Securing broadcast ranging and positioning messages over sidelink interface

Through the side link positioning key management function, temporary group identification and broadcast key are established for UEs in the wireless communication system, solving the security protection problems of broadcast ranging and positioning messages on the side link interface, ensuring the privacy and security of communication.

CN120283422APending Publication Date: 2025-07-08LENOVO (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480005184.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-02-07
Filing Date
2024-02-08
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In wireless communication systems, broadcast ranging and positioning messages of the side link interface lack effective security protection, resulting in privacy-sensitive data being easily eavesdropped, modified or impersonated, and the prior art cannot effectively ensure communication security.

Method used

Through the side link positioning key management function (SLPKMF), temporary group identification and valid time are established between the initiator UE and the auxiliary UE, multicast or separate broadcast keys are generated, SL positioning auxiliary data and location information are protected, and communication content can be decrypted only by participating UEs.

Benefits of technology

The security protection of side link broadcast ranging and positioning messages is realized, preventing non-participation of UE eavesdropping or tampering, and ensuring the privacy and security of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120283422A_ABST
    Figure CN120283422A_ABST
Patent Text Reader

Abstract

Aspects of the present disclosure relate to protecting broadcast ranging and positioning messages over a sidelink interface. An initiator user equipment (UE) may initiate a ranging or positioning procedure with a secondary UE in proximity to the initiator. The initiator UE sends a sidelink (SL) broadcast message with the requested positioning or ranging action along with the temporary group identifier. The secondary UE performs the requested positioning or ranging action and returns its result to the initiator UE. The result is protected (e.g., encrypted) using one or more keys associated with the temporary group identifier. These one or more keys may be group broadcast keys known by all secondary UEs, or may be separate broadcast keys for separate secondary UEs.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims priority to U.S. Patent Application Serial No. 63 / 484,040, entitled "PROTECTING BROADCAST RANGING AND POSITIONING MESSAGES OVER SIDELINK INTERFACE," filed on February 9, 2023, the entire content of which is incorporated herein by reference. Technical Field

[0003] The present disclosure relates to wireless communication and, more particularly, to protecting broadcast ranging and positioning messages over a sidelink (SL) interface. Background Art

[0004] A wireless communication system may include one or more network communication devices, such as a base station, which may also be referred to as an evolved Node B (eNB), a next-generation Node B (gNB), or other suitable terms. Each network communication device (such as a base station) may support wireless communication for one or more user communication devices, which may also be referred to as user equipment (UE) or other suitable terms. The wireless communication system may support wireless communication with one or more user communication devices by utilizing resources of the wireless communication system, such as time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers). Additionally, the wireless communication system may support wireless communication across various radio access technologies, including third-generation (3G) radio access technology, fourth-generation (4G) radio access technology, fifth-generation (5G) radio access technology, and other suitable radio access technologies beyond 5G (e.g., sixth-generation (6G)).

[0005] In a wireless communication system, scenarios occur in which it is desired to know the location of a UE. Various different ranging or positioning processes may be used to determine the location of the UE. One such ranging or positioning process uses SL positioning, in which a UE receives information from other nearby UEs, and the location of the UE is determined from the received information. Summary of the Invention

[0006] The present disclosure relates to methods, apparatuses, and systems for supporting protection of broadcast ranging and positioning messages over a sidelink interface. An initiator UE may initiate a ranging or positioning process with a secondary UE in proximity to the initiator. The initiator UE sends an SL broadcast message with a requested positioning or ranging action, along with a temporary group identifier or identifier (ID). The secondary UE performs the requested positioning or ranging action and returns the result to the initiator UE. The result is protected (e.g., encrypted) using one or more keys associated with the temporary group ID. These one or more keys may be a group broadcast key known to all secondary UEs or individual broadcast keys for individual secondary UEs. By using these keys, SL positioning assistance data and location information are protected during communication.

[0007] Some implementations of the methods and apparatuses described herein may further include: receiving, from a first device, first signaling indicating a broadcast authorization request message that includes an identifier of the first device and a location identifier for the first device; sending, to the first device, second signaling indicating a broadcast authorization response message that includes a temporary group identifier and a valid time; receiving, from a second device, third signaling indicating a sidelink broadcast key request that includes: a temporary group identifier, an identifier of the first device, an identifier of the second device, and a location identifier for the second device; and sending, to the second device, fourth signaling indicating a sidelink broadcast key response message that includes a broadcast key.

[0008] In some implementations of the methods and apparatuses described herein, it further includes: sending a fifth signaling to a third device, the fifth signaling indicating an authorization request message, the authorization request message including an identifier of a first device and a location identifier; receiving a sixth signaling from the third device, the sixth signaling indicating a successful authorization result of the first device; and in response to the sixth signaling, sending a second signaling to the first device. Additionally or alternatively, the methods and apparatuses described herein further include: assigning a temporary group identifier to the first device. Additionally or alternatively, the methods and apparatuses described herein further include: generating a group broadcast key for a broadcast associated with a broadcast authorization request message, wherein the broadcast authorization response message further includes the group broadcast key; and generating a validity period. Additionally or alternatively, the methods and apparatuses described herein further include: verifying whether a sidelink broadcast key request message is received from a second device within the validity period; and in response to the sidelink broadcast key request message being received from the second device within the validity period, sending a fourth signaling to the second device. Additionally or alternatively, the methods and apparatuses described herein further include: sending a fifth signaling to a third device, the fifth signaling indicating a sidelink authorization request, the sidelink authorization request including: an identifier of the first device, an identifier of the second device, and a location identifier; receiving a sixth signaling from the third device, the sixth signaling indicating an authorization result based on whether the first device and the second device have the same location identifier; and in response to the sidelink broadcast key request message being received from the second device within the validity period and the first device and the second device having the same location identifier, sending a fourth signaling to the second device. Additionally or alternatively, the broadcast key includes a group broadcast key, the second signaling includes a group broadcast key, and the method and apparatus further include: sending one or more additional signals to one or more additional UEs, the one or more additional signals indicating the group broadcast key. Additionally or alternatively, the broadcast key includes a first separate broadcast key for the second device, and the method and apparatus further include: sending a fifth signaling to a third device, the fifth signaling indicating a second separate broadcast key for the third device. Additionally or alternatively, the methods and apparatuses described herein further include: sending a sixth signaling to the first device, the sixth signaling indicating the pairing of the first separate broadcast key with the second device and the pairing of the second separate broadcast key with the third device. Additionally or alternatively, the method is implemented by a sidelink positioning key management function, the first device includes a first user equipment, and the second device includes a second user equipment.

[0009] Some implementations of the methods and apparatuses described herein may further include: receiving, from a first device, first signaling indicating an authorization request message that includes an identifier of a second device and a location identifier for the second device; sending, to the first device, second signaling indicating a successful authorization result for the first device; receiving, from the first device, third signaling indicating a sidelink authorization request that includes: an identifier of the second device, an identifier of a third device, and a location identifier for the third device; and sending, to the first device, fourth signaling indicating an authorization result for the sidelink authorization request.

[0010] In some implementations of the methods and apparatuses described herein, it further includes: storing a location identifier for the second device. Additionally or alternatively, the methods and apparatuses described herein further include: checking whether the second device and the third device have the same location identifier based on the location identifier for the second device and the location identifier for the third device; and in response to the second device and the third device having the same location identifier, sending the fourth signaling to the first device. Additionally or alternatively, the method is implemented in a ranging server, the first device implements a sidelink positioning key management function, the second device includes a first user equipment, and the third device includes a second user equipment.

[0011] Some implementations of the methods and apparatuses described herein may further include: receiving, from a first device, first signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and an identifier of the first device; sending, to a second device, second signaling indicating a sidelink broadcast key request that includes: the temporary group identifier, the identifier of the first device, an identifier of the apparatus implementing the method, and a location identifier for the apparatus; and receiving, from the second device, third signaling indicating a sidelink broadcast key response message.

[0012] In some implementations of the methods and apparatuses described herein, in response to the sidelink broadcast key request message being sent to the second device within a valid time period and the device implementing the method and the first device having the same location identifier, the sidelink broadcast key response message includes a broadcast key. Additionally or alternatively, the sidelink broadcast key response message includes a group broadcast key that is also received by one or more additional apparatuses. Additionally or alternatively, the sidelink broadcast key response message includes a separate broadcast key for the device implementing the method. Additionally or alternatively, the method is implemented by a first user equipment, the first device includes a second user equipment, and the second device includes a device implementing a sidelink positioning key management function.

[0013] Some implementations of the methods and apparatuses described herein may also include: sending a first signaling to a first device, the first signaling indicating a broadcast authorization request message that includes an identifier of the apparatus implementing the method and a location identifier for the apparatus; receiving a second signaling from the first device, the second signaling indicating a broadcast authorization response message that includes a temporary group identifier and a validity period; sending a third signaling to a second device, the third signaling indicating a sidelink broadcast message having the requested positioning or ranging action, the sidelink broadcast message including the temporary group identifier and the identifier of the apparatus; receiving a fourth signaling from the first device, the fourth signaling indicating a broadcast key; establishing a sidelink positioning procedure protocol (SLPP) session with the second device using the broadcast key; and receiving a fifth signaling from the second device, the fifth signaling indicating the result of the requested positioning or ranging action protected by the broadcast key.

[0014] In some implementations of the methods and apparatuses described herein, the second signaling and the fourth signaling are the same signaling, and the broadcast key includes a group broadcast key that is also received by one or more additional devices. Additionally or alternatively, the broadcast key includes a separate broadcast key for the device implementing the method. Additionally or alternatively, the method is implemented by a first user equipment, the first device includes a device implementing a sidelink positioning key management function, and the second device includes a second UE. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 An example of a wireless communication system supporting broadcast ranging and positioning message protection via a sidelink interface in accordance with aspects of the present disclosure is shown.

[0016] Figure 2A 、 Figure 2B and Figure 2C An example of an ad-hoc group creation for broadcast SL positioning supporting broadcast ranging and positioning message protection via a sidelink interface in accordance with aspects of the present disclosure is shown.

[0017] Figure 3A 、 Figure 3B and Figure 3C Another example of an ad-hoc group creation for broadcast SL positioning supporting broadcast ranging and positioning message protection via a sidelink interface in accordance with aspects of the present disclosure is shown.

[0018] Figure 4 and Figure 5 An example of a block diagram of a device supporting broadcast ranging and positioning message protection via a sidelink interface in accordance with aspects of the present disclosure is shown.

