Mutual authentication for communication using multiple-input multiple-output (MIMO) signals

By using multiple MIMO paths in wireless communication systems for mutual authentication, the challenge of false transmitters interfering with legal communication is solved, and the security and reliability of the configuration sharing process are achieved.

CN120226004APending Publication Date: 2025-06-27QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380082060.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-21
Filing Date
2023-12-04
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In wireless communication systems, especially in the configuration sharing process using multiple input and multiple output (MIMO) signals, there is a challenge of mutual authentication, especially when preventing false transmitters from interfering with the legitimate send-receive process.

Method used

By exchanging authentication requests, configuration requests, and configuration responses between the transmitter and the receiver, mutual authentication is achieved using different discrete parameters and phase delays to ensure the security and reliability of configuration sharing.

Benefits of technology

This approach improves the security of the adversarial device's inability to manipulate the receiver by sending false configurations, and ensures that the transmitter does not send confidential configurations to the false receiver, enhancing the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120226004A_ABST
    Figure CN120226004A_ABST
Patent Text Reader

Abstract

Systems and techniques for mutual authentication in wireless communications are described herein. For example, a process may include transmitting individual authentication requests using individual MIMO channels between network nodes; sending an authentication proof from one network node to another network node; receiving a configuration request based on a successful authentication of the one network node by the other network node through the corresponding MIMO path; authenticating the configuration request; and transmitting a separate configuration response via the separate MIMO path based on the authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to communication systems, and more particularly to mutual authentication between a transmitter and a receiver during a configuration sharing process using multiple-input multiple-output (MIMO) signals. Background Art

[0002] Wireless communication systems are widely deployed to provide various telecommunication services such as telephony, video, data, messaging, and broadcasting. A typical wireless communication system may employ a multiple access technology capable of supporting communication with multiple users by sharing available system resources. Examples of such multiple access technologies include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems.

[0003] These multiple access technologies have been adopted in various telecommunication standards to provide a common protocol that enables different wireless devices to communicate at the urban, national, regional, and even global levels. An example telecommunication standard is 5G New Radio (NR). 5G NR is part of the continuous evolution of mobile broadband promulgated by the 3rd Generation Partnership Project (3GPP) to meet new requirements associated with latency, reliability, security, scalability (e.g., with the Internet of Things (IoT)), and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine type communication (mMTC), and ultra-reliable low latency communication (URLLC). Some aspects of 5G NR may be based on the 4G Long Term Evolution (LTE) standard. Further improvements to 5G NR technology are needed. These improvements may also apply to other multiple access technologies and telecommunication standards that employ these technologies. Among other possible improvements, it may be necessary to improve data security when sending data using the above technologies, including the security implemented at the physical layer of such data transmission. Summary of the Invention

[0004] In some examples, systems and techniques for mutual authentication in wireless communication are described. According to some aspects of the present disclosure, the systems and techniques may use two or more MIMO paths while exchanging information that allows the corresponding devices participating in the wireless communication to mutually authenticate each other.

[0005] According to at least one example, a process for mutual authentication in wireless communication is provided. The process includes: sending a first authentication request including a first phase from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node; sending a second authentication request including a second phase from the first network node to the second network node via a second MIMO path between the first network node and the second network node; sending an authentication proof from the first network node to the second network node; receiving, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, where the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; receiving, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, where the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; sending a first configuration response in response to the first configuration request at least partially based on authenticating the first configuration request credential; and sending a second configuration response in response to the second configuration request at least partially based on authenticating the second configuration request credential.

[0006] According to at least one example, a process for mutual authentication in wireless communication is provided. The process includes: receiving, at the second network node via a first multiple-input multiple-output (MIMO) path, a first authentication request including a first phase from the first network node; receiving, at the second network node via a second MIMO path, a second authentication request including a second phase from the first network node; receiving an authentication proof at the second network node from the first network node; sending, via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node from the second network node to the first network node, where the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; sending, via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node from the second network node to the first network node, where the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; receiving a first configuration response in response to the first configuration request at least partially based on the authentication of the first configuration request credential; and receiving a second configuration response in response to the second configuration request at least partially based on the authentication of the second configuration request credential.

[0007] In another illustrative example, an apparatus for mutual authentication in wireless communication is provided. The apparatus may include: at least one memory; and at least one processor coupled to the at least one memory and configured to: send a first authentication request including a first phase from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node; send a second authentication request including a second phase from the first network node to the second network node via a second MIMO path between the first network node and the second network node; send an authentication proof from the first network node to the second network node; receive, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, where the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; receive, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, where the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; send a first configuration response in response to the first configuration request based at least in part on authenticating the first configuration request credential; and send a second configuration response in response to the second configuration request based at least in part on authenticating the second configuration request credential.

[0008] In another illustrative example, an apparatus for mutual authentication in wireless communication is provided. The apparatus may include: at least one memory; and at least one processor coupled to the at least one memory and configured to: receive, at a second network node, a first authentication request including a first phase from a first network node via a first multiple-input multiple-output (MIMO) path; receive, at the second network node, a second authentication request including a second phase from the first network node via a second MIMO path; receive, at the second network node, an authentication proof from the first network node; send, via the first MIMO path, from the second network node to the first network node a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; send, via the second MIMO path, from the second network node to the first network node a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; receive a first configuration response in response to the first configuration request, at least partially based on the authentication of the first configuration request credential; and receive a second configuration response in response to the second configuration request, at least partially based on the authentication of the second configuration request credential.

[0009] In some aspects, one or more of the apparatuses described herein are, are part of, and / or include one or more of the following: a mobile or wireless communication device (e.g., a mobile phone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a network-connected watch or other wearable device), a vehicle or a computing device or component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge- or cloud-based server, a personal computer acting as a server device, a mobile device such as a mobile phone acting as a server device, an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system-on-chip (SoC), any combination thereof, and / or other types of devices. In some aspects, the apparatus includes one camera or multiple cameras for capturing one or more images. In some aspects, the apparatus includes a display for displaying one or more images, notifications, and / or other displayable data. In some aspects, the apparatus may include one or more sensors (e.g., one or more RF sensors), such as one or more gyroscopes, one or more gyroscopic testers, one or more accelerometers, any combination thereof, and / or other sensors.

[0010] The invention content is not intended to identify the key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood with reference to the appropriate portions of the entire specification of this patent, any or all of the drawings, and each claim.

[0011] The foregoing, as well as other features and examples, will become more apparent after referring to the following specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is a diagram illustrating an example of a wireless communication system and an access network according to various aspects of the present disclosure.

[0013] Figure 2A is a diagram illustrating an example of a first frame according to various aspects of the present disclosure.

[0014] Figure 2B is a diagram illustrating an example of a downlink (DL) channel within a subframe according to various aspects of the present disclosure.

[0015] Figure 2C is a diagram illustrating an example of a second frame according to various aspects of the present disclosure.

[0016] Figure 2D is a diagram illustrating an example of an uplink (UL) channel within a subframe according to various aspects of the present disclosure.

[0017] Figure 3 is a diagram illustrating an example of a base station and a user equipment (UE) in an access network according to various aspects of the present disclosure.

[0018] Figure 4 is a diagram illustrating an example block diagram of adding artificial physical layer (PHY) impairments.

[0019] Figure 5 is a diagram illustrating an example process for performing secure and reliable configuration sharing according to one or more aspects.

[0020] Figure 6 is a diagram illustrating an example process for performing secure and reliable configuration sharing according to one or more aspects.

[0021] Figure 7 is a diagram of the communication flow of a wireless communication method according to various aspects of the present disclosure.

[0022] Figure 8 is a flowchart of a method of wireless communication according to various aspects of the present disclosure.

[0023] Figure 9A flowchart of a method for wireless communication according to various aspects of the present disclosure.

[0024] Figure 10 A flowchart of a method for wireless communication according to various aspects of the present disclosure.

[0025] Figure 11 A flowchart of a method for wireless communication according to various aspects of the present disclosure.

[0026] Figure 12 A diagram illustrating an example process for secure and reliable configuration sharing using a MIMO channel according to one or more aspects.

[0027] Figure 13 A diagram illustrating an example process for secure and reliable configuration sharing using a MIMO channel according to one or more aspects.

[0028] Figure 14 A flowchart of a method for wireless communication according to various aspects of the present disclosure.

[0029] Figure 15 A flowchart of a method for wireless communication according to various aspects of the present disclosure.

[0030] Figure 16 A diagram illustrating an example of a hardware implementation for an example device and / or network entity according to various aspects of the present disclosure.

[0031] Figure 17 A diagram illustrating an example of a hardware implementation for an example network entity according to various aspects of the present disclosure. Detailed Description

[0032] In some aspects, data confidentiality and integrity in a wireless communication system (e.g., a 5G NR system) can be achieved through upper layer cryptography. Additionally, reference signals can be important in many functions in a wireless communication system (e.g., channel estimation, positioning, etc.). In the absence of secure protection for reference signals, the transmission of reference signals can be vulnerable to malicious attacks. Vulnerable reference signals can also compromise the reliability of subsequent communication functions. Moreover, in some scenarios, certain aspects of reference signals and / or other parameters can be vulnerable to malicious attacks from entities present between a transmitter and a receiver (e.g., within a direct communication path).

[0033] In some aspects, in the presence of non-legitimate (e.g., malicious or false) receivers, a legitimate transmitter can securely and reliably share (transmit) a configuration with a legitimate receiver via a reference signal. On the other hand, in some additional aspects described herein, a legitimate receiver can perform a process for identifying the presence of a non-legitimate (e.g., malicious or false) transmitter, such that the transmission of the reference signal can be made secure and reliable.

[0034] One or more aspects of the present disclosure may relate to physical layer (PHY) authentication techniques for secure and reliable configuration reception via a reference signal to prevent a false transmitter from interfering with a legitimate transmit-receive process (e.g., a false transmitter can interfere with a legitimate transmit-receive process to attempt to steal credentials of a legitimate receiver and / or exploit a misconfiguration to manipulate the legitimate receiver during configuration sharing via the reference signal).

[0035] Specifically, in one or more aspects, a first network node can send an authentication proof to a second network node. The authentication proof can be based on a first credential associated with the first network node (the credential can be any suitable information that can be used to verify the identity of the network node). The first network node can be authenticated based on the authentication proof. The second network node can identify whether the first network node is genuine based on the authentication proof. The second network node can send a configuration request to the first network node. The configuration request can include a phase modulation indication of a second credential associated with the second network node. The configuration request can be based on a phase, which can be a random phase or in some cases a pseudo-random phase. The second network node can be authenticated based on the configuration request. The first network node can send a configuration response to the second network node. The configuration response can include a phase-modulated confidential parameter. The configuration response can be based on the configuration request. Thus, during the configuration sharing process, the transmitter (the first network node) and the receiver (the second network node) can authenticate each other. Thus, an adversarial device may not be able to manipulate the receiver by sending a false configuration. Additionally, the transmitter may not send a confidential configuration to a false receiver.

[0036] In some examples, techniques may be implemented to exchange any number of authentication requests, configuration requests, and / or configuration responses between network nodes during a mutual authentication process using multiple-input multiple-output (MIMO) signals, rather than performing an exchange that includes a single authentication proof, configuration request, and / or configuration response, which may be more resilient to certain attacks where an adversarial device along a direct path between a transmitter and a receiver is less likely to obtain information related to the exchange. Such MIMO-based mutual authentication techniques may use different discrete parameters and / or relative differences between parameters. In some examples, using one or more phase delays between a transmitter and a receiver, an eavesdropper along the signal path between the transmitter and the receiver may be able to decode certain portions of the information transmitted between the transmitter and the receiver, such as, for example, credentials for one of the devices in an authentication device, which are known to the pair of devices to facilitate secure communication.

[0037] The detailed description set forth below in connection with the accompanying drawings is a description of various configurations and does not represent the only configurations in which the concepts described herein may be practiced. To provide a thorough understanding of the various concepts, the detailed description includes specific details. However, the concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring such concepts.

[0038] Certain aspects of a communication system are presented with reference to various apparatuses and methods. These apparatuses and methods are described in the following detailed description and illustrated in the drawings by various blocks, components, circuits, processes, algorithms, etc. (collectively referred to as "elements"). These elements may be implemented using either electronic hardware, computer software, or any combination thereof. Whether such elements are implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system.

[0039] As an example, an element, or any portion of an element, or any combination of elements can be implemented as a "processing system" that includes one or more processors. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, system on a chip (SoC), baseband processors, field programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gated logic components, discrete hardware circuits, and other suitable hardware configured to perform the various functions described throughout this disclosure. One or more processors in the processing system can execute software. Software should be broadly construed to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, processes, functions, or any combination thereof, regardless of whether it is referred to as software, firmware, middleware, microcode, hardware description language, or other terms.

[0040] Thus, in one or more example aspects, embodiments, and / or use cases, the described functionality can be implemented in hardware, software, or any combination thereof. If implemented in software, the functionality can be stored or encoded on a computer-readable medium as one or more instructions or code. Computer-readable media includes computer storage media. Storage media can be any available medium that can be accessed by a computer. By way of example, such computer-readable media can include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage, other magnetic storage devices, combinations of these types of computer-readable media, or any other medium that can be used to store computer-executable code in the form of instructions or data structures that can be accessed by a computer.

[0041] While aspects, embodiments, and / or use cases are described by way of some examples in this application, additional or different aspects, embodiments, and / or use cases may arise in many different arrangements and scenarios. The aspects, embodiments, and / or use cases described herein may be implemented across many different platform types, devices, systems, shapes, sizes, and packaging arrangements. For example, aspects, embodiments, and / or use cases may be implemented via integrated chips and other non-module-component-based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchase devices, medical devices, artificial intelligence (AI)-enabled devices, etc.). Although some examples may or may not be specifically targeted at use cases or applications, the described examples may have broad applicability. Aspects, embodiments, and / or use cases may range from chip-level or modular components to non-modular, non-chip-level embodiments, and further to aggregated, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more of the technologies herein. In some practical settings, devices incorporating the described aspects and features may also include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals necessarily involve multiple components for analog and digital purposes (e.g., hardware components including antennas, RF chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). The technologies described herein may be practiced in a wide variety of devices, chip-level components, systems, distributed arrangements, aggregated components, or disaggregated components, end-user devices, etc., of various sizes, shapes, and configurations.

[0042] The deployment of a communication system (such as a 5G NR system) can be arranged with various components or constituent parts in multiple ways. In a 5G NR system or network, network nodes, network entities, mobility elements of the network, radio access network (RAN) nodes, core network nodes, network elements, or network equipment (such as a base station (BS)) or one or more units (or one or more components) performing base station functions may be implemented in an aggregated or disaggregated architecture. For example, a BS (such as a Node B (NB), evolved NB (eNB), NR BS, 5G NB, access point (AP), transmit receive point (TRP), or cell, etc.) can be implemented as an aggregated base station (also referred to as a stand-alone BS or monolithic BS) or a disaggregated base station.

[0043] A centralized base station may be configured to utilize a radio protocol stack physically or logically integrated within a single RAN node. A split base station may be configured to utilize a protocol stack physically or logically distributed between two or more units, such as one or more central or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs). In some aspects, a CU may be implemented within a RAN node, and one or more DUs may be co-located with the CU, or alternatively, may be geographically or virtually distributed among one or more other RAN nodes. A DU may be implemented to communicate with one or more RUs. Each of the CU, DU, and RU may be implemented as a virtual unit, i.e., a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).

[0044] Base station operation or network design may consider the aggregation characteristics of base station functionality. For example, split base stations may be used in an integrated access backhaul (IAB) network, an open radio access network (O-RAN, such as a network configuration initiated by the O-RAN Alliance), or a virtualized radio access network (vRAN, also known as a cloud radio access network (C-RAN)). Splitting may include distributing functions across two or more units at various physical locations, as well as virtualizing the function of at least one unit, which can achieve flexibility in network design. The various units of a split base station or a split RAN architecture may be configured for wired or wireless communication with at least one other unit.

[0045] Figure 1 FIG. 100 is a diagram illustrating an example of a wireless communication system and an access network. The illustrated wireless communication system includes a split base station architecture. The split base station architecture may include one or more CUs 110, which may communicate directly with the core network 120 via a backhaul link, or indirectly with the core network 120 through one or more split base station units, such as a near real-time (near RT) RAN intelligent controller (RIC) 125 via an E2 link, or a non-real-time (non RT) RIC 115 associated with a service management and orchestration (SMO) framework 105, or both. The CU 110 may communicate with one or more DUs 130 via a respective midhaul link, such as an F1 interface. The DU 130 may communicate with one or more RUs 140 via a respective fronthaul link. The RU 140 may communicate with a respective UE 104 via one or more radio frequency (RF) access links. In some embodiments, the UE 104 may be served simultaneously by multiple RUs 140.

