication is ensured.

Benefits of technology

Improve the security of unicast mode side link communication, prevent unauthorized equipment access, and enhance the security of the communication system and the reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118945655B_ABST
    Figure CN118945655B_ABST
Patent Text Reader

Abstract

A method and apparatus for enhancing security mechanisms in unicast mode sidelink communications. A second user equipment establishes a unicast link with a first user equipment. Furthermore, if at least the second user equipment is executing any direct link key update procedure triggered by the first user equipment for the unicast link, the second user equipment is not permitted to initiate a direct link identifier update procedure or a direct link modification procedure.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 465,611, filed May 11, 2023, the entire disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] The present disclosure relates generally to wireless communication networks, and more particularly, to methods and apparatus for enhancing security mechanisms in unicast mode sidelink communications in wireless communication systems. Background Art

[0004] With the rapidly growing demand for transferring large amounts of data to and from mobile communication devices, traditional mobile voice communication networks have evolved into networks that use Internet Protocol (IP) packet communications. This IP packet communication can provide IP-based voice, multimedia, multicast, and on-demand communication services to users of mobile communication devices.

[0005] An exemplary network architecture is the Evolved Universal Terrestrial Radio Access Network (E-UTRAN). The E-UTRAN system can provide high data throughput to enable the aforementioned IP-based voice and multimedia services. Currently, the 3GPP standards organization is discussing new next-generation (e.g., 5G) radio technologies. Consequently, changes to the current body of 3GPP standards are currently being submitted and considered to evolve and complete the 3GPP standards. Summary of the Invention

[0006] A method and apparatus for a second user equipment (UE). In one embodiment, the second UE establishes a unicast link with a first UE. Furthermore, if at least the second UE is executing any direct link key update procedure triggered by the first UE for the unicast link, the second UE is not allowed to initiate a direct link identifier update procedure or a direct link modification procedure. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 A diagram illustrating a wireless communication system according to an exemplary embodiment is shown;

[0008] Figure 2 is a block diagram of a transmitter system (also referred to as an access network) and a receiver system (also referred to as a user equipment or UE) according to an exemplary embodiment;

[0009] Figure 3 is a functional block diagram of a communication system according to an exemplary embodiment;

[0010] Figure 4According to an exemplary embodiment Figure 3 Functional block diagram of the program code;

[0011] Figure 5 It is 3GPP TS 23.304 V17.5.0 Figure 6 .4.3.1-1 reappearance;

[0012] Figure 6 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.2.2.1 reproduction;

[0013] Figure 7 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.2.2.2 reproduction;

[0014] Figure 8 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.3.2.1 reproduction;

[0015] Figure 9 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.4.2.1 reproduction;

[0016] Figure 10 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.10.2.1 Reproduction;

[0017] Figure 11 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.11.2.1 Reproduction;

[0018] Figure 12 It is 3GPP TS 24.554 V17.4.0 Figure 7 .2.12.2.1 Reproduction;

[0019] Figure 13 is a flow chart according to an exemplary embodiment;

[0020] Figure 14 is a flow chart according to an exemplary embodiment;

[0021] Figure 15 is a flow chart according to an exemplary embodiment. DETAILED DESCRIPTION

[0022] The exemplary wireless communication systems and devices described below employ wireless communication systems that support broadcast services. Wireless communication systems are widely deployed to provide various types of communications, such as voice, data, etc. These systems can be based on code division multiple access (CDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), 3GPP Long Term Evolution (LTE) radio access, 3GPP LTE-A or LTE Advanced (Long Term Evolution Advanced), 3GPP2 Ultra Mobile Broadband (UMB), WiMax, 3GPP New Radio (NR), or some other modulation technology.

[0023] Specifically, the exemplary wireless communication system apparatus described below may be designed to support one or more standards, such as those provided by an association named “3rd Generation Partnership Project” (referred to herein as 3GPP), including: TS 23.304 V17.5.0, “Proximity-based Services (ProSe) in 5G System (5GS) (Release 17)”; and TS 24.554 V17.4.0, “Proximity Services (ProSe) in 5G System (5GS) Protocol Aspects; Stage 3 (Release 17)”. The standards and documents listed above are expressly incorporated herein by reference in their entirety.

[0024] Figure 1 1. A multiple access wireless communication system according to an embodiment of the present invention is shown. An access network 100 (AN) includes multiple antenna groups, one of which includes antennas 104 and 106, another includes antennas 108 and 110, and another includes antennas 112 and 114. Figure 1, only two antennas are shown for each antenna group, but each antenna group may utilize more or fewer antennas. Access terminal 116 (AT) communicates with antennas 112 and 114, where antennas 112 and 114 transmit information to access terminal 116 via forward link 120 and receive information from access terminal 116 via reverse link 118. Access terminal 122 communicates with antennas 106 and 108, where antennas 106 and 108 transmit information to access terminal 122 via forward link 126 and receive information from access terminal 122 via reverse link 124. In an FDD system, communication links 118, 120, 124, and 126 may use different frequencies for communication. For example, forward link 120 may use a different frequency than that used by reverse link 118.

[0025] Each antenna group and / or the area in which they are designed to communicate is often referred to as a sector of the access network. In an embodiment, the antenna groups are each designed to communicate with access terminals in a sector of the area covered by the access network 100.

[0026] In communicating via forward links 120 and 126, the transmit antennas of access network 100 may utilize beamforming to improve the signal-to-noise ratio of the forward links for the different access terminals 116 and 122. Furthermore, an access network that uses beamforming to transmit to access terminals randomly dispersed throughout the coverage area of ​​the access network may cause less interference to access terminals in neighboring cells than an access network that transmits to all of its access terminals via a single antenna.

[0027] An access network (AN) may be a fixed station or base station for communicating with a terminal and may also be referred to as an access point, Node B, base station, enhanced base station, evolved Node B (eNodeB), network node, network, or some other terminology. An access terminal (AT) may also be referred to as user equipment (UE), a wireless communication device, terminal, access terminal, or some other terminology.

[0028] Figure 2 is a simplified block diagram of an embodiment of a transmitter system 210 (also referred to as an access network) and a receiver system 250 (also referred to as an access terminal (AT) or user equipment (UE)) in a MIMO system 200. At the transmitter system 210, traffic data for several data streams is provided from a data source 212 to a transmit (TX) data processor 214.

[0029] In one embodiment, each data stream is transmitted through a respective transmit antenna. TX data processor 214 formats, codes, and interleaves the traffic data for each data stream based on a particular coding scheme selected for that data stream to provide coded data.

[0030] The coded data for each data stream may be multiplexed with pilot data using OFDM techniques. The pilot data is typically a known data pattern that is processed in a known manner and may be used at the receiver system to estimate the channel response. The multiplexed pilot and coded data for each data stream is then modulated (i.e., symbol mapped) based on a particular modulation scheme selected for that data stream (e.g., BPSK, QPSK, M-PSK, or M-QAM) to provide modulation symbols. The data rate, coding, and modulation for each data stream may be determined by instructions executed by processor 230.

[0031] The modulation symbols for all data streams are then provided to a TX MIMO processor 220, which may further process the modulation symbols (e.g., for OFDM). The TX MIMO processor 220 then converts the N T The modulation symbol stream is provided to N T transmitters (TMTR) 222a through 222t. In certain embodiments, TX MIMO processor 220 applies beamforming weights to the symbols of the data streams and to the antenna from which the symbol is being transmitted.

[0032] Each transmitter 222 receives and processes a respective symbol stream to provide one or more analog signals, and further conditions (eg, amplifies, filters, and upconverts) the analog signals to provide a modulated signal suitable for transmission via the MIMO channel. T The antennas 224a to 224t transmit N signals from transmitters 222a to 222t. T a modulated signal.

[0033] At the receiver system 250, N R The transmitted modulated signals are received by each antenna 252a through 252r and the received signal from each antenna 252 is provided to a respective receiver (RCVR) 254a through 254r. Each receiver 254 conditions (e.g., filters, amplifies, and downconverts) a respective received signal, digitizes the conditioned signal to provide samples, and further processes the samples to provide a corresponding "received" symbol stream.

[0034] RX data processor 260 then extracts the N R The receiver 254 receives and processes N R receive symbol streams to provide N TThe RX data processor 260 then demodulates, deinterleaves, and decodes each detected symbol stream to recover the traffic data for the data stream. The processing by the RX processor 260 is complementary to that performed by the TX MIMO processor 220 and the TX data processor 214 at the transmitter system 210.

[0035] Processor 270 periodically determines which pre-coding matrix to use (discussed below). Processor 270 formulates a reverse link message comprising a matrix index portion and a rank value portion.

[0036] The reverse link message may include various types of information related to the communication link and / or the received data stream. The reverse link message is then processed by the TX data processor 238 (which also receives traffic data for a number of data streams from the data source 236), modulated by the modulator 280, conditioned by the transmitters 254a through 254r, and transmitted back to the transmitter system 210.

[0037] At transmitter system 210, the modulated signal from receiver system 250 is received by antenna 224, conditioned by receiver 222, demodulated by demodulator 240, and processed by RX data processor 242 to extract the reverse link message transmitted by receiver system 250. Processor 230 then determines which precoding matrix to use to determine the beamforming weights and then processes the extracted message.

[0038] Steering Figure 3 , this figure shows an alternative simplified functional block diagram of a communication device according to one embodiment of the present invention. Figure 3 As shown in FIG, the communication device 300 in the wireless communication system can be used to implement Figure 1 UE (or AT) 116 and 122 in or Figure 1 The base station (or AN) 100 in the wireless communication system is preferably an NR system. The communication device 300 may include an input device 302, an output device 304, a control circuit 306, a central processing unit (CPU) 308, a memory 310, a program code 312, and a transceiver 314. The control circuit 306 executes the program code 312 in the memory 310 through the CPU 308, thereby controlling the operation of the communication device 300. The communication device 300 can receive signals input by the user through the input device 302 (for example, a keyboard or a keypad), and can output images and sounds through the output device 304 (for example, a display or a speaker). The transceiver 314 is used to receive and transmit wireless signals to pass the received signal to the control circuit 306 and wirelessly output the signal generated by the control circuit 306. The communication device 300 in the wireless communication system can also be used to implement Figure 1 AN 100 in.

[0039] Figure 4 According to one embodiment of the present invention Figure 3 . In this embodiment, program code 312 includes an application layer 400, a layer 3 portion 402, and a layer 2 portion 404, and is coupled to a layer 1 portion 406. Layer 3 portion 402 generally performs radio resource control. Layer 2 portion 404 generally performs link control. Layer 1 portion 406 generally performs physical connectivity.

[0040] 3GPP TS 23.304 describes the following:

[0041] 6.4.3.1 Layer 2 link establishment over the PC5 reference point

[0042] To perform the unicast mode of ProSe direct communication over the PC5 reference point, the UE is configured with the relevant information described in Section 5.1.3.

[0043] Figure 6 .4.3.1-1 shows the Layer 2 link establishment procedure for unicast mode of ProSe direct communication over the PC5 reference point.

[0044] [3GPP TS 23.304 V17.5.0 entitled "Layer 2 Link Establishment Procedure" Figure 6 .4.3.1-1 Reproduced as Figure 5 ]

[0045] 1. As specified in section 5.8.2.4, the UE determines the destination Layer 2 ID for signaling reception for PC5 unicast link establishment.

[0046] 2. The ProSe application layer in UE-1 provides application information for PC5 unicast communication. The application information includes ProSe service information and the UE's application layer ID. The application information may also include the target UE's application layer ID.

[0047] The ProSe application layer in UE-1 may provide the ProSe application requirements for this unicast communication.As specified in Section 5.6.1, UE-1 determines PC5 QoS parameters and PFI.

[0048] If UE-1 decides to reuse the existing PC5 unicast link specified in section 5.3.4, the UE triggers the Layer 2 Link Modification procedure specified in section 6.4.3.4.

[0049] 3. UE-1 sends a direct communication request message to initiate the unicast layer 2 link establishment procedure. The direct communication request message contains:

[0050] - Source user information: the application layer ID of the originating UE (ie, the application layer ID of UE-1).

[0051] If the ProSe application layer provides the target UE's application layer ID in step 2, the following information is included:

[0052] - Target user information: the application layer ID of the target UE (ie, the application layer ID of UE-2).

[0053] -ProSe service information: information about the ProSe identifier requesting Layer 2 link establishment.

[0054] - Security information: information used to establish security.

[0055] NOTE 1 Security information and the necessary protection of source and destination user information are defined by SA WG3.

[0056] As specified in Sections 5.8.2.1 and 5.8.2.4, determine the source Layer 2 ID and destination Layer 2 ID used to send the Direct Communication Request message. The destination Layer 2 ID can be a broadcast or unicast Layer 2 ID. When using a unicast Layer 2 ID, the target user information should be included in the Direct Communication Request message.

[0057] UE-1 transmits a direct communication request message through PC5 which is broadcast or unicast using the source layer 2 ID and the destination layer 2 ID.

[0058] The default PC5 DRX configuration may be used to transmit and receive this message (see TS 38.300

[12] ).

[0059] 4. Establish security for UE-1 as follows:

[0060] 4a. If the target user information is included in the direct communication request message, the target UE, ie, UE-2, responds by establishing security with UE-1.

[0061] 4b. If the target user information is not included in the direct communication request message, the UE interested in using the notified ProSe service over the PC5 unicast link with UE-1 responds by establishing security with UE-1.

[0062] NOTE 2: Signalling for security procedures is defined by SA WG3.

[0063] When security protection is enabled, UE-1 sends the following information to the target UE:

[0064] - If using IP communication, then:

[0065] -IP address configuration: For IP communication, this link requires an IP address configuration, and the IP address configuration indicates one of the following values:

[0066] - "DHCPv4 server", if only IPv4 address allocation mechanism is supported by the initiating UE, i.e. acting as a DHCPv4 server; or

[0067] - "IPv6 router", if only the IPv6 address allocation mechanism is supported by the originating UE, i.e. acting as an IPv6 router; or

[0068] - "DHCPv4 server and IPv6 router", if both IPv4 and IPv6 address allocation mechanisms are supported by the initiating UE; or

[0069] - "Address allocation not supported" if both IPv4 and IPv6 address allocation mechanisms are not supported by the originating UE.

[0070] - Link-local IPv6 address: If UE-1 does not support the IPv6 IP address allocation mechanism, i.e. the IP address configuration indicates "address allocation not supported", then a link-local IPv6 address is formed locally based on RFC 4862

[17] .

[0071] - QoS information: Information about PC5 QoS flows. For each PC5 QoS flow, PFI and corresponding PC5 QoS parameters (ie, PQI and conditionally other parameters such as MFBR / GFBR) and associated ProSe identifier.

[0072] -Optional PC5 QoS rules.

[0073] As specified in sections 5.8.2.1 and 5.8.2.4, the source Layer 2 ID for the security establishment procedure is determined. The destination Layer 2 ID is set to the source Layer 2 ID of the received direct communication request message.

[0074] Upon receiving the Security Setup Procedure message, UE-1 obtains the Layer 2 ID of the peer UE for future communications for signaling and data traffic for this unicast link.

[0075] 5. The target UE, which has successfully established security with UE-1, sends a direct communication acceptance message to UE-1:

[0076] 5a. (Layer 2 Link Establishment Towards UE) If the target user information is included in the Direct Communication Request message, then if the application layer ID for UE-2 matches, the target UE (ie, UE-2) responds with a Direct Communication Accept message.

[0077] 5b. (Layer 2 Link Establishment for ProSe Services) If the Direct Communication Request message does not contain target user information, the UE interested in using the notified ProSe service (in Figure 6 .UE-2 and UE-4 in 4.3.1-1) respond to the request by sending a direct communication accept message.

[0078] The direct communication acceptance message includes:

[0079] -Source user information: the application layer ID of the UE that sends the direct communication accept message.

[0080] - QoS information: Information about PC5 QoS flows. For each PC5 QoS flow, the PFI requested by UE-1 and the corresponding PC5 QoS parameters (ie, PQI and conditionally other parameters such as MFBR / GFBR) and optionally an associated ProSe identifier.

[0081] -Optional PC5 QoS rules.

[0082] - If using IP communication, then:

[0083] -IP address configuration: For IP communication, this link requires an IP address configuration, and the IP address configuration indicates one of the following values:

[0084] - "DHCPv4 server", if only IPv4 address allocation mechanism is supported by the target UE, i.e. act as a DHCPv4 server; or

[0085] - "IPv6 router", if only IPv6 address allocation mechanisms are supported by the target UE, i.e. acting as an IPv6 router; or

[0086] - "DHCPv4 server and IPv6 router", if both IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or

[0087] - "Address allocation not supported" if both IPv4 and IPv6 address allocation mechanisms are not supported by the target UE.

