Prose multi-hop u2n relay security
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QUALCOMM INC
- Filing Date
- 2024-12-23
- Publication Date
- 2026-08-04
Smart Images

Figure CN122514980A_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims the benefit of U.S. Non-Provisional Patent Application Serial No. 18 / 410,978, entitled “PROSE MULTI-HOP U2N RELAY SECURITY”, filed January 11, 2024, the entire contents of which are expressly incorporated herein by reference. Technical Field
[0003] This disclosure relates generally to communication systems, and more specifically to User Equipment (UE) to Network (U2N) relay for wireless communication. Background Technology
[0004] Wireless communication systems are widely deployed to provide a variety of telecommunications services, such as telephone, video, data, messaging, and broadcasting. Typical wireless communication systems may employ multiple access technologies capable of supporting communication with multiple users by sharing available system resources. Examples of such multiple access technologies include Code Division Multiple Access (CDMA) systems, Time Division Multiple Access (TDMA) systems, Frequency Division Multiple Access (FDMA) systems, Orthogonal Frequency Division Multiple Access (OFDMA) systems, Single Carrier Frequency Division Multiple Access (SC-FDMA) systems, and Time Division Synchronous Code Division Multiple Access (TD-SCDMA) systems.
[0005] These multiple access technologies have been adopted in various telecommunications standards to provide a common protocol that enables different wireless devices to communicate at the city, national, regional, and even global levels. An example telecommunications standard is 5G New Radio (NR). 5G NR is part of the Continuous Evolution of Mobile Broadband (CWB) program issued by the 3rd Generation Partnership Project (3GPP) to meet new requirements associated with latency, reliability, security, scalability (e.g., with the Internet of Things (IoT),) and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine-type communications (mMTC), and ultra-reliable low-latency communications (URLLC). Some aspects of 5G NR are based on the 4G Long Term Evolution (LTE) standard. Further improvements to 5G NR technology are needed. These improvements can also be applied to other multiple access technologies and telecommunications standards that adopt them. Summary of the Invention
[0006] The following is a simplified summary of one or more aspects to provide a basic understanding of these aspects. This summary is not a comprehensive overview of all conceived aspects. It neither identifies key or essential elements of all aspects nor describes the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed descriptions that follow.
[0007] In one aspect of this disclosure, a method, computer-readable medium, and apparatus for wireless communication at a user equipment (UE) are provided. The apparatus is configured to: receive a discovery message associated with UE-to-network relay communication; determine a multi-hop discovery based at least on the discovery message; and verify the discovery message, wherein the discovery message is at least protected by integrity.
[0008] In one aspect of this disclosure, a method, computer-readable medium, and apparatus for wireless communication at a relay UE are provided. The apparatus is configured to: receive a discovery message associated with UE-to-network relay communication; determine a multi-hop relay of the discovery message; increment the hop count of the discovery message; protect the integrity of the discovery message; and forward the discovery message with the incremented hop count.
[0009] In one aspect of this disclosure, a method, computer-readable medium, and apparatus for wireless communication at a UE are provided. The apparatus is configured to: determine a multi-hop path for UE-to-network relay communication with a wireless network, the multi-hop path including a plurality of relay UEs between the UE and the wireless network; perform a security process for the UE-to-network relay communication via the multi-hop path to the wireless network; and exchange communication with the wireless network via the multi-hop path based on the security process.
[0010] In one aspect of this disclosure, a method, computer-readable medium, and apparatus are provided for wireless communication at a donor relay UE. The apparatus is configured to: determine a multi-hop path for UE-to-network relay communication; and perform a security process for UE-to-network relay communication via the multi-hop path, the multi-hop path including a donor relay UE and at least one intermediate relay UE between the UE and a wireless network.
[0011] In one aspect of this disclosure, a method, computer-readable medium, and apparatus are provided for wireless communication at an intermediate relay UE. The apparatus is configured to: perform a secure process at the intermediate relay UE for UE-to-network relay communication via a multi-hop path between the UE and the wireless network; and forward communication between the wireless network and the UE via the donor relay UE based on the secure process.
[0012] To achieve the foregoing and related objectives, one or more aspects may include the features fully described below and specifically pointed out in the claims. The following description and drawings set forth some exemplary features of one or more aspects in detail. However, these features indicate only a few of the various ways in which the principles of the various aspects may be employed. Attached Figure Description
[0013] Figure 1This is a diagram illustrating an example of a wireless communication system and an access network.
[0014] Figure 2A This is an illustration of an example of the first frame according to various aspects of this disclosure.
[0015] Figure 2B This is a diagram illustrating examples of downlink (DL) channels within a subframe according to various aspects of this disclosure.
[0016] Figure 2C This is an illustration of an example of a second frame according to various aspects of this disclosure.
[0017] Figure 2D This is a diagram illustrating examples of uplink (UL) channels within a subframe according to various aspects of this disclosure.
[0018] Figure 3 This is a diagram illustrating examples of base stations and user equipment (UEs) in an access network.
[0019] Figure 4 This is a diagram illustrating various aspects of the ProSe system architecture associated with the use of UE-to-Network (U2N) relay according to some aspects of this disclosure.
[0020] Figure 5A and Figure 5B This is a call flowchart illustrating a set of discovery messages associated with a method for discovering a relay UE according to some aspects of this disclosure.
[0021] Figure 6 This is a call flow diagram illustrating a method associated with a user plane-based security process for single-hop U2N trunking, according to some aspects of this disclosure.
[0022] Figure 7 This is a call flow diagram illustrating a method associated with a control plane-based security process for single-hop U2N trunks, according to some aspects of this disclosure.
[0023] Figure 8 This is a call flow diagram illustrating a method associated with a user plane-based security process for multi-hop U2N trunking, according to some aspects of this disclosure.
[0024] Figure 9 This is a call flow diagram illustrating a method associated with a user plane-based security process for multi-hop U2N trunking, according to some aspects of this disclosure.
[0025] Figure 10 This is a call flow diagram illustrating a method associated with a control plane-based security process for multi-hop U2N trunking, according to some aspects of this disclosure.
[0026] Figure 11 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0027] Figure 12 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0028] Figure 13 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0029] Figure 14 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0030] Figure 15 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0031] Figure 16 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0032] Figure 17 This is a flowchart of a wireless communication method according to some aspects of this disclosure.
[0033] Figure 18 This is an illustration illustrating an example of a hardware implementation used in an example device and / or UE.
[0034] Figure 19 This is a diagram illustrating an example of a hardware implementation for an example device and / or a relay UE. Detailed Implementation
[0035] In some aspects of wireless communication, a wireless device (or UE) may use a relay UE, or be available to be used as a relay UE, to communicate with a network (e.g., associated with a U2N relay). Relay usage may be supported for a single relay UE providing connectivity between a remote UE and a network (e.g., a base station) (e.g., via a sidelink (SL) connection). Security procedures for U2N relays may be associated with (restricted) relay discovery, PC5 (e.g., sidelink) link establishment, and privacy procedures (e.g., link identifier update procedures) for SL (e.g., PC5) connections. In some aspects, SL link establishment may be associated with Layer 3 (L3) user plane security procedures, L3 control plane security procedures, or Layer 2 (L2) procedures.
[0036] Various aspects typically involve allowing and / or implementing multi-hop U2N relay for extended coverage. Some aspects more specifically involve additional security features to support multi-hop U2N relay. In some examples, a remote UE is configured to: receive a discovery message associated with UE-to-network relay communication; determine multi-hop discovery based at least on the discovery message; and verify the discovery message, wherein the discovery message is at least protected for integrity. In some aspects, a relay UE is configured to: receive a discovery message associated with UE-to-network relay communication; determine multi-hop relay of the discovery message; increment the hop count of the discovery message; protect the integrity of the discovery message; and forward the discovery message with the incremented hop count.
[0037] The aspects may include determining a multi-hop path for UE-to-network relay communication by a remote UE, relay UE, or donor UE; and performing a security procedure for UE-to-network relay communication via a multi-hop path, which includes a donor relay UE and at least one intermediate relay UE between the UE and the wireless network.
[0038] For multi-hop U2N trunks, this disclosure provides enhanced security for U2N trunk discovery, wherein discovery messages are protected for integrity. Aspects provide improved security for hop-by-hop PC5 link establishment (e.g., from donor trunk UE to remote UE), for example, in cases where a remote UE performs a multi-hop indirect U2N trunk secure establishment procedure with a donor trunk UE.
[0039] The detailed descriptions following, illustrated with reference to the accompanying drawings, describe various configurations and do not represent the only configurations in which the concepts described herein can be practiced. To provide a thorough understanding of the various concepts, the detailed descriptions include specific details. However, these concepts can be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring these concepts.
[0040] Various apparatuses and methods are presented with reference to several aspects of a telecommunications system. These apparatuses and methods are described in detail below and illustrated in the accompanying drawings by various blocks, components, circuits, processes, algorithms, etc. (collectively, “elements”). These elements can be implemented using electronic hardware, computer software, or any combination thereof. Whether such elements are implemented as hardware or software depends on the specific application and the design constraints imposed on the system as a whole.
[0041] As an example, an element, any part of an element, or any combination of elements may be implemented as a "processing system" including one or more processors. When multiple processors are implemented, the multiple processors may perform functions individually or in combination. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, system-on-a-chip (SoCs), baseband processors, field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gate logic, discrete hardware circuits, and other suitable hardware configured to perform the various functionalities described throughout this disclosure. One or more processors in a processing system may execute software. Whether referred to as software, firmware, middleware, microcode, hardware description language, or other terms, software should be broadly interpreted as instructions, instruction sets, code, code segments, program code, programs, subroutines, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, or any combination thereof.
[0042] Therefore, in one or more example aspects, specific implementations, and / or use cases, the described functionality may be implemented in hardware, software, or any combination thereof. If implemented in software, the functionality may be stored or encoded as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media. Storage media can be any available medium that can be accessed by a computer. By way of example, such computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disc storage devices, magnetic disk storage devices, other magnetic storage devices, combinations of these types of computer-readable media, or any other medium that can be used to store computer-executable code in the form of instructions or data structures accessible by a computer.
[0043] While aspects, implementations, and / or use cases are described herein by way of example, additional or different aspects, implementations, and / or use cases may arise in many different arrangements and scenarios. The aspects, implementations, and / or use cases described herein can be implemented across many different platform types, devices, systems, shapes, sizes, and package arrangements. For example, aspects, implementations, and / or use cases may arise via integrated chip implementations and other devices based on non-modular components (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, AI-enabled devices, etc.). While some examples may or may not be specific to a use case or application, the described examples may exhibit broad applicability. Aspects, implementations, and / or use cases can range from chip-level or modular components to non-modular, non-chip-level implementations, and further to aggregated, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more of the technologies described herein. In some practical settings, devices incorporating the described aspects and features may also include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals necessarily involve multiple components for analog and digital purposes (e.g., hardware components including antennas, RF chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). The techniques described herein can be practiced in a wide variety of devices, chip-level components, systems, distributed arrangements, aggregated or decomposed components, end-user equipment, etc., of various sizes, shapes, and configurations.
[0044] The deployment of communication systems such as 5G NR systems can be arranged in a variety of ways using various components or parts. In a 5G NR system or network, network nodes, network entities, network mobility elements, radio access network (RAN) nodes, core network nodes, network elements or network equipment (such as base stations (BS)) or one or more units (or components) performing base station functions can be implemented in aggregated or decomposed architectures. For example, BSs (such as Node B (NB), evolved NB (eNB), NR BS, 5G NB, access point (AP), transmit / receive point (TRP), or cell, etc.) can be implemented as aggregated base stations (also known as standalone BS or monolithic BS) or decomposed base stations.
[0045] Aggregated base stations can be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. Decentralized base stations can be configured to utilize a protocol stack that is physically or logically distributed across two or more units, such as one or more central or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs). In some respects, the CU may be implemented within a RAN node, and one or more DUs may co-located with the CU, or alternatively, may be geographically or virtually distributed across one or more other RAN nodes. DUs may be implemented to communicate with one or more RUs. Each of the CUs, DUs, and RUs may be implemented as a virtual unit, namely a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).
[0046] Base station operation or network design can take into account the aggregation characteristics of base station functionality. For example, decomposed base stations can be utilized in Integrated Access Backhaul (IAB) networks, Open Radio Access Networks (O-RAN (such as network configurations initiated by the O-RAN Alliance)), or Virtualized Radio Access Networks (vRAN, also known as Cloud Radio Access Networks (C-RAN)). Decomposition can include distributing functionality across two or more units in various physical locations, as well as virtually distributing the functionality of at least one unit, which enables flexibility in network design. The various units of a decomposed base station or decomposed RAN architecture can be configured to communicate wirelessly with at least one other unit.
[0047] Figure 1 Figure 100 illustrates an example of a wireless communication system and access network. The illustrated wireless communication system includes a decomposed base station architecture. The decomposed base station architecture may include one or more CUs 110, which may communicate directly with the core network 120 via a backhaul link, or indirectly with the core network 120 via one or more decomposed base station units, such as a near real-time (near-RT) RAN Intelligent Controller (RIC) 125 via an E2 link, or a non-real-time (non-RT) RIC 115 associated with a Service Management and Orchestration (SMO) framework 105, or both. CUs 110 may communicate with one or more DUs 130 via a corresponding midhaul link (such as an F1 interface). DUs 130 may communicate with one or more RUs 140 via a corresponding fronthaul link. RUs 140 may communicate with a corresponding UE 104 via one or more radio frequency (RF) access links. In some implementations, a UE 104 may be served simultaneously by multiple RUs 140.
[0048] Each of these units (i.e., CU 110, DU 130, RU 140, and near-RT RIC 125, non-RT RIC 115, and SMO frame 105) may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) via wired or wireless transmission media. Each of these units, or an associated processor or controller providing instructions to the communication interfaces of these units, may be configured to communicate with one or more other units via transmission media. For example, these units may include wired interfaces configured to receive signals or transmit signals to one or more other units via wired transmission media. Additionally, these units may include wireless interfaces that may include receivers, transmitters, or transceivers (such as RF transceivers) configured to receive signals via wireless transmission media or transmit signals to one or more other units, or both.
[0049] In some aspects, the CU 110 can host one or more higher-level control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Serving Data Adaptation Protocol (SDAP), etc. Each control function can be implemented using an interface configured to signal to other control functions hosted by the CU 110. The CU 110 can be configured to handle user plane functionality (i.e., Central Unit-User Plane (CU-UP)), control plane functionality (i.e., Central Unit-Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 110 can be logically divided into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units can communicate bidirectionally with the CU-CP units via an interface such as an E1 interface. The CU 110 can be implemented to communicate with the DU 130 for network control and signaling, as needed.
[0050] DU 130 may correspond to a logical unit that includes one or more base station functions for controlling the operation of one or more RU 140s. In some aspects, DU 130 may at least partially host one or more of the Radio Link Control (RLC) layer, Media Access Control (MAC) layer, and one or more high physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation, demodulation, etc.) according to functional splits (such as those defined by 3GPP). In some aspects, DU 130 may further host one or more low PHY layers. Each layer (or module) may be implemented using an interface configured to communicate signals with other layers (and modules) hosted by DU 130 or with control functions hosted by CU 110.