[0046] Each unit (i.e., CU 110, DU 130, RU 140, and the near RT RIC 125, non-RT RIC 115, and SMO framework 105) may include one or more interfaces or be coupled to one or more interfaces that are configured to receive or transmit signals, data, or information (collectively referred to as signals) via a wired or wireless transmission medium. Each of the units or the associated processor or controller that provides instructions to the communication interfaces of these units may be configured to communicate with one or more of the other units via the transmission medium. For example, the units may include a wired interface that is configured to receive signals or transmit signals to one or more of the other units via a wired transmission medium. Additionally, the units may include a wireless interface that may include a receiver, transmitter, or transceiver (such as an RF transceiver) that is configured to receive and / or transmit signals to one or more of the other units via a wireless transmission medium.

[0047] In some aspects, the CU 110 may host one or more high-layer control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptation Protocol (SDAP), etc. Each control function may be implemented using an interface that is configured to convey signals with other control functions hosted by the CU 110. The CU 110 may be configured to handle user plane functionality (i.e., Central Unit - User Plane (CU-UP)), control plane functionality (i.e., Central Unit - Control Plane (CU-CP)), or a combination thereof. In some embodiments, the CU 110 may be logically divided into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units may communicate bidirectionally with the CU-CP units via an interface such as the E1 interface. As needed, the CU 110 may be implemented to communicate with the DU 130 for network control and signaling.

[0048] The DU 130 may correspond to a logical unit that includes one or more base station functions for controlling the operation of one or more RUs 140. In some aspects, the DU 130 may host one or more of the Radio Link Control (RLC) layer, Medium Access Control (MAC) layer, and one or more high Physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation, and demodulation, etc.) at least partially according to a functional split (such as those defined by 3GPP). In some aspects, the DU 130 may also host one or more low PHY layers. Each layer (or module) may be implemented using an interface that is configured to convey signals with other layers (and modules) hosted by the DU 130 or with the control functions hosted by the CU 110.

[0049] Lower layer functionality may be implemented by one or more RUs 140. In some deployments, the RUs 140 controlled by the DU 130 may correspond to logical nodes that host RF processing functions or low PHY layer functions (such as performing fast Fourier transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.) or both, at least partially based on function splitting such as lower layer function splitting. In such an architecture, the RU 140 may be implemented to handle over-the-air (OTA) communication with one or more UEs 104. In some embodiments, the real-time and non-real-time aspects of the control plane communication and user plane communication with the RU 140 may be controlled by the corresponding DU 130. In some scenarios, this configuration may enable the implementation of the DU 130 and CU 110 in a cloud-based RAN architecture such as a vRAN architecture.

[0050] The SMO framework 105 may be configured to support the RAN deployment and orchestration of non-virtualized network elements and virtualized network elements. For non-virtualized network elements, the SMO framework 105 may be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which may be managed via an operation and maintenance interface such as the O1 interface. For virtualized network elements, the SMO framework 105 may be configured to interact with a cloud computing platform such as the Open Cloud (O-Cloud) 190 to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface such as the O2 interface. Such virtualized network elements may include, but are not limited to, the CU 110, DU 130, RU 140, and near RT RIC 125. In some embodiments, the SMO framework 105 may communicate with the hardware aspects of the 4G RAN (such as the Open eNB (O-eNB) 111) via the O1 interface. Additionally, in some embodiments, the SMO framework 105 may communicate directly with one or more RUs 140 via the O1 interface. The SMO framework 105 may also include a non-RT RIC 115 configured to support the functionality of the SMO framework 105.

[0051] The non-RT RIC 115 can be configured to include a logic function that enables non-real-time control and optimization of RAN elements and resources, an artificial intelligence (AI) / machine learning (ML) (AI / ML) workflow including model training and updating, or policy-based guidance of applications / features in the near-RT RIC 125. The non-RT RIC 115 can be coupled to or communicate with the near-RT RIC 125 (such as via the A1 interface). The near-RT RIC 125 can be configured to include a logic function that enables near-real-time control and optimization of RAN elements and resources via data collection and actions through an interface (such as via the E2 interface) that connects one or more CUs 110, one or more DUs 130, or both, and the O-eNB to the near-RT RIC 125.

[0052] In some embodiments, to generate an AI / ML model to be deployed in the near-RT RIC 125, the non-RT RIC 115 can receive parameters or external enrichment information from an external server. Such information can be utilized by the near-RT RIC 125 and can be received from non-network data sources or from network functions at the SMO framework 105 or the non-RT RIC 115. In some examples, the non-RT RIC 115 or the near-RT RIC 125 can be configured to tune RAN behavior or performance. For example, the non-RT RIC 115 can monitor long-term trends and patterns of performance and employ an AI / ML model to perform corrective actions via the SMO framework 105 (such as via reconfiguration of O1) or via creation of RAN management policies (such as A1 policies).

[0053] At least one of CU 110, DU 130, and RU 140 may be referred to as base station 102. Thus, base station 102 may include one or more of CU 110, DU 130, and RU 140 (each component is indicated by a dashed line to indicate that each component may or may not be included in base station 102). Base station 102 provides an access point to core network 120 for UE 104. Base station 102 may include macro cells (high-power cellular base stations) and / or small cells (low-power cellular base stations). Small cells include femto cells, pico cells, and micro cells. A network including both small cells and macro cells may be referred to as a heterogeneous network. The heterogeneous network may also include a home evolved Node B (eNB) (HeNB), which may provide services to a restricted group referred to as a closed subscriber group (CSG). The communication link between RU 140 and UE 104 may include an uplink (UL) (also referred to as a reverse link) transmission from UE 104 to RU 140 and / or a downlink (DL) (also referred to as a forward link) transmission from RU 140 to UE 104. The communication link may use multiple-input multiple-output (MIMO) antenna technology, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be over one or more carriers. For each carrier allocated in carrier aggregation of up to a total of Yx MHz (x component carriers) for transmission in each direction, base station 102 / UE 104 may use a spectrum with a bandwidth of up to Y MHz (e.g., 5 MHz, 10 MHz, 15 MHz, 20 MHz, 100 MHz, 400 MHz, etc.). These carriers may or may not be adjacent to each other. The allocation of carriers may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be allocated for DL compared to UL). Component carriers may include a primary component carrier and one or more secondary component carriers. The primary component carrier may be referred to as a primary cell (PCell) and the secondary component carriers may be referred to as secondary cells (SCells).

[0054] Some UEs 104 may use device-to-device (D2D) communication link 158 to communicate with each other. D2D communication link 158 may use DL / UL wireless wide area network (WWAN) spectrum. D2D communication link 158 may use one or more sidelink channels, such as a physical sidelink broadcast channel (PSBCH), a physical sidelink discovery channel (PSDCH), a physical sidelink shared channel (PSSCH), and a physical sidelink control channel (PSCCH). D2D communication may be through various wireless D2D communication systems, such as, for example, Bluetooth, Wi-Fi based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, LTE, or NR.

[0055] The wireless communication system may also include a Wi-Fi AP 150 that communicates with the UE 104 (also referred to as a Wi-Fi station (STA)) via a communication link 154, e.g., in the 5 GHz unlicensed spectrum or the like. When communicating in the unlicensed spectrum, the UE 104 / AP 150 may perform a Clear Channel Assessment (CCA) before communication to determine whether the channel is available.

[0056] The electromagnetic spectrum is generally subdivided into various categories, bands, channels, etc. based on frequency / wavelength. In 5G NR, two initial operating bands have been identified as Frequency Range Designation FR1 (410 MHz - 7.125 GHz) and FR2 (24.25 GHz - 52.6 GHz). Although a part of FR1 is greater than 6 GHz, in various documents and articles, FR1 is generally (interchangeably) referred to as the "sub-6 GHz" band. Regarding FR2, a similar naming issue sometimes occurs, which is generally (interchangeably) referred to as the "millimeter wave" band in documents and articles, although it is different from the Extremely High Frequency (EHF) band (30 GHz - 300 GHz) identified as the "millimeter wave" band by the International Telecommunication Union (ITU).

[0057] The frequencies between FR1 and FR2 are generally referred to as mid-band frequencies. Recent 5G NR research has identified the operating bands for these mid-band frequencies as Frequency Range Designation FR3 (7.125 GHz - 24.25 GHz). The bands falling within FR3 may inherit the characteristics of FR1 and / or FR2, and thus can effectively extend the features of FR1 and / or FR2 to the mid-band frequencies. In addition, higher bands are currently being explored to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as Frequency Range Designation FR2-2 (52.6 GHz - 71 GHz), FR4 (71 GHz - 114.25 GHz), and FR5 (114.25 GHz - 300 GHz). Each of these higher bands falls within the EHF band.

[0058] Considering the above aspects, unless otherwise specifically stated, if the term "sub-6 GHz" or the like is used herein, it may broadly represent frequencies that can be less than 6 GHz, can be within FR1, or can include mid-band frequencies. In addition, unless otherwise specifically stated, if the term "millimeter wave" or the like is used herein, it may broadly represent frequencies that can include mid-band frequencies, can be within FR2, FR4, FR2-2, and / or FR5, or can be within the EHF band.

[0059] Base station 102 and UE 104 may each include multiple antennas (such as antenna elements, antenna panels, and / or antenna arrays) to facilitate beamforming. Base station 102 may transmit beamformed signal 182 to UE 104 in one or more transmission directions. UE 104 may receive the beamformed signal from base station 102 in one or more reception directions. UE 104 may also transmit beamformed signal 184 to base station 102 in one or more transmission directions. Base station 102 may receive the beamformed signal from UE 104 in one or more reception directions. Base station 102 / UE 104 may perform beam training to determine the optimal reception and transmission directions for each of base station 102 / UE 104. The transmission direction and reception direction of base station 102 may be the same or may not be the same. The transmission direction and reception direction of UE 104 may be the same or may not be the same.

[0060] The base station (or any part herein) and UE may use MIMO communication to utilize multipath signal propagation and improve spectral efficiency by transmitting or receiving multiple signals via different spatial layers. Such techniques may be referred to as spatial multiplexing. The multiple signals may be transmitted, for example, by the transmitting device via different antennas or different combinations of antennas. Similarly, the multiple signals may be received by the receiving device via different antennas or different combinations of antennas. Each of the multiple signals may be referred to as a separate spatial stream and may carry information associated with the same data stream (e.g., the same codeword) or different data streams (e.g., different codewords). Different spatial layers may be associated with different antenna ports for channel measurement and reporting. MIMO techniques include: single-user MIMO (SU-MIMO), for which multiple spatial layers are transmitted to the same receiving device; and multi-user MIMO (MU-MIMO), for which multiple spatial layers are transmitted to multiple devices. Other MIMO techniques may be used without departing from the scope of the examples described herein.

[0061] Base station 102 may include and / or be referred to as gNB, Node B, eNB, access point, base station transceiver, radio base station, radio transceiver, transceiver function, basic service set (BSS), extended service set (ESS), transmission and reception point (TRP), network node, network entity, network equipment, or some other suitable term. Base station 102 may be implemented as an integrated access and backhaul (IAB) node, relay node, sidelink node, an aggregated (monolithic) base station with a baseband unit (BBU) (including CU and DU) and RU, or as a disaggregated base station including one or more of CU, DU, and / or RU. The set of base stations that may include disaggregated base stations and / or aggregated base stations may be referred to as next generation (NG) RAN (NG-RAN).

[0062] The core network 120 may include an Access and Mobility Management Function (AMF) 161, a Session Management Function (SMF) 162, a User Plane Function (UPF) 163, a Unified Data Management (UDM) 164, one or more Location Servers 168, and other functional entities. The AMF 161 is a control node that processes signaling between the UE 104 and the core network 120. The AMF 161 supports registration management, connection management, mobility management, and other functions. The SMF 162 supports session management and other functions. The UPF 163 supports packet routing, packet forwarding, and other functions. The UDM 164 supports the generation of Authentication and Key Agreement (AKA) credentials, user identity handling, access authorization, and subscription management. One or more Location Servers 168 are illustrated as including a Gateway Mobile Location Center (GMLC) 165 and a Location Management Function (LMF) 166. However, in general, one or more Location Servers 168 may include one or more location / locationing servers, which may include one or more of the GMLC 165, LMF 166, a Position Determination Entity (PDE), a Serving Mobile Location Center (SMLC), a Mobile Positioning Center (MPC), etc. The GMLC 165 and LMF 166 support UE location services. The GMLC 165 provides an interface for clients / applications (e.g., emergency services) to access UE location information. The LMF 166 receives measurement and assistance information from the NG-RAN and the UE 104 via the AMF 161 to calculate the location of the UE 104. The NG-RAN may utilize one or more positioning methods to determine the location of the UE 104. Positioning the UE 104 may involve signal measurements, location estimation, and optional speed calculation based on these measurements. The signal measurements may be performed by the UE 104 and / or the serving base station 102. The measured signals may be based on a Satellite Positioning System (SPS) 170 (e.g., a Global Navigation Satellite System (GNSS), a Global Positioning System (GPS), a Non-Terrestrial Network (NTN), or one or more of other satellite positioning / location systems), an LTE signal, a Wireless Local Area Network (WLAN) signal, a Bluetooth signal, a Terrestrial Beacon System (TBS), sensor-based information (e.g., an atmospheric pressure sensor, a motion sensor), an NR Enhanced Cell ID (NR E-CID) method, an NR signal (e.g., multi-round-trip time (multi-RTT), DL Angle of Departure (DL-AoD), DL Time Difference of Arrival (DL-TDOA), UL Time Difference of Arrival (UL-TDOA), and UL Angle of Arrival (UL-AoA) positioning), and / or one or more of other systems / signals / sensors).

[0063] Examples of the UE 104 include cellular phones, smart phones, Session Initiation Protocol (SIP) phones, laptop computers, personal digital assistants (PDAs), satellite radios, global positioning systems, multimedia devices, video devices, digital audio players (e.g., MP3 players), cameras, game consoles, tablet computers, smart devices, wearable devices, vehicles, electricity meters, air pumps, large or small kitchen appliances, healthcare devices, implants, sensors / actuators, displays, or any other device with similar functionality. Some of the UEs in the UE 104 may be referred to as IoT devices (e.g., parking meters, air pumps, toasters, vehicles, heart monitors, etc.). The UE 104 may also be referred to as a station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, cell phone, user agent, mobile client, client, or some other suitable term. In some scenarios, the term UE may also apply to one or more companion devices, such as in a device constellation arrangement. One or more of these devices may access the network jointly and / or access the network individually.

[0064] Referring again to Figure 1 , in some aspects, when operating as a second (receiving) network node, the UE 104 may include a security component 198 that may be configured to receive one or more authentication proofs from a first network node. The one or more authentication proofs may be based on one or more credentials associated with the first network node. The security component 198 may be configured to identify whether the first network node is authentic based on the one or more authentication proofs. The security component 198 may be configured to send one or more configuration requests to the first network node. The one or more configuration requests may include phase modulation indications of one or more second credentials associated with the second network node. The one or more configuration requests may be based on one or more phases (e.g., one or more random phases). The second network node may be able to authenticate based on the one or more configuration requests. The security component 198 may be configured to receive one or more configuration responses from the first network node based on the second network node being authenticated. The one or more configuration responses may include one or more phase-modulated confidential parameters. The one or more configuration parameters may be based on the one or more configuration requests.

[0065] In some aspects, the base station 102, when operating as a first (transmitting) network node, may include a security component 199 that may be configured to send one or more authentication proofs to a second network node. The one or more authentication proofs may be based on one or more credentials associated with the first network node. The first network node may be able to authenticate based on the one or more authentication proofs. The security component 199 may be configured to receive one or more configuration requests from the second network node. The one or more configuration requests may include a phase modulation indication of one or more second credentials associated with the second network node. The one or more configuration requests may be based on one or more phases (e.g., one or more random phases). The security component 199 may be configured to send one or more configuration responses to the second network node. The one or more configuration responses may include one or more phase-modulated confidential parameters. The one or more configuration parameters may be based on the one or more configuration requests. Although the following description may focus on 5G NR, the concepts described herein may be applicable to other similar domains, such as LTE, LTE-A, CDMA, GSM, and other wireless technologies.

[0066] Figure 2A FIG. 200 is an illustration of an example of a first subframe within the 5G NR frame structure. Figure 2B FIG. 230 is an illustration of an example of a DL channel within a 5G NR subframe. Figure 2C FIG. 250 is an illustration of an example of a second subframe within the 5G NR frame structure. Figure 2D FIG. 280 is an illustration of an example of a UL channel within a 5G NR subframe. The 5G NR frame structure may be frequency division duplexing (FDD) (where, for a particular set of subcarriers (carrier system bandwidth), the subframes within that set of subcarriers are dedicated to DL or UL), or may be time division duplexing (TDD) (where, for a particular set of subcarriers (carrier system bandwidth), the subframes within that set of subcarriers are dedicated to both DL and UL). In Figure 2A 、 Figure 2CIn the provided example, the 5G NR frame structure is assumed to be TDD, where subframe 4 is configured with slot format 28 (where most are DL), where D is DL, U is UL, and F is flexibly usable between DL / UL, and subframe 3 is configured with slot format 1 (where all are UL). Although subframes 3 and 4 are shown as having slot formats 1 and 28 respectively, any particular subframe can be configured with any of the various available slot formats 0 - 61. Slot formats 0 and 1 are all - DL and all - UL respectively. The other slot formats 2 - 61 include a mixture of DL, UL, and flexible symbols. The UE is configured with the slot format by receiving a slot format indicator (SFI) (configured dynamically via downlink control information (DCI) or semi - statically / statically via radio resource control (RRC) signaling). Note that the following description also applies to the 5G NR frame structure as TDD.