[0019] Figures 6 to 14 A flowchart of a method supporting broadcast ranging and positioning message protection via a sidelink interface in accordance with aspects of the present disclosure is shown. Detailed implementation manners

[0020] The initiating UE can initiate a ranging or positioning process with neighboring UEs by using a broadcast message. This ranging or positioning is typically based on Proximity Services (ProSe) features, which do not provide any security for broadcasting. Broadcasting refers to the communication from a device in a wireless communication system to all devices within the wireless range of that device. Therefore, the broadcast message is sent from a device (e.g., the initiating UE or the secondary UE) to all devices in the wireless communication system within the range of that device. Thus, the SL positioning assistance data and location information sent by UEs near the initiating UE are not protected during the broadcast communication.

[0021] Using the techniques discussed herein, the initiating UE sends a broadcast authorization request message to the Sidelink Positioning Key Management Function (SLPKMF). This broadcast authorization request message includes the identifier of the initiating UE and the location identifier (e.g., area ID) for the initiating UE. The SLPKMF responds with a broadcast authorization message including a temporary group ID and a valid time. The initiating UE sends an SL broadcast message including the requested positioning or ranging action together with the identifier of the initiating UE and the temporary group ID. The secondary UE receives the SL broadcast message, and each secondary UE sends an SL broadcast key request to the SLPKMF. The SL broadcast key request includes: the temporary group identifier, the identifier of the initiating UE, the identifier of the secondary UE, and the location identifier for the secondary UE. If the SL broadcast key request is received within the valid time, the SLPKMF returns an SL broadcast key response message including the broadcast key to the secondary UE. The broadcast key can be a group broadcast key that is the same for all secondary UEs, or the SLPKMF can send different individual broadcast keys to each different secondary UE. The secondary UE performs the requested positioning or ranging action and returns the result to the initiating UE. Each secondary UE uses the broadcast key it received from the SLPKMF to protect (e.g., encrypt) its result.

[0022] A typical SL ranging or positioning process is based on ProSe features, which do not provide any security for broadcast messages. By using the keys discussed herein, SL positioning assistance data and location information are protected during communication. One solution to protect SL positioning assistance data and location information is to pre-configure a group of UEs with a security context (e.g., a security key), allowing the group of UEs to communicate securely. However, for broadcasts, the UEs that will receive the SL broadcast message with the requested ranging or positioning action are unknown. Therefore, those UEs cannot be pre-configured with a security context. Alternatively, if all UEs are pre-configured with the same security context, then performing security does not make sense because all UEs can decrypt the message since they have the same key. The techniques discussed herein allow for an ad-hoc temporary group for only the requested ranging or positioning action, one or more broadcast keys to be associated with the temporary group, and one or more broadcast keys to be used to protect the result of the requested ranging or positioning action returned to the initiating UE.

[0023] Aspects of the present disclosure are described in the context of a wireless communication system. Aspects of the present disclosure will be further illustrated and described with reference to device diagrams and flowcharts.

[0024] Figure 1 An example of a wireless communication system 100 supporting the protection of broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure is shown. The wireless communication system 100 may include one or more network entities 102, one or more UEs 104, a core network 106, and a packet data network 108. The wireless communication system 100 may support various radio access technologies. In some implementations, the wireless communication system 100 may be a 4G network, such as an LTE network or an advanced LTE (LTE-A) network. In some other implementations, the wireless communication system 100 may be a 5G network, such as an NR network. In other implementations, the wireless communication system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technologies, including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communication system 100 may support radio access technologies beyond 5G. Additionally, the wireless communication system 100 may support techniques such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA).

[0025] One or more network entities 102 may be dispersed throughout a geographical area to form a wireless communication system 100. One or more network entities 102 described herein may be or include or may be referred to as network nodes, base stations, network units, radio access networks (RANs), base station transceivers, access points, NodeBs, eNodeBs (eNBs), next-generation NodeBs (gNBs), or other suitable terms. The network entity 102 and the UE 104 may communicate via a communication link 110, which may be a wireless or wired connection. For example, the network entity 102 and the UE 104 may perform wireless communication (e.g., receive signaling, send signaling) via the Uu interface.

[0026] The network entity 102 may provide a geographical coverage area 112 for which the network entity 102 may support services (e.g., voice, video, packet data, messaging, broadcasting, etc.) for one or more UEs 104 within the geographical coverage area 112. For example, the network entity 102 and the UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcasting, etc.) according to one or more radio access technologies. In some implementations, the network entity 102 may be movable, e.g., a satellite associated with a non-terrestrial network. In some implementations, different geographical coverage areas 112 associated with the same or different radio access technologies may overlap, but different geographical coverage areas 112 may be associated with different network entities 102. Information and signals described herein may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the description may be represented by voltage, current, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0027] One or more UEs 104 may be dispersed throughout the geographical area of the wireless communication system 100. The UE 104 may include or may be referred to as a mobile device, wireless device, remote device, remote unit, handheld device, or subscriber device or some other suitable term. In some implementations, the UE 104 may be referred to as a unit, station, terminal, or client, etc. Additionally or alternatively, the UE 104 may be referred to as other examples such as an Internet of Things (IoT) device, Internet of Everything (IoE) device, or machine type communication (MTC) device, etc. In some implementations, the UE 104 may be stationary in the wireless communication system 100. In some other implementations, the UE 104 may be mobile in the wireless communication system 100.

[0028] One or more UEs 104 may be devices of different forms or with different capabilities. Some examples of the UE 104 are in Figure 1is shown. The UE 104 may be capable of communicating with various types of devices, such as the network entity 102, other UEs 104, or network devices (e.g., the core network 106, the packet data network 108, relay devices, integrated access and backhaul (IAB) nodes, or other network devices), as Figure 1 shown. Additionally or alternatively, the UE 104 may support communication with other network entities 102 or UEs 104 that may act as relays in the wireless communication system 100.

[0029] The UE 104 may also be capable of supporting direct wireless communication with other UEs 104 via the communication link 114. For example, the UE 104 may support direct wireless communication with another UE 104 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular V2X deployments, the communication link 114 may be referred to as a sidelink. For example, the UE 104 may support direct wireless communication with another UE 104 via the PC5 interface.

[0030] The network entity 102 may support communication with the core network 106, or with another network entity 102, or both. For example, the network entity 102 may interface with the core network 106 via one or more backhaul links 116 (e.g., via S1, N2, N6, or other network interfaces). The network entities 102 may communicate with each other via backhaul links 116 (e.g., via X2, Xn, or other network interfaces). In some implementations, the network entities 102 may communicate directly with each other (e.g., between the network entities 102). In some other implementations, the network entities 102 may communicate with each other either directly or indirectly (e.g., via the core network 106). In some implementations, one or more network entities 102 may include sub-components, such as an access network entity, which may be an example of an access node controller (ANC). The ANC may communicate with one or more UEs 104 via one or more other access network transmission entities, which may be referred to as radio heads, intelligent radio heads, or transmission-receive points (TRPs).

[0031] In some implementations, network entity 102 can be configured in a split architecture that can be configured to utilize a protocol stack physically or logically distributed between two or more network entities 102, such as an integrated access backhaul (IAB) network, an open RAN (O-RAN) (e.g., a network configuration sponsored by the O-RAN Alliance), or a virtualized RAN (vRAN) (e.g., a cloud RAN (C-RAN)). For example, network entity 102 can include one or more of a central unit (CU), a distributed unit (DU), a radio unit (RU), a RAN intelligent controller (RIC) (e.g., a near-real-time RIC (Near-RT RIC), a non-real-time RIC (Non-RT RIC)), a service management and orchestration (SMO) system, or any combination thereof.

[0032] The RU can also be referred to as a radio head, an intelligent radio head, a remote radio head (RRH), a remote radio unit (RRU), or a transmission reception point (TRP). In a split RAN architecture, one or more components of network entity 102 can be co-located, or one or more components of network entity 102 can be located at distributed locations (e.g., separate physical locations). In some implementations, one or more network entities 102 of the split RAN architecture can be implemented as virtual units (e.g., a virtual CU (VCU), a virtual DU (VDU), a virtual RU (VRU)).

[0033] The functional division between the CU, DU, and RU can be flexible and can depend on the functions performed on the CU, DU, or RU (e.g., network layer functions, protocol layer functions, baseband functions, radio frequency functions, and any combination thereof) to support different functions. For example, the functional division of the protocol stack can be adopted between the CU and the DU such that the CU can support one or more layers of the protocol stack while the DU can support one or more different layers of the protocol stack. In some implementations, the CU can carry higher protocol layer (e.g., layer 3 (L3), layer 2 (L2)) functions and signaling (e.g., radio resource control (RRC), service data adaptation protocol (SDAP), packet data convergence protocol (PDCP)). The CU can be connected to one or more DUs or RUs, and one or more DUs or RUs can carry lower protocol layers, such as layer 1 (L1) (e.g., the physical layer (PHY)) or L2 (e.g., the radio link control (RLC) layer, the media access control (MAC) layer) functions and signaling, and each DU or RU can be at least partially controlled by the CU.

[0034] Additionally or alternatively, the functional split of the protocol stack can be adopted between the DU and the RU, such that the DU can support one or more layers of the protocol stack, while the RU can support one or more different layers of the protocol stack. The DU can support one or more different cells (e.g., via one or more RUs). In some implementations, the functional division between the CU and the DU, or between the DU and the RU, can be within a protocol layer (e.g., certain functions for a protocol layer can be performed by one of the CU, DU, or RU, while other functions of the protocol layer are performed by a different one of the CU, DU, or RU).

[0035] The CU can be further functionally divided into a CU control plane (CU-CP) and a CU user plane (CU-UP) function. The CU can be connected to one or more DUs via a midhaul communication link (e.g., F1, F1c, F1u), and the DU can be connected to one or more RUs via a fronthaul communication link (e.g., Open fronthaul (FH) interface). In some implementations, the midhaul communication link or the fronthaul communication link can be implemented according to an interface (e.g., a channel) between layers of the protocol stack supported by the respective network entity 102 communicating via such a communication link.

[0036] The core network 106 can support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The core network 106 can be an evolved packet core (EPC) or a 5G core (5GC), which can include control plane entities that manage access and mobility (e.g., mobility management entity (MME), access and mobility management function (AMF)) and user plane entities that route packets or interconnect to external networks (e.g., serving gateway (S-GW), packet data network (PDN) gateway (P-GW), or user plane function (UPF)), and a location management function (LMF), which is a control plane entity that manages location services. In some implementations, the control plane entity can manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearer, signaling bearer, etc.) for one or more UEs 104 served by one or more network entities 102 associated with the core network 106.