[0051] Lower-layer functionality can be implemented by one or more RU 140s. In some deployments, an RU140 controlled by a DU 130 may correspond to a logical node that hosts RF processing functions or low-PHY layer functions (such as performing Fast Fourier Transform (FFT), Inverse FFT (iFFT), digital beamforming, Physical Random Access Channel (PRACH) extraction and filtering, or both, based at least in part on functional decomposition (such as lower-layer functional decomposition). In such architectures, the RU 140 may be implemented to handle over-the-air (OTA) communications with one or more UEs 104. In some specific implementations, the real-time and non-real-time aspects of control plane and user plane communications with the RU 140 may be controlled by the corresponding DU 130. In some scenarios, this configuration enables the DU 130 and CU 110 to be implemented in a cloud-based RAN architecture (such as a vRAN architecture).
[0052] SMO framework 105 can be configured to support RAN deployment and provisioning of both non-virtualized and virtualized network elements. For non-virtualized network elements, SMO framework 105 can be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via operation and maintenance interfaces such as the O1 interface. For virtualized network elements, SMO framework 105 can be configured to interact with a cloud computing platform such as Open Cloud (O-Cloud) 190 to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface such as the O2 interface. Such virtualized network elements may include, but are not limited to, CU 110, DU 130, RU 140, and near-RT RIC 125. In some implementations, SMO framework 105 can communicate with the hardware aspects of the 4G RAN (such as Open eNB (O-eNB) 111) via the O1 interface. Additionally, in some implementations, SMO framework 105 can communicate directly with one or more RU 140s via the O1 interface. SMO framework 105 may also include a non-RT RIC 115 configured to support the functionality of SMO framework 105.
[0053] The non-RT RIC 115 can be configured to include logical functions enabling non-real-time control and optimization of RAN elements and resources, including artificial intelligence (AI) / machine learning (ML) workflows for model training and updates, or policy-based guidance for applications / features in the near-RT RIC 125. The non-RT RIC 115 can be coupled to or communicate with the near-RT RIC 125, such as via an A1 interface. The near-RT RIC 125 can be configured to include logical functions enabling near real-time control and optimization of RAN elements and resources via data collection and actions through an interface such as an E2 interface, connecting one or more CU 110s, one or more DU 130s, or both, and O-eNBs to the near-RT RIC 125.
[0054] In some implementations, to generate AI / ML models to be deployed in the near-RT RIC 125, the non-RT RIC 115 may receive parameters or external enrichment information from an external server. This information can be utilized by the near-RT RIC 125 and may be received from non-network data sources or network functions at the SMO framework 105 or the non-RT RIC 115. In some examples, the non-RT RIC 115 or the near-RT RIC 125 may be configured to tune RAN behavior or performance. For example, the non-RT RIC 115 may monitor long-term trends and patterns in performance and employ AI / ML models to perform corrective actions via the SMO framework 105 (such as reconfiguration via O1) or by creating RAN management policies (such as A1 policies).
[0055] At least one of CU 110, DU 130, and RU 140 may be referred to as base station 102. Therefore, base station 102 may include one or more of CU 110, DU 130, and RU 140 (each component is indicated by a dashed line to indicate that each component may or may not be included in base station 102). Base station 102 provides UE 104 with an access point to core network 120. Base station 102 may include macro cells (high-power cellular base stations) and / or small cells (low-power cellular base stations). Small cells include femtocells, picocells, and microcells. A network that includes both small cells and macro cells may be referred to as a heterogeneous network. A heterogeneous network may also include an evolved home node B (eNB) (HeNB), which can provide service to a restricted group referred to as a closed subscriber group (CSG). The communication link between RU 140 and UE 104 may include uplink (UL) transmission (also known as reverse link) from UE 104 to RU 140 and / or downlink (DL) transmission (also known as forward link) transmission from RU 140 to UE 104. The communication link may utilize multiple-input multiple-output (MIMO) antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may use one or more carriers. For each direction, the total number of carriers used for transmission can be up to [number missing]. Yx MHz ( x For each carrier allocated in carrier aggregation (of component carriers), base station 102 / UE 104 can use up to [number] carriers. YA spectrum with a bandwidth of MHz (e.g., 5MHz, 10MHz, 15MHz, 20MHz, 100MHz, 400MHz, etc.). Carriers may be adjacent to each other or may not be adjacent to each other. Carrier allocation may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be allocated to DL compared to UL). Component carriers may include primary component carriers and one or more secondary component carriers. The primary component carrier may be referred to as the primary cell (PCell) and the secondary component carrier may be referred to as the secondary cell (SCell).
[0056] Some UEs 104 may communicate with each other using device-to-device (D2D) communication links 158. D2D communication links 158 may use DL / UL wireless wide area network (WWAN) spectrum. D2D communication links 158 may use one or more sidelink channels, such as Physical Sidelink Broadcast Channel (PSBCH), Physical Sidelink Discovery Channel (PSDCH), Physical Sidelink Shared Channel (PSSCH), and Physical Sidelink Control Channel (PSCCH). Some examples of sidelink communication may include vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I) (e.g., from a vehicle-based communication device to a road infrastructure node such as a roadside unit (RSU), vehicle-to-network (V2N) (e.g., from a vehicle-based communication device to one or more network nodes such as a base station), vehicle-to-pedestrian (V2P), cellular vehicle-to-everything (C-V2X), and / or combinations thereof, and / or vehicle-based communication devices communicating with other devices; these communications may be collectively referred to as vehicle-to-everything (V2X) communication. Sidelink communication can be based on V2X or other D2D communication methods, such as Proximity Services (ProSe). Besides the UE, sidelink communication can also be transmitted and received by other transmitting and receiving devices such as Roadside Units (RSUs). In some aspects, sidelink communication can use the PC5 interface for exchange. D2D communication can be performed through various wireless D2D communication systems, such as Bluetooth. ™ (Bluetooth is a trademark of the Bluetooth Special Interest Group (SIG), and is based on the IEEE 802.11 standard for Wi-Fi.) ™ (Wi-Fi is a trademark of the Wi-Fi Alliance), LTE, or NR.
[0057] The wireless communication system may also include a Wi-Fi AP 150, which communicates with the UE 104 (also referred to as a Wi-Fi station (STA)) via a communication link 154, for example, in an unlicensed spectrum such as 5 GHz. When communicating in unlicensed spectrum, the UE 104 / AP 150 may perform a free channel assessment (CCA) to determine whether the channel is available before communication.
[0058] The electromagnetic spectrum is typically subdivided into various categories, bands, channels, etc., based on frequency / wavelength. In 5G NR, two initial operating bands have been designated as frequency ranges FR1 (410MHz to 7.125GHz) and FR2 (24.25GHz to 52.6GHz). Although a portion of FR1 is greater than 6GHz, in various documents and articles, FR1 is often (interchangeably) referred to as the "sub-6GHz" band. Similar naming issues sometimes occur with FR2, which is often (interchangeably) referred to as the "millimeter wave" band in documents and articles, although this is distinct from the Extremely High Frequency (EHF) band (30GHz to 300GHz) designated as "millimeter wave" by the International Telecommunication Union (ITU).
[0059] The frequencies between FR1 and FR2 are generally referred to as mid-band frequencies. Recent 5G NR studies have identified the operating bands used for these mid-band frequencies as the frequency range designation FR3 (7.125 GHz to 24.25 GHz). Bands falling within FR3 can inherit FR1 and / or FR2 characteristics, thus effectively extending the features of FR1 and / or FR2 to mid-band frequencies. Furthermore, higher frequency bands are currently being explored to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as the frequency range designations FR2-2 (52.6 GHz to 71 GHz), FR4 (71 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands falls within the EHF band.
[0060] In view of the above, unless otherwise specifically stated, the term "below 6 GHz" as used herein can broadly refer to frequencies less than 6 GHz, within FR1, or including intermediate frequency band frequencies. Furthermore, unless otherwise specifically stated, the term "millimeter wave" as used herein can broadly refer to frequencies that can include intermediate frequency band frequencies, within FR2, FR4, FR2-2 and / or FR5, or within the EHF band.
[0061] Base station 102 and UE 104 may each include multiple antennas (such as antenna elements, antenna panels, and / or antenna arrays) to facilitate beamforming. Base station 102 may transmit beamformed signals 182 to UE 104 in one or more transmit directions. UE 104 may receive beamformed signals from base station 102 in one or more receive directions. UE 104 may also transmit beamformed signals 184 to base station 102 in one or more transmit directions. Base station 102 may receive beamformed signals from UE 104 in one or more receive directions. Base station 102 / UE 104 may perform beamforming training to determine the optimal receive and transmit directions for each of base station 102 / UE 104. The transmit and receive directions of base station 102 may be the same or different. The transmit and receive directions of UE 104 may be the same or different.
[0062] Base station 102 may include and / or be referred to as gNB, Node B, eNB, access point, transceiver base station, radio base station, radio transceiver, transceiver function, basic service set (BSS), extended service set (ESS), TRP, network node, network entity, network equipment, or some other suitable terminology. Base station 102 may be implemented as an integrated access and backhaul (IAB) node, relay node, sidelink node, aggregated (monolithic) base station with baseband units (BBU) (including CU and DU) and RU, or may be implemented as a decomposed base station including one or more of CU, DU, and / or RU. A collection of base stations that may include decomposed base stations and / or aggregated base stations may be referred to as Next Generation (NG) RAN (NG-RAN).
[0063] The core network 120 may include Access and Mobility Management Function (AMF) 161, Session Management Function (SMF) 162, User Plane Function (UPF) 163, Unified Data Management (UDM) 164, one or more location servers 168, and other functional entities. AMF 161 is the control node that processes signaling between UE 104 and the core network 120. AMF 161 supports registration management, connection management, mobility management, and other functions. SMF 162 supports session management and other functions. UPF 163 supports packet routing, packet forwarding, and other functions. UDM 164 supports authentication and key agreement (AKA) credential generation, user identity processing, access authorization, and subscription management. One or more location servers 168 are exemplified as including a Gateway Mobile Location Center (GMLC) 165 and a Location Management Function (LMF) 166. However, generally, one or more location servers 168 may include one or more location / positioning servers, which may include one or more of GMLC 165, LMF 166, Position Determination Entity (PDE), Serving Mobile Location Center (SMLC), Mobile Location Center (MPC), etc. GMLC 165 and LMF 166 support UE location services. GMLC 165 provides an interface for clients / applications (e.g., emergency services) to access UE location information. LMF 166 receives measurement and auxiliary information from NG-RAN and UE 104 via AMF 161 to calculate the location of UE 104. NG-RAN may use one or more positioning methods to determine the location of UE 104. Positioning UE 104 may involve signal measurement, location estimation, and optional speed calculation based on these measurements. Signal measurement may be performed by UE 104 and / or base station 102 serving UE 104. The measured signals may be based on one or more of the following: Satellite Positioning System (SPS) 170 (e.g., one or more of Global Navigation Satellite System (GNSS), Global Positioning System (GPS), Non-Terrestrial Network (NTN) or other satellite positioning / location systems), LTE signals, Wireless Local Area Network (WLAN) signals, Bluetooth signals, Terrestrial Beacon System (TBS), sensor-based information (e.g., barometric pressure sensor, motion sensor), NR Enhanced Cell ID (NR E-CID) method, NR signals (e.g., multiple round-trip time (multiple RTT), DL departure angle (DL-AoD), DL time difference of arrival (DL-TDOA), UL time difference of arrival (UL-TDOA), and UL angle of arrival (UL-AoA) positioning) and / or other systems / signals / sensors.
[0064] Examples of UE 104 include cellular phones, smartphones, Session Initiation Protocol (SIP) phones, laptops, personal digital assistants (PDAs), satellite radios, GPS devices, multimedia devices, video devices, digital audio players (e.g., MP3 players), cameras, game consoles, tablets, smart devices, wearable devices, vehicles, electricity meters, air pumps, large or small kitchen appliances, healthcare devices, implants, sensors / actuators, displays, or any other similarly functional device. Some UEs in UE 104 may be referred to as IoT devices (e.g., parking timers, air pumps, toasters, vehicles, heart monitors, etc.). UE 104 may also be referred to as a station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, mobile phone, user agent, mobile client, client, or some other suitable terminology. In some scenarios, the term UE may also be applied to one or more companion devices, such as in a device constellation arrangement. One or more of these devices may access the network together and / or individually.
[0065] Refer again Figure 1 In some aspects, UE 104 may have a multi-hop component 198, which may be configured to: receive a discovery message associated with UE-to-network relay communication; determine a multi-hop discovery based at least on the discovery message; and verify the discovery message, wherein the discovery message is at least protected by integrity. In some aspects, the multi-hop component may be configured to: determine a multi-hop path for UE-to-network relay communication; perform a security procedure for UE-to-network relay communication via the multi-hop path to the wireless network; and exchange communication with the wireless network via the multi-hop path based on the security procedure.
[0066] In some aspects, the UE (e.g., as a relay UE, such as a donor UE or an intermediate relay UE) may include a multi-hop component 199 configured to: receive a discovery message associated with UE-to-network relay communication; determine the multi-hop relay of the discovery message; increment the hop count of the discovery message; protect the integrity of the discovery message; and forward the discovery message with the incremented hop count. The multi-hop component 199 may be configured to: determine a multi-hop path for UE-to-network relay communication; and perform a security procedure for UE-to-network relay communication via the multi-hop path, which includes a donor relay UE and at least one intermediate relay UE between the UE and the wireless network. The multi-hop component 199 may be configured to: perform a security procedure at the intermediate relay UE for UE-to-network relay communication via the multi-hop path between the UE and the wireless network; and forward communication between the wireless network and the UE via the donor relay UE based on the security procedure. As described herein, in some aspects, the UE may be used as a remote UE at one time and as a relay UE (e.g., a donor UE or an intermediate relay UE) at another time. Therefore, in some respects, a single UE may include a multi-hop component 198 and a multi-hop component 199.
[0067] Figure 2A Figure 200 illustrates an example of the first subframe within a 5G NR frame structure. Figure 2B Figure 230 illustrates an example of a DL channel within a 5G NR subframe. Figure 2C Figure 250 is an example of a second subframe within a 5G NR frame structure. Figure 2D Figure 280 illustrates an example of a UL channel within a 5G NR subframe. The 5G NR frame structure can be Frequency Division Duplex (FDD) (where subframes within a specific set of subcarriers (carrier system bandwidth) are dedicated to either DL or UL) or Time Division Duplex (TDD) (where subframes within a specific set of subcarriers (carrier system bandwidth) are dedicated to both DL and UL). Figure 2A , Figure 2CIn the provided example, the 5G NR frame structure is assumed to be TDD, where subframe 4 is configured with slot format 28 (most of which are DL), where D is DL, U is UL, and F is flexible and can be used between DL / UL, and subframe 3 is configured with slot format 1 (all of which are UL). Although subframes 3 and 4 are shown as having slot formats 1 and 28 respectively, any particular subframe can be configured with any of the various available slot formats 0-61. Slot formats 0 and 1 are both DL and UL, respectively. Other slot formats 2-61 include a mixture of DL, UL, and flexible symbols. The slot format is configured for the UE via the received Slot Format Indicator (SFI) (dynamically configured via DL Control Information (DCI) or semi-statically / statically configured via Radio Resource Control (RRC) signaling). Note that the following description also applies to the 5G NR frame structure as TDD.
