Achieving L1 safety by adding artificial AM / PM

By introducing artificial AM/PM impairment features into wireless communication systems, UEs and base stations can identify legitimate transmitters, solving the problem of forged signals in wireless communications and improving physical layer security and communication efficiency.

CN118975292BActive Publication Date: 2025-09-26QUALCOMM INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380032635.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-15
Filing Date
2023-03-24
Publication Date
2025-09-26
Estimated Expiration
2043-03-24

AI Technical Summary

Technical Problem

In wireless communication systems, existing technologies lack effective physical layer security measures, allowing malicious intruders to forge legitimate transmission signals. UEs find it difficult to distinguish between real and forged transmissions, and without sufficient security measures, latency and protocol load are high.

Method used

By adding artificial AM/PM impairment features at the physical layer, the UE can estimate and identify the AM/PM impairment features of a legitimate transmitter. The base station sends an indication of the reference AM/PM impairment features via a safety signal to maintain or discard the downlink channel.

Benefits of technology

It provides an additional layer of security, reduces quantum threats, reduces the load and latency in layer 3, reduces the opportunities for malicious intruders, and improves the security and efficiency of wireless communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118975292B_ABST
    Figure CN118975292B_ABST
Patent Text Reader

Abstract

A network node may select a reference AM / PM impairment signature. The network node may send a first indication of the reference AM / PM impairment signature to a UE via a safety signal. The network node may send at least one reference signal to the UE via a downlink channel. The at least one reference signal may include AM / PM impairments added based on the reference AM / PM impairment signature. The UE may receive at least one reference signal from a transmitter via a downlink channel. The UE may estimate the AM / PM impairment signature in the at least one reference signal. The UE may identify whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. Furthermore, the UE may maintain or discard at least one timeslot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of U.S. patent application serial number 17 / 659,421, filed on April 15, 2022, and entitled “L1 SECURITY BY ADDING ARTIFICIAL AM / PM,” which is expressly incorporated herein by reference in its entirety. Technical Field

[0003] The present disclosure relates generally to communication systems, and more particularly to physical layer security in wireless communication systems. Background Art

[0004] Wireless communication systems are widely deployed to provide a variety of telecommunication services, such as telephony, video, data, messaging, and broadcasts. Typical wireless communication systems may employ multiple access technologies capable of supporting communication with multiple users by sharing available system resources. Examples of such multiple access technologies include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single-carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems.

[0005] These multiple access technologies have been adopted in various telecommunication standards to provide a common protocol that enables different wireless devices to communicate at a city, country, region, and even global level. An example telecommunication standard is 5G New Radio (NR). 5G NR is part of the continued mobile broadband evolution promulgated by the 3rd Generation Partnership Project (3GPP) to meet new requirements associated with latency, reliability, security, scalability (e.g., with the Internet of Things (IoT)) and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine-type communications (mMTC), and ultra-reliable low-latency communications (URLLC). Certain aspects of 5G NR may be based on the 4G Long Term Evolution (LTE) standard. Further improvements to 5G NR technology are needed. In addition, these improvements may also be applicable to other multiple access technologies and telecommunication standards that employ these technologies. Summary of the Invention

[0006] The following presents a summary of one or more aspects in order to provide a basic understanding of these aspects. This summary is not an extensive overview of all contemplated aspects and is neither intended to identify key or critical elements of all aspects nor to describe the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that is presented later.

[0007] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a user equipment (UE). The apparatus may receive at least one reference signal from a transmitter via a downlink channel. The apparatus may estimate an amplitude modulation to phase modulation (AM / PM) impairment signature in the at least one reference signal. The apparatus may identify whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature. The apparatus may maintain or discard at least one timeslot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature.

[0008] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a network node. The apparatus may select a reference AM / PM impairment signature. The apparatus may send a first indication of the reference AM / PM impairment signature to a UE via a safety signal. The apparatus may send at least one reference signal to the UE via a downlink channel. The at least one reference signal may include AM / PM impairments added based on the reference AM / PM impairment signature.

[0009] To accomplish the foregoing and related ends, one or more aspects include the features fully described below and particularly pointed out in the claims. The following description and the accompanying drawings set forth in detail certain illustrative features of one or more aspects. However, these features are indicative of but a few of the various ways in which the principles of the various aspects may be employed, and this description is intended to include all such aspects and their equivalents. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Figure 1 is a diagram illustrating an example of a wireless communication system and an access network.

[0011] Figure 2A is a diagram illustrating an example of a first frame according to various aspects of the present disclosure.

[0012] Figure 2B is a diagram illustrating an example of DL channels within a subframe according to various aspects of the present disclosure.

[0013] Figure 2C is a diagram illustrating an example of a second frame according to various aspects of the present disclosure.

[0014] Figure 2D is a diagram illustrating an example of UL channels within a subframe according to various aspects of the present disclosure.

[0015] Figure 3 is a diagram illustrating an example of a base station and a user equipment (UE) in an access network according to various aspects of the present disclosure.

[0016] Figure 4 is a diagram illustrating an example AM / PM impairment model in accordance with various aspects of the present disclosure.

[0017] Figure 5 is a diagram of a communication flow of a method of wireless communication according to various aspects of the present disclosure.

[0018] Figure 6 is a block diagram illustrating the addition of artificial AM / PM impairments in accordance with various aspects of the present disclosure.

[0019] Figure 7A is a diagram illustrating an example scenario in accordance with various aspects of the present disclosure, wherein AM / PM impairment signatures associated with reference signals (RSs) in downlink traffic match reference AM / PM impairment signatures associated with legitimate transmitters.

[0020] Figure 7B is a diagram illustrating an example scenario in accordance with various aspects of the present disclosure, where an AM / PM impairment signature associated with an RS in downlink traffic does not match a reference AM / PM impairment signature associated with a legitimate transmitter.

[0021] Figure 8 is a block diagram illustrating an iterative digital post-distortion (DPoD) process according to various aspects of the present disclosure.

[0022] Figure 9 is a diagram of a communication flow of a method of wireless communication according to various aspects of the present disclosure.

[0023] Figure 10 is a flow chart of a method of wireless communication according to various aspects of the present disclosure.

[0024] Figure 11 is a flow chart of a method of wireless communication according to various aspects of the present disclosure.

[0025] Figure 12 is a flow chart of a method of wireless communication according to various aspects of the present disclosure.

[0026] Figure 13 is a flow chart of a method of wireless communication according to various aspects of the present disclosure.

[0027] Figure 14 is a diagram illustrating an example of a hardware implementation for an example apparatus according to various aspects of the present disclosure.

[0028] Figure 15 is a diagram illustrating an example of a hardware implementation for an example apparatus according to various aspects of the present disclosure. DETAILED DESCRIPTION

[0029] The detailed description set forth below in conjunction with the accompanying drawings is intended as a description of various configurations and is not intended to represent the only configuration in which the concepts described herein may be practiced. In order to provide a thorough understanding of the various concepts, the detailed description includes specific details. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring these concepts.

[0030] Several aspects of telecommunication systems will now be presented with reference to various apparatuses and methods. These apparatuses and methods are described in the following detailed description and illustrated in the accompanying drawings by various blocks, components, circuits, processes, algorithms, etc. (collectively, "elements"). These elements can be implemented using electronic hardware, computer software, or any combination thereof. Whether these elements are implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system.

[0031] As an example, an element or any part of an element or any combination of elements can be implemented as a "processing system", which includes one or more processors. The example of a processor includes a microprocessor, a microcontroller, a graphics processing unit (GPU), a central processing unit (CPU), an application processor, a digital signal processor (DSP), a reduced instruction set computing (RISC) processor, a system on a chip (SoC), a baseband processor, a field programmable gate array (FPGA), a programmable logic device (PLD), a state machine, a gate logic component, a discrete hardware circuit and other suitable hardware configured to perform various functionalities described throughout the present disclosure. One or more processors in a processing system can execute software. Whether it is referred to as software, firmware, middleware, microcode, hardware description language or other names, software should be broadly interpreted as meaning an instruction, an instruction set, a code, a code segment, a program code, a program, a subroutine, a software component, an application, a software application, a software package, a routine, a subroutine, an object, an executable file, a thread of execution, a procedure, a function etc.

[0032] Therefore, in one or more example embodiments, the described functions can be implemented with hardware, software or any combination thereof. If implemented with software, the functions can be stored or encoded on a computer-readable medium as one or more instructions or codes. Computer-readable media include computer storage media. Storage media can be any available medium that can be accessed by a computer. As an example and not limitation, such computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage, other magnetic storage devices, a combination of these types of computer-readable media, or any other medium that can be used to store instructions or data structure forms that can be accessed by a computer.

[0033] Although various aspects and specific implementations are described in this application by way of illustration of some examples, it will be understood by those skilled in the art that additional specific implementations and use cases may be generated in many other arrangements and scenarios. The innovations described herein can be implemented across many different platform types, devices, systems, shapes, sizes, and packaging arrangements. For example, specific implementations and / or uses may be generated via integrated chip specific implementations and other devices based on non-module components (e.g., end-user devices, vehicles, communication equipment, computing equipment, industrial equipment, retail / purchasing equipment, medical equipment, artificial intelligence (AI) enabled devices, etc.). Although some examples may or may not specifically point to use cases or applications, the applicability of various types of the described innovations may occur. Specific implementations may range from chip-level or modular components to non-modular, non-chip-level specific implementations, and further to the range of aggregated, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more aspects of the described innovations. In some actual environments, the devices incorporating the various aspects and features described may also include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals necessarily include multiple components for both analog and digital purposes (e.g., hardware components including antennas, RF chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). The innovations described herein are intended to be practiced in a variety of devices of varying sizes, shapes, and configurations, chip-level components, systems, distributed arrangements, aggregated or disaggregated components, end-user devices, and the like.

[0034] Security is an important and integral part of wireless communications. Advances in quantum computing may represent a future risk to existing cryptographic-based security methods. Furthermore, due to latency issues, some scheduled downlink transmissions may not be protected by cryptographic-based security. Without adequate security measures, a malicious intruder (e.g., an adversary transmitter) may challenge or even hijack (e.g., spoof) unprotected transmissions by forging transmissions associated with the same format as legitimate transmissions. Without Layer 1 (L1) (i.e., physical layer) security, a UE may not be able to distinguish between genuine (legitimate) transmissions and forged transmissions.