[0037] The core network 106 can communicate with the packet data network 108 via one or more backhaul links 116 (e.g., via S1, N2, N6, or other network interfaces). The packet data network 108 can include an application server 118. In some implementations, one or more UEs 104 can communicate with the application server 118. The UE 104 can establish a session (e.g., a protocol data unit (PDU) session, etc.) with the core network 106 via the network entity 102. The core network 106 can use the established session (e.g., the established PDU session) to route traffic (e.g., control information, data, etc.) between the UE 104 and the application server 118. The PDU session can be an example of a logical connection between the UE 104 and the core network 106 (e.g., one or more network functions of the core network 106).

[0038] In the wireless communication system 100, the network entity 102 and the UE 104 can use the resources of the wireless communication system 100 (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some implementations, the network entity 102 and the UE 104 can support different resource structures. For example, the network entity 102 and the UE 104 can support different frame structures. In some implementations, such as in 4G, the network entity 102 and the UE 104 can support a single frame structure. In some other implementations, such as in 5G and other suitable radio access technologies, the network entity 102 and the UE 104 can support various frame structures (i.e., multiple frame structures). The network entity 102 and the user equipment 104 can support various frame structures based on one or more parameter sets.

[0039] One or more parameter sets can be supported in the wireless communication system 100, and the parameter set can include subcarrier spacing and cyclic prefix. The first parameter set (e.g., μ = 0) can be associated with the first subcarrier spacing (e.g., 15 kHz) and the normal cyclic prefix. The first parameter set (e.g., μ = 0) associated with the first subcarrier spacing (e.g., 15 kHz) can utilize one time slot per subframe. The second parameter set (e.g., μ = 1) can be associated with the second subcarrier spacing (e.g., 30 kHz) and the normal cyclic prefix. The third parameter set (e.g., μ = 2) can be associated with the third subcarrier spacing (e.g., 60 kHz) and the normal cyclic prefix or the extended cyclic prefix. The fourth parameter set (e.g., μ = 3) can be associated with the fourth subcarrier spacing (e.g., 120 kHz) and the normal cyclic prefix. The fifth parameter set (e.g., μ = 4) can be associated with the fifth subcarrier spacing (e.g., 240 kHz) and the normal cyclic prefix.

[0040] The time intervals of resources (e.g., communication resources) can be organized according to frames (also referred to as radio frames). Each frame can have a duration, e.g., a 10 millisecond (ms) duration. In some implementations, each frame can include multiple subframes. For example, each frame can include 10 subframes, and each subframe can have a duration, e.g., a 1 ms duration. In some implementations, each frame can have the same duration. In some implementations, each subframe of a frame can have the same duration.

[0041] Additionally or alternatively, the time intervals of resources (e.g., communication resources) can be organized according to time slots. For example, a subframe can include a certain number (e.g., quantity) of time slots. Each time slot can include a certain number (e.g., quantity) of symbols (e.g., Orthogonal Frequency Division Multiplexing (OFDM) symbols). In some implementations, the number (e.g., quantity) of time slots for a subframe can depend on the parameter set. For a normal cyclic prefix, one time slot can include 14 symbols. For an extended cyclic prefix (e.g., applicable to a 60 kHz subcarrier spacing), one time slot can include 12 symbols. For both the normal cyclic prefix and the extended cyclic prefix, the relationship between the number of symbols per time slot, the number of time slots per subframe, and the number of time slots per frame can depend on the parameter set. It should be understood that a reference to a first parameter set (e.g., μ = 0) associated with a first subcarrier spacing (e.g., 15 kHz) can be used interchangeably between subframes and time slots.

[0042] In a wireless communication system 100, the electromagnetic (EM) spectrum can be divided into various categories, frequency bands, channels, etc. based on frequency or wavelength. By way of example, the wireless communication system 100 can support one or more operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the network entity 102 and the user equipment 104 can perform wireless communication on one or more of the operating frequency bands. In some implementations, FR1 can be used by the network entity 102 and the UE 104 as well as other devices or apparatuses for cellular communication traffic (e.g., control information, data). In some implementations, FR2 can be used by the network entity 102 and the UE 104 as well as other devices or apparatuses for short-range, high data rate capabilities.

[0043] FR1 can be associated with one or more parameter sets (e.g., at least three parameter sets). For example, FR1 can be associated with a first parameter set (e.g., μ = 0) that includes a 15 kHz subcarrier spacing; a second parameter set (e.g., μ = 1) that includes a 30 kHz subcarrier spacing; and a third parameter set (e.g., μ = 2) that includes a 60 kHz subcarrier spacing. FR2 can be associated with one or more parameter sets (e.g., at least two parameter sets). For example, FR2 can be associated with a third parameter set (e.g., μ = 2) that includes a 60 kHz subcarrier spacing; and a fourth parameter set (e.g., μ = 3) that includes a 120 kHz subcarrier spacing.

[0044] The security aspects of ranging-based services and sidelink positioning are discussed herein, particularly the protection of multicast or broadcast. Thus, the following is considered. Using the protocol for SLPP, unicast messages between UEs can be a reference for SL positioning. Additionally, it is also possible to send partial SLPP positioning signaling between UEs via broadcast or multicast. Unicast (one-to-one operation) can be assumed as the reference for the exchange of SLPP signaling between UEs. Operation based on a unicast SLPP session is supported. At least centralized operation is supported, e.g., an operation where one UE performs ranging and / or positioning calculations based on measurement or location information related to itself and / or other UEs. For multicast or broadcast (in addition to unicast), it is at least feasible to send the following positioning signaling: SL positioning capabilities and SL positioning assistance data. Location information can also be included.

[0045] The security issues regarding how to protect SL multicast or broadcast messages are considered. The security issues (e.g., encryption and / or integrity requirements) regarding specific information of SL positioning capabilities and assistance data in multicast or broadcast, as well as the use cases for applying multicast or broadcast are considered. It is also considered that failing to protect SL multicast or broadcast communication can cause the following threats: passive attackers can eavesdrop on privacy-sensitive data exchanged between UEs, active attackers can intercept, modify, or replay data packets exchanged between UEs, and broadcast or multicast UEs can be impersonated by attackers.

[0046] The techniques discussed herein provide solutions to protect SL multicast or broadcast communication.

[0047] Using the techniques discussed herein, a UE 120 (referred to as an initiating UE) sends a broadcast authorization request message to a network entity 102 implementing SLPKMF. The broadcast authorization request message includes an identifier of the UE 120 and a location identifier for the UE 120 (e.g., a region ID). The network entity 102 responds with a broadcast authorization message that includes a temporary group ID and a validity time. The UE 120 sends an SL broadcast message with the requested positioning or ranging action, along with the identifier of the initiating UE and the temporary group ID. One or more secondary UEs 122 and 124 receive the SL broadcast message, and each secondary UE 122 and 124 sends an SL broadcast key request to the network entity 102. The SL broadcast key request includes the temporary group identifier, the identifier of the UE 120, the identifier of the secondary UE 122 or 124, and a location identifier for the secondary UE 122 or 124. If the SL broadcast key request is received within the validity time, the network entity 102 returns an SL broadcast key response message to the secondary UEs 122 and 124 that includes a broadcast key. The broadcast key can be a group broadcast key that is the same for all secondary UEs 122 and 124, or the network entity 102 can send a different individual broadcast key to each different secondary UE 122 and 124. The secondary UEs 122 and 124 perform the requested positioning or ranging action and return their results to the UE 120 via one or more SL communications. Each secondary UE 122 and 124 uses the broadcast key it received from the network entity 102 to protect its results (e.g., encrypt the results or the SL communication).

[0048] Communication between devices discussed herein, such as communication between a UE 104 and a network entity 102, is performed using various different signaling. For example, such signaling can be any of various messages, requests, or responses, such as a trigger message, a configuration message, etc. By another example, such signaling can be any of various signaling media or protocols through which a message is transmitted, such as any combination of radio resource control (RRC), downlink control information (DCI), uplink control information (UCI), sidelink control information (SCI), media access control element (MAC-CE), SLPP, PC5 radio resource control (PC5-RRC), etc.

[0049] The following terms are used to refer to the roles of specific UEs or devices participating in an SL positioning session. The techniques discussed herein can be applied to all of these UE roles.

[0050] An initiating device is a device that initiates an SL positioning or ranging session and can be a network entity (e.g., a gNB, an LMF), a UE, a roadside unit (RSU), etc.

[0051] A responder device refers to a device that responds to an SL positioning or ranging session from an initiator device, and can be a network entity (e.g., gNB, LMF), UE, RSU, etc.

[0052] The target UE can be referred to as the UE of interest, and its positioning (absolute position or relative positioning) will be obtained by the network or the UE itself.

[0053] Sidelink positioning refers to a UE (e.g., an initiator UE) using reference signals transmitted through SL (e.g., the PC5 interface) to obtain absolute positioning, relative positioning, or ranging information.

[0054] Ranging refers to the determination of one or both of the distance and direction between a UE and another entity (e.g., an anchor UE).

[0055] An anchor UE refers to a UE that supports the positioning of a target UE, e.g., by transmitting or receiving reference signals for positioning through an SL interface, providing positioning-related information, etc. The anchor UE can also be referred to as an SL reference UE.

[0056] An assisting UE refers to a UE that supports ranging or sidelink positioning between an SL reference UE and a target UE through the PC5 when direct ranging or sidelink positioning between the SL reference UE or anchor UE and the target UE cannot be supported. The measurements or results of ranging or sidelink positioning between the assisting UE and the SL reference UE and between the assisting UE and the target UE are determined and used to obtain the ranging or sidelink positioning result between the target UE and the SL reference UE.

[0057] An SL positioning server UE refers to a UE that calculates the service supply location for SL positioning and ranging. The SL positioning server interacts with other UEs through the PC5 as needed to calculate the location of the target UE. If location calculation is supported, the target UE or the SL reference UE can act as the SL positioning server UE.

[0058] An SL positioning client UE refers to a third-party UE other than the SL reference UE and the target UE that initiates a ranging or sidelink positioning service request on behalf of the application residing on it. It should be noted that the SL positioning client UE does not have to support ranging or sidelink positioning capabilities, but must support communication between the SL positioning client UE and the SL reference UE or the target UE.

