Modulation enhanced authentication
By generating modulation symbols associated with predefined keys in wireless communications, possible spoofing or eavesdropping attacks by malicious users is solved, improving the security of communication and signal integrity.
Patent Information
- Application Number
- CN202380073480.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-12
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-30
AI Technical Summary
In wireless communications, a malicious user can listen to the communication, change the non-security signal, and resend it, making it more difficult to spoof or eavesdropper attacks.
The security of communication is improved by generating and sending modulated symbols, wherein at least two bit sequences or symbol sequences are associated with a reference bit sequence or symbol sequence, and at least one sequence is associated with a predefined key.
This method improves the security of wireless communications, makes it more difficult to spoof or eavesdropper attacks, and ensures the integrity and authentication of communication signals.
Smart Images

Figure CN120077690A_ABST
Abstract
Description
Technical Field
[0001] The following exemplary embodiments relate to wireless communication. Background Art
[0002] In wireless communication, a malicious user ("spoofing attacker") can eavesdrop on the communication, modify a non-secure signal, and retransmit it as if it originated from the original transmitter. It is desirable to improve the security of wireless communication to make spoofing or similar eavesdropping attacks more difficult. Summary of the Invention
[0003] The scope of protection sought by the various exemplary embodiments is set forth in the independent claims. Exemplary embodiments and features described in this specification that do not fall within the scope of the independent claims (if any) are to be construed as examples useful for understanding the various embodiments.
[0004] According to one aspect, there is provided an apparatus including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: generate modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key; and transmit the modulation symbols.
[0005] According to another aspect, there is provided an apparatus including: means for generating modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key; and means for transmitting the modulation symbols.
[0006] According to another aspect, there is provided a method including: generating modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key; and transmitting the modulation symbols.
[0007] According to another aspect, there is provided a computer program including instructions that, when executed by a device, cause the device to at least perform the following: generate modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key; and transmit the modulation symbols.
[0008] According to another aspect, there is provided a computer-readable medium including program instructions that, when executed by a device, cause the device to at least perform the following: generate modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key; and transmit the modulation symbols.
[0009] According to another aspect, there is provided a non-transitory computer-readable medium including program instructions that, when executed by a device, cause the device to at least perform the following: generate modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key; and transmit the modulation symbols.
[0010] According to another aspect, there is provided a device including at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: receive modulation symbols from a transmitter; compare the modulation symbols with at least expected modulation symbols, wherein the expected modulation symbols are based on a predefined key; and authenticate the transmitter at least in part based on the comparison.
[0011] According to another aspect, there is provided a device including: means for receiving modulation symbols from a transmitter; means for comparing the modulation symbols with at least expected modulation symbols, wherein the expected modulation symbols are based on a predefined key; and means for authenticating the transmitter at least in part based on the comparison.
[0012] According to another aspect, there is provided a method including: receiving modulation symbols from a transmitter; comparing the modulation symbols with at least expected modulation symbols, wherein the expected modulation symbols are based on a predefined key; and authenticating the transmitter at least in part based on the comparison.
[0013] According to another aspect, there is provided a computer program including instructions that, when executed by a device, cause the device to at least perform the following: receive modulation symbols from a transmitter; compare the modulation symbols with at least expected modulation symbols, where the expected modulation symbols are based on a predefined key; and authenticate the transmitter at least in part based on the comparison.
[0014] According to another aspect, there is provided a computer-readable medium including program instructions that, when executed by a device, cause the device to at least perform the following: receive modulation symbols from a transmitter; compare the modulation symbols with at least expected modulation symbols, where the expected modulation symbols are based on a predefined key; and authenticate the transmitter at least in part based on the comparison.
[0015] According to another aspect, there is provided a non-transitory computer-readable medium including program instructions that, when executed by a device, cause the device to at least perform the following: receive modulation symbols from a transmitter; compare the modulation symbols with at least expected modulation symbols, where the expected modulation symbols are based on a predefined key; and authenticate the transmitter at least in part based on the comparison. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Hereinafter, various exemplary embodiments will be described in more detail with reference to the drawings, where
[0017] Figure 1 an example of a cellular communication network is shown;
[0018] Figure 2 an example of a modulation constellation is shown;
[0019] Figure 3A an example of a modulator is shown;
[0020] Figure 3B an example of a first modulator and a second modulator is shown;
[0021] Figure 3C an example of a modulation constellation with Gray labeling is shown;
[0022] Figure 4 a signaling diagram is shown;
[0023] Figure 5 a flowchart is shown;
[0024] Figure 6 a flowchart is shown;
[0025] Figure 7 a flowchart is shown;
[0026] Figure 8 an example of a device is shown; and
[0027] Figure 9An example of the apparatus is shown. Detailed implementation
[0028] The following examples are exemplary. Although the specification may refer to "one", "a", or "some" embodiments in several places in the text, this does not necessarily mean that the same (multiple) embodiments are referred to each time, or that a particular feature applies only to a single embodiment. The individual features of different embodiments can also be combined to provide other embodiments.
[0029] Hereinafter, a radio access architecture based on Long Term Evolution-Advanced (LTE-A), New Radio (NR, 5G), Beyond 5G, or Sixth Generation (6G) will be used as an example of an access architecture to which the example embodiments can be applied, without, however, limiting the example embodiments to such an architecture. It will be apparent to those skilled in the art that the example embodiments can also be applied to other types of communication networks having suitable components by appropriately adjusting parameters and processes. Some examples of other options for suitable systems can be Universal Mobile Telecommunications System (UMTS) Radio Access Network (UTRAN or E-UTRAN), Long Term Evolution (LTE, substantially the same as E-UTRA), Wireless Local Area Network (WLAN or Wi-Fi), Worldwide Interoperability for Microwave Access (WiMAX), Personal Communication Service (PCS), ZigBee Wideband Code Division Multiple Access (WCDMA), systems using Ultra-Wideband (UWB) technology, sensor networks, Mobile Ad-hoc Networks (MANET), and Internet Protocol Multimedia Subsystem (IMS), or any combination thereof.
[0030] Figure 1 An example depicting a simplified system architecture showing some elements and functional entities is shown, all of which are logical units and the implementation thereof may be different from the implementation shown. Figure 1 The connections shown are logical connections; the actual physical connections may be different. It will be apparent to those skilled in the art that the system may also include other functions and structures in addition to Figure 1 the functions and structures shown.
[0031] However, the example embodiments are not limited to the system given as an example, but those skilled in the art can apply the solution to other communication systems having the necessary attributes.
[0032] Figure 1 The example of... shows a part of an exemplary radio access network.
[0033] Figure 1User equipments 100 and 102 are shown, which are configured to wirelessly connect with an access node (AN) 104 (such as an evolved Node B (abbreviated as eNB or eNodeB) or a next-generation Node B (abbreviated as gNB or gNodeB)) on one or more communication channels in a radio cell, thereby providing the radio cell. The physical link from the user equipment to the access node may be referred to as an uplink (UL) or reverse link, and the physical link from the access node to the user equipment may be referred to as a downlink (DL) or forward link. The user equipment may also communicate directly with another user equipment via sidelink (SL) communication. It should be understood that the access node or its functionality may be implemented by using any entity such as a node, host, server, or access point suitable for this purpose.
