Sidelink location security

By generating and distributing group-specific keys in side-link positioning, the security issues of multicast/broadcast communications are resolved, security protection for side-link positioning is achieved, and the security requirements of different positioning scenarios are met.

CN120787477APending Publication Date: 2025-10-14ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380094233.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-17
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

In existing sidelink positioning technologies, the security issues of multicast/broadcast communications have not been effectively addressed, and there are threats such as privacy attacks, data eavesdropping, and malicious UE impersonation. In addition, existing solutions cannot meet the needs of UEs outside of 5G coverage.

Method used

Through message exchange between network devices and terminal devices, group-specific keys are generated and distributed to protect multicast/broadcast communications in side link positioning. The key management functions of LMF and AMF are used to ensure the security of the key generation, distribution and use processes.

Benefits of technology

It improves the security of side-link positioning communications, prevents privacy attacks and data tampering, meets the needs of session-free and session-based positioning, and ensures secure communication in different types of positioning scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120787477A_ABST
    Figure CN120787477A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to sidelink positioning security. And the first terminal device sends the first request message to the first network device or the second terminal device. The first network device then requests an ID related to the group from the second network device. Next, the first network device or the second terminal device sends an acknowledgement message to the first terminal device, the acknowledgement message including a group-specific key for sidelink multicast / broadcast communication in the group of sidelink positioned terminal devices. Thus, an improved solution for security of SL multicast / broadcast communications is provided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Various example embodiments relate to the field of telecommunications, and in particular to devices, methods, apparatuses, and computer-readable storage media for sidelink positioning security. BACKGROUND

[0002] In the field of communications, there is an ongoing evolution in order to provide efficient and reliable solutions for utilizing wireless communication networks. Each new generation has its own technical challenges for handling the different situations and procedures needed for connecting and serving devices connected to wireless networks. In order to meet the demand for wireless data traffic that has increased since the deployment of fourth generation (4G) communication systems, efforts have been made to develop improved fifth generation (5G) or pre-5G communication systems. New communication systems can support various types of service applications for terminal devices.

[0003] Positioning of user equipment (UE), such as cellular phones, can be useful or necessary for a variety of applications including emergency calls, navigation, direction finding, asset tracking, and internet services. The location of a UE can be estimated based on information collected from various systems. Among existing positioning techniques, sidelink (SL) positioning provides a means to determine the geographical location and / or velocity of a user equipment (UE) based on measuring radio signals. Solutions for sidelink positioning still need to be improved. SUMMARY

[0004] Generally, example embodiments of the present disclosure provide solutions for sidelink positioning.

[0005] In a first aspect, a first network device is provided. The first network device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first network device to at least: receive, from a terminal device, a first request message comprising: a first identifier (ID) related to a user equipment (UE) of the terminal device; and send, to the terminal device, a first reply message comprising: a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0006] In a second aspect, a second network device is provided. The second network device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second network device to at least: receive, from a first network device, a request message associated with a first identifier (ID), the request message being to request a second ID related to a group associated with the first ID, wherein the first ID is related to a user equipment (UE) of a terminal device, and the second ID indicates a terminal device group for sidelink positioning; and send, to the first network device, a response message, the response message comprising: the second ID associated with the first ID.

[0007] In a third aspect, a third network device is provided. The third network device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third network device to at least: generate a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning; and send, to a first network device or a second network device, the group-specific key.

[0008] In a fourth aspect, a first terminal device is provided. The first terminal device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first terminal device to at least: send, to a network device or a second terminal device, a request message, the request message comprising: an identifier (ID) related to a user equipment (UE) of the first terminal device; and receive, from the network device or the second terminal device, a response message, the response message comprising: a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0009] In a fifth aspect, a second terminal device is provided. The second terminal device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second terminal device to at least: generate a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning; receive, from a first terminal device in the terminal device group, a request message, the request message comprising: an identifier (ID) related to a user equipment (UE) of the first terminal device; and send, to the first terminal device, a response message, the response message comprising the group-specific key.

[0010] In a sixth aspect, a method is provided. The method comprises: receiving, at a first network device from a terminal device, a request message, the request message comprising: an identifier (ID) related to a user equipment (UE) of the terminal device; and sending, to the terminal device, a response message, the response message comprising: a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0011] In a seventh aspect, a method is provided. The method comprises: receiving, at a second network device, a request message associated with a first identifier (ID) from a first network device, the request message being to request a second ID related to a group associated with the first ID, wherein the first ID is related to a user equipment (UE) of a terminal device and the second ID indicates a terminal device group for sidelink positioning; and sending, to the first network device, a response message including the second ID associated with the first ID.

[0012] In an eighth aspect, a method is provided. The method comprises: generating, at a third network device, a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning; and sending, to the first network device or the second network device, the group-specific key.

[0013] In a ninth aspect, a method is provided. The method comprises: sending, at a first terminal device, a request message to a network device or a second terminal device, the request message including an identifier (ID) related to a user equipment (UE) of the first terminal device; and receiving, from the network device or the second terminal device, a response message including a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0014] In a tenth aspect, a method is provided. The method comprises: generating, at a second terminal device, a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning; receiving, from a first terminal device in the terminal device group, a request message including an identifier related to a user equipment (UE) of the first terminal device; and sending, to the first terminal device, a response message including the group-specific key.

[0015] In an eleventh aspect, an apparatus is provided. The apparatus comprises: means for receiving, at a first network device, a request message from a terminal device, the request message including an identifier (ID) related to a user equipment (UE) of the terminal device; and means for sending, to the terminal device, a response message including a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0016] In a twelfth aspect, an apparatus is provided. The apparatus comprises: means for receiving, at a second network device, a request message associated with a first identifier (ID) from a first network device, the request message being to request a second ID related to a group associated with the first ID, wherein the first ID is related to a user equipment (UE) of a terminal device and the second ID indicates a terminal device group for sidelink positioning; and means for sending, to the first network device, a response message including the second ID associated with the first ID.

[0017] In a thirteenth aspect, there is provided an apparatus comprising: means for generating, at a third network device, a group-specific key for sidelink groupcast / broadcast communication in a group of terminal devices for sidelink positioning; and means for transmitting the group-specific key to a first network device or a second network device.

[0018] In a fourteenth aspect, there is provided an apparatus comprising: means for transmitting, at a first terminal device, a request message to a network device or a second terminal device, the request message comprising: an identifier (ID) related to a user equipment (UE) of the first terminal device; and means for receiving, from the network device or the second terminal device, a reply message, the reply message comprising: a group-specific key for sidelink groupcast / broadcast communication in a group of terminal devices for sidelink positioning.