[0088] - Link-local IPv6 address: If the target UE does not support the IPv6 IP address allocation mechanism, i.e., the IP address configuration indicates "address allocation not supported", and UE-1 includes a link-local IPv6 address in the Direct Communication Request message, then a link-local IPv6 address is formed locally based on RFC4862

[17] . The target UE shall include a non-conflicting link-local IPv6 address.

[0089] If two UEs (ie, the initiating UE and the target UE) are selected to use link-local IPv6 addresses, then the two UEs shall disable dual address detection as defined in RFC 4862

[17] .

[0090] NOTE 3: When the initiating UE or target UE indicates support for IPv6 routers, the corresponding address configuration procedure shall be implemented after the Layer 2 link is established and the link-local IPv6 address shall be ignored.

[0091] The ProSe layer of the UE that establishes a PC5 unicast link passes the PC5 link identifier and PC5 unicast link-related information allocated for the unicast link down to the AS layer. The PC5 unicast link-related information includes Layer 2 ID information (i.e., source Layer 2 ID and destination Layer 2 ID). This enables the AS layer to maintain the PC5 link identifier and PC5 unicast link-related information.

[0092] Two UEs may negotiate the PC5 DRX configuration in the AS layer, and the PC5 DRX parameter value may be configured according to a pair of source / destination Layer 2 IDs in the AS layer.

[0093] 6. ProSe data is transmitted over the established unicast link as follows:

[0094] The PC5 link identifier and PFI are provided to the AS layer together with the ProSe data.

[0095] Additionally, layer 2 ID information (ie, source layer 2 ID and destination layer 2 ID) is optionally provided to the AS layer.

[0096] NOTE 4: It is up to the UE implementation to provide the Layer 2 ID information to the AS layer.

[0097] UE-1 sends ProSe data using a source Layer 2 ID (ie, the Layer 2 ID of UE-1 for this unicast link) and a destination Layer 2 ID (ie, the Layer 2 ID of the peer UE for this unicast link).

[0098] NOTE 5: The PC5 unicast link is bidirectional, so UE-1's peer UE can send ProSe data to UE-1 through the unicast link with UE-1.

[0099] 3GPP TS 24.554 describes the following:

[0100] 7.2.2 5G ProSe Direct Link Establishment Procedure

[0101] 7.2.2.1 Overview

[0102] Depending on the type of 5G ProSe direct link establishment procedure (i.e., UE-oriented Layer 2 link establishment or ProSe service-oriented Layer 2 link establishment in 3GPP TS 23.304 [2]), the 5G ProSe direct link establishment procedure is used to establish a 5G ProSe direct link between two UEs or to establish multiple 5G ProSe direct links between a UE and multiple target UEs. The UE that sends the request message is called the "initiating UE" and the other UE is called the "target UE". If the request message does not indicate a specific target UE (i.e., target user information is not included in the request message) and multiple target UEs are interested in the ProSe application indicated in the request message, the initiating UE shall process the corresponding response messages received from those target UEs. The maximum number of 5G ProSe direct links established in a UE at any one time shall not exceed the implementation-specific maximum number of established 5G ProSe direct links.

[0103] NOTE 1: The recommended maximum number of established 5G ProSe direct links is 8.

[0104] When the 5G ProSe direct link establishment procedure for a 5G ProSe layer 3 remote UE is successfully completed, and if there is a PDU session established for relaying traffic of the 5G ProSe remote UE, the 5G ProSe layer 3 UE to network relay UE shall perform the remote UE reporting procedure specified in 3GPP TS 24.501

[11] .

[0105] NOTE 2: A single PC5 unicast link is established between the 5G ProSe Layer 2 UE to network relay UE and the 5G ProSe Layer 2 remote UE to support the PDU session of the 5G ProSe Layer 2 remote UE, as specified in 3GPP TS 38.300

[21] .

[0106] 7.2.2.2 5G ProSe Direct Link Establishment Procedure Initiated by the Initiating UE

[0107] The initiating UE shall meet the following prerequisites before initiating this procedure:

[0108] a) A request from an upper layer to transmit a packet for a ProSe application through PC5 or a request from a lower layer to trigger a ProSe direct link establishment;

[0109] b) the communication mode is unicast mode (e.g., pre-configured as specified in Section 5.2.4 or indicated by upper layers);

[0110] c) the link layer identifier for the initiating UE (i.e., Layer 2 ID for unicast communication) is available (e.g., pre-configured or self-assigned) and is not used by other existing 5G ProSe direct links within the initiating UE;

[0111] d) the link layer identifier for the destination UE (i.e., the unicast Layer 2 ID or broadcast Layer 2 ID of the target UE) is available to the initiating UE (e.g., pre-configured, obtained as specified in Section 5.2, known via previous ProSe direct communication, or indicated by lower layers);

[0112] NOTE 1: In the case where different ProSe applications are mapped to different preset destination Layer 2 IDs, when the originating UE wishes to establish a single unicast link that can be used for more than one ProSe identifier, the UE may select any of the preset destination Layer 2 IDs for unicast initial signaling.

[0113] e) The originating UE is authorized for 5G ProSe direct communication via PC5 in NR-PC5 in the serving PLMN, has valid authorization for 5G ProSe direct communication via PC5 in NR-PC5 when not served by NG-RAN, or is authorized to use 5G ProSe UE to network relay UE. A UE is considered not to be served by NG-RAN if the following conditions are met:

[0114] 1) Not served by NG-RAN for ProSe direct communication via PC5;

[0115] 2) in the limited service state as specified in 3GPP TS 23.122

[14] , provided that the reason why the UE is in the limited service state is one of the following;

[0116] i) The UE cannot find a suitable cell in the selected PLMN, as specified in 3GPP TS 38.304

[15] ;

[0117] ii) the UE receives a REGISTRATION REJECT message or SERVICE REJECT message with 5GMM cause #11 “PLMN not allowed” as specified in 3GPP TS 24.501

[11] ; or

[0118] iii) the UE receives a REGISTRATION REJECT message or SERVICE REJECT message with 5GMM cause #7 “5GS service not allowed” as specified in 3GPP TS 24.501

[11] ; or

[0119] 3) is in the limited service state as specified in 3GPP TS 23.122

[14] for reasons other than i), ii) or iii) above and is located in a geographical area where the UE has “non-operator managed” radio parameters as specified in section 5.2;

[0120] f) There is no existing 5G ProSe direct link for a pair of peer application layer IDs, or there is an existing 5G ProSe direct link for a pair of peer application layer IDs, and:

[0121] 1) The network layer protocol of the existing 5G ProSe direct link is different from the network layer protocol required by the upper layer for this ProSe application in the initiating UE;

[0122] 2) The security policy (signaling security policy or user plane security policy) corresponding to the ProSe identifier is not compatible with the security policy of the existing 5G ProSe direct link; or

[0123] 3) where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe Layer 3 remote UE and a 5G ProSe Layer 3 UE-to-network relay UE, an existing 5G ProSe direct link for peer UEs is established with a different RSC or is established not for direct communication between the 5G ProSe Layer 3 remote UE and the 5G ProSe Layer 3 UE-to-network relay UE; or

[0124] 4) in case the 5G ProSe direct link establishment procedure is for direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE to a relay UE of the network, establishing an existing 5G ProSe direct link for peer UEs, but which is not used for direct communication between a 5G ProSe layer 2 remote UE and a 5G ProSe layer 2 UE to a relay UE of the network;

[0125] g) the number of established 5G ProSe direct links is less than the implementation-specific maximum number of established 5G ProSe direct links allowed in the UE at any one time; and

[0126] h) Timer T5088 is not associated with the link layer identifier of the destination UE or timer T5088 associated with the link layer identifier of the destination UE has expired or stopped.

[0127] After receiving service data or request from upper layers, the initiating UE shall derive PC5 QoS parameters and assign a PQFI for the PC5 QoS flow established as specified in section 7.2.7.

[0128] If the 5G ProSe Direct Link Establishment procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-network Relay UE, the UE shall apply DUCK or DUSK with the associated encrypted bitmask for UE-to-network relay discovery and a UTC-based counter for encryption:

[0129] a) Relay service code; and

[0130] b) UP-PRUK ID or CP-PRUK ID (if applicable),

[0131] As specified in section 6.3.5.2 of 3GPP TS 33.503

[34] , the UE shall use the security-protected relay service code and the security-protected UP-PRUK ID or the security-protected CP-PRUK ID to create the ProSe Direct Link Setup Request message.

[0132] NOTE 2: If the UE is configured to use neither DUCK nor DUSK, the relay service code and UP-PRUK ID or CP-PRUK ID are not encrypted.

[0133] To initiate the 5G ProSe direct link establishment procedure, the initiating UE will generate a ProSe direct link establishment request message.

[0134] Initiating UE:

[0135] a) shall contain source user information set to the application layer ID of the originating UE received from upper layers;

[0136] b) if the 5G ProSe Direct Link Establishment procedure is not used for 5G ProSe direct communication between a 5G ProSe Remote UE and a 5G ProSe UE to a network relay UE, then the ProSe identifier received from upper layers shall be included;

[0137] c) shall contain the target user information, if received from upper layers or if known based on the unicast Layer 2 ID of the target UE (i.e., the destination Layer 2 ID), said target user information being set to the application layer ID of the target UE as described in section 5.8.2.4 of 3GPP TS 23.304 [3] or to the user information ID of the relay UE from the 5G ProSe UE to the network obtained during the relay discovery procedure from the 5G ProSe UE to the network;

[0138] d) If the 5G ProSe direct link is not used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE to network relay UE:

[0139] 1) If the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection required" or "signaling integrity protection preferred", then the key establishment information container shall be included, and if the UE PC5 unicast signaling integrity protection policy is set to "signaling integrity protection not required", then the key establishment information container may be included;

[0140] NOTE 3: The key establishment information container is provided by the upper layer.

[0141] e) will include:

[0142] 1) Nonce_1, provided that the direct communication is not between a 5G ProSe Remote UE and a 5G ProSe UE to a network relay UE, or provided that the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to a network relay UE and the security procedures on the control plane are used as specified in 3GPP TS 33.503

[34] ;

[0143] 2)K NRP Freshness parameter 1, provided that direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE and security procedures on the user plane are used as specified in 3GPP TS 33.503

[34] ;

[0144] If the UE PC5 unicast signaling integrity protection policy is set to "Signaling integrity protection required" or "Signaling integrity protection preferred", then this field shall contain the 128-bit nonce generated by the initiating UE for the purpose of session key establishment over this 5G ProSe direct link;

[0145] NOTE 4: The Nonce_1 IE in the ProSe Direct Link Setup Request message is used to store the value of Nonce_1 or K NRP Freshness parameter 1.

[0146] f) shall include its UE security capabilities, indicating the list of algorithms supported by the initiating UE for security establishment of this 5G ProSe direct link;

[0147] g) If the UE PC5 unicast signaling integrity protection policy is set to "Signaling integrity protection required" or "Signaling integrity protection preferred", then the K selected by the originating UE as specified in 3GPP TS 33.503

[34] shall be included. NRP-sess MSB of ID;

[0148] NOTE 5: If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a relay UE in the network, then K NRP-sess ID remains corresponding to K NRP-sess If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then K NRP-sess ID remains corresponding to K NRP-sess (if security procedures on the user plane are used) or K relay-sess The ID of the control plane security program (if using).

[0149] h) If the originating UE has an existing K for the target UE NRP , and the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a relay UE on the network, then K NRP ID;

[0150] i) will include its UE PC5 unicast signaling security policy. In the case where different ProSe applications are mapped to different PC5 unicast signaling security policies, when the initiating UE wants to establish a single unicast link that can be used for more than one ProSe application, each signaling security policy of these ProSe applications should be compatible, for example, "signaling integrity protection not required" and "signaling integrity protection required" are incompatible. In the case where the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, the signaling integrity protection policy will be set to "signaling integrity protection required";

[0151] j) if the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay UE, then the Relay Service Code IE shall be included which shall be set to the Relay Service Code of the target relay UE;

[0152] k) containing a UTC-based counter LSB, which is set to the four least significant bits of the UTC-based counter in case the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE;

[0153] l) The UE Identity IE set to the SUCI of the originating UE shall be included if:

[0154] 1) 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE; and

[0155] 2) Security for relaying from a 5G ProSe UE to the network uses security procedures on the control plane and the originating UE does not have a valid CP-PRUK as specified in 3GPP TS 33.503

[34] , or security for relaying from a 5G ProSe UE to the network uses security procedures on the user plane and the originating UE does not have a valid UP-PRUK as specified in 3GPP TS 33.503

[34] ;

[0156] m) shall contain the User Security Key ID IE, which shall be set to:

[0157] 1) The UP-PRUK ID of the initiating UE, provided that:

[0158] i) The 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a relay UE in the network;

[0159] ii) the originating UE has a valid UP-PRUK; and

[0160] iii) security for 5G ProSe UE to network relay using security procedures on the user plane as specified in 3GPP TS 33.503

[34] ; or

[0161] 2) The CP-PRUK ID of the originating UE associated with the relay service code of the target UE, provided that:

[0162] i) The 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a relay UE in the network;

[0163] ii) the originating UE has a valid CP-PRUK associated with the target UE's relay service code; and

[0164] iii) Security for 5G ProSe UE to network relay uses security procedures on the control plane as specified in 3GPP TS 33.503

[34] ;

[0165] n) shall contain the HPLMN ID of the originating UE, provided that the UP-PRUK ID of the originating UE is included and is not in NAI format (see 3GPP TS 33.503

[34] ); and

[0166] o) The MIC IE shall be included, which is set to the calculated MIC value in the case where the 5G ProSe Direct Link Establishment procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE and the UE has a DUIK, as specified in section 6.3.5.3 of 3GPP TS 33.503

[34] .

[0167] After generating the ProSe Direct Link Setup Request message, the initiating UE passes this message along with the source Layer 2 ID and the destination Layer 2 ID to the lower layers for transmission as follows:

[0168] a) If 5G ProSe direct communication is initiated by 5G ProSe direct discovery, as defined in sections 6.2.14, 6.2.15, and 8.2.1:

[0169] self-assigns a source Layer 2 ID and a destination Layer 2 ID set to the source Layer 2 ID in the received ProSe PC5 discovery message for use in the discovery procedure; or

[0170] b) Otherwise:

[0171] self-assigned Source Layer 2 ID and Destination Layer 2 ID set to the Destination Layer 2 ID used for unicast initial signaling as specified in Section 5.2.4,

[0172] NOTE 6: The UE implementation ensures that any value of the self-assigned source Layer-2 ID in a) and b) is different from any other self-assigned source Layer-2 ID used for 5G ProSe direct discovery as specified in sections 6.2.14, 6.2.15 and 8.2.1, and different from any other provided destination Layer-2 ID as specified in section 5.2.

[0173] NOTE 7: The initiating UE may reuse the Layer 2 ID used by the initiating UE in a previous 5G ProSe direct link with the same peer UE.

[0174] And start timer T5080.

[0175] NOTE 8: The preset PC5 DRX configuration is used to transmit the ProSe Direct Link Setup Request message, as specified in 3GPP TS 38.300

[21] .

[0176] While timer T5080 is running, the UE shall not send a new ProSe Direct Link Setup Request message to the same target UE identified by the same application layer ID. If the Target User Information IE is not included in the ProSe Direct Link Setup Request message (i.e., 5G ProSe Direct Link Setup procedure for ProSe applications), the initiating UE shall process multiple ProSe Direct Link Setup Accept messages (if any) received from different target UEs for establishing multiple 5G ProSe direct links before the expiration of timer T5080.

[0177] NOTE 9: To ensure a successful 5G ProSe direct link establishment, T5080 should be set to a value greater than the sum of T5089 and T5092.

[0178] [3GPP TS 24.554 V17.4.0 titled "5G ProSe direct link establishment procedure towards UE" Figure 7 .2.2.2.1 Reproduced as Figure 6 ]

[0179] [3GPP TS 24.554 V17.4.0 titled "5G ProSe direct link establishment procedure for ProSe services" Figure 7 .2.2.2.2 Reproduced as Figure 7 ]

[0180] 7.2.2.3 5G ProSe Direct Link Establishment Procedure Accepted by Target UE

[0181] After receiving the ProSe direct link establishment request message, if the target UE accepts the request, the target UE will uniquely assign a PC5 link identifier and generate a 5G ProSe direct link context.