[0068] Figures 2A to 2D The frame structure is illustrated, and aspects of this disclosure are applicable to other wireless communication technologies that may have different frame structures and / or different channels. A frame (10 ms) can be divided into 10 equal-sized subframes (1 ms). Each subframe may include one or more time slots. Subframes may also include micro-time slots, which may include 7, 4, or 2 symbols. Each time slot may include 14 or 12 symbols, depending on whether the cyclic prefix is normal or extended. For a normal cyclic prefix, each time slot may include 14 symbols, and for an extended cyclic prefix, each time slot may include 12 symbols. These symbols on the DL may be cyclic prefix orthogonal frequency division multiplexing (OFDM) (CP-OFDM) symbols. The symbols on the UL may be CP-OFDM symbols (for high-throughput scenarios) or Discrete Fourier Transform (DFT) extended OFDM (DFT-s-OFDM) symbols (for power-constrained scenarios; limited to single-stream transmission). The number of time slots within a subframe is based on the cyclic prefix and parameter set. The parameter set defines the subcarrier spacing (SCS) (see Table 1). The symbol length / duration can be scaled by 1 / SCS.
[0069]
[0070] Table 1: Parameter Set, SCS, and Cyclic Prefix
[0071] For a normal cyclic prefix (14 symbols / slot), different parameter sets µ 0 through 4 allow 1, 2, 4, 8, and 16 slots per subframe, respectively. For an extended cyclic prefix, parameter set 2 allows 4 slots per subframe. Therefore, for a normal cyclic prefix and parameter set µ, there are 14 symbols per slot and 2 slots per subframe. µ One time slot. The subcarrier spacing can be equal to ,in The parameter sets are 0 to 4. Therefore, the subcarrier spacing is 15 kHz for parameter set µ=0 and 240 kHz for parameter set µ=4. The symbol length / duration is negatively correlated with the subcarrier spacing. Figures 2A to 2D An example is provided with a normal cyclic prefix of 14 symbols per time slot and a parameter set of µ=2 with 4 time slots per subframe. The time slot duration is 0.25 ms, the subcarrier spacing is 60 kHz, and the symbol duration is approximately 16.67 μs. Within the frame set, there may be one or more different bandwidth portions (BWPs) of frequency division multiplexing (see [link to example]). Figure 2B Each BWP can have a specific set of parameters and a loop prefix (normal or extended).
[0072] A resource grid can be used to represent the frame structure. Each time slot consists of a resource block (RB) extending for 12 consecutive subcarriers (also known as a physical RB (PRB)). The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.
[0073] like Figure 2A As illustrated, some of the REs carry reference (pilot) signals (RS) for the UE. RS may include demodulation RS (DM-RS) (indicated as R for a particular configuration, but other DM-RS configurations are possible) and channel state information reference signals (CSI-RS) for channel estimation at the UE. RS may also include beam measurement RS (BRS), beam refinement RS (BRRS), and phase tracking RS (PT-RS).
[0074] Figure 2BExamples of various DL channels within a subframe of a frame are illustrated. The Physical Downlink Control Channel (PDCCH) carries the DCI within one or more Control Channel Elements (CCEs) (e.g., 1, 2, 4, 8, or 16 CCEs), each CCE comprising six RE Groups (REGs), each REG comprising 12 coherent REs in the OFDM symbol of the RB. A PDCCH within a BWP can be referred to as a Control Resource Set (CORESET). The UE is configured to monitor PDCCH candidates in a PDCCH search space (e.g., a common search space, a UE-specific search space) during PDCCH monitoring timing on the CORESET, where the PDCCH candidates have different DCI formats and different aggregation levels. Additional BWPs may be located at higher and / or lower frequencies on the channel bandwidth. The Primary Synchronization Signal (PSS) may be located within symbol 2 of a specific subframe of the frame. The PSS is used by the UE 104 to determine subframe / symbol timing and physical layer identification. The Secondary Synchronization Signal (SSS) may be located within symbol 4 of a specific subframe of the frame. The SSS is used by the UE to determine the Physical Layer Cell Identifier Group Number and radio frame timing. Based on the Physical Layer Identifier and the Physical Layer Cell Identifier Group Number, the UE can determine the Physical Cell Identifier (PCI). Based on the PCI, the UE can determine the location of the DM-RS. The Physical Broadcast Channel (PBCH), carrying the Master Information Block (MIB), can be logically grouped with the PSS and SSS to form a Synchronization Signal (SS) / PBCH block (also known as an SS block (SSB)). The MIB provides the System Frame Number (SFN) and the number of Restricted Frames (RBs) in the system bandwidth. The Physical Downlink Shared Channel (PDSCH) carries user data, broadcast system information not transmitted via the PBCH (such as System Information Blocks (SIBs)), and paging messages.
[0075] like Figure 2C As illustrated, some REs in the REs carry DM-RS (indicated as R for one particular configuration, but other DM-RS configurations are possible) for channel estimation at the base station. The UE can transmit DM-RS for the Physical Uplink Control Channel (PUCCH) and DM-RS for the Physical Uplink Shared Channel (PUSCH). The PUSCH DM-RS can be transmitted in the first or first two symbols of the PUSCH. Depending on whether a short or long PUCCH is transmitted and depending on the specific PUCCH format used, the PUCCH DM-RS can be transmitted in different configurations. The UE can transmit a Sounding Reference Signal (SRS). The SRS can be transmitted in the last symbol of a subframe. The SRS can have a comb structure, and the UE can transmit the SRS on one of the comb teeth. The SRS can be used by the base station for channel quality estimation to enable frequency-dependent scheduling of the UL.
[0076] Figure 2DExamples of various UL channels within a subframe of a frame are illustrated. The PUCCH may be located as indicated in one configuration. The PUCCH carries uplink control information (UCI), such as scheduling requests, channel quality indicators (CQI), pre-decoding matrix indicators (PMI), rank indicators (RI), and hybrid automatic repeat request (HARQ) acknowledgment (ACK) (HARQ-ACK) feedback (i.e., one or more HARQ ACK bits indicating one or more ACKs and / or negative ACKs (NACKs)). The PUCCH carries data and may additionally be used to carry buffer status reports (BSR), power clearance reports (PHR), and / or UCIs.
[0077] Figure 3 This is a block diagram illustrating communication between base station 310 and UE 350 in the access network. In the DL, Internet Protocol (IP) packets can be provided to controller / processor 375. Controller / processor 375 implements Layer 3 and Layer 2 functionality. Layer 3 includes the Radio Resource Control (RRC) layer, and Layer 2 includes the Service Data Adaptation Protocol (SDAP) layer, Packet Data Convergence Protocol (PDCP) layer, Radio Link Control (RLC) layer, and Media Access Control (MAC) layer. The controller / processor 375 provides RRC layer functionality associated with broadcasting system information (e.g., MIB, SIB), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-Radio Access Technology (RAT) mobility, and measurement configuration for UE measurement reporting; PDCP layer functionality associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functionality associated with the delivery of upper-layer packet data units (PDUs), error correction via ARQ, concatenation, segmentation, and reassembly of RLC service data units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority handling, and logical channel priority ordering.
[0078] Transmit (TX) processor 316 and receive (RX) processor 370 implement Layer 1 functionality associated with various signal processing functions. Layer 1 (which includes the physical (PHY) layer) may include error detection on the transport channel, forward error correction (FEC) decoding / decoding of the transport channel, interleaving, rate matching, mapping to the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. TX processor 316 processes the mapping to the signal constellation based on various modulation schemes (e.g., binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), M-order phase shift keying (M-PSK), M-order quadrature amplitude modulation (M-QAM)). The decoded and modulated symbols can then be divided into parallel streams. Each stream can then be mapped to OFDM subcarriers, multiplexed with a reference signal (e.g., a pilot) in the time and / or frequency domains, and then combined using inverse fast Fourier transform (IFFT) to produce a physical channel carrying a stream of time-domain OFDM symbols. The OFDM stream is spatially pre-decoded to generate multiple spatial streams. Channel estimates from channel estimator 374 are used to determine the decoding and modulation scheme, as well as for spatial processing. The channel estimates can be derived from a reference signal transmitted by UE 350 and / or channel condition feedback. Each spatial stream can then be provided to a different antenna 320 via a separate transmitter 318Tx. Each transmitter 318Tx can use the corresponding spatial stream to modulate a radio frequency (RF) carrier for transmission.
[0079] At UE 350, each receiver 354Rx receives signals via its corresponding antenna 352. Each receiver 354Rx recovers the information modulated onto the RF carrier and provides that information to the receive (RX) processor 356. The TX processor 368 and RX processor 356 implement Layer 1 functionality associated with various signal processing functions. The RX processor 356 can perform spatial processing on the information to recover any spatial stream destined for UE 350. If multiple spatial streams are destined for UE 350, the RX processor 356 can combine them into a single OFDM symbol stream. The RX processor 356 then uses a Fast Fourier Transform (FFT) to transform the OFDM symbol stream from the time domain to the frequency domain. The frequency domain signal consists of a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, along with the reference signal, are recovered and demodulated by determining the most probable signal constellation point transmitted by base station 310. These soft decisions can be based on a channel estimate calculated by channel estimator 358. The soft decision is then decoded and deinterleaved to recover the data and control signals originally transmitted by base station 310 on the physical channel. The data and control signals are then provided to controller / processor 359, which implements layer 3 and layer 2 functionality.
[0080] The controller / processor 359 may be associated with at least one memory 360 storing program code and data. The at least one memory 360 may be referred to as a computer-readable medium. In the UL, the controller / processor 359 provides demultiplexing, packet reassembly, decryption, header decompression, and control signal processing between transport and logical channels to recover IP packets. The controller / processor 359 is also responsible for error detection using ACK and / or NACK protocols to support HARQ operation.
[0081] Similar to the functionality described in conjunction with DL transmission performed by base station 310, controller / processor 359 provides RRC layer functionality associated with system information (e.g., MIB, SIB) acquisition, RRC connectivity, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with upper-layer PDU delivery, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto TBs, demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority handling, and logical channel priority ordering.
[0082] The TX processor 368 can use the reference signal transmitted from the base station 310 or the channel estimate derived from feedback by the channel estimator 358 to select an appropriate decoding and modulation scheme and facilitate spatial processing. The spatial stream generated by the TX processor 368 can be provided to different antennas 352 via individual transmitters 354Tx. Each transmitter 354Tx can use the corresponding spatial stream to modulate an RF carrier for transmission.
[0083] UL transmission is processed at base station 310 in a manner similar to that described in conjunction with the receiver function at UE 350. Each receiver 318Rx receives signals via its corresponding antenna 320. Each receiver 318Rx recovers the information modulated onto the RF carrier and provides that information to RX processor 370.
[0084] The controller / processor 375 may be associated with at least one memory 376 storing program code and data. The at least one memory 376 may be referred to as a computer-readable medium. In the UL, the controller / processor 375 provides demultiplexing, packet reassembly, decryption, header decompression, and control signal processing between transport and logical channels to recover IP packets. The controller / processor 375 is also responsible for error detection using ACK and / or NACK protocols to support HARQ operation.
[0085] At least one of the TX processor 368, RX processor 356, and controller / processor 359 can be configured to perform and Figure 1 The multi-hop component 198 and / or multi-hop component 199 are combined in various aspects.
[0086] In some aspects of wireless communication, a wireless device (or UE) may use a relay UE to communicate with a network (e.g., associated with a U2N relay). In some aspects, the communication may be referred to as U2N communication. The relay may be referred to as a U2N relay, relay UE, U2N relay UE, or other names. In some aspects, a UE communicating with a network via a relay may be referred to as a remote UE. The relay UE may provide connectivity between the remote UE and the wireless network (e.g., a base station of the wireless network) (e.g., via an SL connection). For example, communication between the remote UE and the relay UE may be sidelink communication, and communication between the relay UE and the network may be Uu communication. Security procedures for U2N relays may be associated with (restricted) relay discovery, PC5 (e.g., sidelink) link establishment, and privacy procedures (e.g., link identifier update procedures) for SL (e.g., PC5) connections. In some aspects, SL link establishment may be associated with L3 user plane security procedures, L3 control plane security procedures, or L2 procedures. Security mechanisms may be based on U2N relays with single hops or single relays. The aspects presented in this article achieve security for multi-hop U2N relays, where the path between the remote UE and the network includes multiple relay UEs.
[0087] Figure 4 Figure 400 illustrates aspects of a ProSe system architecture supporting U2N relay according to some aspects of this disclosure. Figure 400 illustrates that both UE 405 and UE 406 have (or support) a connection to RAN 402 (e.g., a base station associated with RAN 402, such as NG-RAN) via a UE-UTRAN (Uu) link. In some aspects, one of the UEs may be outside the coverage of RAN 402 and may establish a connection to the RAN via another UE. UE 405 and UE 406 may also be connected to each other via a PC5 link (e.g., SL for direct communication). UE 405 and 406 may be connected to aspects of the core network 420 (e.g., Direct Discovery Name Management Function (DDNMF) / ProSe Key Management Function (PKMF) 424) via PC3a or PC8 links. UE405 and 406 can also be associated with ProSe application 407 or ProSe application 409, respectively, which can be connected to ProSe application server 430 via PC1 link.
[0088] In some aspects, core network 420 may include a policy control function (PCF) 422 that can assign ProSe policies to UE 405 and / or UE 406 and provide security materials and PC5 security policies. In some aspects, DDNMF / PKMF 424 may (e.g., via DDNMF) provide ProSe codes and corresponding discovery security materials. In some aspects, ProSe application server 430 may perform service authorization for ProSe UEs (e.g., 405 and 406). In the following discussion, the elements and functions of core network 420 and data network 410 (and specifically, ProSe application server 430) may be simply referred to as the core or core network, and the functions performed by the core and / or core network may include communication between elements of the core network for performing the functions.
[0089] Security aspects may include relay discovery security, such as scrambling, message-specific confidentiality, and / or integrity protection. Security materials may be provisioned by the PKMF and may be associated with a Relay Service Code (RSC). Relay discovery security may support different discovery modes, such as Model A discovery and Model B discovery. Security aspects may include unicast PC5 link security, such as authorization of remote UEs and unicast PC5 link security key material provisioning by the PKMF. Such PC5 link security may support both user plane (UP) and control plane (CP) approaches. These aspects may be applied to L3 and / or L2 U2N relays.
[0090] In some aspects, the U2N relay discovery process can be configured to allow authorized UEs to discover other UEs or services. In some aspects, a first model or operating mode of U2N relay discovery (e.g., Model A U2N relay discovery) may include a U2N relay UE announcing its ability to act as a U2N relay device. In some aspects, a second model or operating mode of U2N relay discovery (e.g., Model B U2N relay discovery) may include U2N relay queries and responses. In some aspects, discovery messages may be protected with integrity, scrambling, and / or confidentiality as configured and / or determined by the network. In some aspects, scrambling (for confidentiality) may be applied to discovery messages up to 32 bytes (where discovery messages can be as large as 9 kB due to the introduction of proprietary metadata). In some aspects, confidentiality protection may be applied to at least a portion of the discovery message. In some aspects, verification of the discovery message may be performed at the UE.