[0067] Figures 2A to 2D The frame structure is illustrated, and aspects of the present disclosure may be applicable to other wireless communication technologies that may have different frame structures and / or different channels. One frame (10 ms) can be divided into 10 equal - sized subframes (1 ms). Each subframe can include one or more slots. A subframe can also include mini - slots, which can include 7, 4, or 2 symbols. Each slot can include 14 or 12 symbols, depending on whether the cyclic prefix (CP) is normal or extended. For normal CP, each slot can include 14 symbols, and for extended CP, each slot can include 12 symbols. The symbols on the DL can be cyclic prefix orthogonal frequency - division multiplexing (CP - OFDM) symbols. The symbols on the UL can be CP - OFDM symbols (for high - throughput scenarios) or discrete Fourier transform (DFT) - spread OFDM (DFT - s - OFDM) symbols (also known as single - carrier frequency - division multiple access (SC - FDMA) symbols) (for power - limited scenarios; limited to single - stream transmission). The number of slots within a subframe is based on the CP and the parameter set. The parameter set defines the sub - carrier spacing (SCS), and effectively defines the symbol length / duration, which is equal to 1 / SCS.

[0068]

[0069] Table 1, Parameter Set, SCS, and CP

[0070] For normal CP (14 symbols / slot), different parameter sets μ 0 to 4 allow 1, 2, 4, 8, and 16 slots per subframe respectively. For extended CP, parameter set 2 allows 4 slots per subframe. Thus, for normal CP and parameter set μ, there are 14 symbols / slot and 2 µ slots / subframe. The sub - carrier spacing can be equal to , where is the parameter set from 0 to 4. Thus, the subcarrier spacing for parameter set μ = 0 is 15 kHz, and the subcarrier spacing for parameter set μ = 4 is 240 kHz. The symbol length / duration is negatively correlated with the subcarrier spacing. Figures 2A to 2D An example with normal CP having 14 symbols per time slot and parameter set μ = 2 with 4 time slots per subframe is provided. The time slot duration is 0.25 ms, the subcarrier spacing is 60 kHz, and the symbol duration is approximately 16.67 μs. Within the frame set, there may be one or more different bandwidth parts (BWPs) with frequency division multiplexing (see Figure 2B ). Each BWP may have a specific parameter set and CP (normal or extended).

[0071] A resource grid can be used to represent the frame structure. Each time slot includes a resource block (RB) (also known as a physical RB (PRB)) that extends over 12 consecutive subcarriers. The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.

[0072] As Figure 2A illustrated, some of the REs carry reference (pilot) signals (RSs) for the UE. The RSs can include demodulation RSs (DM-RSs) (denoted as R for a specific configuration, but other DM-RS configurations are possible) and channel state information reference signals (CSI-RSs) for channel estimation at the UE. The RSs can also include beam measurement RSs (BRSs), beam refinement RSs (BRRSs), and phase tracking RSs (PT-RSs).

[0073] Figure 2BExamples of various DL channels within a subframe of a frame are illustrated. The Physical Downlink Control Channel (PDCCH) carries DCI within one or more Control Channel Elements (CCEs) (e.g., 1, 2, 4, 8, or 16 CCEs), where each CCE includes six Resource Element groups (REGs), and each REG includes 12 consecutive Resource Elements (REs) in the OFDM symbols of an RB. The PDCCH within a BWP can be referred to as a Control Resource Set (CORESET). The UE is configured to monitor PDCCH candidates in a PDCCH search space (e.g., common search space, UE-specific search space) during a PDCCH monitoring occasion on the CORESET, where the PDCCH candidates have different DCI formats and different aggregation levels. Additional BWPs can be located at higher and / or lower frequencies on the channel bandwidth. The Primary Synchronization Signal (PSS) can be in symbol 2 of a specific subframe of a frame. The PSS is used by the UE 104 to determine subframe / symbol timing and the physical layer identity. The Secondary Synchronization Signal (SSS) can be in symbol 4 of a specific subframe of a frame. The SSS is used by the UE to determine the physical layer cell identity group number and radio frame timing. Based on the physical layer identity and the physical layer cell identity group number, the UE can determine the Physical Cell Identifier (PCI). Based on the PCI, the UE can determine the location of the DM-RS. The Physical Broadcast Channel (PBCH) carrying the Master Information Block (MIB) can be logically grouped with the PSS and SSS to form a Synchronization Signal (SS) / PBCH block (also referred to as an SS block (SSB)). The MIB provides the number of RBs in the system bandwidth and the System Frame Number (SFN). The Physical Downlink Shared Channel (PDSCH) carries user data, broadcast system information not sent via the PBCH (such as System Information Blocks (SIBs)), and paging messages.

[0074] As Figure 2C illustrated, some of the REs carry DM-RS (indicated as R for a specific configuration, but other DM-RS configurations are possible) for channel estimation at the base station. The UE can transmit DM-RS for the Physical Uplink Control Channel (PUCCH) and the Physical Uplink Shared Channel (PUSCH). The PUSCH DM-RS can be transmitted in the previous one or two symbols of the PUSCH. Depending on whether a short PUCCH or a long PUCCH is transmitted and depending on the specific PUCCH format used, the PUCCH DM-RS can be transmitted in different configurations. The UE can transmit a Sounding Reference Signal (SRS). The SRS can be transmitted in the last symbol of a subframe. The SRS can have a comb structure, and the UE can transmit the SRS on one of the teeth of the comb. The SRS can be used by the base station for channel quality estimation to enable frequency-dependent scheduling of the UL.

[0075] Figure 2DExamples of various UL channels within a subframe of a frame are illustrated. The PUCCH may be located at the position indicated in one configuration. The PUCCH carries uplink control information (UCI), such as a scheduling request, a channel quality indicator (CQI), a precoding matrix indicator (PMI), a rank indicator (RI), and a hybrid automatic repeat request (HARQ) acknowledgement (ACK) (HARQ-ACK) feedback (i.e., one or more HARQ ACK bits indicating one or more ACKs and / or negative ACKs (NACKs)). The PUSCH carries data and may additionally be used to carry a buffer status report (BSR), a power headroom report (PHR), and / or UCI.

[0076] Figure 3 Is a block diagram of a base station 310 in an access network communicating with a UE 350. In the DL, Internet Protocol (IP) packets may be provided to a controller / processor 375. The controller / processor 375 implements layer 3 and layer 2 functionality. Layer 3 includes a Radio Resource Control (RRC) layer, and layer 2 includes a Service Data Adaptation Protocol (SDAP) layer, a Packet Data Convergence Protocol (PDCP) layer, a Radio Link Control (RLC) layer, and a Medium Access Control (MAC) layer. The controller / processor 375 provides RRC layer functionality associated with the broadcast of system information (e.g., MIB, SIB), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-radio access technology (RAT) mobility, and measurement configuration for UE measurement reporting; PDCP layer functionality associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functionality associated with the transfer of upper layer packet data units (PDUs), error correction via ARQ, concatenation, segmentation, and reassembly of RLC service data units (SDUs), re-segmentation of RLC data PDUs, and re-ordering of RLC data PDUs; and MAC layer functionality associated with the mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority handling, and logical channel prioritization.

[0077] The transmit (TX) processor 316 and the receive (RX) processor 370 implement layer 1 functionality associated with various signal processing functions. Layer 1, which includes the physical (PHY) layer, may include error detection on the transport channel, forward error correction (FEC) encoding / decoding of the transport channel, interleaving, rate matching, mapping to the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. The TX processor 316 disposes of the mapping to the signal constellation based on various modulation schemes such as binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), M-phase phase shift keying (M-PSK), and M-phase quadrature amplitude modulation (M-QAM). The encoded and modulated symbols may then be split into parallel streams. Each stream may then be mapped to OFDM subcarriers, multiplexed with reference signals (e.g., pilots) in the time domain and / or frequency domain, and then combined together using an inverse fast Fourier transform (IFFT) to generate a physical channel carrying a stream of time-domain OFDM symbols. The OFDM stream is space precoded to generate multiple spatial streams. Channel estimates from the channel estimator 374 may be used to determine the encoding and modulation schemes, as well as for spatial processing. The channel estimates may be derived from reference signals transmitted by the UE 350 and / or channel condition feedback. Each spatial stream may then be provided to a different antenna 320 via a separate transmitter 318Tx. Each transmitter 318Tx may modulate a radio frequency (RF) carrier with the corresponding spatial stream for transmission.

[0078] At the UE 350, each receiver 354Rx receives signals via its corresponding antenna 352. Each receiver 354Rx recovers the information modulated onto the RF carrier and provides the information to the receive (RX) processor 356. The TX processor 368 and the RX processor 356 implement layer 1 functionality associated with various signal processing functions. The RX processor 356 may perform spatial processing on the information to recover any spatial streams destined for the UE 350. If multiple spatial streams are destined for the UE 350, they may be combined by the RX processor 356 into a single OFDM symbol stream. The RX processor 356 then uses a fast Fourier transform (FFT) to convert the OFDM symbol stream from the time domain to the frequency domain. The frequency-domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols and reference signals on each subcarrier are recovered and demodulated by determining the most likely signal constellation points transmitted by the base station 310. These soft decisions may be based on the channel estimates computed by the channel estimator 358. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally transmitted by the base station 310 on the physical channel. The data and control signals are then provided to the controller / processor 359, which implements layer 3 and layer 2 functionality.

[0079] In some examples, although not shown inFigure 3 shown, but the TX processor 316, RX processor 370, various receivers and transmitters (e.g., 318 Tx and 318 RX), and / or antenna 320 may be configured to implement MIMO communication techniques. As an example, multiple antennas may be used to transmit and / or receive signals, thereby allowing multipath signal propagation techniques.

[0080] The controller / processor 359 may be associated with a memory 360 that stores program code and data. The memory 360 may be referred to as a computer-readable medium. In the UL, the controller / processor 359 provides demultiplexing between the transport channel and the logical channel, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets. The controller / processor 359 is also responsible for error detection using the ACK and / or NACK protocols to support HARQ operations.

[0081] Similar to the functionality described in connection with DL transmission by the base station 310, the controller / processor 359 provides RRC layer functionality associated with system information (e.g., MIB, SIB) acquisition, RRC connection, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with the transfer of upper layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, re-segmentation of RLC data PDUs, and re-ordering of RLC data PDUs; and MAC layer functionality associated with the mapping between the logical channel and the transport channel, multiplexing of MAC SDUs onto TBs, demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority handling, and logical channel prioritization.

[0082] Channel estimates derived by the channel estimator 358 based on reference signals or feedback transmitted by the base station 310 may be used by the TX processor 368 to select appropriate decoding and modulation schemes and to facilitate spatial processing. The spatial streams generated by the TX processor 368 may be provided to different antennas 352 via a separate transmitter 354Tx. Each transmitter 354Tx modulates an RF carrier with a corresponding spatial stream for transmission.

[0083] UL transmission is processed at the base station 310 in a manner similar to that described in connection with the receiver functionality at the UE 350. Each receiver 318Rx receives signals via its respective antenna 320. Each receiver 318Rx recovers the information modulated onto the RF carrier and provides the information to the RX processor 370.

[0084] The controller / processor 375 may be associated with a memory 376 that stores program code and data. The memory 376 may be referred to as a computer-readable medium. In the UL, the controller / processor 375 provides demultiplexing between the transport channel and the logical channel, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets. The controller / processor 375 is also responsible for error detection using the ACK and / or NACK protocols to support HARQ operations.

[0085] At least one of the TX processor 368, the RX processor 356, and the controller / processor 359 may be configured to perform aspects of the security component 198 in connection with Figure 1 the aspects of the security component 198 in connection with

[0086] At least one of the TX processor 316, the RX processor 370, and the controller / processor 375 may be configured to perform aspects of the security component 199 in connection with Figure 1 the aspects of the security component 199 in connection with

[0087] In one or more aspects, the transmitter may share with the receiver in advance (i.e., before performing PHY techniques in future steps) a configuration that describes parameters of the PHY techniques (e.g., for security, reliability, etc.). For example, herein, the configuration may refer to a set of parameters that includes all the necessary parameters of the PHY techniques aimed at security and / or reliability. For example, if the PHY technique will add an artificial frequency-domain residual sideband (FDRSB) impairment, the associated configuration may provide the corresponding parameters (e.g., the coefficients of the filter taps) to produce in-phase (I) / quadrature (Q) mismatch. Due to the fast propagation characteristics in the PHY, directly using reference signals to send (share) the configuration in the PHY may have the benefit of a short response time.

[0088] Figure 4 is an example block diagram 400 illustrating the addition of artificial PHY impairments. Artificial PHY impairments (e.g., amplitude-to-phase modulation (AMPM) impairments or FDRSB impairments) may be PHY techniques as described below. For example, artificial PHY impairments may be used as signatures to authenticate the transmitter and encrypt the transmission. The receiver may receive an indication of the PHY impairment from the transmitter. Based on this indication, the receiver may confirm that a transmission with a PHY impairment consistent with the indication was sent by the transmitter. In addition, the receiver may recover the content of the transmission by removing the PHY impairment based on this indication. Adding artificial PHY impairments in the oversampling domain (e.g., the output of the digital front end (DFE) block 408, also referred to as the DAC input) may introduce out-of-band leakage, which may result in violation of the adjacent channel leakage ratio (ACLR) specification. Therefore, artificial PHY impairments may be added in the baseband domain at block 404 between the IFFT block 402 (the IFFT block 402 may receive the output of the baseband frequency-domain processing block 401 as an input) and the DFE block 408.

[0089] Since artificial PHY impairments are introduced into the baseband domain, all impairments can be folded into the band, which can be associated with the cost in terms of error vector magnitude (EVM). Additionally, the added artificial PHY impairments can be removed at the receiver. However, due to other impairments (e.g., thermal noise, channel noise, etc.), removing the artificial PHY impairments at the receiver may not be perfect. In one or more aspects, if artificial PHY impairments are also added to at least one data portion of the downlink traffic (e.g., PDSCH and / or PDCCH), digital post-distortion (DPoD) techniques (which can be applied iteratively) can be utilized to improve (e.g., reduce) the EVM associated with at least one data portion of the downlink traffic.

[0090] In one or more aspects, the transmission from a legitimate transmitter can be: 1) secure directly in the PHY (e.g., via phase difference transmission) such that an adversary capturing the reference signal may not be able to learn the configuration; and 2) authentic such that the transmitter can communicate the configuration only with legitimate receivers.

[0091] In one or more additional configurations, the legitimate receiver can ensure that the party sharing the configuration is not a spoof transmitter (e.g., a spoof transmitter can learn / steal the legitimate receiver's secret credentials and / or manipulate the legitimate receiver with wrong / false configurations to undermine the reliability of subsequent communication steps).

[0092] Thus, according to one or more aspects described herein, to achieve secure and reliable configuration reception via a reference signal, the legitimate receiver can authenticate the transmitter (in addition to the legitimate transmitter authenticating the receiver). In other words, the overall authentication can be mutual, and the legitimate receiver can ensure that its credentials are not captured / stolen by any spoof transmitter. Additionally, mutual authentication can help the legitimate receiver ensure that it is not manipulated by a spoof transmitter with a wrong configuration.

[0093] In one or more aspects, a legitimate receiver may authenticate a transmitter at the start of a configuration sharing process (e.g., before the receiver transmits a configuration request) (e.g., at a first step). The configuration sharing process may refer to a process by which a transmitter may share with a receiver a configuration associated with a PHY technology to be used before the time of the transmission in which the PHY technology is actually used. Additionally, the receiver may trigger the transmitter to transmit the configuration such that the PHY technology can be implemented (e.g., for the receiver to remove an FDRSB impairment, the receiver may need to know the filter taps used by the transmitter to form the impairment, and the receiver may request the transmitter to transmit the configuration associated with the FDRSB impairment). Herein, the trigger provided by the receiver may be referred to as a configuration request. If the transmitter authentication fails (i.e., it proves to be a false transmitter), the legitimate receiver may not continue to transmit its own credentials (e.g., during the configuration request).

[0094] Accordingly, the transmitter may transmit an authentication proof at the start of the configuration sharing process (e.g., the transmitter may share with the receiver a proof indicating that the transmitter is a legitimate transmitter). The authentication proof may include the credentials of the transmitter, where the legitimate receiver may a priori know the credentials of the transmitter. In another example, since there may not be a secret sharing step based on phase difference before transmitting the authentication proof, the credentials of the transmitter may be hidden by an irreversible one-way function (e.g., a hash function) before being transmitted by the transmitter so as to prevent the credentials of the transmitter from being captured in case of exposure. By using the hashed version of the transmitter's credentials, due to the use of an irreversible one-way function, even if the hashed version of the credentials is captured by an unintended receiver / intruder, the credentials cannot be learned. The hashed version of the credentials may be used as proof of the identity of the transmitter to the legitimate receiver since the legitimate receiver can generate the hashed version of the transmitter's credentials itself and can compare the generated version with the received version.