[0182] NOTE 1: The PC5 DRX configuration is preset for receiving the ProSe Direct Link Setup Request message as specified in 3GPP TS 38.300

[21] .

[0183] If the ProSe Direct Link Setup Request message is for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, the target UE shall verify the MIC field in the received ProSe Direct Link Setup Request with the DUIK (if present) and decrypt the encrypted MIC using DUCK or DUSK:

[0184] a) Relay service code; and

[0185] b) UP-PRUK ID or CP-PRUK ID (if received),

[0186] The associated encrypted bit mask is used for 5G ProSe UE to network relay discovery (see section 6.3.5.2 of 3GPP TS 33.503

[34] ) and verifies whether the relay service code matches the code sent by the target UE during the 5G ProSe UE to network relay discovery procedure.

[0187] NOTE 2: If the UE is configured to use neither DUCK nor DUSK, the relay service code and UP-PRUK ID or CP-PRUK ID are not encrypted.

[0188] If the 5G ProSe direct link establishment procedure is not used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, the target UE may initiate the 5G ProSe direct link authentication procedure specified in section 7.2.12 and shall initiate the 5G ProSe direct link security mode control procedure specified in section 7.2.10.

[0189] If the 5G ProSe direct link establishment procedure is used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE, the target UE shall proceed with:

[0190] a) authentication and key agreement procedures as specified in section 5.5.4 of 3GPP TS 24.501

[11] , provided that the security procedures on the control plane as specified in 3GPP TS 33.503

[34] are used; or

[0191] b) the key request procedure as specified in section 8.2.10.2.4, provided that the security procedures on the user plane as specified in 3GPP TS 33.503

[34] are used;

[0192] And the 5G ProSe direct link security mode control procedure will be initiated as specified in Section 7.2.10.

[0193] In the 5G ProSe direct link context, the target UE shall set the source Layer 2 ID and destination Layer 2 ID as specified in Section 7.2.12 and Section 7.2.10, and store the corresponding source Layer 2 ID for unicast communication and store the destination Layer 2 ID for unicast communication.

[0194] if:

[0195] a) The Target User Information IE is included in the ProSe Direct Link Setup Request message, and this IE contains the application layer ID of the target UE; or

[0196] b) the target user information IE is not included in the ProSe direct link setup request message, and the target UE is interested in the ProSe application identified by the ProSe identifier IE in the ProSe direct link setup request message;

[0197] Then the target UE will:

[0198] a) If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE:

[0199] 1) Based on K contained in the ProSe direct link establishment request message NRP ID, identify the existing K NRP ;or

[0200] 2) If K NRP The ID is not included in the ProSe direct link establishment request message, and the target UE does not have the ID for the K included in the ProSe direct link establishment request message. NRP ID's existing K NRP , or the target UE wishes to derive a new K NRP , then derive the new K NRP This may require execution of one or more 5G ProSe direct link authentication procedures as specified in Section 7.2.12.

[0201] b) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to a network relay UE and the security procedures on the control plane specified in 3GPP TS 33.503

[34] are used, then a new K is requested according to the security procedures on the user plane specified in 3GPP TS 33.503

[34] . NR_ProSe ;or

[0202] c) If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE and the security procedures on the user plane specified in 3GPP TS 33.503

[34] are used, then a new K is requested according to the security procedures on the user plane. NRP .

[0203] Note 3: How many times do you need to perform the 5G ProSe direct link authentication procedure to derive a new K NRP Depends on the authentication method used.

[0204] In the identification of existing K NRP Or export new K NRP Afterwards or after receiving a new K NRP or KNRP ProSe Afterwards, the target UE will initiate the 5G ProSe direct link security mode control procedure specified in Section 7.2.10.

[0205] After the 5G ProSe direct link security mode control procedure is successfully completed, in order to determine whether the ProSe direct link establishment request message is acceptable, in the case of IP communication, the target UE checks whether there is at least one common IP address configuration option supported by both the initiating UE and the target UE.

[0206] Before sending the ProSe Direct Link Setup Accept message to the 5G ProSe Remote UE, the target UE, acting as a relay UE for 5G ProSe Layer 3 UE to the network, initiates the UE-Requested PDU Session Establishment procedure specified in 3GPP TS 24.501

[11] in the following cases:

[0207] 1) The PDU session for relaying the service associated with the RSC has not been established; or

[0208] 2) A PDU session for relaying services associated with the RSC has been established, but the PDU session type is unstructured.

[0209] If the target UE accepts the 5G ProSe direct link establishment procedure, the target UE will generate a ProSe direct link establishment accept message.

[0210] a) will contain the source user information set to the application layer ID of the target UE received from upper layers;

[0211] b) If the target UE does not act as a relay UE for a 5G ProSe Layer 2 UE to the network, then the PQFI, the corresponding PC5 QoS parameters and optionally the ProSe identifier accepted by the target UE shall be included;

[0212] c) If the target UE does not act as a relay UE for the 5G ProSe Layer 2 UE to the network, then PC5 QoS rules may be included;

[0213] d) If IP communication is used and the target UE does not act as a relay UE for a 5G ProSe Layer 2 UE to the network, then the IP Address Configuration IE shall be included and set to one of the following values:

[0214] 1) "DHCPv4 server", if only IPv4 address allocation mechanism is supported by the target UE, i.e., acts as a DHCPv4 server;

[0215] 2) "IPv6 router", if the IPv6 address allocation mechanism is supported by the target UE, it acts as an IPv6 router;

[0216] 3) "DHCPv4 server and IPv6 router", if both IPv4 and IPv6 address allocation mechanisms are supported by the target UE; or

[0217] 4) “Address allocation not supported”, if both IPv4 and IPv6 address allocation mechanisms are not supported by the target UE and the target UE does not act as a relay UE for 5G ProSe Layer 3 UE to the network;

[0218] NOTE 4: If Ethernet or Unstructured Data Unit Type is used for communication, then the UE does not include the IP Address Configuration IE nor the Link-Local IPv6 Address IE.

[0219] e) if the IP Address Configuration IE is set to "Address Allocation Not Supported", the received ProSe Direct Link Security Mode Complete message contains a Link-Local IPv6 Address IE and the target UE is neither acting as a 5G ProSe Layer 2 UE to the network relay UE nor as a 5G ProSe Layer 3 relay UE, then a Link-Local IPv6 Address IE formed locally based on IETF RFC 4862

[25] shall be included; and

[0220] f) shall contain the configuration of UE PC5 unicast user plane security protection based on the agreed user plane security policy, as specified in 3GPP TS 33.503

[34] .

[0221] After generating the ProSe Direct Link Setup Accept message, the target UE passes this message together with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication to the lower layer for transmission, and starts the timer T5090 in the following cases:

[0222] a) at least one ProSe identifier used for the 5G ProSe direct link meets the privacy requirements specified in Section 5.2.4; or

[0223] b) T5090 is configured as specified in Section 5.2.5.

[0224] NOTE 5: Two UEs negotiate the PC5 DRX configuration in the AS layer, and the PC5 DRX parameter value is configured according to a pair of source / destination Layer 2 IDs in the AS layer, as specified in 3GPP TS 38.300

[21] .

[0225] After sending the ProSe Direct Link Setup Accept message, the target UE provides the following information together with the Layer 2 ID to the lower layers, which enables the lower layers to process the incoming PC5 signaling or traffic data:

[0226] a) A self-assigned PC5 link identifier for this 5G ProSe direct link;

[0227] b) PQFI and its corresponding PC5 QoS parameters (if applicable); and

[0228] c) Indication to activate PC5 unicast user plane security protection for 5G ProSe direct link (if applicable).

[0229] If the target UE accepts the 5G ProSe direct link establishment request and the 5G ProSe direct link is not established for 5G ProSe direct communication between the 5G ProSe remote UE and the relay UE from the 5G ProSe UE to the network, the target UE may perform the PC5 QoS flow establishment over the 5G ProSe direct link as specified in section 7.2.7. If the 5G ProSe direct link is established for 5G ProSe layer 3 remote UE and the relay UE from the 5G ProSe layer 3 UE to the network, the target UE may perform the PC5 QoS flow establishment over the 5G ProSe direct link as specified in section 8.2.6.

[0230] 7.2.2.4 5G ProSe Direct Link Establishment Procedure Completed by Initiating UE

[0231] If the Target User Information IE is included in the ProSe Direct Link Setup Request message, the initiating UE will stop timer T5080 after receiving the ProSe Direct Link Setup Accept message. If the Target User Information IE is not included in the ProSe Direct Link Setup Request message, the initiating UE may keep timer T5080 running and continue to process multiple response messages (i.e., ProSe Direct Link Setup Accept messages) from multiple target UEs.

[0232] For each of the received ProSe Direct Link Setup Accept messages, the initiating UE will uniquely assign a PC5 link identifier and generate a 5G ProSe direct link context for each of the 5G ProSe direct links. The initiating UE will then store the source Layer 2 ID and destination Layer 2 ID used in the transmission of this message provided by the lower layers in the 5G ProSe direct link context to complete the establishment of the 5G ProSe direct link with the target UE. From this point on, the initiating UE should use the established link for ProSe direct communication over PC5 and any additional PC5 signaling messages to the target UE.

[0233] After receiving the ProSe Direct Link Setup Accept message, the initiating UE provides the following information together with the Layer 2 ID to the lower layers, which enables the lower layers to process the incoming PC5 signaling or traffic data:

[0234] a) A self-assigned PC5 link identifier for this 5G ProSe direct link;

[0235] b) PQFI and its corresponding PC5 QoS parameters (if applicable); and

[0236] c) Indication to activate PC5 unicast user plane security protection for 5G ProSe direct link (if applicable).

[0237] In the following cases, the initiating UE shall start timer T5090:

[0238] a) at least one ProSe identifier used for the 5G ProSe direct link meets the privacy requirements specified in Section 5.2.4; or

[0239] b) T5090 is configured as specified in Section 5.2.5.

[0240] Additionally, the initiating UE may perform PC5 QoS flow establishment over the 5G ProSe direct link as specified in section 7.2.7.

[0241] After timer T5080 expires, if the ProSe Direct Link Setup Request message does not include the Target User Information IE and the initiating UE receives at least one ProSe Direct Link Setup Accept message, it is up to the UE implementation whether to consider the 5G ProSe Direct Link Setup procedure as completed or restart timer T5080.

[0242] […]

[0243] 7.2.3 5G ProSe Direct Link Modification Procedure

[0244] 7.2.3.1 Overview

[0245] The purpose of the 5G ProSe Direct Link Modification procedure is to modify the existing ProSe Direct Link to:

[0246] a) Adding new PC5 QoS flows to existing 5G ProSe direct links;

[0247] b) modifying an existing PC5 QoS flow to update the PC5 QoS parameters of the existing PC5 QoS flow;

[0248] c) modifying an existing PC5 QoS flow to associate a new ProSe application with the existing PC5 QoS flow;

[0249] d) modifying an existing PC5 QoS flow to remove the associated ProSe application from the existing PC5 QoS flow; or

[0250] e) Remove the existing PC5 QoS flow from the existing 5G ProSe direct link.

[0251] In this procedure, the UE that sends the ProSe direct link modification request message is called the "initiating UE", and the other UE is called the "target UE".

[0252] Note: The 5G ProSe direct link modification procedure is not applicable to the 5G ProSe layer 2 UE to network relay case.

[0253] 7.2.3.2 5G ProSe Direct Link Modification Procedure Initiated by the Initiating UE

[0254] Before initiating this procedure to add a new ProSe application to an existing 5G ProSe direct link, the initiating UE shall meet the following prerequisites:

[0255] a) There is a 5G ProSe direct link between the initiating UE and the target UE;

[0256] b) a pair of application layer ID and network layer protocol for this 5G ProSe direct link is the same as those required by the application layer in the initiating UE of this ProSe application; and

[0257] c) The security policy corresponding to the ProSe identifier is consistent with the security policy of the existing 5G ProSe direct link.

[0258] After receiving service data or request from upper layers, the initiating UE shall perform PC5 QoS flow matching as specified in Section 7.2.8. If there is no matching PC5 QoS flow, the initiating UE shall derive PC5 QoS parameters and assign a PQFI for the PC5 QoS flow established as specified in Section 7.2.7.

[0259] If the 5G ProSe direct link modification procedure is to add a new PC5 QoS flow to an existing 5G ProSe direct link, the initiating UE shall create a ProSe Direct Link Modification Request message. In this message, the initiating UE:

[0260] a) shall contain PQFI, corresponding PC5 QoS parameters and optionally ProSe identifier;

[0261] b) shall contain a link modification operation code set to “add a new PC5 QoS flow to an existing 5G ProSe direct link”; and

[0262] c) PC5 QoS rules may include packet filters for indicating PC5 QoS flows.

[0263] If the 5G ProSe direct link modification procedure is to modify the PC5 QoS parameters of an existing PC5 QoS flow in an existing 5G ProSe direct link, the initiating UE shall create a ProSe Direct Link Modification Request message. In this message, the initiating UE:

[0264] a) It will contain PQFI and corresponding PC5 QoS parameters, including ProSe identifier;

[0265] b) shall contain a Link Modify Operation Code set to "Modify PC5 QoS Parameters of an Existing PC5 QoS Flow"; and

[0266] c) PC5 QoS rules may include packet filters for indicating PC5 QoS flows.

[0267] If the 5G ProSe direct link modification procedure is to associate a new ProSe application with an existing PC5 QoS flow, the initiating UE shall create a ProSe direct link modification request message. In this message, the initiating UE:

[0268] a) It will contain PQFI and corresponding PC5 QoS parameters, including ProSe identifier;

[0269] b) shall contain a Link Modify Operation Code set to “Associate a new ProSe application with an existing PC5 QoS flow”; and

[0270] c) PC5 QoS rules may include packet filters for indicating PC5 QoS flows.

[0271] If the PC5 5G ProSe direct link modification procedure is to remove the associated ProSe application from an existing PC5 QoS flow, the initiating UE shall create a ProSe direct link modification request message. In this message, the initiating UE:

[0272] a) will contain the PQFI and corresponding PC5 QoS parameters, including the ProSe identifier; and

[0273] b) shall contain a Link Modification Operation Code set to “Remove ProSe Application from Existing PC5 QoS Flow”.

[0274] If the direct link modification procedure is to remove any PC5 QoS flow from an existing 5G ProSe direct link, the initiating UE shall create a ProSe Direct Link Modification Request message. In this message, the initiating UE:

[0275] a) will include the PQFI; and

[0276] b) shall contain a link modification operation code set to “Remove existing PC5 QoS flow from existing 5G ProSe direct link”.

[0277] After generating the ProSe Direct Link Modification Request message, the initiating UE shall pass this message together with the Layer 2 ID of the initiating UE for 5G ProSe direct communication and the Layer 2 ID of the target UE for 5G ProSe direct communication to lower layers for transmission, and start timer T5081. While timer T5081 is running, the UE shall not send a new ProSe Direct Link Modification Request message to the same target UE.

[0278] [3GPP TS 24.554 V17.4.0 titled “5G ProSe Direct Link Modification Procedure” Figure 7 .2.3.2.1 Reproduced as Figure 8 ]

[0279] 7.2.3.3 5G ProSe Direct Link Modification Procedure Accepted by Target UE

[0280] If the ProSe direct link modification request message is accepted, the target UE will respond with a ProSe direct link modification accept message.

[0281] If the ProSe Direct Link Modification Request message is to add a new ProSe application, add a new PC5 QoS flow, or modify any existing PC5 QoS flow in the 5G ProSe direct link, the target UE:

[0282] a) shall contain the PQFI, the corresponding PC5 QoS parameters and optionally the ProSe identifier accepted by the target UE; and

[0283] b) PC5 QoS rules that may include packet filters for indicating PC5 QoS flows;

[0284] In the ProSe Direct Link Modification Accept message.

[0285] If the ProSe direct link modification request message is to remove an existing ProSe application from the 5G ProSe direct link, the target UE will delete the ProSe identifier received in the ProSe direct link modification request message and the corresponding PQFI and PC5 QoS parameters from the attribute set associated with the 5G ProSe direct link.

[0286] If the ProSe direct link modification request message is to remove an existing PC5 QoS flow from the PC5 5G ProSe direct link, the target UE will delete the PQFI and corresponding PC5 QoS parameters from the attribute set associated with the 5G ProSe direct link.

[0287] If the ProSe direct link modification request message is to add a new ProSe application, add a new PC5 QoS flow, or modify any existing PC5 QoS flow in the 5G ProSe direct link, then after sending the ProSe direct link modification accept message, the target UE provides the added or modified PQFI and corresponding PC5 QoS parameters and PC5 link identifier to the lower layer.