[0034] The communication system may include more than one access node. In this case, the access nodes may also be configured to communicate with each other via wired or wireless links designed for this purpose. These links may be used for signaling purposes and also for routing data from one access node to another. The access node may be a computing device configured to control the radio resources of the communication system to which it is coupled. The access node may also be referred to as a base station, base transceiver station (BTS), access point, or any other type of interface device including a relay station capable of operating in a wireless environment. The access node may include or be coupled to a transceiver. From the transceiver of the access node, a connection may be provided to an antenna unit that establishes a two-way radio link to the user equipment. The antenna unit may include multiple antennas or antenna elements. The access node may also be connected to a core network 110 (CN or next-generation core NGC). Depending on the technology deployed, the counterpart to which the access node may be connected on the CN side may be a serving gateway (S-GW, routing and forwarding user data packets), a packet data network gateway (P-GW) for providing a connection from the user equipment to an external packet data network, a user plane function (UPF), a mobility management entity (MME), or an access and mobility management function (AMF), etc.
[0035] The user equipment shows a type of device to which resources on the air interface can be allocated and assigned, and thus any feature described herein using the user equipment can be implemented using a corresponding device (such as a relay node).
[0036] Examples of such relay nodes can be a Layer 3 relay (self-backhaul relay) towards the access node. The self-backhaul relay node can also be referred to as an integrated access and backhaul (IAB) node. The IAB node can include two logical parts: a mobile terminal (MT) part, which is responsible for the (multiple) backhaul links (i.e., the (multiple) links between the IAB node and the donor node, also referred to as the parent node); and a distributed unit (DU) part, which is responsible for the (multiple) access links (i.e., the (multiple) sub-links between the IAB node and the (multiple) user equipments) and / or the sub-links between the IAB node and other IAB nodes (multi-hop scenario).
[0037] Another example of such a relay node can be a Layer 1 relay called a repeater. The repeater can amplify the signal received from the access node and forward it to the user equipment, and / or amplify the signal received from the user equipment and forward it to the access node.
[0038] The user equipment can also be referred to as a subscriber unit, mobile station, remote terminal, access terminal, user terminal, terminal device, or user equipment (UE), just to mention some names or devices. The user equipment can refer to a portable computing device including a wireless mobile communication device operating with or without a subscriber identity module (SIM), including but not limited to the following types of devices: mobile station (mobile phone), smart phone, personal digital assistant (PDA), cellular phone, device using a wireless modem (alarm or measurement device, etc.), laptop and / or touch screen computer, tablet computer, game console, notebook, multimedia device, reduced-capability (Red Cap) device, wireless sensor device, or any device integrated in a vehicle.
[0039] It should be understood that the user equipment can also be an almost exclusive uplink-only device, examples of which can be a camera or video camera that loads images or video clips onto the network. The user equipment can also be a device capable of operating in an Internet of Things (IoT) network, which is a scenario where the ability to provide objects with the ability to transfer data over the network without human-to-human or human-to-computer interaction can be provided. The user equipment can also utilize the cloud. In some applications, the user equipment can include a small portable or wearable device with radio components (such as a watch, headphones, or glasses), and the computing can be performed in the cloud or in another user equipment. The user equipment (or in some example embodiments, the Layer 3 relay node) can be configured to perform one or more user equipment functions.
[0040] The various techniques described herein can also be applied to cyber-physical systems (CPSs), which are systems of collaborative computing elements that control physical entities. A CPS can implement and utilize a large number of interconnected ICT devices (sensors, actuators, processor microcontrollers, etc.) embedded in physical objects at different locations. A mobile cyber-physical system, where the physical system under discussion can have inherent mobility, is a subcategory of cyber-physical systems. Examples of mobile physical systems include mobile robots and electronic devices transported by humans or animals.
[0041] Additionally, although the device has been depicted as a single entity, different units, processors, and / or memory units ( Figure 1 not all shown in
[0042] 5G enables the use of multiple-input-multiple-output (MIMO) antennas. There are many more base stations or nodes than in LTE (the so-called small cell concept), including macro sites that operate in cooperation with smaller stations and employ various radio technologies depending on service requirements, use cases, and / or available spectrum. 5G mobile communications can support a wide range of use cases and related applications, including video streaming, augmented reality, different ways of data sharing, and various forms of machine type applications (such as (massive) machine type communication (mMTC), including vehicle safety, different sensors, and real-time control). 5G can have multiple radio interfaces. That is, below 6 GHz, centimeter wave (cmWave), and millimeter wave (mmWave), and can also be integrated with existing traditional radio access technologies such as LTE. The integration with LTE can be implemented, for example, as a system where macro coverage can be provided by LTE, and 5G radio interface access can come from small cells aggregated to LTE. In other words, 5G can support both inter-RAT interoperability (such as LTE-5G) and inter-RI interoperability (inter-radio interface interoperability, such as below 6 GHz - centimeter wave - millimeter wave). One of the concepts considered for use in 5G networks can be network slicing, where multiple independent and dedicated virtual sub-networks (network instances) can be created within substantially the same infrastructure to run services with different requirements for latency, reliability, throughput, and mobility.
[0043] The current architecture in LTE networks can be fully distributed in the radio and fully centralized in the core network. Low-latency applications and services in 5G may require bringing content closer to the radio, which leads to local breakout and multi-access edge computing (MEC). 5G enables analytics and knowledge generation to occur at the data source. This approach may require leveraging resources that may not be continuously connected to the network, such as laptops, smartphones, tablets, and sensors. MEC can provide a distributed computing environment for application and service hosting. It can also have the ability to store and process content near cellular subscribers for faster response times. Edge computing can encompass a wide variety of technologies, such as wireless sensor networks, mobile data acquisition, mobile signature analysis, collaborative distributed peer-to-peer ad hoc networking, and also processing that can be classified as local cloud / fog computing and grid / grid computing, dew computing, mobile edge computing, microclouds, distributed data storage and retrieval, self-healing autonomous networks, remote cloud services, augmented and virtual reality, data caching, Internet of Things (mass connectivity and / or latency-critical), critical communications (autonomous vehicles, traffic safety, real-time analytics, time-critical control, healthcare applications).
[0044] The communication system is also capable of communicating with one or more other networks 113, such as the public switched telephone network or the Internet, or leveraging services provided by them. The communication network is also capable of supporting the use of cloud services. For example, at least a portion of the core network operations can be performed as a cloud service (which is depicted by the "cloud" 114 in Figure 1 ). The communication system may also include a central control entity, etc., which provides facilities for networks of different operators to cooperate, for example, in spectrum sharing.
[0045] The access node can also be split into: a radio unit (RU), which includes a radio transceiver (TRX), i.e., a transmitter (Tx) and a receiver (Rx); one or more distributed units (DU) 105, which can be used for so-called layer 1 (L1) processing and real-time layer 2 (L2) processing; and a central unit (CU) 108 (also referred to as a centralized unit), which can be used for non-real-time L2 and layer 3 (L3) processing. The CU 108 can be connected to one or more DUs 105 via, for example, an F1 interface. Such a split can enable the centralization of the CU relative to the cell site and the DU, while the DU can be more distributed and can even remain at the cell site. The CU and the DU together can also be referred to as the baseband or baseband unit (BBU). The CU and the DU can also be included in a radio access point (RAP).
[0046] CU 108 can be defined as a logical node hosting higher layer protocols of an access node, such as Radio Resource Control (RRC), Service Data Adaptation Protocol (SDAP), and / or Packet Data Convergence Protocol (PDCP). DU 105 can be defined as a logical node hosting the Radio Link Control (RLC), Media Access Control (MAC), and / or Physical (PHY) layer of an access node. The operation of the DU can be at least partially controlled by the CU. The CU can include a Control Plane (CU-CP), which can be defined as a logical node hosting the control plane part of the PDCP protocol of the CU for the access node and the RRC. The CU can also include a User Plane (CU-UP), which can be defined as a logical node hosting the user plane part of the PDCP protocol and the SDAP protocol of the CU for the access node.