[0095] Authenticating the transmitter at the start of the configuration sharing process can prevent a false transmitter from learning the credentials of the legitimate receiver or manipulating the legitimate receiver with a false configuration. However, this technique may be associated with the following costs: 1) higher computational complexity due to directly performing irreversible one-way function calculations in the PHY, and 2) combining pilots to coherently detect transmitted tags.

[0096] In one or more additional configurations, a legitimate receiver may authenticate the transmitter at the end of the configuration sharing process (e.g., after a configuration request / response has been communicated) (e.g., at a last step). If the configured transmitter is not authenticated at the end of the configuration sharing process, the legitimate receiver may discard the configuration. Accordingly, manipulation of the legitimate receiver via a false configuration can be prevented.

[0097] Thus, the transmitter can convey the credentials of the transmitter at the end of the configuration sharing process (e.g., when sharing the configuration). Specifically, the transmitter can convey the credentials of the transmitter through a phase-difference-based secret sharing technique (e.g., using the channel phase response from the previous step). Authenticating the transmitter at the end of the configuration sharing process can be associated with the advantage of much lower computational cost compared to authenticating the transmitter at the beginning of the configuration sharing process.

[0098] Since the transmitter is authenticated at the end of the configuration sharing process, this technique may not prevent a false transmitter from learning the credentials of the legitimate receiver, because the receiver can convey its credentials before authenticating the transmitter. Thus, if the transmitter cannot be authenticated, the legitimate receiver can revoke its own credentials for further use.

[0099] Figure 5 FIG. is an illustration of an example process 500 for performing secure and reliable configuration sharing according to one or more aspects. The legitimate receiver 502 and the legitimate transmitter 504 may be simply referred to as the receiver 502 and the transmitter 504. Although in some aspects herein, the receiver 502 may correspond to a UE (e.g., UE 104), and the transmitter 504 may correspond to a base station (e.g., base station 102), the present disclosure is not limited thereto. In different configurations, the receiver 502 and the transmitter 504 may suitably correspond to any suitable type of network node.

[0100] As shown, at 506, the transmitter 504 can convey an authentication request to the receiver 502. The authentication request 506 may include a random phase (e.g., any phase between 0 degrees and 360 degrees). In some aspects, the phase may be known to the transmitter 504 but unknown to the receiver 502. In one or more aspects, whenever a new authentication request is conveyed at 506, the transmitter 504 can select a new phase value (e.g., to prevent replay attacks, i.e., to prevent adversarial devices from recording authentication responses to deceive the receiver 502 at a later time). Additionally, in one or more aspects, whenever the transmitter 504 conveys a new authentication request at 506, the transmitter 504 can use a different beam. Specifically, the transmitter 504 can randomly select the beam (e.g., also for preventing replay attacks).

[0101] At 508, the transmitter 504 can convey an authentication tag (also referred to as the authentication proof of the transmitter 504) , where 510 can be the credentials of the transmitter 504, and can be a time index (e.g., a sequence number - to prevent replay attacks). Specifically, the receiver 502 can (a priori) know 510。

[0102] In one or more aspects, an irreversible one-way function (e.g., a hash function) can be used to generate an authentication tag / certificate 508 to hide the content so that the authentication tag / certificate 508 cannot be captured by a rogue device. Since is an irreversible one-way function, even if the authentication tag / certificate 508 is captured by a rogue device, the rogue device may not be able to learn the content (i.e., the input to ).

[0103] The receiver 502 can obtain an estimate of the received authentication tag as , which can be performed in a coherent manner by using additional pilot resources for first estimating the channel (the way of estimating the received authentication tag can be called coherent because the channel estimation is utilized). Then, to perform the authenticity check 512 to authenticate the transmitter 504, the receiver 502 can compare the estimated value with a reconstructed version of 510 can be used by the receiver 502 and tracked by the receiver 502, and the receiver 502 can independently reconstruct a version of

[0104] In one or more aspects, the transmitter 504 can simultaneously transmit random phases and the authentication tag on different subcarriers. In an additional configuration, the random phases and the authentication tag can be transmitted using adjacent time-frequency resources such that the receiver 502 can correlate the two transmissions at 505 and 508 to assume that the two transmissions are from the same source (i.e., the transmitter 504).

[0105] In response to the transmitter 504 transmitting at 506, the phase output of the channel at the receiver 502 can become , where can be a phase rotation due to the RF front end and the channel (propagation through the channel). The receiver 502 can measure as Thus, the receiver 502 can prepare an authentication response including a phase value where 516 can be a phase modulation credential of the receiver 502 that is also known to the transmitter 504. The phase 516 representing the credential of the receiver 502 can be independent of the credential 510. At 514, the receiver 502 can transmit the phase value back to the transmitter 504.

[0106] Even if an adversarial device can measure the transmitted phase , the adversarial device may not be able to learn the phase 516 representing the credential of the receiver 502 because the adversarial device may not be aware that it is the value measured at the receiver 502 rather than at some other device). Thus, the authentication response included in the configuration request 514 can be PHY secure.

[0107] The corresponding phase of the configuration request 514 at the transmitter 504 can be , due to the channel reciprocity between the authentication request 506 and the authentication response / configuration request 514 (i.e., ), and the fact that .

[0108] The transmitter 504 can measure the received phase as . Since the initial random phase is known to the transmitter 504, the transmitter 504 can easily obtain the phase 516 representing the credential of the receiver 502 from the authentication response / configuration request 514. Further, since 516 is known a priori to the transmitter 504, the transmitter 504 can perform an authenticity check 518 by comparing the obtained from the phase output with the known / expected . Specifically, the authenticity check 518 can be based on an authentication test (e.g., a distribution-based hypothesis test, a Hamming distance-based similarity test, etc.) to determine whether the received credential matches the known / expected credential . If the received phase 516 passes the authentication test, the receiver 502 can be authenticated to the transmitter 504. Thus, the transmitter 504 can then start the process for transmitting the configuration. Otherwise, if the receiver is not authenticated, the transmitter 504 can stop participating in the process.

[0109] If the authentication (i.e., the authenticity check at 518) is successfully completed, then at 520, the transmitter 504 can convey the confidential configuration to the authenticated receiver 502 in a PHY-secure manner (e.g., using a phase-difference-based technique). Thus, the transmitter 504 can treat the authentication response at 514 as a configuration request and can prepare a configuration response 520 to include the configuration represented by the phase modulation parameter The configuration response 520 can be sent by the transmitter 504 in response to the configuration request and can include the requested configuration. The transmitter 504 can then build the configuration response 520 based on the phase value , where 522 can be a phase estimate of the channel output for the configuration request. Even if an adversarial device measures the phase , the adversarial device may not be able to learn the phase 522 because the adversarial device may not be aware of . Thus, the adversarial device may not be able to learn the confidential configuration data represented by the phase 522. Therefore, the configuration response 520 can be PHY-secure.

[0110] The corresponding phase of the configuration response 520 at the receiver 502 can then become , due to channel reciprocity (i.e., ) and the fact that can be similarly equivalent to .

[0111] The receiver 502 can then use the estimate of the residual phase to learn the configuration via the correlation parameter (e.g., 522) because is already known to the receiver 502 (the receiver can build while forming the authentication response / configuration request 514).

[0112] In one or more aspects, the phase parameters and (e.g., 516 and 522) can each be multi-bit long. Thus, multiple tones can be used in the frequency domain to send each of the phase parameters and (e.g., 516 and 522) during the transmission of the configuration request 514 and the configuration response 520, respectively.

[0113] In one example, the transmitter 504 can simultaneously send random phases (e.g., on different subcarriers of an OFDM symbol) and authentication tags / certificates . In one or more aspects, the receiver 502 may assume that OFDM symbols carrying valid are from a legitimate transmitter, and thus, when constructing the configuration request 514, may use the phases measured at subcarriers corresponding to (of the same OFDM symbol).

[0114] In different examples, the transmitter 504 may send phases and authentication tags / certificates in adjacent times or frequencies. Thus, the receiver 502 may correlate (bind) the two transmissions (e.g., based on the location of time-frequency resources) to ensure that the two transmissions are from the same transmitter. Thus, in one configuration, the transmitter 504 may generate the authentication tag / certificate as (i.e., the authentication tag / certificate may also be based on ). Further, the receiver 502 may obtain or estimate . Thus, if the authentication tag / certificate sent by the transmitter 504 in another time-frequency resource (e.g., an adjacent resource) is valid (i.e., the transmitter 504 is authenticated), then the receiver 502 may generate an authentication response / configuration request 514 corresponding to . Thus, the time-frequency resources used for transmitting at 506 and for transmitting at 508 may be correlated (bound). Thus, the transmitter 504 may allocate additional subcarriers (along with the subcarriers carrying ) to transmit pilot symbols, thereby helping the receiver 502 to first estimate the channel and then estimate . Based on the estimated , the receiver 502 may then locally generate a version of the authentication proof and may perform an authentication test at 512. If the authentication at 512 is valid (i.e., if the transmitter 504 is authenticated), then the receiver 502 may use the phase response associated with to generate the authentication response / configuration request 514.

[0115] In one or more aspects, because the randomness of the authentication proof may be well provided by , the time dependence may be discarded without exposing the receiver 502 to replay attacks. In other words, at 508, may be used without exposing the receiver 502 to replay attacks.

[0116] Figure 6FIG. 600 is a diagram illustrating an example process 600 for performing secure and reliable configuration sharing according to one or more aspects. The legitimate receiver 602 and the legitimate transmitter 604 may be abbreviated as receiver 602 and transmitter 604. Although in some aspects herein, the receiver 602 may correspond to a UE (e.g., UE 104), and the transmitter 604 may correspond to a base station (e.g., base station 102), the present disclosure is not limited thereto. In different configurations, the receiver 602 and the transmitter 604 may appropriately correspond to any suitable type of network node.

[0117] At 606, the transmitter 504 may transmit an authentication request to the receiver 602. The authentication request 606 may include a random phase . In one or more aspects, the phase may be known to the transmitter 604 but unknown to other devices. In one or more aspects, whenever a new authentication request is transmitted at 606, the transmitter 604 may select a new phase value (e.g., to prevent replay attacks, i.e., to prevent adversarial devices from recording authentication responses to deceive the receiver 602 at a later time). Additionally, in one or more aspects, whenever the transmitter 604 transmits a new authentication request at 606, the transmitter 604 may use a different beam. Specifically, the transmitter 604 may randomly select a beam (e.g., also to prevent replay attacks).

[0118] In response to the transmission by the transmitter 604 , the phase output of the channel at the receiver 602 may become , where may be a phase rotation caused by the RF front end and the channel (propagation through the channel). The receiver 602 may measure as .

[0119] Thus, the receiver 602 may prepare an authentication response including the phase value , where 610a may be a phase modulation credential of the receiver 602 that is also known to the transmitter 604. The phase 610a representing the credential of the receiver 602 may be independent of the credential 610b. At 608, the receiver 602 may transmit the phase value back to the transmitter 604.

[0120] Even if an adversarial device is able to measure the transmitted phase , the adversarial device may not be able to learn the phase 610a representing the credential of the receiver 602, because the adversarial device may not be aware of is the value measured at the receiver 602, rather than at other devices). Thus, the authentication response included in the configuration request 608 can be PHY-secure.

[0121] The corresponding phase of the configuration request 608 at the transmitter 604 can be , due to the channel reciprocity between the authentication request 606 and the configuration request 608 (i.e., ), and the fact that it can be equivalent to .

[0122] The transmitter 604 can measure the received phase as . Since the initial random phase is known to the transmitter 604, the transmitter 604 can easily obtain from the configuration request 608 the phase 610a representing the credentials of the receiver 602. Additionally, since 610a is known a priori to the transmitter 604, the transmitter 604 can perform an authenticity check 612 by comparing the obtained from the phase output with the known / expected . Specifically, the authenticity check 612 can be based on an authentication test (e.g., a hypothesis test based on distribution, a similarity test based on Hamming distance, etc.) to determine whether the received credentials match the known / expected credentials . If the received phase 610a passes the authentication test, the receiver 602 can be authenticated for the transmitter 604. Thus, the transmitter 604 can then start the process for transmitting the configuration. Otherwise, if the receiver is not authenticated, the transmitter 604 can stop participating in the process.

[0123] If the authentication (i.e., the authenticity check at 612) is successfully completed, the transmitter 604 can transmit both an authentication proof 614 and a configuration response 616 including a confidential configuration to the authenticated receiver 602 in a PHY-secure manner (e.g., using a phase-difference-based technique).

[0124] The authentication proof 614 can include the credentials of the transmitter 604. Specifically, the credentials of the transmitter 604 can be represented by the phase-modulated credentials 610b in the authentication proof 614. Additionally, the configuration response 616 can include the configuration represented by the phase-modulation parameter 618.

[0125] The transmitter 604 can construct the authentication proof 614 and the configuration response 616 based on the phase values and respectively, where can be a phase estimate of the channel output associated with the configuration request 608. Even if the adversary measures either of them, the adversary may not be able to learn the hidden phase or (e.g., 610b or 618), because the adversary may not be aware of . Thus, the authentication proof 614 and the configuration response 616 can be communicated in a PHY-secure manner.

[0126] The respective phase outputs of the authentication proof 614 and the configuration response 616 at the receiver 602 can become , due to channel reciprocity (i.e., ) and the fact that which can be respectively equivalent to and . Because is already available to the receiver 602 (the receiver 602 can construct when forming the configuration request 608), the noise estimates of both 610b and 618 can become available to the receiver 602. Additionally, because 610b is known a priori to the receiver 602, the receiver 602 can perform an authenticity check 620 by comparing the obtained from the phase output with the known / expected . Specifically, the authenticity check 620 can be based on an authentication test (e.g., a distribution-based hypothesis test, a Hamming distance-based similarity test, etc.) to determine whether the received credential matches the known / expected credential . If the received credential 610b passes the authentication test at 620, the receiver 602 can then conclude the legitimacy of the transmitter 604 and can proceed to learn / use the configuration (e.g., the parameters represented by 618). Otherwise, if the transmitter is not authenticated, the receiver 602 can discard the received configuration.

[0127] In one or more aspects, the phase parameters , and (e.g., 610b, 610a and 618) Each may be multi-bit long. Thus, multiple tones can be used in the frequency domain to send phase parameters during the transmission of authentication proof 614, configuration request 608, and configuration response 616, respectively. , and (e.g., 610b, 610a and 618) for each of them.

[0128] In some aspects, transmitter 504 / 604 may include (e.g., append) a cyclic redundancy check (CRC) (e.g., using frequency domain resource blocks) in the phase parameter (e.g., 522 / 618) so that receiver 502 / 602 can verify the accuracy of the received phase 522 / 618 and thus verify the configuration. If receiver 502 / 602 identifies the received phase 522 / 618 as inaccurate based on the CRC, then receiver 502 / 602 can send a negative acknowledgment (NACK) to transmitter 504 / 604. Thus, in some aspects, if transmitter 504 / 604 does not receive a NACK (e.g., within a time window after transmission), then transmitter 504 / 604 can assume that receiver 502 / 602 has correctly learned the configuration.

[0129] If transmitter 504 / 604 receives a NACK, in one configuration, transmitter 504 / 604 can follow the same process as described above to attempt to re-share the configuration. In another configuration, if transmitter 504 / 604 receives a NACK, then transmitter 504 / 604 can pause the configuration sharing process for a pre-configured period of time. In some aspects, if the pause period is longer than the network-selected authentication lifetime or channel coherence time, then the authentication process can also be repeated before resuming the configuration transmission.

[0130] Due to channel reciprocity and defects in phase estimation, the measured , and may be inaccurate / wrong (i.e., deviate from the correct value). Thus, to reduce the negative impact of the deviation, in some aspects, a transmit-receive pair (e.g., transmitter 504 / 604 - receiver 502 / 602 pair) can (periodically or from time to time) exchange known phase parameters , and to measure and quantify , and The error between the received value and the expected / correct value (using , since can be used for the corresponding associated device / party).

[0131] In some aspects, as described above, depending on whether the data sent is known or unknown to the receivers 502 / 602, the network can set thresholds for the errors associated with , and either dynamically or statically. In some aspects, different thresholds can be set for the errors associated with , and . In some aspects, if the error measurements for , and are all below their respective thresholds, a phase-difference-based configuration sharing process as illustrated in Figure 5 and Figure 6 can be allowed. On the other hand, if at least one of the error measurements for , and is below its respective threshold, the phase-difference-based configuration sharing process can be suspended until at least the next phase error is measured.

[0132] Figure 7 is a diagram of a communication flow 700 of a method of wireless communication. As shown, a first network node 702 can correspond to the transmitters 504 / 604, and a second network node 704 can correspond to the receivers 502 / 602. At 706, the first network node 702 can send an authentication request to the second network node 704. The authentication request can include a random phase.

[0133] In one configuration, the authentication request 706 can be associated with a randomly selected beam.