[0288] If the ProSe direct link modification request message is to remove an existing ProSe application or to remove an existing PC5 QoS flow from the 5G ProSe direct link, then after sending the ProSe direct link modification accept message, the target UE provides the removed PQFI and PC5 link identifier to the lower layer.

[0289] If the 5G ProSe direct link is used for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe layer 3 UE-to-network relay UE, and if the initiating UE is a 5G ProSe remote UE, the target UE (as a 5G ProSe layer 3 UE-to-network relay UE) performs the QoS flow handling procedures as specified in sections 8.2.6.3.3 and 8.2.6.4.2.

[0290] If the target UE accepts the 5G ProSe direct link modification request, the target UE may perform PC5 QoS flow establishment on the 5G ProSe direct link as specified in section 7.2.7 and perform PC5 QoS flow matching on the 5G ProSe direct link as specified in section 7.2.8.

[0291] 7.2.3.4 5G ProSe Direct Link Modification Procedure by Initiating UE Completed

[0292] After receiving the ProSe Direct Link Modification Accept message, the initiating UE will stop timer T5081.

[0293] After receiving the ProSe Direct Link Modification Accept message, if the ProSe Direct Link Modification Request message is to add a new ProSe application, add a new PC5 QoS flow, or modify any existing PC5 QoS flow in the 5G ProSe direct link, the initiating UE provides the added or modified PQFI and corresponding PC5 QoS parameters and PC5 link identifier to the lower layer.

[0294] Upon receiving the ProSe direct link modification accept message, if the ProSe direct link modification request message is to remove an existing ProSe application or to remove an existing PC5 QoS flow from the 5G ProSe direct link, the initiating UE provides the removed PQFI and PC5 link identifier to the lower layer.

[0295] 7.2.3.5 5G ProSe Direct Link Modification Procedure Not Accepted by Target UE

[0296] If the 5G ProSe direct link modification request cannot be accepted, the target UE shall send a ProSe direct link modification reject message. The ProSe direct link modification reject message contains the PC5 signaling protocol cause IE, which is set to one of the following cause values:

[0297] #5 Lack of resources for 5G ProSe direct links;

[0298] #6 Required services not permitted;

[0299] #12Inconsistent security policies;

[0300] #16 Lack of local capabilities; or

[0301] #111 Unspecified protocol error.

[0302] If the target UE is not allowed to accept this request, for example because the ProSe application to be added is not allowed according to the operator policy or configuration parameters for ProSe communication over PC5 specified in section 5.2.4, then the target UE shall send a ProSe Direct Link Modify Reject message with PC5 signaling protocol cause value #6 "Required service not allowed".

[0303] If the 5G ProSe direct link modification fails due to congestion issues or other temporary lower layer issues resulting in resource constraints, the target UE shall send a ProSe Direct Link Modification Reject message with PC5 signaling protocol cause value #5 “Lack of resources for 5G ProSe Direct Link”.

[0304] If the Link Modify Action Code is set to "Associate new ProSe application with existing PC5 QoS flow" and the security policy corresponding to the ProSe identifier is not consistent with the security policy applied to the existing 5G ProSe direct link, the target UE shall send a ProSe Direct Link Modify Reject message with PC5 signaling protocol cause value #12 "Inconsistent security policy".

[0305] If the link modification operation requires adding a new PC5 QoS flow, but the target UE is unable to support the additional packet filters that will be required on the target UE's existing PDU sessions, the target UE shall send a ProSe Direct Link Modification Reject message with PC5 signaling protocol cause value #16 "Lack of local capability".

[0306] For other reasons leading to link establishment failure, the target UE will send a ProSe Direct Link Modify Reject message with PC5 signaling protocol cause value #111 "Unspecified protocol error".

[0307] Upon receiving the ProSe Direct Link Modify Reject message, the initiating UE shall stop timer T5081 and abort the 5G ProSe Direct Link Modify procedure. If the PC5 signaling protocol cause value in the ProSe Direct Link Modify Reject message is #11 "Required service not allowed" or #5 "Lack of resources for 5G ProSe direct link" or #12 "Inconsistent security policy", the initiating UE shall not attempt to initiate a 5G ProSe Direct Link Modify with the same target UE to add the same ProSe application, or at least to add or modify the same PC5 QoS flow, within the time period T.

[0308] NOTE: The length of the time period T is UE implementation specific and may be different if the UE receives PC5 signaling protocol cause value #11 "Desired service not allowed" or the UE receives PC5 signaling protocol cause value #5 "Lack of resources for 5G ProSe direct link" or the UE receives PC5 signaling protocol cause value #12 "Inconsistent security policy". The length of the time period T is not less than 30 minutes.

[0309] 7.2.3.6 Abnormal situations

[0310] 7.2.3.6.1 Abnormal situation at the initiating UE

[0311] The following anomalies can be identified:

[0312] a) If timer T5081 expires, the initiating UE will retransmit the ProSe Direct Link Modification Request message and restart timer T5081. After reaching the maximum number of allowed retransmissions, the initiating UE will abort the 5G ProSe Direct Link Modification procedure and may notify upper layers that the target UE is unreachable.

[0313] NOTE 1: The maximum number of allowed retransmissions is UE implementation specific.

[0314] NOTE 2: After reaching the maximum number of allowed retransmissions, whether the initiating UE releases this 5G ProSe direct link depends on its implementation.

[0315] b) For the same 5G ProSe direct link, if the initiating UE receives a ProSe direct link release request message after the initiating UE requested 5G ProSe direct link modification procedure, the initiating UE shall stop timer T5081, abort the 5G ProSe direct link modification procedure, and continue with the 5G ProSe direct link release procedure.

[0316] c) For the same 5G ProSe direct link, if the initiating UE receives a ProSe Direct Link Modification Request message during the 5G ProSe Direct Link Modification procedure, the initiating UE stops timer T5081 and aborts the 5G ProSe Direct Link Modification procedure. The following processing depends on the implementation. For example, if still necessary, the initiating UE waits for an implementation-dependent time to initiate a new 5G ProSe Direct Link Modification procedure.

[0317] NOTE 3: Implementation-dependent timer values ​​need to be set to avoid further conflicts (e.g., random timer values).

[0318] 7.2.3.6.2 Abnormal Situation at Target UE

[0319] The following anomalies can be identified:

[0320] a) For the same 5G ProSe direct link, if the target UE receives a ProSe direct link release request message during the 5G ProSe direct link modification procedure, the target UE shall stop all running timers of this 5G ProSe direct link, abort the 5G ProSe direct link modification procedure, and continue with the 5G ProSe direct link release procedure.

[0321] 7.2.4 5G ProSe Direct Link Identifier Update Procedure

[0322] 7.2.4.1 Overview

[0323] The 5G ProSe Direct Link Identifier Update procedure is used to update and exchange new identifiers (e.g., application layer ID, layer 2 ID, security information, and IP address / prefix) for a 5G ProSe direct link between two UEs before using the new identifiers. The UE that sends the ProSe Direct Link Identifier Update Request message is called the "initiating UE," and the other UE is called the "target UE."

[0324] 7.2.4.2 5G ProSe Direct Link Identifier Update Procedure Initiated by the Initiating UE

[0325] The initiating UE shall initiate the procedure if:

[0326] a) The initiating UE receives a request from upper layers to change the application layer ID, and there is an existing 5G ProSe direct link associated with this application layer ID; or

[0327] b) The privacy timer of the initiating UE's Layer 2 ID (see Section 5.2.4) expires for the existing 5G ProSe direct link.

[0328] If the 5G ProSe direct link identifier update procedure is triggered by a change in the application layer ID of the initiating UE, the initiating UE shall create a ProSe direct link identifier update request message. In this message, the initiating UE:

[0329] a) will contain the new application layer ID of the originating UE received from upper layers;

[0330] b) will contain the new layer 2 ID assigned by the originating UE itself;

[0331] c) will include K NRP-sess The new MSB of the ID; and

[0332] d) If IP communication is used and the 5G ProSe direct link is not used for 5G ProSe direct communication between a 5G ProSe Layer 2 remote UE and a 5G ProSe Layer 2 UE to a relay UE of the network, a new IP address / prefix shall be included.

[0333] If the 5G ProSe Direct Link Identifier Update procedure is triggered by the expiration of the privacy timer T5090 of the initiating UE, as specified in Sections 5.2.4 and 5.2.5, the initiating UE shall create a ProSe Direct Link Identifier Update Request message. In this message, the initiating UE:

[0334] a) will contain a new layer 2 ID assigned by the originating UE itself;

[0335] b) will include K NRP-sessThe new MSB of the ID;

[0336] c) If received from upper layers, it may contain the new application layer ID of the originating UE; and

[0337] d) If IP communication is used and the IP communication changes, and the 5G ProSe direct link is not used for 5G ProSe direct communication between the 5G ProSe Layer 2 remote UE and the 5G ProSe Layer 2 UE to the network relay UE, then a new IP address / prefix shall be included.

[0338] After generating the ProSe Direct Link Identifier Update Request message, the initiating UE passes this message together with the old Layer 2 ID of the initiating UE for 5G ProSe direct communication and the Layer 2 ID of the target UE for 5G ProSe direct communication to the lower layer for transmission, and starts timer T5082. While timer T5082 is running, the UE should not send a new ProSe Direct Link Identifier Update Request message to the same target UE.

[0339] [3GPP TS 24.554 V17.4.0 titled “5G ProSe direct link identifier update procedure” Figure 7 .2.4.2.1 Reproduced as Figure 9 ]

[0340] 7.2.4.3 5G ProSe Direct Link Identifier Update Procedure Accepted by Target UE

[0341] After receiving the ProSe Direct Link Identifier Update Request message, if the target UE determines:

[0342] a) the 5G ProSe direct link associated with this request message remains valid; and

[0343] b) timer T5083 for the 5G ProSe direct link identified by this request message is not running,

[0344] Subsequently, the target UE accepts this request and responds with a ProSe Direct Link Identifier Update Accept message.

[0345] The target UE shall create a ProSe Direct Link Identifier Update Accept message. In this message, the target UE:

[0346] a) will contain the new layer 2 ID assigned by the target UE itself;

[0347] b) will include K NRP-sess New LSB of ID;

[0348] c) Include the K of the initiating UE NRP-sess The new MSB of the ID;

[0349] d) will contain the new layer 2 ID of the originating UE;

[0350] e) If received from upper layers, it shall contain the new application layer ID of the target UE;

[0351] f) If received from an originating UE and using IP communications, the new IP address / prefix of the originating UE will be included;

[0352] g) if received from an originating UE, it will contain the new application layer ID of the originating UE; and

[0353] h) If IP communication is used and the IP communication changes, and the 5G ProSe direct link is not used for 5G ProSe direct communication between a 5G ProSe Layer 2 remote UE and a 5G ProSe Layer 2 UE to network relay UE, then the new IP address / prefix of the target UE shall be included.

[0354] After generating the ProSe Direct Link Identifier Update Accept message, the target UE passes this message together with the old Layer 2 ID of the initiating UE for 5G ProSe direct communication and the old Layer 2 ID of the target UE for 5G ProSe direct communication to lower layers for transmission, and starts timer T5083. While timer T5083 is running, the UE should not send a new ProSe Direct Link Identifier Update Accept message to the same initiating UE.

[0355] Before the target UE receives traffic using the new Layer 2 ID, the target UE will continue to receive traffic with the old Layer 2 ID (ie, the old Layer 2 ID of the originating UE and the old Layer 2 ID of the target UE) from the originating UE.

[0356] Before the target UE receives the ProSe Direct Link Identifier Update Ack message from the initiating UE, the target UE will keep using the old Layer 2 ID to send traffic to the initiating UE (i.e., the old Layer 2 ID of the initiating UE for 5G ProSe direct communication and the old Layer 2 ID of the target UE for 5G ProSe direct communication).

[0357] 7.2.4.4 5G ProSe Direct Link Identifier Update Procedure Confirmed by Initiating UE

[0358] Upon receiving the ProSe Direct Link Identifier Update Accept message, the initiating UE will stop timer T5082 and respond with a ProSe Direct Link Identifier Update Ack message. In this message, the initiating UE:

[0359] a) will contain the new layer 2 ID of the target UE;

[0360] b) Include the K of the target UE NRP-sess New LSB of ID;

[0361] c) will contain the new application layer ID of the target UE (if received); and

[0362] d) Will contain the new IP address / prefix of the target UE (if received).

[0363] After generating the ProSe direct link identifier update Ack message, the initiating UE passes this message together with the old layer 2 ID of the initiating UE for 5G ProSe direct communication and the old layer 2 ID of the target UE for 5G ProSe direct communication to the lower layer for transmission, and stops timer T5090 (if running) and starts timer T5090, which is configured when at least one of the ProSe identifiers used for the 5G ProSe direct link meets the privacy requirements specified in Section 5.2.4 or meets the privacy requirements specified in Section 5.2.5.

[0364] After sending the ProSe direct link identifier update Ack message, the initiating UE will update the associated 5G ProSe direct link context with the new identifier and pass the new layer 2 ID (i.e., the new layer 2 ID of the initiating UE for 5G ProSe direct communication and the new layer 2 ID of the target UE for 5G ProSe direct communication) together with the PC5 link identifier to the lower layer. The initiating UE will then use the new layer 2 ID (i.e., the new layer 2 ID of the initiating UE for 5G ProSe direct communication and the new layer 2 ID of the target UE for 5G ProSe direct communication) to transmit PC5 signaling messages and PC5 user plane data.

[0365] The initiating UE will continue to receive traffic with the old Layer 2 ID (i.e., the old Layer 2 ID of the initiating UE for 5G ProSe direct communication and the old Layer 2 ID of the target UE for 5G ProSe direct communication) from the target UE until it receives traffic with the new Layer 2 ID (i.e., the new Layer 2 ID of the initiating UE and the new Layer 2 ID of the target UE) from the target UE.

[0366] 7.2.4.5 Completion of 5G ProSe Direct Link Identifier Update Procedure by Target UE

[0367] Upon receiving the ProSe Direct Link Identifier Update Ack message, the target UE will update the associated 5G ProSe direct link context with the new identifier, pass the new Layer 2 ID (i.e., the new Layer 2 ID of the initiating UE and the new Layer 2 ID of the target UE) down to the lower layers, stop timer T5083 and timer T5090 (if running), and start timer T5090, which is configured when at least one of the ProSe identifiers used for the 5G ProSe direct link meets the privacy requirements specified in Section 5.2.4 or meets the privacy requirements specified in Section 5.2.5. The target UE will then transmit PC5 signaling messages and PC5 user plane data using the new Layer 2 ID (i.e., the new Layer 2 ID of the initiating UE for 5G ProSe direct communication and the new Layer 2 ID of the target UE for 5G ProSe direct communication).

[0368] 7.2.4.6 5G ProSe Direct Link Identifier Update Procedure Not Accepted by Target UE

[0369] If the ProSe Direct Link Identifier Update Request message cannot be accepted, the target UE shall send a ProSe Direct Link Identifier Update Reject message. The ProSe Direct Link Identifier Update Reject message contains the PC5 signaling protocol cause IE, which is set to one of the following cause values:

[0370] #3 A conflict of Layer 2 IDs for 5G ProSe direct communication is detected; or

[0371] #111 Unspecified protocol error.

[0372] For a ProSe Direct Link Identifier Update Request message received from a Layer 2 ID (for 5G ProSe direct communication), if the target UE already has an existing link using this Layer 2 ID or is currently processing a ProSe Direct Link Identifier Update Request message from the same Layer 2 ID but whose user information is different from the User Information IE contained in this new incoming message, then the target UE shall send a ProSe Direct Link Identifier Update Reject message with PC5 Signaling Protocol Cause Value #3 "Conflict detected for Layer 2 ID for 5G ProSe direct communication".

[0373] NOTE: After receiving the ProSe direct link identifier update reject message, whether the initiating UE initiates a 5G ProSe direct link release procedure or another 5G ProSe direct link identifier update procedure with a new Layer 2 ID depends on the UE implementation.

[0374] For other reasons that lead to link identifier update failure, the target UE will send a ProSe direct link identifier update reject message with PC5 signaling protocol cause value #111 "Unspecified protocol error".

[0375] After receiving the ProSe direct link identifier update reject message, the initiating UE will stop timer T5082 and abort the 5G ProSe direct link identifier update procedure.