[0019] In a fifteenth aspect, there is provided an apparatus comprising: means for generating, at a second terminal device, a group-specific key for sidelink groupcast / broadcast communication in a group of terminal devices for sidelink positioning; means for receiving, from a first terminal device in the group of terminal devices, a request message, the request message comprising: an identifier (ID) related to a user equipment (UE) of the first terminal device; and means for transmitting, to the first terminal device, a reply message, the reply message comprising the group-specific key.

[0020] In a sixteenth aspect, there is provided a non-transitory computer-readable medium comprising program instructions for causing an apparatus to perform at least the method according to any of the above sixth to tenth aspects.

[0021] In a seventeenth aspect, there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the above sixth to tenth aspects.

[0022] In a seventeenth aspect, there is provided a first network device. The first network device comprises: receiving circuitry configured to receive, from a terminal device, a first request message, the first request message comprising: a first identifier (ID) related to a user equipment (UE) of the terminal device; and transmitting circuitry configured to transmit, to the terminal device, a first reply message, the reply message comprising: a group-specific key for sidelink groupcast / broadcast communication in a group of terminal devices for sidelink positioning.

[0023] In an eighteenth aspect, a second network device is provided. The second network device comprises: receiving circuitry configured to receive, from a first network device, a request message associated with a first identifier (ID), the request message being to request a second ID related to a group associated with the first ID, wherein the first ID is related to a user equipment (UE) of a terminal device, and the second ID indicates a terminal device group for sidelink positioning; and transmitting circuitry configured to transmit, to the first network device, a reply message including the second ID associated with the first ID.

[0024] In a nineteenth aspect, a third network device is provided. The third network device comprises: generating circuitry configured to generate a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning; and transmitting circuitry configured to transmit, to the first network device or the second network device, the group-specific key.

[0025] In a twentieth aspect, a first terminal device is provided. The first terminal device comprises: transmitting circuitry configured to transmit, to a network device or a second terminal device, a request message including an identifier (ID) related to a user equipment (UE) of the first terminal device; and receiving circuitry configured to receive, from the network device or the second terminal device, a reply message including a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0026] In a twenty-first aspect, a second terminal device is provided. The second terminal device comprises: generating circuitry configured to generate a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning; receiving circuitry configured to receive, from a first terminal device in the terminal device group, a request message including an identifier (ID) related to a user equipment (UE) of the first terminal device; and transmitting circuitry configured to transmit, to the first terminal device, a reply message including the group-specific key.

[0027] It will be understood that the Summary section is not intended to identify key or essential features of embodiments of the disclosure, nor is it intended to be used in limiting the scope of the disclosure. Other features, aspects, and advantages of the disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0028] Some example embodiments will now be described, by way of example, with reference to the accompanying drawings, in which:

[0029] Figure 1 An example communication network in which embodiments of the disclosure can be implemented is illustrated;

[0030] Figure 2 FIG. 1 illustrates an example diagram illustrating a procedure for protecting sidelink groupcast / broadcast communication according to some embodiments of the present disclosure;

[0031] Figure 3 FIG. 1 illustrates an example diagram illustrating a procedure for protecting sidelink groupcast / broadcast communication according to some embodiments of the present disclosure;

[0032] Figure 4 FIG. 1 illustrates an example diagram illustrating a procedure for protecting sidelink groupcast / broadcast communication according to some embodiments of the present disclosure;

[0033] Figure 5 FIG. 1 illustrates an example diagram illustrating a procedure for protecting sidelink groupcast / broadcast communication according to some embodiments of the present disclosure;

[0034] Figure 6 FIG. 1 illustrates a flowchart of a method implemented at a network device according to some embodiments of the present disclosure;

[0035] Figure 7 FIG. 1 illustrates a flowchart of another method implemented at a network device according to some embodiments of the present disclosure;

[0036] Figure 8 FIG. 1 illustrates a flowchart of another method implemented at a network device according to some embodiments of the present disclosure;

[0037] Figure 9 FIG. 1 illustrates a flowchart of a method implemented at a terminal device according to some other embodiments of the present disclosure;

[0038] Figure 10 FIG. 1 illustrates a flowchart of another method implemented at a terminal device according to some other embodiments of the present disclosure;

[0039] Figure 11 FIG. 1 illustrates a simplified block diagram of a device suitable for implementing embodiments of the present disclosure; and

[0040] Figure 12 FIG. 1 illustrates a block diagram of an example computer-readable medium according to some embodiments of the present disclosure.

[0041] Throughout the drawings, identical or similar reference numerals can indicate identical or similar elements. DETAILED DESCRIPTION

[0042] The principles of the present disclosure will now be described with reference to some example embodiments. It will be appreciated that these embodiments are described for purposes of illustration only and to aid in the understanding of and implementation of the present disclosure, and are not intended to be limiting of the scope of the present disclosure. The present disclosure described herein can be implemented in various ways, other than those described below.

[0043] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0044] Reference throughout this disclosure to "one embodiment", "an embodiment", "example embodiment", etc., indicates that a described embodiment can include a particular feature, structure, or characteristic, but every embodiment can not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one of ordinary skill in the art to effect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described or clearly illustrated.

[0045] It should be understood that although the terms "first" and "second" etc. can be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.

[0046] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises", "comprising", "includes" and / or "including", when used herein, specify the presence of stated features, elements and / or components etc. but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof. As used herein, "at least one of " and "one or more of " and the like means at least any one of the elements, or, any combination of at least two or more of the elements.

[0047] As used in this application, the term“circuitry” can refer to one or more or all of the following:

[0048] (a) hardware-only circuitry implementations (such as implementations in only analog and / or digital circuitry) and

[0049] (b) combinations of hardware circuits and software, such as (as applicable):

[0050] (i) combinations of analog and / or digital hardware circuit(s) with software / firmware and

[0051] (ii) portions of hardware processor(s) with software (including digital signal processors), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions and

[0052] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but need not necessarily have such software present.

[0053] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation that has a hardware circuit or processor (or multiple processors) and accompanying software or firmware that work together to cause an apparatus to perform various functions described herein. For example, and if applicable to particular claim elements, the term circuitry also covers a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in a server, cellular network device, or other computing or network device.

[0054] As used herein, the term“communication network” refers to a network that follows any suitable communication standard, such as Long-Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code-Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band-Internet of Things (NB-IoT), etc. Further, communication between a terminal device and a network device in a communication network can be performed according to any suitable generation communication protocol, including but not limited to first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G), future sixth generation (6G) communication protocols, and / or any other protocol that is presently known or that later becomes known. Embodiments of the present disclosure can be applied to various communication systems. Because of the rapid development in this field, future types of communication technologies and systems will of course appear, which utilize them to implement the present disclosure. The scope of the present disclosure should not be understood as limited only to the above-described systems.