[0059] In one or more implementations, protecting broadcast ranging and positioning messages through a side link interface establishes a temporary group for broadcast responders. Since SL positioning capabilities, SL positioning assistance data, and location information will not be leaked to other UEs not participating in the SLPP process, the focus of protection is on the response from the participating UEs of the ranging or positioning action. In addition or alternatively, security protection can be extended to request and response message pairs for SL positioning capabilities, SL positioning assistance data, and location information. In addition or alternatively, security protection can also be extended to SL positioning error message indications from one SL positioning UE to another SL positioning UE. Therefore, the UEs responding to the broadcast request from the initiator UE will form a self-organizing temporary group only for the requested action, and the self-organizing temporary group will be protected using one key per group or a separate key for each participating UE. The temporary group may include SL UEs or nodes (e.g., anchor UEs, target UEs, etc.) that are interested in or necessary to perform SL positioning (including absolute or relative position estimation or ranging for at least one distance, direction, or orientation). The temporary group may include a set of validity criteria based on time criteria, including but not limited to validity timers, time windows, etc. Additionally or alternatively, the temporary nature of the group may include a set of validity criteria based on spatial criteria, such as geographic proximity location information, including but not limited to cell ID, region ID, beam ID, 2D or 3D location coordinates, etc.

[0060] The implementation of SLPKMF can be independent or co-located with the SL positioning application or ranging application server. SLPKMF can be implemented as an application function (AF), application server (AS) or network function (NF), or co-located with unified data management (UDM), LMF, etc. Both SLPKMF and NF can be implemented in the network for use within the coverage, and can also be implemented in the authorized UE for use outside the coverage.

[0061] Figure 2A , Figure 2B and Figure 2CExample 200 shows the creation of an ad-hoc group for supporting broadcast SL positioning that protects broadcast ranging and positioning messages through a sidelink interface according to aspects of the present disclosure. Example 200 includes UE 202 (also referred to as the initiating UE or initiator UE), multiple additional UEs 204, additional UE 206, and additional UE 208 (each also referred to as a participating UE or secondary UE), SLPKMF 210, and ranging server 212. SLPKMF 210 may be implemented on the same device as ranging server 212 or on separate devices. In one or more implementations, SLPKMF 210 is implemented in a UE. Although three participating UEs 204, participating UE 206, and participating UE 208 are shown, it should be noted that the techniques discussed herein can be used with any number of participating UEs.

[0062] At 214, UE 202 wants to initiate an SL broadcast authorization request and sends a broadcast authorization request message to SLPKMF 210, which includes the ID of UE 202 and the region ID where UE 202 is located. The region ID may also be referred to as a location identifier. The region ID identifies the region where UE 202 is located, where the region is a specific physical location or a general physical area where UE 202 is located. If UE 202 has the ability to provide such information, for example, UE 202 has a Global Navigation Satellite System (GNSS) to calculate its own absolute position, then the region ID may be provided by UE 202, where the calculation of the region ID is based on the following set of equations:

[0063] x1 = Floor(x / L) Mod 64,

[0064] y1 = Floor(y / L) Mod 64,

[0065] Zone_id = y1 * 64 + x1,

[0066] where L is the value of sl-ZoneLength included in an RRC message or information element (IE) (e.g., sl-ZoneConfig); x is the geodetic distance in longitude between the current position of UE 202 and the geographic coordinate (0,0) according to the World Geodetic System 84 (WGS84) model and is expressed in units such as meters, and y is the geodetic distance in latitude between the current position of UE 202 and the geographic coordinate (0,0) according to the WGS84 model and is expressed in units such as meters.

[0067] At 216, the SLPKMF 210 sends an authorization request (e.g., an authorization request message) for the UE 202's broadcast request to the ranging server 212. The authorization request includes the ID of the UE 202 and the area ID for the UE 202.

[0068] At 218, the ranging server 212 authorizes the request, e.g., based on the UE 202 subscription. The ranging server 212 also stores the area ID corresponding to the UE 202.

[0069] At 220, the ranging server provides an authorization result to the SLPKMF 210.

[0070] At 222, the SLPKMF 210 assigns a temporary group ID and generates a group broadcast key K for the broadcast communication B 。The SLPKMF210 also sets a valid time for the broadcast process, e.g., as discussed below, the UEs responding to the broadcast request must respond within the valid time. Additionally, in one or more implementations, the group broadcast key K in the participating UEs 204, 206, and 208 B will be removed after the expiration of the valid time. Thus, the SLPKMF 210 sets the valid time to allow the positioning or ranging action to complete. The valid time can be specified in various ways, such as a fixed time (e.g., the current time plus a specific number of milliseconds).

[0071] At 224, the SLPKMF 210 provides the temporary group ID, the group broadcast key K B and the valid time to the UE 202 in a broadcast authorization response message.

[0072] At 226, the UE 202 sends an SL broadcast message that has the requested positioning or ranging action, the ID of the UE202, and the temporary group ID.

[0073] At 228, each of the UEs 204, 206, and 208 receives the SL broadcast message from the UE 202 and sends a broadcast key request to the SLPKMF 210. The broadcast key request includes the temporary group ID, the ID of the UE 202, the ID of the UE sending the broadcast key request (e.g., the ID of the UE 204, 206, or 208), and the location identifier of the UE sending the broadcast key request (e.g., the area ID) (e.g., the ID of the UE 204, 206, or 208), indicating the local area where the UE sending the broadcast key request is located.

[0074] At 230, the SLPKMF 210 checks whether the UE will respond within the valid time of the broadcast request (e.g., whether the broadcast key request is received from the UE 204, UE 206, or UE 208 within the valid time or at least within a threshold amount of time before the valid time). In one or more implementations, if the UE will respond within the valid time of the broadcast request, the SLPKMF 210 sends an authorization request to the ranging server 212. Additionally or alternatively, if the UE will not respond within the valid time of the broadcast request, the SLPKMF 210 need not send an authorization request to the ranging server 212 and may send a rejection indication or message to the UE 202 indicating that the requested SL ranging or positioning action is rejected or denied (e.g., and thus not performed).

[0075] At 232, the SLPKMF 210 sends an authorization request to the ranging server 212. The SLPKMF 210 may send a separate request for each UE or may accumulate requests for all UEs that respond to the same temporary group ID and initiator ID (the ID of the UE 202). The authorization request includes the ID of the UE 202, the ID of the responder UE (UE 204, UE 206, or UE 208), and the location ID (e.g., area ID) of the responder UE (UE 204, UE 206, or UE 208).

[0076] At 234, the ranging server 212 authorizes the requests of the participating UEs and may check whether all participating UEs are located in the same area or location, which is also referred to as a proximity check. For example, the ranging server 212 compares the location identifier provided by the UE 202 at 216 with the location identifiers from the UE 204, UE 206, and UE 208. If the location identifier of the UE 202 and the location identifier (e.g., area) of at least one of the responder UEs 204, 206, or 208 are different, the ranging server 212 may reject the authorization. If the location identifier of the UE 202 and the location identifiers (e.g., areas) of the responder UEs 204, 206, and 208 are the same (or within the same threshold amount), the ranging server 212 may accept or approve the authorization.

[0077] At 236, the ranging server 212 provides an authorization result to the SLPKMF 210. Depending on the request at 232, the ranging server 212 may send a separate response for each of the UEs 204, 206, and 208 or may send an accumulated response for all of the responder UEs 204, 206, and 208.

[0078] At 238, the SLPKMF 210 provides the group broadcast key K generated at 222 to all responsive UEs 204, 206, and 208. B In one or more implementations, the SLPKMF 210 provides the group broadcast key K to all responsive UEs 204, 206, and 208 in response to an authorized result indicating approval at 236. B Additionally or alternatively, if the authorization result at 236 indicates failure or rejection, the SLPKMF 210 does not provide the group broadcast key K to all responsive UEs 204, 206, and 208. B The SLPKMF 210 may also provide a rejection indication or message to the UE 202 indicating that the requested SL ranging or positioning action is rejected or denied (e.g., and thus not performed).

[0079] At 240, all UEs 202, 204, 206, and 208 participate in the requested SL ranging or positioning action according to the request at 226.

[0080] At 242, if SLPP session-based operations are used, the 202 establishes an SLPP session with the participating UEs 204, 206, and 208. The SLPP session may use the broadcast key K B for authentication and establishment. If no SLPP session operations are used, the session establishment at 242 may be skipped.

[0081] At 244, the participating UEs 204, 206, and 208 provide the results of the SL ranging or positioning action they performed at 240. For example, the UEs 204, 206, and 208 provide at least one of auxiliary data, configuration information, or location information to the 202 protected by the common group broadcast key K B .

[0082] If no SLPP session operations are used, each participating UE 204, 206, and 208 broadcasts this information.

[0083] If SLPP session-based operations are used, each participating UE 204, 206, and 208 sends this information within the established SLPP session.

[0084] At 246, if SLPP session-based operations are used, when the SL ranging or positioning action has been completed, the UE 202 terminates the SLPP session with the participating UEs 204, 206, and 208.

[0085] Figure 3A 、Figure 3B and Figure 3C illustrates an example 300 for supporting the creation of an ad-hoc group for broadcast SL positioning that protects broadcast ranging and positioning messages through a sidelink interface according to aspects of the present disclosure. Example 200 includes a UE 202 (also referred to as an initiating UE or initiator UE), a plurality of additional UEs 204, UE 206, and UE 208 (each also referred to as a participating UE or assisting UE), an SLPKMF 210, and a ranging server 212. The SLPKMF 210 may be implemented on the same device as the ranging server 212 or on separate devices. In one or more implementations, the SLPKMF 210 is implemented in a UE. Although three participating UEs 204, UE 206, and UE 208 are shown, it should be noted that the techniques discussed herein may be used with any number of participating UEs.

[0086] Example 300 is similar to Figure 2A 、 Figure 2B and Figure 2C Example 200 in Bx but differs in that Example 300 uses a separate broadcast key K Bx for UEs 204, UE 206, and UE 208, while Example 200 uses a common group broadcast key K B .

[0087] At 302, the UE 202 wants to initiate an SL broadcast authorization request and sends a broadcast authorization request message to the SLPKMF 210. The broadcast authorization request message includes the UE ID of the UE 202 and the region ID where the UE 202 is located. The region ID identifies the region where the UE 202 is located, where the region is a specific physical location or a general physical area where the UE 202 is located. If the UE 202 has the ability to provide such information, the region ID may be provided by the UE 202. For example, the UE 202 has GNSS capabilities to calculate its own absolute position, and the region ID is calculated based on the following set of equations:

[0088] x1 = Floor(x / L) Mod 64,

[0089] y1 = Floor(y / L) Mod 64,

[0090] Zone_id = y1 * 64 + x1,

[0091] Where L is the value of sl-ZoneLength included in the RRC message or IE (e.g., sl-ZoneConfig); x is the geodetic distance in longitude between the current location of UE 202 and the geographic coordinate (0,0) according to the World Geodetic System 84 (WGS84) model and is expressed in, for example, meters, and y is the geodetic distance in latitude between the current location of UE 202 and the geographic coordinate (0,0) according to the WGS84 model and is expressed in, for example, meters.