[0047] The cloud computing platform can also be used to run the CU 108 and / or the DU 105. The CU can run in the cloud computing platform, which can be referred to as a virtualized CU (vCU). In addition to the vCU, there can also be a virtualized DU (vDU) running in the cloud computing platform. Furthermore, there can also be a combination where the DU can use a so-called bare metal solution, such as an Application-Specific Integrated Circuit (ASIC) or a Customer-Specific Standard Product (CSSP) System-on-Chip (SoC) solution. It should also be understood that the functional distribution between the above access node units or different core network operations and access node operations may vary.
[0048] Edge cloud can be brought into the Radio Access Network (RAN) by leveraging Network Function Virtualization (NFV) and Software Defined Network (SDN). Using edge cloud can mean that access node operations are to be implemented at least partially in a server, host, or node operably coupled to a Remote Radio Head (RRH) or Radio Unit (RU), or an access node including a radio part. It is also possible that node operations are distributed among multiple servers, nodes, or hosts. The application of the cloud RAN architecture enables the implementation of RAN real-time functions on the RAN side (e.g., in the DU 105), and non-real-time functions can be implemented in a centralized manner (e.g., in the CU 108).
[0049] It should also be understood that the functional distribution between core network operations and access node operations can be different from that of LTE, or may not even exist. Some other technological advancements that can be used include big data and all-IP, which can change the way the network is built and managed. 5G (or New Radio, NR) networks can be designed to support multiple tiers, where the MEC server can be placed between the core and the access node. It should be understood that MEC can also be applied to 4G networks.
[0050] 5G can also utilize non-terrestrial communications. For example, satellite communications, to enhance or supplement the coverage of 5G services, e.g., by providing backhaul. Possible use cases can be to provide service continuity for machine-to-machine (M2M) or Internet of Things (IoT) devices or for passengers on vehicles, or to ensure the service availability of critical communications and future railway / sea / air communications. Satellite communications can utilize geostationary Earth orbit (GEO) satellite systems and can also utilize low Earth orbit (LEO) satellite systems, especially mega-constellations (systems in which hundreds (nanosatellites) are deployed). A given satellite 106 in a mega-constellation can cover a network entity of several supporting satellites that create a terrestrial cell. The terrestrial cell can be created by terrestrial relay nodes or by access nodes 104 located on the ground or in satellites.
[0051] It is expected that 6G networks will adopt flexible decentralized and / or distributed computing systems and architectures and ubiquitous computing, where local spectrum licensing, spectrum sharing, infrastructure sharing, and intelligent automation management are determined by mobile edge computing, artificial intelligence, short-packet communications, and blockchain technologies. Key features of 6G can include management and control functions for intelligent connections, programmability, integrated sensing and communication, reduction of energy footprint, trusted infrastructure, scalability, and affordability. In addition to these, 6G also targets new use cases that integrate positioning and sensing capabilities into the system definition for coverage to unify the user experience across the physical and digital worlds.
[0052] It will be apparent to those skilled in the art that the depicted system is only an example of a part of a radio access system, and in practice, the system can include multiple access nodes, user equipment can access multiple radio cells, and the system can also include other devices, such as physical layer relay nodes or other network elements, etc. At least one of the access nodes can be a home eNodeB or a home gNodeB.
[0053] Additionally, in a geographical area of a radio communication system, multiple different types of radio cells and multiple radio cells can be provided. The radio cells can be macro cells (or umbrella cells), which can be large cells with a diameter of up to several tens of kilometers, or smaller cells, such as micro cells, femto cells, or pico cells. Figure 1 The (multiple) access nodes can provide any of these types of cells. A cellular radio system can be implemented as a multi-layer network including several radio cells. In a multi-layer network, one access node can provide one type of radio cell or multiple radio cells, so multiple access nodes may be required to provide such a network structure.
[0054] To meet the need for improving the deployment and performance of communication systems, the concept of "plug-and-play" access nodes can be introduced. In addition to the Home eNodeB or Home gNodeB, networks that can use "plug-and-play" access nodes can also include the Home Node B Gateway or HNB-GW ( Figure 1 not shown in
[0055] When two or more UEs or a base station and a UE communicate with each other, they may need to check whether the other party of the message passing is trustworthy. There are situations where spoofing or impersonation may occur, and the target (e.g., a UE or a base station or multiple units) will receive a message with modified or forged information.
[0056] For example, two or more UEs can send reference signals to each other, but neither of them can be authenticated (e.g., by the base station). Problems arise when a malicious user ("spoofing party") listens to the communication, changes the non-secure signal, and re-transmits it as if it came from the original transmitter.
[0057] Generally, for any type of signaling, in situations where the integrity of the communication is a concern, adding an additional security layer may be beneficial. Physical layer security provides some advantages, such as time-dependence. Time-dependence means that the signal flow (e.g., in 5G NR) depends on time slots and symbol numbers, and whenever the received time slot and / or symbol number do not match, the receiver can discard the received message.
[0058] Reference signals are typically used for specific purposes in wireless systems, such as for channel acquisition, positioning, delay estimation, channel estimation, etc. Physical layer security has traditionally focused on improving the security or integrity of general data, while here we consider a specific embodiment involving reference signals.
[0059] Reference signals (such as the positioning reference signal (PRS) or sounding reference signal (SRS)) may not contain any encryption themselves. For example, the PRS or SRS can be formed based on a pseudo-random sequence (such as the Zadoff-Chu sequence). The reference signal may not use the same physical channel, such as the physical downlink shared channel (PDSCH), but the PDSCH can be used to configure them (e.g., the PRS) in the presence of a base station. Therefore, the reference signal itself is not encrypted, but the information required to identify it can be encrypted. This information can be sent in the configuration message using the PDSCH. In other words, when in the connected mode (i.e., when a base station link to the UE is established), the reference signal can be protected through configuration on the PDSCH.
[0060] Thus, if a deceiver knows the cell identifier and / or the time slot and symbol numbers, the deceiver may be able to read, modify a reference signal (e.g., PRS or SRS) and re-transmit it to the target. The cell identifier can be used as a seed for a symbol generator, and the time slot and symbol numbers can be part of a configuration message and change over time, thus requiring the demodulation reference signal.
[0061] In sidelink communication (i.e., direct device-to-device communication between two or more UEs), the encryption for the base station as described above may be ineffective because sidelink communication may not be authenticated in the same way. In sidelink communication, the need for authentication may be an issue for the same reasons as described above for the base station case. The target UE (receiving UE) should know how to authenticate the sending UE, i.e., how to authenticate the messages sent by the sending UE.
[0062] A UE can use one of the following resource allocation modes for sidelink: NR sidelink mode 1 (network control mode) or NR sidelink mode 2 (UE autonomous mode). In NR sidelink mode 1, the network (e.g., the base station) allocates sidelink resources for the UE. In NR sidelink mode 2, the UE autonomously selects sidelink resources based on a sensing mechanism. For NR sidelink mode 1, the UE may need to be in the RRC_CONNECTED state, i.e., in network coverage. When the UE is outside network coverage (e.g., when the UE is in the RRC_INACTIVE or RRC_IDLE state), NR sidelink mode 2 can be applied.
[0063] Currently, when the sidelink is not configured by the base station, there is no standardized method to authenticate the message sender in sidelink communication. Therefore, new mechanisms for authentication may be needed, e.g., for out-of-coverage scenarios (i.e., when the UE is outside network coverage).
[0064] Some example embodiments are described below using the principles and terms of 5G technology, however, the example embodiments are not limited to 5G communication systems.
[0065] Some example embodiments relate to the authentication of a transmitter. Authentication in this context means that the identity of the transmitter is verified (at least to a certain confidence level). Authentication may be beneficial in a malicious environment where transmissions may be mimicked, which would lead to incorrect detection and interpretation of reference signals.