[0035] One or more aspects of the present disclosure may involve adding an additional layer of security in L1. The presence of physical layer security may provide an additional layer of security to counter quantum threats. Furthermore, where applicable, the use of physical layer security may help reduce the load in Layer 3 (L3) and, therefore, may help reduce latency and overhead. Furthermore, the use of physical layer security may help reduce the chances of falling victim to malicious intruders targeting protocols at layers below L3. In one or more configurations, a legitimate transmitter may add scrambling in L1 when transmitting a physical channel or timeslot. Thus, a receiver may identify whether a transmission is from a legitimate transmitter based on detecting whether the transmission contains the expected scrambling in L1.

[0036] Figure 1 1 is a diagram illustrating an example of a wireless communication system and access network 100. The wireless communication system (also referred to as a wireless wide area network (WWAN)) includes a base station 102, a UE 104, an evolved packet core (EPC) 160, and another core network 190 (e.g., a 5G core (5GC)). The base station 102 may include a macro cell (a high-power cellular base station) and / or a small cell (a low-power cellular base station). A macro cell includes a base station. Small cells include femto cells, pico cells, and micro cells.

[0037] A base station 102 configured for 4G LTE (collectively referred to as the Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN)) may interface with the EPC 160 via a first backhaul link 132 (e.g., an S1 interface). A base station 102 configured for 5G NR (collectively referred to as the Next Generation RAN (NG-RAN)) may interface with the core network 190 via a second backhaul link 184. The base station 102 may perform, among other functions, one or more of the following: delivery of user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, distribution of non-access stratum (NAS) messages, NAS node selection, synchronization, radio access network (RAN) sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracking, RAN information management (RIM), paging, positioning, and delivery of warning messages. Base stations 102 can communicate with each other directly or indirectly (eg, via EPC 160 or core network 190) via a third backhaul link 134 (eg, an X2 interface). First backhaul link 132, second backhaul link 184, and third backhaul link 134 can be wired or wireless.

[0038] Base stations 102 can communicate wirelessly with UEs 104. Each of base stations 102 can provide communication coverage for a corresponding geographic coverage area 110. There may be overlapping geographic coverage areas 110. For example, a small cell 102′ can have a coverage area 110′ that overlaps with the coverage area 110 of one or more macro base stations 102. A network that includes both small cells and macro cells can be referred to as a heterogeneous network. A heterogeneous network can also include home evolved Node Bs (eNBs) (HeNBs), which can provide service to a restricted group called a closed subscriber group (CSG). The communication link 120 between base station 102 and UE 104 can include uplink (UL) (also known as reverse link) transmissions from UE 104 to base station 102 and / or downlink (DL) (also known as forward link) transmissions from base station 102 to UE 104. The communication link 120 can use multiple-input multiple-output (MIMO) antenna technology, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link can be over one or more carriers. For each carrier allocated in the carrier aggregation for up to Yx MHz (x component carriers) in total for transmission in each direction, the base station 102 / UE 104 can use spectrum with a bandwidth of up to Y MHz (e.g., 5 MHz, 10 MHz, 15 MHz, 20 MHz, 100 MHz, 400 MHz, etc.). The carriers may be adjacent to each other or may not be adjacent to each other. The allocation of carriers may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be allocated for DL ​​compared to UL). The component carriers may include a primary component carrier and one or more secondary component carriers. The primary component carrier may be referred to as a primary cell (PCell) and the secondary component carriers may be referred to as secondary cells (SCells).

[0039] Some UEs 104 may communicate with each other using device-to-device (D2D) communication links 158. The D2D communication links 158 may use DL / UL WWAN spectrum. The D2D communication links 158 may use one or more sidelink channels, such as a physical sidelink broadcast channel (PSBCH), a physical sidelink discovery channel (PSDCH), a physical sidelink shared channel (PSSCH), and a physical sidelink control channel (PSCCH). D2D communication may be accomplished through various wireless D2D communication systems, such as, for example, WiMedia, Bluetooth, ZigBee, Wi-Fi based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, LTE, or NR.

[0040] The wireless communication system may also include a Wi-Fi access point (AP) 150 that communicates with a Wi-Fi station (STA) 152 via a communication link 154, e.g., in a 5 GHz unlicensed spectrum, etc. When communicating in the unlicensed spectrum, the STA 152 / AP 150 may perform a clear channel assessment (CCA) to determine whether the channel is available before communicating.

[0041] The small cell 102' can operate in licensed and / or unlicensed spectrum. When operating in the unlicensed spectrum, the small cell 102' can adopt NR and use the same unlicensed spectrum (e.g., 5 GHz, etc.) used by the Wi-Fi AP 150. The small cell 102' adopting NR in the unlicensed spectrum can improve the coverage of the access network and / or increase the capacity of the access network.

[0042] The electromagnetic spectrum is typically subdivided into various categories, bands, channels, etc. based on frequency / wavelength. In 5G NR, two initial operating bands have been identified as frequency range designations FR1 (410 MHz - 7.125 GHz) and FR2 (24.25 GHz - 52.6 GHz). Although a portion of FR1 is greater than 6 GHz, FR1 is often (interchangeably) referred to as the "sub-6 GHz" band in various documents and articles. A similar naming issue sometimes occurs with respect to FR2, which is often (interchangeably) referred to as the "millimeter wave" band in documents and articles, although it is different from the extremely high frequency (EHF) band (30 GHz - 300 GHz) identified as the "millimeter wave" band by the International Telecommunication Union (ITU).

[0043] Frequencies between FR1 and FR2 are generally referred to as mid-band frequencies. Recent 5G NR research has identified the operating bands for these mid-band frequencies as frequency range designation FR3 (7.125GHz-24.25GHz). The frequency bands falling within FR3 can inherit FR1 characteristics and / or FR2 characteristics, and thus the features of FR1 and / or FR2 can be effectively extended to mid-band frequencies. In addition, higher frequency bands are currently being explored to extend 5G NR operation to more than 52.6GHz. For example, three higher operating bands have been identified as frequency range designations FR2-2 (52.6GHz-71GHz), FR4 (71GHz-114.25GHz), and FR5 (114.25GHz-300GHz). Each of these higher frequency bands falls within the EHF band.

[0044] In view of the above aspects, unless otherwise specified, it should be understood that if the term "sub-6 GHz" or the like is used herein, it can be broadly referred to as frequencies that may be less than 6 GHz, may be within FR1, or may include mid-band frequencies. In addition, unless otherwise specified, it should be understood that if the term "millimeter wave" or the like is used herein, it can be broadly referred to as frequencies that may include mid-band frequencies, may be within FR2, FR4, FR2-2 and / or FR5, or may be within the EHF band.

[0045] Base station 102 (whether a small cell 102' or a large cell (e.g., a macro base station)) may include and / or be referred to as an eNB, gNodeB (gNB), or another type of base station. Some base stations, such as gNB 180, may operate in traditional sub-6 GHz spectrum, in millimeter wave frequencies, and / or near millimeter wave frequencies to communicate with UE 104. When gNB 180 operates in millimeter wave or near millimeter wave frequencies, gNB 180 may be referred to as a millimeter wave base station. Millimeter wave base station 180 may utilize beamforming 182 with UE 104 to compensate for path loss and short range. Base station 180 and UE 104 may each include multiple antennas (such as antenna elements, antenna panels, and / or antenna arrays) to facilitate beamforming.

[0046] Base station 180 may transmit beamformed signals in one or more transmit directions 182′ to UE 104. UE 104 may receive beamformed signals from base station 180 in one or more receive directions 182″. UE 104 may also transmit beamformed signals in one or more transmit directions to base station 180. Base station 180 may receive beamformed signals in one or more receive directions from UE 104. Base station 180 / UE 104 may perform beam training to determine the best receive direction and transmit direction for each of base station 180 / UE 104. The transmit direction and receive direction of base station 180 may be the same or different. The transmit direction and receive direction of UE 104 may be the same or different.

[0047] EPC 160 may include a Mobility Management Entity (MME) 162, other MMEs 164, a Serving Gateway 166, a Multimedia Broadcast Multicast Service (MBMS) Gateway 168, a Broadcast Multicast Service Center (BM-SC) 170, and a Packet Data Network (PDN) Gateway 172. MME 162 may communicate with a Home Subscriber Server (HSS) 174. MME 162 is a control node that handles signaling between UE 104 and EPC 160. Generally speaking, MME 162 provides bearer and connection management. All user Internet Protocol (IP) packets are passed through Serving Gateway 166, which itself is connected to PDN Gateway 172. PDN Gateway 172 provides UE IP address allocation and other functions. PDN Gateway 172 and BM-SC 170 are connected to IP Services 176. IP Services 176 may include the Internet, an intranet, an IP Multimedia Subsystem (IMS), PS streaming services, and / or other IP services. BM-SC 170 can provide functionality for configuring and delivering MBMS user services. BM-SC 170 can serve as the entry point for content providers' MBMS delivery, authorize and initiate MBMS bearer services in the Public Land Mobile Network (PLMN), and schedule MBMS delivery. MBMS Gateway 168 can distribute MBMS services to base stations 102 within a Multicast Broadcast Single Frequency Network (MBSFN) area that broadcasts specific services, and can be responsible for session management (start / stop) and collecting eMBMS-related billing information.

[0048] Core network 190 may include access and mobility management function (AMF) 192, other AMFs 193, session management function (SMF) 194, and user plane function (UPF) 195. AMF 192 may communicate with unified data management (UDM) 196. AMF 192 is a control node that handles signaling between UE 104 and core network 190. Generally speaking, AMF 192 provides QoS flow and session management. All user Internet Protocol (IP) packets are passed through UPF 195. UPF 195 provides UE IP address allocation and other functions. UPF 195 is connected to IP services 197. IP services 197 may include the Internet, intranet, IP multimedia subsystem (IMS), packet switched (PS) streaming (PSS) services, and / or other IP services.