[0092] At 304, the SLPKMF 210 sends an authorization request (e.g., an authorization request message) for the ranging request by UE 202 to the ranging server 212. The authorization request includes the ID of UE 202 and the area ID for UE 202.

[0093] At 306, the ranging server 212 authorizes the request, e.g., based on the subscription of UE 202. The ranging server 212 also stores the area ID corresponding to UE 202.

[0094] At 308, the ranging server provides an authorization result to the SLPKMF 210.

[0095] At 310, the SLPKMF 210 assigns a temporary group ID for the broadcast communication. The SLPKMF 210 also sets the time-to-live for the broadcast process, e.g., as discussed below, the UEs responding to the broadcast request must respond within the time-to-live. Additionally, in one or more implementations, the individual broadcast key K Bx (discussed in more detail below) will be removed after the time-to-live expires. Thus, the SLPKMF 210 sets the time-to-live to allow the positioning or ranging action to be completed. The time-to-live can be specified in various ways, such as a fixed time (e.g., the current time plus a specific number of milliseconds).

[0096] At 312, the SLPKMF 210 provides the temporary group ID and the time-to-live to UE 202 in a broadcast authorization response message. The individual broadcast key K Bx will be assigned per each participating UE 204, UE 206, and UE 208, as discussed in more detail below.

[0097] At 314, UE 202 sends an SL broadcast message that has the requested positioning or ranging action, the ID of UE202, and the temporary group ID.

[0098] At 316, each of UEs 204, 206, and 208 receives an SL broadcast message from UE 202 and sends a broadcast key request to SLPKMF 210. The broadcast key request includes a temporary group ID, the ID of UE 202, the ID of the UE sending the broadcast key request (e.g., the ID of UE 204, 206, or 208), and a location identifier of the UE sending the broadcast key request (e.g., a region ID) (e.g., the ID of UE 204, 206, or 208), indicating the local area where the UE sending the broadcast key request is located.

[0099] At 318, SLPKMF 210 checks whether the UE will respond within the valid time of the broadcast request (e.g., whether the broadcast key request is received from UE 204, 206, or 208 within the valid time or at least within a threshold amount of time before the valid time). In one or more implementations, if the UE will respond within the valid time of the broadcast request, then SLPKMF 210 sends an authorization request to ranging server 212. Additionally or alternatively, if the UE will not respond within the valid time of the broadcast request, then SLPKMF 210 need not send an authorization request to ranging server 212 and may send a rejection indication or message to UE 202 indicating that the requested SL ranging or positioning action is rejected or denied (e.g., and thus not performed).

[0100] At 320, SLPKMF 210 sends an authorization request to ranging server 212. SLPKMF 210 may send a separate request for each UE or may accumulate requests from all UEs in response to the same temporary group ID and initiator ID (the ID of UE 202). The authorization request includes the ID of UE 202, the ID of the responder UE (UE 204, 206, or 208), and the location ID (e.g., a region ID) of the responder UE (UE 204, 206, or 208).

[0101] At 322, the ranging server 212 authorizes the requests of the participating UEs and can check whether all the participating UEs are located in the same area or location, which is also known as proximity check. For example, the ranging server 212 compares the location identifier provided by the UE 202 at 216 with the location identifiers from the UEs 204, 206, and 208. If the location identifier (e.g., area) of the UE 202 is different from the location identifiers of at least one of the responding UEs 204, 206, or 208, the ranging server 212 can reject the authorization. If the location identifiers (e.g., area) of the UE 202 and the responding UEs 204, 206, and 208 are the same (or within the same threshold amount), the ranging server 212 can accept or approve the authorization.

[0102] At 324, the ranging server 212 provides the authorization result to the SLPKMF 210. Depending on the request at 232, the ranging server 212 can send individual responses for each of the UEs 204, 206, and 208, or a cumulative response for all the responding UEs 204, 206, and 208.

[0103] At 326, the SLPKMF 210 generates a separate broadcast key K for each responding UEx Bx . For example, the SLPKMF 210 generates a separate broadcast key K for UE2 (UE 204) B2 , a separate broadcast key K for UE3 (UE 206) B3 , and a separate broadcast key K for UE4 (UE 208) B4 .

[0104] At 328, the SLPKMF 210 provides each responding UEx with the separate broadcast key K generated for UEx at 326 Bx . For example, the SLPKMF 210 provides the separate broadcast key K to UE2 (UE 204) B2 , the separate broadcast key K to UE3 (UE 206) B3 , and the separate broadcast key K to UE4 (UE 208) B4 .

[0105] At 330, the SLPKMF 210 provides the UE 202 with all the separate broadcast keys K Bx and the pairings of the responding UEx IDs. Accordingly, the UE 202 receives the pairings of each of the UEs 204, 206, and 208 with their respective separate broadcast keys.

[0106] At 332, all UEs 204, 206, and 208 participate in the requested SL ranging or positioning action in accordance with the request at 226.

[0107] At 334, if SLPP session-based operations are used, 202 establishes an SLPP session with the participating UEs 204, 206, and 208. The SLPP session can use the broadcast key K Bx for authentication and establishment. If no SLPP session operation is used, the session establishment at 242 can be skipped.

[0108] At 336, the participating UEs 204, 206, and 208 provide the results of the SL ranging or positioning action they performed at 332. For example, UEs 204, 206, and 208 provide at least one of auxiliary data, configuration information, or location information to 202 protected by a separate broadcast key K Bx .

[0109] If no SLPP session operation is used, each participating UE 204, 206, and 208 broadcasts this information.

[0110] If SLPP session-based operations are used, each participating UE 204, 206, and 208 sends this information within the established SLPP session.

[0111] At 338, if SLPP session-based operations are used, UE 202 terminates the SLPP session with the participating UEs 204, 206, and 208 after the SL ranging or positioning action has been completed.

[0112] Thus, a UE can initiate ranging or positioning with nearby UEs using a broadcast message. UEs that respond to the broadcast request from the initiating UE will form an ad-hoc temporary group solely for the requested action, and this ad-hoc temporary group will be protected using a per-group key or a per-participating-UE individual key. Thus, SL positioning assistance data and location information are protected during communication.

[0113] Figure 4FIG. 400 is an example of a block diagram showing a device 402 that supports protecting broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. The device 402 may be an example of the network entity 102 or the UE 104 as described herein. The device 402 may support wireless communication with one or more network entities 102, UEs 104, or any combination thereof. The device 402 may include components for two-way communication, and the components for two-way communication include components for transmitting and receiving communication, such as a processor 404, a memory 406, a transceiver 408, and an I / O controller 410. These components may be electronically communicated or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., a bus).

[0114] The processor 404, the memory 406, the transceiver 408, or various combinations or various components thereof may be examples of components for performing various aspects of the present disclosure as described herein. For example, the processor 404, the memory 406, the transceiver 408, or various combinations or components thereof may support a method for performing one or more operations described herein.

[0115] In some implementations, the processor 404, the memory 406, the transceiver 408, or various combinations or components thereof may be implemented in hardware (e.g., in a communication management circuit system). The hardware may include a processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which are configured to or otherwise support components for performing the functions described in the present disclosure. In some implementations, the processor 404 and the memory 406 coupled to the processor 404 may be configured to perform one or more functions described herein (e.g., the processor 404 executes instructions stored in the memory 406).

[0116] For example, the processor 404 may support wireless communication at the device 402 in accordance with examples disclosed herein. The processor 404 may be configured to or otherwise support: receiving, from a first device, a first signaling indicating a broadcast authorization request message, the broadcast authorization request message including: an identifier of the first device and a location identifier for the first device; sending, to the first device, a second signaling indicating a broadcast authorization response message, the broadcast authorization response message including a temporary group identifier and a valid time; receiving, from a second device, a third signaling indicating a sidelink broadcast key request, the sidelink broadcast key request including: the temporary group identifier, the identifier of the first device, the identifier of the second device, and a location identifier for the second device; sending, to the second device, a fourth signaling indicating a sidelink broadcast key response message, the sidelink broadcast key response message including a broadcast key.

[0117] Additionally or alternatively, the processor 404 may be configured to or otherwise support: sending a fifth signaling to a third device, the fifth signaling indicating an authorization request message that includes an identifier of the first device and a location identifier; receiving a sixth signaling from the third device, the sixth signaling indicating a successful authorization result of the first device; and in response to the sixth signaling, sending a second signaling to the first device; to: assign a temporary group identifier to the first device; to: generate a group broadcast key for a broadcast associated with the broadcast authorization request message, wherein the broadcast authorization response message further includes the group broadcast key; and generate a validity time; additionally or alternatively, the processor 404 may be configured to or otherwise support: to: verify whether a sidelink broadcast key request message is received from the second device within the validity time; and in response to the sidelink broadcast key request message being received from the second device within the validity time, sending a fourth signaling to the second device; to: send a fifth signaling to the third device, the fifth signaling indicating a sidelink authorization request that includes: an identifier of the first device, an identifier of the second device, and a location identifier; receiving a sixth signaling from the third device, the sixth signaling indicating an authorization result based on whether the first device and the second device have the same location identifier; and in response to the sidelink broadcast key request message being received from the second device within the validity time and the first device and the second device having the same location identifier, sending a fourth signaling to the second device; wherein the broadcast key includes the group broadcast key, the second signaling includes the group broadcast key, and the processor is further configured to cause the device to: send one or more additional signaling to one or more additional UEs, the one or more additional signaling indicating the group broadcast key; wherein the broadcast key includes a first separate broadcast key for the second device, and the processor is further configured to cause the device to: send a fifth signaling to the third device, the fifth signaling indicating a second separate broadcast key for the third device; wherein the processor is further configured to cause the device to: send a sixth signaling to the first device, the sixth signaling indicating the pairing of the first separate broadcast key with the second device and the pairing of the second separate broadcast key with the third device; wherein the device implements a sidelink positioning key management function, the first device includes a first user equipment, and the second device includes a second user equipment.

[0118] For example, the processor 404 may support wireless communication at the device 402 according to the examples disclosed herein. The processor 404 may be configured to or otherwise support: receiving, from a first device, a first signaling indicating an authorization request message that includes an identification of a second device and a location identification for the second device; sending, to the first device, a second signaling indicating a successful authorization result for the first device; receiving, from the first device, a third signaling indicating a sidelink authorization request that includes an identification of the second device, an identification of a third device, and a location identification for the third device; and sending, to the first device, a fourth signaling indicating an authorization result for the sidelink authorization request.

[0119] Additionally or alternatively, the processor 404 may be configured to or otherwise support: storing a location identification for the second device; by: checking whether the second device and the third device have the same location identification based on the location identification for the second device and the location identification for the third device; and in response to the second device and the third device having the same location identification, sending the fourth signaling to the first device; wherein the apparatus includes a ranging server, the first device implements a sidelink positioning key management function, the second device includes a first user equipment, and the third device includes a second user equipment.