[0055] As used herein, the term “network device” or “network element” refers to a node in a communication network via which terminal devices access the network and receive services therefrom. The communication network can be a core network (CN). A network device or element in the CN (also referred to herein as a core network element) can refer to a policy control function (PCF), an access management function (AMF), a session management function (SMF), a user plane function (UPF), a unified data management (UDM), a unified data repository (UDR), an authentication server function (AUSF), a ProSe key management function (PKMF), a direct discovery name management function (DDNMF), a network exposure function (NEF), and the like.

[0056] The communication network can be a radio access network (RAN). A network device or element in the RAN can refer to a base station (BS) or an access point (AP), such as a NodeB (NodeB or NB), an evolved NodeB (eNodeB or eNB), a NR Next Generation NodeB (also referred to as gNB), a remote radio unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, a low power node (such as femto, pico, and the like), depending on the terminology used and technology applied. A radio access network (RAN) split architecture includes a gNB-CU (centralized unit hosting radio resource control (RRC), service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP) layers) controlling multiple gNB-DUs (distributed units hosting radio link control (RLC), medium access control (MAC), and physical (PHY) layers).

[0057] The term "terminal device" refers to any terminal device that can be capable of wireless communication. By way of example, and without limitation, a terminal device can also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). A terminal device can include, but is not limited to, a mobile phone, a cellular phone, a smart phone, a voice over IP (VoIP) phone, a wireless local loop phone, a tablet, a wearable terminal device, a personal digital assistant (PDA), a portable computer, a desktop computer, an image capture terminal device such as a digital camera, a game terminal device, a music storage and playback appliance, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop-embedded equipment (LEE), a laptop-mounted equipment (LME), a USB dongle, a smart device, a wireless customer-premises equipment (CPE), an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical appliance or application, industrial equipment and applications such as robots and / or other wireless devices operating in an industrial and / or an automated processing chain environments, consumer electronics, devices operating on a business and / or industrial wireless networks, etc. In the following description, the terms "terminal device", "communication device", "terminal", "user equipment" and "UE" can be used interchangeably.

[0058] Although in various example embodiments, the functionality described herein can be performed in a fixed and / or wireless network node, in other embodiments, the functionality can be implemented in a user equipment device such as a cellular phone or a tablet or laptop or desktop computer or a mobile IoT device or a fixed IoT device. For example, the user equipment device can be equipped with corresponding capabilities as described in connection with the fixed and / or wireless network node(s). The user equipment device can be a user equipment and / or a control device, such as a chipset or processor, configured to control the user equipment when installed in the user equipment. Examples of the functionality include a bootstrap server function and / or a home subscriber server, which can be implemented in the user equipment device by providing software to the user equipment device, which is configured to cause the user equipment device to perform from the perspective of these functions / nodes.

[0059] Some embodiments of the present disclosure consider the case of SL positioning, where a target UE positions itself by measuring SL positioning reference signals (PRS) transmitted by other UEs, referred to as anchor UEs. Coordination of SL PRS resources is done at the network side, at a location management function entity (LMF), or by another UE, referred to as a server UE. The LMF or the server UE is also the entity that manages the security aspects of positioning, and thus the encryption key (CK).

[0060] For the above SL positioning, certain positioning signaling such as SL positioning capabilities and SL positioning assistance data need to be transmitted between terminal device(s) or / and network device(s). Groupcast and broadcast communication for sidelink positioning is necessary for efficient data dissemination. For example, broadcast of configuration / assistance data can eliminate the need for multiple unicast sessions, each preceded by complex signaling and thus involving non-negligible latency and overhead.

[0061] To enable groupcast / broadcast, two candidate layers such as PDCP and PC5-U are provided for groupcast / broadcast transmission. However, neither of the two candidate layers supports secure communication to protect sensitive information such as node locations (e.g., anchor locations) and / or their precursors (e.g., time of arrival measurements). Thus, security issues of specific information of SL positioning capabilities and assistance data during groupcast / broadcast communication need to be solved.

[0062] Furthermore, there are the following limitations for security of groupcast and broadcast communication for sidelink positioning. For example, the registration procedure needs to be changed and new fields including dedicated for SL positioning protocol (SLPP) groupcast / broadcast are proposed. Only in-coverage scenarios are applicable. New types of keys for SL positioning via PC5 communication overlap with existing PC5 protection solutions. The location of the UEs in communication is not verified before the keys are provided. The roles of “target UE” and “reference UE” seem to be exchanged from a groupcast / broadcast perspective. A malicious server UE can be an additional threat. Limitations for UEs outside 5G coverage are a challenge. The possibility for a UE to only want to listen to some broadcasted session-less and lightweight requirements cannot be fulfilled. An automated moving vehicle can only want to listen to some broadcast / groupcast that can provide useful information about routes or locations. The transmitting UE does not have any control over which UEs can receive the message. The location of the UEs in communication is not verified before the keys are provided.

[0063] Furthermore, if the group information is not securely transformed by the application layer, an intruder can link this group information back to the UE group membership, revealing which UEs have been associated with a particular group and thus causing a privacy attack. In case of a failure of protection for SL groupcast / broadcast communication, there are the following threats. A passive attacker can eavesdrop on the data packets exchanged between UEs. An active attacker can intercept, modify, or repeat the data packets exchanged between UEs. A UE being a group member can be impersonated by an attacker. As can be seen, the security of SL groupcast / broadcast communication needs to be improved. Currently, there is no known solution to the above problems for secure groupcast / broadcast for sidelink positioning in a way that complies with 3GPP regulations.

[0064] In view of this, embodiments of the present disclosure provide a solution for protection of groupcast / broadcast in sidelink positioning. In this solution, a terminal device sends a request message to a network device or another terminal device. The request message comprises an identifier (ID) related to the terminal device’s UE. In response to receiving the request message, the network device or another terminal device can send a response message to the terminal device. The response message comprises a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning. The group-specific key can be used for sidelink groupcast / broadcast communication in the terminal device group for sidelink positioning.

[0065] In this way, an improved solution for security of SL groupcast / broadcast communication is provided. By means of the encryption key management function of the LMF and the key distribution function of the AMF, some embodiments of the present disclosure relate to how the keys are generated, how the keys are assigned to individual UE groups, and how the keys are used in different types of positioning, etc.

[0066] The principles and implementations of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0067] Example of a communication environment

[0068] Figure 1 A schematic overview of an example communication environment 100 in which embodiments of the present disclosure can be implemented is illustrated. As shown in Figure 1 the communication environment 100 can involve a plurality of devices, such as devices 110 and 120, and a core network (CN) 130.

[0069] In this example, the devices 110 and 120 are illustrated as mobile telephones. It should be noted that any of the devices 110 and 120 can be any other suitable type of terminal device or network device. Furthermore, it will be appreciated that the number of devices is merely for illustration purposes and does not imply any limitation. The communication environment 100 can comprise any suitable number or type of devices suitable for implementing embodiments of the present disclosure.