[0049] A base station may include and / or be referred to as a gNB, Node B, eNB, access point, base transceiver station, radio base station, radio transceiver, transceiver functionality, basic service set (BSS), extended service set (ESS), transmit receive point (TRP), or some other suitable terminology. Base station 102 provides an access point to EPC 160 or core network 190 for UE 104. Examples of UE 104 include a cellular phone, a smartphone, a Session Initiation Protocol (SIP) phone, a laptop, a personal digital assistant (PDA), a satellite radio, a global positioning system, a multimedia device, a video device, a digital audio player (e.g., an MP3 player), a camera, a game console, a tablet, a smart device, a wearable device, a vehicle, an electric meter, a gas pump, a large or small kitchen appliance, a healthcare device, an implant, a sensor / actuator, a display, or any other similarly functional device. Some of UE 104 may be referred to as IoT devices (e.g., a parking meter, a gas pump, a toaster, a vehicle, a heart monitor, etc.). UE 104 may also be referred to as a station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other suitable terminology. In some scenarios, the term UE may also apply to one or more supporting devices, such as in a device cluster arrangement. One or more of these devices may access a network collectively and / or individually.

[0050] Reference again Figure 1In certain aspects, UE 104 may include a physical layer security component 198 configured to receive at least one reference signal from a transmitter via a downlink channel. Physical layer security component 198 may be configured to estimate an AM / PM impairment signature in the at least one reference signal. Physical layer security component 198 may be configured to identify whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature. Physical layer security component 198 may be configured to maintain or discard at least one timeslot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. In certain aspects, base station / network node 180 may include a physical layer security component 199 configured to select a reference AM / PM impairment signature. Physical layer security component 199 may be configured to send a first indication of the reference AM / PM impairment signature to the UE via a security signal. Physical layer security component 199 may be configured to send at least one reference signal to the UE via a downlink channel. The at least one reference signal may include added AM / PM impairments based on the reference AM / PM impairment signature. Although the following description may focus on 5G NR, the concepts described herein may be applicable to other similar areas such as LTE, LTE-A, CDMA, GSM, and other wireless technologies.

[0051] Figure 2A FIG200 is a diagram illustrating an example of a first subframe within a 5G NR frame structure. Figure 2B FIG230 is a diagram illustrating an example of DL channels within a 5G NR subframe. Figure 2C FIG250 is a diagram illustrating an example of a second subframe within a 5G NR frame structure. Figure 2D FIG280 is a diagram illustrating an example of UL channels within a 5G NR subframe. The 5G NR frame structure may be frequency division duplex (FDD) (wherein, for a particular set of subcarriers (carrier system bandwidth), subframes within that subcarrier set are dedicated to either DL or UL), or may be time division duplex (TDD) (wherein, for a particular set of subcarriers (carrier system bandwidth), subframes within that subcarrier set are dedicated to both DL and UL). Figure 2A 、 Figure 2CIn the example provided, the 5G NR frame structure is assumed to be TDD, where subframe 4 is configured with slot format 28 (most of which are DL), where D is DL, U is UL, and F is flexible between DL / UL, and subframe 3 is configured with slot format 1 (all of which are UL). Although subframes 3 and 4 are shown as having slot formats 1 and 28, respectively, any particular subframe can be configured with any of the various available slot formats 0 to 61. Slot formats 0 and 1 are all DL and all UL, respectively. Other slot formats 2 to 61 include a mix of DL, UL, and flexible symbols. The slot format is configured for the UE via a received slot format indicator (SFI) (dynamically configured via DL control information (DCI) or semi-statically / statically configured via radio resource control (RRC) signaling). Note that the following description also applies to the 5G NR frame structure as TDD.

[0052] Figures 2A to 2D The frame structure is illustrated, and various aspects of the present disclosure are applicable to other wireless communication technologies that may have different frame structures and / or different channels. A frame (10ms) can be divided into 10 equally sized subframes (1ms). Each subframe may include one or more time slots. A subframe may also include a mini-time slot, which may include 7, 4, or 2 symbols. Each time slot may include 14 or 12 symbols, depending on whether the cyclic prefix (CP) is normal or extended. For a normal CP, each time slot may include 14 symbols, and for an extended CP, each time slot may include 12 symbols. The symbols on the DL may be CP orthogonal frequency division multiplexing (OFDM) (CP-OFDM) symbols. The symbols on the UL may be CP-OFDM symbols (for high throughput scenarios) or discrete Fourier transform (DFT) spread OFDM (DFT-s-OFDM) symbols (also known as single carrier frequency division multiple access (SC-FDMA) symbols) (for power-limited scenarios; limited to single-stream transmission). The number of time slots within a subframe is based on the CP and parameter set. The parameter set defines the subcarrier spacing (SCS) and effectively defines the symbol length / duration, which is equal to 1 / SCS.

[0053]

[0054] Table 1. Parameter sets, SCS, and CP

[0055] For normal CP (14 symbols / slot), different parameter sets (μ) 0 to 4 allow 1, 2, 4, 8, and 16 slots per subframe, respectively. For extended CP, parameter set 2 allows 4 slots per subframe. Therefore, for normal CP and parameter set μ, there are 14 symbols / slot and 2 μ time slots / subframe. The subcarrier spacing can be equal to 2μ *15kHz, where μ is parameter set 0 to 4. Thus, parameter set μ=0 has a subcarrier spacing of 15kHz, and parameter set μ=4 has a subcarrier spacing of 240kHz. Symbol length / duration is inversely related to subcarrier spacing. Figures 2A to 2D An example is provided for a normal CP with 14 symbols per slot and a parameter set μ=2 with 4 slots per subframe. The slot duration is 0.25 ms, the subcarrier spacing is 60 kHz, and the symbol duration is approximately 16.67 μs. Within a frame set, there may be one or more different bandwidth parts (BWPs) that are frequency-division multiplexed (see Figure 2B ). Each BWP can have a specific parameter set and CP (normal or extended).

[0056] A resource grid can be used to represent the frame structure. Each slot includes a resource block (RB) (also known as a physical RB (PRB)) extending over 12 consecutive subcarriers. The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.

[0057] like Figure 2A As illustrated, some of the REs carry reference (pilot) signals (RS) for the UE. The RS may include a demodulation RS (DM-RS or DMRS) (indicated as R for a specific configuration, but other DM-RS configurations are possible) and a channel state information reference signal (CSI-RS) for channel estimation at the UE. The RS may also include a beam measurement RS (BRS), a beam refinement RS (BRRS), and a phase tracking RS (PT-RS).

[0058] Figure 2BExamples of various DL channels within a subframe of a frame are illustrated. The physical downlink control channel (PDCCH) carries DCI within one or more control channel elements (CCEs) (e.g., 1, 2, 4, 8, or 16 CCEs), each CCE comprising six RE groups (REGs), each REG comprising 12 consecutive REs in an OFDM symbol of an RB. The PDCCH within a BWP may be referred to as a control resource set (CORESET). The UE is configured to monitor PDCCH candidates in a PDCCH search space (e.g., a common search space, a UE-specific search space) during a PDCCH monitoring opportunity on the CORESET, where the PDCCH candidates have different DCI formats and different aggregation levels. Additional BWPs may be located at higher and / or lower frequencies across the channel bandwidth. The primary synchronization signal (PSS) may be within symbol 2 of a specific subframe of a frame. The PSS is used by the UE 104 to determine subframe / symbol timing and physical layer identification. The secondary synchronization signal (SSS) may be within symbol 4 of a specific subframe of a frame. The SSS is used by the UE to determine the physical layer cell identity group number and radio frame timing. Based on the physical layer identity and the physical layer cell identity group number, the UE can determine the physical cell identifier (PCI). Based on the PCI, the UE can determine the location of the DM-RS. The physical broadcast channel (PBCH) carrying the master information block (MIB) can be logically grouped with the PSS and SSS to form a synchronization signal (SS) / PBCH block (also known as an SS block (SSB)). The MIB provides the number of RBs in the system bandwidth and the system frame number (SFN). The physical downlink shared channel (PDSCH) carries user data, broadcast system information not sent through the PBCH, such as the system information block (SIB), and paging messages.

[0059] like Figure 2C As illustrated, some of the REs carry DM-RS (indicated as R for a specific configuration, but other DM-RS configurations are possible) for channel estimation at the base station. The UE may transmit the DM-RS of the physical uplink control channel (PUCCH) and the DM-RS of the physical uplink shared channel (PUSCH). The PUSCH DM-RS may be transmitted in the first or first two symbols of the PUSCH. Depending on whether a short PUCCH or a long PUCCH is transmitted and depending on the specific PUCCH format used, the PUCCH DM-RS may be transmitted in different configurations. The UE may transmit a sounding reference signal (SRS). The SRS may be transmitted in the last symbol of the subframe. The SRS may have a comb structure, and the UE may transmit the SRS on one of the comb structures in the comb structure. The SRS may be used by the base station for channel quality estimation to achieve frequency-dependent scheduling of the UL.

[0060] Figure 2DExamples of various UL channels within a subframe of a frame are illustrated. The PUCCH may be located at a position as indicated in one configuration. The PUCCH carries uplink control information (UCI), such as a scheduling request, a channel quality indicator (CQI), a precoding matrix indicator (PMI), a rank indicator (RI), and hybrid automatic repeat request (HARQ) acknowledgement (ACK) (HARQ-ACK) feedback (i.e., one or more HARQ ACK bits indicating one or more ACKs and / or negative ACKs (NACKs)). The PUSCH carries data and may additionally be used to carry a buffer status report (BSR), a power headroom report (PHR), and / or UCI.

[0061] Figure 3 3 is a block diagram of a base station 310 in an access network communicating with a UE 350. In the DL, IP packets from the EPC 160 may be provided to the controller / processor 375. The controller / processor 375 implements layer 3 and layer 2 functionality. Layer 3 includes the radio resource control (RRC) layer, and layer 2 includes the service data adaptation protocol (SDAP) layer, the packet data convergence protocol (PDCP) layer, the radio link control (RLC) layer, and the medium access control (MAC) layer. The controller / processor 375 provides RRC layer functionality associated with broadcasting of system information (e.g., MIB, SIB), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-radio access technology (RAT) mobility, and measurement configuration for UE measurement reporting; PDCP layer functionality associated with header compression / decompression, security (ciphering, deciphering, integrity protection, integrity verification), and handover support functions; RLC layer functionality associated with delivery of upper layer packet data units (PDUs), error correction through ARQ, concatenation, segmentation and reassembly of RLC service data units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction through HARQ, priority handling, and logical channel prioritization.