[0120] For example, the processor 404 may support wireless communication at the device 402 according to the examples disclosed herein. The processor 404 may be configured to or otherwise support components for: receiving, from a first device, a first signaling indicating a broadcast authorization request message that includes an identification of the first device and a location identification for the first device; sending, to the first device, a second signaling indicating a broadcast authorization response message that includes a temporary group identifier and a valid time; receiving, from a second device, a third signaling indicating a sidelink broadcast key request that includes the temporary group identifier, the identification of the first device, the identification of the second device, and a location identification for the second device; and sending, to the second device, a fourth signaling indicating a sidelink broadcast key response message that includes a broadcast key.

[0121] Additionally or alternatively, the processor 404 may be configured to or otherwise support: sending a fifth signaling to a third device, the fifth signaling indicating an authorization request message that includes an identifier of the first device and a location identifier; receiving a sixth signaling from the third device, the sixth signaling indicating a successful authorization result of the first device; and in response to the sixth signaling, sending a second signaling to the first device; assigning a temporary group identifier to the first device; generating a group broadcast key for a broadcast associated with the broadcast authorization request message, wherein the broadcast authorization response message further includes the group broadcast key; and generating a validity period; verifying whether a sidelink broadcast key request message is received from the second device within the validity period; and in response to the sidelink broadcast key request message being received from the second device within the validity period, sending a fourth signaling to the second device; sending a fifth signaling to the third device, the fifth signaling indicating a sidelink authorization request that includes: an identifier of the first device, an identifier of the second device, and a location identifier; receiving a sixth signaling from the third device, the sixth signaling indicating an authorization result based on whether the first device and the second device have the same location identifier; and in response to the sidelink broadcast key request message being received from the second device within the validity period and the first device and the second device having the same location identifier, sending a fourth signaling to the second device; wherein the broadcast key includes the group broadcast key, the second signaling includes the group broadcast key, and the method further includes: sending one or more additional signaling to one or more additional UEs, the one or more additional signaling indicating the group broadcast key; wherein the broadcast key includes a first separate broadcast key for the second device, and the method further includes: sending a fifth signaling to the third device, the fifth signaling indicating a second separate broadcast key for the third device; sending a sixth signaling to the first device, the sixth signaling indicating the pairing of the first separate broadcast key with the second device and the pairing of the second separate broadcast key with the third device; wherein the method is implemented by a sidelink positioning key management function, the first device includes a first user equipment, and the second device includes a second user equipment.

[0122] For example, the processor 404 may support wireless communication at the device 402 according to examples disclosed herein. The processor 404 may be configured to or otherwise support components for: receiving a first signaling from a first device, the first signaling indicating an authorization request message that includes: an identifier of a second device and a location identifier for the second device; sending a second signaling to the first device, the second signaling indicating a successful authorization result for the first device; receiving a third signaling from the first device, the third signaling indicating a sidelink authorization request that includes: an identifier of the second device, an identifier of a third device, and a location identifier for the third device; and sending a fourth signaling to the first device, the fourth signaling indicating an authorization result for the sidelink authorization request.

[0123] Additionally or alternatively, the processor 404 may be configured to or otherwise support: storing a location identifier for a second device; checking whether the second device and a third device have the same location identifier based on the location identifier for the second device and the location identifier for the third device; and in response to the second device and the third device having the same location identifier, sending a fourth signaling to a first device; wherein the method is implemented in a ranging server, the first device implements a sidelink positioning key management function, the second device includes a first user equipment, and the third device includes a second user equipment.

[0124] The processor 404 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some implementations, the processor 404 may be configured to operate a memory array using a memory controller. In some other implementations, the memory controller may be integrated into the processor 404. The processor 404 may be configured to execute computer-readable instructions stored in a memory (e.g., the memory 406) to cause the device 402 to perform various functions of the present disclosure.

[0125] The memory 406 may include random access memory (RAM) and read-only memory (ROM). The memory 406 may store computer-readable, computer-executable code that includes instructions that, when executed by the processor 404, cause the device 402 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or other types of memory. In some implementations, the code may not be directly executable by the processor 404, but may cause a computer (e.g., when compiled and executed) to perform the functions described herein. In some implementations, the memory 406 may include a basic input / output system (BIOS) among other functions, which may control basic hardware or software operations, such as interactions with peripheral components or devices.

[0126] The I / O controller 410 may manage input and output signals for the device 402. The I / O controller 410 may also manage peripheral devices not integrated into the device 402. In some implementations, the I / O controller 410 may represent a physical connection or port to an external peripheral device. In some implementations, the I / O controller 410 may utilize an operating system, such as

[0127] or other known operating systems. In some implementations, the I / O controller 410 can be implemented as part of a processor (such as the processor 404). In some implementations, a user can interact with the device 402 via the I / O controller 410 or via hardware components controlled by the I / O controller 410.

[0128] In some implementations, the device 402 can include a single antenna 412. However, in some other implementations, the device 402 can have more than one antenna 412 (i.e., multiple antennas), including multiple antenna panels or antenna arrays, which may be capable of concurrently transmitting or receiving multiple wireless transmissions. The transceiver 408 can communicate bidirectionally via one or more antennas 412, wired or wireless links, as described herein. For example, the transceiver 408 can represent a wireless transceiver and can communicate bidirectionally with another wireless transceiver. The transceiver 408 can also include a modem to modulate packets, to provide the modulated data packets to one or more antennas 412 for transmission, and to demodulate data packets received from one or more antennas 412.

[0129] Figure 5 FIG. 500 is an example of a block diagram showing a device 502 that supports protecting broadcast ranging and positioning messages via a sidelink interface, in accordance with aspects of the present disclosure. The device 502 can be an example of the UE 104 as described herein. The device 502 can support wireless communication with one or more network entities 102, UEs 104, or any combination thereof. The device 502 can include components for bidirectional communication, and the components for bidirectional communication include components for sending and receiving communication, such as a processor 504, a memory 506, a transceiver 508, and an I / O controller 510. These components can communicate electronically or otherwise be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., a bus).

[0130] The processor 504, the memory 506, the transceiver 508, or various combinations or various components thereof can be examples of components for performing various aspects of the present disclosure as described herein. For example, the processor 504, the memory 506, the transceiver 508, or various combinations or components thereof can support a method for performing one or more operations described herein.

[0131] In some implementations, the processor 504, the memory 506, the transceiver 508, or various combinations or components thereof may be implemented in hardware (e.g., in a communication management circuitry). The hardware may include a processor, a digital signal processor (DSP), an ASIC, a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which are configured to or otherwise support components for performing the functions described in this disclosure. In some implementations, the processor 504 and the memory 506 coupled to the processor 504 may be configured to perform one or more functions described herein (e.g., the processor 504 executes instructions stored in the memory 506).

[0132] For example, the processor 504 may support wireless communication at the device 502 according to the examples disclosed herein. The processor 504 may be configured to or otherwise support: receiving a first signaling from a first device, the first signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and an identification of the first device; sending a second signaling to a second device, the second signaling indicating a sidelink broadcast key request, the sidelink broadcast key request including: a temporary group identifier, an identification of the first device, an identification of the device, and a location identification for the device; receiving a third signaling from the second device, the third signaling indicating a sidelink broadcast key response message.

[0133] Additionally or alternatively, the processor 504 may be configured to or otherwise support: wherein in response to the sidelink broadcast key request message being sent to the second device within a valid time and the device having the same location identification as the first device, the sidelink broadcast key response message includes a broadcast key; wherein the sidelink broadcast key response message includes a group broadcast key, which is also received by one or more additional devices; wherein the sidelink broadcast key response message includes a separate broadcast key for the device; wherein the device includes a first user equipment, the first device includes a second user equipment, and the second device includes a device implementing a sidelink positioning key management function.

[0134] For example, the processor 504 may support wireless communication at the device 502 according to the examples disclosed herein. The processor 504 may be configured to or otherwise support the following: sending a first signaling to a first device, the first signaling indicating a broadcast authorization request message, the broadcast authorization request message including: an identifier of the device and a location identifier for the device; receiving a second signaling from the first device, the second signaling indicating a broadcast authorization response message, the broadcast authorization response message including: a temporary group identifier and a valid time; sending a third signaling to a second device, the third signaling indicating a sidelink broadcast message with a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and an identifier of the device; receiving a fourth signaling from the first device, the fourth signaling indicating a broadcast key; establishing a protocol for an SLPP session with the second device using the broadcast key; receiving a fifth signaling from the second device, the fifth signaling indicating a result of the requested positioning or ranging action protected by the broadcast key.

[0135] Additionally or alternatively, the processor 504 may be configured to or otherwise support the following: where the second signaling and the fourth signaling are the same signaling, and the broadcast key includes a group broadcast key, the group broadcast key is also received by one or more additional devices; where the broadcast key includes a separate broadcast key for the device; where the device includes a first user equipment, the first device includes a device implementing a sidelink positioning key management function, and the second device includes a second UE.

[0136] For example, the processor 504 may support wireless communication at the device 502 according to the examples disclosed herein. The processor 504 may be configured to or otherwise support components for the following: receiving a first signaling from a first device, the first signaling indicating a sidelink broadcast message with a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and an identifier of the first device; sending a second signaling to a second device, the second signaling indicating a sidelink broadcast key request, the sidelink broadcast key request including: a temporary group identifier, an identifier of the first device, an identifier of the device implementing the method, and a location identifier for the device; and receiving a third signaling from the second device, the third signaling indicating a sidelink broadcast key response message.

[0137] Additionally or alternatively, the processor 504 may be configured to or otherwise support: wherein in response to a sidelink broadcast key request message being sent to a second device within a valid time and the device implementing the method having the same location identifier as a first device, the sidelink broadcast key response message includes a broadcast key; wherein the sidelink broadcast key response message includes a group broadcast key that is also received by one or more additional devices; wherein the sidelink broadcast key response message includes a separate broadcast key for the device implementing the method; wherein the method is implemented by a first user equipment, the first device includes a second user equipment, and the second device includes a device implementing a sidelink positioning key management function.

[0138] For example, the processor 504 may support wireless communication at the device 502 in accordance with the examples disclosed herein. The processor 504 may be configured to or otherwise support components for: sending a first signaling to a first device, the first signaling indicating a broadcast authorization request message that includes: an identifier of the device implementing the method and a location identifier for the device; receiving a second signaling from the first device, the second signaling indicating a broadcast authorization response message that includes: a temporary group identifier and a valid time; sending a third signaling to a second device, the third signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and an identifier of the device; receiving a fourth signaling from the first device, the fourth signaling indicating a broadcast key; establishing a protocol for an SLPP session with the second device using the broadcast key; and receiving a fifth signaling from the second device, the fifth signaling indicating a result of the requested positioning or ranging action protected by the broadcast key.