[0070] As shown in Figure 1 the CN 130 can comprise a plurality of CN elements, e.g. an AMF 131, an LMF 132, and a PKMF 133. It will be appreciated that the CN elements in the CN 130 are merely for illustration purposes and do not imply any limitation. The communication environment 100 can comprise more or less CN elements suitable for implementing embodiments of the present disclosure.

[0071] In some embodiments, the devices 101 and 102 can communicate with each other, with the core network 130, via a radio access network (RAN). The RAN can comprise any suitable network equipment (not shown) and can take any suitable RAN technology. It will be understood that the communication environment 100 can comprise any suitable number or type of RAN and CN suitable for implementing embodiments of the disclosure.

[0072] Communications in the communication environment 100 can be implemented according to any suitable communication protocol(s), including but not limited to first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), fifth generation (5G) cellular communication protocols or future sixth generation (6G) wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol that is presently known or that may be developed in the future. Moreover, communications can utilize any suitable wireless communication techniques, including but not limited to code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplexing (FDD), time division duplexing (TDD), multiple-input multiple-output (MIMO), orthogonal frequency division multiplexing (OFDM), discrete Fourier transform spread OFDM (DFT-s-OFDM), and / or any other techniques that are presently known or that may be developed in the future.

[0073] Reference is now made to Figure 2 which shows a procedure 200 for protecting sidelink groupcast / broadcast communications, in accordance with various embodiments of the present disclosure. For discussion purposes, the procedure 200 will be described with reference to the Figure 1 communication environment 100. The procedure 200 can involve the terminal devices 110 and 120, and the network devices 131, 132 and 133, as illustrated in Figure 1 . It will be understood that any of the graphical elements, reference numerals and descriptive text in these figures are for illustration purposes only and do not imply any limitation.

[0074] In the procedure 200, the terminal device 110 sends (201) a request message 202 to the network device 131. The request message comprises an identifier (ID) associated with the UE of the terminal device 110. In an example, the ID associated with the UE of the terminal device 110 can be a “session ID” or a “positioning procedure ID” that the UE can use to request a particular encryption key. It will be understood that if a UE participates in multiple sessions, it can have many “session IDs”.

[0075] At the network side, after receiving (203) the request message 202, the network device 131 sends (204) another request message 205 to the network device 132. The request message 205 is associated with the UE-related ID and is used to request the group-related ID. For example, the UE-related ID can be processed and forwarded by the request message 205. The group-related ID is associated with the UE-related ID and indicates the group of terminal devices used for sidelink positioning.

[0076] Thus, the network device 132 receives (206) the request message 205 and sends (207) an answer message 208 to the network device 131. The answer message 208 comprises the group-related ID. Then, the network device 131 can obtain the group-related ID from the answer message 208 after receiving (209) the answer message 208 and sends (210) another answer message 211 to the terminal device 110. The answer message 211 can contain the group-specific key 213 for the sidelink groupcast / broadcast communication in the group of terminal devices used for sidelink positioning and is received (212) by the terminal device 110.

[0077] In an example, the group-specific key 213 can be generated (214) by the network device 132 and sent from the network device 132 to the network device 131. The network device 131 can receive the group-specific key from the network device 132 before receiving the request message 202 from the terminal device 110. In another example, the group-specific key can be generated (215) by the network device 133 or other functional blocks in the CN 130 and sent from the network device 133 to the network device 131. The network device 131 can receive the group-specific key 213 from the network device 133 before receiving the request message 202 from the terminal device 110. In yet another example, the group-specific key 213 can be generated (215) by the network device 133 or other functional blocks in the CN 130 and sent from the network device 133 to the network device 132. The network device 131 can receive the group-specific key 213 from the network device 132 before receiving the request message 202 from the terminal device 110.

[0078] In some embodiments, the network device 131 can receive, from the network device 132, mapping information 216 between the group-related ID and the group-specific key before receiving the request message 202 from the terminal device 110, and store 217 the mapping information 216. In an example, the mapping information 216 can be generated in the following way. For example, the network device 132 can assign a group-specific key with a group-related ID before receiving the request message 205 from the network device 131. Additionally or alternatively, the network device 131 can assign the ID associated with the UE to the group-related ID based on the response message 208 received from the network device 132. Thus, the mapping information between the ID associated with the UE and the group-related ID can be stored by the network device 131. For example, in this way, the network device 131 can determine the group-specific key based on the received response message 208 and the group-related ID in the mapping information.

[0079] In some embodiments, the group-specific key is used for session-based sidelink positioning. Session-based sidelink positioning refers to positioning involving bidirectional communication between a target UE and at least one anchor UE, where such communication involves exchange of confirmed control signals.

[0080] Additionally or alternatively, the response message 208 can comprise a non-specific key for sidelink communication of the terminal device 110 for sidelink positioning. In an example, the non-specific key can be generated by the network device 133 or other functional blocks in the CN 130, and transmitted from the network device 133 to the network device 132. The network device 132 can transmit the non-specific key to the network device 131. The terminal device 110 can receive the non-specific key from the network device 131 via the same or similar request and repetition messages as the specific key described above. In another example, the non-specific key can be generated by the network device 132, and transmitted from the network device 132 to the network device 131. The terminal device 110 can receive the non-specific key from the network device 131 via the same or similar request and repetition messages as the specific key described above.

[0081] In an example, the non-specific key is used for session-less sidelink positioning. Session-less sidelink positioning refers to a positioning procedure that does not involve any exchange of determined control signals between the target UE and the anchor UE(s).

[0082] Reference is now made to Figure 3 which shows a procedure 300 for securing sidelink groupcast / broadcast communication according to various embodiments of the present disclosure. For the purpose of discussion, reference will be made to Figure 1 The procedure 300 will be described. The procedure 300 can involve as in Figure 1The terminal devices 110 and 120 shown in the figures. It will be understood that any graphical elements, reference signs, and descriptive text in these figures are for illustration purposes only and do not imply any limitations.

[0083] As shown in Figure 3 The terminal device 110 sends (301) a request message 302 to the terminal device 120. The request message 302 comprises an ID related to the UE of the terminal device 110. Thus, the terminal device 120 receives (303) the request message from the terminal device 110 in the terminal device group. And the terminal device 120 sends (304) an answer message 305 to the terminal device 110. The group specific key is included in the answer message 305. Thus, the terminal device 110 receives (306) the answer message 305 and obtains the group specific key for the sidelink groupcast / broadcast communication in the terminal device group used for sidelink positioning. In an example, the terminal device 120 can generate (307) the group specific key. In another example, the terminal device 120 can obtain the group specific key generated by other functional blocks.