[0062] The transmit (TX) processor 316 and receive (RX) processor 370 implement Layer 1 functionality associated with various signal processing functions. Layer 1, which includes the physical (PHY) layer, may include error detection on the transport channel, forward error correction (FEC) coding / decoding of the transport channel, interleaving, rate matching, mapping onto the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. The TX processor 316 handles the mapping onto signal constellations based on various modulation schemes (e.g., binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), M-order phase shift keying (M-PSK), and M-order quadrature amplitude modulation (M-QAM)). The coded and modulated symbols may then be separated into parallel streams. Each stream may then be mapped to an OFDM subcarrier, multiplexed with a reference signal (e.g., a pilot) in the time and / or frequency domain, and then combined using an inverse fast Fourier transform (IFFT) to produce a physical channel carrying a time-domain OFDM symbol stream. The OFDM stream is spatially pre-coded to produce multiple spatial streams. Channel estimates from a channel estimator 374 may be used to determine the coding and modulation schemes, as well as for spatial processing. The channel estimates may be derived from a reference signal and / or channel state feedback transmitted by the UE 350. Each spatial stream may then be provided to a different antenna 320 via a separate transmitter 318TX. Each transmitter 318TX may modulate a radio frequency (RF) carrier with a corresponding spatial stream for transmission.

[0063] At the UE 350, each receiver 354RX receives a signal via its corresponding antenna 352. Each receiver 354RX recovers the information modulated onto the RF carrier and provides the information to a receive (RX) processor 356. The TX processor 368 and the RX processor 356 implement layer 1 functionality associated with various signal processing functions. The RX processor 356 can perform spatial processing on the information to recover any spatial streams destined for the UE 350. If multiple spatial streams are destined for the UE 350, they can be combined into a single OFDM symbol stream by the RX processor 356. The RX processor 356 then converts the OFDM symbol stream from the time domain to the frequency domain using a fast Fourier transform (FFT). The frequency domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, as well as the reference signal, are recovered and demodulated by determining the most likely signal constellation point transmitted by the base station 310. These soft decisions can be based on channel estimates calculated by the channel estimator 358. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally sent on the physical channel by base station 310. The data and control signals are then provided to controller / processor 359, which implements layer 3 and layer 2 functionality.

[0064] The controller / processor 359 may be associated with a memory 360 that stores program codes and data. The memory 360 may be referred to as a computer-readable medium. In the UL, the controller / processor 359 provides demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets from the EPC 160. The controller / processor 359 is also responsible for error detection using ACK and / or NACK protocols to support HARQ operations.

[0065] Similar to the functionality described in conjunction with DL transmissions performed by the base station 310, the controller / processor 359 provides RRC layer functionality associated with system information (e.g., MIB, SIB) acquisition, RRC connection, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with delivery of upper layer PDUs, error correction through ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto TBs, demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction through HARQ, priority handling, and logical channel prioritization.

[0066] The TX processor 368 may use channel estimates derived by the channel estimator 358 from a reference signal or feedback transmitted by the base station 310 to select appropriate coding and modulation schemes and to facilitate spatial processing. The spatial streams generated by the TX processor 368 may be provided to different antennas 352 via separate transmitters 354TX. Each transmitter 354TX may modulate an RF carrier with a corresponding spatial stream for transmission.

[0067] UL transmissions are processed at the base station 310 in a manner similar to that described in conjunction with the receiver functionality at the UE 350. Each receiver 318RX receives a signal through its respective antenna 320. Each receiver 318RX recovers information modulated onto an RF carrier and provides the information to an RX processor 370.

[0068] The controller / processor 375 may be associated with a memory 376 that stores program codes and data. The memory 376 may be referred to as a computer-readable medium. In the UL, the controller / processor 375 provides demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets from the UE 350. The IP packets from the controller / processor 375 may be provided to the EPC 160. The controller / processor 375 is also responsible for error detection using an ACK and / or NACK protocol to support HARQ operations.

[0069] At least one of the TX processor 368, the RX processor 356, and the controller / processor 359 may be configured to combine Figure 1 The 198 came to perform all aspects.

[0070] At least one of the TX processor 316, the RX processor 370, and the controller / processor 375 may be configured to combine Figure 1 199 to perform all aspects.

[0071] The network nodes herein may be implemented as converged base stations, decomposed base stations, integrated access and backhaul (IAB) nodes, relay nodes, sidelink nodes, etc. The network nodes / entities may be implemented in a converged or monolithic base station architecture, or alternatively in a decomposed base station architecture, and may include one or more of a central unit (CU), a distributed unit (DU), a radio unit (RU), a near real-time (near-RT) RAN intelligent controller (RIC), or a non-real-time (non-RT) RIC.

[0072] Security is an important and integral part of wireless communications. Communication security can be used to protect confidential or sensitive information (such as personal data) or in diverse applications, such as business applications (e.g., finance, healthcare, and pharmaceuticals), government organizations, the military, or social networking applications.

[0073] In some configurations, link security can be achieved using cryptography that can provide security via higher layer (e.g., L3 or higher) algorithms. One advantage associated with cryptographic-based security can be that hacking the cryptographic algorithm can take a long time, making the cryptographic algorithm considered virtually unbreakable. On the other hand, disadvantages associated with cryptographic-based security can include that the cryptographic algorithm can introduce significant overhead, especially for small packets, and can increase latency. For example, a 256-bit or 128-bit security key can add significant overhead when sending small packets and can determine a lower limit.

[0074] Furthermore, advances in quantum computing could represent a future risk for existing cryptography-based methods. In particular, quantum mechanics can exploit features such as superposition, whereby qubits can exist in a combination of several states simultaneously, which could hypothetically reduce the complexity of exhaustive hacking attacks from exponential to linear complexity.

[0075] In addition, due to latency issues, some scheduled downlink transmissions may not be protected by cryptographic-based security. For example, such downlink transmissions may include MAC signaling (e.g., MAC-Control Element (MAC-CE)), for which low communication latency may be more important than reliability. Examples of downlink transmissions not protected by cryptographic-based security may also include broadcast information (e.g., SIB) and paging information.

[0076] Without adequate security measures, a malicious intruder (e.g., an adversary transmitter) may challenge or even hijack (e.g., spoof) an unprotected transmission by forging a transmission associated with the same format as a legitimate transmission (e.g., a PDCCH or PDSCH transmission). Without L1 (i.e., physical layer) security, the UE may not be able to distinguish between real (legitimate) transmissions and forged transmissions.

[0077] One or more aspects of the present disclosure may involve adding an additional layer of security at L1. Physical layer security may not completely replace L3-based security. However, physical layer security can be associated with many improvements compared to scenarios where physical layer security is not utilized. For example, the presence of physical layer security can provide an additional layer of security to address quantum threats. Furthermore, where applicable, the use of physical layer security can help reduce the load at L3 and, therefore, help reduce latency and overhead. Furthermore, the use of physical layer security can help reduce the chances of falling victim to malicious intruders targeting protocols at layers below L3.

[0078] In one or more configurations, a legitimate transmitter may add scrambling in L1 when transmitting a physical channel or time slot. Thus, a receiver may identify whether a transmission is from a legitimate transmitter based on detecting whether the transmission contains the expected scrambling in L1.

[0079] In one or more configurations, physical layer security representing an additional layer of security may be based on (natural or artificial) amplitude modulation to phase modulation (AM / PM) impairments. Natural AM / PM impairments may be physical impairments that may be naturally present in almost every power amplifier. For example, the function for AM / PM impairments may be f(x) = |x|·e j·φ(|x|) , where x can be a time domain signal, may be an AM / PM mapping, and f(x) may be an operator including AM / PM.

[0080] AM / PM impairments may not be energy impairments. Therefore, adding AM / PM impairments may not consume any additional power, which can make AM / PM impairments a good candidate for physical layer security. However, using AM / PM impairments may impose constraints on error vector magnitude (EVM) and / or out-of-band emissions.

[0081] In one or more configurations, natural AM / PM impairments can be used for physical layer security. Because natural AM / PM impairments may be present in virtually all power amplifiers, a receiver can determine whether a transmission is legitimate by comparing the AM / PM impairment signature associated with the transmission with a reference (anchor) natural AM / PM impairment signature associated with a legitimate transmitter. If the AM / PM impairment signature associated with the transmission does not match the reference natural AM / PM impairment signature associated with a legitimate transmitter, the receiver can classify the transmission as a malicious attack and can therefore perform further action (e.g., the receiver can discard or drop the transmission).

[0082] Figure 4 is a diagram 400 illustrating an example AM / PM impairment model. In diagram 400, the x-axis may correspond to AM and the y-axis may correspond to PM. Additionally, a and β may be parameters representing the example AM / PM mapping model. Diagram 400 may correspond to the formula In some examples, natural AM / PM impairments may not be used for physical layer security because Figure 4 As shown, the example natural AM / PM impairment model can be similar for all options, where each option can correspond to a value for a. Therefore, the trade-off between false positives (e.g., failing to detect a transmission from an intruder) and false negatives (e.g., discarding a transmission from a legitimate transmitter) can be unsatisfactory. Furthermore, using natural AM / PM impairments for physical layer security can be undesirable because digital pre-distortion (DPD) can be applied at the transmitter (without DPD, out-of-band emissions due to natural AM / PM impairments can violate regulations), which can significantly reduce or eliminate the natural AM / PM impairments (i.e., setting the natural AM / PM impairment signature to zero or near zero). Consequently, no distinguishable natural AM / PM impairment signature can be left in legitimate transmissions for the receiver to identify.