[0066] As an example, a malicious attack on the PRS may alter the signal in such a way that the target fails to identify its position within an event. For example, the PRS can be used in autonomous driving to locate the vehicle's position. In traffic, a drop within an event may mean, for example, a collision with an object that is not in the lane on the road (e.g., other cars, poles, etc.), i.e., the car cannot maintain the correct lane. In a more complex scenario, it can also be an object that should not be there in the lane (for normal traffic), but for any reason, it is there and the system detects it and notifies the car. However, due to the attack and thus the failed position information, the braking system may not operate. It should be noted that this is merely an example, and some example embodiments can also be used in other applications besides traffic.
[0067] Some example embodiments provide a method for performing authentication that embeds a secret key in a reference signal (physical layer signal) while still using the reference signal definition. There can be at least two options to increase the modulation order and add authentication: 1) establish a mapping between modulations, transform the signal to a higher-order modulation according to the mapping rules, and apply the authentication key by using a perturbation technique, or 2) add authentication bits to the signal (i.e., directly to the higher-order modulation). The mapping can also be referred to as a label herein.
[0068] When it is desired to increase the integrity of the reference signal, the method can be applied to any reference signal. In this context, integrity refers to positioning integrity, which is a measure of the trust in the accuracy of position-related data provided by a positioning system and the ability to provide timely and effective warnings to a Location Service (LCS) client when the positioning system does not meet the conditions for the expected operation.
[0069] Some example embodiments can be applied to any non-encrypted reference signal, such as the PRS or SRS used for positioning, which are currently not secure in the sidelink mode. Sidelink means that there are two or more UEs communicating with each other, either not configured by a base station or fully or partially configured by a base station. Note that "sidelink" can be referred to as "device-to-device" communication in other standards or other wireless systems, for example.
[0070] In addition to sidelink communication, some example embodiments can also be applied to, for example, downlink communication, uplink communication, Wifi, or Bluetooth.
[0071] Some example embodiments can also be applied to situations where encryption is applied or encryption is possible, but for any reason, an additional security layer is desired.
[0072] It should be noted that some example embodiments are not limited to PRS or SRS for positioning, and they can also be applied to any other reference signals, such as phase-tracking reference signals (PTRS) or channel state information reference signals (CSI-RS). The PRS herein can refer to the downlink PRS. The SRS for positioning can be an uplink reference signal or a sidelink reference signal.
[0073] In an example embodiment, the modulation order of the reference signal can be increased by at least one level in the number of symbol allocations in the in-phase / quadrature (I / Q) space. Increasing the modulation order can mean, for example, using 16QAM modulation instead of QPSK for the reference signal. QAM is an abbreviation for quadrature amplitude modulation, and QPSK is an abbreviation for quadrature phase shift keying. 16QAM is a quadrature amplitude modulation based on a constellation of 16 symbols.
[0074] However, some example embodiments are not limited to QPSK and 16QAM, and higher-order or lower-order modulations can also be used. Thus, for example, if the reference signal is 16QAM and the increased modulation is 32QAM or 64QAM, a similar increase in the modulation order can be accomplished. In principle, if the PRS symbol is QPSK (two bits are mapped to a symbol constellation with a specific label), the increased modulation order can be constructed by multiplexing an additional N bits according to a specific "key" (2^N possible states for each QPSK constellation point). Then, the final result is a signal with 2^(N + 2) states. Additionally, if, for example, the same additional bits are applied to two different symbols, or if they are applied only to some of the PRS symbols in the PRS symbol sequence, it may not be necessary to increase the number of states by a power of 2. The increased constellation or modulation order can be implemented at the bit level (e.g., increasing the bit rate while keeping the symbol rate fixed) or at the symbol level (e.g., summing to each symbol with a fixed symbol rate). In the former case, bit labeling can be performed to achieve the desired technical purpose. For example, the bit label can be changed for at least one symbol in the symbol sequence according to a "key" unknown to potential spoofers.
[0075] For example, the actual reference signal (which is modulated to a higher level of modulation) can be "perturbed" according to a secret key. The perturbation forms a pattern on the modulation constellation over time. Due to the perturbation, existing signals (including pilots) can be used, so the function(s) of the pilot(s) is / are retained. This time-domain pattern is read by the receiver (e.g., the UE), and if it matches the secret key, the transmitter is authenticated. At the same time, the actual reference signal can also be read when it is encoded as 16QAM modulation. If necessary, it can be reduced back to QPSK before demodulation and other functions in the receiver.
[0076] The advantages of time-domain processing or implicitly processing time constraints for authentication purposes arise from the physical layer implementation, as this makes it more difficult for an attacker to read and retransmit a (modified) signal within a desired latency. The higher the latency (due to spoofing), the more likely it is that the receiver will detect that the signal has been spoofed and, for example, make a decision not to use the received signal. If the receiver receives a signal with an excessive latency, the receiver can choose to ignore the signal because there is a possibility that the signal has been modified and retransmitted by an attacker. The physical layer has less processing-related latency and can thus make the time domain (constraint) more stringent. For example, compared to any malicious signal processing, the radio channel itself can be very fast and the delay spread can be short (e.g., 10 - 100 ns). Thus, if the signal arrives at the receiver later than this, the receiver can ignore the signal. Therefore, actual encryption may not need to be as strong as long as it is certain that decrypting the signal by an attacker would take a sufficiently large amount of time.
[0077] Figure 2 Examples of a QPSK modulation constellation 210 and a 16QAM modulation constellation 220 are shown. In Figure 2 this, the given "stars" 211, 221, 222, 223, 224 represent modulation symbols. Modulation symbols can also be referred to as constellation points in this document. Digital data can be transmitted using different symbols corresponding to different bits. QPSK can have 4 symbols and each symbol uses 2 bits (i.e., 2 bits can be used to define a given symbol out of 4 symbols). 16QAM can have 16 symbols and each symbol uses 4 bits, where the first 2 bits can define the quadrant and the last 2 bits can define the 16QAM encoding of a given symbol. Increasing the modulation order enables additional bits to be embedded in the signal for authentication purposes, but it can also reduce the resistance to errors because, for example, depending on the power allocation, the symbols are closer to each other.
[0078] In an example scenario, a UE (e.g., a UE embedded in a vehicle) can initially be within the coverage area of a base station (e.g., a gNB), and the UE can be authenticated by the base station. The UEs can communicate with each other (e.g., using sidelink configuration) in order to control the distance between vehicles, i.e., to continue non-collision traffic. The UE may be approaching an area with weak or no network coverage (e.g., a tunnel without installed repeaters). Thus, the base station notifies the UE (vehicle) that other nearby UEs (vehicles) are authenticated. Then, the vehicle enters the tunnel.
[0079] In a tunnel, the UE can be outside the coverage of the network. However, before the vehicle travels outside the covered area, the base station may have shared the key for the authenticated UE. In this case, the key can be local and time-varying. In the tunnel, autonomous driving (i.e., collision control) can be managed by sidelink communication. This key can be used to prevent malicious deceivers from lying to the UE and to avoid accidents.
[0080] As an example, when using QPSK to 16QAM transformation, the key can be a sequence of 2-bit binary codes (e.g., 00, 01, 11, 10). These 2-bit codes can be used for the same quadrant of the constellation diagram. If higher-order modulation is used, additional bits can be used. The more bits, the higher the complexity of finding the pattern.