[0134] At 708a or 708b, the first network node 702 can send an authentication proof to the second network node 704. The authentication proof can be based on a first credential associated with the first network node 702. The first network node 702 can authenticate based on the authentication proof.

[0135] At 712a or 712b, the second network node 704 can identify whether the first network node 702 is genuine based on the authentication proof 708a or 708b.

[0136] In one configuration, the first network node 702 can authenticate based on a distribution-based hypothesis test or a Hamming distance-based similarity test.

[0137] At 714, the second network node 704 may send a configuration request to the first network node 702. The configuration request may include a phase modulation indication of a second credential associated with the second network node 704 (i.e., the representation of (binary) data according to a phase pair). The configuration request may be based on a random phase. The second network node 704 may authenticate based on the configuration request.

[0138] In one configuration, before the first network node 702 receives the configuration request 714 from the second network node 704, the first network node 702 may send an authentication proof 708a to the second network node 704. Based on the first network node 702 being authenticated based on the authentication proof 708a, the first network node 702 may receive the configuration request 714 from the second network node 704.

[0139] In one configuration, the authentication proof 708a may also be based on a time index and an irreversible one-way function.

[0140] In one configuration, the authentication request 706 and the authentication proof 708a may be sent simultaneously via different subcarriers.

[0141] In one configuration, the authentication request 706 and the authentication proof 708a may be sent via adjacent time-frequency resources. The authentication proof 708a may also be based on a random phase and a one-way hash function.

[0142] In one configuration, after the first network node 702 receives the configuration request 714 from the second network node 704, the first network node 702 may send an authentication proof 708b to the second network node 704.

[0143] In one configuration, the authentication proof 708b may also be based on the configuration request 714.

[0144] In one configuration, the authentication proof 708b may be associated with multiple tones.

[0145] In one configuration, the configuration request 714 and the configuration response 718 may each be associated with multiple tones.

[0146] In one configuration, a first transmission from the first network node 702 to the second network node 704 may be subject to a first phase rotation (e.g., total phase rotation) associated with the first transmission, and the first phase rotation is reciprocal to a second phase rotation (e.g., total phase rotation) associated with a second transmission from the second network node 704 to the first network node 702. The second transmission may be subject to the second phase rotation.

[0147] At 716, the first network node 702 may identify whether the second network node 704 is authentic based on the configuration request 714.

[0148] In one configuration, it can be identified whether the second network node 704 is genuine based on a distribution-based hypothesis test or a Hamming distance-based similarity test.

[0149] At 718, the first network node 702 can send a configuration response to the second network node 704. The configuration response can include phase-modulated confidential parameters (i.e., the confidential parameters can be represented according to the phase) (the confidential parameters can include, for example, parameters of the PHY technology). The configuration response can be based on the configuration request 714. If the second network node 704 is identified as genuine, the configuration response can be sent to the second network node 704.

[0150] At 720, the second network node 704 can obtain a PHY signature based on the configuration response 718.

[0151] At 722, the second network node 704 can perform 722a or 722b. At 722a, if the first network node 702 is identified as genuine, the second network node 704 can demodulate another transmission from the first network node 702 based on the PHY signature.

[0152] At 722b, if the first network node 702 is identified as not genuine based on the authentication proof 708b, the second network node 704 can revoke the second credential associated with the second network node 704.

[0153] At 724, the first network node 702 can receive a NACK from the second network node 704 based on the CRC.

[0154] At 726a, in response to the NACK, the first network node 702 can retransmit the configuration response to the second network node 704.

[0155] At 726b, in response to the NACK, the first network node 702 can suppress sending the configuration response to the second network node 704 within a predetermined time period.

[0156] Figure 8 It is a flowchart 800 of a method for wireless communication. The method can be executed by a base station or a first (transmitting) network node (e.g., base station 102 / 310; transmitter 504 / 604; first network node 702; network entity 1602). At 802, the first network node can send an authentication proof to the second network node. The authentication proof can be based on a first credential associated with the first network node. The first network node can authenticate based on the authentication proof. For example, 802 can be executed by Figure 17 component 199 in. Refer to Figure 7 , at 708a or 708b, the first network node 702 can send an authentication proof to the second network node 704.

[0157] At 804, a first network node may receive a configuration request from a second network node. The configuration request may include an indication of phase modulation of a second credential associated with the second network node. The configuration request may be based on a random phase. For example, 804 may be performed by Figure 17 component 199 in Figure 7 , at 714, the first network node 702 may receive a configuration request from the second network node 704.

[0158] At 806, the first network node may send a configuration response to the second network node. The configuration response may include a phase-modulated confidential parameter. The configuration response may be based on the configuration request. For example, 806 may be performed by Figure 17 component 199 in Figure 7 , at 718, the first network node 702 may send a configuration response to the second network node 704.

[0159] Figure 9 is a flowchart 900 of a method of wireless communication. The method may be performed by a base station or a first (transmitting) network node (e.g., base station 102 / 310; transmitter 504 / 604; first network node 702; network entity 1602). At 904, the first network node may send an authentication proof to the second network node. The authentication proof may be based on a first credential associated with the first network node. The first network node may authenticate based on the authentication proof. For example, 904 may be performed by Figure 17 component 199 in Figure 7 , at 708a or 708b, the first network node 702 may send an authentication proof to the second network node 704.

[0160] At 906, the first network node may receive a configuration request from the second network node. The configuration request may include an indication of phase modulation of a second credential associated with the second network node. The configuration request may be based on a random phase. For example, 906 may be performed by Figure 17 component 199 in Figure 7 , at 714, the first network node 702 may receive a configuration request from the second network node 704.

[0161] At 910, the first network node may send a configuration response to the second network node. The configuration response may include a phase-modulated confidential parameter. The configuration response may be based on the configuration request. For example, 910 may be performed by Figure 17 component 199 in Figure 7 , at 718, the first network node 702 may send a configuration response to the second network node 704.

[0162] In one configuration, at 902, a first network node may send an authentication request to a second network node. The authentication request may include a random phase. For example, 902 may be performed by Figure 17 component 199 in. Refer to Figure 7 , at 706, a first network node 702 may send an authentication request to a second network node 704.

[0163] At 908, the first network node may identify whether the second network node is genuine based on a configuration request. If the second network node is identified as genuine, a configuration response may be sent to the second network node. For example, 908 may be performed by Figure 17 component 199 in. Refer to Figure 7 , at 716, a first network node 702 may identify whether a second network node 704 is genuine based on a configuration request 714.

[0164] In one configuration, refer to Figure 7 , the authentication request 706 may be associated with a randomly selected beam.

[0165] In one configuration, refer to Figure 7 , it may be possible to identify whether the second network node 704 is genuine at 716 based on a distribution-based hypothesis test or a Hamming distance-based similarity test.

[0166] In one configuration, refer to Figure 7 , an authentication proof 708a may be sent to the second network node 704 before receiving the configuration request 714 from the second network node 704. Based on the first network node 702 being authenticated based on the authentication proof 708a, the configuration request 714 may be received from the second network node 704.

[0167] In one configuration, refer to Figure 7 , the authentication proof 708a may also be based on a time index and an irreversible one-way function.

[0168] In one configuration, refer to Figure 7 , the authentication request 706 and the authentication proof 708a may be sent simultaneously via different subcarriers.

[0169] In one configuration, refer to Figure 7 , the authentication request 706 and the authentication proof 708a may be sent via adjacent time-frequency resources. The authentication proof 708a may also be based on a random phase and a one-way hash function.

[0170] In one configuration, refer to Figure 7 , an authentication proof 708b may be sent to the second network node 704 after receiving the configuration request 714 from the second network node 704.

[0171] In one configuration, reference Figure 7 , the authentication proof 708b may also be based on the configuration request 714.

[0172] In one configuration, reference Figure 7 , the authentication proof 708b may be associated with multiple tones.

[0173] In one configuration, reference Figure 7 , the configuration request 714 and the configuration response 718 may each be associated with multiple tones.

[0174] In one configuration, reference Figure 7 , the first transmission from the first network node 702 to the second network node 704 may be subject to a first phase rotation associated with the first transmission, and the first phase rotation is reciprocal to a second phase rotation associated with a second transmission from the second network node 704 to the first network node 702. The second transmission may be subject to the second phase rotation.

[0175] In one configuration, reference Figure 7 , the first network node 702 may authenticate based on a distribution-based hypothesis test or a Hamming distance-based similarity test.

[0176] Figure 10 is a flowchart 1000 of a method of wireless communication. The method may be performed by a UE or a second (receiving) network node (e.g., UE 104 / 350; receiver 502 / 602; second network node 704; device 1604). At 1002, the second network node may receive an authentication proof from the first network node. The authentication proof can be based on a first credential associated with the first network node. For example, 1002 may be performed by Figure 16 component 198 in. Reference Figure 7 , at 708a or 708b, the second network node 704 may receive an authentication proof from the first network node 702.

[0177] At 1004, the second network node may identify whether the first network node is authentic based on the authentication proof. For example, 1004 may be performed by Figure 16 component 198 in. Reference Figure 7 , at 712a or 712b, the second network node 704 may identify whether the first network node 702 is authentic based on the authentication proof 708a or 708b.

[0178] At 1006, the second network node may send a configuration request to the first network node. The configuration request can include a phase modulation indication of a second credential associated with the second network node. The configuration request can be based on a random phase. The second network node can authenticate based on the configuration request. For example, 1006 may be performed by Figure 16by component 198 in Figure 7 At 714, the second network node 704 may send a configuration request to the first network node 702.

[0179] At 1008, the second network node may receive a configuration response from the first network node based on the second network node being authenticated. The configuration response may include phase-modulated confidential parameters. The configuration response may be based on the configuration request. For example, 1008 may be performed by Figure 16 component 198 in Figure 7 At 718, the second network node 704 may receive a configuration response from the first network node 702 based on the second network node 704 being authenticated.

[0180] Figure 11 is a flowchart 1100 of a method of wireless communication. The method may be performed by a UE or a second (receiving) network node (e.g., UE 104 / 350; receiver 502 / 602; second network node 704; device 1604). At 1104, the second network node may receive an authentication proof from the first network node. The authentication proof may be based on a first credential associated with the first network node. For example, 1104 may be performed by Figure 16 component 198 in Figure 7 At 708a or 708b, the second network node 704 may receive an authentication proof from the first network node 702.

[0181] At 1106, the second network node may identify whether the first network node is authentic based on the authentication proof. For example, 1106 may be performed by Figure 16 component 198 in Figure 7 At 712a or 712b, the second network node 704 may identify whether the first network node 702 is authentic based on the authentication proof 708a or 708b.

[0182] At 1108, the second network node may send a configuration request to the first network node. The configuration request may include a phase modulation indication of a second credential associated with the second network node. The configuration request may be based on a random phase. The second network node may be authenticated based on the configuration request. For example, 1108 may be performed by Figure 16 component 198 in Figure 7 At 714, the second network node 704 may send a configuration request to the first network node 702.

[0183] At 1110, a second network node may receive a configuration response from a first network node based on the second network node being authenticated. The configuration response may include phase-modulated confidential parameters. The configuration response may be based on the configuration request. For example, 1110 may be performed by Figure 16 component 198 in. Refer to Figure 7 , at 718, the second network node 704 may receive a configuration response from the first network node 702 based on the second network node 704 being authenticated.

[0184] In one configuration, at 1102, the second network node may receive an authentication request from the first network node. The authentication request may include a random phase. For example, 1102 may be performed by Figure 16 component 198 in. Refer to Figure 7 , at 706, the second network node 704 may receive an authentication request from the first network node 702.

[0185] At 1112, the second network node may obtain a PHY signature based on the configuration response. For example, 1112 may be performed by Figure 16 component 198 in. Refer to Figure 7 , at 720, the second network node 704 may obtain a PHY signature based on the configuration response 718.

[0186] At 1114, if the first network node is identified as being authentic, the second network node may demodulate another transmission from the first network node based on the PHY signature. For example, 1114 may be performed by Figure 16 component 198 in. Refer to Figure 7 , at 722a, if the first network node 702 is identified as being authentic, the second network node 704 may demodulate another transmission from the first network node 702 based on the PHY signature.

[0187] In one configuration, refer to Figure 7 , the authentication request 706 may be associated with a random beam.

[0188] In one configuration, refer to Figure 7 , an authentication proof 708a may be received from the first network node 702 before sending a configuration request 714 to the first network node 702. If the first network node is identified as being authentic based on the authentication proof 708a, the configuration request 714 may be sent to the first network node 702.

[0189] In one configuration, refer to Figure 7 , the authentication proof 708a may also be based on a time index and an irreversible one-way function.

[0190] In one configuration, refer to Figure 7, the authentication request 706 and the authentication certificate 708a can be received simultaneously via different subcarriers.

[0191] In one configuration, referring to Figure 7 , the authentication request 706 and the authentication certificate 708a can be received via adjacent time-frequency resources. The authentication certificate 708a can also be based on a random phase and a one-way hash function.

[0192] In one configuration, referring to Figure 7 , the authentication certificate 708b can be received from the first network node 702 after sending a configuration request 714 to the first network node 702.

[0193] In one configuration, referring to Figure 7 , the authentication certificate 708b can also be based on the configuration request 714.

[0194] In one configuration, at 1116, if the first network node is identified as not being authentic based on the authentication certificate, the second network node can revoke the second credential associated with the second network node. For example, 1116 can be performed by Figure 16 component 198 in. Referring to Figure 7 , at 722b, if the first network node 702 is identified as not being authentic based on the authentication certificate 708b, the second network node 704 can revoke the second credential associated with the second network node 704.

[0195] In one configuration, referring to Figure 7 , the authentication certificate 708b can be associated with multiple tones.

[0196] In one configuration, referring to Figure 7 , the configuration request 714 and the configuration response 718 can each be associated with multiple tones.

[0197] In one configuration, referring to Figure 7 , the first transmission from the first network node 702 to the second network node 704 can be subject to a first phase rotation associated with the first transmission, and the first phase rotation is reciprocal to a second phase rotation associated with a second transmission from the second network node 704 to the first network node 702. The second transmission can be subject to the second phase rotation.

[0198] In one configuration, referring to Figure 7 , it can be identified whether the first network node 702 is authentic based on a first distribution-based hypothesis test or a first Hamming distance-based similarity test. The second network node 704 can authenticate based on a second distribution-based hypothesis test or a second Hamming distance-based similarity test.

[0199] Figure 12FIG. is an illustration of an example process 1200 for performing secure and reliable configuration sharing in accordance with one or more aspects. The legitimate receiver 1202 and the legitimate transmitter 1204 may be abbreviated as receiver 1202 and transmitter 1204. Although in some aspects herein, the receiver 1202 may correspond to a UE (e.g., UE 104), and the transmitter 1204 may correspond to a base station (e.g., base station 102), the present disclosure is not limited thereto. In different configurations, the receiver 1202 and the transmitter 1204 may suitably correspond to any suitable type of network node.

[0200] As shown, at 1206, the transmitter 1204 may transmit any two or more authentication requests to the receiver 1202 via two or more MIMO signal paths. Each authentication request 1206 may include a random phase (e.g., any phase between 0 degrees and 360 degrees). In some aspects, the phase may be known to the transmitter 1204, but unknown to the receiver 1202. In one or more aspects, whenever a new authentication request is transmitted at 1206, the transmitter 1204 may select a new phase value (e.g., to prevent replay attacks, i.e., to prevent an adversarial device from recording an authentication response to deceive the receiver 1202 at a later time). Additionally, in one or more aspects, whenever the transmitter 1204 transmits a new authentication request at 1206, the transmitter 1204 may use a different beam. Specifically, the transmitter 1204 may randomly select a beam (e.g., also to prevent replay attacks).

[0201] As an example, the transmitter 1204 may transmit multiple authentication requests to the receiver 1202 along multiple MIMO paths (e.g., 1 and 2 as Figure 12 shown), which are composed of random phases 1 and 2. Each MIMO path is a signal path between the transmitter and the receiver, and the multiple MIMO paths are spatially separated. In some examples, the random phases 1 and 2 need to be known only to the transmitter. Although Figure 12 an example using both 1 and 2 is shown, some examples may alternatively use relative phases. As an example, if there are two random phases, the difference between the phases may be used as an authentication request parameter. In examples where there are more than two MIMO paths, more than two random phases are sent via the more than two MIMO paths, and the relative difference between one of the random phases and the other random phases may be used as an authentication request parameter, which may reduce the impact of possible phase noise.

[0202] At 1208, transmitter 1204 may transmit an authentication tag (also referred to as the authentication proof of transmitter 1204) to receiver 1202 , where 1210 may be a credential of transmitter 1204 and may be a time index (e.g., a sequence number ─ to prevent replay attacks). Specifically, receiver 1202 may (a priori) know 1210. Although not shown in Figure 12 , in some examples, two or more authentication tags may be transmitted as authentication proofs (e.g., one authentication tag per MIMO channel).