[0083] In one or more configurations, artificial AM / PM impairments can be intentionally added to transmissions at a transmitter for physical layer security purposes. Thus, a receiver can determine whether a transmission is legitimate by comparing the AM / PM impairment signature associated with the transmission with a reference (anchor) artificial AM / PM impairment signature associated with a legitimate transmitter. In one or more configurations, because AM / PM impairments are not energy-constrained, artificial AM / PM impairments can be added in the time domain in the baseband domain of the transmitter.

[0084] In one configuration, the artificial AM / PM impairment may be added at a digital-to-analog converter (DAC) rate (e.g., the sampling rate of the DAC). Adding the artificial AM / PM impairment at the DAC rate may make the artificial AM / PM impairment appear more natural (e.g., more closely resemble the natural AM / PM impairment introduced by the power amplifier). However, adding the artificial AM / PM impairment at the DAC rate may result in a violation of out-of-band emission regulations. Therefore, in one configuration, the artificial AM / PM impairment may be added at the baseband rate. Adding the artificial AM / PM impairment at the baseband rate may be useful, at least for FR1, where compliance with out-of-band emission regulations may be challenging. In one or more configurations, adding the artificial AM / PM impairment may not be associated with any (significant) power consumption.

[0085] Furthermore, in one or more configurations, DPD can be used to at least partially cancel natural AM / PM impairments. When natural AM / PM impairments are canceled, a transmitter (e.g., a network node) can better control the overall AM / PM impairment characteristics of a transmission by controlling artificial AM / PM impairments added in the baseband digital domain.

[0086] Figure 5 FIG. 5 is a diagram of a communication flow 500 of a method for wireless communication according to one or more aspects. Figure 5 As shown, the network node 504 may transmit (e.g., broadcast) a safety RS 506 (SERS) to the UE 502. The SERS 506 may include added artificial AM / PM impairments and may be used to indicate to the UE 502 a reference AM / PM impairment signature associated with the network node 504. The SERS 506 may be different from the SERS described above with respect to Figures 2A to 2CIn some examples, the process for selecting a reference AM / PM impairment signature can be pre-specified or pre-configured. In some configurations, the network node 504 can periodically (e.g., more than once, with a period / frequency) or occasionally send the SERS 506. Furthermore, the artificial AM / PM impairments included in the SERS 506 can be updated or refreshed (changed) periodically or occasionally. At 508, the UE 502 can estimate the AM / PM impairments included in the SERS 506 and can store or remember the AM / PM impairments included in the SERS 506 as a reference AM / PM impairment signature associated with the network node 504.

[0087] When the UE 502 is not in connected mode (e.g., when the UE 502 is in idle mode) and does not have any higher layer communications or traffic, it may be appropriate or advantageous for the network node 504 to use SERS to indicate the reference AM / PM impairment signature. In one or more configurations, when the UE 502 is in an RRC connected state (RRC_connected), the network node 504 may indicate the reference AM / PM impairment signature to the UE 502 via higher layer communications (e.g., RRC signaling). It will be appreciated that increasing the frequency of reference AM / PM impairment signature updates or refreshes may improve security because an intruder may have less time to sniff and identify the reference AM / PM impairment signature before the next reference AM / PM impairment signature update / refresh and may therefore be more challenging.

[0088] Thereafter, the network node 504 may transmit downlink traffic (e.g., a time slot including a PDSCH and / or a PDCCH) that may include an RS (e.g., a DMRS) to the UE 502. In one configuration, when transmitting the downlink traffic, the network node 504 may add an artificial AM / PM impairment signature to the RS. The artificial AM / PM impairment signature added to the RS may be the same as the artificial AM / PM impairment included in the SERS 506. In one or more configurations, for additional security, the network node 504 may also add the artificial AM / PM impairment signature to at least one data portion of the downlink traffic.

[0089] Thus, at 510 , UE 502 may estimate an AM / PM impairment signature associated with the RS and may compare the AM / PM impairment signature associated with the RS with a reference AM / PM impairment signature associated with network node 504 at 512 .

[0090] If the AM / PM impairment signature associated with the RS matches the reference AM / PM impairment signature associated with the network node 504 (i.e., the AM / PM impairment signatures are identical), then at 514, the UE 502 may (e.g., after removing the AM / PM impairment) retain and use the time slot corresponding to the downlink traffic because the time slot may have been received from the legitimate network node 504. Otherwise, if the AM / PM impairment signature associated with the RS does not match the reference AM / PM impairment signature associated with the network node 504 (i.e., the AM / PM impairment signatures are different), then at 516, the UE 502 may discard or drop the time slot corresponding to the downlink traffic because the time slot may have been received from an adversary transmitter (not shown). The UE 502 may discard or drop the time slot by refraining from decoding or otherwise further processing the time slot.

[0091] Figure 6 6 is a block diagram illustrating the addition of artificial AM / PM impairments according to one or more aspects. Adding artificial AM / PM impairments in the oversampled domain (e.g., the output of the digital front end (DFE) block 608, also referred to as the DAC input) may introduce out-of-band leakage, which may result in violations of adjacent channel leakage ratio (ACLR) specifications. Therefore, in one or more configurations, artificial AM / PM impairments may be added in the baseband domain at block 604 between the IFFT block 602 and the DFE block 608.

[0092] Because the artificial AM / PM impairments are introduced into the baseband domain, all impairments are folded into the band, which can be associated with a cost in terms of EVM. In addition, the added artificial AM / PM impairments can be removed at the receiver. However, due to other impairments (e.g., thermal noise, channel noise, etc.), the removal of the artificial AM / PM impairments at the receiver may not be perfect. In one or more configurations, if the artificial AM / PM impairments are also added to at least one data portion of the downlink traffic (e.g., PDSCH and / or PDCCH), a digital post-distortion (DPoD) technique (which can be applied iteratively) can be utilized to improve (e.g., reduce) the EVM associated with the at least one data portion of the downlink traffic.

[0093] In one or more configurations, the addition of artificial AM / PM impairment at the transmitter may be expressed using the following formula:

[0094] x[n]=|x[n]|·e -j·φ(|x[n]|)

[0095]

[0096] Where a can be the number of periods of the sine function, D can be the delay, F can be the frequency, and A mCan be amplitude. Increase F, a and / or A m The value of can make it more difficult for an attacker (also referred to as an adversary transmitter) to repair (e.g., remove) the added artificial AM / PM impairment signature, thereby improving security. However, it should be understood that there can be a trade-off between security and signal-to-noise ratio (SNR). However, in practice, even when the attacker knows the range of possible artificial AM / PM impairment signatures, a security improvement of over 90% can be achieved with very little performance loss.

[0097] Figure 7A is a diagram 700A illustrating an example scenario in which an AM / PM impairment signature associated with an RS in downlink traffic matches a reference AM / PM impairment signature associated with a legitimate transmitter. Figure 7B FIG700B is a diagram illustrating an example scenario in which the AM / PM impairment signature associated with the RS in the downlink traffic does not match the reference AM / PM impairment signature associated with the legitimate transmitter. Figure 7A and Figure 7B In the two scenarios illustrated in , single symbol processing can be used.

[0098] Re-reference Figure 5 In one or more configurations, when the UE 502 compares the AM / PM impairment signature associated with the RS with a reference AM / PM impairment signature associated with the network node 504 at 512, the UE 502 may identify a correlation amount (correlation metric) associated with a correlation between the AM / PM impairment signature associated with the RS and the reference AM / PM impairment signature associated with the network node 504. If the correlation amount is greater than a threshold, the UE 502 may identify that the AM / PM impairment signature associated with the RS matches the reference AM / PM impairment signature associated with the network node 504. On the other hand, if the correlation amount is less than the threshold, the UE 502 may identify that the AM / PM impairment signature associated with the RS does not match the reference AM / PM impairment signature associated with the network node 504.

[0099] In one or more examples, the correlation metric may be identified based on a maximum ratio combining (MRC) method, where a larger weight may be given to a larger magnitude. In particular, in one non-limiting example, the correlation metric may be identified based on the following formula:

[0100]

[0101] where am may be the corresponding amplitude, and rms may be the root mean square (quadratic average).

[0102] Figure 8800 is a block diagram illustrating an iterative DPoD process. In one or more configurations, iterative DPoD techniques can be utilized when the transmitter also adds artificial AM / PM impairment features to the data portion of the traffic. At the receiver, at 802, an AM / PM impairment model can be estimated. Based on the estimated AM / PM impairment model, an initial AM / PM impairment repair / removal 804 can be attempted, the results of which can be fed into a first FFT block 806 to perform DPoD. A hard decision (HD) block 816 can precede the IFFT block 808. Based on the output of the IFFT block 808, at 810, another estimate of the AM / PM impairment model can be performed. Subsequently, at 810, another AM / PM impairment repair / removal 812 can be attempted based on the additional AM / PM impairment model estimate. Thereafter, the results of the additional AM / PM impairment repair / removal 812 can be fed into a second FFT block 814 to perform additional DPoD. Thus, the DPoD process can be iteratively performed to remove artificial AM / PM impairments. It should be appreciated that DPoD techniques (regular or iterative) may work based on utilizing symbols belonging to a finite set in the frequency domain.

[0103] Figure 9 is an illustration of a communication flow 900 of a method of wireless communication.At 906, the network node 904 may select a reference AM / PM impairment signature.

[0104] At 908 , the network node 904 may send a first indication of a reference AM / PM impairment characteristic to the UE 902 via a secure signal, and the UE 902 may receive the first indication from the network node 904 via a secure signal.

[0105] In one or more configurations, the safety signal may correspond to SERS or RRC signaling.

[0106] At 910 , network node 904 may apply DPD to the downlink channel to at least partially remove natural AM / PM distortion associated with the power amplifier.

[0107] At 912, network node 904 may transmit at least one reference signal to UE 902 via a downlink channel, and UE 902 may receive at least one reference signal from network node 904 via the downlink channel. The at least one reference signal may include added AM / PM impairments based on a reference AM / PM impairment characteristic. In one configuration, the added AM / PM impairments may be added to the at least one reference signal in a baseband domain. In one configuration, the added AM / PM impairments may be further added by network node 904 to at least one data portion of the downlink channel.

[0108] At 912', UE 902 may receive at least one reference signal from enemy transmitter 904' via a downlink channel.