[0081] Reference Figure 2 , the perturbation can mean running the transformation, e.g., first from the upper left quadrant of box 210 to the constellation points in the upper left quadrant of box 220 (and the corresponding other quadrants), and applying the perturbation according to the key as follows: encoding 00 does not move the constellation point, encoding 10 moves (rotates) the constellation point once in the clockwise direction in the quadrant (e.g., from point 221 to point 222), encoding 11 moves the constellation point two steps clockwise (e.g., from point 221 to point 224), and 01 moves the constellation point once counterclockwise (e.g., from point 221 to point 223). However, it should be noted that this is only an example, and other perturbation methods and their combinations are also possible. In addition, the base station can instantaneously change the encoding definition. For example, in the next time instance, the base station can define that encoding 00 means moving the symbol two times in the clockwise direction, and so on.
[0082] Figure 3AFIG. 0 shows an example of a modulator 310 that can be used by a transmitter in an example embodiment. A bit stream including a known bit sequence and an authentication key sequence can be fed into the modulator 310 to generate modulated symbols (e.g., 16QAM symbols). The known sequence can be, for example, a Zadoff-Chu sequence, a PRS sequence, or an SRS sequence. The authentication key sequence can be provided by the network or predefined. The association of symbols and bits can be provided by a label, such as Gray labelling. The label can be optionally changed for another symbol or for another symbol sequence. In one embodiment, for example, another 16QAM symbol can apply another label (which is typically unknown to a deceiver) preferably agreed upon by the transmitter and the receiver, where the label is mirrored with respect to the I axis (such that, for example, the labels 0010 and 0000 are swapped, and similarly for 0100, 0110, and for 0001 and 0011, etc.). Obviously, there are other ways to determine the label (e.g., mirroring with respect to the Q axis, etc.). In addition, one symbol can have a Gray label while the next symbol can not. Further, the authentication key sequence can have one or more bits per 16QAM symbol, although two bits (per symbol) are used in the above example. If only one authentication bit is used per symbol, the resulting constellation will be 8QAM instead of 16QAM, as will be clear to those skilled in the art.
[0083] Applying a label can be beneficial such that a perturbed symbol (e.g., a 16QAM symbol) is in the same quadrant of the modulation constellation as the original symbol (e.g., a QPSK symbol). In this way, the authentication scheme can be backward compatible, i.e., a receiver that does not support authentication can still use the reference signal. Further, by keeping the symbols in the same quadrant, the reference signal maintains its orthogonality characteristics with other reference signal sources.
[0084] Figure 3B FIG. 7 shows an example of a first modulator 321 and a second modulator 322 that can be used by a transmitter in another example embodiment. An authentication key sequence can be fed into the first modulator 321, and a known bit sequence can be fed into the second modulator 322. The known sequence can be, for example, a Zadoff-Chu sequence, a PRS sequence, or an SRS sequence. The authentication key sequence can be provided by the network or predefined. The first modulator 321 can generate a first symbol (e.g., a first 4QAM symbol), and the second modulator 322 can generate a second symbol (e.g., a second 4QAM symbol). The first symbol and the second symbol can then be combined to generate a symbol with a higher order modulation (e.g., a 16QAM symbol). A similar use of the label or a change of the label and its indication as described above can be used in this embodiment and applied to the 4QAM symbols.
[0085] Figure 3CAn example of a constellation diagram 330 for Gray-coded 16QAM is shown. In 16QAM, a given symbol can be defined by four bits as shown in FIG. 3, where b 1 represents the first bit, b 2 represents the second bit, b 3 represents the third bit, b 4 represents the fourth bit. If both the first and third bits are zero (b 1 =0, b 3 =0), the symbol can be in the upper left quadrant of the constellation. If the first bit is zero and the third bit is one (b 1 =0, b 3 =1), the symbol can be in the lower left quadrant of the constellation. If the first bit is 1 and the third bit is 0 (b 1 =1, b 3 =0), the symbol can be in the upper right quadrant of the constellation. If the first bit is 1 and the third bit is 1 (b 1 =1, b 3 =1), the symbol can be in the lower right quadrant of the constellation.
[0086] In an example embodiment, as described above, the labels (e.g., from the labels shown in Figure 3C ) can be changed such that the authentication key sequence changes the bit definition for a given 16QAM symbol. For example, the symbols can be rotated according to the key sequence. As another example, the labels can be changed for all bits. As another instance, the labels can be changed only for odd or even bits. For example, the odd and even bits can swap labels so that an eavesdropper does not know it. The specific label method can be predefined or indicated by the network. However, it should be noted that all the labels (or encodings) presented herein are merely examples, and it should be understood that other (e.g., more complex) labels are possible.
[0087] Figure 4 A signaling diagram according to an example embodiment is shown.
[0088] Referring to Figure 4 , in block 401, the transmitter generates a reference signal using a first modulation. The transmitter can be, for example, a UE or a network node (e.g., a base station) of a wireless communication network.
[0089] In block 402, the modulation scheme of the reference signal is changed. In other words, the first modulation is transformed into a second modulation, where the second modulation includes a higher modulation order than the first modulation. For example, the first modulation can include QPSK, and the second modulation can include 16QAM.
[0090] The reference signal itself can be created based on seeds and polynomials defined in 3GPP standards. Therefore, no change is required in the creation of the reference signal. However, the reference signal can be presented in a 16QAM constellation.
[0091] In block 403, the secret key can be embedded into the reference signal through a perturbation technique. Here, perturbation means modifying or changing the modulation pattern of the second modulation in the reference signal in a predefined manner (i.e., based on a predefined key). In this article, the modulation pattern can represent the pattern of constellation points (symbols). For example, as Figure 2 shown. This pattern can be applied to consecutive symbols in the modulation domain. Although the reference signal can be generated in the QPSK domain, the modulation level or complexity can be increased by at least one level to obtain a certain distance ("error distance") between actual modulation constellation points, and thus a certain EVM is intentionally created. As an alternative to the two-dimensional pattern, the key can also include other domains to change the modulation constellation, such as zeroing, power change, time-domain delay, and also frequency shift (however, then applied at different phases of the transmit-receive operation).
[0092] There can be a 1:1 mapping between different levels of modulation. For example, this means that for each QPSK constellation point, there may be a corresponding point in 16QAM explicitly, and similarly for all higher-order modulations. In other words, although the actual signal can be generated into the QPSK domain, a mapping from QPSK to the next supported higher-order modulation can be created. In this article, 16QAM is used as an example of a higher-order modulation (QPSK uses 2 bits per symbol, while 16QAM uses 4 bits per symbol). Therefore, for each QPSK constellation point, there are 4 potential 16QAM points that the QPSK constellation point can correspond to. However, the mapping should be unique, and thus only one of the 4 points in 16QAM is correct (in other words, defined as correct). The other 3 points have certain error distances in the sense of error vector magnitude (EVM). These error distances are also unique, and thus there are four possible perturbations for the constellation points.
[0093] Applying perturbations sequentially, there are four options for each constellation point: 1) no change, 2) change in the in-phase (I) direction, 3) change in the quadrature (Q) direction, or 4) change in both the I and Q directions. In other words, the transmitter can modify the modulation pattern by moving one or more modulation symbols of the modulation pattern in the in-phase direction, or the quadrature direction, or both the in-phase and quadrature directions based on a predefined key.
[0094] Including the option "no change" may increase the computational complexity of the deceiver because there are four options instead of three to analyze. Therefore, not every symbol needs to be perturbed, but the key indicates whether the perturbation is applied to a given symbol.
[0095] It may be beneficial to apply perturbations such that the average transmit power of the reference signal does not change relative to the original (unperturbed) reference signal.
[0096] At block 404, the transmitter uses a second modulation (e.g., 16QAM) and a modified (perturbed) modulation pattern to send a reference signal to the receiver. The receiver receives the reference signal. The receiver can be, for example, another UE or a network node (e.g., a base station) of a wireless communication network.
[0097] In the case of downlink communication, the transmitter can be a base station and the receiver can be a UE. In the case of uplink communication, the transmitter can be a UE and the receiver can be a base station. In the case of sidelink communication, the transmitter can be a UE and the receiver can be another UE.