[0376] 7.2.4.7 Abnormal Situations

[0377] 7.2.4.7.1 Abnormal situation at the initiating UE

[0378] The following anomalies can be identified:

[0379] a) If timer T5082 expires, the initiating UE will retransmit the ProSe Direct Link Identifier Update Request message and restart timer T5082. After reaching the maximum number of allowed retransmissions, the initiating UE will abort the 5G ProSe Direct Link Identifier Update procedure and may notify upper layers that the target UE is unreachable.

[0380] NOTE 1: The maximum number of allowed retransmissions is UE implementation specific.

[0381] NOTE 2: After reaching the maximum number of allowed retransmissions, whether the initiating UE releases this 5G ProSe direct link depends on its implementation.

[0382] b) For the same 5G ProSe direct link, if the initiating UE receives a ProSe Direct Link Identifier Update Request message during the 5G ProSe Direct Link Identifier Update procedure, the initiating UE stops timer T5082 and aborts the 5G ProSe Direct Link Identifier Update procedure. The following processing depends on the implementation. For example, if still necessary, the initiating UE waits for an implementation-dependent time to initiate a new 5G ProSe Direct Link Identifier Update procedure.

[0383] NOTE 3: Implementation-dependent timer values ​​need to be set to avoid further conflicts (e.g., random timer values).

[0384] c) For the same 5G ProSe direct link, if the initiating UE receives a ProSe direct link key update request message after initiating the 5G ProSe direct link identifier update procedure, the initiating UE shall ignore the ProSe direct link key update request message and continue with the 5G ProSe direct link identifier update procedure.

[0385] d) For the same 5G ProSe direct link, if the initiating UE receives a ProSe direct link release request message after initiating the 5G ProSe direct link identifier update procedure, the initiating UE shall stop timer T5082, abort the 5G ProSe direct link identifier update procedure, and continue with the 5G ProSe direct link release procedure.

[0386] e) After sending the ProSe Direct Link Identifier Update ACK message to the target UE, if another ProSe Direct Link Identifier Update Accept message is received from the target UE before receiving traffic from the target UE with a new Layer 2 ID, the initiating UE shall retransmit the ProSe Direct Link Identifier Update ACK message together with the old Layer 2 ID of the initiating UE and the old Layer 2 ID of the target UE.

[0387] NOTE 4: If such traffic has already been sent before the initiating UE retransmits the ProSe Direct Link Identifier Update ACK message, the handling of traffic delivery failure for the new Layer 2 ID is implementation dependent.

[0388] f) After sending the ProSe Direct Link Identifier Update ACK message to the target UE, if the initiating UE keeps receiving traffic from the target UE with the old Layer 2 ID and does not receive traffic from the target UE with the new Layer 2 ID during an implementation-specific time, which is greater than the value of timer T5083, the initiating UE shall abort the 5G ProSe direct link identifier update procedure and may release the 5G ProSe direct link.

[0389] 7.2.4.7.2 Abnormal Situation at Target UE

[0390] The following anomalies can be identified:

[0391] a) If timer T5083 expires, the target UE will retransmit the ProSe Direct Link Identifier Update Accept message and restart timer T5083. After reaching the maximum number of allowed retransmissions, the target UE will abort the 5G ProSe Direct Link Identifier Update procedure and may notify the upper layer that the initiating UE is unreachable.

[0392] NOTE 1: The maximum number of allowed retransmissions is UE implementation specific.

[0393] NOTE 2: After the maximum number of allowed retransmissions is reached, whether the target UE releases the 5G ProSe direct link depends on its implementation.

[0394] b) If the ProSe Direct Link Identifier Update Request is received while timer T5083 is running, the target UE shall stop timer T5083 and abort the ongoing 5G ProSe Direct Link Identifier Update procedure. The target UE shall process the new ProSe Direct Link Identifier Update Request as specified in section 7.2.4.3.

[0395] c) For the same 5G ProSe direct link, if the target UE receives a ProSe direct link release request message during the 5G ProSe direct link identifier update procedure, the target UE shall stop timer T5083, abort the 5G ProSe direct link identifier update procedure, and continue with the 5G ProSe direct link release procedure.

[0396] […]

[0397] 7.2.10 5G ProSe Direct Link Security Mode Control Procedure

[0398] 7.2.10.1 Overview

[0399] The 5G ProSe Direct Link Security Mode Control procedure is used to establish security between two UEs during the 5G ProSe Direct Link Establishment Procedure or the 5G ProSe Direct Link Key Update Procedure. If UE PC5 signaling integrity protection is not activated, security is not established. After successful completion of the 5G ProSe Direct Link Security Mode Control procedure, the selected security algorithms and their associated non-null keys are used to integrity protect and encrypt all PC5 signaling messages exchanged over this 5G ProSe direct link between the UEs, and the security context can be used to protect all PC5 user plane data exchanged over this 5G ProSe direct link between the UEs. The UE that sends the ProSe Direct Link Security Mode Command message is referred to as the "initiating UE," and the other UE is referred to as the "target UE."

[0400] 7.2.10.2 5G ProSe Direct Link Security Mode Control Procedure Initiated by UE

[0401] The initiating UE shall meet the following prerequisites before initiating the 5G ProSe direct link security mode control procedure:

[0402] a) The target UE has initiated the 5G ProSe direct link establishment procedure towards the initiating UE by sending a ProSe Direct Link Setup Request message along with the following:

[0403] 1) ProSe Direct Link Establishment Request Message:

[0404] i) contains the target user information IE, which contains the application layer ID of the originating UE; or

[0405] ii) the target user information IE is not included and the initiating UE is interested in the ProSe service identified by the ProSe identifier in the ProSe direct link establishment request message; and

[0406] 2) Initiating UE:

[0407] i) If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then the direct communication is based on the K contained in the ProSe Direct Link Setup Request message. NRP ID identifies the existing K NRP , or export a new K NRP ;

[0408] ii) If direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE, where user plane security procedures are used, then the new K is received according to the user plane security procedures specified in 3GPP TS 33.503

[34] . NRP ;

[0409] iii) If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE, where the control plane security procedures are used, then the new K is received according to the control plane security procedures specified in 3GPP TS 33.503

[34] . NR_ProSe ;or

[0410] iv) has decided not to activate security protection based on its UE 5G ProSe direct signalling security policy and the target UE’s 5G ProSe direct signalling security policy; or

[0411] b) The target UE has initiated the 5G ProSe direct link key update procedure towards the initiating UE by sending a ProSe direct link key update request message along with the following:

[0412] 1) If the target UE has included a re-authentication indication in the ProSe direct link key update request message, then the initiating UE has derived a new K NRP .

[0413] when:

[0414] a) Direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE. If the new K NRP has been derived by the initiating UE; or

[0415] b) Direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE. If the initiating UE receives a new K according to the security procedures on the user plane or the security procedures on the control plane, respectively NRP or K NR_ProSe , as specified in 3GPP TS 33.503

[34] ;

[0416] The initiating UE will generate K NRP The 2 MSBs of ID are used to ensure that the resulting K NRP The ID is unique within the initiating UE.

[0417] NOTE 1: If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then K NRP ID remains corresponding to K NRP If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then K NRP ID remains corresponding to K NRP (if security procedures on the user plane are used) or K NR_ProSe The ID of the control plane security program (if using).

[0418] The initiating UE shall select a security algorithm based on its UE 5G ProSe direct signaling security policy and the target UE's 5G ProSe direct signaling security policy. If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, then if the 5G ProSe direct signaling integrity protection policy of either the initiating UE or the target UE is set to "signaling integrity protection required", then the initiating UE shall not select the null integrity protection algorithm. If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, then the initiating UE:

[0419] a) If the integrity protection algorithm currently used for the 5G ProSe direct link is different from the null integrity protection algorithm, the null integrity protection algorithm shall not be selected;

[0420] b) If the encryption protection algorithm currently used for the 5G ProSe direct link is different from the null encryption protection algorithm, the null encryption protection algorithm should not be selected;

[0421] c) if the integrity protection algorithm currently in use is the null integrity protection algorithm, then the null integrity protection algorithm will be selected; and

[0422] d) If the encryption protection algorithm currently in use is the null encryption protection algorithm, then the null encryption protection algorithm should be selected.

[0423] Next, the initiating UE will:

[0424] a) If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE:

[0425] 1) Generate a 128-bit Nonce_2 value;

[0426] 2) Nonce_1 and K received in the ProSe direct link establishment request message NRP and Nonce_2 to derive K NRP-sess , as specified in 3GPP TS 33.536

[37] ; and

[0427] 3) From K NRP-sess and the selected security algorithm to derive the NR PC5 encryption key NRPEK and the NR PC5 integrity key NRPIK as specified in 3GPP TS 33.536

[37] ;

[0428] b) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE and the security procedures on the control plane specified in 3GPP TS 33.503

[34] are used:

[0429] 1) From the K received in the ProSe Direct Link Setup Request message NR_ProSe , Nonce_2 and Nonce_1 derive K relay-sess , as specified in 3GPP TS 33.503

[34] ; and

[0430] 2) From K relay-sess and the selected security algorithm to derive the NR PC5 encryption key K relay-enc and NR PC5 integrity key K relay-int , as specified in 3GPP TS 33.503

[34] ; or

[0431] c) If the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE and the security procedures on the user plane specified in 3GPP TS 33.503

[34] are used:

[0432] 1) K received from the ProSe Direct Link Setup Request message specified in 3GPP TS 33.503

[34] NRP , K NRPFreshness parameter 2 and K NRP Freshness parameter 1 derives K NRP-sess ;as well as

[0433] 2) From K NRP-sess and the selected security algorithm to derive the NR PC5 encryption key NRPEK and the NR PC5 integrity key NRPIK as specified in 3GPP TS 33.503

[34] ; and

[0434] d) Create a ProSe Direct Link Security Mode Command message. In this message, the initiating UE:

[0435] 1) The key establishment information container IE will be included, provided that the 5G ProSe direct link is not used for direct communication between the 5G ProSe remote UE and the 5G ProSe UE to the network relay UE, and the new K has been derived at the initiating UE NRP , and is used to generate K NRP The authentication method requires sending information to complete the 5G ProSe direct link authentication procedure;

[0436] NOTE 2: The key establishment information container is provided by the upper layer.

[0437] 2) will include K NRP MSB of ID IE, provided that the new K has been derived NRP Or the initiating UE has received a new K NRP or K NR_ProSe ;

[0438] 3) Will contain Nonce_2IE, which:

[0439] i) When the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, it is set to a 128-bit temporary value generated by the initiating UE;

[0440] ii) When direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to network relay UE and the security procedures on the user plane specified in 3GPP TS 33.503

[34] are used, set to the K received by the initiating UE NRP Freshness parameter 2 value; or

[0441] iii) when direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to a network relay UE and the security procedures on the control plane specified in 3GPP TS 33.503

[34] are used, set to the Nonce_2 value received by the initiating UE;

[0442] If the selected integrity protection algorithm is not the null integrity protection algorithm, then for the purpose of session key establishment over this 5G ProSe direct link;

[0443] 4) will include the selected security algorithm;

[0444] 5) including the UE security capabilities received from the target UE in the ProSe direct link setup request message or the ProSe direct link key update request message;

[0445] 6) Include the UE 5G ProSe direct signaling security policy received from the target UE in the ProSe direct link establishment request message;

[0446] 7) If the selected integrity protection algorithm is not the null integrity protection algorithm, it shall include the K selected by the initiating UE as specified in 3GPP TS 33.536

[37] NRP-sess LSB of ID;

[0447] NOTE 3: If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a relay UE in the network, then K NRP-sess ID remains corresponding to K NRP-sess If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then K NRP-sess ID remains corresponding to K NRP-sess (if security procedures on the user plane are used) or K relay-sess The ID of the control plane security program (if using).

[0448] 8) When direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE, the GPI shall be included if received from the 5G PKMF according to the security procedures on the user plane specified in 3GPP TS 33.503

[34] ; and

[0449] 9) When direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to network Relay UE, an EAP message shall be included if received from the network according to the security procedures on the control plane specified in 3GPP TS 33.503

[34] .

[0450] If the security protection of this 5G ProSe direct link is activated by using a non-null integrity protection algorithm or a non-null ciphering protection algorithm, the initiating UE will receive the K received from the ProSe Direct Link Setup Request message or the ProSe Direct Link Key Update Request message. NRP-sessThe MSB of the ID and the K contained in the ProSe direct link security mode command message NRP-sess The LSB of ID forms K NRP-sess ID. The initiating UE will use K NRP-sess The ID identifies the new security context.

[0451] The initiating UE shall set the source Layer 2 ID and the destination Layer 2 ID as follows:

[0452] 1) If the originating UE acts as a relay UE for a 5G ProSe layer 3 UE to the network and uses an EAP-AKA' based authentication method as specified in section 6.3.3.3 of 3GPP TS 33.503

[34] ,

[0453] Set the source layer 2 ID to the source layer 2 ID used for the ProSe AA message transmission request message, and set the destination layer 2 ID to the destination layer 2 ID used for the ProSe AA message transmission request message;

[0454] 2) If the initiating UE does not act as a relay UE from the 5G ProSe UE to the network and the 5G ProSe direct link authentication procedure has been initiated:

[0455] Set the source layer 2 ID to the source layer 2 ID for the ProSe direct link authentication request message, and set the destination layer 2 ID to the destination layer 2 ID for the ProSe direct link authentication request message;

[0456] 3) Otherwise, assign a source Layer 2 ID by itself and set the destination Layer 2 ID to the source Layer 2 ID in the ProSe Direct Link Setup Request message.

[0457] NOTE 4: The UE implementation ensures that any value of the self-assigned source Layer-2 ID is different from any other self-assigned source Layer-2 ID used for 5G ProSe direct discovery as specified in sections 6.2.14, 6.2.15 and 8.2.1, and different from any other provided destination Layer-2 ID as specified in section 5.2.

[0458] 5: The target UE may reuse the Layer 2 ID that the target UE used in the previous 5G ProSe direct link with the same peer UE.

[0459] After generating the ProSe Direct Link Security Mode Command message, the initiating UE sends this message along with the source layer 2 ID and destination layer 2 ID, NRPIK (or K relay-int , if applicable), NRPEK (if applicable) (or K relay-enc , if applicable), K NRP-sessThe UE shall pass the 5G ProSe Direct Link Security Mode Command message to the target UE along with the ID, the selected security algorithm specified in TS 33.536

[37] , and an activation indication of 5G ProSe direct signaling security protection for the 5G ProSe direct link with the new security context (if applicable) to lower layers for transmission, and start timer T5089. While timer T5089 is running, the initiating UE shall not send a new ProSe Direct Link Security Mode Command message to the same target UE.

[0460] NOTE 6: The ProSe Direct Link Security Mode Command message is integrity protected (and not encrypted) at the lower layer by using a new security context.

[0461] If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, the initiating UE provides an activation indication of 5G ProSe direct user plane security protection for the 5G ProSe direct link with a new security context (if applicable) to the lower layers together with the layer 2 ID of the initiating UE for 5G ProSe direct communication and the layer 2 ID of the target UE for 5G ProSe direct communication.

[0462] [3GPP TS 24.554 V17.4.0 titled “5G ProSe direct link security mode control procedures” Figure 7 .2.10.2.1 Reproduced as Figure 10 ]

[0463] 7.2.10.3 5G ProSe Direct Link Security Mode Control Procedure Accepted by Target UE

[0464] Upon receiving the ProSe Direct Link Security Mode Command message, if the newly assigned Layer 2 ID of the initiating UE is included and if the 5G ProSe Direct Link authentication procedure has not yet been performed, the target UE will replace the Layer 2 ID of the original initiating UE with the newly assigned Layer 2 ID of the initiating UE for 5G ProSe direct communication. The target UE will check the Selected Security Algorithm IE contained in the ProSe Direct Link Security Mode Command message. If "Null Integrity Algorithm" is included in the Selected Security Algorithm IE, security protection is not provided for this 5G ProSe direct link, and signaling messages are transmitted unprotected. If "Null Ciphering Algorithm" and an integrity algorithm other than "Null Integrity Algorithm" are included in the Selected Algorithm IE, security protection is not provided for this 5G ProSe direct link, and signaling messages are transmitted unprotected. If the 5G ProSe direct signaling integrity protection policy of the target UE is set to "Signaling Integrity Protection Required", the target UE will check that the Selected Security Algorithm IE in the ProSe Direct Link Security Mode Command message does not include a Null Integrity Protection Algorithm. If the Selected Integrity Protection Algorithm is not a Null Integrity Protection Algorithm, the target UE will:

[0465] a) If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE:

[0466] 1) From the K received in the ProSe Direct Link Security Mode Command message NRP , Nonce_1 and Nonce_2 derive K NRP-sess , as specified in 3GPP TS 33.536

[37] ;

[0467] 2) From K NRP-sess and the selected integrity algorithm to derive the NRPIK, as specified in 3GPP TS 33.536

[37] ; and

[0468] 3) If K is derived NRP-sess And the selected encryption protection algorithm is not the null encryption protection algorithm, then the target UE will NRP-sess and the selected encryption algorithm to derive the NRPEK, as specified in 3GPP TS 33.536

[37] ; or

[0469] b) If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE:

[0470] 1) If the control plane security procedures specified in 3GPP TS 33.503

[34] are used, K is derived according to the control plane security procedures. relay-sess , and from Krelay-sess and the selected integrity algorithm to derive K relay-int , as specified in 3GPP TS 33.503

[34] . If K relay-sess If the encryption protection algorithm is not the null encryption protection algorithm, the target UE will select K relay-sess and the selected encryption algorithm to derive K relay-enc , as specified in 3GPP TS 33.503

[34] ; or

[0471] 2) If the user plane security procedures specified in 3GPP TS 33.503

[34] are used, K is derived according to the user plane security procedures. NRP-sess , and from K NRP-sess and the selected integrity algorithm to derive the NRPIK, as specified in 3GPP TS 33.503

[34] . If K NRP-sess If the encryption protection algorithm is not the null encryption protection algorithm, the target UE will select K NRP-sess and the selected encryption algorithm to derive the NRPEK, as specified in 3GPP TS 33.503

[34] .