[0109] In one configuration, the at least one reference signal may be a DMRS.In one or more configurations, the downlink channel may be a PDCCH or a PDSCH.

[0110] At 914, UE 902 may estimate an AM / PM impairment characteristic in the at least one reference signal.

[0111] At 916, UE 902 may identify whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature.

[0112] In one configuration, whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature may be identified based on a correlation amount between the estimated AM / PM impairment signature and the reference AM / PM impairment signature. In one configuration, the correlation amount may be identified based on an MRC method.

[0113] At 918, UE 902 may maintain or drop at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature.

[0114] In one configuration, if the estimated AM / PM impairment signature matches a reference AM / PM impairment signature, the at least one time slot may be maintained. If the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the at least one time slot may be discarded. In one configuration, if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the transmitter may correspond to network node 904. If the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the transmitter may correspond to adversary transmitter 904'.

[0115] At 920, UE 902 may apply DPoD to at least one data portion of the downlink channel based on the reference AM / PM impairment signature.

[0116] At 922 , UE 902 may periodically receive further indications of updated reference AM / PM impairment signatures from network node 904 .

[0117] Figure 10 1000 is a flow chart of a method of wireless communication. The method may be performed by a UE (e.g., UE 104 / 350 / 502 / 902; apparatus 1402). At 1002, the UE may receive at least one reference signal from a transmitter via a downlink channel. For example, 1002 may be performed by Figure 14The physical layer security component 1440 is used to perform the above. Figure 9 At 912 or 912', the UE 902 may receive at least one reference signal from a transmitter (network node 904 or enemy transmitter 904') via a downlink channel.

[0118] At 1004, the UE may estimate the AM / PM impairment characteristics in the at least one reference signal. For example, 1004 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 914, UE 902 may estimate an AM / PM impairment characteristic in the at least one reference signal.

[0119] At 1006, the UE may identify whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. For example, 1006 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 916, UE 902 may identify whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature.

[0120] At 1008, the UE may maintain or drop at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. For example, 1008 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 918, UE 902 may maintain or drop at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature.

[0121] Figure 11 1100 is a flow chart of a method of wireless communication. The method may be performed by a UE (e.g., UE 104 / 350 / 502 / 902; apparatus 1402). At 1104, the UE may receive at least one reference signal from a transmitter via a downlink channel. For example, 1104 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 912 or 912', the UE 902 may receive at least one reference signal from a transmitter (network node 904 or enemy transmitter 904') via a downlink channel.

[0122] At 1106, the UE may estimate the AM / PM impairment characteristic in the at least one reference signal. For example, 1106 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9At 914, UE 902 may estimate an AM / PM impairment characteristic in the at least one reference signal.

[0123] At 1108, the UE may identify whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. For example, 1108 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 916, UE 902 may identify whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature.

[0124] At 1110, the UE may maintain or drop at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. For example, 1110 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 918, UE 902 may maintain or drop at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature.

[0125] In one configuration, if the estimated AM / PM impairment signature matches a reference AM / PM impairment signature, the at least one time slot may be maintained. If the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the at least one time slot may be discarded.

[0126] In one configuration, reference Figure 9 If the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the transmitter may correspond to network node 904. If the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the transmitter may correspond to adversary transmitter 904'.

[0127] In one configuration, at 1102, the UE may receive a first indication of a reference AM / PM impairment characteristic from a network node via a secure signal. For example, 1102 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 908, UE 902 may receive a first indication of a reference AM / PM impairment characteristic from network node 904 via a secure signal.

[0128] In one configuration, the safety signal may correspond to SERS or RRC signaling.

[0129] In one configuration, at 1114, the UE may periodically receive further indications of updated reference AM / PM impairment characteristics from the network node. For example, 1114 may be provided by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 922 , UE 902 may periodically receive further indications of updated reference AM / PM impairment signatures from network node 904 .

[0130] In one configuration, reference Figure 9 At 916 , it may be identified whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature based on an amount of correlation between the estimated AM / PM impairment signature and the reference AM / PM impairment signature.

[0131] In one configuration, the correlation amount may be identified based on an MRC method.

[0132] In one configuration, the at least one reference signal is a DMRS.

[0133] In one configuration, the downlink channel may be a PDCCH or a PDSCH.

[0134] In one configuration, at 1112, the UE may apply DPoD to at least one data portion of a downlink channel based on a reference AM / PM impairment signature. For example, 1112 may be performed by Figure 14 The physical layer security component 1440 is used to perform the above. Figure 9 At 920, UE 902 may apply DPoD to at least one data portion of a downlink channel based on a reference AM / PM impairment signature.

[0135] Figure 12 1200 is a flow chart of a method of wireless communication. The method may be performed by a network node (e.g., base station / network node 102 / 180 / 310; network node 504 / 904; device 1502). At 1202, the network node may select a reference AM / PM impairment signature. For example, 1202 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 906, the network node 904 may select a reference AM / PM impairment signature.

[0136] At 1204, the network node may send a first indication of a reference AM / PM impairment characteristic to the UE via a secure signal. For example, 1204 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 908, the network node 904 may send a first indication of a reference AM / PM impairment characteristic to the UE 902 via a secure signal.

[0137] At 1206, the network node may send at least one reference signal to the UE via a downlink channel. The at least one reference signal may include an added AM / PM impairment based on a reference AM / PM impairment characteristic. For example, 1206 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 912, the network node 904 may send at least one reference signal to the UE 902 via a downlink channel.

[0138] Figure 13 1300 is a flow chart of a method of wireless communication. The method may be performed by a network node (e.g., base station / network node 102 / 180 / 310; network node 504 / 904; device 1502). At 1302, the network node may select a reference AM / PM impairment signature. For example, 1302 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 906, the network node 904 may select a reference AM / PM impairment signature.

[0139] At 1304, the network node may send a first indication of a reference AM / PM impairment characteristic to the UE via a secure signal. For example, 1304 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 908, the network node 904 may send a first indication of a reference AM / PM impairment characteristic to the UE 902 via a secure signal.

[0140] At 1308, the network node may send at least one reference signal to the UE via a downlink channel. The at least one reference signal may include an added AM / PM impairment based on a reference AM / PM impairment characteristic. For example, 1308 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 912, the network node 904 may send at least one reference signal to the UE 902 via a downlink channel.

[0141] In one configuration, the added AM / PM impairment may be added to at least one reference signal in the baseband domain.

[0142] In one configuration, the safety signal may correspond to SERS or RRC signaling.

[0143] In one configuration, at 1310, the network node may periodically send further indications of updated reference AM / PM impairment characteristics to the UE. For example, 1310 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 922, the network node 904 may periodically send a further indication of the updated reference AM / PM impairment signature to the UE 902.

[0144] In one configuration, the at least one reference signal may be a DMRS.

[0145] In one configuration, the downlink channel may be a PDCCH or a PDSCH.

[0146] In one configuration, at 1306, the network node may apply DPD to the downlink channel to at least partially remove the natural AM / PM distortion associated with the power amplifier. For example, 1306 may be performed by Figure 15 The physical layer security component 1540 is used to perform the above. Figure 9 At 910 , the network node 904 may apply DPD to the downlink channel to at least partially remove natural AM / PM distortion associated with the power amplifier.

[0147] In one configuration, added AM / PM impairments may be further added to at least one data portion of the downlink channel.

[0148] Figure 1414 is a diagram illustrating an example of a hardware implementation for an apparatus 1402. Apparatus 1402 may be a UE, a component of a UE, or may implement UE functionality. In some aspects, apparatus 1402 may include a cellular baseband processor 1404 (also referred to as a modem) coupled to a cellular RF transceiver 1422. In some aspects, apparatus 1402 may also include one or more subscriber identity module (SIM) cards 1420, an application processor 1406 coupled to a secure digital (SD) card 1408 and a screen 1410, a Bluetooth module 1412, a wireless local area network (WLAN) module 1414, a global positioning system (GPS) module 1416, or a power supply 1418. Cellular baseband processor 1404 communicates with UE 104 and / or BS 102 / 180 via cellular RF transceiver 1422. Cellular baseband processor 1404 may include computer-readable media / memory. The computer-readable media / memory may be non-transitory. The cellular baseband processor 1404 is responsible for general processing, including executing software stored on a computer-readable medium / memory. When executed by the cellular baseband processor 1404, the software causes the cellular baseband processor 1404 to perform the various functions described above. The computer-readable medium / memory may also be used to store data manipulated by the cellular baseband processor 1404 when executing the software. The cellular baseband processor 1404 also includes a receive component 1430, a communication manager 1432, and a transmit component 1434. The communication manager 1432 includes one or more of the illustrated components. The components within the communication manager 1432 may be stored in the computer-readable medium / memory and / or configured as hardware within the cellular baseband processor 1404. The cellular baseband processor 1404 may be a component of the UE 350 and may include memory 360 and / or at least one of the TX processor 368, the RX processor 356, and the controller / processor 359. In one configuration, the apparatus 1402 may be a modem chip and include only the baseband processor 1404, and in another configuration, the apparatus 1402 may be the entire UE (see, e.g., Figure 3 350) and includes additional modules of device 1402.

[0149] The communications manager 1432 includes a physical layer security component 1440 that can be configured to receive a first indication of a reference AM / PM impairment signature from a network node via a secure signal, e.g., as described in conjunction with Figure 11 The physical layer security component 1440 may be configured to receive at least one reference signal from a transmitter via a downlink channel, for example, as described in conjunction with Figure 10 1002 and Figure 11The physical layer security component 1440 can be configured to estimate the AM / PM impairment characteristics in at least one reference signal, for example, as described in conjunction with Figure 10 1004 and Figure 11 The physical layer security component 1440 may be configured to identify whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature, for example, as described in conjunction with Figure 10 1006 and Figure 11 The physical layer security component 1440 can be configured to maintain or drop at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature, for example, as described in conjunction with Figure 10 1008 and Figure 11 The physical layer security component 1440 may be configured to apply DPoD to at least one data portion of the downlink channel based on a reference AM / PM impairment signature, for example, as described in conjunction with Figure 11 The physical layer security component 1440 may be configured to periodically receive further indications of updated reference AM / PM impairment signatures from network nodes, for example, as described in conjunction with Figure 11 As described in 1114.