[0098] It should be noted that in the case of a reference signal, the receiver knows the signal a priori, and thus the "correct" and "perturbed" signals can be distinguished from each other. In the case of other signals than the reference signal, any technique for transmitting the correct signal can be used.
[0099] At block 405, the receiver reads the modulation pattern of the reference signal.
[0100] At block 406, the receiver can inverse-transform the second modulation to the first modulation (e.g., transform 16QAM modulation to QPSK) and process the reference signal based on the first modulation. However, the inverse-transform can be optional. After secret key demodulation, the information of the reference signal is also at a higher level of modulation, and thus the receiver can read the reference signal while the reference signal is encoded as the second modulation.
[0101] At block 407, the receiver compares the modulation pattern read (e.g., 16QAM) with at least the expected modulation pattern, where the expected modulation pattern is based on a predefined key. In other words, the expected modulation pattern can correspond to the expected reference signal with perturbations. The predefined key can be known at the transmitter and the receiver, but it may not be known to other parties. For example, the key can be predefined by the network for the transmitter and the receiver. The comparison can be made in different ways, such as using the EVM metric. The EVM metric uses the concept of EVM when defining the distance of the received constellation points (symbols) to the predefined assumed constellation points (symbols).
[0102] The modulation quality can be defined by the difference between the measured carrier signal and the ideal signal. The modulation quality can be expressed, for example, as EVM. EVM is a measure of the difference between the ideal symbol and the measured symbol after equalization. This difference is called the error vector.
[0103] Thus, each received constellation point (symbol) can be compared with a threshold. Alternatively, in the sense of the error vector, the error can be within a range of two values. If the error of a given constellation point (symbol) is less than a predefined threshold, the perturbation location is found and the process can move to the next constellation point.
[0104] Block 406 and block 407 can be parallel signal processing steps.
[0105] At block 408, the receiver authenticates the transmitter based on this comparison.
[0106] One option to authenticate the transmitter can be to compare the received reference signal with a local reference #1 created in the receiver (e.g., a reference signal with an expected perturbation) and with a local reference #2 created in the receiver (e.g., just the reference signal). If local reference #1 provides a better correlation with the received signal than local reference #2, the authentication can be considered successful. A threshold can optionally be used in the comparison, e.g., if a higher level of trust is required when applying the authentication. In this case, it would not be sufficient for the correlation of local reference #1 to be just better than that of local reference #2, but it should be better by some additional margin indicated by the threshold.
[0107] Figure 5 A flowchart of an example embodiment of a method performed by a device is shown. For example, the device can be or include or be included in a user equipment. The user equipment can also be referred to as a subscriber unit, mobile station, remote terminal, access terminal, user terminal, terminal device, user equipment (UE), or transmitter UE. The user equipment can correspond to Figure 1 UE 100 or Figure 4 the transmitter.
[0108] As another example, the device can be or include or be included in a network node of a wireless communication network. The network node can correspond to Figure 1 access node 104 or Figure 4 the transmitter.
[0109] Referring to Figure 5 , at block 501, modulation symbols are generated based on at least two bit sequences (see the example in Figure 3A ) or at least two symbol sequences (see the instance in Figure 3B ), where at least one of the at least two bit sequences or at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or at least two symbol sequences is associated with a predefined key.
[0110] For example, the modulation symbols can be Figure 4 part of a reference signal.
[0111] At least two bit sequences means at least two different bit sequences, where a given bit sequence can include one or more bits. Similarly, the at least two symbol sequences means at least two different symbol sequences, where a given symbol sequence can include one or more symbols.
[0112] For example, modulation symbols can be generated by providing at least two bit sequences to at least one modulator and applying a label to associate the modulation symbols with the at least two bit sequences. Examples thereof are described above with reference to Figure 3A the description.
[0113] A reference bit sequence or a reference symbol sequence can be associated with at least one of the following: a Zadoff-Chu sequence, a positioning reference signal, and a sounding reference signal.
[0114] A predefined key can be associated with authentication information. The predefined key is known to the expected receiver of the modulation symbols.
[0115] In block 502, the modulation symbols are transmitted.
[0116] Figure 6 FIG. shows a flowchart of an example embodiment of a method performed by a device. For example, the device can be or include or be included in a user equipment. The user equipment can also be referred to as a subscriber unit, a mobile station, a remote terminal, an access terminal, a user terminal, a terminal device, a user equipment (UE), or a transmitter UE. The user equipment can correspond to Figure 1 UE 100 of Figure 4 the transmitter.
[0117] As another example, the device can be or include or be included in a network node of a wireless communication network. The network node can correspond to Figure 1 access node 104 of Figure 4 the transmitter.
[0118] Reference Figure 6 , in block 601, modulation symbols are generated based on at least two bit sequences (see examples of Figure 3A ), where at least one of the at least two bit sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences is associated with a predefined key. Modulation symbols can be generated by providing at least two bit sequences to at least one modulator and applying a label to associate the modulation symbols with the at least two bit sequences.
[0119] A reference bit sequence or a reference symbol sequence can be associated with at least one of the following: a Zadoff-Chu sequence, a positioning reference signal, and a sounding reference signal.
[0120] A predefined key can be associated with authentication information. The predefined key is known to the expected receiver of the modulation symbols.
[0121] In block 602, modulation symbols are transmitted.
[0122] In block 603, an indication is received from a network node, where the indication indicates a change of label.
[0123] In block 604, based on the indication received from the network node, the label is changed for at least one of the following: at least one modulator or at least one other transmitted modulation symbol. At least one other transmitted modulation symbol may be transmitted after the indication is received and the label is changed. The label may be changed in a manner known to the expected receiver. For example, the receiver may also receive an indication from the network node.
[0124] As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases, where the list of two or more elements is joined by "and" or "or", means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.
[0125] Figure 7 A flowchart illustrating an example embodiment of a method performed by a device is shown. For example, the device may be or include or be included in a user equipment. The user equipment may also be referred to as a subscriber unit, a mobile station, a remote terminal, an access terminal, a user terminal, a terminal device, a user equipment (UE), or a receiving UE. The user equipment may correspond to Figure 1 UE 102 of Figure 4 the receiver.
[0126] As another example, the device may be or include or be included in a network node of a radio access network. The network node may correspond to Figure 1 access node 104 of Figure 4 the receiver.
[0127] Referring to Figure 7 , in block 701, modulation symbols are received from a transmitter. For example, the modulation symbols may be Figure 4 part of a reference signal of
[0128] In block 702, the device compares the modulation symbols at least with expected modulation symbols, where the expected modulation symbols are based on a predefined key. For example, the comparison may be based on the error vector magnitude between the received modulation symbols and the expected modulation symbols associated with the predefined key.
[0129] In block 703, the transmitter is authenticated at least in part based on the comparison.
[0130] The above-described boxes, related functions, and information exchange (messages) are not in absolute chronological order, and some of them can be executed simultaneously or in a different order than described. Other functions can also be performed between or within them, and other information can be sent and / or other rules can be applied. Some boxes or parts of boxes or one or more messages can also be omitted or replaced with corresponding boxes or parts of boxes or one or more messages. Figures 4 to 7 The boxes, related functions, and information exchange (messages) described above are not in absolute chronological order, and some of them can be executed simultaneously or in a different order than described. Other functions can also be performed between or within them, and other information can be sent and / or other rules can be applied. Some boxes or parts of boxes or one or more messages can also be omitted or replaced with corresponding boxes or parts of boxes or one or more messages.