[0091] In some aspects of multi-hop U2N relay, the system architecture may include a remote UE indirectly connected to a network (e.g., a base station) via two or more U2N relay UEs. The two or more relay UEs may include a donor U2N relay UE (which may be referred to as a donor UE, donor relay UE, U2N donor relay UE, U2N relay UE, or relay UE) and one or more intermediate U2N relay UEs (which may be referred to as an intermediate UE, intermediate relay UE, U2N intermediate relay UE, U2N relay UE, or relay UE). A donor U2N relay UE may be a relay UE directly connected to the network (or base station) and providing network connectivity (directly) to a first intermediate U2N relay UE and (indirectly) to any additional intermediate U2N relay UEs and the remote UE. Each intermediate U2N relay UE is indirectly connected to the network and provides network connectivity to at least one additional UE (e.g., an additional intermediate U2N relay UE or a remote UE).
[0092] Figure 5A and Figure 5B These are call flowcharts, such as 500 and 550, illustrating a set of discovery messages associated with a method for discovering a relay UE according to some aspects of this disclosure. Call flowchart 500 illustrates aspects associated with a core network 502 for discovery announcement messages (e.g., such as in Model A discovery), a donor UE 504 (e.g., a first relay UE or a donor U2N relay UE), a first intermediate relay UE 505 (e.g., a first intermediate U2N relay UE), a second intermediate relay UE 506 (e.g., a second intermediate U2N relay UE), and a remote UE 508. Figure 5B Example aspects for discovering requests and responses (e.g., as in Model B discovery) are illustrated.
[0093] The aspects are illustrated with respect to a core network 502 (e.g., an example of a network device or network node and an associated element of a core network that may include one or more components of a decomposed base station) communicating with at least donor UE 504, first intermediate relay UE 505, second intermediate relay UE 506, and remote UE 508 (e.g., as an example of a wireless device). In some aspects, the functions belonging to the core network 502 may be provided by the core network, network entities, network nodes, or network devices (as described above regarding...). Figure 1 The described single network entity / node / device or decomposed network entity / node / device, or as described above regarding Figure 4The functions described herein are performed by one or more components of the core network. Similarly, in some aspects, functions attributable to the UE (e.g., donor UE 504, first intermediate relay UE 505, second intermediate relay UE 506, and remote UE 508) may be performed by one or more components of a wireless device that supports communication with network entities / nodes / devices. Therefore, the reference to “transmit” in the following description can be understood as referring to the first component of the core network 502 (or UE) outputting (or providing) an indication of the content to be transmitted by different components of the core network 502 (or UE). Similarly, the reference to “receive” in the following description can be understood as referring to the first component of the core network 502 (or UE) receiving the transmitted signal and outputting (or providing) the received signal (or information based on the received signal) to different components of the core network 502 (or UE).
[0094] Relay discovery material can be allocated to each remote UE (e.g., 508) and relay UE (e.g., 504, 505, 506). In some aspects, the core network 502 can provide relay discovery security material 512, which can be received by the first intermediate relay UE 505, the second intermediate relay UE 506, and the remote UE 508. The relay discovery security material can indicate one or more parameters associated with integrity protection for discovery-related messages. Based on the relay discovery security material 512, the remote UE 508 can initiate a U2N discovery request 532 (e.g., for model B U2N relay discovery), such as... Figure 5B As shown. The U2N discovery request 532 can be sent by the remote UE 508 and received by one or more of the donor UE 504, the first intermediate relay UE 505, and / or the second intermediate relay UE 506. Alternatively (e.g., for Model A U2N relay discovery), the remote UE 508 may not make a request (e.g., the U2N discovery request 532 may be omitted), but may instead monitor announcements from potential relay UEs (e.g., relay UE candidates). Figure 5A As shown, each relay UE that receives an announcement message (e.g., the announcement message may be referred to as a discovery message) may increment the hop count of the message. For example, if the hop count of the announcement message (e.g., discovery message 516) is 1, then relay UE 505 may increment the hop count to hop count 2 at 518 before sending an announcement message (e.g., discovery message 520). Relay UE 506 receives the announcement message with a hop count of 2, increments the hop count to 3 at 522, and sends an announcement message with a hop count of 3 (e.g., discovery message 524).
[0095] Figure 5BAn example of Model B discovery is illustrated, where, for instance, the discovering UE provides a query or request, and the discovered UE responds using a response message (e.g., this response message may be referred to as a request and response message). The request and / or response message may also be referred to as a discovery message. For example, remote UE 508 sends request 532 to relay UE 506. Request 532 may indicate a hop count of 1. At 534, relay UE 506 increments the hop count before sending discovery request 536 to relay UE 505 based on request 532. The hop count in request 536 is 2. At 538, relay UE 505 increments the hop count before sending discovery request 540 to donor UE 504 based on request 534. The hop count in request 540 is 3. Based on receiving U2N discovery request 540, donor UE 504 may reply to or announce the availability of the donor UE as a relay UE by sending a U2N response / announcement (e.g., discovery message 544). The notification (e.g., it may be referred to as a discovery message) may include or indicate RSC, relay user information, and / or hop count. A U2N response / notification (e.g., 544) may include an indication (e.g., a hop count equal to one) of a single-hop path to the network (e.g., a base station) indicated by the donor UE 504. In some aspects, discovery message 516 (in...) Figure 5A and / or Figure 5BThe relay UE 504 may have integrity protection (configured based on relay discovery security material 512) to prevent path length manipulation by attackers. In some aspects, message 544 may be associated with emergency services, and the integrity protection may use a null integrity protection algorithm (e.g., it may be referred to as having no integrity protection). Message 544 may be received by the first intermediate relay UE 505, and the first intermediate relay UE 505 may verify the integrity of the message, increment the hop count, and apply integrity protection at 546. The first intermediate relay UE 505 may send a U2N reply / announcement (e.g., discovery message 520) that can be received at the second intermediate relay UE 506 and / or the remote UE 508. The discovery message may include or indicate RSC, relay user information, and / or the incremented hop count. The relay UE 505 may increment the hop count at 546. A U2N response / announcement (e.g., discovery message 548) may include an indication (e.g., a hop count equal to two) of a two-hop multi-hop path to a network (e.g., a base station) from the first intermediate relay UE 505. Based on the receipt of the U2N discovery message (e.g., 548), the second intermediate relay UE 506 may verify the integrity of the message at 552, increment the hop count (e.g., from 2 to 3), and apply integrity protection before sending (or forwarding) the discovery message. The second intermediate relay UE 506 may then send a discovery message 554, which can be received by the remote UE 508. The discovery message may include or indicate RSC, relay user information, and / or a hop count (e.g., 3). Discovery message 554 may include an indication (e.g., a hop count equal to three hops between the remote UE 508 and the donor UE) of a three-hop multi-hop path to a network (e.g., a base station) from the second intermediate relay UE 506.
[0096] Upon receiving one or more U2N discovery responses and / or announcements (e.g., 524 or 554), the remote UE 508 may verify message integrity and select a multi-hop path and associated relay UE at 526 or 556. In some aspects, the U2N discovery message 524 or 556 may be associated with emergency services, and integrity protection may use a null integrity protection algorithm (e.g., no integrity protection). This selection may be based on multiple factors and / or criteria, including the number of hops associated with each multi-hop path. After selecting a multi-hop path at 526 or 556, the remote UE 508 and donor UE 504 (and either the first intermediate relay UE 505 or the second intermediate relay UE 506 along the multi-hop path) may establish a secure U2N relay at 528 or 558. As an example, the remote UE 508 may establish a secure (e.g., for L2) end-to-end Uu connection setup with the network via multiple relays.
[0097] Figure 6This is a call flowchart illustrating a method associated with a user plane-based security process for single-hop U2N relay according to some aspects of this disclosure. Call flowchart 600 illustrates a set of elements associated with core network 602, relay UE 604, and remote UE 608. The method is illustrated with respect to core network 602 (e.g., as an example of an associated element of a core network that may include one or more components of a network device or network node and may include a decomposed base station) communicating with relay UE 604 and remote UE 608 (e.g., as an example of a wireless device). In some aspects, the functions attributable to core network 602 may be provided by the core network, network entities, network nodes, or network devices (as described above regarding...). Figure 1 The described single network entity / node / device or decomposed network entity / node / device, or as described above regarding Figure 4 The functions described herein are performed by one or more components of the core network. Similarly, in some aspects, functions attributable to the UE (e.g., relay UE 604 and remote UE 608) may be performed by one or more components of a wireless device that supports communication with network entities / nodes / devices. Therefore, the reference to “transmit” in the following description can be understood as referring to the first component of core network 602 (or UE) outputting (or providing) an indication of the content to be transmitted by different components of core network 602 (or UE). Similarly, the reference to “receive” in the following description can be understood as referring to the first component of core network 602 (or UE) receiving the transmitted signal and outputting (or providing) the received signal (or information based on the received signal) to different components of core network 602 (or UE).
[0098] At 610, remote UE 608 and relay UE 604 can participate in the relay discovery process. After discovering relay UE 604, remote UE 608 can exchange one or more configuration messages 612 with core network 602 in association with ProSe Remote User Key (PRUK) configuration. Based on the PRUK configuration associated with one or more configuration messages 612, remote UE 608 can send a communication request 614, which relay UE 604 can receive. In some aspects, communication request 614 may include a relay service code (RSC) value, a PRUK identifier (ID), and a first random number. Based on communication request 614, relay UE 604 can send a key request 616, which core network 602 (the PKMF or ProSe anchor function of core network 602) can receive. In some aspects, key request 616 may include an RSC value, a PRUK ID, and a first random number.
[0099] Based on key request 616, core network 602 can generate a key at 618. Core network 602 can send key response 620, and relay UE 604 can receive this key response. In some aspects, key response 620 may include a PRUK-based key (e.g., K...). NRP ), the first random number and the second random number. Based on the key associated with key response 620 (e.g., K). NRP Relay UE 604 can send a Direct Security Mode command 622, and remote UE 608 can receive the Direct Security Mode command. The Direct Security Mode command 622 may include a second random number. Upon receiving the Direct Security Mode command message, as shown at 624, remote UE 608 can generate a key (e.g., K). NRP The remote UE 608 can send a Direct Security Mode Completion Message 626 indicating successful key generation and message verification, and the relay UE 604 can receive this Direct Security Mode Completion Message.
[0100] Figure 7 This is a call flowchart illustrating a method associated with a control plane-based security process for single-hop U2N relay according to some aspects of this disclosure. Call flowchart 700 illustrates a set of elements associated with core network 702, relay UE 704, and remote UE 708. The method is illustrated with respect to core network 702 (e.g., as an example of an associated element of a core network that may include one or more components of a network device or network node and may include a decomposed base station) communicating with relay UE 704 and remote UE 708 (e.g., as an example of a wireless device). In some aspects, the functions attributable to core network 702 may be provided by the core network, network entities, network nodes, or network devices (as described above regarding...). Figure 1 The described single network entity / node / device or decomposed network entity / node / device, or as described above regarding Figure 4 The functions described herein are performed by one or more components of the core network. Similarly, in some aspects, functions attributable to the UE (e.g., relay UE 704 and remote UE 708) may be performed by one or more components of a wireless device that supports communication with network entities / nodes / devices. Therefore, the reference to “transmit” in the following description can be understood as referring to the first component of core network 702 (or UE) outputting (or providing) an indication of the content to be transmitted by different components of core network 702 (or UE). Similarly, the reference to “receive” in the following description can be understood as referring to the first component of core network 702 (or UE) receiving the transmitted signal and outputting (or providing) the received signal (or information based on the received signal) to different components of core network 702 (or UE).
[0101] At 710, remote UE 708 and relay UE 704 can participate in the relay discovery process. Based on the relay discovery process at 710, remote UE 708 can send a communication request 714, and relay UE 704 can receive the communication request. In some aspects, communication request 714 may include an RSC value, a Subscription Hidden ID (SUCI) or PRUK ID, and a first random number. Based on communication request 714, relay UE 704 can send a Non-Access Stratum (NAS) request 716, and core network 702 (the AMF and / or Authentication Server Function (AUSF) of core network 702 associated with relay UE 704) can receive the NAS request. In some aspects, NAS request 716 may include an RSC, a SUCI or PRUK ID, and a first random number.
[0102] In some aspects, when a PRUK ID is not provided, the remote UE 708 may exchange one or more master authentication messages 718 with the core network 702 (e.g., the Home Public Land Mobile Network (HPLMN) associated with the remote UE 708) in association with master authentication to derive the PRUK and PRUK ID. In some aspects, one or more master authentication messages 718 may include or be associated with storing the PRUK and PRUK ID at the ProSe anchor function of the core network 702. Based on the PRUK, the core network 702 may generate a key (e.g., K) at 720 based on the PRUK, a first random number, and a second random number. NRP In response to NAS request 716, core network 702 may send NAS response 722, and relay UE 704 may receive the NAS response, which includes the key generated at 720 (e.g., K). NRP The key includes a second random number and a third random number used to generate it. To establish a secure link, relay UE 704 can send a security message 724 including the second random number, and remote UE 708 can receive this security message. (As in...) Figure 6 As described in 622, 624, and 626, the remote UE 708 may generate a key at 726 based on the PRUK and a second random number (received in security message 724) to verify security message 724. The remote UE 708 and the relay UE 704 may exchange additional messages and perform additional operations to establish a secure link based on the security message and / or key provided to the remote UE 708 and the relay UE 704. For example, as shown at 728, the remote UE 708 may send a message to the relay UE 704 indicating a response to security message 724, such as a completion message.
[0103] Figure 8This is a call flowchart illustrating a method associated with a user plane-based security process for multi-hop U2N relay according to some aspects of this disclosure. Call flowchart 800 illustrates a set of elements associated with core network 802, donor UE 804 (e.g., a first relay UE or donor U2N relay UE), first intermediate relay UE 805 (e.g., a first intermediate U2N relay UE), second intermediate relay UE 806 (e.g., a second intermediate U2N relay UE), and remote UE 808.
[0104] This method is illustrated with respect to a core network 802 (e.g., an example of a network device or network node and an associated element of a core network that may include one or more components of a decomposed base station) communicating with at least donor UE 804, first intermediate relay UE 805, second intermediate relay UE 806, and remote UE 808 (e.g., as an example of a wireless device). In some aspects, the functions attributable to core network 802 may be provided by the core network, network entities, network nodes, or network devices (as described above regarding...). Figure 1 The described single network entity / node / device or decomposed network entity / node / device, or as described above regarding Figure 4 The functions described herein are performed by one or more components of the core network. Similarly, in some aspects, functions attributable to the UE (e.g., donor UE 804, first intermediate relay UE 805, second intermediate relay UE 806, and remote UE 808) may be performed by one or more components of a wireless device that supports communication with network entities / nodes / devices. Therefore, the reference to “transmit” in the following description can be understood as referring to a first component of the core network 802 (or UE) outputting (or providing) an indication of the content to be transmitted by different components of the core network 802 (or UE). Similarly, the reference to “receive” in the following description can be understood as referring to a first component of the core network 802 (or UE) receiving the transmitted signal and outputting (or providing) the received signal (or information based on the received signal) to different components of the core network 802 (or UE).
[0105] At point 810, donor UE 804, first intermediate relay UE 805, second intermediate relay UE 806, and remote UE 808 can participate in the multi-hop relay discovery process. After discovering one or more relay UEs (e.g., second intermediate relay UE 806), remote UE 808 can obtain a PRUK and PRUK ID, as per [reference needed]. Figure 6One or more dispatch messages 612 are described. Based on multi-hop relay discovery, a first intermediate relay UE 805 may establish a secure link with donor UE 804 at 812, and a second intermediate relay UE 806 may establish a secure link with the first intermediate relay UE 805 at 814. In some aspects, a secure link may be established between the first intermediate relay UE 805 and donor UE 804 at 812, as per [reference to...]. Figure 6 As described, and similarly, a secure link can be established at 814 between the second intermediate relay UE 806 and the first intermediate relay UE 805, as per [reference to...]. Figure 6 The description refers to (using a first intermediate relay UE 805 and a donor UE 804 to communicate with (or access) the core network 802).