[0139] Additionally or alternatively, the processor 504 may be configured to or otherwise support: wherein the second signaling and the fourth signaling are the same signaling and the broadcast key includes a group broadcast key that is also received by one or more additional devices; wherein the broadcast key includes a separate broadcast key for the device implementing the method; wherein the method is implemented by a first user equipment, the first device includes a device implementing a sidelink positioning key management function, and the second device includes a second UE.

[0140] A processor 504 of a device 502 (such as UE 104) may support wireless communication according to the examples disclosed herein. The processor 504 includes at least one controller coupled to at least one memory and is configured or operable to cause the processor to: send a first signaling to a first device, the first signaling indicating a broadcast authorization request message, the broadcast authorization request message including: an identification of a means for implementing the method and a location identification for the means; receive a second signaling from the first device, the second signaling indicating a broadcast authorization response message, the broadcast authorization response message including: a temporary group identification and a valid time; send a third signaling to a second device, the third signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and an identification of the device; receive a fourth signaling from the first device, the fourth signaling indicating a broadcast key; establish a protocol for an SLPP session with the second device using the broadcast key; and receive a fifth signaling from the second device, the fifth signaling indicating a result of the requested positioning or ranging action protected by the broadcast key.

[0141] A processor 504 of a device 502 (such as UE 104) may support wireless communication according to the examples disclosed herein. The processor 504 includes at least one controller coupled to at least one memory and is configured or operable to cause the processor to: receive a first signaling from a first device, the first signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including: a temporary group identifier and a first device identification; and send a second signaling to a second device, the second signaling indicating a sidelink broadcast key request, the sidelink broadcast key request including: a temporary group identifier, an identification of the first device, an identification of the device, and a location identification for the device.

[0142] The processor 504 may include intelligent hardware devices (e.g., general-purpose processor, DSP, CPU, microcontroller, ASIC, FPGA, programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some implementations, the processor 504 may be configured to operate a memory array using a memory controller. In some other implementations, the memory controller may be integrated into the processor 504. The processor 504 may be configured to execute computer-readable instructions stored in a memory (e.g., memory 506) to cause the device 502 to perform various functions of the present disclosure.

[0143] Memory 506 may include random access memory (RAM) and read-only memory (ROM). Memory 506 may store computer-readable, computer-executable code that includes instructions that, when executed by processor 504, cause device 502 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. In some implementations, the code may not be directly executable by processor 504 but may cause a computer (e.g., when compiled and executed) to perform the functions described herein. In some implementations, memory 506 may include a basic input / output system (BIOS) among other functions, which may control basic hardware or software operations, such as interactions with peripheral components or devices.

[0144] I / O controller 510 may manage input and output signals for device 502. I / O controller 510 may also manage peripheral devices not integrated into device 502. In some implementations, I / O controller 510 may represent a physical connection or port to an external peripheral device. In some implementations, I / O controller 510 may utilize an operating system, such as

[0145] or other known operating systems. In some implementations, I / O controller 510 may be implemented as part of a processor (such as processor 504). In some implementations, a user may interact with device 502 via I / O controller 510 or via a hardware component controlled by I / O controller 510.

[0146] In some implementations, device 502 may include a single antenna 512. However, in some other implementations, device 502 may have more than one antenna 512 (i.e., multiple antennas), including multiple antenna panels or antenna arrays, which may be capable of concurrently transmitting or receiving multiple wireless transmissions. Transceiver 508 may communicate bidirectionally via one or more antennas 512, wired or wireless links, as described herein. For example, transceiver 508 may represent a wireless transceiver and may communicate bidirectionally with another wireless transceiver. Transceiver 508 may also include a modem to modulate packets, to provide the modulated data packets to one or more antennas 512 for transmission, and to demodulate data packets received from one or more antennas 512.

[0147] Figure 6 A flowchart of a method 600 for supporting the protection of broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure is shown. Operations of method 600 may be implemented by a device or components thereof as described herein. For example, operations of method 600 may be performed by network entity 102 or UE 104, as referencedFigures 1 to 5 As described. In some implementations, the device may execute a set of instructions to control the functional elements of the device to perform the functions. Additionally or alternatively, the device may use dedicated hardware to perform aspects of the functions.

[0148] At 605, the method may include: receiving, from a first device, a first signaling that indicates a request message. The operation at 605 may be performed according to the examples described herein. In some implementations, aspects of the operation at 605 may be performed by a device as described with reference to Figure 1 the description.

[0149] At 610, the method may include: sending, to the first device, a second signaling that indicates a response message, the response message including an identifier and a validity time. The operation at 610 may be performed according to the examples described herein. In some implementations, aspects of the operation at 610 may be performed by a device as described with reference to Figure 1 the description.

[0150] At 615, the method may include: receiving, from a second device, a third signaling that indicates a sidelink broadcast key request. The operation at 615 may be performed according to the examples described herein. In some implementations, aspects of the operation at 615 may be performed by a device as described with reference to Figure 1 the description.

[0151] At 620, the method may include: sending, to the second device, a fourth signaling that indicates a sidelink broadcast key response message, the sidelink broadcast key response message including a broadcast key. The operation at 620 may be performed according to the examples described herein. In some implementations, aspects of the operation at 620 may be performed by a device as described with reference to Figure 1 the description.

[0152] Figure 7 FIG. shows a flowchart of a method 700 for supporting protection of broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. The operations of method 700 may be implemented by a device or its components as described herein. For example, the operations of method 700 may be performed by network entity 102 or UE 104, as described with reference to Figures 1 to 5 the description. In some implementations, the device may execute a set of instructions to control the functional elements of the device to perform the described functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0153] At 705, the method may include: assigning an identifier to a first device, wherein the response message further includes a group broadcast key associated with the request message. The operation at 705 may be performed according to the examples described herein. In some implementations, aspects of the operation at 705 may be performed by a device as described with reference toFigure 1 is performed by the described device.

[0154] Figure 8 FIG. 800 is a flow chart illustrating a method for protecting broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. Operations of method 800 may be implemented by a device or components thereof as described herein. For example, operations of method 800 may be performed by network entity 102 or UE 104 as referenced Figures 1 to 5 as described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the functions.

[0155] At 805, the method may include sending a fifth signaling to a third device, the fifth signaling indicating a second separate broadcast key for the third device. The operation of 805 may be performed in accordance with examples as described herein. In some implementations, aspects of the operation of 805 may be performed by a device as referenced Figure 1 as described.

[0156] At 810, the method may include: sending a sixth signaling to a first device, the sixth signaling indicating pairing of a first separate broadcast key with a second device and pairing of the second separate broadcast key with the third device. The operation of 810 may be performed in accordance with examples as described herein. In some implementations, aspects of the operation of 810 may be performed by a device as referenced Figure 1 as described.

[0157] Figure 9 FIG. 900 is a flow chart illustrating a method for protecting broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. Operations of method 900 may be implemented by a device or components thereof as described herein. For example, operations of method 900 may be performed by network entity 102 or UE 104 as referenced Figures 1 to 5 as described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the described functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0158] At 905, the method may include: receiving a first signaling from a first device, the first signaling indicating an authorization request message, the authorization request message including: an identifier of a second device and a location identifier for the second device. The operation of 905 may be performed in accordance with examples as described herein. In some implementations, aspects of the operation of 905 may be performed by a device as referenced Figure 1 as described.

[0159] At 910, the method may include: sending a second signaling to a first device, the second signaling indicating a successful authorization result for the first device. The operation at 910 may be performed according to the examples described herein. In some implementations, aspects of the operation at 910 may be performed by a device as referenced Figure 1 as described.

[0160] At 915, the method may include: receiving a third signaling from a first device, the third signaling indicating a sidelink authorization request, the sidelink authorization request including: an identifier of a second device, an identifier of a third device, and a location identifier for the third device. The operation at 915 may be performed according to the examples described herein. In some implementations, aspects of the operation at 915 may be performed by a device as referenced Figure 1 as described.

[0161] At 920, the method may include: sending a fourth signaling to the first device, the fourth signaling indicating an authorization result for the sidelink authorization request. The operation at 920 may be performed according to the examples described herein. In some implementations, the operation at 920 may be performed by a device as referenced Figure 1 described.

[0162] Figure 10 FIG. 16 shows a flowchart of a method 1000 for supporting the protection of broadcast ranging and positioning messages through a sidelink interface according to aspects of the present disclosure. The operations of method 1000 may be implemented by a device or components thereof as described herein. For example, the operations of method 1000 may be performed by network entity 102 or UE 104, as referenced Figures 1 to 5 as described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the described functions. Additionally or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0163] At 1005, the method may include: checking whether the second device and the third device have the same location identifier based on the location identifier for the second device and the location identifier for the third device. The operation at 1005 may be performed according to the examples described herein. In some implementations, aspects of the operation at 1005 may be performed by a device as referenced Figure 1 as described.

[0164] At 1010, the method may include: in response to the second device and the third device having the same location identifier, sending a fourth signaling to the first device. The operation at 1010 may be performed according to the examples described herein. In some implementations, aspects of the operation at 1010 may be performed by a device as referenced Figure 1 described.

[0165] Figure 11FIG. 1100 is a flow diagram showing a method 1100 that supports protecting broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. Operations of method 1100 may be implemented by a device or components thereof as described herein. For example, operations of method 1100 may be performed by UE 104 as referenced Figures 1 to 5 as described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the described functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0166] At 1105, the method may include: receiving, from a first device, first signaling that indicates a sidelink broadcast message having a requested positioning or ranging operation, the sidelink broadcast message including: an identifier and an identity of the first device. The operation of 1105 may be performed in accordance with examples as described herein. In some implementations, aspects of the operation of 1105 may be performed by a device as referenced Figure 1 as described.

[0167] At 1110, the method may include: sending, to a second device, second signaling that indicates a sidelink broadcast key request. The operation of 1110 may be performed in accordance with examples as described herein. In some implementations, aspects of the operation of 1110 may be performed by a device as referenced Figure 1 as described.

[0168] At 1115, the method may include: receiving, from the second device, third signaling that indicates a sidelink broadcast key response message. The operation of 1115 may be performed in accordance with examples as described herein. In some implementations, aspects of the operation of 1115 may be performed by a device as referenced Figure 1 as described.