[0150] The apparatus may include executing Figures 9 to 11 The flowchart of the algorithm is an additional component of each box. Figures 9 to 11 Each block in the flowchart of can be performed by a component, and the apparatus can include one or more of those components. These components can be one or more hardware components that are specifically configured to perform the process / algorithm, implemented by a processor configured to perform the process / algorithm, stored in a computer-readable medium for implementation by a processor, or some combination thereof.

[0151] As shown, apparatus 1402 may include various components configured for various functions. In one configuration, apparatus 1402 (and in particular, cellular baseband processor 1404) includes means for receiving at least one reference signal from a transmitter via a downlink channel. Apparatus 1402 (and in particular, cellular baseband processor 1404) includes means for estimating an AM / PM impairment signature in the at least one reference signal. Apparatus 1402 (and in particular, cellular baseband processor 1404) includes means for identifying whether the estimated AM / PM impairment signature matches a reference AM / PM impairment signature. Apparatus 1402 (and in particular, cellular baseband processor 1404) includes means for maintaining or discarding at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature.

[0152] In one configuration, if the estimated AM / PM impairment signature matches a reference AM / PM impairment signature, at least one time slot may be maintained. If the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the at least one time slot may be discarded. In one configuration, if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the transmitter may correspond to a network node. If the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the transmitter may correspond to an adversary transmitter. In one configuration, the apparatus 1402 (and in particular the cellular baseband processor 1404) includes means for receiving a first indication of the reference AM / PM impairment signature from the network node via a secure signal. In one configuration, the secure signal may correspond to SERS or RRC signaling. In one configuration, the apparatus 1402 (and in particular the cellular baseband processor 1404) includes means for periodically receiving further indications of an updated reference AM / PM impairment signature from the network node. In one configuration, whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature may be identified based on a correlation between the estimated AM / PM impairment signature and the reference AM / PM impairment signature. In one configuration, the correlation may be identified based on an MRC method. In one configuration, the at least one reference signal is a DMRS. In one configuration, the downlink channel may be a PDCCH or a PDSCH. In one configuration, the apparatus 1402 (and in particular the cellular baseband processor 1404) includes means for applying DPoD to at least one data portion of the downlink channel based on the reference AM / PM impairment signature.

[0153] These means may be one or more of the components of the apparatus 1402 configured to perform the functions recited by these means. As described above, the apparatus 1402 may include the TX processor 368, the RX processor 356, and the controller / processor 359. Thus, in one configuration, these means may be the TX processor 368, the RX processor 356, and the controller / processor 359 configured to perform the functions recited by these means.

[0154] Figure 15 15 is a diagram illustrating an example hardware implementation for apparatus 1502. Apparatus 1502 may be a base station, a component of a base station, or may implement base station functionality. In some aspects, apparatus 1502 may include a baseband unit 1504. Baseband unit 1504 may communicate with UE 104 via a cellular RF transceiver 1522. Baseband unit 1504 may include computer-readable media / memory. Baseband unit 1504 is responsible for general processing, including executing software stored on computer-readable media / memory. This software, when executed by baseband unit 1504, enables baseband unit 1504 to perform the various functions described above. The computer-readable media / memory may also be used to store data manipulated by baseband unit 1504 when executing the software. Baseband unit 1504 also includes a receiving component 1530, a communication manager 1532, and a transmitting component 1534. Communication manager 1532 includes one or more of the components illustrated. The components within the communication manager 1532 may be stored in a computer-readable medium / memory and / or configured as hardware within the baseband unit 1504. The baseband unit 1504 may be a component of the base station 310 and may include memory 376 and / or at least one of the TX processor 316, RX processor 370, and controller / processor 375.

[0155] The communications manager 1532 includes a physical layer security component 1540 that can be configured to select a reference AM / PM impairment signature, for example, as combined with Figure 12 1202 and Figure 13 The physical layer security component 1540 may be configured to send a first indication of a reference AM / PM impairment characteristic to the UE via a secure signal, for example, as described in conjunction with Figure 12 1204 and Figure 13 The physical layer security component 1540 can be configured to apply DPD to the downlink channel to at least partially remove the natural AM / PM distortion associated with the power amplifier, for example, as described in conjunction with Figure 13 The physical layer security component 1540 may be configured to send at least one reference signal to the UE via a downlink channel, for example, as described in conjunction with Figure 121206 and Figure 13 The physical layer security component 1540 may be configured to periodically send further indications of updated reference AM / PM impairment characteristics to the UE, for example, as described in conjunction with Figure 13 As described in 1310.

[0156] The apparatus may include executing Figure 9 、 Figure 12 and Figure 13 The flowchart of the algorithm is an additional component of each box. Figure 9 、 Figure 12 and Figure 13 Each block in the flowchart of can be performed by a component, and the apparatus can include one or more of those components. These components can be one or more hardware components that are specifically configured to perform the process / algorithm, implemented by a processor configured to perform the process / algorithm, stored in a computer-readable medium for implementation by a processor, or some combination thereof.

[0157] As shown, apparatus 1502 may include various components configured for various functions. In one configuration, apparatus 1502 (and in particular, baseband unit 1504) includes means for selecting a reference AM / PM impairment signature. Apparatus 1502 (and in particular, baseband unit 1504) includes means for transmitting a first indication of the reference AM / PM impairment signature to a UE via a safety signal. Apparatus 1502 (and in particular, baseband unit 1504) includes means for transmitting at least one reference signal to the UE via a downlink channel. The at least one reference signal may include an added AM / PM impairment based on the reference AM / PM impairment signature.

[0158] In one configuration, the added AM / PM impairment may be added to at least one reference signal in the baseband domain. In one configuration, the safety signal may correspond to SERS or RRC signaling. In one configuration, the apparatus 1502 (and in particular the baseband unit 1504) includes means for periodically sending a further indication of the updated reference AM / PM impairment characteristics to the UE. In one configuration, the at least one reference signal may be a DMRS. In one configuration, the downlink channel may be a PDCCH or a PDSCH. In one configuration, the apparatus 1502 (and in particular the baseband unit 1504) includes means for applying DPD to the downlink channel to at least partially remove natural AM / PM distortion associated with the power amplifier. In one configuration, the added AM / PM impairment may further be added to at least one data portion of the downlink channel.

[0159] These means may be one or more of the components of the apparatus 1502 configured to perform the functions recited by these means. As described above, the apparatus 1502 may include the TX processor 316, the RX processor 370, and the controller / processor 375. Thus, in one configuration, these means may be the TX processor 316, the RX processor 370, and the controller / processor 375 configured to perform the functions recited by these means.

[0160] Re-reference Figures 4 to 15 , the network node may select a reference AM / PM impairment signature. The network node may send a first indication of the reference AM / PM impairment signature to the UE via a secure signal. The network node may send at least one reference signal to the UE via a downlink channel. The at least one reference signal may include AM / PM impairments added based on the reference AM / PM impairment signature. The UE may receive at least one reference signal from a transmitter via a downlink channel. The UE may estimate the AM / PM impairment signature in the at least one reference signal. The UE may determine whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. Furthermore, the UE may maintain or discard at least one timeslot associated with the downlink channel based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature. Thus, a measure of physical layer security may be achieved. As mentioned above, the presence of physical layer security may be associated with numerous improvements compared to a scenario without physical layer security. For example, physical layer security may provide an additional layer of security to counter quantum threats. Furthermore, where applicable, the use of physical layer security may help reduce load in Layer 3 (L3) and, therefore, latency and overhead. Furthermore, the use of physical layer security can help reduce the chances of falling victim to malicious intruders targeting protocols at layers below L3.

[0161] It should be understood that the specific order or hierarchy of blocks in the disclosed process / flowchart is merely illustrative of an exemplary method. It should be understood that the specific order or hierarchy of blocks in the process / flowchart may be rearranged based on design preferences. In addition, some blocks may be combined or omitted. The accompanying method claims provide elements of each block in a sample order, but are not intended to be limited to the specific order or hierarchy provided.

[0162] The foregoing description is provided to enable anyone skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Accordingly, the claims are not intended to be limited to the aspects shown herein, but rather to be consistent with the full scope of the claims consistent with the language of the claims, wherein reference to an element in the singular is not intended to mean "one and only one," unless specifically so stated, but rather "one or more." Terms such as "if," "when," and "while" should be interpreted as meaning "under the condition of," rather than implying an immediate temporal relationship or reaction. That is, these phrases, such as "when," do not imply immediate action in response to the occurrence of an action or during the occurrence of an action, but simply imply that if the condition is met, the action will occur, but without requiring a specific or immediate time limit for the action to occur. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other aspects. Unless otherwise specifically stated, the term "some" refers to one or more. Combinations such as “at least one of A, B, or C,” “one or more of A, B, or C,” “at least one of A, B, and C,” “one or more of A, B, and C,” and “A, B, C, or any combination thereof” include any combination of A, B, and / or C and may include multiple A’s, multiple B’s, or multiple C’s. Specifically, combinations such as “at least one of A, B, or C,” “one or more of A, B, or C,” “at least one of A, B, and C,” “one or more of A, B, and C,” and “A, B, C, or any combination thereof” may be only A, only B, only C, A and B, A and C, B and C, or A, B, and C, where any such combination may include one or more members of A, B, or C. A set should be interpreted as a set of elements, where the number of elements is one or more. Thus, for a set of X, X will include one or more elements. All structural and functional equivalents to the elements of various aspects described throughout this disclosure that are or later become known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be encompassed by the claims. Furthermore, nothing disclosed herein is intended to be disclosed to the public, regardless of whether such disclosure is explicitly recited in the claims. Words such as "module," "mechanism," "element," and "device" are not intended to replace the term "component." Thus, no claim element will be construed as a component-plus-function unless the element is explicitly phrased using the phrase "component for..."

[0163] The following aspects are merely illustrative and may be combined with other aspects or teachings described herein without limitation.