[0106] Remote UE 808 may send a communication request 816, which may be received by a second intermediate relay UE 806. In some aspects, communication request 816 may include an RSC value, a PRUK ID, and a first random number. Based on communication request 816, the second intermediate relay UE 806 may send a key request 822, which may be received by core network 802 (the PKMF or ProSe anchor function of core network 802). In some aspects, key request 822 may include an RSC value, a PRUK ID (based on the first random number), and a first random number.
[0107] Based on key request 822, core network 802 can generate a key at 824. Core network 802 can send key response 826, and the second intermediate relay UE 806 can receive the key response. In some aspects, key response 826 may include a PRUK-based key (e.g., K...). NRP The first random number and the second random number. To establish a secure link, the second intermediate relay UE 806 can send a direct secure mode command message 832, and the remote UE 808 can receive this direct secure mode command message, which includes a second random number and an additional value for generating a third key. (As in...) Figure 6 and Figure 7 As described, at 834, the remote UE 808 can generate a key based on PRUK, a first random number, and a second random number to verify the Direct Security Mode command message 832. The remote UE 808 can send a Direct Security Mode completion message 836, and the second intermediate relay UE 806 can receive this Direct Security Mode completion message to establish a secure link based on the key. (See also: [link to relevant documentation]). Figure 8 As described, the method establishes a series of hop-by-hop secure connections that can be used as multi-hop U2N relays to provide network access to a remote UE808.
[0108] Figure 9 This is a call flow diagram 900 illustrating a method associated with a user plane-based security procedure for multi-hop U2N trunking, according to some aspects of this disclosure. Figure 8 The UP-based security process in this context can be referred to as the first mode, and Figure 9 The UP-based security process in this context can be referred to as the second mode. In some respects, network entities (e.g., such as PKMF or DDNMF) can be configured, configured, or otherwise indicated to be used for the security process; for example, the indication may include combining... Figure 8 The first model or combination of the described aspects Figure 9 The second mode of the described aspects. Call flowchart 900 illustrates the set of elements associated with core network 902, donor UE 904 (e.g., first trunk UE or donor U2N trunk UE), first intermediate trunk UE 905 (e.g., first intermediate U2N trunk UE), second intermediate trunk UE 906 (e.g., second intermediate U2N trunk UE), and remote UE 908.
[0109] This method is illustrated with respect to a core network 902 (e.g., an example of a network device or network node and an associated element of a core network that may include one or more components of a decomposed base station) communicating with at least donor UE 904, first intermediate relay UE 905, second intermediate relay UE 906, and remote UE 908 (e.g., as an example of a wireless device). In some aspects, the functions attributable to the core network 902 may be provided by the core network, network entities, network nodes, or network devices (as described above regarding...). Figure 1 The described single network entity / node / device or decomposed network entity / node / device, or as described above regarding Figure 4 The functions described herein are performed by one or more components of the core network. Similarly, in some aspects, functions attributable to the UE (e.g., donor UE 904, first intermediate relay UE 905, second intermediate relay UE 906, and remote UE 908) may be performed by one or more components of a wireless device that supports communication with network entities / nodes / devices. Therefore, the reference to “transmit” in the following description can be understood as referring to the first component of the core network 902 (or UE) outputting (or providing) an indication of the content to be transmitted by different components of the core network 902 (or UE). Similarly, the reference to “receive” in the following description can be understood as referring to the first component of the core network 902 (or UE) receiving the transmitted signal and outputting (or providing) the received signal (or information based on the received signal) to different components of the core network 902 (or UE).
[0110] At point 910, donor UE 904, first intermediate relay UE 905, second intermediate relay UE 906, and remote UE 908 can participate in the multi-hop relay discovery process. Based on multi-hop relay discovery, second intermediate relay UE 906 can establish a secure link with first intermediate relay UE 905 at point 912, and first intermediate relay UE 905 can establish a secure link with donor UE 904. In some aspects, a secure link between first intermediate relay UE 905 and donor UE 904 can be established at point 914, as per [reference to...]. Figure 7 As described, and similarly, a secure link can be established at 912 between the second intermediate relay UE 906 and the first intermediate relay UE 905, as per [reference to...]. Figure 7 The description refers to using a first intermediate relay UE 905 and a donor UE 904 to communicate with (or access) the core network 902.
[0111] Based on the relay discovery process at 910, remote UE 908 may send a communication request 916, which may be received by second intermediate relay UE 906. In some aspects, communication request 916 may include an RSC value, a PRUK ID, and a first random number. Based on communication request 916, second intermediate relay UE 906 may forward a forwarding request 918 including an RSC value, a PRUK ID, and a first random number, which may be received by first intermediate relay UE 905. First intermediate relay UE 905 may forward a forwarding request 920 including an RSC value, a PRUK ID, and a first random number, which may be received by donor UE 904. Based on communication request 914, relay UE 904 may send a key request 922, which may be received by core network 902 (e.g., a Key Management Network Entity (PKMF)). In some aspects, key request 922 may include an RSC value, a PRUK ID, and a first random number.
[0112] Based on the key request, core network 902 can generate a key at 924. (For example, the key management network entity of core network 902) can send a key response 926, which can be received by donor UE 904. In some aspects, key response 926 may include a first key based on PRUK (e.g., K...). NRP ) and a second random number. The donor UE 904 can generate a second key (e.g., K) based on the first key. NRP ') and sends a key response 928, which the first intermediate relay UE 905 can receive, the key response including a second key based on the first key (e.g., based on K). NRP And K with additional values (such as key export count or relay UE ID) NRP'), a second random number, and additional values used to generate the second key. As an example, if K NRP If it is shared, the donor UE 904 will set the key export count to, for example, 0. If K is provided NRP If the donor UE 904 sets the key export count to 1, then when receiving a key response from the donor UE 904, if the relay UE 905 exports K... NRP If the key export count is '', then the relay UE 905 increments the key export count to 2. By checking the key export count in the direct security mode command, the remote UE can determine how to export the same key. The first intermediate relay UE 905 can generate a third key (e.g., K) based on the second key. NRP '') and sends a key response 930, which the second intermediate relay UE 906 can receive, the key response including a third key based on the second key (e.g., based on K). NRP 'and additional values (such as key export count or relay UEID) K NRP ''), a second random number, and additional values used to generate the third key. (For example, combining...) Figure 6 , Figure 7 , Figure 8 and Figure 10 As described, to establish a secure link, the second intermediate relay UE 906 can send a Direct Security Mode Command Message 932, and the remote UE 908 can receive this Direct Security Mode Command Message, which includes a second random number and an additional value for generating a third key. At 934, the remote UE 908 can generate a third key (e.g., K) based on PRUK, the first random number, the second random number, and the additional value for generating the third key. NRP The remote UE 908 can send a direct security mode completion message 936 to verify the direct security mode command message 932. The second intermediate relay UE 906 can receive the direct security mode completion message to establish a secure link based on the third key.
[0113] Figure 10 This is a call flowchart illustrating a method associated with a control plane-based security process for multi-hop U2N relay according to some aspects of this disclosure. Call flowchart 1000 illustrates a set of elements associated with core network 1002, donor UE 1004 (e.g., a first relay UE or donor U2N relay UE), first intermediate relay UE 1005 (e.g., a first intermediate U2N relay UE), second intermediate relay UE 1006 (e.g., a second intermediate U2N relay UE), and remote UE 1008.
[0114] This method is illustrated with respect to a core network 1002 (e.g., an example of a network device or network node and an associated element of a core network that may include one or more components of a decomposed base station) communicating with at least donor UE 1004, first intermediate relay UE 1005, second intermediate relay UE 1006, and remote UE 1008 (e.g., as an example of a wireless device). In some aspects, the functions attributable to the core network 1002 may be provided by the core network, network entities, network nodes, or network devices (as described above regarding...). Figure 1 The described single network entity / node / device or decomposed network entity / node / device, or as described above regarding Figure 4 The functions described herein are performed by one or more components of the core network. Similarly, in some aspects, functions attributable to the UE (e.g., donor UE 1004, first intermediate relay UE 1005, second intermediate relay UE 1006, and remote UE 1008) may be performed by one or more components of a wireless device that supports communication with network entities / nodes / devices. Therefore, the reference to “transmit” in the following description can be understood as referring to the first component of core network 1002 (or UE) outputting (or providing) an indication of the content to be transmitted by different components of core network 1002 (or UE). Similarly, the reference to “receive” in the following description can be understood as referring to the first component of core network 1002 (or UE) receiving the transmitted signal and outputting (or providing) the received signal (or information based on the received signal) to different components of core network 1002 (or UE).
[0115] At location 1010, donor UE 1004, first intermediate relay UE 1005, second intermediate relay UE 1006, and remote UE 1008 can participate in the multi-hop relay discovery process. Based on multi-hop relay discovery, second intermediate relay UE 1006 can establish a secure link with first intermediate relay UE 1005 at location 1014, and first intermediate relay UE 1005 can establish a secure link with donor UE 1004 at location 1012. In some aspects, a secure link can be established between first intermediate relay UE 1005 and donor UE 1004 at location 1012, as per [reference to...]. Figure 7 As described, and similarly, a secure link can be established at 1014 between the second intermediate relay UE 1006 and the first intermediate relay UE 1005, as per [reference to...]. Figure 7 The description refers to (using a first intermediate relay UE 1005 and a donor UE 1004 to communicate with (or access) the core network 1002).
[0116] Based on the relay discovery process at 1010, remote UE 1008 may send a direct communication request 1016, which can be received by second intermediate relay UE 1006. In some aspects, direct communication request 1016 may include an RSC value, a SUCI or PRUK ID, and a first random number. Based on direct communication request 1016, second intermediate relay UE 1006 may forward a forwarding request 1018 including an RSC value, a SUCI or PRUK ID, and a first random number, which can be received by first intermediate relay UE 1005. First intermediate relay UE 1005 may forward a forwarding request 1020 including an RSC value, a SUCI or PRUK ID, and a first random number, which can be received by donor UE 1004. Based on communication request 1014, relay UE 1004 may send NAS request 1022, and core network 1002 (the AMF and / or AUSF of core network 1002 associated with donor UE 1004) may receive the NAS request. In some aspects, NAS request 1022 may include an RSC value, a SUCI or PRUK ID, and a first random number.
[0117] In some aspects, when a PRUK ID is not provided, the remote UE 1008 may exchange one or more master authentication messages 1023 with the core network 1002 (e.g., the HPLMN of the core network 1002 associated with the remote UE 1008) in association with master authentication to receive the PRUK and PRUK ID. In some aspects, one or more master authentication messages 1023 may include or be associated with storing the PRUK and PRUK ID at the ProSe anchor function of the core network 1002.
[0118] Based on a key request (e.g., NAS request 1022), core network 1002 may generate a key at 1024. Core network 1002 may send a NAS response 1026, which donor UE 1004 may receive. In some aspects, NAS response 1026 may include a first key based on PRUK (e.g., K...). NRP ) and a second random number. The donor UE 1004 can generate a second key (e.g., K) based on the first key. NRP ') and sends a key response 1028, which the first intermediate relay UE 1005 can receive, the key response including a second key based on the first key (e.g., based on K). NRP K and additional values (such as hop count or relay UE ID) NRP The first intermediate relay UE 1005 can generate a third key (e.g., K) based on the second key, a second random number, and additional values used to generate the second key. NRP'') and sends a key response 1030, and the second intermediate relay UE 1006 can receive the key response, which includes a third key based on the second key (e.g., based on K). NRP 'and additional values (such as hop count or relay UE ID) K NRP ''), a second random number, and additional values used to generate the third key. (For example, combining...) Figure 6 , Figure 7 , Figure 8 and Figure 9 As described, to establish a secure link, the second intermediate relay UE 1006 may send a Direct Secure Mode Command Message 1032 including a second random number and an additional value for generating a third key, and the remote UE 1008 may receive the Direct Secure Mode Command Message. At 1034, the remote UE 1008 may generate a third key based on the PRUK, the first random number, the second random number, and the additional value for generating the third key to verify the Direct Secure Mode Command Message 1032. The remote UE 1008 may send a Direct Secure Mode Completion Message 1036, and the second intermediate relay UE 1006 may receive the Direct Secure Mode Completion Message to establish a secure link based on the third key.
[0119] Figure 11 This is a flowchart 1100 of a wireless communication method. This method can be performed by a wireless device, such as a remote UE (e.g., UE 104, 350, 405, 406, 508, 608, 708, 808, 1008; device 1804)). At 1102, the remote UE can receive a discovery message (U2N relay discovery message) associated with UE-to-network relay communication. For example, 1102 can be performed by… Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 are executed. In some aspects, the discovery message may be a discovery announcement message, a discovery response message, or a discovery request message. In some aspects, the discovery message may also include hop count information for multi-hop discovery. For example, refer to... Figure 5A and Figure 5B As part of the discovery process, the remote UE 508 may receive a U2N response / announcement including hop count (e.g., discovery message 524).
[0120] At 1104, the remote UE can determine multi-hop discovery based at least on the discovery message. For example, 1104 can be determined by... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform the determination. In some aspects, this determination may be based on the hop count included in the discovery message. For example, refer to... Figure 5A and Figure 5BThe remote UE 508 can select a multi-hop path and associated relay UE at 526 based on a U2N reply / announcement (e.g., discovery message 524).
[0121] At point 1106, the remote UE can verify the discovery message. For example, 1106 can be accessed by... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform the operation. In some aspects, the discovery message may be at least protected by integrity. In some aspects, integrity protection may be applied at least to the hop count information included in the discovery message. For example, refer to... Figure 5A and Figure 5B The remote UE 508 can verify the integrity of the message.
[0122] Figure 12 This is a flowchart 1200 of a wireless communication method. This method can be performed by a wireless device, such as a remote UE (e.g., UE 104, 405, 406; remote UE 508, 808, 1008; device 1804)). At 1202, the remote UE can receive a discovery message (U2N relay discovery message) associated with UE-to-network relay communication. For example, 1202 can be performed by… Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 are executed. In some aspects, the discovery message may be a discovery announcement message, a discovery response message, or a discovery request message. In some aspects, the discovery message may also include hop count information for multi-hop discovery. For example, refer to... Figure 5A or Figure 5B As part of the discovery process, the remote UE508 may receive a U2N reply / announcement including hop count (e.g., discovery message 524).
[0123] At point 1204, the remote UE can determine multi-hop discovery based at least on the discovery message. For example, point 1204 can be determined by... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform the operation. Determining that a discovery message is associated with a multi-hop U2N relay can be based on including a hop count in the discovery message. In some aspects, this determination can be based on the hop count included in the discovery message. For example, refer to... Figure 5A or Figure 5B The remote UE 508 can receive a U2N reply / announcement (e.g., discovery message 524) that can be identified as a multi-hop U2N relay discovery message, and at 526 select a multi-hop path and associated relay UE based on the U2N reply / announcement (e.g., discovery message 524).