[0169] Figure 12 FIG. 1200 is a flow diagram showing a method 1200 that supports protecting broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. Operations of method 1200 may be implemented by a device or components thereof as described herein. For example, operations of method 1200 may be performed by UE 104 as referenced Figures 1 to 5 as described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the described functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0170] At 1205, the method may include: in response to a sidelink broadcast key request message being sent to a second device within a valid time, and the device implementing the method having the same location identifier as a first device, the sidelink broadcast key response message includes a broadcast key. The operation of 1205 may be performed according to the examples described herein. In some implementations, aspects of the operation of 1205 may be performed by a device as referenced Figure 1 as described.

[0171] Figure 13 FIG. shows a flowchart of a method 1300 for supporting the protection of broadcast ranging and positioning messages via a sidelink interface according to aspects of the present disclosure. The operations of method 1300 may be implemented by a device or its components as described herein. For example, the operations of method 1300 may be performed by UE 104, as referenced Figures 1 to 5 as described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the described functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0172] At 1305, the method may include: sending a first signaling indicating a request message to a first device. The operation of 1305 may be performed according to the examples described herein. In some implementations, aspects of the operation of 1305 may be performed by a device referenced Figure 1 as described.

[0173] At 1310, the method may include: receiving a second signaling indicating a response message from the first device, the response message including an identifier and a valid time. The operation of 1310 may be performed according to the examples described herein. In some implementations, aspects of the operation of 1310 may be performed by a device referenced Figure 1 as described.

[0174] At 1315, the method may include: sending a third signaling to a second device, the third signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including: an identifier and an identification of the device. The operation of 1315 may be performed according to the examples described herein. In some implementations, aspects of the operation of 1315 may be performed by a device as referenced Figure 1 described.

[0175] At 1320, the method may include: receiving a fourth signaling from the first device, the fourth signaling indicating a broadcast key. The operation of 1320 may be performed according to the examples described herein. In some implementations, aspects of the operation of 1320 may be performed by a device as referenced Figure 1 described.

[0176] At 1325, the method may include: establishing a protocol for an SLPP session with a second device using a broadcast key. The operation at 1325 may be performed according to the examples described herein. In some implementations, aspects of the operation at 1325 may be performed by a device as described with reference to Figure 1 the device described.

[0177] At 1330, the method may include: receiving, from the second device, a fifth signaling that indicates a result of a requested positioning or ranging action protected by a broadcast key. The operation at 1330 may be performed according to the examples described herein. In some implementations, aspects of the operation at 1330 may be performed by a device as described with reference to Figure 1 the device described.

[0178] Figure 14 FIG. shows a flowchart of a method 1400 for supporting the protection of broadcast ranging and positioning messages via a sidelink interface in accordance with aspects of the present disclosure. The operations of method 1400 may be implemented by a device or components thereof as described herein. For example, the operations of method 1400 may be performed by UE 104, as described with reference to Figures 1 to 5 the device described. In some implementations, the device may execute a set of instructions to control functional elements of the device to perform the described functions. Additionally, or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0179] At 1405, the method may include: the second signaling and the fourth signaling are the same signaling, and the broadcast key includes a group broadcast key that is also received by one or more additional devices. The operation at 1405 may be performed according to the examples described herein. In some implementations, aspects of the operation at 1405 may be performed by a device as described with reference to Figure 1 the device described.

[0180] It should be noted that the methods described herein describe possible implementations, and the operations and steps may be rearranged or otherwise modified, and other implementations are possible. Additionally, aspects from two or more methods may be combined.

[0181] The various illustrative blocks and components associated with the present disclosure may be implemented or performed using a general-purpose processor, DSP, ASIC, CPU, FPGA, or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which are designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but alternatively, the processor may be any processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration).

[0182] The functions described herein can be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions can be stored on or transmitted via a computer-readable medium as one or more instructions or code. Other examples and implementations are within the scope of the present disclosure and the appended claims. For example, due to the nature of software, the functions described herein can be implemented using software executed by a processor, hardware, firmware, hardwiring, or any combination thereof. Features implementing the functions can also be physically located in various positions, including being distributed such that portions of the functions are implemented at different physical locations.

[0183] Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. Non-transitory storage media can be any available media that can be accessed by a general or special purpose computer. By way of example, and not limitation, non-transitory computer-readable media can include RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory, compact disc (CD) ROM or other optical disc storage, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to carry or store desired program code components in the form of instructions or data structures and that can be accessed by a general or special purpose computer, or a general or special purpose processor.

[0184] Any connection can be properly termed a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of computer-readable medium. As used herein, disk and disc (including CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc, where disks generally reproduce data magnetically, while discs utilize lasers to optically reproduce data. Combinations of the above are also included within the scope of computer-readable media.

[0185] As used herein (including in the claims), the "or" used in a list of items (e.g., a list of items that begins with a phrase such as "at least one" or "one or more" or "one or two") indicates an inclusive list, such that a list of at least one of A, B, or C, for example, means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Similarly, a list of one or more of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Additionally, as used herein, the phrase "based on" should not be construed as a reference to a closed set of conditions. For example, an exemplary step described as "based on condition A" can be based on both condition A and condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase "based on" should be interpreted in the same manner as the phrase "at least partially based on". Further, as used herein, including in the claims, a "set" can include one or more elements.

[0186] When referring to a network entity, the terms "send", "receive", or "communicate" can refer to any part of a network entity of the RAN (e.g., a base station, CU, DU, RU) communicating with another device (e.g., directly or via one or more other network entities).

[0187] The description set forth herein in conjunction with the drawings describes exemplary configurations and does not represent all examples that can be implemented or that are within the scope of the claims. The term "exemplary" as used herein means "serving as an example, instance, or illustration" and not "preferred" or "superior to other examples". The detailed description includes specific details for the purpose of providing an understanding of the described techniques. However, the techniques can be practiced without these specific details. In some instances, well-known structures and devices are shown in block diagram form to avoid obscuring the concepts of the described examples.

[0188] The description herein is provided to enable a person skilled in the art to make or use the present disclosure. Various modifications to the present disclosure will be apparent to those skilled in the art, and the general principles defined herein can be applied to other variations without departing from the scope of the present disclosure. Thus, the present disclosure is not limited to the examples and designs described herein, but is to be accorded the widest scope consistent with the principles and novel features described herein.

Claims

1. A device for wireless communication, comprising: a processor; and a memory coupled to the processor, the processor being configured to cause the device to: receive a first signaling from a first device, the first signaling indicating a request message; send a second signaling to the first device, the second signaling indicating a response message, the response message including an identifier and a validity period; receive a third signaling from a second device, the third signaling indicating a sidelink broadcast key request; and send a fourth signaling to the second device, the fourth signaling indicating a sidelink broadcast key response message, the sidelink broadcast key response message including a broadcast key.

2. The device according to claim 1, wherein the processor is further configured to cause the device to: send a fifth signaling to a third device, the fifth signaling indicating an authorization request message, the authorization request message including an identifier of the first device; and receive a sixth signaling from the third device, the sixth signaling indicating a successful authorization result of the first device.

3. The device according to claim 1, wherein the processor is further configured to cause the device to: assign the identifier to the first device.

4. The device according to claim 3, wherein the response message further includes a group broadcast key associated with the request message.

5. The device according to claim 1, wherein the broadcast key includes a group broadcast key, the second signaling includes the group broadcast key, and the processor is further configured to cause the device to: send one or more additional signaling to one or more additional UEs, the one or more additional signaling indicating the group broadcast key.

6. The device according to claim 1, wherein the device implements a key management function, the first device includes a first user equipment, and the second device includes a second user equipment.

7. A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to cause the UE to: send a first signaling to a first device, the first signaling indicating a request message; receive a second signaling from the first device, the second signaling indicating a response message, the response message including an identifier and a validity period; send a third signaling to a second device, the third signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including the identifier and an identifier of the UE; receive a fourth signaling from the first device, the fourth signaling indicating a broadcast key; establish a sidelink positioning process protocol (SLPP) session with the second device using the broadcast key; and receive a fifth signaling from the second device, the fifth signaling indicating a result of the requested positioning or ranging action protected by the broadcast key.

8. The UE according to claim 7, wherein the second signaling and the fourth signaling are the same signaling, and the broadcast key includes a group broadcast key, the group broadcast key being received by one or more additional devices as well.

9. The UE according to claim 7, wherein the broadcast key includes a separate broadcast key for the UE.

10. The UE according to claim 7, wherein the UE includes a first user equipment, the first equipment includes a device that implements the sidelink positioning key management function, and the second equipment includes a second UE.

11. A method, comprising: Receiving a first signaling from a first device, the first signaling indicating a request message; Sending a second signaling to the first device, the second signaling indicating a response message, the response message including an identifier and a validity period; Receiving a third signaling from a second device, the third signaling indicating a sidelink broadcast key request; And Sending a fourth signaling to the second device, the fourth signaling indicating a sidelink broadcast key response message, the sidelink broadcast key response message including a broadcast key.

12. The method according to claim 11, further comprising: Sending a fifth signaling to a third device, the fifth signaling indicating an authorization request message, the authorization request message including an identifier of the first device; And Receiving a sixth signaling from the third device, the sixth signaling indicating a successful authorization result of the first device.

13. The method according to claim 11, further comprising: Assigning the identifier to the first device.

14. The method according to claim 13, Wherein the response message further includes a group broadcast key associated with the request message.

15. The method according to claim 11, wherein the broadcast key includes a group broadcast key, the second signaling includes the group broadcast key, and the method further comprises: Sending one or more additional signaling to one or more additional UEs, the one or more additional signaling indicating the group broadcast key.

16. The method according to claim 11, wherein the method is implemented by a sidelink positioning key management function, the first device includes a first user equipment, and the second device includes a second user equipment.

17. A processor for wireless communication, comprising: At least one controller, the at least one controller being coupled to at least one memory and configured to cause the processor to: Receive a first signaling from a first device, the first signaling indicating a sidelink broadcast message having a requested positioning or ranging action, the sidelink broadcast message including an identifier and an identifier of the first device; Send a second signaling to a second device, the second signaling indicating a sidelink broadcast key request; Receive a third signaling from the second device, the third signaling indicating a sidelink broadcast key response message.

18. The processor according to claim 17, wherein in response to the sidelink broadcast key request message being sent to the second device within a validity period and the device including the processor having the same location identifier as the first device, the sidelink broadcast key response message includes a broadcast key.

19. The processor according to claim 17, wherein the sidelink broadcast key response message includes a group broadcast key, and the group broadcast key is also received by one or more additional devices.

20. The processor according to claim 17, wherein the processor is included in a first user equipment, the first equipment includes a second user equipment, and the second equipment includes a device implementing a sidelink positioning key management function.