[0164] Aspect 1 is an apparatus for wireless communication at a UE, the apparatus comprising at least one processor coupled to a memory and configured to: receive at least one reference signal from a transmitter via a downlink channel; estimate an AM / PM impairment characteristic in the at least one reference signal; identify whether the estimated AM / PM impairment characteristic matches a reference AM / PM impairment characteristic; and maintain or discard at least one time slot associated with the downlink channel based on whether the estimated AM / PM impairment characteristic matches the reference AM / PM impairment characteristic.

[0165] Aspect 2 is an apparatus according to aspect 1, wherein if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the at least one time slot is maintained, and if the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the at least one time slot is discarded.

[0166] Aspect 3 is an apparatus according to any one of Aspects 1 and 2, wherein if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the transmitter corresponds to a network node, and if the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the transmitter corresponds to an enemy transmitter.

[0167] Aspect 4 is the apparatus of aspect 3, wherein the at least one processor is further configured to: receive a first indication of the reference AM / PM impairment signature from the network node via a secure signal.

[0168] Aspect 5 is the apparatus according to aspect 4, wherein the safety signal corresponds to SERS or RRC signaling.

[0169] Aspect 6 is the apparatus according to any one of aspects 4 and 5, the at least one processor being further configured to: periodically receive a further indication of an updated reference AM / PM impairment signature from the network node.

[0170] Aspect 7 is an apparatus according to any one of aspects 1 to 6, wherein whether the estimated AM / PM impairment feature matches the reference AM / PM impairment feature is identified based on an amount of correlation between the estimated AM / PM impairment feature and the reference AM / PM impairment feature.

[0171] Aspect 8 is the apparatus according to aspect 7, wherein the correlation amount is identified based on an MRC method.

[0172] Aspect 9 is an apparatus according to any one of aspects 1 to 8, wherein the at least one reference signal is a DMRS.

[0173] Aspect 10 is an apparatus according to any one of aspects 1 to 9, wherein the downlink channel is a PDCCH or a PDSCH.

[0174] Aspect 11 is the apparatus of any one of aspects 1 to 10, the at least one processor being further configured to apply DPoD to at least one data portion of the downlink channel based on the reference AM / PM impairment signature.

[0175] Aspect 12 is the apparatus of any one of aspects 1 to 11, further comprising: a transceiver coupled to the at least one processor.

[0176] Aspect 13 is an apparatus for wireless communication at a network node, the apparatus comprising: at least one processor coupled to a memory and configured to select a reference AM / PM impairment characteristic; send a first indication of the reference AM / PM impairment characteristic to a UE via a safety signal; and send at least one reference signal to the UE via a downlink channel, the at least one reference signal comprising added AM / PM impairments based on the reference AM / PM impairment characteristic.

[0177] Aspect 14 is the apparatus of aspect 13, wherein the added AM / PM impairment is added to the at least one reference signal in a baseband domain.

[0178] Aspect 15 is an apparatus according to any one of aspects 13 to 14, wherein the safety signal corresponds to SERS or RRC signaling.

[0179] Aspect 16 is an apparatus according to any one of aspects 13 to 15, the at least one processor being further configured to periodically send a further indication of an updated reference AM / PM impairment signature to the UE.

[0180] Aspect 17 is an apparatus according to any one of aspects 13 to 16, wherein the at least one reference signal is a DMRS.

[0181] Aspect 18 is an apparatus according to any one of aspects 13 to 17, wherein the downlink channel is a PDCCH or a PDSCH.

[0182] Aspect 19 is an apparatus according to any one of aspects 13 to 18, the at least one processor being further configured to: apply DPD to the downlink channel to at least partially remove natural AM / PM distortion associated with a power amplifier.

[0183] Aspect 20 is an apparatus according to any one of aspects 13 to 19, wherein the added AM / PM impairment is further added to at least one data portion of the downlink channel.

[0184] Aspect 21 is the apparatus of any one of aspects 13 to 20, further comprising: a transceiver coupled to the at least one processor.

[0185] Aspect 22 is a method for implementing wireless communication according to any one of aspects 1 to 21.

[0186] Aspect 23 is an apparatus for wireless communication, comprising means for implementing any one of aspects 1 to 21.

[0187] Aspect 24 is a computer-readable medium storing computer-executable code, wherein the code, when executed by a processor, causes the processor to implement any one of aspects 1 to 21.

Claims

1. An apparatus for wireless communication at a user equipment (UE), the apparatus comprising: at least one memory comprising instructions; and at least one processor configured to execute the instructions to cause the apparatus to: receiving at least one reference signal from a transmitter via a downlink channel; estimating an amplitude modulation to phase modulation AM / PM impairment signature in the at least one reference signal; Identifying whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature; and At least one time slot associated with the downlink channel is maintained or dropped based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature.

2. The apparatus of claim 1 , wherein if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the at least one time slot is maintained, and if the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the at least one time slot is discarded.

3. The apparatus of claim 1 , wherein if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the transmitter corresponds to a network node, and if the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the transmitter corresponds to an adversary transmitter.

4. The apparatus of claim 3, wherein the at least one processor is further configured to cause the apparatus to: A first indication of the reference AM / PM impairment signature is received from a network node via a secure signal. The apparatus according to claim 4 , wherein the safety signal corresponds to a Safety Reference Signal (SERS) or a Radio Resource Control (RRC) signaling.

6. The apparatus of claim 4, wherein the at least one processor is further configured to: Further indications of updated reference AM / PM impairment signatures are periodically received from the network node. 7 . The apparatus of claim 1 , wherein whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature is identified based on an amount of correlation between the estimated AM / PM impairment signature and the reference AM / PM impairment signature. The apparatus according to claim 7 , wherein the correlation amount is identified based on a Maximum Ratio Combining (MRC) method. 9 . The apparatus of claim 1 , wherein the at least one reference signal is a demodulation reference signal (DMRS). 10 . The apparatus according to claim 1 , wherein the downlink channel is a physical downlink control channel (PDCCH) or a physical downlink shared channel (PDSCH).

11. The apparatus of claim 1 , wherein the at least one processor is further configured to cause the apparatus to: Digital post-distortion (DPoD) is applied to at least one data portion of the downlink channel based on the reference AM / PM impairment signature.

12. The apparatus of claim 1, further comprising a transceiver coupled to the at least one processor, wherein the apparatus is a wireless communication device.

13. A method for wireless communication at a user equipment (UE), the method comprising: receiving at least one reference signal from a transmitter via a downlink channel; estimating an amplitude modulation to phase modulation AM / PM impairment signature in the at least one reference signal; Identifying whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature; and At least one time slot associated with the downlink channel is maintained or dropped based on whether the estimated AM / PM impairment signature matches the reference AM / PM impairment signature.

14. The method of claim 13, wherein if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the at least one time slot is maintained, and if the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the at least one time slot is discarded.

15. The method of claim 13, wherein if the estimated AM / PM impairment signature matches the reference AM / PM impairment signature, the transmitter corresponds to a network node, and if the estimated AM / PM impairment signature does not match the reference AM / PM impairment signature, the transmitter corresponds to an adversary transmitter.

16. An apparatus for wireless communication at a network node, the apparatus comprising: at least one memory comprising instructions; and at least one processor configured to execute the instructions to cause the apparatus to: Select reference amplitude modulation to phase modulation AM / PM impairment characteristics; sending a first indication of the reference AM / PM impairment characteristic to a user equipment (UE) via a secure signal; and transmitting at least one reference signal to the UE via a downlink channel, the at least one reference signal comprising an added AM / PM impairment based on the reference AM / PM impairment characteristic, The UE identifies whether the estimated AM / PM impairment feature matches the reference AM / PM impairment feature.

17. The apparatus of claim 16, wherein the added AM / PM impairment is added to the at least one reference signal in a baseband domain. The apparatus according to claim 16 , wherein the safety signal corresponds to a Safety Reference Signal (SERS) or a Radio Resource Control (RRC) signaling.

19. The apparatus of claim 16, wherein the at least one processor is further configured to cause the apparatus to: A further indication of an updated reference AM / PM impairment signature is periodically sent to the UE.

20. The apparatus of claim 16, wherein the at least one reference signal is a demodulation reference signal (DMRS).

21. The apparatus of claim 16, wherein the downlink channel is a physical downlink control channel (PDCCH) or a physical downlink shared channel (PDSCH).

22. The apparatus of claim 16, wherein the at least one processor is further configured to cause the apparatus to: Digital predistortion (DPD) is applied to the downlink channel to at least partially remove natural AM / PM distortion associated with a power amplifier.

23. The apparatus of claim 16, wherein the added AM / PM impairment is further added to at least one data portion of the downlink channel.

24. The apparatus of claim 16, further comprising a transceiver coupled to the at least one processor, wherein the apparatus is a wireless communication device.

25. A method of wireless communication at a network node, the method comprising: Select reference amplitude modulation to phase modulation AM / PM impairment characteristics; sending a first indication of the reference AM / PM impairment characteristic to a user equipment (UE) via a secure signal; and transmitting at least one reference signal to the UE via a downlink channel, the at least one reference signal comprising an added AM / PM impairment based on the reference AM / PM impairment characteristic, The UE identifies whether the estimated AM / PM impairment feature matches the reference AM / PM impairment feature.

26. The method of claim 25, wherein the added AM / PM impairment is added to the at least one reference signal in the baseband domain. The method according to claim 25 , wherein the safety signal corresponds to a Safety Reference Signal (SERS) or a Radio Resource Control (RRC) signaling.

28. The method according to claim 25, further comprising: A further indication of an updated reference AM / PM impairment signature is periodically sent to the UE.

29. The method of claim 25, wherein the at least one reference signal is a demodulation reference signal (DMRS).

30. The method of claim 25, wherein the downlink channel is a Physical Downlink Control Channel (PDCCH) or a Physical Downlink Shared Channel (PDSCH).

31. A computer-readable storage medium having stored thereon instructions that, when executed, cause one or more processors to perform the method of any one of claims 13-15 and 25-30.

Citation Information

Patent Citations

  • Over the air acquisition of radio frequency impairment information

    CN109328442A

  • Fallback procedures when the path loss or spatial transmit quasi-collocation (QCL) reference from neighboring cells is failing for sounding reference signals (SRS) for positioning

    CN113841447A