[0124] At point 1206, the remote UE can verify the discovery message. For example, 1206 can be accessed by... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform the operation. In some aspects, the discovery message may be at least protected by integrity. In some aspects, integrity protection may be applied at least to the hop count information included in the discovery message. For example, refer to... Figure 5A or Figure 5B The remote UE 508 can verify the integrity of the message.
[0125] At 1208, a remote UE can receive additional discovery messages associated with emergency services without integrity protection. For example, 1208 can be... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform the operation. In some aspects, a null integrity protection algorithm is used for integrity protection of discovery messages. For example, refer to... Figure 5A or Figure 5B The remote UE 508 can receive U2N responses / announcements associated with emergency services (e.g., discovery message 524), and integrity protection can use an empty integrity protection algorithm (e.g., no integrity protection).
[0126] Figure 13 This is a flowchart 1300 of a wireless communication method. This method can be performed by a wireless device (such as a relay UE (e.g., UE 104, 405, 406; first intermediate relay UE 505, 805, 1005; second intermediate relay UE 506, 806, 1006; donor UE 504, 804, 1004; device 1904)). At 1302, the relay UE can receive a discovery message (U2N relay discovery message) associated with UE-to-network relay communication. For example, 1302 can be performed by... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform the operation. In some aspects, the discovery message may be a discovery announcement message, a discovery response message, or a discovery request message. In some aspects, the discovery message may also include hop count information for multi-hop discovery. For example, refer to... Figure 5A or Figure 5B As part of the discovery process, the first intermediate relay UE 505 (or the second intermediate relay UE 506) may receive a U2N reply / announcement including hop count (e.g., discovery message 516) or a U2N reply / announcement (e.g., discovery message 520).
[0127] At 1304, the relay UE can determine multi-hop discovery based at least on the discovery message. For example, 1304 can be determined by... Figure 19The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform the operation. In some aspects, the discovery message may be at least protected by integrity. Determining that the discovery message is associated with a multi-hop U2N relay may be based on including a hop count in the discovery message. In some aspects, this determination may be based on the hop count included in the discovery message. For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE 505 (or the second intermediate relay UE 506) may receive a U2N reply / announcement (e.g., discovery message 516) or a U2N reply / announcement (e.g., discovery message 520) that may be identified as a multi-hop U2N relay discovery message based on hop count.
[0128] At position 1306, the relay UE can increment the hop count of the discovery message. For example, position 1306 can be... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform this. In some aspects, the relay UE can verify the integrity of the discovery message before incrementing the hop count (where the hop count is also protected by integrity protection). For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE 505 (or the second intermediate relay UE 506) may increment the hop count at 518 (or at 522).
[0129] At 1308, the relay UE can protect the integrity of the discovery message. For example, 1308 can be... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 are executed. In some aspects, a null integrity protection algorithm is used for integrity protection of discovery messages. For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE505 (or the second intermediate relay UE506) can increment the hop count at 518 (or at 522) and apply integrity protection.
[0130] At 1310, the relay UE can forward a discovery message with an incremented hop count. For example, 1310 can be... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 execute the discovery. The discovery message can be a discovery announcement message, a discovery reply message, or a discovery request message. For example, refer to... Figure 5A or Figure 5BThe first intermediate relay UE 505 (or the second intermediate relay UE 506) may send (or forward) a U2N reply / announcement (e.g., discovery message 520) including an incremented hop count (or a U2N reply / announcement (e.g., discovery message 524)).
[0131] Figure 14 This is a flowchart 1400 of a wireless communication method. This method can be performed by a wireless device (such as a relay UE (e.g., UE 104, 405, 406; first intermediate relay UE 505, 805, 1005; second intermediate relay UE 506, 806, 1006; donor UE 504, 804, 1004; device 1904)). At 1402, the relay UE can receive a discovery message (U2N relay discovery message) associated with UE-to-network relay communication. For example, 1402 can be performed by... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform the operation. In some aspects, the discovery message may be a discovery announcement message, a discovery response message, or a discovery request message. In some aspects, the discovery message may also include hop count information for multi-hop discovery. For example, refer to... Figure 5A or Figure 5B As part of the discovery process, the first intermediate relay UE 505 (or the second intermediate relay UE 506) may receive a U2N reply / announcement including hop count (e.g., discovery message 516) or a U2N reply / announcement (e.g., discovery message 520).
[0132] At point 1404, the relay UE can determine multi-hop discovery based at least on the discovery message. For example, 1404 can be determined by... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform the operation. In some aspects, the discovery message may be at least protected by integrity. Determining that the discovery message is associated with a multi-hop U2N relay may be based on including a hop count in the discovery message. In some aspects, this determination may be based on the hop count included in the discovery message. For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE 505 (or the second intermediate relay UE 506) may receive a U2N reply / announcement (e.g., discovery message 516) or a U2N reply / announcement (e.g., discovery message 520) that may be identified as a multi-hop U2N relay discovery message based on hop count.
[0133] At position 1406, the relay UE can increment the hop count of the discovery message. For example, position 1406 can be... Figure 19The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform this. In some aspects, the relay UE can verify the integrity of the discovery message before incrementing the hop count (where the hop count is also protected by integrity protection). For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE 505 (or the second intermediate relay UE 506) may increment the hop count at 518 (or at 522).
[0134] At point 1408, the relay UE can protect the integrity of the discovery message. For example, 1408 can be... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 are executed. In some aspects, a null integrity protection algorithm is used for integrity protection of discovery messages. For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE505 (or the second intermediate relay UE506) can increment the hop count at 518 (or at 522) and apply integrity protection.
[0135] At 1410, the relay UE can forward a discovery message with an incremented hop count. For example, 1410 can be... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 execute the discovery. The discovery message can be a discovery announcement message, a discovery reply message, or a discovery request message. For example, refer to... Figure 5A or Figure 5B The first intermediate relay UE 505 (or the second intermediate relay UE 506) may send (or forward) a U2N reply / announcement (e.g., discovery message 520) or a U2N reply / announcement (e.g., discovery message 524) including an incremented hop count.
[0136] At 1412, the relay UE can provide additional discovery messages associated with emergency services and with integrity protection based on a null integrity protection algorithm. For example, 1208 can be provided by... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 are executed. In some aspects, a null integrity protection algorithm is used for integrity protection of discovery messages. For example, refer to... Figure 5A or Figure 5BThe first intermediate relay UE 505 (or the second intermediate relay UE 506) may send a U2N reply / announcement (e.g., discovery message 520) or a U2N reply / announcement (e.g., discovery message 524) associated with emergency services and having integrity protection based on the null integrity protection algorithm (e.g., no integrity protection).
[0137] Figure 15 This is a flowchart 1500 of a wireless communication method. This method can be performed by a UE (e.g., UE 104, 350, 405, 406, 508, 608, 708, 808, 1008; device 1804). This method implements multi-hop security protection for secure multi-hop U2N discovery.
[0138] At step 1502, the UE determines a multi-hop path for UE-to-network relay communication with the wireless network. The multi-hop path includes multiple relay UEs between the UE and the wireless network, such as a donor UE and one or more intermediate relay UEs. For example, 1502 may be determined by... Figure 18 The application processor 1806, the cellular baseband processor 1824, and / or the multi-hop component 198 are executed. Figure 8 , Figure 9 and Figure 10 An example aspect of multi-hop paths for U2N communication is illustrated.
[0139] At step 1504, the UE performs a security procedure for UE-to-network relay communication via a multi-hop path to the wireless network. For example, 1504 may be performed by... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform this process. In some aspects, performing the secure procedures for the multi-hop path includes: receiving a prose relay user key (PRUK) and a PRUK ID from a network entity; providing a direct communication request to the wireless network via a donor relay UE and an intermediate relay UE in the multi-hop path between the UE and the wireless network; and establishing a secure PC5 link with the intermediate relay UE based on a derived key associated with the PRUK (e.g., the PRUK associated with the PRUK ID). In some aspects, the derived key is the same derived key used for both the donor relay UE and the intermediate relay UE in the multi-hop path to the wireless network. For example, the key may correspond to a combination of... Figure 8 or Figure 9 The described K NRP In some respects, the derived key is a second key derived from a first key associated with the donor relay UE. For example, the key may correspond to, as in combination with... Figure 9 or Figure 10 The described K NRP 'or K NRPIn some respects, safety procedures are used for UPs. Figure 7 and Figure 10 Example aspects of the safety procedures used for UP are illustrated. In some aspects, the safety procedures are used for CP. Figure 6 , Figure 8 and Figure 9 Example aspects of the security procedures used in UP are illustrated. Figure 8 , Figure 9 and Figure 10 Example aspects of a security procedure for multi-hop U2N communication are illustrated. Figure 6 and Figure 7 Example aspects of the security procedures used for U2N communication are illustrated.
[0140] At step 1506, the UE communicates with the wireless network via a multi-hop path based on a security procedure. For example, 1506 may be... Figure 18 The application processor 1806, cellular baseband processor 1824, transceiver 1822, antenna 1880, and / or multi-hop component 198 perform this. For example, the UE may transmit and / or receive wireless communications with the wireless network (e.g., U2N relay communication) via a multi-hop path after a security procedure.
[0141] Figure 16 This is a flowchart 1600 of a wireless communication method. The method can be performed by a UE (such as a donor relay UE (e.g., UE104, 350, 405, 406, donor UEs 504, 804, 1004; device 1904)). This method implements multi-hop security protection for secure multi-hop U2N discovery.
[0142] At step 1602, the donor relay UE determines the multi-hop path for UE-to-network relay communication. For example, 1602 may be determined by... Figure 19 The application processor 1906, the cellular baseband processor 1924, and / or the multi-hop component 199 are executed. Figure 8 , Figure 9 and Figure 10 An example aspect of multi-hop paths for U2N communication is illustrated. Figure 5A and Figure 5B An example aspect of the multi-hop U2N discovery process is illustrated. Figure 6 and Figure 7 Example aspects of the security procedures used for U2N communication are illustrated.
[0143] At step 1604, the donor relay UE performs a secure procedure for UE-to-network relay communication via a multi-hop path, which includes a donor relay UE and at least one intermediate relay UE between the UE and the wireless network. For example, 1604 may be performed by... Figure 19The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980 and / or multi-hop component 199 are executed. Figure 8 , Figure 9 and Figure 10 Example aspects of multi-hop paths for U2N communication are illustrated. In some aspects, performing a security procedure for the UE includes: receiving a direct communication request from the UE, wherein the communication request includes a PRUK ID for the UE; requesting a key from the network based on the PRUK ID; and obtaining a first key from the network. In some aspects, the donor relay UE may also provide a second key to at least one intermediate relay UE in the multi-hop path. In some aspects, the second key is the same key as the first key obtained by the donor relay UE. For example, the key may correspond to a combination of... Figure 8 or Figure 9 The described K NRP In some respects, the donor relay UE can also derive a second key from the first key, wherein the second key is a key different from the first key. For example, the key may correspond to, as in the combination of... Figure 9 or Figure 10 The described K NRP 'or K NRP In some respects, safety procedures are used for UPs. Figure 6 and Figure 10 Example aspects of the safety procedures used for UP are illustrated. In some aspects, the safety procedures are used for CP. Figure 6 , Figure 8 and Figure 9 Example aspects of the security procedures used in UP are illustrated.
[0144] Figure 17 This is a flowchart 1700 of a wireless communication method. The method can be performed by a UE (such as a relay UE, which may be referred to as an intermediate relay UE) (e.g., UE 104, 350, 405, 406, relay UEs 505, 506, 604, 704, 805, 806, 1005, 1006; device 1904). This method implements multi-hop security protection for secure multi-hop U2N discovery.
[0145] At step 1702, the intermediate relay UE performs a secure procedure for UE-to-network relay communication via a multi-hop path between the UE and the wireless network. For example, 1604 may be performed by... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980 and / or multi-hop component 199 are executed. Figure 8 , Figure 9 and Figure 19 An example aspect of multi-hop paths for U2N communication is illustrated. Figure 5A and Figure 5B An example aspect of the multi-hop U2N discovery process is illustrated. Figure 6 and Figure 7 Example aspects of security procedures used in U2N communication are illustrated. In some aspects, the security procedures are for the UP (Uploader). In other aspects, the security procedures are for the CP (Client). Figure 7 and Figure 10 An example security procedure for CP is illustrated. (Figure) Figure 6 , Figure 8 and Figure 9 Example aspects of the security procedures used in UP are illustrated.
[0146] In some aspects, performing a secure procedure for UE-to-network relay communication via a multi-hop path includes: receiving a direct communication request from the UE, wherein the communication request includes a PRUK ID; requesting a key based on the PRUK ID; obtaining the key from the donor relay UE; and establishing secure communication with the UE based on the key. In some aspects, the key is the same key used for the donor relay UE. For example, the key may correspond to a combination of... Figure 8 or Figure 9 The described K NRP In some respects, the key is a second key that is different from the first key used for the donor relay UE, and wherein the second key is derived from the first key. For example, the second key may correspond to a combination of... Figure 9 or Figure 10 The described K NRP In some aspects, the intermediate relay UE can also provide a third key to an additional intermediate relay UE between the UE and the intermediate relay UE, wherein the third key is derived from the second key. For example, the third key may correspond to, as in combination with... Figure 9 or Figure 10 The described K NRP 'or K NRP ''.
[0147] At 1704, the intermediate relay UE forwards communication between the wireless network and the UE via the donor relay UE based on a secure procedure. For example, 1604 can be... Figure 19 The application processor 1906, cellular baseband processor 1924, transceiver 1922, antenna 1980, and / or multi-hop component 199 perform this. For example, a relay UE can forward wireless communications with a wireless network (e.g., U2N relay communication) via a multi-hop path after a security process.
[0148] Figure 18 Figure 1800 illustrates an example of a hardware implementation of device 1804. Device 1804 may be a UE, a component of a UE, or a device that implements UE functionality. In some aspects, the device may correspond to a remote UE, for example, as in conjunction with... Figures 5A to 10As described in any of the above. In some aspects, the device can operate as a donor UE or an intermediate relay UE, and may also include a combination of Figure 19The multi-hop component 199 is described. In some aspects, device 1804 may include at least one cellular baseband processor 1824 (also referred to as a modem) coupled to one or more transceivers 1822 (e.g., cellular RF transceivers). Cellular baseband processor 1824 may include at least one on-chip memory 1824'. In some aspects, device 1804 may also include one or more subscriber identity module (SIM) cards 1820 and at least one application processor 1806 coupled to a secure digital card (SD) card 1808 and a screen 1810. Application processor 1806 may include on-chip memory 1806'. In some aspects, device 1804 may also include a Bluetooth module 1812, a WLAN module 1814, an SPS module 1816 (e.g., a GNSS module), one or more sensor modules 1818 (e.g., a barometric pressure sensor / altimeter; motion sensors such as an inertial measurement unit (IMU), a gyroscope, and / or an accelerometer; light detection and ranging (LIDAR), radio-assisted detection and ranging (RADAR), sound navigation and ranging (SONAR), a magnetometer, audio, and / or other technologies for positioning), an additional memory module 1826, a power supply 1830, and / or a camera 1832. Bluetooth module 1812, WLAN module 1814, and SPS module 1816 may include on-chip transceivers (TRX) (or in some cases, only receivers (RX)). Bluetooth module 1812, WLAN module 1814, and SPS module 1816 may include their own dedicated antennas and / or communicate using one or more antennas 1880. Cellular baseband processor 1824 communicates with UE 104 and / or RU associated with network entity 1802 via transceiver 1822 through one or more antennas 1880. Cellular baseband processor 1824 and application processor 1806 may each include computer-readable media / memory 1824', 1806'. Additional memory module 1826 may also be considered computer-readable media / memory. Each computer-readable media / memory 1824', 1806', 1826 may be non-transitory. Cellular baseband processor 1824 and application processor 1806 are each responsible for general processing, including the execution of software stored on the computer-readable media / memory. When executed by cellular baseband processor 1824 / application processor 1806, the software causes cellular baseband processor 1824 / application processor 1806 to perform the various functions described above. The computer-readable media / memory may also be used to store data manipulated by cellular baseband processor 1824 / application processor 1806 during software execution. The cellular baseband processor 1824 / application processor 1806 may be a component of the UE 350 and may include at least one of a memory 360 and / or at least one of a TX processor 368, an RX processor 356 and a controller / processor 359.In one configuration, device 1804 may be at least one processor chip (modem and / or application) and includes only cellular baseband processor 1824 and / or application processor 1806, while in another configuration, device 1804 may be the entire UE (see, for example). Figure 3 The UE 350 includes an additional module of the device 1804.