[0203] In one or more aspects, any number of irreversible one-way functions (e.g., hash functions) may be used to generate one or more authentication tags (e.g., authentication proof 1208) to hide the content so that the authentication tag / proof 1208 cannot be captured by adversarial devices. Because is an irreversible one-way function, even if the authentication tag / proof 1208 is captured by an adversarial device, the adversarial device may not be able to learn the content (i.e., the input to ).

[0204] Receiver 1202 may obtain an estimate of the received one or more authentication tags as one or more instances (e.g., one instance per authentication tag), which may be performed in a coherent manner by employing additional pilot resources for first estimating the channel (the manner of estimating the received authentication tag may be referred to as coherent because channel estimation is utilized). Then, to perform the authenticity check 1212 to authenticate transmitter 1204, receiver 1202 may compare the estimated one or more with a reconstructed version of one or more instances (since any number of discrete values 1210 may be used for receiver 1202, and for each corresponding value tracked by receiver 1202, receiver 1202 may independently reconstruct the instance version). In one or more aspects, to decide the legitimacy of transmitter 1204 at 1212, this comparison may be based on a distribution-based hypothesis test and / or a Hamming distance-based similarity test. Thereafter, if transmitter 1204 is confirmed as legitimate based on the authenticity check 1212, receiver 1202 may continue to transmit its own credential. Otherwise, if the transmitter cannot be authenticated, receiver 1202 may stop participating in the configuration sharing process.

[0205] In one or more aspects, each phase and the corresponding authentication tag can be simultaneously transmitted in a paired manner by the transmitter 1204 on different sub - carriers of a given MIMO communication path. In an additional configuration, each random phase and the corresponding authentication tag can be transmitted using adjacent time - frequency resources on a given MIMO communication path such that the receiver 1202 can associate the two transmissions to assume that the two transmissions are from the same source (i.e., the transmitter 1204).

[0206] In response to the transmission by the transmitter 1204 at 1206 (e.g., 1 or 2), the phase output of the channel at the receiver 1202 can become , where can be the phase rotation due to the RF front - end and the channel (propagation through the channel). The receiver 1202 can measure as . Such measurements can be performed for each i received from the transmitter 1204. As an example, the phase output at the receiver (in response to the transmission i ) becomes , where is the phase rotation due to the RF front - end and the channel of the MIMO path (propagation through the channel), and the receiver measures it as . Thus, the receiver 1202 can prepare an authentication response consisting of the phase values , where can be a phase - modulation credential also known to the transmitter (independent of or ), and transmit it back to the transmitter 1204 along each MIMO path .

[0207] Even if an adversarial device can measure the transmitted phase , the adversarial device may not be able to learn the phase 1216 representing the credential of the receiver 1202 because the adversarial device may not be aware of (the individual values are the values measured at the receiver 1202, not at other devices). Thus, the authentication response included in the configuration request 1214 can be PHY - secure.

[0208] Additionally or alternatively, in some examples, rather than using discrete value, but uses different MIMO communication paths The relative value between the values ​​is used as the authentication parameter. As an example, if there are two MIMO communication paths, the difference between β1 for one path and β2 for the other path can be used as the authentication parameter.

[0209] In some examples, for the phase value , the corresponding phases of the configuration request 1214 at the transmitter 1204 may each be (For example, ), due to the channel reciprocity between the authentication request 1206 and the authentication response / authentication request 1214 (i.e., ) and for each corresponding MIMO channel i, The fact that it is equivalent to In some examples, the effects of phase noise are: and is different because the phase noise between the two parties acting as transmitters or as receivers (e.g., transmitter 1204 and receiver 1202) or between the components of each party transmitting and receiving is different and / or because the phase noise varies with time, but and are measured at different times. However, in some examples, the phase noise can be considered to be the same on multiple MIMO paths; therefore, as long as the RF signals for multiple paths come from the same RF source, the relative phases are reciprocal even in the presence of phase noise: .

[0210] The transmitter 1204 may measure the received phase for each MIMO path as Because the initial random phase for the MIMO communication path The sender 1204 is known, so the sender 1204 can easily obtain the phase representing the credentials of the receiver 1202 from the authentication response / configuration request 1214. 1216. In addition, because The value 1216 (for example, Figure 12 shown and ) is known a priori to the transmitter 1204, the transmitter 504 can obtain the phase output by Values ​​vs. known / expected The authenticity check 1218 may be performed by comparing the received credentials with the received credentials. Specifically, the authenticity check 1218 may be based on an authentication test (eg, a hypothesis test based on a distribution, a similarity test based on a Hamming distance, etc.) to determine whether the received credentials are Whether to match known / expected credentials If each of the received phases 1216 passes the authentication test, then the receiver 1202 can be authenticated for the transmitter 1204. Thus, the transmitter 1204 can then begin the process for transmitting the configuration. Otherwise, if the receiver 1202 is not authenticated, the transmitter 1204 can stop participating in the configuration process. In some examples, instead of measuring the discrete values of θ for the MIMO paths, relative values representing the differences between the θ values for different MIMO paths can be used, allowing the relative differences between the expected β values to be used to determine whether the authenticity check 1218 is passed. As an example, can be used to infer . In some examples, there are more than two MIMO paths, can be used to infer .

[0211] If the authentication (i.e., the authenticity check at 1218) is successfully completed, then at 1220, the transmitter 1204 can transmit the confidential configuration to the authenticated receiver 1202 in a PHY-secure manner (e.g., using a phase-difference-based technique). Thus, the transmitter 1204 can treat the authentication response at 1214 as a configuration request and can prepare the configuration response 1220 to include the configuration represented by the phase modulation parameters for each MIMO path (e.g., i for each MIMO path i). The configuration response 1220 can be sent by the transmitter 1204 in response to the configuration request 1214 and can include the requested configuration. The transmitter 1204 can then build the configuration response 1220 based on the phase values , where each 1222 (e.g., corresponding to each MIMO path) can be the phase estimate of the channel output for the configuration request on a given MIMO path. Even if an adversarial device measures the phase , the adversarial device may not be able to learn the phase 1222 because the adversarial device may not be aware of . Thus, the adversarial device may not be able to learn the confidential configuration data represented by the phase 1222. Thus, the configuration response 1220 can be PHY-secure. In some examples with two MIMO paths, can be used for actual information instead of the discrete values. In some examples with more than two MIMO paths, can be used.

[0212] For each MIMO path used, the corresponding phase of the configuration response 1220 at the receiver 1202 can then become , due to channel reciprocity for each MIMO path (i.e., ), and for each corresponding for each MIMO path, it can similarly be equivalent to . In some examples, for each MIMO path i, based on there is phase noise, ( ) becomes ).

[0213] In some examples, for each MIMO path, an estimate of the residual phase can then be utilized by the receiver 1202 to learn the configuration via the relevant parameters (e.g., 1222), since the value of for each MIMO path is already known to the receiver 1202 (for each MIMO path, the receiver can construct while forming the authentication response / configuration request 1214). In some examples, for each MIMO path i, based on there is phase noise, ( ) becomes ) and can be inferred.

[0214] In one or more aspects, for each MIMO path, the phase parameters and may each be multi-bit long. Thus, multiple tones can be used in the frequency domain to transmit each of the phase parameters and during the transmission of the configuration request 1214 and the configuration response 1220, respectively.

[0215] In one example, the random phase for each MIMO path and the corresponding authentication tag / proof (or multiple authentication tags corresponding to different MIMO paths i) can be transmitted simultaneously by the transmitter 1204 (e.g., on different subcarriers of an OFDM symbol). In one or more aspects, the receiver 1202 can assume that the OFDM symbol carrying the valid is from a legitimate transmitter, and thus, when constructing the configuration request 1214, the phase measured at the subcarrier corresponding to (of the same OFDM symbol) can be used.

[0216] In different examples, for each individual MIMO path i, the phase and the authentication tag / certificate can be transmitted by the transmitter 1204 in adjacent time - frequency. Thus, the receiver 1202 can associate the two transmissions (e.g., based on the location of the time - frequency resources) to ensure that the two transmissions are from the same transmitter. Thus, in one configuration, the transmitter 1204 can generate the authentication tag / certificate for each MIMO path i as (i.e., the authentication tag / certificate can also be based on ) or in an example as a separate authentication tag , using a separate authentication tag for each MIMO path. Additionally, the receiver 1202 can obtain or estimate a given value for a given MIMO path. Thus, if the corresponding authentication tag / certificate transmitted by the transmitter 1204 in another time - frequency resource (e.g., an adjacent resource) is valid (i.e., if the transmitter 1204 is authenticated), then the receiver 1202 can generate an authentication response / configuration request 1214 corresponding to a particular . Thus, the time - frequency resources used for transmitting at 1206 and transmitting at 1208 can be associated (bonded). Thus, the transmitter 1204 can allocate additional sub - carriers (along with the sub - carriers carrying ) to transmit pilot symbols, thereby helping the receiver 1202 to first estimate the channel and then estimate the being used for each MIMO channel. Based on the estimated for a given MIMO channel, the receiver 1202 can then locally generate a version of the authentication certificate for that MIMO path and can perform an authentication test at 1212. If the authentication at 1212 is valid (i.e., if the transmitter 1204 is authenticated), then the receiver 1202 can use the corresponding phase response for the MIMO path associated with the relevant to generate the authentication response / configuration request 1214.

[0217] In one or more aspects, for each MIMO path, since the randomness of the corresponding authentication certificate can be well provided by , the time - dependence of the MIMO path can be discarded without exposing the receiver 1202 to replay attacks. In other words, at 1208, the for a particular MIMO path can be used without exposing the receiver 1202 to replay attacks.

[0218] Figure 13 FIG. 1300 is a diagram illustrating an example process 1300 for performing secure and reliable configuration sharing in accordance with one or more aspects. The legitimate receiver 1302 and the legitimate transmitter 1304 may be abbreviated as receiver 1302 and transmitter 1304. Although in some aspects herein, the receiver 1302 may correspond to a UE (e.g., UE 104), and the transmitter 1304 may correspond to a base station (e.g., base station 102), the present disclosure is not limited thereto. In different configurations, the receiver 1302 and the transmitter 1304 may suitably correspond to any suitable type of network node.

[0219] At 1306, the transmitter 1304 may transmit two or more authentication requests to the receiver 1302 using a separate MIMO communication path i. Each authentication request 606 may include a random phase corresponding to one of the MIMO paths in the MIMO path. . As an example, in Figure 13 the example shown, there are two MIMO communication paths 1 and 2 with corresponding random phase values 1 and 2 for the two authentication requests. In one or more aspects, the phase may be known to the transmitter 1304 but unknown to other devices. In one or more aspects, whenever a new authentication request is transmitted at 1306, the transmitter 1304 may select a new phase value for each MIMO path (e.g., to prevent replay attacks, i.e., to prevent adversarial devices from recording authentication responses to deceive the receiver 1302 at a later time). Additionally, in one or more aspects, whenever the transmitter 604 transmits a new authentication request at 1306, the transmitter 1304 may use different beams for each MIMO channel. Specifically, the transmitter 1304 may randomly select the beams (e.g., also to prevent replay attacks). In some examples, each random phase for each MIMO path is used as part of the authentication parameter. In other examples, the difference between the random phases is used as the authentication parameter. As an example, in a scenario where there are two MIMO paths, only is used as the authentication parameter, rather than and both. In some examples, if there are more than two paths, all can be used as the authentication parameter; where is the MIMO path index. In some examples, the motivation for using the relative phase is to reduce the impact from phase noise due to the correlation in the phase noise seen by the receiver of multiple MIMO paths.

[0220] In response to the transmitter 1304 transmitting For the response to each value, for each MIMO path i, the phase output of the channel at the receiver 1302 can become , where can be the phase rotation caused by the RF front end and the channel (through the propagation of the channel). The receiver 602 can measure as for each MIMO channel (e.g., can be used for each MIMO path i).

[0221] Therefore, the receiver 1302 can prepare an authentication response for each MIMO path that includes the phase value , where each 1310a can be the phase modulation credential of the receiver 1302 that is also known to the transmitter 1304. The phase 1310a representing the credential of the receiver 1302 for a given MIMO channel can be independent of the credential for a specific MIMO path. At 1308, the receiver 1302 can send the individual phase values for each MIMO path back to the transmitter 1304.

[0222] In some examples, for a specific MIMO path, even in a scenario where an adversarial device can measure the phase sent for the MIMO path, the adversarial device may not be able to learn the phase representing the credential of the receiver 1302 for the MIMO path, because the adversarial device may not be able to know the for a specific MIMO path (e.g., because the value for a specific MIMO path is the value measured at the receiver 1302 but not at other devices). Therefore, the authentication response included in the configuration request 1308 can be PHY secure. In some examples, the relative difference between the values of each MIMO path can be used as an authentication parameter instead of using the discrete value for each of the paths. As an example, in a scenario where there are two MIMO paths, only can be used and is known to the transmitter, and if there are more than two MIMO paths, for all can be used as an authentication parameter.

[0223] The corresponding phase of the configuration request 1308 at the transmitter 1304 can be for each MIMO path i, due to the channel reciprocity between the authentication request 1306 and the configuration request 1308 (i.e., ) and for each MIMO path, Based on the fact that, for each MIMO path, it can be equivalent to . In some examples, instead of using the discrete values of θ for each MIMO path, the relative difference between θ values can be used to infer the difference between β values. As an example, can be used to infer , and if there are more than two MIMO paths, can be used to infer .

[0224] Transmitter 1304 can measure the received phase as for MIMO path i. Since the initial random phase for a given MIMO path is known to transmitter 1304, transmitter 1304 can obtain from the configuration request 1308 the phase representing the credentials of receiver 602 for a specific MIMO path. In addition, since each for each MIMO path is known a priori to transmitter 1304, transmitter 1304 can perform the authenticity check 1312 by comparing each value obtained from the phase output with the known / expected value. Specifically, the authenticity check 1312 can be based on an authentication test (e.g., a hypothesis test based on distribution, a similarity test based on Hamming distance, etc.) to determine whether a given received credential for a specific MIMO path matches the known / expected credential for the MIMO path. If each received phase value passes the authentication test, then receiver 1302 can be authenticated to transmitter 1304. Thus, transmitter 1304 can then start the process for sending the configuration. Otherwise, if the receiver is not authenticated, transmitter 1304 can stop participating in the process.

[0225] If the authentication (i.e., the authenticity check at 1312) is successfully completed, transmitter 1304 can transmit both the authentication proof 1314 and the configuration response 1316 including the confidential configuration to the authenticated receiver 1302 in a PHY-secure manner (e.g., using a phase-difference-based technique).

[0226] The authentication proof 1314 can include one or more credentials of transmitter 1304. Specifically, one or more credentials of transmitter 1304 can be represented by the phase modulation credentials in the authentication proof 1314. In some examples, each MIMO path used is associated with a separate phase modulation credential i associated. In addition, the configuration response 1316 can include the phase modulation parameters The configuration shown. In some examples, each MIMO path used is associated with a separate phase modulation parameter i associated with it.

[0227] The transmitter 1304 can construct the authentication proof 1314 and the configuration response 1316 respectively based on the phase values and where can be the phase estimate of the channel output associated with the configuration request 1308. Even if an adversarial device measures either of them, the adversarial device may not be able to learn the hidden phase or because the adversarial device may not be aware of . Thus, the authentication proof 1314 and the configuration response 1316 can be communicated in a PHY-secure manner. In the example of using separate values of i and ϕ i for each individual MIMO path, the same may hold true on a per-MIMO-path basis. In the example, the relative phases ) and ) can be used in a similar manner.

[0228] The corresponding phase outputs of the authentication proof 1314 and the configuration response 1316 at the receiver 1302 can become respectively due to the channel reciprocity on a per-MIMO-path basis (i.e., ) and the fact that which can be equivalent to and respectively. Since each value i corresponding to each MIMO path i can be used by the receiver 1302 (e.g., the receiver 1302 can construct ) when forming the configuration request 1308, the noise estimates of both 1310b and 1318 can become available for the receiver 1302. Additionally, since for a given MIMO path, 1310b is known a priori to the receiver 1302, the receiver 1302 can perform the authenticity check 1320 by comparing the obtained from the phase output with the known / expected for the specific MIMO path. Specifically, the authenticity check 1320 can be based on an authentication test (e.g., a distribution-based hypothesis test, a Hamming distance-based similarity test, etc.) to determine the received credentials Whether the received credentials match known / expected credentials for a particular MIMO path If the received credentials 1310b pass the authentication test at 1320, the receiver 1302 can then determine the legitimacy of the transmitter 1304 and can proceed to learn / use the configuration (e.g., the parameters represented by 1318). Otherwise, if the transmitter is not authenticated, the receiver 1302 can discard the received configuration.

[0229] In one or more aspects, for each MIMO path used in the authentication process (e.g., 1310b, 1310a, and 1318), the phase parameters , and may be multi-bit long. Thus, multiple tones can be used in the frequency domain to separately transmit the phase parameters , and (e.g., 1310b, 1310a, and 1318) for each MIMO path during the transmission of the authentication proof 1314, the configuration request 1308, and the configuration response 1316.