[0472] The target UE shall determine whether the ProSe Direct Link Security Mode Command message is acceptable by:

[0473] a) If the 5G ProSe direct signaling integrity protection policy of the target UE is set to "signaling integrity protection required", check that the security algorithm selected in the ProSe Direct Link Security Mode Command message does not include a null integrity protection algorithm;

[0474] b) If the selected integrity protection algorithm is not the null integrity protection algorithm, the lower layer is required to use NRPIK (or K relay-int , if applicable) and the selected integrity protection algorithm to check the integrity of the ProSe direct link security mode command message;

[0475] c) checking that the received UE security capabilities have not changed compared to the values ​​sent by the target UE to the initiating UE in the ProSe Direct Link Setup Request message or the ProSe Direct Link Key Update Request message;

[0476] d) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, then

[0477] 1) checking that the received UE 5G ProSe Direct Signalling security policy has not changed compared to the value sent by the target UE to the initiating UE in the ProSe Direct Link Setup Request message; and

[0478] 2) Check the K contained in the ProSe direct link security mode command message NRP-sess LSBs of the ID are not set to the same values ​​as those received from another UE in response to the target UE's ProSe direct link establishment request message; and

[0479] e) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure and the integrity protection algorithm currently used for the 5G ProSe direct link is different from the null integrity protection algorithm, then check that the security algorithm selected in the ProSe direct link security mode command message does not include the null integrity protection algorithm.

[0480] If the target UE does not include K in the ProSe direct link establishment request message NRP If the target UE has a Re-Authentication ID, the target UE includes a Re-Authentication Indication in the ProSe Direct Link Key Update Request message, or the initiating UE chooses to derive:

[0481] a) New K NRP , if the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a relay UE in the network, then the target UE will derive K NRP , as specified in 3GPP TS 33.536

[37] ;

[0482] b) New K NRP , if the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE and the security procedures on the user plane specified in 3GPP TS 33.503

[34] are used, then the target UE shall derive K NRP , as specified in 3GPP TS 33.536

[37] ; or

[0483] c) New K NR_ProSe , if the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE and the security procedures on the control plane specified in 3GPP TS 33.503

[34] are used, then the target UE shall derive K NR_ProSe , as specified in 3GPP TS 33.536

[37] ; and

[0484] The target UE should select K NRP The 2 LSBs of ID are used to ensure that the resulting K NRP The ID will be unique in the target UE. The target UE shall NRP MSB of ID and its selected K NRP The 2 LSBs of ID form KNRP ID, and should store NRP / K NR_ProSe The complete K NRP ID.

[0485] NOTE 1: If the direct communication is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then K NRP ID remains corresponding to K NRP If the direct communication is between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then K NRP ID remains corresponding to K NRP (if security procedures on the user plane are used) or K NR_ProSe The ID of the control plane security program (if using).

[0486] If GPI is included in the ProSe Direct Link Security Mode Command message and the direct communication is between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE, then according to the security procedures on the user plane specified in 3GPP TS 33.503

[34] , the target UE shall derive UP-PRUK from GPI and obtain UP-PRUK ID, and use UP-PRUK to derive K NRP .

[0487] If the target UE accepts the ProSe Direct Link Security Mode Command message, the target UE shall generate a ProSe Direct Link Security Mode Complete message. In this message, the target UE:

[0488] a) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure:

[0489] 1) If the 5G ProSe direct link is not used for 5G ProSe direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, then the PQFI and corresponding PC5 QoS parameters shall be included; or

[0490] 2) If the 5G ProSe direct link is used for 5G ProSe direct communication between a 5G ProSe Layer 3 remote UE and a 5G ProSe Layer 3 UE to a network relay UE, then the PQFI and corresponding PC5 QoS parameters may be included;

[0491] NOTE 2: If the 5G ProSe direct link is used for 5G ProSe direct communication between a 5G ProSe Layer 2 remote UE and a 5G ProSe Layer 2 UE to a network relay UE, the PQFI and corresponding PC5 QoS parameters are not included.

[0492] b) If IP communication is used and the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, the IP address configuration IE set to one of the following values ​​shall be included:

[0493] 1) "IPv6 router", if the IPv6 address allocation mechanism is supported by the target UE, i.e., act as an IPv6 router; or

[0494] 2) “Address allocation not supported”, if the IPv6 address allocation mechanism is not supported by the target UE;

[0495] c) If IP communication is used, the IP Address Configuration IE is set to “Address Allocation Not Supported” and the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Establishment procedure, then the Link-Local IPv6 Address IE formed locally based on IETF RFC4862

[25] shall be included;

[0496] d) If the new K is derived NRP Or receive a new K NRP or K NR_ProSe , then it will contain K NRP The 2 LSBs of the ID; and

[0497] e) If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link establishment procedure, its UE 5G ProSe direct user plane security policy for this 5G ProSe direct link shall be included. In the case where different ProSe services are mapped to different 5G ProSe direct user plane security policies, when more than one ProSe identifier is included in the ProSe direct link setup request message, each of the user plane security policies of those ProSe services shall be compatible, for example, "user plane integrity protection not required" and "user plane integrity protection required" are not compatible.

[0498] If the selected integrity protection algorithm is not the Null Integrity Protection Algorithm, the target UE will use the K NRP-sess The MSB of the ID and the K received in the ProSe Direct Link Security Mode Command message NRP-sess The LSB of ID forms KNRP-sess ID. The target UE will use K NRP-sess The ID identifies the new security context.

[0499] After generating the ProSe Direct Link Security Mode Complete message, the target UE sends this message along with the target UE's layer 2 ID for 5G ProSe direct communication and the initiating UE's layer 2 ID, NRPIK (or K relay-int , if applicable), NRPEK (if applicable) (or K relay-enc , if applicable), K NRP-sess The ID, the selected security algorithm specified in 3GPP TS 33.536

[37] , and an activation indication of 5G ProSe direct signaling security protection for the 5G ProSe direct link with the new security context (if applicable) are passed to lower layers for transmission.

[0500] NOTE 3: The ProSe Direct Link Security Mode Complete message and other 5G ProSe direct signaling messages are integrity protected and encrypted (if applicable) using the new security context at the lower layer.

[0501] If the 5G ProSe direct link security mode control procedure is triggered during the 5G ProSe direct link key update procedure, the target UE provides an activation indication of 5G ProSe direct user plane security protection for the 5G ProSe direct link with a new security context (if applicable) together with the layer 2 ID of the initiating UE for 5G ProSe direct communication and the layer 2 ID of the target UE for 5G ProSe direct communication to the lower layers.

[0502] 7.2.10.4 Completing the 5G ProSe Direct Link Security Mode Control Procedure by Initiating UE

[0503] Upon receiving the ProSe Direct Link Security Mode Complete message, the initiating UE stops timer T5089. If the selected integrity protection algorithm is not the Null Integrity Protection Algorithm, the UE checks the integrity of the ProSe Direct Link Security Mode Complete message. If the integrity check passes, the initiating UE proceeds with triggering the 5G ProSe Direct Link Security Mode Control procedure. If the selected integrity protection algorithm is the Null Integrity Protection Algorithm, the UE continues the procedure without checking integrity protection.

[0504] After receiving the ProSe Direct Link Security Mode Complete message, the initiating UE will delete its old security context for the target UE (if any).

[0505] 7.2.10.5 5G ProSe Direct Link Security Mode Control Procedure Not Accepted by Target UE

[0506] If the ProSe Direct Link Security Mode Command message cannot be accepted, the target UE shall send a ProSe Direct Link Security Mode Reject message and the target UE shall abort the ongoing procedure that triggered the initiation of the 5G ProSe Direct Link Security Mode Control procedure, unless the ongoing procedure is a 5G ProSe Direct Link Establishment procedure and the target user information is not included in the ProSe Direct Link Establishment Request message. The ProSe Direct Link Security Mode Reject message contains the PC5 Signaling Protocol Cause IE, which indicates one of the following cause values:

[0507] #5: Lack of resources for 5G ProSe direct links;

[0508] #7: Integrity failure;

[0509] #8: UE security capabilities do not match;

[0510] #9: K NRP-sess LSB conflict of ID;

[0511] #10: UE PC5 unicast signaling security policy does not match;

[0512] #14: Authentication synchronization error; or

[0513] #111: Unspecified protocol error.

[0514] If this 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Establishment procedure and the implementation-specific maximum number of established NR 5G ProSe direct links has been reached, the target UE shall send a ProSe Direct Link Security Mode Reject message with PC5 signaling protocol cause value #5 "Lack of resources for 5G ProSe Direct Link".

[0515] If the ProSe Direct Link Security Mode Command message cannot be accepted because the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Establishment procedure, the selected security algorithm in the ProSe Direct Link Security Mode Command message includes a null integrity protection algorithm, and the 5G ProSe direct signaling integrity protection policy of the target UE is set to "Signaling integrity protection required", then the target UE shall include PC5 signaling protocol cause #10 "UE PC5 unicast signaling security policy mismatch" in the ProSe Direct Link Security Mode Reject message.

[0516] If the ProSe Direct Link Security Mode Command message cannot be accepted because the 5G ProSe Direct Link Security Mode Control procedure is triggered during the 5G ProSe Direct Link Key Update procedure, the integrity protection algorithm currently used for the 5G ProSe direct link is different from the Null Integrity Protection Algorithm, and the Selected Security Algorithm in the ProSe Direct Link Security Mode Command message includes the Null Integrity Protection Algorithm, then the target UE shall include PC5 signaling protocol cause #10 "UE PC5 unicast signaling security policy mismatch" in the ProSe Direct Link Security Mode Reject message.

[0517] If the target UE detects that the UE security capabilities received in the ProSe Direct Link Security Mode Command message have changed compared to the most recent value sent by the target UE to the initiating UE in the ProSe Direct Link Setup Request message or the ProSe Direct Link Key Update Request message, the target UE shall include PC5 signaling protocol cause #8 “UE security capabilities mismatch” in the ProSe Direct Link Security Mode Reject message.

[0518] If the target UE detects that the K NRP-sess If the LSBs of the ID are set to the same value as those received from another UE in response to the target UE's ProSe Direct Link Setup Request message, the target UE shall include PC5 signaling protocol cause #9 "K NRP-sess LSB of ID conflicts".

[0519] If the 5G ProSe Direct Link Security Mode Control procedure is used for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE-to-network Relay UE, and the ProSe Direct Link Security Mode Command message cannot be accepted due to a synchronization error in processing the authentication vector (if any) contained in the GPI sent by the 5G ProSe UE-to-network Relay UE to the 5G ProSe Remote UE, then the target UE shall include PC5 signaling protocol cause #14 "Authentication Synchronization Error" in the ProSe Direct Link Security Mode Reject message and shall include the RAND and AUTS parameters in the ProSe Direct Link Security Mode Reject message.

[0520] After generating the ProSe Direct Link Security Mode Reject message, the target UE passes this message together with the Layer 2 ID of the initiating UE for 5G ProSe direct communication and the Layer 2 ID of the target UE for 5G ProSe direct communication to the lower layer for transmission.

[0521] After receiving the ProSe Direct Link Security Mode Reject message, the initiating UE shall stop timer T5089 and provide an indication to the lower layers to deactivate 5G ProSe Direct Security protection and delete the security context for the 5G ProSe direct link (if applicable):

[0522] a) If the PC5 signaling protocol cause IE in the ProSe Direct Link Security Mode Reject message is set to #9 "K NRP-sess LSB of ID conflicts", then retransmit K NRP-sess The ProSe direct link security mode command message has a different value for the LSB of the ID and restarts the timer T5089;

[0523] b) if the PC5 Signalling Protocol Cause IE in the ProSe Direct Link Security Mode Reject message is set to #14 “Authentication Synchronisation Error”, the message contains RAND and AUTS, and the 5G ProSe Direct Link Security Mode Control procedure is for direct communication between a 5G ProSe Remote UE and a 5G ProSe UE to Network Relay UE, then fresh GPI may be extracted from the PKMF by sending a Key Request message containing RAND and AUTS, as specified in 3GPP TS 33.503

[34] ; or

[0524] c) If the PC5 signaling protocol reason IE is set to other than #9 "K NRP-sess If the value is other than "LSB collision of ID" and other than #14 "Authentication synchronization error", the ongoing procedure that triggered the initiation of the 5G ProSe direct link security mode control procedure is aborted.

[0525] 7.2.10.6 Abnormal situations

[0526] 7.2.10.6.1 Abnormal situation at the initiating UE

[0527] a) Timer T5089 expires.

[0528] The initiating UE shall retransmit the ProSe Direct Link Security Mode Command message and restart the timer T5089. After reaching the maximum number of allowed retransmissions, the initiating UE shall abort the 5G ProSe Direct Link Security Mode Control procedure, provide an indication to the lower layers to deactivate 5G ProSe Direct Security protection and delete the security context for the 5G ProSe direct link (if applicable), and abort the ongoing procedure that triggered the initiation of the 5G ProSe Direct Link Security Mode Control procedure.

[0529] NOTE 1: The maximum number of allowed retransmissions is UE implementation specific.

[0530] b) This 5G ProSe direct link does not need to be used any more before the 5G ProSe direct link security mode control procedure is completed.

[0531] The initiating UE shall abort the procedure, shall provide an indication to lower layers to deactivate 5G ProSe Direct Security protection and delete the security context for the 5G ProSe direct link (if applicable), and shall abort the ongoing procedure that triggered the initiation of the 5G ProSe Direct Link Security Mode Control procedure.

[0532] c) If the ProSe direct link modification request message or the ProSe direct link identifier update request message is received while the timer T5089 is running, the initiating UE shall discard the ProSe direct link modification request message or the ProSe direct link identifier update request message.

[0533] d) If the ProSe direct link release request message is received while timer T5089 is running, the initiating UE shall stop timer T5089, abort the 5G ProSe direct link security mode control procedure, and continue with the 5G ProSe direct link release procedure.

[0534] NOTE 2: The exception cases described in item number c) or d) only occur when the 5G ProSe Direct Link Security Mode Control procedure is used to establish security between two UEs during the 5G ProSe Direct Link Key Update procedure.

[0535] 7.2.11 5G ProSe Direct Link Key Update Procedure

[0536] 7.2.11.1 Overview

[0537] The purpose of the 5G ProSe direct link key update procedure is to derive:

[0538] a) New K NRP-sess , and optionally a new K for an existing 5G ProSe direct link between a UE that is not a 5G ProSe remote UE and a relay UE from a 5G ProSe UE to the network NRP ;

[0539] b) A new K for an existing 5G ProSe direct link between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE when using the security procedures on the user plane specified in 3GPP TS 33.503

[34] NRP-sess ;or

[0540] c) A new K for an existing 5G ProSe direct link between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE when using the security procedures on the control plane specified in 3GPP TS 33.503

[34] relay-sess .

[0541] The UE that sends the ProSe direct link key update request message is called the "initiating UE", and the other UE is called the "target UE".

[0542] NOTE 1: There is no benefit in performing the 5G ProSe direct link key update procedure when the null integrity protection algorithm is used, so it is recommended not to trigger it when the null integrity protection algorithm is used.