[0149] As discussed above, component 198 can be configured to: receive a discovery message associated with UE-to-network relay communication; determine multi-hop discovery based at least on the discovery message; and verify the discovery message, wherein the discovery message is at least protected by integrity. In some aspects, component 198 can be configured to receive an additional discovery message associated with emergency services without integrity protection, wherein the integrity protection for the discovery message uses a null integrity protection algorithm. In some aspects, component 198 can be configured to: determine a multi-hop path for UE-to-network relay communication; perform a security procedure for UE-to-network relay communication via the multi-hop path to the wireless network; and exchange communication with the wireless network via the multi-hop path based on the security procedure. In some aspects, component 198 can be configured to: receive a PRUK and PRUK ID from a network entity; provide a direct communication request to the wireless network via a donor relay UE and an intermediate relay UE in the multi-hop path between the UE and the wireless network; and establish a secure PC5 link with the intermediate relay UE based on a derived key associated with the PRUK ID. Component 198 can also be configured to perform combined... Figure 11 , Figure 12 and / or Figure 15 The flowchart describes various aspects and / or is provided by the remote UE. Figures 5A to 10Any aspect of the communication process executed in any of the following. Component 198 may be within cellular baseband processor 1824, application processor 1806, or both cellular baseband processor 1824 and application processor 1806. Component 198 may be one or more hardware components specifically configured to execute the stated process / algorithm, implemented by one or more processors configured to execute the stated process / algorithm, stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. When multiple processors are implemented, the multiple processors may execute the stated process / algorithm individually or in combination. As shown, device 1804 may include a variety of components configured for various functions. In one configuration, device 1804 (and specifically cellular baseband processor 1824 and / or application processor 1806) may include: components for receiving discovery messages associated with UE-to-network relay communication; components for determining multi-hop discovery at least based on the discovery messages; and components for verifying the discovery messages, wherein the discovery messages are at least protected for integrity. In some aspects, apparatus 1804 may include components for receiving an additional discovery message associated with emergency services without integrity protection, wherein an empty integrity protection algorithm is used for integrity protection of the discovery message. In some aspects, apparatus 1804 may include: components for determining a multi-hop path for UE-to-network relay communication; components for performing a security procedure for UE-to-network relay communication via the multi-hop path to the wireless network; and components for exchanging communication with the wireless network via the multi-hop path based on the security procedure. In some aspects, apparatus 1804 may include: components for receiving a PRUK and a PRUK ID from a network entity; components for providing a direct communication request to the wireless network from a donor relay UE and an intermediate relay UE in the multi-hop path between the UE and the wireless network; and components for establishing a secure PC5 link with the intermediate relay UE based on a derived key associated with the PRUK ID. Apparatus 1804 may also include components for performing a combination Figure 11 , Figure 12 and / or Figure 15 The flowchart describes various aspects and / or is provided by the remote UE. Figures 5A to 10 Any component in any aspect of the communication process of any of the components. These components may be components 198 of device 1804 configured to perform the functions described therein. As described above, device 1804 may include TX processor 368, RX processor 356, and controller / processor 359. Thus, in one configuration, these components may be TX processor 368, RX processor 356, and / or controller / processor 359 configured to perform the functions described therein.
[0150] Figure 19Figure 1900 illustrates an example of a hardware implementation of device 1904. Device 1904 may be a UE, a component of a UE, or implement UE functionality. In some aspects, the device may correspond to a relay UE, such as a donor UE or an intermediate relay UE, for example, as in combination with... Figures 5A to 10 As described in any of the above. The device can operate as a donor UE in some cases and as an intermediate relay UE in others. In some aspects, the device can operate as a remote UE and may also include a combination of... Figure 18The multi-hop component 198 is described. The device 1904 may support relay UE operation, for example, as described in combination with a donor UE or an intermediate relay UE. In some aspects, the device 1804 may include at least one cellular baseband processor 1924 (also referred to as a modem) coupled to one or more transceivers 1922 (e.g., cellular RF transceivers). The cellular baseband processor 1924 may include at least one on-chip memory 1924'. In some aspects, the device 1904 may also include one or more Subscriber Identity Module (SIM) cards 1920 and at least one application processor 1906 coupled to a Secure Digital Card (SD) card 1908 and a screen 1910. The application processor 1906 may include on-chip memory 1906'. In some aspects, device 1904 may also include a Bluetooth module 1912, a WLAN module 1914, an SPS module 1916 (e.g., a GNSS module), one or more sensor modules 1918 (e.g., a barometric pressure sensor / altimeter; motion sensors such as an inertial measurement unit (IMU), a gyroscope, and / or an accelerometer; light detection and ranging (LIDAR), radio-assisted detection and ranging (RADAR), sound navigation and ranging (SONAR), a magnetometer, audio, and / or other technologies for positioning), an additional memory module 1926, a power supply 1930, and / or a camera 1932. Bluetooth module 1912, WLAN module 1914, and SPS module 1916 may include on-chip transceivers (TRX) (or in some cases, only receivers (RX)). Bluetooth module 1912, WLAN module 1914, and SPS module 1916 may include their own dedicated antennas and / or communicate using one or more antennas 1980. Cellular baseband processor 1924 communicates with UE 104 and / or RU associated with network entity 1902 via transceiver 1922 through one or more antennas 1980. Cellular baseband processor 1924 and application processor 1906 may each include computer-readable media / memory 1924', 1906' respectively. Additional memory module 1926 may also be considered as computer-readable media / memory. Each computer-readable media / memory 1924', 1906', 1926 may be non-transitory. Cellular baseband processor 1924 and application processor 1906 are each responsible for general processing, including the execution of software stored on the computer-readable media / memory. When executed by cellular baseband processor 1924 / application processor 1906, the software causes cellular baseband processor 1924 / application processor 1906 to perform the various functions described above. The computer-readable media / memory can also be used to store data manipulated by cellular baseband processor 1924 / application processor 1906 during software execution.Cellular baseband processor 1924 / application processor 1906 may be a component of UE 350 and may include at least one of memory 360 and / or TX processor 368, RX processor 356 and controller / processor 359. In one configuration, device 1904 may be at least one processor chip (modem and / or application) and may include only cellular baseband processor 1924 and / or application processor 1906, while in another configuration, device 1904 may be the entire UE (see, for example). Figure 3 The UE 350 includes an additional module for device 1904.
[0151] As discussed above, component 199 can be configured to: receive a discovery message associated with UE-to-network relay communication; determine the multi-hop relay of the discovery message; increment the hop count of the discovery message; protect the integrity of the discovery message; and forward the discovery message with the incremented hop count. In some aspects, multi-hop component 199 can be configured to provide additional discovery messages associated with emergency services and having integrity protection based on a null integrity protection algorithm. In some aspects, multi-hop component 199 can be configured to: determine a multi-hop path for UE-to-network relay communication; and perform a security procedure for UE-to-network relay communication via the multi-hop path, which includes a donor relay UE and at least one intermediate relay UE between the UE and the radio network. In some aspects, multi-hop component 199 can be configured to: receive a communication request from the UE, wherein the communication request includes the UE's UE identifier (ID); request a key from the network based on the UE ID; and obtain a first key from the network. In some aspects, multi-hop component 199 can be configured to provide a second key to at least one intermediate relay UE in the multi-hop path. In some aspects, the multi-hop component 199 can be configured to derive a second key from a first key, wherein the second key is a key different from the first key. In some aspects, the multi-hop component 199 can be configured to: perform a secure procedure at an intermediate relay UE for UE-to-network relay communication via a multi-hop path between the UE and the network; and forward communication between the network and the UE via a donor relay UE based on the secure procedure. In some aspects, the multi-hop component 199 can be configured to: receive a communication request from the UE, wherein the communication request includes a UE identifier (ID); request a key based on the UE ID; obtain a key from the donor relay UE; and establish secure communication with the UE based on the key. In some aspects, the multi-hop component 199 can be configured to provide a third key to an additional intermediate relay UE between the UE and the intermediate relay UE, wherein the third key is derived from the second key. Component 199 can also be configured to perform a combination... Figure 13 , Figure 14 , Figure 16 and / or Figure 17The flowchart describes various aspects and / or is provided by the relay UE in Figures 5A to 10Any aspect of the communication process executed in any of the following. Component 199 may be within cellular baseband processor 1924, application processor 1906, or both cellular baseband processor 1924 and application processor 1906. Component 199 may be one or more hardware components specifically configured to execute the stated process / algorithm, implemented by one or more processors configured to execute the stated process / algorithm, stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. When multiple processors are implemented, the multiple processors may execute the stated process / algorithm individually or in combination. As shown, device 1904 may include a variety of components configured for various functions. In one configuration, apparatus 1904 (and specifically cellular baseband processor 1924 and / or application processor 1906) may include: components for receiving a discovery message associated with UE-to-network relay communication; components for determining a multi-hop relay of the discovery message; components for incrementing the hop count of the discovery message; components for protecting the integrity of the discovery message; and components for forwarding the discovery message with the incremented hop count. In some aspects, apparatus 1904 may include components for providing an additional discovery message associated with emergency services and having integrity protection based on a null integrity protection algorithm. In some aspects, apparatus 1904 may include: components for determining a multi-hop path for UE-to-network relay communication; and components for performing a security procedure for UE-to-network relay communication via a multi-hop path, the multi-hop path including a donor relay UE and at least one intermediate relay UE between the UE and the wireless network. In some aspects, apparatus 1904 may include: means for receiving a communication request from a UE, wherein the communication request includes a UE identifier (ID); means for requesting a key from a network based on the UE ID; and means for obtaining a first key from the network. In some aspects, apparatus 1904 may include means for providing a second key to at least one intermediate relay UE in a multi-hop path. In some aspects, apparatus 1904 may include means for deriving a second key from the first key, wherein the second key is a key different from the first key. In some aspects, apparatus 1904 may include: means for performing a secure procedure at an intermediate relay UE for UE-to-network relay communication via a multi-hop path between the UE and the wireless network; and means for forwarding communication between the wireless network and the UE via a donor relay UE based on the secure procedure. In some aspects, apparatus 1904 may include: means for receiving a communication request from a UE, wherein the communication request includes a UE identifier (ID); means for requesting a key based on the UE ID; means for obtaining a key from a donor relay UE; and means for establishing secure communication with the UE based on the key.In some aspects, apparatus 1904 may include components for providing a third key to an additional intermediate relay UE between the UE and the intermediate relay UE, wherein the third key is derived from the second key. Apparatus 1904 may also include components for performing a combination. Figure 13 , Figure 14 , Figure 16 and / or Figure 17 The flowchart describes various aspects and / or is provided by the relay UE in Figures 5A to 10 Any component in any aspect of the communication process of any of the components. These components may be components 199 of device 1904 configured to perform the functions described therein. As described above, device 1904 may include TX processor 368, RX processor 356, and controller / processor 359. Thus, in one configuration, these components may be TX processor 368, RX processor 356, and / or controller / processor 359 configured to perform the functions described therein.
[0152] It should be understood that the specific order or hierarchy of the boxes in the disclosed process / flowcharts is merely an example of the exemplary method. It should be understood that the specific order or hierarchy of the boxes in the process / flowcharts may be rearranged based on design preferences. Furthermore, some boxes may be combined or omitted. The appended method claims present the elements of various boxes in a sample order, but are not limited to the given specific order or hierarchy.
[0153] The foregoing description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Therefore, the claims are not limited to the aspects described herein but should be given the full scope consistent with the language of the claims. Unless specifically stated otherwise, references to elements in the singular form do not mean “one and only one” but rather “one or more.” Terms such as “if,” “when,” and “simultaneously” do not imply a direct temporal relationship or reaction. That is, these phrases, such as “when,” do not imply an immediate action in response to the occurrence of an action or during the occurrence of an action, but simply suggest that if a condition is met, then the action will occur, without requiring a specific or immediate time limit for the occurrence of the action. The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any aspect described herein as “exemplary” is not necessarily to be construed as preferred or superior to other aspects. Unless specifically stated otherwise, the term “some” refers to one or more. Combinations such as "at least one of A, B, or C", "one or more of A, B, or C", "at least one of A, B, and C", "one or more of A, B, and C", and "A, B, C, or any combination thereof" include any combination of A, B, and / or C, which may include multiple A, multiple B, or multiple C. Specifically, combinations such as "at least one of A, B, or C", "one or more of A, B, or C", "at least one of A, B, and C", "one or more of A, B, and C", and "A, B, C, or any combination thereof" can be only A, only B, only C, A and B, A and C, B and C, or A and B and C, where any such combination may contain one or more members of A, B, or C. A set should be interpreted as a collection of elements, where the number of elements is one or more. Therefore, for a set of X, X will include one or more elements. When at least one processor is configured to execute a set of functions, the at least one processor is configured to execute the set of functions individually or in any combination. Therefore, each of the at least one processor can be configured to execute a specific subset of the set of functions, wherein the subset is the complete set, a suitable subset of the set, or an empty subset of the set. A processor may be referred to as a processor circuit. A memory / memory module may be referred to as a memory circuit. If a first device receives data from or sends data to a second device, data can be received / sent directly between the first and second devices, or indirectly between the first and second devices through a set of devices. A device configured to "output" data (such as transmission, signal, or message) may, for example, transmit the data using a transceiver, or may transmit the data to the device that sent the data.A device configured to "acquire" data (such as, transmit, signal, or message) may receive the data, for example, using a transceiver, or may obtain the data from a device that receives the data. Information stored in memory includes instructions and / or data. All structural and functional equivalents of the elements throughout the various aspects described herein that are known to those skilled in the art or will later be known are expressly incorporated herein by reference and are covered by the claims. Furthermore, nothing disclosed herein is intended to be offered to the public, whether or not such disclosure is expressly recited in the claims. The words "module," "mechanism," "element," "device," etc., cannot replace the word "component." Therefore, no claim element will be construed as a functional component unless the element is expressly recited using the phrase "component for..."
[0154] As used in this article, the phrase “based on” should not be interpreted as referring to a closed set of information, one or more conditions, one or more factors, etc. In other words, the phrase “based on A” (where “A” can be information, conditions, factors, etc.) should be interpreted as “based on at least A”, unless otherwise stated otherwise.