[0230] In some aspects, the transmitter 1204 / 1304 can include (e.g., append) a cyclic redundancy check (CRC) (e.g., using frequency domain resource blocks) in the phase parameters for each MIMO path so that the receiver 1202 / 1302 can verify the accuracy of the received phase and thus verify the configuration. If the receiver 1202 / 1302 identifies the received phase as inaccurate based on the CRC, the receiver 1202 / 1302 can send a negative acknowledgment (NACK) to the transmitter 1204 / 1304. Thus, in some aspects, if the transmitter 1204 / 1304 does not receive a NACK (e.g., within a time window after transmission), the transmitter 1204 / 1304 can assume that the receiver 1202 / 1302 has correctly learned the configuration.

[0231] If the transmitter 1204 / 1304 receives one or more NACKs, in one configuration, the transmitter 1204 / 1304 may follow the same process as described above to attempt to re-share the configuration. In another configuration, if the transmitter 1204 / 1304 receives a NACK, the transmitter 1204 / 1304 may pause the configuration sharing process for a pre-configured period of time. In some aspects, if the pause period is longer than the authentication lifetime or channel coherence time selected by the network, the authentication process may also be repeated before resuming the configuration transmission.

[0232] Due to defects in channel reciprocity and phase estimation based on each MIMO path, the measured 、 and for any given MIMO path and / or set of MIMO paths may be inaccurate / incorrect (e.g., deviate from the correct value). Therefore, in some aspects, to reduce the negative impact of the deviation, a transmit-receive pair (e.g., the transmitter 1204 / 1304 - receiver 1202 / 1302 pair) may (periodically or from time to time) exchange known phase parameters for all or any part of the MIMO paths 、 and to measure and quantify the error between the received values of 、 and and the expected / correct values (using , because can be used by the corresponding associated device / party).

[0233] In some aspects, as described above, based on whether the data sent is known or unknown to the receiver 1202 / 1302, the network may (e.g., per MIMO path) set thresholds (dynamically or statically) for the errors associated with 、 and . In some aspects, different thresholds may be set for the errors associated with 、 and . In some aspects, if the error measurements for 、 and are all below their respective thresholds for all MIMO paths being used, the phase-difference-based configuration sharing process as illustrated by Figure 12 and Figure 13 may be allowed. On the other hand, if the errors for 、 and If at least one of the error measurements is below its corresponding threshold, the phase-difference-based configuration sharing process may be suspended until at least the next phase error is measured.

[0234] Figure 14 is an example flowchart illustrating an example of process 1400 for mutual authentication in wireless communication. Process 1400 may be performed at least in part by any one of, for example: Figure 1 UE 104 as shown and described above, Figure 1 BS 102 as shown and described above, Figure 3 BS 310 as shown and described above, Figure 3 UE 350 as shown and described above, Figure 5 receiver 502 as shown and described above, Figure 5 transmitter 504 as shown and described above, Figure 6 receiver 602 as shown and described above, Figure 6 transmitter 604 as shown and described above, Figure 12 receiver 1202 as shown and described above, Figure 12 transmitter 1204 as shown and described above, Figure 13 receiver 1302 as shown and described above, Figure 13 transmitter 1304 as shown and described above, Figure 16 any component or element shown by any of the components shown by device 1604, network entity 1702, and / or any of the foregoing components described above.

[0235] At block 1402, process 1400 includes sending a first authentication request from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node, the first authentication request including a first phase. The phase may be a random phase known to the transmitter but unknown to the receiver. A new phase value may be used for each new authentication request.

[0236] At block 1404, process 1400 includes: sending a second authentication request from the first network node to the second network node via a second MIMO path between the first network node and the second network node, the second authentication request including a second phase. The phase may be a random phase known to the transmitter but unknown to the receiver. A new phase value may be used for each new authentication request. Separate MIMO paths may be used to convey the first authentication request and the second authentication request, and the separate MIMO paths may be spatially separated. The first authentication request and the second authentication request may be used to verify the authenticity of the first network node, respectively. Additionally or alternatively, the relative difference between the phases of the authentication requests may be used to verify the authenticity of the first network node.

[0237] At block 1406, process 1400 includes: sending an authentication proof from the first network node to the second network node. The authentication proof may be referred to as and / or include an authentication tag. The authentication proof may include , where may be a credential of the first network node, and may be a time index (e.g., a sequence number). In some examples, may be known a priori to the second network node. In some examples, two or more authentication tags may be sent as the authentication proof (e.g., one authentication tag per MIMO channel).

[0238] In one or more aspects, any number of irreversible one-way functions (e.g., hash functions) may be used to generate one or more authentication tags (e.g., authentication proofs) to hide the content so that the authentication tag / proof 1208 cannot be captured by an adversarial device. Since is an irreversible one-way function, even if the authentication tag / proof is captured by an adversarial device, the adversarial device may not be able to learn 's content (i.e., the input to ). The second network node may obtain an estimate of the received one or more authentication tags as 's one or more instances (e.g., one instance per authentication tag), which may be performed in a coherent manner by employing additional pilot resources for first estimating the channel (the way of estimating the received authentication tag may be called coherent because channel estimation is utilized). Then, to perform an authenticity check to authenticate the first network node, the second network node may compare the estimated one or more instances with a reconstructed version of one or more instances (since any number of discrete values may be used for the second network node, and the corresponding for each is tracked by the second network node, the second network node may independently construct 's instance version). In one or more aspects, to determine the legitimacy of the first network node, the comparison may be based on a distribution-based hypothesis test and / or a Hamming distance-based similarity test. Thereafter, if the first network node is confirmed as legitimate based on the authenticity check, the second network node may continue to transmit its own credentials. In one or more aspects, the phase and the corresponding authentication tag may be simultaneously sent in a paired manner by the first network node on different subcarriers of a given MIMO communication path. In an additional configuration, each random phase and corresponding authentication tags They can be sent using adjacent time - frequency resources on a given MIMO communication path, such that the second network node can associate two transmissions to assume that the two transmissions are from the same source (e.g., the first network node).

[0239] At block 1408, process 1400 includes: receiving, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, where the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof.

[0240] At block 1410, process 1400 includes: receiving, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, where the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof. The first configuration request credential and the second configuration request credential can be referred to as, for example and , which may be known a priori to the first network node. The first configuration request credential and the second configuration request credential can be combined with the phases before being sent to the first network node. The phases with which the configuration request credentials are combined can be at least partially based on the respective phases of the MIMO channels via which the authentication requests are received from the first network node. In some examples, the first network node derives the configuration request credentials at least partially based on the phases transmitted on the respective MIMO channels during the authentication request.

[0241] At block 1412, process 1400 includes: sending a first configuration response in response to the first configuration request, at least partially based on authenticating the first configuration request credential.

[0242] At block 1414, process 1400 includes: sending a second configuration response in response to the second configuration request, at least partially based on authenticating the second configuration request credential.

[0243] In some examples, the configuration request credentials are derived by the first network node and compared with the configuration request credentials known to the first network node to determine whether the credentials match, and based on a successful match, it is determined that the second network node is legitimate. In some examples, the first configuration response and the second configuration response include respective configuration parameters to be used during the communication between the first network node and the second network node.

[0244] Figure 15is a flowchart exemplifying an example of process 1500 for mutual authentication in wireless communication. Process 1500 may be performed at least in part by any one of, for example, the following: Figure 1 UE 104 as shown and described above, Figure 1 BS 102 as shown and described above, Figure 3 BS 310 as shown and described above, Figure 3 UE 350 as shown and described above, Figure 5 receiver 502 as shown and described above, Figure 5 transmitter 504 as shown and described above, Figure 6 receiver 602 as shown and described above, Figure 6 transmitter 604 as shown and described above, Figure 12 receiver 1202 as shown and described above, Figure 12 transmitter 1204 as shown and described above, Figure 13 receiver 1302 as shown and described above, Figure 13 transmitter 1304 as shown and described above, Figure 16 any component or element shown by any of the components shown by device 1604, network entity 1702 and / or any of the foregoing components described above.

[0245] At block 1502, process 1500 includes: receiving, at a second network node via a first multiple-input multiple-output (MIMO) path from a first network node, a first authentication request including a first phase.

[0246] At block 1504, process 1500 includes: receiving, at the second network node via a second MIMO path from the first network node, a second authentication request including a second phase.

[0247] In some examples, the first authentication request and the second authentication request are transmitted via different MIMO paths. In some examples, each authentication request includes a separate phase, which may be a random phase. In some examples, the phases are known to the first network node but unknown to the second network node. In some examples, a new phase is selected by the first network node for each authentication request per MIMO path. In some examples, each phase is used as an authentication parameter. In some examples, the difference between the phases is used as an authentication parameter.

[0248] At block 1506, process 1500 includes: sending, via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node to the first network node, where the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof.

[0249] At block 1508, process 1500 includes: sending, via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node to the first network node, where the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof.

[0250] In some examples, the second network node determines a phase output corresponding to the phases of the respective MIMO channels received at block 1502 and block 1506, where the phase output is at least partially based on the phase received from the first network node and the characteristics of the respective MIMO paths. In some examples, the second network node prepares an authentication response to the received phase, the authentication response being based on the calculated phase output and the configuration request credential per MIMO channel that is known a priori to the first network node. In some examples, the authentication request is included as part of the respective configuration request per MIMO channel. In some examples, the phase measured by the first network node for the respective per MIMO path configuration request is equivalent to the difference between the respective configuration request credential and the phase known to the first network node of the communication transmitted via the MIMO channel to the second network node. Thus, in some examples, the respective configuration request credential can be obtained by the first network node and compared with the expected configuration request credential known to the first network node to determine the legitimacy of the second network node.

[0251] At block 1510, process 1500 includes: receiving an authentication proof at the second network node from the first network node. In some examples, based on the successful verification of the configuration request credential received at the first network node at block 1506 and block 1508, the authentication proof is sent from the first network node to the second network node.

[0252] At block 1512, process 1500 includes: receiving a first configuration response in response to the first configuration request, at least partially based on the authentication of the first configuration request credential.

[0253] At block 1514, process 1500 includes: receiving a second configuration response in response to the second configuration request, at least partially based on the authentication of the second configuration request credential.

[0254] In some examples, the first configuration response and the second configuration response each include respective confidential configuration information to be used at the second network node during communication with the first network node.

[0255] Figure 16FIG. 1600 is an illustration of an example of a hardware implementation for apparatus 1604. Apparatus 1604 may be a UE, a component of a UE, or may implement UE functionality. In some aspects, apparatus 1604 may include a cellular baseband processor 1624 (also referred to as a modem) coupled to one or more transceivers 1622 (e.g., cellular RF transceivers). The cellular baseband processor 1624 may include on-chip memory 1624'. In some aspects, apparatus 1604 may also include one or more subscriber identity module (SIM) cards 1620 and an application processor 1606, which is coupled to a secure digital (SD) card 1608 and a screen 1610. The application processor 1606 may include on-chip memory 1606'. In some aspects, apparatus 1604 may also include a Bluetooth module 1612, a WLAN module 1614, an SPS module 1616 (e.g., GNSS module), one or more sensor modules 1618 (e.g., barometric pressure sensor / altimeter; motion sensors such as an inertial management unit (IMU), gyroscope, and / or accelerometer; light detection and ranging (LIDAR), radio aided detection and ranging (RADAR), sound navigation and ranging (SONAR), magnetometer, audio, and / or other technologies for positioning), an additional memory module 1626, a power supply 1630, and / or a camera 1632. The Bluetooth module 1612, the WLAN module 1614, and the SPS module 1616 may include on-chip transceivers (TRX) (or in some cases, only receivers (RX)). The Bluetooth module 1612, the WLAN module 1614, and the SPS module 1616 may include their own dedicated antennas and / or communicate using antenna 1680. The cellular baseband processor 1624 communicates with UE 104 and / or with an RU associated with network entity 1602 via transceiver 1622 through one or more antennas 1680. The cellular baseband processor 1624 and the application processor 1606 may each separately include computer-readable media / memory 1624', 1606'. The additional memory module 1626 may also be considered computer-readable media / memory. Each computer-readable media / memory 1624', 1606', 1626 may be non-transitory. The cellular baseband processor 1624 and the application processor 1606 are each responsible for general processing, including executing software stored on the computer-readable media / memory. The software, when executed by the cellular baseband processor 1624 / application processor 1606, causes the cellular baseband processor 1624 / application processor 1606 to perform the various functions described herein. The computer-readable media / memory may also be used to store data manipulated by the cellular baseband processor 1624 / application processor 1606 when executing the software.The cellular baseband processor 1624 / application processor 1606 can be components of the UE 350 and can include at least one of the memory 360 and / or the TX processor 368, the RX processor 356, and the controller / processor 359. In one configuration, the device 1604 can be a processor chip (modem and / or application) and include only the cellular baseband processor 1624 and / or the application processor 1606, and in another configuration, the device 1604 can be the entire UE (e.g., see Figure 3 of 350) and include additional modules of the device 1604.

[0256] As discussed above, component 198 is configured to receive one or more authentication proofs from a first network node. The one or more authentication proofs may be based on one or more credentials associated with the first network node. Component 198 may be configured to identify whether the first network node is authentic based on the one or more authentication proofs. Component 198 may be configured to send one or more configuration requests to the first network node. The one or more configuration requests may include a phase modulation indication of one or more second credentials associated with the second network node. The one or more configuration requests may be based on one or more random phases. The second network node may be capable of authenticating based on the one or more configuration requests. Component 198 may be configured to receive one or more configuration responses from the first network node based on the second network node being authenticated. The one or more configuration responses may include phase-modulated confidential parameters. The one or more configuration parameters may be based on the one or more configuration requests. Component 198 may be within the cellular baseband processor 1624, the application processor 1606, or both the cellular baseband processor 1624 and the application processor 1606. Component 198 may be one or more hardware components specifically configured to perform the stated processes / algorithms, implemented by one or more processors configured to perform the stated processes / algorithms, stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. As shown, device 1604 may include various components configured for various functions. In one configuration, device 1604 (and particularly the cellular baseband processor 1624 and / or the application processor 1606) includes means for receiving one or more authentication proofs from a first network node. The one or more authentication proofs may be based on one or more credentials associated with the first network node. Device 1604 (and particularly the cellular baseband processor 1624 and / or the application processor 1606) includes means for identifying whether the first network node is authentic based on the authentication proof. Device 1604 (and particularly the cellular baseband processor 1624 and / or the application processor 1606) includes means for sending one or more configuration requests to the first network node. The one or more configuration requests may include a phase modulation indication of one or more second credentials associated with the second network node. The one or more configuration requests may be based on one or more random phases. The second network node may be capable of authenticating based on the one or more configuration requests. Device 1604 (and particularly the cellular baseband processor 1624 and / or the application processor 1606) includes means for receiving one or more configuration responses from the first network node based on the second network node being authenticated. The one or more configuration responses may include phase-modulated confidential parameters. The configuration response may be based on the one or more configuration requests.

[0257] In one configuration, device 1604 (and in particular cellular baseband processor 1624 and / or application processor 1606) includes components for receiving one or more authentication requests from the first network node. The one or more authentication requests may include one or more random phases. Device 1604 (and in particular cellular baseband processor 1624 and / or application processor 1606) includes components for obtaining a PHY signature based on the configuration response. Device 1604 (and in particular cellular baseband processor 1624 and / or application processor 1606) includes components for demodulating another transmission from the first network node based on the PHY signature when the first network node is identified as being authentic. In one configuration, the one or more authentication requests may be associated with one or more random beams. In one configuration, the one or more authentication certificates may be received from the first network node before sending the one or more configuration requests to the first network node. If the first network node is identified as being authentic based on the one or more authentication certificates, the one or more configuration requests may be sent to the first network node. In one configuration, the one or more authentication certificates may also be based on one or more time indices and one or more irreversible one-way functions. In one configuration, the one or more authentication requests and the one or more authentication certificates may be received simultaneously and via different subcarriers. In one configuration, the one or more authentication requests and the one or more authentication certificates may be received via adjacent time-frequency resources. The one or more authentication certificates may also be based on the one or more random phases and one or more one-way hash functions. In one configuration, the one or more authentication certificates may be received from the first network node after sending the one or more configuration requests to the first network node. In one configuration, the one or more authentication certificates may also be based on the one or more configuration requests. In one configuration, device 1604 (and in particular cellular baseband processor 1624 and / or application processor 1606) includes components for revoking the second credential associated with the second network node when the first network node is identified as not being authentic based on the one or more authentication certificates. In one configuration, the one or more authentication certificates may be associated with multiple tones. In one configuration, the one or more configuration requests and the one or more configuration responses may each be associated with multiple tones. In one configuration, a first transmission from a first network node to a second network node may be subject to a first phase rotation associated with the first transmission, the first phase rotation being reciprocal to a second phase rotation associated with a second transmission from the second network node to the first network node. The second transmission may be subject to the second phase rotation. In one configuration, whether the first network node is authentic may be identified based on a first distribution-based hypothesis test or a first Hamming distance-based similarity test. The second network node may be authenticated based on a second distribution-based hypothesis test or a second Hamming distance-based similarity test.