[0543] 7.2.11.2 5G ProSe Direct Link Key Update Procedure Initiated by the Initiating UE

[0544] The initiating UE shall meet the following prerequisites before initiating the 5G ProSe direct link key update procedure:

[0545] a) There is a 5G ProSe direct link between the initiating UE and the target UE; and

[0546] 1) If the session key K used to protect the 5G ProSe direct link NRP-sess or K relay-sess (See Section 7.2.11.1) Refresh is required, and timers T5089 and T5091 are not running;

[0547] 2) If UE wants to refresh K NRP , when the 5G ProSe direct link is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, timers T5089 and T5091 are not running; or

[0548] 3) If the lower layer indicates that the 5G ProSe direct link key update procedure needs to be performed.

[0549] To initiate the 5G ProSe direct link key update procedure, the initiating UE shall create a ProSe direct link key update request message. In this message, the initiating UE:

[0550] a) If the 5G ProSe direct link is not used for direct communication between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE and the null integrity protection algorithm is not in use, then the Key Establishment Information Container IE shall be included;

[0551] NOTE 1: The key establishment information container is provided by the upper layer.

[0552] b) If the Null Integrity Protection Algorithm is not in use, then the Nonce_1 IE shall be included, which is set to a 128-bit temporary value generated by the initiating UE for the purpose of session key refresh on this 5G ProSe direct link;

[0553] c) shall contain its UE security capabilities, which indicate the list of algorithms supported by the initiating UE for key update for this 5G ProSe direct link;

[0554] d) If the Null Integrity Protection Algorithm is not in use, then K NRP-sess MSB of ID or K relay-sess The MSB of the ID (see section 7.2.11.1), which is selected by the initiating UE as specified in 3GPP TS 33.503

[34] ;

[0555] Note 2: K in the ProSe direct link key update request message NRP-sess The MSB of ID IE is used to hold K NRP-sess MSB of ID or K relay-sess The value of the MSB of ID.

[0556] e) If the initiating UE wants to derive a new K NRP If the 5G ProSe direct link key update procedure is not between a 5G ProSe remote UE and a 5G ProSe UE to a network relay UE, a re-authentication indication may be included;

[0557] NOTE 3: When the 5G ProSe direct link key update procedure is between a 5G ProSe remote UE and a 5G ProSe UE to network relay UE, the new K NRP It is always derived according to the security procedures on the user plane or the security procedures on the control plane as specified in 3GPP TS 33.503

[34] and therefore does not contain a reauthentication indication.

[0558] f) The User Security Key ID IE shall be included and set to:

[0559] 1) The UP-PRUK ID of the initiating UE, provided that:

[0560] i) The UE has a valid UP-PRUK;

[0561] ii) 5G ProSe direct link key update procedure is between 5G ProSe remote UE and 5G ProSe UE to network relay UE; and

[0562] iii) the user plane security procedures specified in 3GPP TS 33.503

[34] are used; or

[0563] 2) The CP-PRUK ID of the originating UE associated with the relay service code of the target UE, provided that:

[0564] i) The UE has a valid CP-PRUK associated with the relay service code of the target UE;

[0565] ii) 5G ProSe direct link key update procedure is between 5G ProSe remote UE and 5G ProSe UE to network relay UE; and

[0566] iii) the control plane security procedures specified in 3GPP TS 33.503

[34] are used; and

[0567] g) If the UP-PRUK ID is included and is not in NAI format (see 3GPP TS 33.503

[34] ), then the HPLMN ID of the 5G ProSe Remote UE shall be included.

[0568] After generating the ProSe Direct Link Key Update Request message, the initiating UE passes this message along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication to lower layers for transmission, and starts timer T5091. While timer T5091 is running, the UE will not send a new ProSe Direct Link Key Update Request message to the same target UE.

[0569] NOTE 4: To ensure successful 5G ProSe direct link key update, T5091 should be set to a value greater than the sum of T5092 and T5089.

[0570] [3GPP TS 24.554 V17.4.0 titled “5G ProSe Direct Link Key Update Procedure” Figure 7 .2.11.2.1 Reproduced as Figure 11 ]

[0571] 7.2.11.3 5G ProSe Direct Link Key Update Procedure Accepted by Target UE

[0572] After receiving the ProSe direct link key update request message, if the ProSe direct link key update request message contains a re-authentication indication, the target UE shall derive a new K NRP This may require execution of one or more 5G ProSe direct link authentication procedures, as specified in Section 7.2.12.

[0573] Note: The 5G ProSe direct link certification procedure is to export the new K NRP The number of times this needs to be performed depends on the authentication method used.

[0574] The target UE shall then initiate the 5G ProSe Direct Link Security Mode Control procedure as specified in section 7.2.10, where if the 5G ProSe Direct Link Key Update procedure is sent from the 5G ProSe Remote UE to the 5G ProSe UE to the network's Relay UE, the target UE shall proceed to establish a new K according to the security procedure on the user plane or the security procedure on the control plane, respectively. NRP or K NR_ProSe , as specified in 3GPP TS 33.503

[34] .

[0575] After the 5G ProSe direct link security mode control procedure is successfully completed, the target UE will create a ProSe direct link key update response message.

[0576] After generating the ProSe direct link key update response message, the target UE passes this message together with the layer 2 ID of the originating UE for unicast communication and the layer 2 ID of the target UE for unicast communication to the lower layer for transmission.

[0577] 7.2.11.4 5G ProSe Direct Link Key Update Procedure by Initiating UE Completed

[0578] After receiving the ProSe direct link key update response message, the initiating UE will stop the timer T5091 and use the new NRPIK to check the integrity of the ProSe direct link key update response message.

[0579] After receiving the ProSe Direct Link Key Update Response message, the initiating UE will delete the old security context it has for the target UE.

[0580] 7.2.11.5 Abnormal situation at the initiating UE

[0581] The following anomalies can be identified:

[0582] a) Timer T5091 expires.

[0583] The initiating UE will retransmit the ProSe Direct Link Key Update Request message and restart the timer T5091. After the maximum number of allowed retransmissions is reached, the initiating UE will abort the 5G ProSe Direct Link Key Update procedure, provide an indication to the lower layers to deactivate PC5 unicast security protection and delete the security context for the 5G ProSe direct link (if applicable), along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication, and may initiate a 5G ProSe Direct Link Release procedure.

[0584] NOTE: The maximum number of allowed retransmissions is UE implementation specific.

[0585] b) This 5G ProSe direct link does not need to be used any more until the 5G ProSe direct link key update procedure is completed.

[0586] The initiating UE shall abort the procedure and shall provide to the lower layers an indication to deactivate PC5 unicast security protection and delete the security context for the 5G ProSe direct link (if applicable) along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication.

[0587] c) For the same 5G ProSe direct link, if the initiating UE receives a ProSe direct link identifier update request message after initiating the 5G ProSe direct link key update procedure, the initiating UE shall stop timer T5091, abort the 5G ProSe direct link key update procedure, and continue with the 5G ProSe direct link identifier update procedure.

[0588] 7.2.12 5G ProSe Direct Link Authentication Procedure

[0589] 7.2.12.1 Overview

[0590] The 5G ProSe Direct Link Authentication procedure is used to perform mutual authentication of UEs establishing a 5G ProSe direct link and to derive a new K shared between two UEs during the 5G ProSe Direct Link Establishment procedure or the 5G ProSe Direct Link Key Update procedure. NRP Following the successful completion of the 5G ProSe direct link certification process, the new K NRP Used for security establishment during the 5G ProSe Direct Link Security Mode Control procedure, as specified in Section 7.2.10. The UE that sends the ProSe Direct Link Authentication Request message is called the "initiating UE" and the other UE is called the "target UE".

[0591] NOTE: The 5G ProSe direct link authentication procedure is not applicable to either 5G ProSe layer 3 UE-to-network relay or 5G ProSe layer 2 UE-to-network relay.

[0592] 7.2.12.2 5G ProSe Direct Link Authentication Procedure Initiated by the Initiating UE

[0593] The initiating UE shall meet one of the following prerequisites when establishing non-null signaling integrity protection based on the initiating UE's decision before initiating the 5G ProSe direct link authentication procedure:

[0594] a) The target UE has initiated a 5G ProSe direct link establishment procedure towards the initiating UE by sending a ProSe direct link establishment request message, and:

[0595] 1) ProSe Direct Link Establishment Request Message:

[0596] i) contains the target user information IE, which contains the application layer ID of the originating UE; or

[0597] ii) does not contain the Target User Information IE, and the initiating UE is interested in the ProSe service identified by the ProSe identifier in the ProSe Direct Link Setup Request message; and

[0598] 2)K NRP The ID is not included in the ProSe direct link establishment request message, or the initiating UE has a problem with the K contained in the ProSe direct link establishment request message. NRP ID does not have an existing K NRP , or initiate UE to export new K NRP ;or

[0599] b) The target UE has initiated a 5G ProSe direct link key update procedure towards the initiating UE by sending a ProSe direct link key update request message, and the ProSe direct link key update request message contains a re-authentication indication.

[0600] To initiate the 5G ProSe direct link authentication procedure, the initiating UE shall create a ProSe direct link authentication request message.

[0601] In this message, the initiating UE:

[0602] a) Will contain the Key Establishment Information Container IE.

[0603] NOTE 1: The key establishment information container is provided by the upper layer.

[0604] The initiating UE will assign a source Layer 2 ID by itself, and the destination Layer 2 ID is set to the source Layer 2 ID in the ProSe Direct Link Setup Request message.

[0605] NOTE 2: The UE implementation ensures that any value of the self-assigned source Layer-2 ID is different from any other self-assigned source Layer-2 ID used for 5G ProSe direct discovery as specified in sections 6.2.14, 6.2.15 and 8.2.1, and different from any other provided destination Layer-2 ID as specified in section 5.2.

[0606] NOTE 3: The target UE may reuse the Layer 2 ID that the target UE used in a previous 5G ProSe direct link with the same peer UE.

[0607] After generating the ProSe Direct Link Authentication Request message, the initiating UE passes this message together with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication to the lower layer for transmission.

[0608] The initiating UE will start timer T5092. The UE will not send a new ProSe Direct Link Authentication Request message to the same target UE while timer T5092 is running.

[0609] [3GPP TS 24.554 V17.4.0 titled “5G ProSe direct link authentication procedure” Figure 7 .2.12.2.1 Reproduced as Figure 12 ]

[0610] 7.2.12.3 5G ProSe Direct Link Authentication Procedure Accepted by Target UE

[0611] Upon receiving the ProSe Direct Link Authentication Request message, if it contains the newly assigned Layer 2 ID of the initiating UE, the target UE shall replace the original Layer 2 ID of the initiating UE with the newly assigned Layer 2 ID of the initiating UE for unicast communication. If the target UE determines that the ProSe Direct Link Authentication Request message is acceptable, the target UE shall create a ProSe Direct Link Authentication Response message. The target UE shall check whether the number of established 5G ProSe direct links is less than the implementation-specific maximum number of established NR 5G ProSe direct links allowed in the UE at one time. In this message, the target UE:

[0612] a) Will contain the Key Establishment Information Container IE.

[0613] Note: The key establishment information container is provided by the upper layer.

[0614] After generating the ProSe direct link authentication response message, the target UE passes this message together with the layer 2 ID of the target UE for unicast communication and the layer 2 ID of the originating UE for unicast communication to the lower layer for transmission.

[0615] 7.2.12.4 Completion of 5G ProSe Direct Link Authentication Procedure by Initiating UE

[0616] After receiving the ProSe direct link authentication response message, if the initiating UE determines that the ProSe direct link authentication response message is acceptable, the initiating UE will stop timer T5092.

[0617] Note: The initiating UE derives the new K during the 5G ProSe direct link authentication procedure. NRP The time depends on the authentication method used.

[0618] 7.2.12.5 5G ProSe Direct Link Authentication Procedure Not Accepted by Target UE

[0619] If the ProSe Direct Link Authentication Request message cannot be accepted, the target UE shall create a ProSe Direct Link Authentication Reject message. In this message, the target UE shall include the PC5 Signaling Protocol Cause IE, which indicates one of the following cause values:

[0620] #5: Lack of resources for 5G ProSe direct links;

[0621] #6: Authentication failed.

[0622] If this 5G ProSe Direct Link Authentication procedure is triggered during the 5G ProSe Direct Link Establishment procedure and the implementation-specific maximum number of established NR 5G ProSe direct links has been reached, the target UE shall send a ProSe Direct Link Authentication Reject message with PC5 signaling protocol cause value #5 "Lack of resources for 5G ProSe Direct Link".

[0623] After generating the ProSe Direct Link Authentication Reject message, the target UE passes this message together with the Layer 2 ID of the originating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication to the lower layer for transmission.

[0624] If the ongoing procedure is a 5G ProSe direct link establishment procedure and the target user information is included in the ProSe direct link setup request message, the target UE shall abort the ongoing procedure that triggered the initiation of the 5G ProSe direct link authentication procedure.

[0625] After receiving the ProSe Direct Link Authentication Reject message, the initiating UE will stop timer T5092 and abort the ongoing procedure that triggered the initiation of the 5G ProSe Direct Link Authentication procedure.

[0626] 7.2.12.6 5G ProSe Direct Link Authentication Procedure Not Accepted by the Initiating UE

[0627] If the ProSe Direct Link Authentication Response message cannot be accepted, the initiating UE stops timer T5092 and generates a ProSe Direct Link Authentication Failure message. In this message, the initiating UE may include a Key Establishment Information Container (IE) (if provided by upper layers). After generating the ProSe Direct Link Authentication Failure message, the initiating UE passes it, along with the Layer 2 ID of the initiating UE for unicast communication and the Layer 2 ID of the target UE for unicast communication, to lower layers for transmission.

[0628] The initiating UE shall abort the ongoing procedure that triggered the initiation of the 5G ProSe direct link authentication procedure.

[0629] Upon receiving the ProSe direct link authentication failure message, the target UE shall abort the ongoing procedure that triggered the initiation of the 5G ProSe direct link authentication procedure and shall indicate to upper layers that the authentication has failed.

[0630] 7.2.12.7 Abnormal Situations

[0631] 7.2.12.7.1 Abnormal situation at the initiating UE

[0632] a) Timer T5092 expires.

[0633] The initiating UE will retransmit the ProSe Direct Link Authentication Request message and restart the timer T5092. After reaching the maximum number of allowed retransmissions, the initiating UE will abort the 5G ProSe Direct Link Authentication procedure and will abort the ongoing procedure that triggered the initiation of the 5G ProSe Direct Link Authentication procedure.

[0634] NOTE 1: The maximum number of allowed retransmissions is UE implementation specific.

[0635] b) There is no need to use this 5G ProSe direct link until the 5G ProSe direct link certification procedure is completed.

[0636] The initiating UE shall abort the 5G ProSe direct link authentication procedure and shall abort the ongoing procedure that triggered the initiation of the 5G ProSe direct link authentication procedure.

[0637] c) For the same 5G ProSe direct link, if the initiating UE receives a ProSe direct link release request message during the 5G ProSe direct link authentication procedure, the initiating UE shall stop all running timers of this 5G ProSe direct link, abort the 5G ProSe direct link authentication procedure, and continue with the 5G ProSe direct link release procedure.

[0638] NOTE 2: The exception described in item number c) only occurs when the 5G ProSe direct link authentication procedure is used to perform mutual authentication of the UE during the 5G ProSe direct link key update procedure.

[0639] 3GPP TS 23.304 describes the unicast mode that supports Layer 2 link establishment for ProSe direct communication over the PC5 reference point, while 3GPP TS 24.554 specifies the Stage 3 details regarding Layer 2 link establishment (or 5G ProSe direct link establishment, as discussed in 3GPP TS 24.554). For example, UE1 and UE2 want to perform unicast mode sidelink communication with each other. According to 3GPP TS 23.304 and 3GPP TS 24.554, UE1 sends a Direct Communication Request message to UE2 to request the establishment of a unicast link. UE2 then sends a Security Mode Control Command message to UE1 to request the establishment of a security context (e.g., including security keys and algorithms) for the unicast link.