[0084] Additionally or alternatively, the answer message can comprise a non-specific key for sidelink communication of the first terminal device for sidelink positioning. In an example, the terminal device 120 can generate (308) the non-specific key. In another example, the terminal device 120 can obtain the non-specific key generated by other functional blocks.

[0085] For the purpose of a more clear understanding, some other embodiments of the present disclosure herein will now be described in detail below with reference to Figure 4 and Figure 5 of the present disclosure herein.

[0086] More specifically, some embodiments of the present disclosure propose that the LMF keeps control of how encryption keys are associated with UEs, but it is the AMF that distributes the keys to the actual UEs while using a secure UE-AMF Non-Access Stratum (NAS) context. Different encryption keys are provided for session-based positioning and non-session-based positioning. Session-based positioning is understood as a closed group positioning by UEs interacting with each other within an established positioning session (e.g., as part of a multi-RTT method), which is characterized, for example, by a minimum predefined positioning accuracy. A positioning session involves a determined exchange of control messages between the involved entities (target UE and anchor UEs) and is typically a case where the positioning application has to meet certain Quality of Service (QoS) requirements. A session-specific key is needed to protect sensitive session information such as absolute anchor location information (needed for absolute positioning).

[0087] Session-less positioning is understood as a positioning that removes the context / session establishment, where any target UE can freely benefit from existing PRS transmissions in an opportunistic way, i.e. without confirmation of the measurements and without providing any report to other entities. The main application is relative ranging for cost-free methods, such as Observed Time Difference of Arrival (OTDOA). Here, only a Public Land Mobile Network (PLMN) specific encryption key is needed to ensure broad mutual compatibility of all UEs belonging to the same PLMN

[0088] Figure 4 An example of a procedure 400 for securing sidelink groupcast / broadcast communications is illustrated in accordance with some example embodiments of the present disclosure. An LMF-centric example is shown in Figure 4 It will be appreciated that the procedure 400 can be considered a more specific example of the procedure 200 in Figure 2 In this regard, the SL positioning UE in Figure 4 may be considered the terminal device 110 in Figure 1 may be considered the network device 131 in Figure 4 may be considered the network device 132 in Figure 1 may be considered the network device 133 in Figure 4 may be considered the network device 133 in Figure 1 may be considered the network device 132 in Figure 4 may be considered the network device 131 in Figure 1 may be considered the network device 133 in

[0089] In the procedure 400, at 405, the LMF 403 obtains non-specific encryption keys (CKs) from the PKMF. These keys allow for the encryption of UE communications such that all UEs within the same PLMN can decrypt them. Preferably, such keys are then used for session-less positioning, where no prior context or only minimal prior context is established between the target UE and the anchor UEs.

[0090] At 406, the LMF 403 can also generate group-specific CKs for the exchange of secure information within a predefined group of UEs. These group-specific keys are then used for session-based positioning. UEs that are not part of a session will not be able to decrypt the exchanged information, e.g. absolute anchor coordinates. In this example, at 407, the LMF 403 assigns a group-specific CK to each session or group of otherwise associated UEs. Each group is characterized by a “GroupID”. At 408, the mapping of “CK” and “GroupID” (“CK+GroupID”) is then communicated to the AMF by using the “Nlmf_BroadcastCipherKeyData” notification message.

[0091] At 409, the AMF 402 then stores this "Ck + GroupID" information. From a NAS registration request (identified by "ueID") from the UE, the AMF retrieves the group association for this particular UE from the LMF on demand (410). This is done by the "Request GroupID" and "Answer GroupID" messages at 411 and 422. The AMF 402 can maintain internally the mapping of different UEs to different groups to avoid repeated requests to the LMF 403 (e.g., during NAS registration update). At 413, the AMF 402 assigns "ueID" to "GroupID".

[0092] At 414, the AMF 402 then provides the appropriate CK to the UE. By default, a non-specific CK is assigned. If permitted by the LMF 403, a group-specific key is also conveyed to indicate / enable membership of the UE in the (LMF-controlled) positioning session.

[0093] Figure 5 FIGURE 13 illustrates an example of a procedure 500 for securing sidelink groupcast / broadcast communications, according to some example embodiments of the present disclosure. An AMF-centric example is shown in Figure 5 For brevity, only the differences between the procedure 500 and the procedure 400 are described herein, and identical or similar details will not be repeated and can be referred to each other.

[0094] As shown in Figure 5 The main difference is that the AMF stores and manages the CK. For example, the AMF 402 can receive a non-specific encryption key and / or a group-specific encryption key from the PKMF 404 (415). The PKMF 404 can generate at least one of: a non-specific encryption key and a group-specific encryption key (416). It should be understood that at least one of the non-specific encryption key and the group-specific encryption key can be generated by other functional blocks in the CN 130. And the AMF 402 can obtain the non-specific encryption key and / or the group-specific encryption key from other functional blocks in the CN 130. The LMF 403 retains control over the actual assignment of CKs to individual UEs.

[0095] By any of the above procedures, an improved solution to the security of SL groupcast / broadcast communications for sidelink positioning is provided, addressing at least one of the above-mentioned deficiencies.

[0096] Figure 6 FIGURE 13 illustrates a flowchart of an example method 600 implemented at a network device, according to some embodiments of the present disclosure. For discussion purposes, the method 600 will be described with reference to the Figure 1 or the first network device is described from the perspective of the network device 131.

[0097] At block 610, the network device 131 receives, from the terminal device, a first request message including a first identifier (ID) related to a user equipment (UE) of the terminal device. At block 620, the network device 131 sends, to the terminal device, a first response message including a group-specific key for a sidelink groupcast / broadcast of the terminal device group for sidelink positioning.

[0098] In some embodiments, the network device 131 sends, to a second network device, a second request message associated with the first ID, the request message to request a second ID related to a group associated with the first ID, wherein the second ID indicates the terminal device group. The network device 131 receives, from the second network device, a second response message including the second ID associated with the first ID.

[0099] In some embodiments, the network device 131 receives, from the second network device, mapping information between the second ID and the group-specific key before receiving the first request message from the terminal device. The network device 131 stores the mapping information between the second ID and the group-specific key.

[0100] In some embodiments, the network device 131 determines the group-specific key based on the second ID in the received second response message and the mapping information.

[0101] In some embodiments, based on the received second response message from the second network device, the network device 131 stores mapping information between the first ID and the second ID.

[0102] In some embodiments, the network device 131 receives the group-specific key from the second network device or a third network device before receiving the first request message from the terminal device.

[0103] In some embodiments, the second response message further includes a non-specific key for a sidelink communication of the first terminal device for sidelink positioning.

[0104] In some embodiments, the network device 131 receives the non-specific key from the second network device or the third network device.