[0258] The component can be component 198 of apparatus 1604 configured to perform the functions recited by the component. As described above, apparatus 1604 can include TX processor 368, RX processor 356, and controller / processor 359. Thus, in one configuration, the component can be TX processor 368, RX processor 356, and / or controller / processor 359 configured to perform the functions recited by the component.

[0259] Figure 17 FIG. 1700 is a diagram illustrating an example of a hardware implementation for network entity 1702. Network entity 1702 can be a BS, a component of a BS, or can implement BS functionality. Network entity 1702 can include at least one of CU 1710, DU 1730, or RU 1740. For example, depending on the layer functionality processed by component 199, network entity 1702 can include CU 1710; both CU 1710 and DU 1730; each of CU 1710, DU 1730, and RU 1740; DU 1730; both DU 1730 and RU 1740; or RU 1740. CU 1710 can include CU processor 1712. CU processor 1712 can include on-chip memory 1712'. In some aspects, CU 1710 can also include additional memory module 1714 and communication interface 1718. CU 1710 communicates with DU 1730 via an intermediate link such as F1 interface. DU 1730 can include DU processor 1732. DU processor 1732 can include on-chip memory 1732'. In some aspects, DU 1730 can also include additional memory module 1734 and communication interface 1738. DU 1730 communicates with RU 1740 via a fronthaul link. RU 1740 can include RU processor 1742. RU processor 1742 can include on-chip memory 1742'. In some aspects, RU 1740 can also include additional memory module 1744, one or more transceivers 1746, antenna 1780, and communication interface 1748, and can implement all or any part of any number of MIMO paths. RU 1740 communicates with UE 104. On-chip memories 1712', 1732', 1742' and additional memory modules 1714, 1734, 1744 can each be considered a computer-readable medium / memory. Each computer-readable medium / memory can be non-transitory. Each of processors 1712, 1732, 1742 is responsible for general processing, including executing software stored on the computer-readable medium / memory. The software, when executed by the corresponding processor, causes the processor to perform the various functions described above. The computer-readable medium / memory can also be used to store data manipulated by the processor when executing the software.

[0260] As discussed above, component 199 is configured to send one or more authentication proofs to a second network node. The one or more authentication proofs may be based on one or more credentials associated with the first network node. The first network node may be able to authenticate based on the one or more authentication proofs. Component 199 may be configured to receive one or more configuration requests from the second network node. The one or more configuration requests may include one or more phase modulation indications of one or more second credentials associated with the second network node. The one or more configuration requests may be based on one or more random phases. Component 199 may be configured to send one or more configuration responses to the second network node. The one or more configuration responses may include one or more phase-modulated confidential parameters. The one or more configuration parameters may be based on the one or more configuration requests. Component 199 may be within one or more processors of one or more of CU 1710, DU 1730, and RU 1740. Component 199 may be one or more hardware components that are generally configured to perform the stated processes / algorithms, implemented by one or more processors configured to perform the stated processes / algorithms, stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. Network entity 1702 may include various components configured for various functions. In one configuration, network entity 1702 includes means for sending one or more authentication proofs to a second network node. The one or more authentication proofs may be based on one or more credentials associated with the first network node. The first network node may be able to authenticate based on the one or more authentication proofs. Network entity 1702 includes means for receiving one or more configuration requests from the second network node. The one or more configuration requests may include one or more phase modulation indications of one or more second credentials associated with the second network node. The one or more configuration requests may be based on one or more random phases. Network entity 1702 includes means for sending one or more configuration responses to the second network node. The one or more configuration responses may include one or more phase-modulated confidential parameters. The one or more configuration parameters may be based on the one or more configuration requests.

[0261] In one configuration, network entity 1702 includes components for sending one or more authentication requests to the second network node. The one or more authentication requests may include one or more random phases. Network entity 1702 includes components for identifying whether the second network node is genuine based on the one or more configuration requests. If the second network node is identified as genuine, the one or more configuration responses may be sent to the second network node. In one configuration, the one or more authentication requests may be associated with randomly selected beams. In one configuration, whether the second network node is genuine may be identified based on a distribution-based hypothesis test or a Hamming distance-based similarity test. In one configuration, the one or more authentication certificates may be sent to the second network node before receiving the one or more configuration requests from the second network node. Based on the first network node being authenticated based on the one or more authentication certificates, the one or more configuration requests may be received from the second network node. In one configuration, the one or more authentication certificates may also be based on one or more time indices and one or more irreversible one-way functions. In one configuration, the one or more authentication requests and the one or more authentication certificates may be sent simultaneously and via different subcarriers. In one configuration, the one or more authentication requests and the one or more authentication certificates may be sent via adjacent time-frequency resources. The one or more authentication certificates may also be based on the one or more random phases and one or more one-way hash functions. In one configuration, the one or more authentication certificates may be sent to the second network node after receiving the one or more configuration requests from the second network node. In one configuration, the one or more authentication certificates may also be based on the one or more configuration requests. In one configuration, the one or more authentication certificates may be associated with multiple tones. In one configuration, the one or more configuration requests and the one or more configuration responses may each be associated with multiple tones. In one configuration, a first transmission from a first network node to a second network node may be subject to a first phase rotation associated with the first transmission, and the first phase rotation is reciprocal to a second phase rotation associated with a second transmission from the second network node to the first network node. The second transmission may be subject to the second phase rotation. In one configuration, the first network node may authenticate based on a distribution-based hypothesis test or a Hamming distance-based similarity test.

[0262] The component may be component 199 of network entity 1702 configured to perform the functions recited by the component. As described above, network entity 1702 may include TX processor 316, RX processor 370, and controller / processor 375. Thus, in one configuration, the component may be TX processor 316, RX processor 370, and / or controller / processor 375 configured to perform the functions recited by the component.

[0263] The following aspects are merely illustrative and can be combined with other aspects or teachings described herein without limitation.

[0264] Aspect 1: A method for mutual authentication in wireless communication, the method comprising: sending a first authentication request from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node, the first authentication request including a first phase; sending a second authentication request from the first network node to the second network node via a second MIMO path between the first network node and the second network node, the second authentication request including a second phase; sending an authentication proof from the first network node to the second network node; receiving, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; receiving, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; sending a first configuration response in response to the first configuration request based at least in part on authenticating the first configuration request credential; and sending a second configuration response in response to the second configuration request based at least in part on authenticating the second configuration request credential.

[0265] Aspect 2: The method according to aspect 1, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

[0266] Aspect 3: The method according to aspect 1 or 2, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

[0267] Aspect 4: The method according to any one of aspects 1 to 3, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

[0268] Aspect 5: The method according to any one of aspects 1 to 4, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

[0269] Aspect 6: The method according to any one of Aspects 1 to 5, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

[0270] Aspect 7: The method according to any one of Aspects 1 to 6, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

[0271] Aspect 8: The method according to any one of Aspects 1 to 7, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

[0272] Aspect 9: The method according to any one of Aspects 1 to 8, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

[0273] Aspect 10: The method according to any one of Aspects 1 to 9, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

[0274] Aspect 11: The method according to any one of Aspects 1 to 10, wherein: the first phase is a first random phase; and the second phase is a second random phase.

[0275] Aspect 12: A method for mutual authentication in wireless communication, the method comprising: receiving, at a second network node, a first authentication request including a first phase from a first network node via a first multiple-input multiple-output (MIMO) path; receiving, at the second network node, a second authentication request including a second phase from the first network node via a second MIMO path; receiving, at the second network node, an authentication proof from the first network node; sending, from the second network node to the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; sending, from the second network node to the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; receiving a first configuration response in response to the first configuration request at least partially based on the authentication of the first configuration request credential; and receiving a second configuration response in response to the second configuration request at least partially based on the authentication of the second configuration request credential.

[0276] Aspect 13: The method according to aspect 12, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

[0277] Aspect 14: The method according to aspect 12 or 13, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

[0278] Aspect 15: The method according to any one of aspects 12 to 14, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

[0279] Aspect 16: The method according to any one of aspects 12 to 15, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

[0280] Aspect 17: The method according to any one of aspects 12 to 16, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

[0281] Aspect 18: The method according to any one of Aspects 12 to 17, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

[0282] Aspect 19: The method according to any one of Aspects 12 to 18, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

[0283] Aspect 20: The method according to any one of Aspects 12 to 19, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credentials associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credentials associated with the second network node.

[0284] Aspect 21: The method according to any one of Aspects 12 to 20, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

[0285] Aspect 22: The method according to any one of Aspects 12 to 21, wherein: the first phase is a first random phase; and the second phase is a second random phase.

[0286] Aspect 23: A device for mutual authentication in wireless communication, the device comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to: send a first authentication request from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node, the first authentication request including a first phase; send a second authentication request from the first network node to the second network node via a second MIMO path between the first network node and the second network node, the second authentication request including a second phase; send an authentication proof from the first network node to the second network node; receive, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; receive, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; send a first configuration response in response to the first configuration request based at least in part on authenticating the first configuration request credential; and send a second configuration response in response to the second configuration request based at least in part on authenticating the second configuration request credential.

[0287] Aspect 24: The device according to aspect 23, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

[0288] Aspect 25: The device according to aspect 23 or 24, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

[0289] Aspect 26: The device according to any one of aspects 23 to 25, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

[0290] Aspect 27: The device according to any one of aspects 23 to 26, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

[0291] Aspect 28: The apparatus according to any one of aspects 23 to 27, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

[0292] Aspect 29: The apparatus according to any one of aspects 23 to 28, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

[0293] Aspect 30: The apparatus according to any one of aspects 23 to 29, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

[0294] Aspect 31: The apparatus according to any one of aspects 23 to 30, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

[0295] Aspect 32: The apparatus according to any one of aspects 23 to 31, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

[0296] Aspect 33: The apparatus according to any one of aspects 23 to 32, wherein: the first phase is a first random phase; and the second phase is a second random phase.

[0297] Aspect 34: An apparatus and method for mutual authentication in wireless communication, the apparatus comprising: at least one memory; and at least one processor coupled to the at least one memory and configured to: receive, at a second network node, a first authentication request including a first phase from a first network node via a first multiple-input multiple-output (MIMO) path; receive, at the second network node, a second authentication request including a second phase from the first network node via a second MIMO path; receive an authentication proof at the second network node from the first network node; send, via the first MIMO path, from the second network node to the first network node a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; send, via the second MIMO path, from the second network node to the first network node a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; receive a first configuration response in response to the first configuration request, at least partially based on the authentication of the first configuration request credential; and receive a second configuration response in response to the second configuration request, at least partially based on the authentication of the second configuration request credential.

[0298] Aspect 35: The apparatus according to aspect 34, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

[0299] Aspect 36: The apparatus according to aspect 34 or 35, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

[0300] Aspect 37: The apparatus according to any one of aspects 34 to 36, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

[0301] Aspect 38: The apparatus according to any one of aspects 34 to 37, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

[0302] Aspect 39: The apparatus according to any one of aspects 34 to 38, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

[0303] Aspect 40: The apparatus according to any one of aspects 34 to 39, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

[0304] Aspect 41: The apparatus according to any one of aspects 34 to 40, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

[0305] Aspect 42: The apparatus according to any one of aspects 34 to 41, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

[0306] Aspect 43: The apparatus according to any one of aspects 34 to 42, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

[0307] Aspect 44: The apparatus according to any one of aspects 34 to 43, wherein: the first phase is a first random phase; and the second phase is a second random phase.

Claims

1. A method for mutual authentication in wireless communication, the method comprising: Sending a first authentication request from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node, the first authentication request including a first phase; Sending a second authentication request from the first network node to the second network node via a second MIMO path between the first network node and the second network node, the second authentication request including a second phase; Sending an authentication proof from the first network node to the second network node; Receiving, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; Receiving, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; Sending a first configuration response in response to the first configuration request, at least partially based on authenticating the first configuration request credential; And Sending a second configuration response in response to the second configuration request, at least partially based on authenticating the second configuration request credential.

2. The method according to claim 1, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

3. The method according to claim 2, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

4. The method according to claim 1, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

5. The method according to claim 1, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

6. The method according to claim 5, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

7. The method according to claim 1, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

8. The method according to claim 7, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

9. The method according to claim 1, wherein: The first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and The second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

10. The method according to claim 1, wherein: The first configuration response includes first configuration parameters; and The second configuration response includes second configuration parameters.

11. The method according to claim 1, wherein: The first phase is a first random phase; and The second phase is a second random phase.

12. A method for mutual authentication in wireless communication, the method comprising: Receiving, at a second network node via a first multiple-input multiple-output (MIMO) path, a first authentication request including a first phase from a first network node; Receiving, at the second network node via a second MIMO path, a second authentication request including a second phase from the first network node; Receiving, at the second network node, an authentication proof from the first network node; Sending, via the first MIMO path, from the second network node to the first network node a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and authentication of the authentication proof; Sending, via the second MIMO path, from the second network node to the first network node a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; Receiving a first configuration response in response to the first configuration request, at least partially based on authentication of the first configuration request credential; and Receiving a second configuration response in response to the second configuration request, at least partially based on authentication of the second configuration request credential.

13. The method according to claim 12, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

14. The method according to claim 13, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

15. The method according to claim 12, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

16. The method according to claim 12, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

17. The method according to claim 16, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

18. The method according to claim 12, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

19. The method according to claim 18, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

20. The method according to claim 12, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

21. The method according to claim 12, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

22. The method according to claim 12, wherein: the first phase is a first random phase; and the second phase is a second random phase.

23. An apparatus for mutual authentication in wireless communication, the apparatus comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to: send a first authentication request including a first phase from the first network node to the second network node via a first multiple-input multiple-output (MIMO) path between the first network node and the second network node; send a second authentication request including a second phase from the first network node to the second network node via a second MIMO path between the first network node and the second network node; send an authentication proof from the first network node to the second network node; receive, at the first network node via the first MIMO path, a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication proof; receive, at the first network node via the second MIMO path, a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication proof; send a first configuration response in response to the first configuration request, at least partially based on authenticating the first configuration request credential; and send a second configuration response in response to the second configuration request, at least partially based on authenticating the second configuration request credential.

24. The apparatus according to claim 23, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

25. The apparatus according to claim 24, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

26. The apparatus according to claim 23, wherein the authentication certificate includes a first authentication certificate portion corresponding to the first MIMO path and a second authentication certificate portion corresponding to the second MIMO path.

27. The apparatus according to claim 23, wherein the authentication certificate is sent before receiving the first configuration request and the second configuration request.

28. The apparatus according to claim 27, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication certificate.

29. The apparatus according to claim 27, wherein the authentication certificate is sent after receiving the first configuration request and the second configuration request.

30. The apparatus according to claim 29, wherein the authentication certificate is at least partially based on the first configuration request and the second configuration request.

31. The apparatus according to claim 23, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

32. The apparatus according to claim 23, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

33. The apparatus according to claim 23, wherein: the first phase is a first random phase; and the second phase is a second random phase.

34. An apparatus for mutual authentication in wireless communication, the apparatus comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to: receive, at a second network node, a first authentication request including a first phase from a first network node via a first multiple-input multiple-output (MIMO) path; receive, at the second network node, a second authentication request including a second phase from the first network node via a second MIMO path; receive, at the second network node, an authentication certificate from the first network node; send, via the first MIMO path, from the second network node to the first network node a first configuration request corresponding to a first configuration request credential associated with the second network node, wherein the first configuration request credential is at least partially based on the first phase and the authentication of the authentication certificate; send, via the second MIMO path, from the second network node to the first network node a second configuration request corresponding to a second configuration request credential associated with the second network node, wherein the second configuration request credential is at least partially based on the second phase and the authentication of the authentication certificate; receive a first configuration response in response to the first configuration request, at least partially based on the authentication of the first configuration request credential; and receive a second configuration response in response to the second configuration request, at least partially based on the authentication of the second configuration request credential.

35. The apparatus according to claim 34, wherein the authentication proof includes a first authentication request credential corresponding to the first MIMO path and a second authentication request credential corresponding to the second MIMO path.

36. The apparatus according to claim 35, wherein the authentication proof is configured to be authenticated by the second network node based on a relative difference between the first phase and the second phase.

37. The apparatus according to claim 34, wherein the authentication proof includes a first authentication proof portion corresponding to the first MIMO path and a second authentication proof portion corresponding to the second MIMO path.

38. The apparatus according to claim 34, wherein the authentication proof is sent before receiving the first configuration request and the second configuration request.

39. The apparatus according to claim 38, wherein receiving the first configuration request and the second configuration request is at least partially based on the first network node being authenticated based on the authentication proof.

40. The apparatus according to claim 34, wherein the authentication proof is sent after receiving the first configuration request and the second configuration request.

41. The apparatus according to claim 40, wherein the authentication proof is at least partially based on the first configuration request and the second configuration request.

42. The apparatus according to claim 34, wherein: the first configuration request includes a first phase modulation indication of the first configuration request credential associated with the second network node; and the second configuration request includes a second phase modulation indication of the second configuration request credential associated with the second network node.

43. The apparatus according to claim 34, wherein: the first configuration response includes first configuration parameters; and the second configuration response includes second configuration parameters.

44. The apparatus according to claim 34, wherein: the first phase is a first random phase; and the second phase is a second random phase.