[0640] In response to receiving the Security Mode Control Command message, UE1 responds to UE2 with a Security Mode Control Complete message to complete security context establishment. Finally, UE2 responds to UE1 with a Direct Communication Accept message to complete direct link establishment. After the unicast link is established, UE1 may initiate a direct link key update procedure to establish a new security context for the unicast link. During the direct link key update procedure, UE1 may send a Direct Link Key Update Request message to UE2. In response to receiving the Direct Link Key Update Request message, UE2 may initiate (a direct link authentication procedure and) a direct link security mode control procedure. UE2 may send a Direct Link Security Mode Command message to UE1, and UE1 may respond to UE2 with a Direct Link Security Mode Complete message. UE2 may then respond to UE1 with a Direct Link Key Update Response message to complete the direct link key update procedure. UE2 may begin applying the new security context after the Direct Link Security Mode Command message is passed to lower layers for transmission, and UE1 may begin applying the new security context after the Direct Link Security Mode Complete message is passed to lower layers for transmission.

[0641] UE1 may initiate a direct link identifier update procedure after the direct link key update procedure has already been initiated (e.g., due to a change in UE1's application layer ID, expiration of the privacy timer for UE1's Layer 2 ID, or other reasons). During the direct link identifier update procedure, UE1 may send a direct link identifier update request message to UE2. According to section 7.2.10.6.1 of 3GPP TS 24.554, if UE2 is executing a direct link security mode control procedure (i.e., timer T5089 is running), UE2 only discards the direct link identifier update request message. From a resource efficiency perspective, it is preferable for UE1 to delay the direct link identifier update procedure until the direct link key update procedure is complete (i.e., when timer T5091 is not running), thereby saving radio resources used to transmit the discarded direct link identifier update request message. Similarly, if UE2 is executing a direct link security mode control procedure (i.e., timer T5089 is running), UE2 also discards the direct link modification request message. Therefore, it is also beneficial for UE1 to delay the direct link modification procedure until the direct link key update procedure is completed.

[0642] The solution may be as shown in the following example from the text proposal of 3GPP TS 24.554:

[0643]

[0644] The solution may alternatively be as shown in the following example of the text proposal of 3GPP TS 24.554:

[0645]

[0646] Alternatively, UE2 may initiate a direct link identifier update procedure after the direct link security mode control procedure (initiated by UE2) (e.g., due to a change in UE2's application layer ID, expiration of the privacy timer for UE2's Layer 2 ID, or other reasons). Note that this direct link security mode control procedure is triggered by the direct link key update procedure initiated by UE1. During the direct link security mode control procedure, UE2 sends a direct link security mode command message to UE1 and receives a direct link security mode complete message from UE1. During the direct link identifier update procedure, UE2 sends a direct link identifier update request message to UE1.

[0647] According to section 7.2.11.5 of 3GPP TS 24.554, in response to receiving a Direct Link Identifier Update Request message from UE2, UE1 aborts the Direct Link Identifier Update procedure and then proceeds with the Direct Link Identifier Update procedure (initiated by UE2). Aborting the Direct Link Identifier Update procedure implies that UE1 may not apply the new security context. Therefore, UE1 will apply the old security context and proceed with the Direct Link Identifier Update procedure. However, from UE2's perspective, the Direct Link Security Mode Control procedure can still complete, even if the Direct Link Identifier Update procedure is initiated. In this case, UE2 will apply the new security context and proceed with the Direct Link Identifier Update procedure. To this end, because the signaling messages for the Direct Link Identifier Update procedure are sent with encryption protection, the Direct Link Identifier Update procedure cannot complete if the security contexts between the two UEs are not inconsistent, and the unicast link can be released. To address this issue, UE2 preferably delays the Direct Link Identifier Update procedure until the Direct Link Identifier Update procedure is complete (i.e., the Direct Link Identifier Update Request message may be sent to UE1 after UE2 sends the Direct Link Identifier Update Response message to UE1).

[0648] The solution may be as shown in the following example from the text proposal of 3GPP TS 24.554:

[0649]

[0650] It should be noted that one or more solutions may be as shown in the following exemplary text proposal of 3GPP TS 24.554:

[0651]

[0652] Figure 13 1300 is a flow chart of a method for a second UE. In step 1305, the second UE establishes a unicast link with the first UE. In step 1310, if at least the second UE is performing any direct link key update procedure triggered by the first UE for the unicast link, the second UE is not allowed to initiate a direct link identifier update procedure or a direct link modification procedure.

[0653] In one embodiment, if at least a specific timer for the unicast link is running on the second UE, the second UE may not be allowed to initiate a direct link identifier update procedure or a direct link modification procedure. The specific timer for the unicast link may be T5091.

[0654] In one embodiment, the second UE may be aware of the need to initiate a direct link identifier update procedure or a direct link modification procedure with the first UE for a unicast link. The need to initiate the direct link identifier update procedure may indicate that the second UE has changed its application layer identifier (ID) or the privacy timer for its Layer 2 ID has expired. The need to initiate the direct link modification procedure may also indicate that the second UE has added, modified, or removed at least one of a PC5 Quality of Service (QoS) flow and a Proximity-Based Services (ProSe) application / service for the unicast link.

[0655] In one embodiment, a direct link key update procedure may be used to update the security context of a unicast link.

[0656] In one embodiment, not allowing the second UE to initiate the direct link identifier update procedure or the direct link modification procedure means prohibiting the second UE from initiating the direct link identifier update procedure or the direct link modification procedure.

[0657] Return Reference Figure 3 and Figure 4 In one example from the perspective of a second UE, the second UE 300 includes program code 312 stored in memory 310. The CPU 308 can execute the program code 312 to enable the second UE to: (i) establish a unicast link with the first UE; and (ii) not initiate a direct link identifier update procedure or a direct link modification procedure if at least the second UE is executing any direct link key update procedure triggered by the first UE for the unicast link. Furthermore, the CPU 308 can execute the program code 312 to perform all of the aforementioned actions and steps, or other actions and steps described herein.

[0658] Figure 14 1400 is a flow chart of a method for a first UE. In step 1405, the first UE establishes a unicast link with a second UE. In step 1410, the first UE recognizes the need to initiate a direct link identifier update procedure or a direct link modification procedure for the unicast link. In step 1415, the first UE delays initiating the direct link identifier update procedure or the direct link modification procedure until one or more specific timers for the unicast link are no longer running.

[0659] In one embodiment, delaying the initiation of a direct link identifier update procedure or a direct link modification procedure may mean that the first UE does not send a direct link identifier update request message during the direct link identifier update procedure or does not send a direct link modification request message during the direct link modification procedure to the second UE. Delaying the initiation of a direct link identifier update procedure or a direct link modification procedure may also mean that the first UE does not send any direct link identifier update request message during the direct link identifier update procedure or does not send any direct link modification request message during the direct link modification procedure to the second UE. In one embodiment, the one or more specific timers include at least T5091.

[0660] In one embodiment, the need to initiate a direct link identifier update procedure may mean that the first UE changes the application layer ID or the privacy timer of the first UE's layer 2 ID expires. The need to initiate a direct link modification procedure may also mean that the first UE adds, modifies, or releases / removes a PC5 QoS flow or ProSe application / service for a unicast link.

[0661] Return Reference Figure 3 and Figure 4 In one example from the perspective of a first UE, the first UE 300 includes program code 312 stored in memory 310. The CPU 308 can execute the program code 312 to enable the first UE to: (i) establish a unicast link with a second UE; (ii) be aware of the need to initiate a direct link identifier update procedure or a direct link modification procedure for the unicast link; and (iii) delay initiating the direct link identifier update procedure or the direct link modification procedure until one or more specific timers for the unicast link are no longer running. Furthermore, the CPU 308 can execute the program code 312 to perform all of the aforementioned actions and steps, or other actions and steps described herein.

[0662] Figure 15 1500 is a flow chart of a method for a second UE. In step 1505, the second UE establishes a unicast link with a first UE. In step 1510, the second UE recognizes the need to initiate a direct link identifier update procedure or a direct link modification procedure with the first UE for the unicast link. In step 1515, if the second UE is not currently executing any direct link key update procedure triggered by the first UE for the unicast link, the second UE is allowed to initiate the direct link identifier update procedure or the direct link modification procedure.

[0663] In one embodiment, if a second UE is currently executing a direct link key update procedure triggered by a first UE for a unicast link, the second UE may delay initiating a direct link identifier update procedure or a direct link modification procedure. The second UE may receive a direct link key update request message for the direct link key update procedure from the first UE. After the second UE sends a direct link key update response message corresponding to the direct link key update request message to the first UE, the second UE may initiate the direct link identifier update procedure or the direct link modification procedure.

[0664] In one embodiment, before sending the direct link key update response message, the second UE may not send any direct link identifier update request message in the direct link identifier update procedure or any direct link modification request message in the direct link modification procedure to the first UE.

[0665] In one embodiment, the need to initiate a direct link identifier update procedure may mean that the second UE changes the application layer ID or the privacy timer of the second UE's layer 2 ID expires. The need to initiate a direct link modification procedure may also mean that the second UE adds, modifies, or releases / removes a PC5 QoS flow or ProSe application / service for the unicast link.

[0666] Return Reference Figure 3 and Figure 4 In one example from the perspective of a second UE, the second UE 300 includes program code 312 stored in memory 310. The CPU 308 can execute the program code 312 to enable the second UE to: (i) establish a unicast link with the first UE; (ii) be aware of the need to initiate a direct link identifier update procedure or a direct link modification procedure with the first UE for the unicast link; and (iii) allow the initiation of a direct link identifier update procedure or a direct link modification procedure if the second UE is not currently executing any direct link key update procedure triggered by the first UE for the unicast link. Furthermore, the CPU 308 can execute the program code 312 to perform all of the aforementioned actions and steps, or other actions and steps described herein.

[0667] Various aspects of the present disclosure have been described above. It should be understood that the teachings herein can be implemented in a wide variety of forms, and any specific structure, functionality, or both disclosed herein are merely representative. Based on the teachings herein, those skilled in the art will appreciate that the aspects disclosed herein can be implemented independently of any other aspects, and that two or more of these aspects can be combined in various ways. For example, a device or method can be implemented using any number of the aspects described herein. Furthermore, the device or method can be implemented using other structures, functionality, or structures and functionality in addition to or different from one or more of the aspects described herein. As an example of some of the above concepts, in some aspects, parallel channels can be established based on pulse repetition frequency. In some aspects, parallel channels can be established based on pulse position or offset. In some aspects, parallel channels can be established based on a time hopping sequence. In some aspects, parallel channels can be established based on pulse repetition frequency, pulse position or offset, and a time hopping sequence.

[0668] Those skilled in the art will understand that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0669] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, processors, components, circuits, and algorithm steps described in connection with the various aspects disclosed herein can be implemented as electronic hardware (e.g., a digital implementation, an analog implementation, or a combination of the two, which can be designed using source decoding or some other technique), and various forms of programs or design code with instructions (which, for convenience, may be referred to herein as "software" or "software modules"), or a combination of the two. To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether this functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each specific application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0670] Furthermore, the various illustrative logical blocks, modules, and circuits described in connection with the aspects disclosed herein may be implemented within or performed by an integrated circuit ("IC"), an access terminal, or an access point. An IC may include a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, electrical components, optical components, mechanical components, or any combination thereof designed to perform the functions described herein, and may execute code or instructions residing within the IC, external to the IC, or both. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a combination of multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0671] It should be understood that any specific order or hierarchy of steps in any disclosed process is an example of a sample approach. It should be understood that based on design preferences, the specific order or hierarchy of steps in a process can be rearranged while remaining within the scope of the present disclosure. The accompanying method claims present elements of the various steps in a sample order and are not meant to be limited to the specific order or hierarchy presented.

[0672] The steps of the methods or algorithms described in conjunction with the various aspects disclosed herein can be implemented directly in hardware, in software modules executed by a processor, or in a combination of the two. Software modules (e.g., containing executable instructions and associated data) and other data can reside in a data storage device, such as RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of computer-readable storage medium known in the art. An example storage medium can be coupled to a machine such as a computer / processor (for convenience, the machine may be referred to herein as a "processor") so that the processor can read information (e.g., code) from the storage medium and write information to the storage medium. An example storage medium can be integrated with the processor. The processor and storage medium can reside in an ASIC. The ASIC can reside in a user device. In an alternative, the processor and storage medium can reside in a user device as discrete components. In addition, in some aspects, any suitable computer program product may include a computer-readable medium that includes code related to one or more of the various aspects of the present disclosure. In some aspects, the computer program product may include packaging materials.

[0673] Although the present invention has been described in conjunction with various aspects, it will be understood that the invention is capable of further modification. This application is intended to cover any variations, uses, or adaptations of the invention that generally follow the principles of the invention and include such deviations from the present disclosure as come within the scope of known and customary practice in the art to which the invention pertains.

Claims

1. A method for a second user equipment (UE), comprising: Establishing a unicast link with the first UE; as well as When the second UE is performing a direct link key update procedure triggered by the first UE for the unicast link established between the first UE and the second UE, the second UE is not allowed to initiate a direct link identifier update procedure or a direct link modification procedure.

2. The method according to claim 1, wherein if at least a specific timer for the unicast link is running on the second UE, the second UE is not allowed to initiate the direct link identifier update procedure or the direct link modification procedure. 3 . The method according to claim 2 , wherein the specific timer for the unicast link is T5091. 4 . The method according to claim 1 , wherein the second UE knows that it is necessary to initiate the direct link identifier update procedure or the direct link modification procedure with the first UE for the unicast link. 5 . The method according to claim 4 , wherein the need to initiate the direct link identifier update procedure means that the second UE changes an application layer identifier (ID) or a privacy timer of a layer 2 ID of the second UE expires.

6. The method according to claim 4, wherein the need to initiate the direct link modification procedure means that the second UE adds, modifies or removes at least one of a PC5 quality of service flow and a proximity-based service application / service for the unicast link.

7. The method of claim 1, wherein the direct link key update procedure is used to update a security context of the unicast link.

8. The method according to claim 1, wherein not allowing the second UE to initiate the direct link identifier update procedure or the direct link modification procedure means prohibiting the second UE from initiating the direct link identifier update procedure or the direct link modification procedure.

9. A second user equipment (UE), comprising: control circuit; a processor installed in the control circuit; as well as a memory installed in the control circuit and operatively coupled to the processor; The processor is configured to execute the program code stored in the memory to perform the following operations: Establishing a unicast link with the first UE; as well as When the second UE is performing a direct link key update procedure triggered by the first UE for the unicast link established between the first UE and the second UE, the second UE is not allowed to initiate a direct link identifier update procedure or a direct link modification procedure.

10. The second UE according to claim 9, wherein if at least a specific timer for the unicast link is running on the second UE, the second UE is not allowed to initiate the direct link identifier update procedure or the direct link modification procedure. The second UE according to claim 10 , wherein the specific timer for the unicast link is T5091. 12 . The second UE according to claim 9 , wherein the second UE is aware of the need to initiate the direct link identifier update procedure or the direct link modification procedure with the first UE for the unicast link. 13 . The second UE according to claim 12 , wherein the need to initiate the direct link identifier update procedure means that the second UE changes an application layer identifier (ID) or a privacy timer of a layer 2 ID of the second UE expires. 14 . The second UE according to claim 12 , wherein the need to initiate the direct link modification procedure means that the second UE adds, modifies, or removes at least one of a PC5 quality of service flow and a proximity-based service application / service for the unicast link. 15 . The second UE according to claim 9 , wherein the direct link key update procedure is used to update a security context of the unicast link. 16 . The second UE according to claim 9 , wherein not allowing the second UE to initiate the direct link identifier update procedure or the direct link modification procedure means prohibiting the second UE from initiating the direct link identifier update procedure or the direct link modification procedure.

17. A second user equipment (UE), comprising: control circuit; a processor installed in the control circuit; as well as a memory installed in the control circuit and operatively coupled to the processor; The processor is configured to execute the program code stored in the memory to perform the following operations: Establishing a unicast link with the first UE; When the second UE is performing a direct link key update procedure triggered by the first UE for the unicast link established between the first UE and the second UE, determining that the second UE is not allowed to initiate a direct link identifier update procedure or a direct link modification procedure; as well as When the second UE does not perform a direct link key update procedure triggered by the first UE for the unicast link established between the first UE and the second UE, it is determined that the second UE is allowed to initiate the direct link identifier update procedure or the direct link modification procedure.

18. The second UE according to claim 17, wherein if at least a specific timer for the unicast link is running on the second UE, the second UE is not allowed to initiate the direct link identifier update procedure or the direct link modification procedure. The second UE according to claim 18 , wherein the specific timer for the unicast link is T5091. 20 . The second UE according to claim 17 , wherein the second UE is aware of the need to initiate the direct link identifier update procedure or the direct link modification procedure with the first UE for the unicast link.

Citation Information

Patent Citations

  • Roll-over of identifiers and keys for unicast vehicle to vehicle communication links

    US20190364424A1