[0105] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0106] Figure 7 A flowchart illustrating an example method 700 implemented at a network device, in accordance with some embodiments of the present disclosure, is shown. For purposes of discussion, the method 700 will be described with reference to the network device 132. Figure 1 The method 700 will be described from the perspective of the network device 132 or the second network device.

[0107] At block 701, the network device receives, from a first network device, a request message associated with a first identifier (ID), the request message to request a second ID related to a group associated with the first ID, wherein the first ID is related to a user equipment (UE) of a terminal device, and the second ID indicates a terminal device group for sidelink positioning. At block 720, the network device 132 sends, to the first network device, a response message including the second ID associated with the first ID.

[0108] In some embodiments, the network device 132 allocates a group-specific key with the second ID before receiving the request message from the first network device, wherein the group-specific key is used for sidelink groupcast / broadcast communication in the terminal device group for sidelink positioning. The network device 132 sends, to the first network device, mapping information between the second ID and the group-specific key.

[0109] In some embodiments, the network device 132 generates the group-specific key before allocating the group-specific key with the second ID.

[0110] In some embodiments, the network device 132 receives the group-specific key from a third network device before allocating the group-specific key with the second ID.

[0111] In some embodiments, the network device 132 receives, from a third network device, a non-specific key for sidelink communication of the terminal device for sidelink positioning.

[0112] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0113] Figure 8 A flowchart illustrating an example method 800 implemented at a network device, in accordance with some embodiments of the present disclosure, is shown. For purposes of discussion, the method 800 will be described with reference to the network device 133. Figure 1 The method 800 will be described from the perspective of the network device 133, or a third network device.

[0114] At block 810, the network device 133 generates a group-specific key for sidelink groupcast / broadcast communication in the terminal device group for sidelink positioning. At block 820, the network device 133 sends, to the first network device or the second network device, the group-specific key.

[0115] In some embodiments, the network device 133 generates a non-specific key for sidelink communication of the terminal device for sidelink positioning. The network device 133 sends, to the first network device or the second network device, the non-specific key.

[0116] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0117] Figure 9 A flowchart illustrating an example method 900 implemented at a terminal device, according to some embodiments of the disclosure, is shown. For discussion purposes, the method 900 will be described from the perspective of the terminal device 110. Figure 1 or the first terminal device from the perspective of the terminal device 110.

[0118] At block 910, the terminal device 110 sends, to a network device or a second terminal device, a request message including an identifier (ID) related to a user equipment (UE) of the first terminal device. At block 920, the terminal device 110 receives, from the network device or the second terminal device, a response message including a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning.

[0119] In some embodiments, the response message further includes a non-specific key for sidelink communication of the first terminal device for sidelink positioning.

[0120] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0121] Figure 10 A flowchart illustrating an example method 1000 implemented at a terminal device, according to some embodiments of the disclosure, is shown. For discussion purposes, the method 1000 will be described from the perspective of the terminal device 120. Figure 1 or the second terminal device from the perspective of the terminal device 120.

[0122] At block 1010, the terminal device 120 generates a group-specific key for sidelink groupcast / broadcast communication in a terminal device group for sidelink positioning. At block 1020, the terminal device 120 receives, from a first terminal device in the terminal device group, a request message including an identifier (ID) related to a user equipment (UE) of the first terminal device. At block 1030, the terminal device 120 sends, to the first terminal device, a response message including the group-specific key.

[0123] In some embodiments, the response message further includes a non-specific key for sidelink communication of the first terminal device for sidelink positioning.

[0124] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0125] In some embodiments, an apparatus, e.g., a network device 131, capable of performing the method 600 can comprise means for performing respective steps of the method 600. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or a software module.

[0126] In some embodiments, the apparatus comprises means for receiving, from a terminal device, a first request message comprising a first identifier (ID) related to a user equipment (UE) of the terminal device, and means for transmitting, to the terminal device, a first answer message comprising a group-specific key for a sidelink groupcast / broadcast communication in a terminal device group for a sidelink positioning.

[0127] In some embodiments, the apparatus further comprises means for transmitting, to a second network device, a second request message associated with the first ID, the request message being to request a second ID related to a group associated with the first ID, wherein the second ID indicates the terminal device group, and means for receiving, from the second network device, a second answer message comprising the second ID associated with the first ID.

[0128] In some embodiments, the apparatus further comprises means for receiving, from the second network device, mapping information between the second ID and the group-specific key before receiving the first request message from the terminal device, and means for storing the mapping information between the second ID and the group-specific key.

[0129] In some embodiments, the apparatus further comprises means for determining the group-specific key based on the second ID in the received answer message and the mapping information.

[0130] In some embodiments, the apparatus further comprises means for storing mapping information between the first ID and the second ID based on the received second answer message from the second network device.

[0131] In some embodiments, the apparatus further comprises means for receiving the group-specific key from the second network device or a third network device before receiving the first request message from the terminal device.

[0132] In some embodiments, the second answer message further comprises a non-specific key for a sidelink communication of the first terminal device for the sidelink positioning.

[0133] In some embodiments, the apparatus further comprises means for receiving the non-specific key from the second network device or the third network device.

[0134] In some embodiments, the group-specific key is used for a session-based sidelink positioning. In some embodiments, the non-specific key is used for a non-session-based sidelink positioning.

[0135] In some embodiments, the apparatus also includes means for performing other steps in some embodiments of the method 600. In some embodiments, the means includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform.

[0136] In some embodiments, an apparatus (e.g., network device 132) capable of performing the method 700 can include means for performing the corresponding steps of the method 700. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or software modules.

[0137] In some embodiments, the apparatus includes means for receiving, from a first network device, a request message associated with a first identifier (ID), the request message being to request a second ID related to a group associated with the first ID, wherein the first ID is related to a user equipment (UE) of a terminal device, and the second ID indicates a terminal device group for sidelink positioning. And means for sending, to the first network device, a response message including the second ID associated with the first ID.

[0138] In some embodiments, the apparatus further includes means for assigning, before receiving the request message from the first network device, a group-specific key with the second ID, wherein the group-specific key is used for sidelink groupcast / broadcast communication in the terminal device group for sidelink positioning; and means for sending, to the first network device, mapping information between the second ID and the group-specific key.

[0139] In some embodiments, the apparatus further includes means for generating, before assigning the group-specific key with the second ID, the group-specific key.

[0140] In some embodiments, the apparatus further includes means for receiving, from a third network device, the group-specific key before assigning the group-specific key with the second ID.

[0141] In some embodiments, the apparatus further includes means for receiving, from a third network device, a non-specific key for sidelink communication of a terminal device for sidelink positioning.

[0142] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0143] In some embodiments, the apparatus also includes means for performing other steps in some embodiments of the method 700. In some embodiments, the means includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform.