[0155] The following aspects are merely illustrative and may be combined with other aspects or teachings described herein without limitation.
[0156] Aspect 1 is a method for performing wireless communication at a UE, the method comprising: receiving a discovery message associated with UE-to-network relay communication; determining a multi-hop discovery based at least on the discovery message; and verifying the discovery message, wherein the discovery message is at least protected by integrity.
[0157] In aspect 2, according to the method of aspect 1, the method further includes: the discovery message further includes hop count information for the multi-hop discovery, wherein verification of the discovery message is based at least in part on the hop count information.
[0158] In aspect 3, the method according to aspect 1 or 2 further includes: the discovery message includes a discovery notification message and a discovery request message.
[0159] In aspect 4, the method according to any one of aspects 1 to 3 further includes: receiving an additional discovery message associated with an emergency service without integrity protection, wherein the integrity protection for the discovery message uses a null integrity protection algorithm.
[0160] Aspect 5 is a method for wireless communication at a relay UE, the method comprising: receiving a discovery message associated with UE-to-network relay communication; determining a multi-hop relay of the discovery message; incrementing a hop count of the discovery message; protecting the integrity of the discovery message; and forwarding the discovery message having the incremented hop count.
[0161] In aspect 6, according to the method of aspect 5, the method further includes: the discovery message includes a discovery notification message, a discovery request message, or a discovery response message.
[0162] In aspect 7, the method according to aspect 5 or 6 further includes: providing an additional discovery message associated with emergency services and having integrity protection based on a null integrity protection algorithm.
[0163] Aspect 8 is a method for wireless communication at a UE, the method comprising: determining a multi-hop path for UE-to-network relay communication with a wireless network, the multi-hop path including a plurality of relay UEs between the UE and the wireless network; performing a security procedure for the UE-to-network relay communication via the multi-hop path to the wireless network; and exchanging communication with the wireless network via the multi-hop path based on the security procedure.
[0164] In aspect 9, according to the method of aspect 8, the method further includes: performing the security process for the multi-hop path including: receiving a PRUK and a PRUK ID from a network entity; providing a direct communication request to the wireless network via a donor relay UE and an intermediate relay UE in the multi-hop path between the UE and the wireless network; and establishing a secure PC5 link with the intermediate relay UE based on a derived key associated with the PRUK.
[0165] In aspect 10, according to the method of aspect 9, the method further includes: the derived key is the same derived key used for the donor relay UE and the intermediate relay UE in the multi-hop path to the wireless network.
[0166] In aspect 11, according to the method of aspect 9, the method further includes: the derived key is a second key derived from a first key associated with the donor relay UE.
[0167] In aspect 12, the method according to any one of aspects 8 to 11, the method further includes: the safety process is for UP.
[0168] In aspect 13, the method according to any one of aspects 8 to 11, the method further includes: the security process is for CP.
[0169] Aspect 14 is a method for wireless communication at a donor relay UE, the method comprising: determining a multi-hop path for UE-to-network relay communication; and performing a security procedure for the UE-to-network relay communication via the multi-hop path, the multi-hop path including the donor relay UE and at least one intermediate relay UE between the UE and a wireless network.
[0170] In aspect 15, the method according to aspect 14 further includes: performing the security process for the UE comprising: receiving a direct communication request from the UE, wherein the communication request includes a PRUK ID for the UE; requesting a key from the network based on the PRUK ID; and obtaining a first key from the network.
[0171] In aspect 16, according to the method of aspect 15, the method further includes: providing a second key to at least one intermediate relay UE in the multi-hop path.
[0172] In aspect 17, according to the method of aspect 16, the method further includes: the second key is the same key as the first key obtained by the donor relay UE.
[0173] In aspect 18, the method according to aspect 16 further includes: deriving a second key from the first key, wherein the second key is a key different from the first key.
[0174] In aspect 19, the method according to any one of aspects 14 to 18, the method further includes: the safety process is for UP.
[0175] In aspect 20, the method according to any one of aspects 14 to 18, the method further includes: the security process is for CP.
[0176] Aspect 21 is a method for wireless communication at an intermediate relay equipment (UE), the method comprising: performing a secure procedure at the intermediate relay UE for UE-to-network relay communication via a multi-hop path between the UE and a wireless network; and forwarding communication between the wireless network and the UE via a donor relay UE based on the secure procedure.
[0177] In aspect 22, according to the method of aspect 21, the method further includes: performing the security process for the UE-to-network relay communication via the multi-hop path, comprising: receiving a direct communication request from the UE, wherein the communication request includes a PRUK ID; requesting a key based on the PRUK ID; obtaining the key from the donor relay UE; and establishing secure communication with the UE based on the key.
[0178] In aspect 23, according to the method of aspect 22, the method further includes: the key is the same key used for the donor relay UE.
[0179] In aspect 24, according to the method of aspect 22, the method further includes: the key is a second key different from a first key used for the donor relay UE, and wherein the second key is derived from the first key.
[0180] In aspect 25, according to the method of aspect 24, the method further includes: providing a third key to an additional intermediate relay UE between the UE and the intermediate relay UE, wherein the third key is derived from the second key.
[0181] In aspect 26, the method according to any one of aspects 21 to 25, the method further includes: the security process is for UP.
[0182] In aspect 27, the method according to any one of aspects 21 to 25, the method further includes: the security process is for CP.
[0183] Aspect 28 is an apparatus for wireless communication at a device, the apparatus comprising: a memory; and at least one processor coupled to the at least one memory and based at least in part on stored information stored in the at least one memory, the at least one processor being configured individually or in any combination to implement any one of aspects 1 to 4.
[0184] Aspect 29 is the apparatus according to aspect 28, the apparatus further comprising a transceiver or antenna coupled to the at least one processor.
[0185] Aspect 30 is an apparatus for wireless communication at a device, the apparatus including components for implementing any one of aspects 1 to 4.
[0186] Aspect 31 is a computer-readable medium (e.g., a non-transitory computer-readable medium) that stores computer-executable code, wherein the code, when executed by one or more processors, causes the one or more processors to implement any one of aspects 1 to 4.
[0187] Aspect 32 is an apparatus for wireless communication at a device, the apparatus comprising: a memory; and at least one processor coupled to the at least one memory and based at least in part on stored information stored in the at least one memory, the at least one processor being configured individually or in any combination to implement any one of aspects 5 to 7.
[0188] Aspect 33 is the apparatus according to aspect 32, the apparatus further comprising a transceiver or antenna coupled to the at least one processor.
[0189] Aspect 34 is an apparatus for wireless communication at a device, the apparatus including components for implementing any one of aspects 5 to 7.
[0190] Aspect 35 is a computer-readable medium (e.g., a non-transitory computer-readable medium) that stores computer-executable code, wherein the code, when executed by one or more processors, causes the one or more processors to implement any one of aspects 5 to 7.
[0191] Aspect 36 is an apparatus for wireless communication at a device, the apparatus comprising: a memory; and at least one processor coupled to the at least one memory and based at least in part on stored information stored in the at least one memory, the at least one processor being configured individually or in any combination to implement any one of aspects 8 to 13.
[0192] Aspect 37 is the apparatus according to aspect 36, the apparatus further comprising a transceiver or antenna coupled to the at least one processor.
[0193] Aspect 38 is an apparatus for wireless communication at a device, the apparatus including components for implementing any one of aspects 8 to 13.
[0194] Aspect 39 is a computer-readable medium (e.g., a non-transitory computer-readable medium) that stores computer-executable code, wherein the code, when executed by one or more processors, causes the one or more processors to implement any one of aspects 8 to 13.
[0195] Aspect 40 is an apparatus for wireless communication at a device, the apparatus comprising: a memory; and at least one processor coupled to the at least one memory and based at least in part on stored information stored in the at least one memory, the at least one processor being configured individually or in any combination to implement any one of aspects 14 to 20.
[0196] Aspect 41 is the apparatus according to aspect 40, the apparatus further comprising a transceiver or antenna coupled to the at least one processor.
[0197] Aspect 42 is an apparatus for wireless communication at a device, the apparatus including components for implementing any one of aspects 14 to 20.
[0198] Aspect 43 is a computer-readable medium (e.g., a non-transitory computer-readable medium) that stores computer-executable code, wherein the code, when executed by one or more processors, causes the one or more processors to implement any one of aspects 14 to 20.
[0199] Aspect 44 is an apparatus for wireless communication at a device, the apparatus comprising: a memory; and at least one processor coupled to the at least one memory and based at least in part on stored information stored in the at least one memory, the at least one processor being configured individually or in any combination to implement any one of aspects 21 to 27.
[0200] Aspect 45 is the apparatus according to aspect 44, the apparatus further comprising a transceiver or antenna coupled to the at least one processor.
[0201] Aspect 46 is an apparatus for wireless communication at a device, the apparatus including components for implementing any one of aspects 21 to 27.
[0202] Aspect 47 is a computer-readable medium (e.g., a non-transitory computer-readable medium) that stores computer-executable code, wherein the code, when executed by one or more processors, causes the one or more processors to implement any one of aspects 21 to 27.
Claims
1. An apparatus for wireless communication at a user equipment (UE), the apparatus comprising: At least one memory; and At least one processor, coupled to the at least one memory, and configured, individually or in any combination, based at least in part on stored information stored in the at least one memory, to cause the UE to: Receive discovery messages associated with UE-to-network relay communication; Multi-hop discovery is determined at least based on the discovery message; and Verify the discovery message, wherein the discovery message is at least protected by integrity.
2. The apparatus of claim 1, wherein the discovery message further includes hop count information for the multi-hop discovery, wherein verification of the discovery message is based at least in part on the hop count information.
3. The apparatus of claim 1, wherein the discovery message includes a discovery notification message and a discovery request message.
4. The apparatus of claim 1, wherein the at least one processor is further configured, individually or in any combination, to cause the UE to: Receive additional discovery messages associated with emergency services that lack integrity protection, wherein the integrity protection for the discovery messages uses an empty integrity protection algorithm.
5. The apparatus according to claim 1, further comprising: A transceiver coupled to the at least one processor, the transceiver being configured to receive the discovery message.
6. An apparatus for conducting wireless communication at a relay user equipment (UE), the apparatus comprising: At least one memory; and At least one processor, coupled to the at least one memory, and configured individually or in any combination, based at least in part on information stored in the at least one memory, to cause the relay UE to: Receive discovery messages associated with UE-to-network relay communication; Determine the multi-hop relay of the discovery message; Increment the hop count of the discovery message; Protect the integrity of the discovery message; as well as Forward the discovery message with an incremented hop count.
7. The apparatus of claim 6, wherein the discovery message includes a discovery notification message, a discovery request message, or a discovery response message.
8. The apparatus of claim 6, wherein the at least one processor is further configured, individually or in any combination, to cause the relay UE to: Provides additional discovery messages associated with emergency services and with integrity protection based on the null integrity protection algorithm.
9. The apparatus according to claim 6, further comprising: A transceiver coupled to the at least one processor, the transceiver being configured to receive the discovery message.
10. An apparatus for wireless communication at a user equipment (UE), the apparatus comprising: At least one memory; and At least one processor, coupled to the at least one memory, and configured, individually or in any combination, based at least in part on stored information stored in the at least one memory, to cause the UE to: Determine a multi-hop path for UE-to-network relay communication with the wireless network, the multi-hop path including multiple relay UEs between the UE and the wireless network; Perform a secure procedure for the UE-to-network relay communication via the multi-hop path to the wireless network; as well as Based on the security process, communication is exchanged with the wireless network via the multi-hop path.
11. The apparatus of claim 10, wherein, in order to perform the security process for the multi-hop path, the at least one processor is further configured, individually or in any combination, to cause the UE to: Receive the prose relay user key (PRUK) and PRUK identifier (ID) from the network entity. The UE provides a direct communication request to the wireless network via the donor relay UE and intermediate relay UE in the multi-hop path between the UE and the wireless network; and A secure PC5 link is established with the intermediate relay UE based on the derived key associated with the PRUK.
12. The apparatus of claim 11, wherein the derived key is the same derived key used for the donor relay UE and the intermediate relay UE in the multi-hop path to the wireless network.
13. The apparatus of claim 11, wherein the derived key is a second key derived from a first key associated with the donor relay UE.
14. The apparatus of claim 10, wherein the security process is for the user plane (UP).
15. The apparatus of claim 10, wherein the safety process is for the control plane (CP).
16. The apparatus of claim 10, further comprising: A transceiver coupled to the at least one processor, the transceiver being configured to exchange the communication with the wireless network.
17. An apparatus for wireless communication at a donor relay user equipment (UE), the apparatus comprising: At least one memory; and At least one processor, coupled to the at least one memory, and configured individually or in any combination, based at least in part on stored information stored in the at least one memory, to cause the donor relay UE to: Determine the multi-hop path used for UE-to-network relay communication; as well as Perform a secure procedure for the UE-to-network relay communication via the multi-hop path, the multi-hop path including the donor relay UE and at least one intermediate relay UE between the UE and the wireless network.
18. The apparatus of claim 17, wherein, in order to perform the security process for the multi-hop path, the at least one processor is configured individually or in any combination to cause the donor relay UE to: The UE receives a direct communication request, wherein the direct communication request includes a prose relay user key (PRUK) (ID) for the UE. Request a key from the network based on the PRUK ID; and Obtain the first key from the network.
19. The apparatus of claim 18, wherein the at least one processor is further configured, individually or in any combination, to cause the donor relay UE to: A second key is provided to the intermediate relay UE in the multi-hop path.
20. The apparatus of claim 19, wherein the second key is the same as the first key obtained by the donor relay UE.
21. The apparatus of claim 19, wherein the at least one processor is further configured, individually or in any combination, to cause the donor relay UE to: The second key is derived from the first key, wherein the second key is a key different from the first key.
22. The apparatus of claim 17, wherein the security process is for the user plane (UP).
23. The apparatus of claim 17, wherein the safety process is for the control plane (CP).
24. An apparatus for performing wireless communication at an intermediate relay equipment (UE), the apparatus comprising: At least one memory; and At least one processor, coupled to at least one memory, and configured individually or in any combination, based at least in part on information stored in the at least one memory, to enable the intermediate relay UE to: A secure procedure is performed at the intermediate relay UE for UE-to-network relay communication via a multi-hop path between the UE and the wireless network; as well as Based on the security process, communication between the wireless network and the UE is forwarded via the donor relay UE.
25. The apparatus of claim 24, wherein, in order to perform the security process for the UE-to-network relay communication via the multi-hop path, the at least one processor is further configured, individually or in any combination, to cause the intermediate relay UE to: The UE receives a direct communication request, wherein the direct communication request includes a prose relay user key (PRUK) identifier (ID). Request the key based on the PRUK ID; Obtain the key from the donor relay UE; and Secure communication is established with the UE based on the key.
26. The apparatus of claim 25, wherein the key is the same key used for the donor relay UE.
27. The apparatus of claim 25, wherein the key is a second key different from the first key used for the donor relay UE, and wherein the second key is derived from the first key.
28. The apparatus of claim 27, further comprising: A transceiver coupled to the at least one processor, wherein the at least one processor, individually or in any combination, is also configured to enable the intermediate relay UE to: A third key is provided to an additional intermediate relay UE between the UE and the intermediate relay UE, wherein the third key is derived from the second key.
29. The apparatus of claim 24, wherein the security process is for the user plane (UP).
30. The apparatus of claim 24, wherein the safety process is for the control plane (CP).