[0131] Some of the technical advantages provided by the example embodiments are that they can improve the security of wireless communication. For example, an eavesdropper monitoring a reference signal cannot utilize the signal and the expected receiver because, without knowing the key, the eavesdropper sees a noisier signal (or a completely different signal), and it is more difficult for the eavesdropper to authenticate / crack the signal within a limited time. Time is a factor against deceivers because if the signal arrives too late, the transmitter may decide not to use it due to the risk of malicious manipulation.
[0132] In addition, some of the example embodiments may not require any additional bandwidth because no additional bits need to be presented. Therefore, some of the example embodiments do not require new functions for creating different modulations to be implemented at the hardware level.
[0133] Figure 8 An example of an apparatus 800 including components for performing one or more of the above example embodiments is shown. For example, the apparatus 800 can be an apparatus such as a user equipment or an apparatus including a user equipment or an apparatus included in a user equipment. The user equipment can correspond to Figure 1 user equipment 100, 102 of Figure 4 or one of the transmitters or receivers of
[0134] The user equipment can also be referred to as a subscriber unit, mobile station, remote terminal, access terminal, user terminal, terminal device, or user equipment (UE).
[0135] At least one processor 810 is coupled to at least one memory 820. The at least one processor is configured to read data from and write data to the at least one memory 820. The at least one memory 820 may include one or more memory cells. The memory cells may be volatile or non-volatile. It should be noted that there may be one or more non-volatile memory cells and one or more volatile memory cells, or alternatively, one or more non-volatile memory cells, or alternatively, one or more volatile memory cells. Volatile memory may be, for example, random access memory (RAM), dynamic random access memory (DRAM), or synchronous dynamic random access memory (SDRAM). Non-volatile memory may be, for example, read-only memory (ROM), programmable read-only memory (PROM), electrically erasable programmable read-only memory (EEPROM), flash memory, optical storage, or magnetic storage. Generally, the memory may be referred to as a non-transitory computer-readable medium. As used herein, the term "non-transitory" is a limitation of the medium itself (i.e., tangible, rather than a signal), rather than a limitation on data storage persistence (e.g., RAM versus ROM). The at least one memory 820 stores computer-readable instructions executed by the at least one processor 810 to perform one or more of the above example embodiments. For example, the non-volatile memory stores the computer-readable instructions, and the at least one processor 810 uses the volatile memory to execute the instructions to temporarily store data and / or instructions. The computer-readable instructions may refer to computer program code.
[0136] The computer-readable instructions may be pre-stored in the at least one memory 820, or alternatively or additionally, they may be received by the device via an electromagnetic carrier signal and / or may be copied from a physical entity such as a computer program product. Execution of the computer-readable instructions by the at least one processor 810 causes the device 800 to perform one or more of the above example embodiments. That is, the at least one processor and the at least one memory storing the instructions may provide components for providing or causing the execution of any of the above methods and / or blocks.
[0137] In the context of this document, "memory" or "computer-readable medium" or "computer-readable medium" may be any non-transitory medium or medium or component that can contain, store, communicate, propagate, or transmit instructions for use by or in connection with an instruction execution system, apparatus, or device such as a computer. As used herein, the term "non-transitory" is a limitation of the medium itself (i.e., tangible, rather than a signal), rather than a limitation on data storage persistence (e.g., RAM versus ROM).
[0138] The apparatus 800 may also include or be connected to an input unit 830. The input unit 830 may include one or more interfaces for receiving inputs. The one or more interfaces may include, for example, one or more temperature, motion, and / or orientation sensors, one or more cameras, one or more accelerometers, one or more microphones, one or more buttons, and / or one or more touch detection units. In addition, the input unit 830 may include an interface to which an external device may be connected.
[0139] The apparatus 800 may also include an output unit 840. The output unit may include or be connected to one or more displays capable of presenting visual content, such as a light-emitting diode (LED) display, a liquid crystal display (LCD), and / or a liquid crystal on silicon (LCoS) display. The output unit 840 may also include one or more audio outputs. The one or more audio outputs may be, for example, speakers.
[0140] The apparatus 800 further includes a connection unit 850. The connection unit 850 enables a wireless connection to one or more external devices. The connection unit 850 includes at least one transmitter and at least one receiver that may be integrated into the apparatus 800 or to which the apparatus 800 may be connected. The at least one transmitter includes at least one transmit antenna, and the at least one receiver includes at least one receive antenna. The connection unit 850 may include an integrated circuit or a set of integrated circuits that provides the apparatus 800 with wireless communication capabilities. Alternatively, the wireless connection may be a hardwired application specific integrated circuit (ASIC). The connection unit 850 may also provide components for performing at least some of the blocks of the one or more example embodiments described above. The connection unit 850 may include one or more components controlled by a corresponding control unit, such as: a power amplifier, a digital front end (DFE), an analog-to-digital converter (ADC), a digital-to-analog converter (DAC), a frequency converter, a (de)modulator, and / or an encoder / decoder circuitry.
[0141] It should be noted that the apparatus 800 may also include Figure 8 various components not shown herein. The various components may be hardware components and / or software components.
[0142] Figure 9 An example of an apparatus 900 including components for performing one or more of the example embodiments described above is shown. For example, the apparatus 900 may be an apparatus of a network node such as a radio access network, or an apparatus included in a network node of a radio access network, or an apparatus included in a network node of a radio access network. The network node may correspond to Figure 1 the access node 104 of Figure 4A receiver. A network node may also be referred to as, for example, a network element, a radio access network (RAN) node, a next generation radio access network (NG-RAN) node, a NodeB, an eNB, a gNB, a base transceiver station (BTS), a base station, an NR base station, a 5G base station, an access node, an access point (AP), a relay node, a repeater, an integrated access and backhaul (IAB) node, an IAB donor node, a distributed unit (DU), a central unit (CU), a baseband unit (BBU), a radio unit (RU), a radio head, a remote radio head (RRH), or a transmission and receive point (TRP).
[0143] Apparatus 900 may include, for example, circuitry or a chipset suitable for implementing one or more of the above example embodiments. Apparatus 900 may be an electronic device including one or more electronic circuitry systems. Apparatus 900 may include communication control circuitry 910, such as at least one processor, and at least one memory 920 storing instructions 922 that, when executed by the at least one processor, cause apparatus 900 to perform one or more of the above example embodiments. Such instructions 922 may include, for example, computer program code (software), where the at least one memory and the computer program code (software) are configured to, together with the at least one processor, cause apparatus 900 to perform one or more of the above example embodiments. The at least one processor and the at least one memory storing the instructions may provide means for providing or causing the execution of any of the above methods and / or blocks.
[0144] The processor is coupled to the memory 920. The processor is configured to read data from and write data to the memory 920. The memory 920 may include one or more memory cells. The memory cells may be volatile or non-volatile. It should be noted that there may be one or more non-volatile memory cells and one or more volatile memory cells, or alternatively, one or more non-volatile memory cells, or alternatively, one or more volatile memory cells. Volatile memory may be, for example, random access memory (RAM), dynamic random access memory (DRAM), or synchronous dynamic random access memory (SDRAM). Non-volatile memory may be, for example, read-only memory (ROM), programmable read-only memory (PROM), electrically erasable programmable read-only memory (EEPROM), flash memory, optical storage, or magnetic storage. Generally, the memory may be referred to as a non-transitory computer-readable medium. As used herein, the term "non-transitory" is a limitation of the medium itself (i.e., tangible, rather than a signal), rather than a limitation on data storage persistence (e.g., RAM vs. ROM). The memory 920 stores computer-readable instructions executed by the processor. For example, non-volatile memory stores computer-readable instructions, and the processor uses volatile memory to execute the instructions to temporarily store data and / or instructions.
[0145] The computer-readable instructions may be pre-stored in the memory 920, or alternatively or additionally, they may be received by the device via an electromagnetic carrier signal and / or may be copied from a physical entity such as a computer program product. Execution of the computer-readable instructions causes the device 900 to perform one or more of the above functions.