[0144] In some embodiments, an apparatus (e.g., network equipment 133) capable of performing the method 800 can include means for performing the corresponding steps of the method 800. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or software modules.

[0145] In some embodiments, the apparatus includes means for generating a group-specific key for sidelink groupcast / broadcast communications in a group of terminal devices for sidelink positioning; and means for transmitting the group-specific key to a first network equipment or a second network equipment.

[0146] In some embodiments, the apparatus also includes means for generating a non-specific key for sidelink communications of a terminal device for sidelink positioning; and means for transmitting the non-specific key to a first network equipment or a second network equipment.

[0147] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0148] In some embodiments, the apparatus also includes means for performing other steps in some embodiments of the method 800. In some embodiments, the means includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform.

[0149] In some embodiments, an apparatus (e.g., terminal device 110) capable of performing the method 900 can include means for performing the corresponding steps of the method 900. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or software modules.

[0150] In some embodiments, the apparatus includes means for transmitting a request message to a network equipment or a second terminal device, the request message comprising: an identifier (ID) related to a user equipment (UE) of the first terminal device; and means for receiving a response message from the network equipment or the second terminal device, the response message comprising: a group-specific key for sidelink groupcast / broadcast communications in a group of terminal devices for sidelink positioning.

[0151] In some embodiments, the reply message further comprises a non-specific key for sidelink communication of the first terminal device for sidelink positioning.

[0152] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0153] In some embodiments, the apparatus further comprises means for performing other steps of some embodiments of the method 900. In some embodiments, the means comprises at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform.

[0154] In some embodiments, an apparatus (e.g., terminal device 120) capable of performing the method 1000 can include means for performing the corresponding steps of the method 1000. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or software modules.

[0155] In some embodiments, the apparatus comprises generating a group-specific key for sidelink groupcast / broadcast communication in a group of terminal devices for sidelink positioning; means for receiving a request message from a first terminal device in the group of terminal devices, the request message comprising an identifier (ID) related to a user equipment (UE) of the first terminal device; and means for sending a reply message to the first terminal device, the reply message comprising the group-specific key.

[0156] In some embodiments, the reply message further comprises a non-specific key for sidelink communication of the first terminal device for sidelink positioning.

[0157] In some embodiments, the group-specific key is used for session-based sidelink positioning. In some embodiments, the non-specific key is used for session-less sidelink positioning.

[0158] In some embodiments, the apparatus further comprises means for performing other steps of some embodiments of the method 1000. In some embodiments, the means comprises at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform.

[0159] Figure 11 is a simplified block diagram of a device 1110 suitable for implementing embodiments of the present disclosure. The device 1100 can be provided to implement a communication device, for example in Figure 1The terminal device 110, the terminal device 120, the network device 131, the network device 132, or the network device 133 shown in FIG. 1. As shown, the device 1100 includes one or more processors 1110, one or more memories 1140 coupled to the processors 1110, and one or more transmitters and / or receivers (TX / RX) 1140 coupled to the processors 1110.

[0160] The TX / RX 1140 is for bidirectional communication. The TX / RX 1140 has at least one antenna to facilitate communication. The communication interface can represent any interface necessary to communicate with other network elements.

[0161] The processor 110 can be of any type suitable to the local technical network and can include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multi-core processor architectures, as non-limiting examples. The device 1100 can have multiple processors such as a special purpose integrated circuit chip that is subject to a clock that synchronizes the main processor.

[0162] The memory 1120 can include one or more non-transitory memories and one or more transitory memories. Examples of non-transitory memories include, but are not limited to, read-only memories (ROMs) 1124, electrically programmable read-only memories (EPROMs), flash memories, hard disks, compact disks (CDs), digital video disks (DVDs), and other magnetic and / or optical storage devices. Examples of transitory memories include, but are not limited to, random access memories (RAMs) 1122 and other volatile memories that do not persist during a power-off duration.

[0163] The computer program 1130 includes computer executable instructions that are executed by the associated processor 1110. The program 1130 can be stored in the ROM 1220. The processor 1110 can perform any suitable action and processing by loading the program 1130 into the RAM 1120.

[0164] Embodiments of the present disclosure can be implemented by means of the program 1130, such that the device 1100 can perform any process of the present disclosure as discussed with reference to Figures 2 to 10 Embodiments of the present disclosure can also be implemented by hardware, or by a combination of software and hardware.

[0165] In some embodiments, program 1130 can be tangibly embodied in a computer- readable medium, which can be included in device 1100 (such as in memory 1120) or in another storage device accessible by device 1100. Device 1100 can load program 1130 from the computer-readable medium into RAM 1122 in order to execute the program. The computer-readable medium can include any type of tangible non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD-ROM, DVD, etc. Figure 12 An example of a computer-readable medium 1200 in the form of a CD or DVD is shown. The computer-readable medium has program 1130 stored thereon.

[0166] In general, the various embodiments of the disclosure can be implemented in hardware or special-purpose circuits, software, logic or any combination thereof. Some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software which can be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the disclosure are illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it will be understood that the blocks, apparatus, systems, techniques or methods described herein can be implemented in hardware, software, firmware, special-purpose circuits or logic, general purpose hardware or controler or other computing devices, or some combination thereof.

[0167] The disclosure also provides at least one computer program product which is tangibly embodied in a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions for execution by a device on a target real or virtual processor, such as those included in program modules, to perform the methods 600, 700, 800, 900 or 1000 described above with reference to Figure 6 , Figure 7 , Figure 8 , Figure 9 or Figure 10 Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules can be combined or split between program modules as desired in various embodiments. Machine executable instructions for program modules can be executed within the local or distributed device. In a distributed device, program modules can be located in both local and remote memory storage devices.

[0168] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, causes the machine to perform the functions / acts specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0169] In the context of the present disclosure, computer program code or related data can be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations as described above. Examples of carriers include signals, computer readable media, and the like.

[0170] The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. As used in this document, the term "non-transitory" is merely intended to exclude portable data storage such as volatile memory or RAM, as data stored thereon can be lost in the event of a power failure, but does not exclude other forms of computer readable media, such as non-volatile storage.

[0171] Furthermore, although illustrated as occurring in a particular sequence or order, this should not be understood as requiring such a specific sequence or order, or to execute the illustrated operations in the order shown, or to execute the illustrated operations to achieve a desired result. In certain circumstances, multitasking and parallel processing can be advantageous. Likewise, although certain specific implementation details are included in the above discussion, these should not be understood as limiting the scope of the disclosure, but rather as being descriptive of features that can be specific to particular embodiments. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented separately or in any suitable sub-combination.

[0172] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A first network device, comprising: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the first network device to at least: receiving a first request message from a terminal device, the first request message including: a first identifier (ID) associated with a user equipment (UE) of the terminal device; and A first response message is sent to the terminal device, the first response message including a group-specific key for sidelink multicast / broadcast communication in a group of terminal devices for sidelink positioning.

2. The first network device according to claim 1, wherein the first network device is further configured to: Sending a second request message associated with the first ID to a second network device, the second request message being used to request a second ID associated with a group associated with the first ID, wherein the second ID indicates the terminal device group; and A second response message is received from the second network device, where the second response message includes: The second ID associated with the first ID.

3. The first network device according to claim 1 or 2, wherein the first network device is further configured to: Before receiving the first request message from the terminal device, receiving mapping information between the second ID and the group-specific key from the second network device; and The mapping information between the second ID and the group-specific key is stored.

4. The first network device according to claim 3, wherein the first network device is further configured to: The group-specific key is determined based on the second ID received in the second response message and the mapping information.

5. The first network device according to any one of claims 2 to 4, wherein the first network device is further configured to: Based on the second response message received from the second network device, mapping information between the first ID and the second ID is stored.

6. The first network device according to any one of claims 1 to 5, wherein the first network device is further configured to: The group-specific key is received from the second network device or the third network device before the first request message is received from the terminal device.

7. The first network device according to any one of claims 1 to 6, wherein the second response message further comprises: A non-specific key for sidelink communication of the first terminal device used for sidelink positioning.

8. The first network device according to claim 7, wherein the first network device is further configured to: The non-specific key is received from the second network device or the third network device.

9. The first terminal device according to claim 7 or 8, wherein at least one of the following items: The group-specific key is used for session-based sidelink positioning; or The non-specific key is used for session-less sidelink positioning.

10. A second network device, comprising: at least one processor; as well as at least one memory storing instructions, which, when executed by the at least one processor, cause the second network device to at least: receiving a request message associated with a first identifier (ID) from a first network device, the request message being for requesting a second ID associated with a group associated with the first ID, wherein the first ID is associated with a user equipment (UE) of a terminal device, and the second ID indicates a group of terminal devices for sidelink positioning; as well as A response message is sent to the first network device, where the response message includes: the second ID associated with the first ID.

11. The second network device according to claim 10, wherein the second network device is further configured to: Before receiving the request message from the first network device, allocating a group-specific key having the second ID, wherein the group-specific key is used for sidelink multicast / broadcast communication in the group of terminal devices for sidelink positioning; and Mapping information between the second ID and the group-specific key is sent to the first network device.

12. The second network device according to claim 10 or 11, wherein the second network device is further configured to: Before allocating the group specific key with the second ID, the group specific key is generated.

13. The second network device according to claim 10 or 11, wherein the second network device is further configured to: Prior to allocating the group-specific key with the second ID, the group-specific key is received from a third network device.

14. The second network device according to any one of claims 10 to 13, wherein the second network device is further configured to: A non-specific key for sidelink communication of the terminal device for sidelink positioning is received from a third network device.

15. The first terminal device according to claim 14, wherein at least one of the following items: The group-specific key is used for session-based sidelink positioning; or The non-specific key is used for session-less sidelink positioning.

16. A third network device, comprising: at least one processor; as well as at least one memory storing instructions, which, when executed by the at least one processor, cause the third network device to at least: generating a group-specific key for sidelink multicast / broadcast communication in a group of end devices for sidelink positioning; as well as The group-specific key is sent to the first network device or the second network device.

17. The third network device according to claim 16, wherein the third network device is further configured to: generating a non-specific key for sidelink communication of an end device for sidelink positioning; and The non-specific key is sent to the first network device or the second network device.

18. The first terminal device according to claim 17, wherein at least one of the following items: The group-specific key is used for session-based sidelink positioning; or The non-specific key is used for session-less sidelink positioning.

19. A first terminal device, comprising: at least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the first terminal device to at least: Sending a request message to a network device or a second terminal device, the request message including: an identifier (ID) associated with a user equipment (UE) of the first terminal device; A reply message is received from the network device or the second terminal device, the reply message including a group-specific key for sidelink multicast / broadcast communication in a group of sidelink located terminal devices.

20. The first terminal device according to claim 19, wherein the response message further comprises: A non-specific key for sidelink communication of the first terminal device used for sidelink positioning.

21. The first terminal device according to claim 20, wherein at least one of the following items: The group-specific key is used for session-based sidelink positioning; or The non-specific key is used for session-less sidelink positioning.

22. A second terminal device, comprising: at least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the second terminal device to at least: generating a group-specific key for sidelink multicast / broadcast communication in a group of end devices for sidelink positioning; receiving a request message from a first terminal device in the terminal device group, the request message including: an identifier (ID) associated with a user equipment (UE) of the first terminal device; A response message is sent to the first terminal device, where the response message includes: the group-specific key.

23. The second terminal device according to claim 22, wherein the response message further comprises: A non-specific key for sidelink communication of the first terminal device used for sidelink positioning.

24. The second terminal device according to claim 23, wherein at least one of the following items: The group-specific key is used for session-based sidelink positioning; or The non-specific key is used for session-less sidelink positioning.

25. A method comprising: At a first network device, receiving a request message from a terminal device, the request message including: an identifier (ID) associated with a user equipment (UE) of the terminal device; and A reply message is sent to the terminal device, the reply message including a group-specific key for sidelink multicast / broadcast communication in the group of terminal devices for sidelink positioning.

26. A method comprising: receiving, at a second network device, a request message associated with a first identifier (ID) from a first network device, the request message being for requesting a second ID associated with a group associated with the first ID, wherein the first ID is associated with a user equipment (UE) of a terminal device, and the second ID indicates a group of terminal devices for sidelink positioning; as well as A response message is sent to the first network device, where the response message includes: the second ID associated with the first ID.

27. A method comprising: generating, at a third network device, a group-specific key for sidelink multicast / broadcast communication in a group of sidelink-located terminal devices; as well as The group-specific key is sent to the first network device or the second network device.

28. A method comprising: At a first terminal device, sending a request message to a network device or a second terminal device, the request message including: an identifier (ID) related to a user equipment (UE) of the first terminal device; and A reply message is received from the network device or the second terminal device, the reply message including a group-specific key for sidelink multicast / broadcast communication in a group of sidelink located terminal devices.

29. A method comprising: generating, at the second terminal device, a group-specific key for sidelink multicast / broadcast communication in the group of terminal devices for sidelink positioning; receiving a request message from a first terminal device in the terminal device group, the request message including: an identifier (ID) associated with a user equipment (UE) of the first terminal device; as well as A response message is sent to the first terminal device, where the response message includes the group-specific key.

30. A non-transitory computer-readable medium comprising program instructions for causing an apparatus to at least perform the method according to any one of claims 25 to 29.