[0146] The memory 920 may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and / or removable memory. The memory may include a configuration database for storing configuration data. For example, the configuration database may store a list of current neighboring cells, and in some example embodiments, the structure of the frames used in the detected neighboring cells.
[0147] The apparatus 900 may further include a communication interface 930, which includes hardware and / or software for implementing a communication connection according to one or more communication protocols. The communication interface 930 includes at least one transmitter (Tx) and at least one receiver (Rx) that may be integrated into the apparatus 900 or to which the apparatus 900 may be connected. The communication interface 930 may provide components for performing some of the blocks of the one or more example embodiments described above. The communication interface 930 may include one or more components controlled by a corresponding control unit, such as: a power amplifier, a digital front end (DFE), an analog-to-digital converter (ADC), a digital-to-analog converter (DAC), a frequency converter, a (de)modulator, and / or an encoder / decoder circuit.
[0148] The communication interface 930 provides the apparatus with radio communication capabilities to communicate in a cellular communication system. The communication interface may, for example, provide a radio interface to one or more user devices. The apparatus 900 may further include another interface towards a core network, such as a network coordinator device or an AMF, and / or an access node of the cellular communication system.
[0149] The apparatus 900 may further include a scheduler 940 configured to allocate radio resources. The scheduler 940 may be configured together with the communication control circuitry 910 or may be configured separately.
[0150] It should be noted that the apparatus 900 may further include Figure 9 various components not shown in the figure. The various components may be hardware components and / or software components.
[0151] As used in this application, the term "circuitry" may refer to one or more or all of the following: a) only hardware circuit implementations (such as implementations in only analog and / or digital circuitry); and b) combinations of hardware circuits and software, such as, as applicable: i) combinations of (multiple) analog and / or digital hardware circuits and software / firmware, and ii) (multiple) hardware processors and any part of the software, including (multiple) digital signal processors, software, and (multiple) memories that work together to cause an apparatus such as a mobile phone to perform various functions; and c) (multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or parts of (multiple) microprocessors, which require software (such as firmware) to operate, but where the software may not be present when it is not needed to operate.
[0152] This definition of circuitry applies to all uses of the term in this application (including any claims). As another example, as used in this application, the term circuitry also encompasses implementations of only hardware circuits or processors (or multiple processors) or portions of hardware circuits or processors and their (or its) accompanying software and / or firmware. The term circuitry also encompasses, for example and if applicable to a particular claim element, a baseband integrated circuit or a processor integrated circuit for a mobile device or a similar integrated circuit in a server, a cellular network device, or other computing or network device.
[0153] The techniques and methods described herein may be implemented in a variety of ways. For example, these techniques may be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules), or a combination thereof. For a hardware implementation, the (multiple) apparatuses of the example embodiments may be implemented within one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), graphics processing units (GPUs), processors, controllers, microcontrollers, microprocessors, other electronic units designed to perform the functions described herein, or a combination thereof. For firmware or software, the implementation may be through modules of at least one chip set (e.g., procedures, functions, etc.) that perform the functions described herein. The software code may be stored in a memory unit and executed by a processor. The memory unit may be implemented within the processor or external to the processor. In the latter case, it may be communicatively coupled to the processor via various components known in the art. Additionally, the components of the systems described herein may be rearranged and / or supplemented by additional components so as to facilitate the implementation of the various aspects described thereof, etc., and they are not limited to the exact configurations set forth in a given drawing, as will be appreciated by those skilled in the art.
[0154] It will be apparent to those skilled in the art that, as technology progresses, the inventive concept may be implemented in various ways. The embodiments are not limited to the above example embodiments, but may vary within the scope of the claims. Accordingly, all words and expressions should be construed broadly and they are intended to illustrate rather than limit the example embodiments.
Claims
1. A device comprising at least one processor and at least one memory storing instructions which, when executed by the at least one processor, cause the device to at least: generate modulation symbols based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or the at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or the at least two symbol sequences is associated with a predefined key; and transmit the modulation symbols.
2. The device according to claim 1, wherein the reference bit sequence or the reference symbol sequence is associated with at least one of the following: a Zadoff-Chu sequence, a positioning reference signal, and a sounding reference signal.
3. The device according to any one of the preceding claims, wherein the predefined key is associated with authentication information.
4. The device according to any one of the preceding claims, wherein the predefined key is known to a predicted receiver of the modulation symbols.
5. The device according to any one of the preceding claims, wherein the modulation symbols are generated by providing the at least two bit sequences to at least one modulator and applying a tag to associate the modulation symbols with the at least two bit sequences.
6. The device according to claim 5, further being caused to: change the tag for at least one of the following based on an indication received from a network node: the at least one modulator, and at least one other transmitted modulation symbol, wherein the tag is changed in a manner known to a predicted receiver.
7. The device according to any one of the preceding claims, further being caused to: generate a reference signal using a first modulation, wherein the modulation symbols are part of the reference signal; transform the first modulation of the reference signal to a second modulation, wherein the second modulation includes a higher modulation order than the first modulation; modify a modulation pattern of the second modulation in the reference signal based on the predefined key; and transmit the reference signal using the second modulation and the modified modulation pattern.
8. The device according to claim 7, wherein the modulation pattern is modified by moving one or more modulation symbols of the modulation pattern in-phase, or in-quadrature, or both in-phase and in-quadrature based on the predefined key.
9. The device according to any one of claims 7 to 8, wherein the first modulation includes quadrature phase shift keying QPSK, and the second modulation includes 16-quadrature amplitude modulation 16QAM.
10. A device comprising at least one processor and at least one memory storing instructions which, when executed by the at least one processor, cause the device to at least: receive modulation symbols from a transmitter; compare the modulation symbols with at least expected modulation symbols, wherein the expected modulation symbols are based on a predefined key; and authenticate the transmitter at least in part based on the comparison.
11. The apparatus according to claim 10, wherein the comparison is based on an error vector magnitude between the received modulated symbol and the expected modulated symbol.
12. The apparatus according to any one of claims 10 to 11, further configured to: receive a reference signal having a second modulation, wherein the modulated symbol is part of the reference signal; read a modulation mode of the reference signal; compare the modulation mode with at least an expected modulation mode, wherein the expected modulation mode is based on the predefined key; and authenticate the transmitter based on the comparison.
13. The apparatus according to claim 12, further configured to: read the reference signal while the reference signal is encoded with the second modulation.
14. The apparatus according to any one of claims 12 to 13, further configured to: convert the second modulation to a first modulation, wherein the second modulation includes a higher modulation order than the first modulation; and process the reference signal based on the first modulation.
15. A method, comprising: generating a modulated symbol based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or the at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or the at least two symbol sequences is associated with a predefined key; and transmitting the modulated symbol.
16. A method, comprising: receiving a modulated symbol from a transmitter; comparing the modulated symbol with at least an expected modulated symbol, wherein the expected modulated symbol is based on a predefined key; and and authenticating the transmitter at least in part based on the comparison.
17. A non-transitory computer-readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to at least perform the following: generating a modulated symbol based on at least two bit sequences or at least two symbol sequences, wherein at least one of the at least two bit sequences or the at least two symbol sequences is associated with a reference bit sequence or a reference symbol sequence, and at least one other of the at least two bit sequences or the at least two symbol sequences is associated with a predefined key; and transmitting the modulated symbol.
18. A non-transitory computer-readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to at least perform the following: receiving a modulated symbol from a transmitter; comparing the modulated symbol with at least an expected modulated symbol, wherein the expected modulated symbol is based on a predefined key; and authenticating the transmitter at least in part based on the comparison.